# Flow Security, If, then How can it be done?

**URL:** <https://discourse.nodered.org/t/flow-security-if-then-how-can-it-be-done/16507>\
**Category:** Feature Requests\
**Tags:** security\
**Created:** [9 October 2019 13:23 UTC](https://discourse.nodered.org/t/flow-security-if-then-how-can-it-be-done/16507 "2019-10-09T13:23:03Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [20 January 2020 09:58 UTC](https://discourse.nodered.org/t/flow-security-if-then-how-can-it-be-done/16507/6 "2020-01-20T09:58:25Z")

</div>

> [@tree-frog](#):
>
> I would like to submit this as a FEATURE REQUEST.  
> Tab Permissions to tighten security on the Flow Tab level.

Hi, did anything come of this?

As I become responsible for more (node-red) integration I find scenarios where I would like to lock down a TAB but permit another user (e.g. 1st line 24/7 support operator) to log in & view/debug the flows and perhaps even allow modification of permitted tab(s).

Mock scenario - support member could view and operate debug/injects on TAB1 but not TAB2 however via permissions, he can look at and inspect TAB2. If so permitted, could be permitted to modify TAB1...

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/1/d1bd0628bf250c6d0887bd5c56a5d83ccbe275d0.png)

Another scenario I face - I write the complex logic and processing on 1 TAB (this must be locked down to protect the process) but there is no reason a support member cannot be permitted to add items to a setup (change node) e.g. fill in a list IP addresses to poll on separate TAB. Yes this could be completed on a separate instance and transmitted via HTTP/MQTT etc however the added complexity and components somewhat muddy the waters.

Is there anything in the works or under consideration?

**I do realise this will be quite involved and require much more thought, discussion and consideration than my 20 minutes preparing this response this but I am interested to know if this is something under consideration or currently in development?**

Cheers, Steve.

_inner voice / thoughts..._  
_I realise much of this could be achieved by a dashboard or MQTT/HTTP to external application however, node-red itself is a very good tool in terms of visual comprehension and being able to see where a problem stems from (chasing the debug messages) can give a greater insight to the issue at hand_

---

_[View the full topic](https://discourse.nodered.org/t/flow-security-if-then-how-can-it-be-done/16507)._
