- Getting started
- Best practices
- Organization Modeling in Orchestrator
- Automation Best Practices
- Optimizing Unattended Infrastructure Using Machine Templates
- Organizing Resources With Tags
- Orchestrator Read-only Replica
- Exporting grids in the background
- Enforcing user-level Integration Service connection governance
- Tenant
- About the Tenant Context
- Searching for Resources in a Tenant
- Managing Robots
- Connecting Robots to Orchestrator
- Storing Robot Credentials in CyberArk
- Storing Unattended Robot Passwords in Azure Key Vault (read only)
- Storing Unattended Robot Credentials in HashiCorp Vault (read only)
- Storing Unattended Robot Credentials in AWS Secrets Manager (read only)
- Deleting Disconnected and Unresponsive Unattended Sessions
- Robot Authentication
- Robot Authentication With Client Credentials
- Configuring automation capabilities
- Solutions
- Audit
- Cloud robots
- Folders Context
- Automations
- Processes
- Jobs
- Apps
- Triggers
- Logs
- Monitoring
- Queues
- Assets
- Business Rules
- Storage Buckets
- MCP Servers
- Indexes
- Orchestrator testing
- Resource Catalog Service
- Integrations
- Troubleshooting

Orchestrator user guide
Enforcing user-level Integration Service connection governance
linkUse this procedure to prevent regular users from creating shared Integration Service connections in team folders, while still allowing them to create and use private connections in their Personal Workspace.
- You have Orchestrator administrator permissions to manage roles, folders, and assignments. For more information, check the Access control page.
- Integration Service is enabled on your tenant.
- Personal Workspaces are enabled for end users. For more information, check the Personal Workspaces page.
-
Go to the shared folder where the attended automation is deployed.
This folder is used for shared attended processes. If you do not have a shared folder, create one.
Users can run processes from this folder. They cannot create new connections from here, but they can view and use shared connections deployed by an administrator. This ensures that end users cannot expose their personal connections in the shared folder, where others would gain access to them.
For more information on how to create folders, check the Managing folders page.
-
Assign the built-in Automation User role to the users running the attended
automation in that folder via UiPath Assistant.
The Automation User role does not include the Connections.Create permission by default. With this action you make sure that users with the Automation User role assigned cannot create Connections in shared folders.
Alternatively, you can create a custom role at folder-level that does not have the Connections.Create permission and assign it to the users with the Automation User role.
For more information on how to create custom roles, check the Managing custom roles page.
For more information on default roles, check the Default roles page.
-
Create and make sure that users have a Personal Workspace.
By having a Personal Workspace, users will have a private space where they can create and manage their own connections without exposing them to other users.
For more information on Personal Workspaces, check the Personal Workspace page.