Pipelines are part of the Administrator and Manager roles. Both can create pipelines, edit them, move entries and delete them — there's no split between using a board and configuring it.
Agents don't have pipelines at all: no Pipelines entry in the sidebar, and no Pipelines tab on a contact or company. If a colleague can't find pipelines anywhere, their role is the reason — and since everyone you invite joins as a Manager by default, this usually means someone was deliberately set to Agent.
Each pipeline has a Visible to all users switch, in the create form and again in the settings. On — the default — means it's listed for everyone who has pipelines. Off means it's yours: it stops appearing in the list for your colleagues.
Use it to keep the list uncluttered rather than as a wall. Something genuinely confidential doesn't belong on a board your Managers can reach — and there's no per-person sharing here, so a private pipeline is a solo pipeline.
Anyone who can open a pipeline can move any card, edit any field, change the stages and delete the whole thing. There's no notion of owning an entry, and no confirmation beyond the one on deleting a pipeline.
In practice this is fine for a team that agrees on how the board works, and it's why the Activity list on each entry matters: it's the record of who moved what, and it's how you reconstruct a board that someone reorganised.
An automation isn't limited by the role of whoever triggered it — it does what it's configured to do. Emails it sends and tickets it raises appear as coming from your project, not from a person.
That makes publishing an automation a bigger decision than moving a card, and worth a second pair of eyes on a board with a lot of records.