As a best practice, flows should be restricted to certain users.

Omitting restrictions, potentially gives all users the possibility to invoke a flow. Permissions to run certain flows should be defined either at the profile or at the permission set level.

Did this answer your question?