Summary
This article provides you an overview of Access Policies, what they are, and how to use them to manage your users’ access to Ironclad.
Use Case
At Classics Inc., legal operations uses Access Policies to keep contracts for each business unit separate while allowing a central team to manage shared workflows. They create a baseline policy for legal operations and add a scoped policy so regional teams can view and edit only the workflows and records for their region.
Permissions
| Features | Access Policies |
| Permissions |
To access and manage Groups and Access Policies, you must be an administrator. Policy-Based Access Control is generally available for new customers. Existing customers must complete a migration before they can use this feature. If you’re an existing customer, contact your Ironclad representative or Support to learn more about the migration process and timeline. |
What is Policy-Based Access Control?
Policy-Based Access Control is a permissions model that helps admins manage access with reusable policies and detailed rules. An Access Policy bundles Access Rules and can be assigned to multiple groups, making it easier to reuse the same permissions.
Each Access Rule gives admins more control by defining:
- what resources a group can access,
- what actions it can take,
- and whether access should be limited by conditions such as region.
For example, a rule could allow a group to view and edit workflows only when the region is North America.
What can admins do with Policy Based Access Control?
Access Policies help admins:
- Control what groups can view, edit, launch, or manage.
- Keep workflows and records separate by region, business unit, or sensitivity when supported.
- Protect confidential agreements, such as M&A or executive contracts.
- Give local admins control over users and groups in a specific business unit or operating company without giving them global administrator access.
- Start with built-in policies, create custom policies, or combine multiple policies for a group.
- Reuse the same set of rules across multiple groups.
Groups start with no access by default. A group receives access only when an Access Policy or local Access Rule grants it. When multiple policies are assigned to a group, the group receives the combined access from all of them.
Key terms
Access Policies use a few building blocks to define permissions. The table below explains how groups, resource types, actions, and scopes work together to control access in Ironclad.
| Term | Definition | Example or note |
| Access Policy | A named, reusable bundle of access rules that can be assigned to one or more groups. | A Contract Reviewer policy could allow a group to view and edit workflows and records. |
| Access Rule | The basic building block of an Access Policy. An Access Rule determines what actions can be done on which resource types, and under what conditions. | Allow view and edit on workflows, but only in the EMEA region. |
| Resource Type | The kind of object that an access rule applies to. | Workflows, records, groups, or users. |
| Group | A collection of users that share access. | A user's access is determined by which groups they are a member of and the Access Policies and Access Rules that have been applied to those groups. |
| Action | What a group is allowed to do with a resource. | View, edit, launch, or manage. |
| Scope | A limit on where an access rule applies, based on attributes on the resource. | Region, business unit, or sensitivity. |
| Local Access Rule | An access rule added directly to one group. | Gives one group extra access without changing a shared Access Policy. |
| System Policy | A read-only access policy created by Ironclad from common permission patterns. | Duplicate it to create an editable custom policy or to add a more narrow scope. |
| Custom Policy | An access policy created or changed by a customer. | Can be edited and deleted to meet specific access needs. |
How filtering and search work
Admins can use filters and search on the Access Policies page to narrow the list and find a specific policy.
Next steps
- Create an Access Policy: Learn how to create a policy and define the access rules it contains.
- Duplicate an Access Policy: Learn how to copy an existing policy and use it as a starting point for a new policy.
- Edit an Access Policy: Learn how to update an existing policy and its access rules.
Resources
Explore articles, courses, and support options to get the most out of Ironclad.
Help Center
- No relevant resources at this time.
Academy
- No relevant resources at this time.