Summary
This article walks you through how to create an access policy.
Use Case
At Classics Inc., legal operations uses Access Policies to keep contracts for each business unit separate while allowing a central team to manage shared workflows. They create a baseline policy for legal operations and add a scoped policy so regional teams can view and edit only the workflows and records for their region.
Permissions
| Features | Access Policies |
| Permissions |
To access and manage Groups and Access Policies, you must be an administrator. Policy-Based Access Control is generally available for new customers. Existing customers must complete a migration before they can use this feature. If you’re an existing customer, contact your Ironclad representative or Support to learn more about the migration process and timeline. |
Overview
There are three parts to creating an Access Policy. You must:
Part One: Create an Access Policy
You do not need to apply an access policy to a group in order to save it. You can create, edit, review, and experiment with access rules before applying the policy. Until you apply the policy to a group, the rules do not grant access to that group, which helps prevent unintended access while you configure the policy.
- Click on your profile icon in the top right corner, and then select Company Settings > Access Policies. All of the Access Policies in your company’s instance are displayed.
- Click Create +.
- Enter a name for the policy.
- Add a description to explain what the policy allows.
- Select one or more groups to assign the policy to.
- Click Add access rule.
Part Two: Build the access rules
Configure access rules for different types of resources across Ironclad. To maintain platform security, access is restricted by default; users will have no access to a resource unless an explicit rule is created here to allow it.
An access rule combines a resource type, one or more actions, and an optional scope.
For example, an access rule can allow a group to view and edit workflows only when the workflow’s region is EMEA.
When creating a rule:
- Select the resource type that the group needs to access.
- Select the actions the group needs to perform.
- Add a scope only when access should be limited to matching resources.
- Review the rule summary to confirm what access the rule grants.
If a policy has no access rules, it grants no access. Add only the rules that the assigned groups need.
Important considerations
- Access is additive. A group can receive access from multiple policies, and its total access is the combined access from those policies.
- Scope is not available for every resource type because it depends on the attributes available for that resource. The first dropdown in Scope lists the resource attributes you can use to further limit access. When planning how to scope access, review the properties available for the resource in your company.
- Launching a workflow is an action that occurs on a Workflow Configuration resource, while access is controlled via actions on the regular Workflow resource for already-launched workflows.
- Use a local access rule for access that applies to one group only and does not need to be reused.
Part Three: Review and save the Access Policy
Review the access rules and resulting seat type. You can find the seat type underneath the Applied Groups section.
When you are done reviewing, click Save. The Access Policy is active.
Next steps
After creating a policy, review how to Duplicate an Access Policy or Edit an Access Policy.
Resources
Explore articles, courses, and support options to get the most out of Ironclad.
Help Center
- No relevant resources at this time.
Academy
- No relevant resources at this time.