Access to Policy Foundry is managed in the Users app in the Kio Cloud section of the Launchpad, not within Policy Foundry itself. Each person who needs access must have a user profile and be assigned a Policy Foundry role. An app appears on a user's Kontakt.io Launchpad only if they are assigned a role for it.
Roles are assigned by a user with the User Management Administrator role. See Add a user and Assign roles and access to a user.
What makes up a user's access
Access to Policy Foundry is by role only. Policy Foundry has two roles — Administrator and User — and is not limited by campus or department.
Roles
Policy Foundry has two roles.
| Role | Who it's for |
|---|---|
| Administrator | People who create and manage policies and their actions — full configuration access. |
| User | People who need to view policies and activity without changing anything. |
What each role can do
Yes means the role has the permission; No means it does not.
| Capability | Administrator | User |
|---|---|---|
| View the policy list and policy status | Yes | Yes |
| View the Activity Log | Yes | Yes |
| Create, edit, pause, or delete a policy | Yes | No |
| Create, edit, or delete a Stream, Email, or Text Message action (under Templates) | Yes | No |
How users and Groups are managed
How users are created and maintained depends on whether your organization uses single sign-on (SSO):
- Managed users are created and maintained directly in the Users app. A Managed Group can assign roles to several users at once.
- SSO users sign in through your identity provider, which supplies their identity and roles. These sync into the Users app as view-only — you change them in the identity provider.
Instead of setting roles in each person's profile, you can assign them to a Group and add members to it. Members inherit the Group's application roles in addition to anything set directly on their profile. See About Groups and Assign application roles to a Group.
The tasks for managing users are shared across all Kio apps and live in the Users app:
- Add a user — create a managed user.
- Assign roles and access to a user — give a person a Policy Foundry role.
- Enable, disable, or delete a user — change or remove a person's access.
Roles that live outside Policy Foundry
- User Management Administrator — required to create users and assign Policy Foundry roles, in the Users app.