Access to Policy Foundry is managed in the Users app in the Kio Cloud section of the Launchpad, not within Policy Foundry itself. Each person who needs access must have a user profile and be assigned a Policy Foundry role. An app appears on a user's Kontakt.io Launchpad only if they are assigned a role for it.
Roles are assigned by a user with the User Management Administrator role. See Add a user and Assign roles and access to a user.
What makes up a user's access
Access to Policy Foundry is by role only. Policy Foundry has two roles — Administrator and User — and is not scoped by campus or department.
Roles
Policy Foundry has two roles.
| Role | Who it's for |
|---|---|
| Administrator | People who create and manage policies and their actions — full configuration access. |
| User | People who need to view policies and activity without changing anything. |
What each role can do
Yes means the role has the permission; No means it does not.
| Task | Administrator | User |
|---|---|---|
| View the policy list and policy status | Yes | Yes |
| View the Activity Log | Yes | Yes |
| Create, edit, pause, or delete a policy | Yes | No |
| Create, edit, or delete a Stream, Email, or Text Message action (under Templates) | Yes | No |
How users and Groups are managed
- Accounts without SSO: a User Management Administrator assigns Policy Foundry roles directly in the Users app. A Managed Group can assign roles to several users at once.
- Accounts with SSO: users, roles, campus access, and Groups sync from your organization's identity provider and are view-only in the Users app; you change them in the identity provider.
See About Groups.
Roles that live outside Policy Foundry
- User Management Administrator — required to create users and assign Policy Foundry roles, in the Users app.