Create Scheme Policies on PrivaceraCloud
For conceptual background and planning, see the Scheme Policies Overview.
Steps to Create Scheme Policies on PrivaceraCloud#
- Login to the Privacera Portal.
- Navigate to Access Manager > Scheme Policies.
- Find and click the PEG resource name.
- If you want this scheme policy to be in effect for only a specific time period, in the upper right, click Add Validity Period and enter the details of that period.
- Enter a name for the scheme policy.
- If needed, select any policy labels you want for this scheme policy.
- If you do not want audit logging, use the Audit Logging toggle to turn it off.
- With the Enabled toggle, you can create the policy but not yet enable it.
- In the Encryption Schemes field, select the name of the encryption scheme to which you want to apply the policy. Repeat this for all required encryption schemes.
- For Presentation Schemes field, select the name of the presentation scheme to which you want to apply the policy. Repeat this for all required presentation schemes.
- Enter a description of this scheme policy.
-
Depending on how you have decided to allow or deny access, use the fields in Allow conditions or Deny Conditions and follow the corresponding steps below:
-
Allow Access
- Under Allow Conditions, in the role, group, and user fields, select the names of roles, groups, or users you want to give access to the schemes.
- On the right, click Add Permission and specify the permission you want to give. Note:
- getSchemes permission is required for Databricks UDFs.
- protect/unprotect permissions are required for REST API calls.
- On the far right, click Delegate Admin if you want the service user to be able to make API requests on behalf of the application user.
- If you want to deny access to specific roles, groups, or users, under Exclude from Allow Conditions, select those roles, groups, or users you want to exclude.
-
Deny Access
- Under Deny Conditions, in the role, group, and user fields, select the names of roles, groups, or users you want to deny access to the schemes.
- On the right, click Add Permission and specify the permission you want to deny.
- On the far right, click Delegate Admin if you want the service user to be able to make API requests on behalf of the application user.
- If you want to give access to specific roles, groups, or users, under Exclude from Deny Conditions, select those roles, groups, or users you want to allow.
-
-
Save your scheme policy.
Last update: December 21, 2021