This capability is available only for PlainID Preview Tenants (Pre-prod).
Controls define what Agents can access after the Platform authorizes an interaction.
In addition to Identities, MCP, RAG, and Output Guardrails, the Policy Builder supports Custom Asset Types, your own Asset templates, as Controls within a Policy. Custom Asset Types let you bring Assets unique to your organization into the same least-privileged access model as every other Control.
Custom Asset Type controls answer the question:
Which custom Assets can these users, through these Agents, access, and under what Conditions?
Granting Access to Custom Assets
Asset Types that are generated manually under Asset Types appear as Custom Asset Types.
To connect a Custom Asset Type:
- In the Policies Workspace in the Environment sidebar, select a Policy or create one.
- In the Policy Canvas, click the plus (+) icon on the Custom control component.
.png)
- From the dropdown list, select the Custom Asset Type template you want to connect.
.png)
- The canvas adds the selected template, and a configuration panel opens on the right, named after the Asset Type.
.png)
- In the configuration panel, use the Groups and Assets tabs to grant access:
- Select from the available Rulesets or Assets associated with the template, or generate a new Ruleset.
- If the Asset Type supports Actions, use the toggle to select the Actions you want to allow. Note that two Actions are allowed per Template.
You can connect multiple Custom Asset Type templates to a single Policy. Each one appears as a separate box on the canvas, stacked one below the other, so you can review and manage them at a glance.
Example use cases:
- Connect a Vendor Catalog Asset Type so an Agent can only access approved vendor records.
- Grant a support Agent access to a Ticketing Queue Asset Type, limited to read-only Actions.
- Bring a proprietary internal system into a Policy without waiting on a built-in integration.
By supporting Custom Asset Types alongside Identities, MCP, and RAG Controls, the Policy Builder lets you extend least-privileged access to any Asset Type your organization works with.