PlainID includes the Policy Canvas, a visual way to create and manage Policies in a Policies Workspace. You build a Policy on the canvas from three building blocks, Identities, Assets, and Conditions, and the Platform generates the underlying Policy for you. You do not need to know Rego or any other policy language.
The Policy Canvas is a Workspace-level choice. Each Policies Workspace uses either the Policy Canvas or the Policy Wizard to author Policies. New Workspaces use the Wizard by default. When a Workspace uses the Policy Canvas, the canvas replaces the Wizard for creating Policies and replaces the Rules and Map views when you open a Policy.
Enabling the Policy Canvas
The Policy Canvas is off by default. New Policies Workspaces use the Policy Wizard until you switch them to the canvas. You set this per Workspace in the Workspace settings, and you need permission to edit the Workspace settings to change it.
To enable the Policy Canvas for a Workspace:
- In the Workspaces list, hover over the relevant Policies Workspace and click the settings icon. The Policies Workspace Settings screen opens on the Details tab.
- Click Edit.
- Under Policy View, click Canvas.
- Click Save.
The change takes effect immediately for the Workspace. The Create New options in the Policy Catalog switch to the canvas, and every Policy in the Workspace opens with a Canvas tab. You can switch a Workspace back to Wizard at any time, including when it already contains Policies. For more information on Workspace settings, see Policies Workspace Settings.
Accessing the Policy Canvas
You open the Policy Canvas in one of two ways:
- To create a new Policy: Select a Policies Workspace. In the Policy Catalog, click + and select From Canvas.
- To view or edit an existing Policy: In the Policy Workspace, click the relevant Policy, then select the Canvas tab.
The Policy page also includes the Details, Code, and Audit tabs. For more information on these tabs, see Managing Policies.
Policy Building Blocks
The canvas arranges a Policy as three boxes, read from left to right: Identities, then Assets, then Conditions. Each box defines one part of the Policy, and a number on the box shows how many items you selected in it.
| Box | Defines | What you select | What you can create from the canvas | More information |
|---|---|---|---|---|
| Identities | Who gets access | One or more Identity Templates, and Dynamic Groups within each template | New Dynamic Groups | Managing Dynamic Groups |
| Assets | What they can access | One or more Asset Types, and Rulesets or Assets within each Asset Type, each with its Action | New Rulesets | Managing Rulesets, Managing Assets |
| Conditions | When access applies | One or more Conditions from the Workspace | New Conditions | Managing Conditions |
Clicking an item in a box opens a panel on the right side of the canvas where you can add each Identity Template, Asset Type, and Condition to a Policy. The Canvas offers only templates and Asset Types that exist in your Environment and Workspace.
Use the controls in the lower-left corner of the canvas to zoom in, zoom out, and fit the Policy to the screen.
AI Policy Assistant
The Identities and Conditions configuration panels include the AI Policy Assistant, a chat that helps you build that part of the Policy in natural language. To open it, click the AI Assistant icon in the upper corner of the panel. The chat is scoped to the box you opened. To return to the list of items, click Back To Structured.
Creating a Policy
You create a Policy by filling the three boxes on an empty canvas and then naming the Policy.
To create a Policy from the canvas:
- In the Policies Workspace, open the Policies tab.
- In the Policy Catalog, click + and select From Canvas. An empty canvas opens with the + Identities, + Assets, and + Conditions boxes.
- Define who gets access:
- Click + Identities and select an Identity Template from the list. The template appears on the canvas and its configuration panel opens.
- Select one or more Dynamic Groups. To create a Dynamic Group, click Add New, define its name and rules, and click Save.
- To add another Identity Template, click + Identities again.
- Define what they can access:
- Click + Assets and select an Asset Type from the list. The Asset Type appears on the canvas and its configuration panel opens under Allow access to.
- On the Rulesets tab, select one or more Rulesets, or click Select All. To create a Ruleset, click Add New, define its name and rules, and click Save.
- For Platform Asset Types, you can also open the Assets tab and select specific Assets.
- Define when access applies: click + Conditions and select one or more Conditions. To create a Condition, click Add New.
- Click Save. The Save Policy dialog opens.
- Enter the Policy details:
- Display Name (required)
- Policy ID (required)
- Description (optional)
- Click Save. The Platform creates the Policy and adds it to the Policy Catalog.
To discard the Policy at any point before you save it, click Cancel. To close a configuration panel without leaving the canvas, click X in the upper corner of the panel.
Viewing and editing a Policy
The Canvas tab of a Policy opens in view mode. It shows the Identity Templates, Asset Types, and Conditions the Policy uses, with the selected items listed in each box. To see the rules behind an item, click its filter icon.
To edit a Policy on the canvas:
- In the Policy Catalog, click the Policy and select the Canvas tab.
- Click Edit in the upper-right corner of the canvas. Empty boxes appear for any building block the Policy does not use yet, for example + Assets.
- Make your changes:
- To change the selected items, click a box and select or clear items in its configuration panel.
- To remove an item from the Policy, hover over it in its box and click Remove (X).
- To add an Identity Template, Asset Type, or Condition, click the matching + box.
- Click Save to apply your changes, or Cancel to discard them.
To change the Policy name, ID, or description, use the Details tab. For more information, see Managing Policies.
Use Cases
Use the Policy Canvas to build and maintain Allow Policies in Workspaces with a single Application. The canvas supports the following use cases.
Future capabilities will be added in the following table.
| Use case | Example |
|---|---|
| Grant a group of Identities access to a set of Assets | Allow the Managers Dynamic Group to access every Asset in the All Ruleset of the Claims Asset Type. |
| Grant access to specific Assets | For an Platform Asset Type, select individual Assets on the Assets tab instead of a whole Ruleset. |
| Allow a specific Action on Assets | Select the All Ruleset together with the View Action in one step. |
| Combine several Identity Templates or Asset Types in one Policy | Grant both employees and partners access to the same Ruleset. |
| Limit access with Conditions | Grant access only when the user has the admin role or the request meets a Condition. |
| Create building blocks while you build the Policy | Create a Dynamic Group, Ruleset, or Condition with Add New without leaving the canvas. |
| Get help from AI while you build | Describe the Identities or Conditions you need to the AI Policy Assistant. |
| Review and update existing Policies visually | Open a Policy on the Canvas tab to see who gets access, to what, and when, then click Edit to change it. |
For more information on the building blocks, see About Assets and Asset Types, About Conditions, and Managing Dynamic Groups.