You can assign different permission sets to different policy users, so that they can create and modify specific product policies. Some users can approve or deny changes from policies and policy assignments submitted by other users.
Policies can be managed by users with different permissions. As an administrator, you can create users with hierarchical levels of policy permissions. For example, you can create these policy users:
Policy administrator — Approves policies and policy assignments created and modified by other users.
Policy and Policy Assignment user — Duplicates and creates policies and modifies the policy assignment, that they submit to the policy administrator for approval before they are used.
Overview of creating policy users
In Permission Sets, create different permission sets for the policy administrator and policy user.
In User Management, create policy administrator and policy user, then manually assign them the different permission sets.
Policy user capabilities
Duplicate, modify, or create policies and policy assignments and submit them to the policy administrator for approval.
Monitor the approval status by the policy administrator.
Policy administrator capabilities
All functions of the policy user.
Approve or reject changes.
Capabilities | Policy user | Policy administrator |
|---|---|---|
Duplicate, modify, or create policies and policy assignments and submit them for approval | × | × |
Monitor the approval status | × | × |
Approve or reject policies | × |