Access Policies

Access Policies let administrators control which Cloud data users can access in Yarken.

You can create policies using Cloud attributes and define conditions that determine which data is available to a user. Yarken applies the assigned policy automatically whenever the user accesses Cloud data.

Access Policies provide an additional layer of data access control. They work alongside existing role, account, cost center, and entity restrictions.


How Access Policies work

An Access Policy contains one or more rules that define the Cloud data a user can access.

The workflow is:

  1. Create an Access Policy.

  2. Define the required Cloud attribute rules.

  3. Save the policy.

  4. Assign the policy to a user from Admin > User Management > Users.

Yarken automatically applies the assigned policy when the user accesses Cloud data.

Note: You can assign only one Access Policy to each user.


Who can manage Access Policies

Administrators can create and manage Access Policies and assign them to users.

Access Policies do not restrict Admin or Cost Model Manager users. These roles do not require an Access Policy and retain unrestricted access to Cloud data.


How Access Policies affect users

Access Policy behaviour depends on the user's role and whether the user already exists in Yarken.

Existing users

For existing users in roles that require Access Policies, Yarken automatically assigns the default Full Access Policy. This preserves their unrestricted Cloud data access.

The Full Access Policy is system-defined and cannot be edited or deleted.

To restrict an existing user's Cloud data access, assign an appropriate custom Access Policy.

Important: If the Full Access Policy is replaced or removed from a user, Yarken does not automatically restore it. If the user is left without a required Access Policy, Yarken displays No access policy assigned, and the user cannot access the application until an administrator assigns a policy.

New users

New users in roles that require Access Policies must have a policy assigned before they can access Yarken.

If a required user does not have an Access Policy assigned, Yarken displays the following message after login:

No access policy assigned

The user cannot access menus or use Yarken until an administrator assigns an Access Policy.

Note: Admin and Cost Model Manager users do not require an Access Policy.


Where Access Policies apply

Access Policies restrict Cloud data wherever Yarken queries the Cloud cube, including:

  • Analytics reports

  • Custom Dashboards

  • Standard dashboards

  • Ask Yarken

  • Insights

  • Exported report data

  • APIs

  • Other features that query the Cloud cube. For example, an Analytics report returns only the Cloud data permitted by the user's Access Policy.


How Access Policies work with other access controls

Access Policies work alongside existing Yarken access controls. They do not replace role, account, cost center, or entity restrictions.

If multiple access controls apply to a user, Yarken enforces all applicable restrictions.

For example, if a Power User has both an Account Access restriction and an Access Policy, the user can access only data permitted by both controls.


Important considerations

Keep the following behaviours in mind when using Access Policies:

  • You can assign only one Access Policy to each user.

  • Admin and Cost Model Manager users are not restricted by Access Policies and do not require a policy assignment.

  • Existing users in roles that require Access Policies are initially assigned the default Full Access Policy.

  • The Full Access Policy cannot be edited or deleted.

  • New users in roles that require Access Policies must have a policy before they can access Yarken.

  • Access Policies work in addition to existing role, account, cost center, and entity restrictions.

  • Changes to an Access Policy take effect immediately.

  • You cannot delete a policy while it is assigned to a user.

  • Removing a required user's Access Policy without assigning another policy prevents that user from accessing Yarken.

  • Yarken does not automatically restore the Full Access Policy after it is replaced or removed from a user.


Next step


Related content