Create an SoD policy
SoD policies define the conflicting entitlement combinations Zluri detects and how it responds when it finds a match. Creating a policy takes you through a 5-step wizard: Basic & Triggers, Scope, Rules, Remediation, and Review & Publish.
Navigate to IGA > SoD > Policy Library and select Create Policy to open the wizard. The wizard navigation lists all five steps.
Configure basics and triggers
The first step sets the policy name, assignees, severity, and detection schedule.
Steps
- Enter a Policy Name. Names must be unique within your organization.
- Enter an optional Description (up to 512 characters).
- Select up to 3 Owners. Owners are responsible for this policy. Owners must hold the Owner, Admin, or IT Admin role.
- Select up to 5 Assignees. Assignees receive violation tasks when the policy detects a conflict.
- Select a Severity: Low, Medium, or High. Zluri applies this severity to all violations the policy raises.
- Select + Add Trigger to open the Add trigger modal.
- Select a Schedule Type and configure the schedule.
- Interval: Set Runs every (a number and unit, for example 1 Month), Runs on (day of the month), Runs at (time of day), and Timezone. The preview banner at the bottom updates as you configure each field, for example: "Every month on day 1st at 01:00 AM (UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi."
- Cron: Enter a cron expression in the Cron Expression field. The default expression is
0 0 1 * *. Select a Timezone.
- Select Save to add the trigger as a card on the Basic & Triggers step.
- Select Next to proceed to Scope.
Next becomes active only after you enter a Policy Name, select at least one Owner, at least one Assignee, a Severity, and add at least one trigger.
Scope identities
The Scope step defines which identities this policy evaluates. Narrowing scope reduces false positives and speeds up detection runs.
[SCREENSHOT: Scope step showing the Scope Identities section with the Inclusion area (+ Add Specific Identities and + Add by Criteria options) and the Exclusion (Optional) area below it, with the empty Preview panel on the right]
Steps
- In the Inclusion section, add identities using one or both methods:
- + Add Specific Identities: select identities from the list. The list shows User Name, Unique ID, User Type, and Status for each identity. Selected identities appear in the Selected Identities panel on the right.
- + Add by Criteria: build filter conditions using the attributes in the table below. Zluri joins multiple conditions with And or Or logic.
- Optionally, in the Exclusion section, add identities to subtract from the inclusion match set using + Exclude Specific Identities or + Add by Criteria.
- Select Preview to review matched identities in the panel on the right.
- Select Next to proceed to Rules.
A non-blocking warning appears if the matched identity count exceeds 50,000.
Use the following attributes to build criteria-based scope filters:
| Attribute | Description |
|---|---|
| Source | The identity source, for example, Okta, Azure AD, or BambooHR. |
| Identity Type | Employee, External, Service Account, or Group Account. |
| App Category | The category of an application the identity has access to. |
| Tags | Custom tags applied to the identity in Zluri. |
| Department | The identity's department from the connected HRMS. |
| Location | The identity's location from the connected HRMS. |
Configure rule sets
The Rules step defines the two conflicting entitlement sets. Set A and Set B are always present. You cannot remove them or add a third set.
[SCREENSHOT: Rules page showing the Set A card and Set B card, each in an empty state with a Configure button]
Steps
- Select Configure on the Set A card to open the rule set editor.
- Enter a Rule Set Name (defaults to "Set A", up to 100 characters).
- In the Access Criteria section, add entitlements to the Inclusion area using + Add Specific Entitlements, + Add by Criteria, or both. Zluri joins multiple blocks with OR logic.
- To require an AND condition, select the + button next to an entitlement chip in the Inclusion area. Both entitlements must be present for that block to match.
- Optionally, in the Exclusion area, add entitlements to subtract from the inclusion match set using + Exclude Specific Entitlements or + Add by Criteria.
- Select Save Rule Set.
- Repeat for Set B.
Both rule sets must have at least one inclusion block before Next becomes active. Once both sets are saved, each card shows the entitlement summary (for example, "1 Roles") and an Edit button. If Set A and Set B match identical entitlement sets, Zluri displays a non-blocking warning: "Your sets overlap. Violations may over-fire."
Add specific entitlements
Steps
- Select + Add Specific Entitlements to open the Add Entitlement modal.
- Select one or more entitlements from the list. The list shows Entitlement Type (Role, Permission, or Group) and Entitlement name for each item.
- Selected entitlements appear in the Selected Entitlements panel on the right. Select Clear all to deselect all.
- Select Save to add the entitlements to the rule set.
[SCREENSHOT: Add Entitlement modal showing the entitlement list with Entitlement Type and Entitlement columns, with one entitlement selected and shown in the Selected Entitlements panel on the right]
Use this method when you know the exact roles, permissions, or group memberships that form one side of the conflict.
Add entitlements by criteria
Steps
- Select + Add by Criteria.
- Build filter conditions using the attributes in the table below.
- Select Preview to see the entitlements the criteria match.
- Select Save Criteria Set to add the criteria block to the rule set.
[SCREENSHOT: Add by Criteria modal showing filter conditions in the Filters panel and matched entitlements in the Preview panel]
Use this method when you want a rule that automatically adapts as entitlements change in the source application, for example, "all privileged permissions in Workday."
Use the following attributes to build criteria-based rules:
| Attribute group | Available attributes |
|---|---|
| Role attributes | Role Name, Role Type, Privileged Role (yes or no), Role Description |
| Permission attributes | Permission Name, Permission Type, Privileged Permission (yes or no), Permission Description |
| Group attributes | Group Name, Group Source, Group Tag |
| Application attributes | Application, App Status, App Category, App Sub-Category, App Authorization Status, App Owner, App IT Owner, App Finance Owner, App Sources, App Custom Fields |
After saving both rule sets, the Rules summary page shows the configured entitlements for Set A and Set B and the Simulate button becomes active. Use Simulate to verify which identities match the toxic combination before proceeding to Remediation.
[SCREENSHOT: Rules summary page showing both configured sets — Set A and Set B each showing Inclusion entitlement type chips (for example, 1 Roles) and Exclusion showing "No exclusions configured", with the active Simulate button in the top right and Next button active at the bottom]
Select Next to proceed to Remediation.
Simulate a policy before publishing
Simulation validates a policy's detection accuracy without writing violations to the live violation store. The Simulate option becomes available after you configure both Scope and Rules.
Run a Quick Validation
Steps
- On the Rules summary page, select Simulate.
- Select Quick Validation.
- Search for and select a single identity.
- Zluri evaluates the selected identity against both rule sets and displays the verdict within seconds. The result shows whether Zluri detected a violation, which sets matched, and the contributing entitlements. When Zluri detects no violation, it displays an explanation of why the identity did not match.
Use Quick Validation to spot-check whether a specific identity matches the configured toxic combination before running a full simulation.
Run a Full Simulate
Steps
- On the Rules summary page, select Simulate.
- Select Full Simulate.
- Zluri runs detection across the entire matched scope in the background.
- When the simulation completes, select View Results to see matched identities and their offending entitlements. The results table shows up to the first 500 matched identities.
- Select Export CSV to download the full simulation results.
[SCREENSHOT: Full Simulate results table showing matched identities with columns for identity name, Set A entitlements, and Set B entitlements, plus the Simulate Again button and the last-run timestamp]
Zluri displays the timestamp of the most recent simulation run. Select Simulate Again to run a fresh simulation.
Use Full Simulate to understand total violation volume before publishing and to build confidence in the rule configuration before promoting to Enforce mode.
Configure remediation
The Remediation step defines how Zluri handles violations this policy detects. Select a mode first; the remaining fields change based on your selection.
Set up Monitor mode
Steps
- Select Monitor (Detect and Notify).
[SCREENSHOT: Remediation step with Monitor (Detect and Notify) selected, showing the mode info banner, the required Remediation steps rich text field (0/500 characters), and the Allow exemptions toggle]
- Enter Remediation steps (up to 500 characters). Describe the manual steps a reviewer should follow to resolve a violation.
- Optionally, turn on Allow exemptions? to let policy owners request exemptions for specific identities.
- Select Next to proceed to Review & Publish.
Zluri keeps violations open for review in Monitor mode and notifies the policy owner when violations are found.
Use Monitor mode when first deploying a policy to validate that the rules catch the right violations before enabling enforcement.
Set up Enforce mode
Steps
- Select Enforce (Detect and Act).
[SCREENSHOT: Remediation step with Enforce (Detect and Act) selected, showing the Violation Handling options (Assignee decides which side to remove / Choose the default side to remove now), the Remediation Playbook for Set A and Remediation Playbook for Set B dropdowns, and the Allow exemptions toggle]
- Choose a Violation Handling option:
- Assignee decides which side to remove: Zluri routes a decision task to the assignees configured in Basics & Triggers. The assignee reviews the violation and selects which set to revoke. Zluri runs the corresponding Playbook.
- Choose the default side to remove now: Zluri automatically revokes entitlements from a pre-selected set using the configured Playbook. No human approval is needed.
- Select a Remediation Playbook for Set A and a Remediation Playbook for Set B. Each Playbook defines the revocation actions to run when that set is selected for removal.
- Optionally, turn on Allow exemptions? to let policy owners request exemptions for specific identities.
- Select Next to proceed to Review & Publish.
Use Enforce mode after validating the policy in Monitor mode and confirming it catches the right violations.
Review and publish
The final step presents a complete summary of the policy for review before publishing.
[SCREENSHOT: Review & Publish page showing all four summary cards — Basics & Trigger (with Policy Name, Type, Owner, and Trigger), Scope, Rules (with Set A and Set B entitlement chips), and Remediation (showing Remediation Mode and Exemptions) — each with a pencil edit icon, and the Publish Note field at the bottom]
Steps
- Review all four summary cards: Basics & Trigger, Scope, Rules, and Remediation.
- Select the pencil icon on any card to return to that step and make changes without losing other configurations.
- Review the Rules card to confirm the entitlements configured for Set A and Set B.
- Review the Remediation card to confirm the Remediation Mode and Exemptions settings.
- Enter a Publish Note (mandatory, 512-character limit). Zluri records this note in the policy's version history and audit log.
- Select Publish. A confirmation dialog appears: "Are you sure you want to publish this policy? Publishing will activate this policy and begin evaluation."
- Select Publish in the dialog to confirm.
[SCREENSHOT: Publish confirmation dialog showing "Are you sure you want to publish this policy?" with the message "Publishing will activate this policy and begin evaluation" and Cancel and Publish buttons]
After publishing, the policy status changes from Draft to Published. Zluri queues the first detection scan based on the configured trigger schedule and writes an entry to the audit log with the author, timestamp, policy version, and Publish Note.
Updated 8 days ago