Steps to Create a Policy
Follow these steps to create and publish a policy.
Basic & Triggers
- Navigate to Identity Governance & Administration > Policy > Policy Library.
- Select Create Policy.
- Enter a unique Policy Name.
- Enter a Description.
- Confirm the Type. The type is set to Application Governance Policy.
- Assign one or more Owners. Up to three owners can be assigned.
- Assign one or more Assignees. Up to five assignees can be assigned.
- Select a Severity:
- Low
- Medium
- High
Add a Trigger
- Select + Add Trigger.
- In the Select a Trigger panel, choose one of the following:
- Scheduled
- App Ownership Changed
- App Subcategory Changed
- App Type Changed
- New App Discovered
- Application Archive
- Application Unarchive
- App Link Updated
- App Status Changed
- App Auth Status Change
- App User Status Change
- Configure trigger settings:
- For Scheduled, configure frequency, time, and timezone.
- For event-based triggers, define required conditions such as Changed from and Changed to.
- Select Save.
- Select Next.
Multiple triggers can be configured within the same policy.
Scope
-
Select the Entity Type:
- Application
- Application User
-
Under Include, define which entities the policy evaluates:
- Select Scope Applications to choose specific applications.
- Or select Add by Criteria to define attribute-based conditions.
-
Define at least one inclusion condition.
At least one inclusion condition is required.
-
Under Exclude (Optional), define exclusions if needed:
- Scope specific applications
- Or define exclusion criteria using attributes
-
Select Save and Preview.
-
Review matching entities in the preview panel.
-
Select Next.
Rules
- Select the Entity Type:
- Application
- Application User
- Under Include, select Add by Criteria.
- In the filter panel:
- Select a category such as Application, Licence, Contract, Spend/Cost, or User.
- Select the required attribute.
- Choose an operator such as:
- Is greater than
- Is greater than or equal to
- Is less than
- Is less than or equal to
- Is equal to
- Is in range
- Enter the comparison value.
- Select Apply Filter.
- Use Add Filter to add additional conditions within the same criteria set.
- Use Add Filter Group to define additional logical groups.
- Under Exclude (Optional), define exclusion conditions if required.
- Select Save and Preview.
- Review matching entities in the preview panel.
- Select Next.
Rules define the violation criteria evaluated against scoped entities.
Remediation
- Under Remediation, select a Mode:
- Monitor (Detect Only) — Records violations without enforcement.
- Enforce (Detect and enforce) — Records violations and executes a selected playbook.
- If Monitor is selected, enter required Remediation steps.
- If Enforce is selected, select a required Playbook.
- Enable Allow exemptions if policy owners should be able to request exemptions.
- Review notification events:
- New Violation Detected
- Policy Status Changed
- Exemption Created
- Exemption Revoked
- Remediation Failed
- Policy Evaluation Failed
- Select Next.
Review & Publish
- Review the configuration summary:
- Basics & Trigger
- Scope
- Rules
- Remediation
- Select the edit icon next to any section to modify configuration if required.
- Enter a required Publish Note.
- Select Publish.
After Publishing
- The policy status changes to Published – v1.
- The policy appears in Policy Library with status Published.
- The system records:
- Published Version
- Published On
- Published By
If the policy remains unpublished, the status remains Draft, and the policy does not execute.
Updated about 4 hours ago
