Manage Interactions - Access
When creating an Access policy, define which applications should be allowed or blocked according to organizational needs and practical use cases. Instead of applying blanket restrictions, consider the context in which each application is used. For example, you might allow access to ChatGPT for marketing content generation but block it for source code development to prevent intellectual property exposure. This approach ensures policies are tailored to business requirements while maintaining security.
In the Access page, select applications, assign rules to user groups, and set enforcement actions such as Allow or Block. Use filters like risk level and business function to fine-tune your policy for different scenarios. To learn examples of the Access policies, see Control Policy Framework.
To add a new rule:
-
From the left menu, select Workforce AI > Manage Interactions > Access.
-
On the toolbar, click Create new.
-
On the right pane, edit the new rule:
-
On the Settings tab, enter the rule name.
-
Set the Active slider to ON (green).
-
Select Entire organization to apply the rule for all users.
-
Select Selected users and groups to set the rule granularity:
-
Select the relevant groups from the list. The groups appear based on the selected Identity Provider.
-
Select the relevant users from the list. The users appear based on the selected Identity Provider.
-
-
Set the destination where the rule applies:
-
Any - for all applications
-
Applications - select one or more discovered AI tools
-
-
Select the Action to perform when the rule is triggered:
-
Allow
-
Ask
-
Block
-
-
Select to enable or disable Logging.
-
-
For Ask actions only, configure Customization:
-
Below Blocking message, select:
-
Default to use global blocking messages configured in Settings > User Interactions.
-
Custom to edit a rule-specific message:
-
Edit Title.
-
Edit Description.
-
Click Preview page to see the message.
-
-
-
-
Click Save.
| Policy |
Short Description |
Behavior |
Data Flow | Data Control |
|---|---|---|---|---|
|
Allow |
Always allow the action |
Accepts the entered data without restrictions. Action proceeds normally. |
Allowed |
Not restricted |
|
Ask |
User must confirm |
Prompts the user to approve or cancel the action before proceeding. |
Conditional |
Conditional |
|
Block |
Do not allow the action |
Rejects the entered data and stops the action. |
Not allowed |
Attempt blocked |
|
Detect |
Log the event only |
Identifies and records the data event without changing or interrupting the action. |
Allowed |
Not restricted |
|
Prevent |
Strictly block the action |
Actively stops the action and may disable the ability to submit data. |
Not allowed |
Action disabled |
|
Redact |
Remove sensitive data |
Allows the action but removes or masks sensitive information before processing. |
Sanitized only |
Sensitive data |