Skip to main content

Access policy concepts

Access policies decide whether a caller may perform an action on a TaruviBase resource. Read these pages before writing rules, because the Console views, the SDK checks, and Database filtering all apply the same model.

  • Access decisions: the caller, resource, action, and condition that produce every allow or deny decision.
  • Roles, policies, and conditions: how App Roles, memberships, synchronized Role Policies, and access-policy types relate to each other.
  • Automatic system policies: how TaruviBase synchronizes policies for system resources, and how to recover when synchronization is incomplete.

Put the model to work#

Apply the model through the policy lifecycle, then use Live Testing before assigning access through Users and authentication. If the model and observed decision disagree, stop at Troubleshooting.