Previous Topic: Security ModelsNext Topic: Management Groups


Policy Roles

You can use policy roles to ensure that a user can only see events captured by specific types of trigger when they search for events.

For categorization purposes, you can associate individual triggers with a policy class, such as ‘Employee Behavior’ or ‘Legal’. When a trigger fires, the policy class is stored with the associated event.

A policy role links a user to a collection of policy classes. In effect, the policy role determines which policy classes a user is permitted to see. When the user runs a search, the results only include events associated with these policy classes.