Creating a Policy
This page walks through the fields you'll fill in when creating a Policy. For what each of these pieces means and why, see Policies.
Video walkthrough
From an earlier product version, so field names may have shifted slightly (Rule Pack is now Policy), but the flow is the same.
Navigate to Central Services → Policies and click the + button. You'll be prompted for:
- Name: name of the Policy
- Description: short description of the Policy
1. Choose what to protect
Select the Attributes or Attribute Groups this Policy applies to.
- On the left, you'll see your existing Attribute Groups and pre-built Classifications (for example, Corporate Data, Employee Data).
- Select a Group, Classification, or individual Attribute, then Add Selected.
You can mix individual Attributes and whole Attribute Groups in the same Policy.
2. Choose which countries it applies to
Click Select Country to choose one or more countries this Policy governs, then Add Selected. Because data-sharing regulations vary by jurisdiction, this scopes the Policy to requests coming from (or targeting) those countries specifically.
3. Add Claims
Claims (the "Boolean Engine") match conditions passed through the eXate API against the request, for example a user's department or role. Add a Claim Pack, built in the Claims step, and eXate checks whatever is passed through the API against it before granting access.
4. Set Purpose of Use
Click Purpose of Use and select which declared reasons for accessing the data are permitted under this Policy, then Add Selected. Requests declaring any other purpose are restricted from accessing that data. The available purposes are configured under Data Usage, covered below.
Editing a Policy
Open any existing Policy from the Policies page via the pencil icon. Attributes, Attribute Groups, Countries, Claims, and Purpose of Use can all be amended from here. Edits can be submitted for approval, saved, or discarded.
Configuring Data Usage (Purpose of Use options)
Data Usage is where the list of purposes available in step 4 above is maintained, Central Services → Data Management → Data Usage.
Video walkthrough
From an earlier product version, so field names or screens may have shifted slightly.
Click the "+" button at the top of the Data Usage page and fill in:
- Data Usage Name: name of the data usage
- Description: description of how the data will be used
- Is consent required: toggle indicating whether consent is required
Click on a chosen entry to view or edit it.
Worked Example: Putting It Together
A Policy ties Attributes, Countries, Claims, and Purpose of Use together. Example configuration:
- Attributes: Customer, Date of Birth, First Name, Last Name
- Countries: United Kingdom, Luxembourg
- Claims: Sensitive Client Data Claim Pack
- Purpose of Use: Legitimate Use
Video walkthrough
From an earlier product version (shown there as a Rule Pack, now called a Policy), so field names may have shifted slightly.