Introduction
The Access Control screen allows you to control which users have access to what information on the Teramind Dashboard and what settings they are allowed to change.
1. Click the + New Policy button to create a new access rule.
2. Click the TThree Dots
icon in front of an access control rule to open its Context Menu:
Select View Access Rule to inspect the configuration of built-in access control rules (indicated by a "Default" badge, such as Employee or Administrator).
Select Edit Access Rule to view and edit a custom access rule. You can also click the name of an access control rule to edit it. Editing an access rule is similar to creating a new access control policy/rule (see below).
Select Delete to permanently remove an access rule.
Access Control Policy Types
There are two types of access control policies you can create:
List Access Control Policy: A List or Regular access control policy allows you to define what information privileged users can view or edit.
Role Access Control Policy: A Role-Based Access Control (RBAC) policy allows you to assign special management permissions in addition to the view/edit permissions to privileged users. For example, the ability to edit employee profiles, create behavior policies and rules, etc. With the Role policies, you can create some unique user roles. For example, turn a department manager into a ‘semi-admin’ who can manage employees like an admin but only employees in his/her department (unlike an admin who has access to all employees).
Creating a List Access Control Policy
Information:
This section allows you to configure the basic details of the policy.
1. Enter a Policy Name to identify the policy (required).
2. Optionally, enter a Policy Description to explain the policy's purpose.
3. Select List Access Control Policy from the Type drop-down list.
Grant Privileges:
This section defines which users will receive the access privilege configured in this policy.
4. Use the Grant Privilege dropdown to select the employees or departments that will be granted the policies/permissions defined below. Selected users (e.g., “John Doe”, “Oliver Cruze” in the example screenshot above) are shown as removable tags above the dropdown.
Policies:
Policies are like containers for permissions. This section lets you organize permissions into separate, named policies within the same access control rule.
5. Use the Policy tabs (e.g., Policy 1, Policy 2, etc.) to manage multiple policies within the same access control rule. Click + New Policy to add another policy. Each tab represents an independent set of permissions and resources. Note that every permission in a policy applies to every resource in it, so add a separate policy for each unique permission-resource combination.
Permissions:
Permissions define which features (such as menus, dashboards, and widgets) privileged users can access, as well as the specific actions (such as view or edit) they are allowed to perform.
6. Use the permission type tabs (e.g., View, Play, Edit, Access Widgets) to switch between permission categories. The counter next to each tab (e.g., 3/35) shows how many permissions of that type have been selected out of the total available. Click Select all to enable all permissions in the current category at once.
7. Check or uncheck individual permissions within the selected category to grant or revoke specific capabilities. In the example screenshot above, the "View risk dashboard," "View webpages and applications report," and "View behavior alerts report" are enabled. The note at the bottom indicates how many permissions are currently granted by this policy.
8. Use the Search field to quickly find specific permissions by name.
Resources:
Resources are the specific target entities (e.g., employees, departments, etc.) that policies and permissions apply to. They define the scope of access for privileged users, limiting their access strictly to the assigned entities.
9. Use the Type dropdown to select the type of resource (e.g., Employee, Department, Computer, Shared List) and then use the Select Resources from the list below dropdown to choose the specific resources the permissions will apply to. Selected resources (e.g., “Edgar Jones”, “john's macbook air”, “Marketing”, “White listed applications” in the example screenshot above) appear as removable tags at the top of the Resources panel.
Saving:
10. Click Save to create the policy, or Cancel to discard all changes and return to the Access Control list.
Creating a Role Access Control Policy
Information:
This section allows you to configure the basic details of the policy.
1. Enter a Policy Name to identify the policy (required).
2. Optionally, enter a Policy Description to explain the policy's purpose.
3. Select List Access Control Policy from the Type drop-down list.
Grant To:
This section explains how the policy is assigned to users.
4. Unlike a List Access Control Policy, privileges for a Role Access Control Policy is not granted from the policy itself. Instead, it is assigned from the individual employee's profile (under the Access Control tab), along with the specific resources it grants access over.
Permissions:
Permissions define which features (such as menus, dashboards, and widgets) privileged users can access, as well as the specific actions (such as view or edit) they are allowed to perform.
5. Use the permission type tabs (e.g., View, Play, Edit, Management Features, Access Widgets) to switch between permission categories. The counter next to each tab (e.g., 3/35) shows how many permissions of that type have been selected out of the total available. Click Select all to enable all permissions in the current category at once.
6. Check or uncheck individual permissions to grant or revoke specific capabilities. In this example, the Management features tab is active and "Configure access control policies," "Configure access tokens," and "Create new agents" are enabled. The note at the bottom shows the total number of permissions currently granted by this policy.
7. Use the Search field to quickly find specific permissions by name.
Saving:
8. Click Save to create the policy, or Cancel to discard all changes and return to the Access Control list.
Assigning Role Access Control Policies to Users
Unlike List Access Control policies, which let you select privileged users directly while creating or editing the policy, Role Access Control policies require you to assign privileged users and targets from the employee's profile under the Access Control tab.



