IGA
Policy Engine
The policy engine evaluates access requests against declarative rules in real time. Policies can enforce time-of-day restrictions, geo-fencing (allow access only from specific countries or IP ranges), minimum approval depth, and conditional requirements (e.g., require MFA step-up for production workspaces). Policies are versioned and auditable -- every change is tracked in the audit log.
Policy simulation mode lets administrators test proposed policies against historical access data before activating them in enforcement mode.
Key Configuration
- Policy type (time, geo, approval, conditional)
- Scope (tenant-wide, workspace, resource type)
- Enforcement mode (enforce / simulate / audit-only)
- Policy priority and conflict resolution