Add the required users and configure access policies to define who can access the vault, their role, and access level.
- The system creates a default admin policy. You can add users to this default policy. This is the only admin policy available for tokenization vaults.
- You create additional policies for users and add the required users to each policy.
See below for the roles granted to the Administrator and User access policies.
Role | Administrator | User |
|---|---|---|
Access all tokenization policies |
| |
Create tokenization policies |
| |
Edit tokenization policies |
| |
Delete tokenization policies | ||
Create local users | ||
Manage all access policies to determine user access and roles | ||
Manage the vault, including authentication and HSM configuration | ||
View the audit log |
|
See below for how to manage policies and users.
- Creating an access policy
- Editing an access policy
- Deleting an access policy
- Adding Cryptographic APIs users
- Editing Cryptographic APIs users
- Deleting Cryptographic APIs Users
If the vault is configured for Active Directory authentication, the Users tab does not appear, and you add AD users and groups directly in the access policy.