Permission Policies

A permission policy grants a User a set of permissions and membership in one or more Environments. Use policies when you onboard people through SSO. API keys still carry their own permission flags; policies are how SSO knows which environment to mint a key in.

Without a policy that lists at least one environment, SSO cannot mint a session. A User record alone is not enough.

Configure policies in Canopy as part of Setting up Single Sign-On (step 3).

Policies vs API key permissions

Surface

What it controls

API key permissions

What a specific key can do in its environment (execute, manage webhooks, …). See API Key Permissions

Permission policy

Which permission set and which environments an SSO user may enter. Used when Poly mints the SSO key

Do not treat the two as the same UI. Key checkboxes are the v1 catalog. Policies bind people to environments.

Related: Authentication model.