Visibility

Most Poly resources have a visibility field: ENVIRONMENT, TENANT, or PUBLIC. Visibility controls who can discover and call the resource. It does not grant write access. Updates still need permissions in the resource’s home environment.

Most resources default to ENVIRONMENT on create unless a product surface says otherwise. Applications default to TENANT. SSO login apps must be PUBLIC (Setting up Single Sign-On).

What each value means

Value

Discovery / execute

ENVIRONMENT

API keys in the same environment

TENANT

API keys in any environment of the same tenant

PUBLIC

Any tenant on the instance, unless that tenant has blocked some public scopes. Any tenant application or user can execute it if their API key permissions allow it

PUBLIC is truly public on that Poly instance. Do not set it unless you intend other tenants on na1 / eu1 to find the resource.

When to choose which

  1. Building alone in dev → ENVIRONMENT.

  2. Sharing a catalog with teammates who have keys in other environments of the same company → TENANT.

  3. Publishing helpers or an SSO login Application → PUBLIC, after a security review.

Footguns

Symptom

Check

Teammate cannot see a function

Resource is ENVIRONMENT and they are on another env key. Use TENANT or the same env key

Another tenant found our resource

It is PUBLIC. Change it unless that was the point

SSO login missing for others

Application left at default TENANT. Set PUBLIC

Assumed TENANT lets another env edit the resource

Visibility is discovery/execute, not mutate. Writes still need permissions in the home environment

Related: Platform Overview, Authentication model, Project Glide.