Visibility¶
Most Poly resources have a visibility field: ENVIRONMENT, TENANT, or PUBLIC. Visibility controls who can discover and call the resource. It does not grant write access. Updates still need permissions in the resource’s home environment.
Most resources default to ENVIRONMENT on create unless a product surface says otherwise. Applications default to TENANT. SSO login apps must be PUBLIC (Setting up Single Sign-On).
What each value means¶
Value |
Discovery / execute |
|---|---|
|
API keys in the same environment |
|
API keys in any environment of the same tenant |
|
Any tenant on the instance, unless that tenant has blocked some public scopes. Any tenant application or user can execute it if their API key permissions allow it |
PUBLIC is truly public on that Poly instance. Do not set it unless you intend other tenants on na1 / eu1 to find the resource.
When to choose which¶
Building alone in
dev→ENVIRONMENT.Sharing a catalog with teammates who have keys in other environments of the same company →
TENANT.Publishing helpers or an SSO login Application →
PUBLIC, after a security review.
Footguns¶
Symptom |
Check |
|---|---|
Teammate cannot see a function |
Resource is |
Another tenant found our resource |
It is |
SSO login missing for others |
Application left at default |
Assumed TENANT lets another env edit the resource |
Visibility is discovery/execute, not mutate. Writes still need permissions in the home environment |
Related: Platform Overview, Authentication model, Project Glide.