Scenario
An administrator needs to configure inheritance policy for a
Policy-on application in AIC so access is granted and revoked
only through group membership, rather than manual user-level role changes. This supports governance by centralizing access rules in
Applications, under the application
Access tile using
View and Update, where
roles are assigned to groups from the
Groups tab. It is typically performed during onboarding, role redesign, or remediation after audit findings to ensure users inherit only approved access. This approach simplifies ongoing access management because updates to group membership drive effective access consistently.