Configure inheritance policies

Last update:
Aug 21, 2026
Scenario
An administrator needs to configure inheritance policy for a Policy-on application in AIC so access is granted and revoked only through group membership, rather than manual user-level role changes. This supports governance by centralizing access rules in Applications, under the application Access tile using View and Update, where roles are assigned to groups from the Groups tab. It is typically performed during onboarding, role redesign, or remediation after audit findings to ensure users inherit only approved access. This approach simplifies ongoing access management because updates to group membership drive effective access consistently.
Prerequisites
  • Administrator has access to Applications and permission to update the application Access configuration.
  • Target Policy-on application is identified (Application name or Application ID).
  • Target Group name is identified (the group that will drive inherited access).
  • Required Roles exist for the application (or the admin can create them).
  • Admin has clarity on the required governance mapping (which group should inherit which roles).
Steps
  1. Sign in to Aikyam Identity Console.
  2. Navigate to Applications from the left navigation pane.
  3. Open the application Access tile.
  4. Click View and Update.
  5. In the Access section, select the Groups tab.
  6. Locate the required group (use Search group by name if needed) and click the Group name to open group details.
  7. In the group left menu, select Roles , assign the required role or roles to the group.
  8. Click Save.
Note:
  • In this UI, inheritance policy is implemented by assigning roles to groups in the application Access configuration. Users inherit these roles through group membership.
  • For Policy-on applications, revocation should be done by removing the user from the group, not by manually removing roles at the user level.
  • If a user belongs to multiple groups, they may inherit access from multiple group mappings (effective access can be cumulative depending on system behavior).

On this page

Powered by Aikyam @2025 All rights reserved