Add the required users and configure access policies to define who can access the vault, their role, and access level. 

  • The system creates a default admin policy. You can add users to this default policy. This is the only admin policy available for tokenization vaults.
  • You create additional policies for users and add the required users to each policy.

See below for the roles granted to the Administrator and User access policies.

Role

Administrator

User

Access all tokenization policies

(tick)

(tick) 

Create tokenization policies

(tick)

(tick)  

Edit tokenization policies

(tick)

(error)  

Delete tokenization policies

(tick)

(error)

Create local users

(tick)

(error)

Manage all access policies to determine user access and roles

(tick)

(error)

Manage the vault, including authentication and HSM configuration

(tick)

(error)

View the audit log

(tick)

(tick) 

See below for how to manage policies and users.

If the vault is configured for Active Directory authentication, the Users tab does not appear, and you add AD users and groups directly in the access policy.