Skip to content

5. Policies

5.1. What is a Policy?

Policies are a way to restrict access within a project to certain users. Project roles (Viewer, Member, Admin, Owner — see Project Members) control what a user can do across a project as a whole. Policies operate at a finer grain: they let you limit who can see or work with particular content inside a project, so that membership of the project does not automatically grant access to everything within it.

This is useful where a single project contains information that should be visible only to a subset of its members. For example, a project might hold documents or attributes that are appropriate for the clinical team but not for every collaborator who otherwise needs access to the case. A policy allows that separation to be enforced within the project rather than requiring a separate project.

5.2. When to Use a Policy

Most teams will not need policies for routine work: standard project roles, together with the project privacy levels (Public, Protected, Private) described in Creating Projects and Collections, are sufficient for the majority of cases. Consider a policy when:

  • A project must be shared broadly, but some of its content is sensitive and should be visible only to specific users.
  • Different collaborators on the same case have different need-to-know requirements.
  • You need an access boundary inside a project without splitting the case across multiple projects.

5.3. Setting Up Policies

Because policies define an access-control boundary, they should be configured carefully and in line with your organization's data-governance requirements. If you would like to use policies to restrict access within a project, please contact the Frameshift team, who can help you design and apply a policy that matches your needs.

Warning! Policies govern who can access information within a project. As with any access-control mechanism, review the configuration carefully before relying on it, and confirm that the users who should — and should not — have access are correctly scoped.