Policy Requests
Policy requests are generated when you create cross-scope policies using the method described in (Advanced) Create Cross-Scope Policies. Each time a policy is created in a consumer scope's primary workspace when the provider is a member of a different scope, if the policy does not yet exist in the primary workspace associated with the provider's scope, a policy request is generated.
This policy request alerts the owner of the provider application to allow dependent applications to access necessary services.
See options for viewing and responding to policy requests at Viewing, Accepting, and Rejecting Policy Requests and Automate Handling of Cross-Scope Policy Requests.
Additional details about policy requests
-
The provided services page (on which policy requests appear) is only available to primary workspaces. This is to ensure that isolated experiments on secondary workspaces do not create notifications on other primary workspaces.
-
If an external scope (when the provider specified in the policy belongs to a different scope than the consumer) does not have a primary workspace, no requests are sent (for example, this could be the case for the root scope, or any scope defined for workloads outside the organization). If an external scope has not published any policy, policy analysis and enforcement are carried out on the consumer end only.
-
Clusters are not supported when the provider is in a different scope than the consumer. If the policy’s consumer is a cluster, the policy request will be made as if the policy request were from the consumer application’s scope. Multiple policies consuming the same service from a provider could be grouped together.
-
Policy requests are generated only for providers, not for consumers. If a consumer workspace is analyzing or enforcing policies, it has to explicitly include policies that allow all its legitimate consuming flows, either through automatic policy discovery or by explicitly manually crafting policies (no policy requests from external provider workspaces are generated to it).