Troubleshoot Cross-Scope Policies
If cross-scope policies were created using the method described in (Advanced) Create Cross-Scope Policies, the primary workspaces for the consumer and provider workloads must each have a policy that allows the traffic. Ensure that the required policies exist in both workspaces.
No notification is given if one of the policies is deleted or modified.
If the policy pair was generated during policy discovery, see information about approving policies to protect them from subsequent discovery runs. See Approve Policies.
Verify that other requirements are still being met, as listed in (Advanced) Create Cross-Scope Policies.
Both consumer and provider workspaces that have the required policies must be enforced.
Useful tools for cross-scope policies
-
Use the External? filter option to find policies in which the provider is in a different scope from the scope in which you discovered policies.
-
The policy visual view has an option to display external policies. See Policy Visual Representation.
If you are using Default Policy Discovery Config
Make sure you have clicked Save on the Default Policy Discovery Config page after making changes to make default external dependency configurations available to individual workspaces.