Skip to main content

Conditional Policy

Control of Business SystemsConditional PolicyThe tab manages policies that limit the number of screens that can be opened simultaneously in the work system (app, URL input field) accessible by each member and in the isolated browser.

⚠️ Must Read: This policy applies to all access to work systems.Highest Priority Control PolicyIt is. The menus that are not allowed here cannot be accessed by users regardless of how the sub conditional policies (app conditional policies, URL input field conditional policies) are set.


Feature Overview

Conditional policies restrict the menus that users can access in SHIELDGate and efficiently manage isolated browser resources.Top-level permission controlIt is a feature.

Controllable Items

  • app: Access Permissions for Registered App List
  • URL input field: Direct URL input feature access permission
  • Maximum number of screens: Limit on the number of screens that can be opened simultaneously in an isolated browser

Policy Application Structure

Conditional Policy (Top Level)
├── Allow App → App conditional policy applicable
├── Allow URL Input Field → URL input field conditional policy applicable
└── Set Maximum Number of Screens → Limit number of screens per member

Example:

  • Conditional policy "URL input field" not allowed → URL input field conditional policy invalid
  • Conditional policy "app" not allowed → App conditional policy invalid
  • Set the maximum number of screens to 10 in the conditional policy → The corresponding member can use up to 10 screens only.

Policy Priorities

If the same member is included in multiple policies,**Policies with higher priority (smaller numbers) are applied first.**It is possible.

Example:

  • Priority 1: Member Hong Gil-dong / Work SystemAllowed / Maximum number of screens 5
  • Priority 2: Member Organization / Work SystemandURL입력창Allowed / Maximum number of screens unlimited
  • result: Hong Gil-dong has a priority 1 policy applied, making the URL input field unavailable, and a maximum of 5 screens can be used.

Screen Configuration

Admin Page →Business System ControlConditional PolicyMove to tab

Main Components

1. Policy List

  • Priority: Policy Application Order (1 is the highest priority)
  • Policy Name: Unique name identifying the policy
  • Members: Users/Groups to which the policy applies
  • Target Business System: Allowed Menu (App, URL Input Field)
  • Maximum number of screens: Number of screens that can be used simultaneously
  • Modification Date: Last modified date

2. Top Features

  • [+ Policy Registration]: Create a new control policy
  • Search: Policy name, members, target, usage status, and various other conditions can be searched.
  • Edit/Delete: Modify or delete the selected policy

You can search for policies based on various criteria, including not only the policy name but also members, target business systems, and usage status.

Types of Search Filters

FilterSearch MethodDescription
Policy NameIncluded SearchSearch for policy names containing keywords
MembersInclude Search + Dropdown SelectionUser (Name·Email), Group, Department Search, Assignment/Exception Classification Selection, Multiple Selection Available
TargetDropdown selectionApp, URL input field selection, multiple selection possible
UsageDropdown selectionUse / Not Use Selection
conditionInclude Search + Dropdown SelectionSearch by location (IP), time, device conditions, multiple selections available
Execution PolicyDropdown selectionAccess Allow/Deny, Select Additional Authentication Methods (Email·OTP), Multiple Selections Possible

Member Search Details

  • When you enter a name or email in the search box, results will be displayed in real-time in a dropdown.
  • Allocation / ExceptionYou can select a tab to distinguish between cases where the member is assigned to the policy and cases that are exceptions.
  • 모든 구성원is fixed at the bottom of the dropdown and is included in the search results only when selected directly.
  • Location: 위치 제한 없음or enter a registered location name to search. The results are위치명 | IP 범위It will be displayed in the format.
  • time: 시간 제한 없음You can search by entering the registered time name. The results are시간명 | 시간 범위It will be displayed in the format.
  • Device: 모든 디바이스, Desktop, Tablet, MobileSelect an option.

Search Condition Combination Rules

  • Between filters (AND condition): If you set multiple different filters, only the policies that satisfy all conditions simultaneously will be displayed.
  • Filter inside (OR condition): If you select multiple items within the same filter, any policy that matches at least one will be displayed.
  • Each set condition is displayed in the form of tags, and the tags'×You can remove individual conditions with the button.

⚠️ When search filters are applied, priority changes (drag and drop) are not possible. To change the priority, please clear all search filters.

3. Policy Trends
If no policy is registered, the following message will be displayed:

  • "There are no registered task system control policies."
  • Policy Registration Guide Text:
    • You can control members' access to the business system (app and URL input field).
    • Even if you set conditional policies in the [App and URL Input Field] of the complete menu, assigned members cannot access the business system.

Add Policy

1. Start Adding Policy

  • **[+ Policy Registration]**Button Click
  • The policy addition slide panel opens from the right.

2. Policy Basic Information

This is the default settings item displayed at the top of the slide panel.

Policy Name

  • Enter a unique name to identify the policy
  • Duplicate names cannot be used.
  • Example: "Development Team", "Basic Policy", "Executive Only" etc.

Members

Select the target to which the policy will be applied.

Select allocation method:

  • All users: Apply policy to all users
  • Select User or Group: Specify a specific user or group

When selecting users/groups:

  1. Select Target in the Allocation Tab
  2. Select exception target in the exclusion tab (optional)
  3. Search for username or group name through the search bar
  4. The selected members can be confirmed in the box below.

Target Business System

Select the allowed menu with checkboxes:

  • app: Allow access to the list of registered apps
  • URL input field: Allow access to direct URL input feature
  • You can select both or only one.

3. Conditions

You can set conditions for location, time, and device to restrict the policy to apply only in specific environments.

Location (IP)

No location restrictionsWhen selected:

  • Apply policies at all locations

Location restrictions applyWhen selected:

  • Select from the locations registered in the Security365 condition items.
  • Apply the policy only at the selected location
  • If a new location condition is required**[+Location Registration]**Click

time

No time limitWhen selected:

  • Applying policies at all times, 24 hours a day

time limit existsWhen selected:

  • Select from the registered time in the Security365 condition items.
  • Apply the policy only to the selected time zone
  • If a new time condition is needed**[+Time Registration]**Click

Device

No device restrictionsWhen selected:

  • Apply policies on all devices

Device restrictions applyWhen selected:

  • Select from the devices registered in the Security365 condition items.
  • Apply the policy only on the selected device
  • If new device conditions are required**[+Device Registration]**Click

4. Control Policy

Number of simultaneous screens

Set the maximum number of screens that can be opened simultaneously in the isolation browser.

Setting Options:

  • No limit on the number of screens(Default): Unlimited use without screen number limits
  • Specify maximum number of screens: Enter the maximum number of screens directly
    • Input format: Integer greater than or equal to 1 (at least 1)
    • For example: When entering 10 → The corresponding member can use a maximum of 10 screens only.

Effect of Screen Count Limit:

  • Preventing Excessive Use of System Resources
  • Fair Resource Allocation
  • Ensuring overall system performance stability
  • Flexible resource management with differentiated restrictions by member

5. Settings

Policy Settings

Set whether the policy is activated.

  • use: Activate the policy immediately and apply it to members
  • Not used: Save the policy but keep it disabled

6. Save Policy

  • After completing all settings**[Save]**Button Click
  • The policy is applied immediately and reflected to the respective members.

Policy Modification

Correction Method

  1. Policy Selection: Select a single policy to edit from the list.
  2. Edit Button: Activated at the top**[Edit]**Button Click
  3. Content modification: Change necessary items on the policy modification slide
  4. Save: **[Save]**Apply changes with the button

Editable Items

  • Policy Name (No Duplicates Allowed)
  • Member Assignment/Exclusion
  • Allowed Work System (App/URL Input Field)
  • Condition Settings (Location/Time/Device)
  • Maximum Screen Count Setting
  • Policy Settings

Change Priority

After selecting a policy, you can change the priority using the following method.

  • Drag and Drop: Drag and drop the policy directly from the list to the desired location
  • Move to top / Move to bottom: Move immediately to the top or bottom
  • Priority Move Dropdown: Select the desired number to move directly to a specific location

⚠️ Priority changes are not possible when search filters are applied. Please proceed after clearing all filters.


Download Policy Status

You can download the list of conditional policies as an Excel (.xlsx) file. This is provided separately from the existing JSON backup feature.

  • Full Download: Save all registered policy information as an Excel file
  • Download Search Results: Save only the results with the current search filter applied as an Excel file

💡 JSON download is for policy backup and restoration, while Excel download is used for status analysis and reporting purposes.


Delete Policy

Deletion Method

  1. Policy Selection: Select one or more policies to delete from the list
  2. Delete Button: Activated at the top**[Delete]**Button Click
  3. Delete Confirmation: Confirmation modal window at**[Check]**Button Click

Caution

  • Deleted policies cannot be restored.
  • Members of the policy are subject to the basic policy or other policies.

User Experience

When the screen limit is reached

If the user attempts to open a new screen while reaching the maximum number of screens set, an informational modal window will be displayed.

Modal Window Example (Limit of 10)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━  
Screen Opening Limit Notification
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Currently, users can open a maximum of 10 isolated browser screens at the same time. (Individual limits according to administrator policy)

To open a new screen, please close the existing screens and try again.

[Confirm]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Action Description:

  • If the user closes the existing screen and retries, normal access will be granted.
  • The "N" in the modal window is dynamically displayed based on the set maximum number of screens.
  • [Confirm] When clicked, the modal window closes and the user can manage the existing screen.

Problem Solving

Common Issues

When a conditional policy is set but the user cannot access it:

⚠️ Most Common Causes: The menu is not allowed in the conditional policy.

  1. Check Order:
    • 1st priority: Check whether the corresponding menu (app/URL input field) is allowed in the conditional policy.
    • 2nd priority: Check if the user is included in the conditional policy
    • 3rd Priority: Check the settings for subordinate conditional policies (app conditional policies, URL input field conditional policies)
  2. Solution: Allow the necessary menu in the conditional policy first, then set the sub-policy.

When the user can no longer open the screen:

  • Check the maximum number of screens set in the conditional policy.
  • Check the priority of the policies applied to the user
  • Modify the policy to increase the maximum number of screens or change it to unlimited if necessary.

When the policy is not applied:

  • Check Priority (whether there is a higher priority policy)
  • Check member settings (whether included in the exclusion list)
  • Check Condition Settings (Time/Location Condition Fulfillment Status)

When the menu is not visible:

  • Check the policies applied to the user
  • Check if the required menus are checked in the business system selection options.

Condition setting error:

  • Check if the location/time/device conditions are correctly registered in the Security365 condition items.
  • Check if the required condition is set to "Limit Exists"

Policy Setting Order

Step 1: Set Conditional Policy

  • Basic Menu Access Permission Settings (App/URL Input Field)
  • Setting Maximum Number of Screens per Member

Step 2: Set App Conditional Policies

  • Detailed permission settings for individual apps

Step 3: Set Conditional Policy for URL Input Field

  • Detailed Permission Settings by URL

⚠️ Caution: The menus not allowed in step 1 make the settings in steps 2-3 meaningless.

Priority Management

  • Set exceptional policies to high priority
  • Set general policies to low priority
  • Regularly review the priority system

Screen Count Limit Recommendations

  • Development Team/Designer: 30~50 items (multiple references needed)
  • General Office Position: 10~20 items (work documents and system access)
  • Executives/Management: Unlimited or high limits (flexible work environment needed)
  • External Partners/Contract Workers: 5~10 items (limited access recommended)

Monitoring Methods

  • Session ManagementCheck real-time screen usage status in the tab
  • Excessive Screen User Identification and Policy Adjustment
  • Regular Policy Effectiveness Review