Conditional Policy Registration and Management
1. Overview
Conditional policies specify targets (storage, members) and conditions (location, time, device), and connect EDO execution workflows by trigger to control file events. This guide explains the entire flow of registering, modifying, copying, deleting conditional policies, and managing priorities on the admin page, as well as how to set each category during registration.
2. Page Entry
- Click on [Conditional Policy] in the left menu of the admin page.
- You must be logged in with a SHIELD Drive administrator account and have Write permissions for conditional policies.
- If you do not have permission, the [Register Policy] button and the action icons in the list (edit, copy, delete, change priority) will be disabled or not displayed.
3. List Screen
Registered conditional policies are displayed in order of priority. You can filter by entering the policy name in the top search field (press Enter or click the search icon), and the list loads in an infinite scroll of 100 items at a time.
| column | Explanation |
|---|---|
| Priority | Sequential number starting from 1. Reassigned immediately upon change. |
| Policy Name | Policy Name |
| Explanation | Policy Description (if not entered -) |
| Storage | Storage type + quantity (e.g., shared box (3)). If it's a single item, display the storage name. |
| Members | "All users" or "Assignment: User(N), Group(N), Policy Group(N) | Exceptions: …" |
| Usage status | Use / Do not use |
| Expiration Date | YYYY-MM-DD ~ YYYY-MM-DD. If all are unset, -, if only one side is unset, "indefinitely" |
| Revision Date | YYYY-MM-DD HH:mm |
- Expiration Badge: If the expiration date is before the current date, "Expired" will be displayed, and if it is within 7 days from the current date, a "Pending Expiration" warning will be shown.
4. Action Area
The top action is displayed differently depending on the selection state.
| Selection State | Possible Actions |
|---|---|
| Policy Not Selected | Policy Registration, Total Count, Search, Refresh |
| Select 1 policy | Close, Move Up·Down, Edit, Copy, Delete |
| Select more than 2 policies | Close, Multi Delete |
- If you do not have permission, the action icon will be disabled or not displayed.
5. Policy Registration
Clicking the top [Policy Registration] button opens the full-screen registration page. Click on the categories in the left sidebar to set values on the right, and the categories are organized in the following order.
Policy Basic Information → Target Storage → Members → Conditions (Location·Time·Device) → Enforcement Policy → Policy Operation Settings
Conditions for Activating the Register Button
- Policy name · Members · Target storage are all valid.
- The execution policy category has been opened once, and the EDO mapping preparation (iframe load) is complete.
5-1. Policy Basic Information
- Policy Name (Required, within 50 characters): As soon as input is entered, asynchronous duplicate checking is performed, and if the same name exists, it cannot be registered.
- Description (optional, within 200 characters)
5-2. Target Storage
- Select one storage purpose as a radio button (Personal Storage / Shared Storage / Common Storage, for companies with MS Teams enabled, add Teams Storage).
- The purpose cannot be changed in edit mode and can only be selected during registration. Changing the purpose will reset the selected storage list.
- Click the selection box to search for storage in the right drawer and select more than one. (The execution policy category will be activated only when one or more storages are selected.)
- Drawer table columns: Name, Type, Purpose, Storage Method, Approval Usage Status. Approval Usage Status is
approvalStorage === trueUse if, otherwise do not use.
5-3. Members
- Select the allocation method as radio: All users / Select users and groups.
- In "Select Users and Groups" mode, specify the targets and exceptions respectively. Search and select through the drawer's All / Users / Groups / Policy Groups tabs (infinite scroll in units of 100).
- You must specify one or more targets for application, and if the same target is duplicated in both assignments and exceptions, the exception takes precedence.
5-4. Condition - Location (IP)
The conditions consist of location, time, and device, and are combined with AND (all set conditions must be satisfied to apply).
- No location restrictions / Select from registered locations.
- In "Registered Location" mode, you can select multiple application and exception locations from the drawer.
- Register a new location condition at the top of the drawer by clicking [Add]: Enter condition name (required, 50 characters, duplicate check) · description, starting IP ~ ending IP (IPv4 validation) and add the IP range chip by clicking [Add] (1 or more, no duplicates allowed). The registered conditions will be shared and reused with other policies.
5-5. Condition - Time
- No time limit / Operates in registered time mode, allowing for multiple selection of application and exception times.
- Register new time condition: specify condition name·description, start time:minute ~ end time:minute (hour 00–23, minute 00–59) and add time zone chip with [Add] (at least 1, no duplicates).
5-6. Condition - Device
- No device restrictions / Select from device types.
- In the "Select Device Type" mode, you can select one or more of the PC / Tablet / Mobile cards.
5-7. Execution Policy (EDO Execution Workflow)
Some of the operations of the conditional policy are delegated to the EDO (Enforcement & Detection Orchestrator) workflow. The EDO workflow defines the flow of trigger (file event) → step (validation·transformation) → result (allow·block), and automates subsequent processing such as CDR, transformation, and additional validation.
- Entry prerequisites: At least one target storage must be selected, and the EDO service must be operating normally.
- When you click on the category, the EDO execution workflow settings screen opens on the right, and you select the workflow template to apply for each trigger.
| Storage Purpose | Mappable Triggers |
|---|---|
| personalization | File Upload (shieldrive_file_upload_before), File Download (shieldrive_file_download), Inter-network Transfer (shieldrive_file_transfer_hunesion) |
| Shared Box / Common Box / Teams Box | File Download (shieldrive_file_download) - Exclude Network Link Transfer |
- Network linkage (HuneSion) transmission occurs only in the personal mailbox, so the network linkage transmission trigger is excluded for purposes outside the personal mailbox.
- For details on the actions that can be mapped by trigger (allow/block/CDR/transform, etc.) and input/output fields, please refer to the EDO execution workflow management guide.
5-8. Policy Operation Settings
- Policy Activation Toggle: On / Off. In the Off state, the policy is not applied.
- Validity Period: Specify the start and end dates using the DatePicker or set the end date to "indefinite".
6. Policy Modification
- After selecting one policy from the list and clicking [Edit], an edit page will open with the existing values filled in.
- You can change the policy text or EDO mapping, and the changes to the EDO mapping will be saved after the text is saved first.
- If either one is changed, the [Edit] button will be activated. The storage purpose cannot be changed.
7. Policy Copy
- After selecting one policy from the list and clicking [Copy], a registration page will open with basic information and EDO mapping pre-filled.
- After modifying only the necessary values and clicking [Register], a new policy will be created. A copy will always be created at the bottom of the list in an inactive state.
8. Delete Policy
- Select one or more policies and then click [Delete] → Select [Delete] in the confirmation modal.
- Multi-deletion is processed in parallel by item, and in case of partial/full failure, you can re-execute only the failed items by clicking "Retry" in the failure notification modal.
- When a policy is deleted, the associated EDO mappings are also cleaned up, and any failed mapping cleanup items are included in the deletion failure notification.
9. Change Priority
You can change it in two ways.
- Action Bar [Move Up / Down]: Moves one step when a policy is selected and the button is clicked. It will be disabled if there is no permission, 0 or 2 or more items selected, moving up from the first item/down from the last item, or if a previous change is being processed.
- Drag and Drop: Drag a row and drop it in the desired position. The priority number is updated immediately while dragging.
Changes are reflected on the screen immediately, and the next change is temporarily blocked during processing. In case of failure, the order and number are automatically restored to the previous state, and a notification is displayed.
10. View Policy Details
- When a row is clicked again while one policy is selected, the detailed drawer on the right will open.
- You can check the basic information of the policy, target, conditions, execution policy, policy operation settings, and modification date at a glance, and you can see the mapped EDO trigger labels in the execution policy area.
- If you click while holding down Ctrl or Shift, it will be treated as a multi-selection and the drawer will not open.
11. Error Notification
| situation | Notification |
|---|---|
| Policy registration failed | "Policy registration failed" modal, display error code. Re-request with "Try again" |
| Policy modification failed | "Policy Modification Failed" modal, same action |
| Failed to save EDO mapping | Mapping Retry Modal, re-request mapping save only with "Retry" |
| Policy deletion failure | "Failed to delete some policies." Only the failed items can be re-executed. |
| Policy deletion failed entirely | "Failed to delete the policy." Retry possible |
| Priority change failed | "Failed to change the priority of the conditional policy." Automatic restoration of order |