Write the rule once. The platform enforces it.
Password, access, approval and retention policies, applied on every login, record and high-value action.
Overview
Policies are how you govern the platform without policing it by hand. Instead of trusting that everyone remembers the rules, you encode them once and the system enforces them on every login, every record and every high-value action. Four policy types cover the ground most Indian SMBs and enterprises need: Password, Access, Approval and Retention.
Password Policy sets credential rules — length, rotation, reuse blocking and whether MFA is mandatory — across the tenant or per role. Access Policy decides who may reach what under which conditions, including time of day, location and device. Approval Policy defines thresholds and approver chains so high-value actions cannot be taken unilaterally. Retention Policy governs how long each kind of record is kept before deletion or archival — the operational face of the DPDP Act's storage-limitation principle. Every policy carries an effective date and status, so changes are deliberate and reversible.
Explore Security & Policies →- ✓ Password rules: length, rotation, reuse and mandatory MFA
- ✓ Conditional access by time, location and device
- ✓ Approval thresholds and approver chains for high-value actions
- ✓ Retention rules that operationalize DPDP storage limits
- ✓ Per-role or tenant-wide scope on every policy
- ✓ Effective dates so changes are deliberate and auditable
Everything Policies gives you
Password Policy
Enforce minimum length, rotation cadence, reuse blocking and mandatory MFA across the tenant.
Access Policy
Allow or deny access based on role, time, location and device conditions.
Approval Policy
Set value thresholds and approver chains so big actions need a second sign-off.
Retention Policy
Define how long each record type is kept before deletion or archival, with a legal basis.
Scoped Enforcement
Apply each policy tenant-wide or to specific roles for precise control.
Escalation Rules
Route unactioned approvals up the chain after a set number of hours so nothing stalls.
How the AI agent follows Policies
The AI agent follows the same policies as people — it cannot bypass them, and every step is logged.
Sense
Follows the same policies as the people it works for.
Decide
Cannot bypass approval thresholds, access rules or retention limits.
Act
Routes any action above a threshold to the right approver, and logs every step.
Five-tier model routing · field-level permissions · full audit trail. See the AI layer →
Live in four steps
Set credential rules
Configure password length, rotation, reuse and MFA requirements for your tenant.
Condition access
Write access rules that permit or block by role, time, location and device.
Require approvals
Add thresholds and approver chains so high-value actions get a second sign-off.
Govern retention
Set retention periods and expiry actions to meet DPDP storage-limitation duties.
Where teams put it to work
Enforcing credential hygiene
A password policy mandates a minimum length, blocks reuse of the last several passwords and requires MFA, so weak or recycled credentials never make it into the tenant.
Restricting off-hours access
An access policy blocks logins to finance data outside business hours and from unapproved locations, closing a common window for misuse.
Controlling high-value transactions
An approval policy requires a manager's sign-off on any discount or purchase above a set threshold, and escalates automatically if it is not actioned in time.
The payoff
Compliance by default
Keeps the platform DPDP compliant and aligned with ISO 27001 controls, with documented rules for passwords, access, approvals and retention.
No unilateral risk
Approval chains ensure high-value actions always carry a second pair of eyes.
Consistent enforcement
Policies apply to users, API calls and the AI agent alike, within the scope you set.
Defensible data lifecycle
Retention rules give you a documented basis for how long personal data is kept and when it is purged.
Questions, answered
Four core policy types cover most needs: Password, Access, Approval and Retention. Each can be scoped tenant-wide or to specific roles and carries an effective date and status.
Yes. Access policies evaluate conditions such as role, time, location and device, so you can allow, restrict or block access based on the context of each request rather than identity alone.
You define a threshold and an approver chain on an object, so actions above the threshold — like a large discount or purchase — require sign-off. Escalation hours route the request higher if it is not actioned in time.
Retention policies set how long each record type is kept before deletion or archival and record the legal basis, which operationalizes the DPDP Act's storage-limitation principle and gives you a defensible data-lifecycle position.
Policies carry an effective date and status, so you can stage changes, activate them deliberately and see exactly when a rule took effect — every change is recorded for audit.
Related capabilities
Roles & Permissions — Granular RBAC & Access Control
Grant every person exactly the access their job needs — no more, no less.
Sessions & MFA — Session Control, 2FA & Device Management
See every active login, kill the ones that look wrong, and put multi-factor authentication in front of the accounts that matter.
Audit Trails — Tamper-Evident Logs of Who Did What, When
A tamper-evident, searchable record of every action across the platform, so you can always answer who changed what, when — and prove it to an auditor.
See Policies in your workflow
Start free, or get a guided walkthrough with our team — on the one platform that runs Security & Access and your whole business.

