graph-studio
Creating Policies
Types of Policies
Three types of policies can be created:
- Masking Policies - Masking policies enable flexible data obfuscation. A typical use case for creating a masking policy is to protect personally identifiable information or other sensitive data fields, such as those containing financial details, email addresses, and social security numbers (SSNs), within a dataset. When such a masking policy is implemented, different users may see the same data table but with varying levels of access based on their attributes.
- Filtering Policies - These types of policies enable row-level filtering, which is particularly useful for data segregation based on legal, compliance, or business considerations. You would create a filtering policy if, for example, you wish to limit user access to datasets according to some attribute, such as a specific region or jurisdiction.
- Access Policies - Access policies determine whether users are authorized to access a dataset. The combination of access and masking policies offers precise control over which users can see the data (access) and what or how much of it (content) they see. Suppose you have a dataset that includes patient electronic health records. An access policy can bar users from reading these records if they belong to the HR Department. If the user belong to the In-Patient Department, however, they may be allowed to read these records, but a masking policy may prevent them from viewing SSN or billing information.
Viewing Policies
All policies created display on the Policies screen, which can be accessed by expanding the User Management features in the Admin screen and selecting Policies.

The Policy Manager must be enabled to access the Policies screen.
Creating Policies
All policies are created via the Create Policy screen, which appears when you click Add Policyon the Policies screen and select Document from the options that display.

You can create multiple policies in a "group" policy and apply all or only a subset of these policies as necessary.

The next topics in this section provide the basic steps to create masking, filtering, and access policies.
Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/abac-create-policy.htm · retrieved 2026-08-23