Thresholds and defaults
Policies carry a handful of fixed numbers that decide when Ploy asks you to confirm, how long things take, and what a new policy starts with. This page collects all of them in one place.
Saving and activating
Setting | Value | Notes |
|---|---|---|
Confirmation threshold | 50 people | Activating or saving a policy that reaches more than this many people asks you to confirm first. |
When the confirmation applies | Enforcement stronger than Suggest only | A Suggest only policy never asks, however many people it reaches, because a person still approves every change. |
How an edit is counted | The people who move in or out of the policy | Changing the enforcement setting is the exception: that counts everyone the policy matches. |
The builder handles this inline. Crossing the threshold flips the footer to an amber banner reading "Activating applies this to N people today. That's above the confirmation threshold (50)", with Back and Save for N people. Outside the builder, re-enabling or bulk editing shows the same gate as a dialog.
The threshold itself is a Ploy side setting. There is no control for it in the dashboard, so ask us if 50 is the wrong number for your organisation. Writes through the API answer the confirmation automatically, on the basis that whoever ran the change has already reviewed its plan.
What a new policy starts with
Setting | Default |
|---|---|
Enforcement | Suggest only |
Manual overrides | Flag |
Days without use, on a Remove when unused policy | 60 |
Status, when you write it by hand | Active, because the button is Create & activate |
Status, when Luna or Ploy suggests it | Proposed, waiting for you |
Request terms | Silent, so the resource's own approval policy decides |
A policy is silent on terms one knob at a time. If you set a maximum duration but say nothing about extensions, the resource's own setting decides extensions.
Terms Luna suggests
Tier | Suggested terms |
|---|---|
On request, everyday access | 90 days at a time, extendable |
Sensitive access | 30 days at a time, reason required |
Hygiene | Suggest only, so a person approves each removal |
Timings
What | How often |
|---|---|
A save starts its own pass | Immediately, scoped to that policy |
The safety sweep that catches everything else | Every 15 minutes |
Coverage percentages | Recalculated at most every 5 minutes |
Luna re-checks your access for new suggestions | Weekly |
Expiring soon | Access lapsing within the next 14 days |
The access requests card on the Overview tab | The last 30 days |
The 15 minute sweep is a safety net, not the main path. It catches people who join a matching profile later, accounts that appear after the save, and anything an earlier pass skipped.
The floors Luna's suggestions must clear
Luna proposes a standing grant only when the evidence is strong, because activating one grants access to everyone it matches.
Signal | Floor |
|---|---|
Share of the group that already holds the app, for a standing grant | 0.85 |
People in the group, for a standing grant | 5 |
Fit, for a policy proposed from the coverage ledger | 0.70, higher for riskier apps |
Share of the app's holders the group accounts for, used for ranking only | 0.25 |
Repeat approvals before a per person suggestion becomes a group wide one | 3 |
Caps and limits
Limit | Value |
|---|---|
New hire suggestions | Within 30 days of joining, up to 5 per hire, up to 200 across the organisation per day |
How deep a suggested group goes | Two attributes, for example department and job function |
Near misses shown when nothing qualified | Up to 3 |
Apps in one suggestion shortlist | Up to 25 |
Targets named in a policy sentence | Up to 3, then "& 4 more" |
Statuses the API can write | Active and Disabled only |
Good to know
Coverage percentages and the coverage ledger read the same figures, so the card and the list can never disagree.
Deleting a policy keeps its history but removes it from every list, including the API. Disabling keeps it in the list and switches it off.
The days without use value must be a whole number above zero.
A group of five people is the smallest Ploy will propose a standing grant for. Below that, expect a suggestion to ask rather than to grant.
"Awaiting" on the coverage ledger means a policy has asked for access that has not been provisioned yet. It is not a request somebody has to answer, so it clears itself on the next pass unless a batch is waiting for approval.