Let Luna draft your access model
If you would rather not start from a blank builder, Luna can draft your whole access model from what your organisation already looks like, then land it as policies tier by tier. Ask Luna to set up your access policies, or use the Ask Luna about your policies card on the Policies tab.
What Luna does, in order
Remembers what was agreed. If you have been through this before, Luna recalls the decisions you made last time, which apps you called sensitive, how you treat contractors, how granular you wanted cohorts, and carries them straight into the draft instead of asking again.
Gathers the evidence and shows it to you. Luna reads your real coverage (the five slices, as a percentage table), the shape of your organisation (headcounts, profiles, and which attributes are filled in well enough to build on), and the gaps in the draft. Nothing is proposed at this point, it is all presentation.
Interviews you, but only for the gaps. One question at a time, and only questions the data genuinely cannot answer: which apps count as sensitive, whether contractors should hold what employees hold, whether cohorts should be by department or by department and job function, and whether region or legal entity needs its own split. Your answers are saved as soon as you give them.
Lands the model one tier at a time. Birthright first: Luna previews each cohort and app pairing, shows you a table of who would gain, who would lose and who is blocked, checks overlaps, and creates those policies disabled, so nothing switches on yet. Then the on-request tier as Can request policies, landed active, because a request policy hands out nothing by itself. Then sensitive access, on tighter terms such as 30 days with a reason required, plus Can't request where a population should not even be able to ask. Then hygiene: Remove when unused and Must satisfy, set to suggest so a person approves each change.
Summarises. One table of what is now governed, coverage before and after, what is still unexplained, and a link into the Policies tab.
What to expect on a small or messy organisation
Blank departments. If attributes are thin, the evidence step says so, and the interview asks whether your data can describe anyone at all. Fix the feed and re-run; a model built on empty fields would only match Everyone.
Few or no birthrights. A cohort earns a birthright only when at least 85% of it already holds the app and the cohort has at least 5 people. Small teams often clear neither, so more lands in the on-request tier. That is the model working, not failing.
An empty suggestion list explains itself. When nothing qualified, Luna can still tell you which cohorts scored and which floor they missed, so you can decide whether to widen the cohort or write the policy by hand.
Good to know
Individual suggestions also arrive on their own, on the Suggested policies card. Create policy there is one click with no confirmation dialog, so read the card first. Dismiss takes the suggestion away and stops Ploy suggesting that exact thing again. Deleting a policy later does not carry that suppression, so the same idea can come back as a suggestion.
Every number in Luna's tables is computed by Ploy, not by the model, including previews, counts and the estate picture.
Luna is gated on the same permission as the Policies tab, so a person who cannot open the page cannot get the answers in chat either.
Luna lands birthright policies disabled on purpose. Nothing provisions until you activate them