Grant and revoke connector access
Each connector has a connector policy that decides which users can reach it. In the console, you manage a connector's policy by granting directory groups access to it. A connector with no groups is unreachable.
The Connector Gateway evaluates the policy on every request, so a grant or revocation takes effect on the caller's next request.
Grant access to directory groups
- In the console, open the connector and select the Access tab.
- Select Add groups.
- Select one or more groups, then select Grant access.
Membership is inherited, so granting to a parent group reaches every subgroup beneath it. See Subgroups and inherited membership. Directory groups are separate from the OpenID Connect (OIDC) claim groups that cluster authorization policy matches. See Directory groups and OIDC claim groups.
Revoke a group's access
- On the connector's Access tab, open the actions menu for the group.
- Select Revoke access.
The revocation applies immediately, with no confirmation step. Revoking the last group leaves the connector unreachable by anyone.
Cedar-mode connectors
A connector policy can also be in Cedar mode, where a Cedar policy document decides access instead of group grants. For a Cedar-mode connector, the console shows a notice on the Access tab and disables group editing.
Switch modes and write Cedar policy documents through the connector policy routes of the Enterprise Manager API.
Next steps
- Configure connector authentication to set the credential the gateway sends to the backend.
- Review tool usage to confirm the right users are calling the connector.
Related information
- Directory groups and OIDC claim groups - how connector policies relate to cluster authorization groups
- Users and groups - manage the directory groups that policies reference