Overview
Create a communication client, exact operation grants, transport permissions, and delegation policies.
Prerequisites
Permissions required
Steps (4)
-
1
Probe the application
Use AccessGuard integration discovery to inspect the installed application and its capabilities.
Tips
Validation
Success criteria
-
2
Create the communication client
Register the trusted application principal and allowed inbound transport classes.
Tips
Validation
Success criteria
-
3
Grant operations
Assign only the AccessGuard canonical operations and Handler/RCP/Bridge transports required by the application.
Tips
Validation
Success criteria
-
4
Add downstream delegation where needed
Create a target/operation/transport-specific delegation policy when AccessGuard may represent the source application to a provider.
Tips
Validation
Success criteria
About this guide
AccessGuard centralizes workspace authentication and customer identity. External websites can use the signed Bridge v2 proxy and JavaScript SDK for registration, login, verification, recovery, token refresh, profile management, protected media, and notification inbox operations.
Inside the workspace, AccessGuard owns users, sessions, verified identities, customer profiles, communication preferences and consent, approval state, KYC documents, risk flags, notification state, audience segments, application operation grants, delegation policies, and trusted context actions. Canonical capabilities are available through Handler and RCP, with selected operations available through Bridge v2.
Configured providers handle downstream delivery and human work: email, SMS, WhatsApp, voice, push, and case/problem operations can be delegated while AccessGuard preserves the identity, authorization, provenance, and customer-policy record.