> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getjumper.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create and assign access policies

> Open the Admin Panel, create a policy that limits tabs and analysis folders, and assign it to licenses.

A policy controls which Jumper tabs and analysis folders a license can use. A policy can represent a role, a production, or a combination of the two.

<Info>
  Before you begin: you have a Jumper Enterprise license. For background on policies, see the [Enterprise overview](/enterprise/overview).
</Info>

## Open the Admin Panel

Select **Admin controls…** from Jumper's menu. The screenshot below shows the macOS menu bar menu.

<img src="https://mintcdn.com/jumper/i8K5Ek4tPyC1n1YR/images/admin-panel/open-admin-controls.webp?fit=max&auto=format&n=i8K5Ek4tPyC1n1YR&q=85&s=b905b91e4d08aa63539e7f2475a60981" alt="Jumper menu bar menu with Admin controls highlighted" width="502" height="208" data-path="images/admin-panel/open-admin-controls.webp" />

Sign in with the account that manages your organization's Enterprise licenses. Authentication opens in your system browser and returns to the Admin Panel. The sign-in screen offers Google, Microsoft, Apple, email, and **Company SSO** when configured.

<Accordion title="View the sign-in screen">
  <img src="https://mintcdn.com/jumper/i8K5Ek4tPyC1n1YR/images/admin-panel/sign-in.webp?fit=max&auto=format&n=i8K5Ek4tPyC1n1YR&q=85&s=00aad5241e237566e871f6a6c849c60b" alt="Enterprise Admin sign-in screen with social sign-in, work email, and Company SSO options" width="1054" height="717" data-path="images/admin-panel/sign-in.webp" />
</Accordion>

## Create a policy

For example, create a policy for editors who should search Show A and Show B without changing their analysis or face collections.

<Steps>
  <Step title="Start a new policy">
    Open **Policies** and select **New**.
  </Step>

  <Step title="Name it">
    Give the policy a descriptive **Name**.
  </Step>

  <Step title="Choose the accessible tabs">
    Under **Accessible tabs**, enable the tabs those licenses should be able to open.
  </Step>

  <Step title="Choose the analysis folders">
    Under **Analysis folders**, choose **Specific folders** and use **Enter a path** to add the allowed analysis locations, or choose **Any folder** for unrestricted folder access.
  </Step>

  <Step title="Create the policy">
    Select **Create policy**.
  </Step>
</Steps>

To provide search access without analysis, face collection management, or model and settings changes, enable **Search** and disable **Media**, **People**, and **Settings**. You can also control access to **Summaries**, **Tags**, and **Help**. The example below enables Search, Tags, and Help.

<img src="https://mintcdn.com/jumper/i8K5Ek4tPyC1n1YR/images/admin-panel/create-policy.webp?fit=max&auto=format&n=i8K5Ek4tPyC1n1YR&q=85&s=530487075ae7b6039cc903fef314ed57" alt="Policy editor allowing Search, Tags, and Help, with analysis folders restricted to Show A and Show B" width="1378" height="1522" data-path="images/admin-panel/create-policy.webp" />

## Limit access by production

Add only the analysis folders that the policy's members should use. In the screenshot above, both **Show A** and **Show B** are allowed, while Show C is excluded. To keep the two shows separate, create one policy for Show A and another for Show B, each with only its own analysis folder.

Allowed paths include their subfolders. Add each production's analysis folder rather than a parent folder containing several productions.

Use paths as they appear on the editors' machines. For a team using both macOS and Windows, add the corresponding paths for both platforms. A macOS path alone will not match a Windows machine. The policy editor prompts you to add the missing platform's path.

Keep your shared storage permissions aligned with the same production access rules. See [project-specific analysis folders](/guides/shared-analysis#confidential-footage-and-project-specific-analysis-folders) for the storage setup.

## Assign policies to licenses

Open **Licenses** to see your organization's seats and their assigned policies. Use the policy dropdown beneath a license to change its memberships. You can also select multiple licenses and apply a policy to them together.

<img src="https://mintcdn.com/jumper/i8K5Ek4tPyC1n1YR/images/admin-panel/assign-licenses.webp?fit=max&auto=format&n=i8K5Ek4tPyC1n1YR&q=85&s=a349336a09351ec418205d2f217ce398" alt="Licenses page showing two selected seats assigned to Only Search and Tags and one seat with Full Access" width="1242" height="749" data-path="images/admin-panel/assign-licenses.webp" />

A license can belong to more than one policy, and the access granted by those policies is combined. When restricting a license, remove **Full Access** and any other policy that grants access beyond what that editor needs.

<Note>
  A license with no assigned policy has **No Access**. Assign a policy before handing the license to an editor. Sending a configuration alone does not grant access.
</Note>

## Next

[Send a configuration](/enterprise/send-configuration) to the licenses you assigned.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.