Isolation policies support role-based access control (RBAC). Because isolation policies are Gateway HTTP policies with the Isolate action, Gateway’s account-level and resource-scoped roles apply to them directly.
Use the Zero Trust HTTP Policies Admin account-level role to grant access to all HTTP policies in the account. You can also assign a resource-scoped role to let a team member manage a specific isolation policy without exposing other Gateway resources.
Policy settings such as copy/paste, file download/upload, keyboard, and printing are part of the policy object and follow the same permissions.
For setup instructions, refer to Granular permissions for Gateway.
Source: Cloudflare


