SC26AI agents lab + dinner on the river · Nov 17
Parallel Works

Platform Policies

In the Admin Panel sidebar, under Configuration, click Policies.

Overview

Platform policies apply to every organization. Only platform admins can change them.

Each policy is a dropdown or field whose first choice is No policy. With no policy, each organization can set its own organization policy, and organizations that don't get the default described there. Pick a value and click Save policy.

A platform policy set to any value takes precedence over every organization's own setting, and organization admins can no longer change it. Setting Allow password login or Allow device code sign-in here, for example, stops organizations from disabling them. Choose No policy to hand the decision back to organizations.

Every change is recorded as a policy event.

Policies set by platform or organization

These policies work the same way at both levels. See Organization Policies for what each one does and its default.

Platform-level differences:

  • Event Retention set here covers every event on the platform, and organization retention policies stop applying.
  • Disable Password Login can only be enabled when at least one other authentication method is configured on the platform. Allow password login is offered only here.
  • Disable Device Code Sign-in offers Allow device code sign-in only here.
  • Allow Public Sessions offers Disallow public sessions only here. It turns public sessions off in every organization and turns off any session that is currently public.
  • Allow Organization Session Sharing offers Allow sharing only here. Disallow sharing set here turns it off in every organization and unshares every session currently shared with an organization.

Platform-only policies

Workspace Retention

Delete the user workspace and its persistent volume for users who have not signed in for 30, 60, 90, 120, 180, or 365 days. This permanently removes the workspace home directory and its data, for both Kubernetes and Docker workspaces. A new workspace is provisioned when the user signs in again. When no policy is set, workspaces are kept forever.

Base Image Compliance

How base-image compliance rules apply across all organizations:

  • Off: rules are ignored.
  • Audit (log only): findings are logged and recorded as events without blocking. This is the default.
  • Enforce (block): snapshot use, session starts, and node scale-ups are blocked when a base image is disabled or removed.

In every mode, a disabled catalog image can't be selected for new resources, and Latest never resolves to a disabled image.

Organization MFA

Enforce MFA is set per organization, not here. Platform admins change it on each organization's Policies page; see Enforce MFA.