# Governance & Policies

The single place to manage and enforce every policy across your organization. Policies build on the organizational context you already have and keep learning from every new conversation and change.

## Governance & Policies

The single place to manage and enforce every policy across your organization. Policies build on the organizational context you already have and keep learning from every new conversation and change.

## How Governance & Policies helps your teams

Employee lifecycle policies: define how onboarding, offboarding, and role changes run by role, department, and location, so people are set up and wound down automatically and HR and IT handle only the exceptions

Privileged access management: define who qualifies for elevated access and under what conditions, from time limits to peer review to executive sign-off, so access is granted the moment it’s justified

Travel and expense pre-approval: define spending limits, approval paths, and exceptions up front, so employees get an instant answer and finance steps in only when a request falls outside policy

Vendor and contractor access: define scoped, time-bound access that expires on its own, with eligibility tied to engagement type and duration

Asset purchase and refresh: define a single purchase policy for every scenario - new hire, upgrade, replacement, refresh - with eligibility that adapts by role, location, and budget

## Define policy once, enforce it everywhere

### Define Once

Define once, enforce everywhere: set each policy a single time instead of maintaining it in a dozen places

### Less Manual Work

Less manual work: policies are detected and drafted automatically from what your organization already does

### Audit Ready

Always audit-ready: know exactly which policy applied, to whom, and when

### Early Warnings

Problems caught early: get alerted when policies leak, fail, or fall short, before they become a risk

## Powerful capabilities built for enterprise IT

- One place to manage every policy: every policy across IT, HR, finance, and security lives in one governed space instead of scattered documents, emails, and team knowledge
- Effortless creation and editing: build a policy from scratch, upload an existing document, or adjust a live policy in minutes, with changes taking effect everywhere instantly
- Continuous policy learning: reads your knowledge base, documents, and day-to-day requests to understand the policies already operating across your organization
- Governance and audit: every policy carries a named owner, approval chain, and full version history

## Learn and enforce policies from the systems you already run on

- **HRIS: **HiBob, BambooHR, Workday, UKG Pro, SAP SuccessFactors, Sage HR, Rippling, Ceridian Dayforce, Namely
- **Documentation: **Confluence, Notion, Microsoft SharePoint, email, Google Drive
- **Service desks: **Freshservice, ServiceNow
- **Employee platforms: **Workvivo, Simpplr
- **Manual upload: **PDFs, internal docs, and any file format

## FAQ

### What does Harmony's Governance & Policies layer control?

Harmony’s Governance & Policies layer gives IT admins fine-grained control over who can access what across the service desk, dashboards, data sources, and API integrations, covering role-based access control, identity-driven group management, and audit log streaming for compliance.

### How does Harmony's role-based access control work?

Harmony uses a two-tier RBAC model: Platform Roles (Admin, Agent, Observer) applied tenant-wide, and Desk Roles (Manager, Agent, Observer) scoped to a specific desk, with platform and desk roles assigned independently of each other.

### Can Harmony assign roles automatically from an identity provider?

Yes. Harmony syncs group membership from Okta, Microsoft Entra ID, or Google Workspace every 4 hours, automatically updating Platform and Desk role assignments as employees join or leave a group.

### How granular are dashboard permissions in Harmony?

Harmony controls dashboard access at three levels - dashboard, individual widget, and underlying data source - so a company-wide dashboard can be shared while each team sees only their own desk’s data.

### Does Harmony support audit log streaming for compliance?

Yes. Harmony streams real-time audit events covering authentication activity, asset changes, and ticket operations as structured JSON via webhook to SIEM tools like Sumo Logic or Splunk, enabling continuous compliance monitoring without manual log exports.

### What are the main benefits of Harmony's Governance & Policies layer?

Harmony’s Governance & Policies layer reduces access-control overhead by syncing roles automatically from Okta, Entra ID, or Google Workspace every 4 hours, so permissions stay current without manual admin work. Three-level dashboard permissions let teams share reporting safely, and real-time audit log streaming to SIEM tools supports compliance monitoring without manual log exports.