Example: Removing the ability of auction managers to retract bids

By default, auction managers for a store can retract bids submitted at their auctions. In some cases, you might not want to grant this authority to anyone. To make this change, you must find the resource-level policy that defines who can retract bids and delete it.

In Auctions Scenario 1, the action, close bidding, was one of several included in the policy. Consequently, you had only to remove the action from the policy's action group. In this example, however, an entire policy controls bid retraction. Therefore, you must delete a policy not just an action.

To delete the policy, you need to do the following:

  • Determine the resource-level policy that covers the retraction of auction bids by auction managers.
  • Delete the policy.

Note: Before you delete the policy, make note of its name, access group name, resource group name, and action group name so you can recreate it for the next example.

Steps to take

  1. Determine the resource-level policy to be changed. The policy is:
    
    AuctionManagersForOrgExecuteAdminRetractBidCommandsOnAuctionResource
    
  2. From the Organization Administration Console, click Access Management > Policies.
  3. For View, select Root Organization to display the policies that it owns.
  4. From the list of policies, select the following:
    
    AuctionManagersForOrgExecuteAdminRetractBidCommandsOnAuctionResource
    
  5. Click Delete.

Update the policy registry with your changes

  1. Open the Administration Console.
  2. Click Configuration > Registry.
  3. From the list of registries, select Access Control Policies.
  4. Click Update.
  5. Repeat steps 3 and 4 for the Access Control Policy Groups Registry.