Knocs
A knoc is the access rule your users see. It says who can request access to a resource and under what conditions. Several knocs can share one integration.
Manage knocs under Admin > Knocs.
What a knoc is made of
Every knoc points at one integration, the connection to the system it opens, and one integration can back many knocs (see the Integrations chapter). The knoc then sets who can request access, the users and groups you choose, and the rules that apply, either a trust policy (see the Trust Engine chapter) or legacy per-Knoc source restrictions. It also carries a name, icon and category so users can find it on their portal.
Creating a knoc
Admin > Knocs > New opens the wizard.
- Install an agent, if you have none yet.
- Integration. Reuse an existing integration, or create a new one (agent, credentials, connection details).
- Knoc options. Name, icon and category, and the access rules, either a trust policy or legacy source restrictions.
- Environment variables, for script backends only.
- Select users and groups who can request access.
- Review and create.
The wizard offers existing integrations as you go and can show a diagram of how the server, agent and protected resource fit together. Connection checks help catch setup problems before you finish.
Managing knocs
- List. Admin > Knocs shows every knoc. Search and filter to find one.
- Detail. Open a knoc to edit its integration, users and rules, and to see its grant history.
Access rules
A knoc's access is decided by the trust policy attached to it. It weighs who is connecting, from where, and over what kind of network. See the Trust Engine chapter. A knoc carried over from before the Trust Engine can keep its own per-Knoc source restrictions on Legacy; see the Legacy Knocs page.