Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a machine identity access control

Enable administrators to define and enforce granular control for integration users by introducing User Access Profiles. This feature provides an additional layer of security and control, allowing admins to specify the exact resources (REST APIs and SOAP APIs) that an integration user can access, ensuring tighter governance and minimizing security risks.

Before you begin

Role required: admin

Procedure

  1. Navigate to All > System Security > Machine Identity Access Controls.

  2. Select the New button.

  3. Fill in the fields of the form.

FieldDescription
NameName of the access control record.
ApplicationApplication containing the record.
DescriptionDescription of the record.
ActiveDetermines if the policy is active
REST API PolicySelect the target REST API policy. Note: Select the
Image omitted: machine-acl-lock-icon.png
Lock and the [Omitted image "machine-acl-search-icon.png"] Alt text: Search icon to add a policy.</td></tr><tr><td>
SOAP API Policy
Select the target SOAP API policy. Note: Select the
Image omitted: machine-acl-lock-icon.png
Lock and the [Omitted image "machine-acl-search-icon.png"] Alt text: Search icon to add a policy.</td></tr><tr><td>
Tables
Select the tables this policy applies to
Applies to Child TableCheck this to apply the policy to child tables of the Tables field
  1. Select the Insert a row below prompt and add users to apply the control to.

    You can add multiple users to the access control.

    Note: You can only select users with Web Service Access.

  2. Select Submit.

Result

The following is an example of a machine identity access control form that has been filled out:

Image omitted: machine-acl-example.png
An example of a machine identity access control form filled out.

A user with an machine identity access control cannot access any other APIs (REST or SOAP) and will only be able to access the resources explicitly stated in the access control, even if they have the required roles.