Skip to content
OpenAppPhysical access, simplified
Login

Linked-account admin

Type
linked_account_admin
Category
Sharing
Enforced at
Authoring-time
Tiers
Org
Enforcement
Enforce
Default
Not configured — warn and require acknowledgment (historical PalGate default).

PalGate setup probes whether the connected vendor account is a hardware admin of the gate. This org-tier policy decides what happens when it is not. Default when no row exists is warn and require acknowledgment (the historical PalGate default). Who may share gate users is a separate user_sharing policy.

When it is enforced

Evaluated when someone creates or updates an invitation, hold, or share. Requests that would exceed the limit are rejected — they are not silently rewritten.

Where to set it

Settings → Policies (org).

Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.

Arguments

The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.

NameTypeRequiredValuesDescription
modestringYes
warn_onlywarn_and_ackadmin_only
warn_only: allow setup with a warning. warn_and_ack: require the operator to acknowledge. admin_only: block until a hardware-admin vendor account is used.

How overlapping rows combine

Most-restrictive mode across applicable org-tree rows.

Example

Connecting PalGate with a non-admin vendor account cannot finish setup until an admin account is used.

config
{
"mode": "admin_only"
}

Integrations

This type is documented on these connectors: