Tags

A tag is a label you attach to workstations, users, lock policies, and applications policies. On its own a tag does nothing — it becomes meaningful when you grant someone access over it on the Access Grants page. Tagging is how you carve the environment into the slices that different administrators are allowed to see.
Use this page when you are setting up delegated administration: create the tags that describe how your organization is actually divided (by department, by site, by device role), attach the relevant resources to them, then hand out grants.
Tags Table
Section titled “Tags Table”Each row is a single tag.
Name: The tag name, shown as a colored chip. The color is chosen when the tag is created and is used wherever the tag appears elsewhere in the portal.Description: A free-text explanation of what the tag covers. Worth filling in — it is what another administrator reads when deciding whether a grant is appropriate.Assignments: How many resources currently carry the tag, across all resource types.
The table header includes the following quick actions:
- add Create a new tag.
- download Export the current data set to Excel.
- sync Refresh the list.
Each row includes the following actions:
- visibility Show everything the tag currently covers.
- edit Change the tag’s name, description, or color.
- delete Delete the tag.
Creating a tag
Section titled “Creating a tag”Selecting add opens a panel asking for a name, an optional description, and a color. Names must be unique.
Coverage
Section titled “Coverage”Selecting visibility on a row opens the coverage view, which lists every resource carrying that tag, grouped by type — workstations, users, lock policies, and applications policies.
Check coverage before granting access over a tag. The grant applies to whatever the tag covers at the time it is used, not at the time it was issued, so a tag that later gains a workstation silently widens every grant already made over it.
Assigning resources to a tag
Section titled “Assigning resources to a tag”Tags are attached from the resource’s own page rather than from here. The Users and Workstations lists both carry a Tags column and allow you to select several rows and tag them in one action.
Reserved tags
Section titled “Reserved tags”The tag named All is created by Lockfy and cannot be edited or deleted. It represents the entire organization and exists so that access can be granted org-wide; see Access Grants. It does not appear as an option when tagging individual resources.
Deleting a tag
Section titled “Deleting a tag”Deleting a tag removes it from every resource carrying it, and removes every access grant made over it. Administrators who relied on those grants lose that access immediately. Review the coverage view and the grants list before deleting a tag that is in use.