1.1 On the Publish a Service Tunnel doc, navigate from Steps to Publish a Service Tunnel > Step 1: Create a Tunnel Policy. Follow this step to create a Service Tunnel Policy in your org.
1.2 Is SCIM enabled in your org?
If yes, then directly assign your users to the Service Tunnel Policy.
If not, then instruct your end users to log into the CSE app and register their devices; Afterward, assign your end users to the Service Tunnel Policy.
2.2 Apply the Tunnel Policy (created above in Step 1.1) to the tunnel, so that your end users can access the Service Tunnel.