Do you want to restrict usage to only assumed users? Not authenticated users as well? WG has three levels of security for users. One is no authentication (guest), another is to assume users and the third is to authenticate users. Generally when you restrict users by an assumption you are preventing guests from having privileges. An authenticated user has at least an assumed level of security so any policies created for assumed users would work for them as well.
I presume that you want to restrict users to at least an assumed level or higher. You must then apply policies that require at least a "User may be asssumed" level.
This link to Qbik's knowledgebase has step by step instructions on how to setup a System wide policy based on "User must be authenticated" but it is the same process for assuming users, you would just check the "User may be assumed" radio button instead.
http://support.qbik.com/index.php?_a=kn ... %3C%2Fa%3E
As an alternative you could set this restriction to only WWW browsing by setting up the same policy in the WWW Proxy service and choosing to ignore the System policy thus only browsing is restricted in this manner not email or FTP etc. Let us know if you need mor information.