Create or update a principal's policy override
API key required. Sets the decision mode for one or more verbs in
one principal’s override — the top policy layer, beating the
environment override and the tenant default. The override is
sparse: only the verbs you send are stored; every other verb keeps
inheriting downward. Every successful update bumps that override’s
version by one — environment and tenant versions are untouched.
Fail closed: configuring policy on a tombstoned or disabled
principal is 400 (principal_inactive) — an identity that cannot
authorize checks cannot carry policy either. Disabling or deleting
a principal later makes its override inert (it never supplies a
mode); re-enabling re-arms it. The override data is kept, not
wiped.
Body shapes match PUT /v1/policies/environments/{env}, plus
"inherit": sending {"refund": "inherit"} removes that verb from
the override so it inherits downward again.