Skip to navigation

Create or update a principal's policy override

API key required. Sets the decision mode for one or more verbs in one principal’s override — the top policy layer, beating the environment override and the tenant default. The override is sparse: only the verbs you send are stored; every other verb keeps inheriting downward. Every successful update bumps that override’s version by one — environment and tenant versions are untouched.

Fail closed: configuring policy on a tombstoned or disabled principal is 400 (principal_inactive) — an identity that cannot authorize checks cannot carry policy either. Disabling or deleting a principal later makes its override inert (it never supplies a mode); re-enabling re-arms it. The override data is kept, not wiped.

Body shapes match PUT /v1/policies/environments/{env}, plus "inherit": sending {"refund": "inherit"} removes that verb from the override so it inherits downward again.

Path parameters

principalIdstringRequired

Request

This endpoint expects a map from strings to enums.
Allowed values:

Response

The updated override plus its effective policy and provenance.

Errors

400
Bad Request Error
401
Unauthorized Error
404
Not Found Error