Skip to navigation

Get one principal's policy override

API key required. Returns the principal’s sparse override — only the verbs it explicitly sets — in policy, plus the effectivePolicy it resolves to and policyProvenance, which names the winning layer (principal, environment, or tenant) per verb. ?environment=dev|staging|prod folds that environment’s override into the middle layer, exactly as a check naming it would evaluate. An override that was never configured returns an empty policy, version: 0 (“no override yet”).

Tombstoned principals still return 200 — they stay resolvable forever — with "inert": true: their override never supplies a mode while the principal is deleted or disabled. A principalId from another tenant is 404.

Path parameters

principalIdstringRequired

Query parameters

environmentenumOptional
Allowed values:

Response

The override plus its effective policy and provenance.

Errors

400
Bad Request Error
401
Unauthorized Error
404
Not Found Error