Get one principal's policy override
API key required. Returns the principal’s sparse override — only
the verbs it explicitly sets — in policy, plus the
effectivePolicy it resolves to and policyProvenance, which names
the winning layer (principal, environment, or tenant) per
verb. ?environment=dev|staging|prod folds that environment’s
override into the middle layer, exactly as a check naming it would
evaluate. An override that was never configured returns an empty
policy, version: 0 (“no override yet”).
Tombstoned principals still return 200 — they stay resolvable
forever — with "inert": true: their override never supplies a
mode while the principal is deleted or disabled. A principalId from
another tenant is 404.
Path parameters
principalId
Query parameters
environment
Allowed values:
Response
The override plus its effective policy and provenance.
Errors
400
Bad Request Error
401
Unauthorized Error
404
Not Found Error