Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Update an approval policy

Needs policies:write. Omitted fields are unchanged; an explicit null clears a nullable matcher. Enabling or disabling a policy is a patch of enabled. Bumps the version. Decisions already recorded on invocations keep the explanation they were made with.

PATCH/api/v2/approval-policies/{policyId}
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Path parameters
policyIdstringrequired

Public approval-policy id (apol_xxx).

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Request body
requiredapplication/json
namestring
min length 1 · max length 80
priorityinteger
min 0 · max 10000
enabledboolean
matchKindstring
Allowed:anyactioncustom
matchActionNamestring | null
min length 1 · max length 200
matchAgentIdstring | null
max length 60
matchUserIdstring | null
max length 200
matchTagsstring[] | null
max items 50
minAmountnumber | null
min 0
conditionsobject | null
conditionstring | null

A CEL expression (https://cel.dev) that must also hold, over input, agent.id, user.id, tags, action.name and kind. Checked against the target action's input schema when saved. An evaluation error (for example a missing field) requires approval rather than skipping the policy; guard optional fields with has().

min length 1 · max length 2000
effectstring
Allowed:require_approvalauto_approveauto_deny
requiredApprovalsinteger
min 1 · max 20
acknowledgeBroadScopeboolean
Responses
200

A single approval policy.

successbooleanrequired
Allowed:true
dataApprovalPolicyrequired
Show properties
idstringrequired

Public policy id (apol_xxx).

environmentIdstring<uuid>required

The environment the policy governs. Policies never span environments.

namestringrequired
priorityintegerrequired

Lower runs first. Ties are broken by creation time, then by id, so the order is always deterministic.

enabledbooleanrequired
scopestringrequired

What the policy applies to, derived from match. Never inferred from the name.

Allowed:specific_actionall_actionscustom_requestsall_requests
needsScopeReviewbooleanrequired

True on a broad policy nobody has confirmed the scope of. Every policy created before explicit targeting is in this state, because the old form sent no action selector. Preserved as it was, and flagged.

matchApprovalPolicyMatchrequired
Show properties
kindstringrequired
Allowed:anyactioncustom
actionNamestring | nullrequired
agentIdstring | nullrequired
userIdstring | nullrequired
tagsstring[] | nullrequired
minAmountnumber | nullrequired
conditionsobject | nullrequired
conditionstring | nullrequired

A CEL expression (https://cel.dev) that must also hold, over input, agent.id, user.id, tags, action.name and kind. Checked against the target action's input schema when saved. An evaluation error (for example a missing field) requires approval rather than skipping the policy; guard optional fields with has().

effectstringrequired
Allowed:require_approvalauto_approveauto_deny
requiredApprovalsintegerrequired

Distinct approvers needed (N-of-M).

versionintegerrequired

Bumps on each edit; recorded on approvals this policy governs.

scopeReviewedAtstring<date-time> | nullrequired
createdAtstring<date-time>required
updatedAtstring<date-time>required
managedByobject | null

Set when a policy file owns this policy. Console and API edits of it are refused; change the file.

Show properties
filestringrequired
keystringrequired
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
404

Not Found - Resource does not exist

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
409

The request conflicts with current resource state or a concurrent decision.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X PATCH 'https://api.anlyon.com/api/v2/approval-policies/string' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "priority": 0,
  "enabled": true,
  "matchKind": "any",
  "matchActionName": "string",
  "matchAgentId": "string",
  "matchUserId": "string",
  "matchTags": [
    "string"
  ],
  "minAmount": 0,
  "conditions": {},
  "condition": "string",
  "effect": "require_approval",
  "requiredApprovals": 1,
  "acknowledgeBroadScope": true
}'
Response
{
  "success": true,
  "data": {
    "id": "string",
    "environmentId": "19f5cc2e-7657-437a-9268-83cd3d563563",
    "name": "string",
    "priority": 0,
    "enabled": true,
    "scope": "specific_action",
    "needsScopeReview": true,
    "match": {
      "kind": "any",
      "actionName": "string",
      "agentId": "string",
      "userId": "string",
      "tags": [
        "string"
      ],
      "minAmount": 0,
      "conditions": {},
      "condition": "string"
    },
    "effect": "require_approval",
    "requiredApprovals": 0,
    "version": 0,
    "scopeReviewedAt": "2019-08-24T14:15:22Z",
    "createdAt": "2019-08-24T14:15:22Z",
    "updatedAt": "2019-08-24T14:15:22Z",
    "managedBy": {
      "file": "string",
      "key": "string"
    }
  }
}