PolicyReview
/api/v1/policies/reviewsA scheduled (or completed) periodic review of a policy. Enforces 'all policies reviewed at least annually' controls.
listgetcreateupdatedeletecompleteSchema
| Field | Type | Notes |
|---|---|---|
| id* | uuid | Server-assigned ULID with type prefix (e.g. per_…). |
| tenant_id* | string | Tenant scope — auto-stamped from the caller's JWT. |
| app_id | string | App scope. Stamped ONLY when the caller's JWT was minted for a specific Application (integration API keys). Absent for human-user sessions. Filters reads when present. |
| created_at* | date-time | Server stamp. |
| updated_at* | date-time | Server stamp; updated on every patch. |
| created_by | uuid | FK → UserUser id from the caller's JWT (sub). |
| updated_by | uuid | FK → UserUser id from the last writer's JWT (sub). |
| source | string | Provenance tag — defaults to 'edm'. |
| source_type | enum | frontend | backend | server | system | apiWhere the write originated. Defaults to 'api'. |
| is_deleted | boolean | Soft-delete flag. Excluded from default list queries. |
| deleted_at | date-time | Stamped when soft-deleted; null otherwise. |
| deleted_by | uuid | FK → UserUser id who soft-deleted; null otherwise. |
| schema_version | number | Document schema version. Bumped on incompatible writes. |
| policy_id* | uuid | FK → PolicyThe policy under review. |
| reviewer_id | uuid | FK → UserAssigned reviewer (user id). |
| due_at* | date-time | When the review is due. |
| completed_at | date-time | When the review was completed. Null if still pending. |
| status | enum | scheduled | in_progress | completed | overdueReview lifecycle state. |
| outcome | enum | no_change | minor_revision | major_revision | retireResult of the review. Set via the complete action. |
| notes | string | Reviewer notes — e.g. what was changed and why. |
API
client.policies.reviews.*Loading manifest…