Playground

Playground

PolicyReview

/api/v1/policies/reviews

A scheduled (or completed) periodic review of a policy. Enforces 'all policies reviewed at least annually' controls.

listgetcreateupdatedeletecomplete

Schema

FieldTypeNotes
id*uuidServer-assigned ULID with type prefix (e.g. per_…).
tenant_id*stringTenant scope — auto-stamped from the caller's JWT.
app_idstringApp scope. Stamped ONLY when the caller's JWT was minted for a specific Application (integration API keys). Absent for human-user sessions. Filters reads when present.
created_at*date-timeServer stamp.
updated_at*date-timeServer stamp; updated on every patch.
created_byuuidFK → UserUser id from the caller's JWT (sub).
updated_byuuidFK → UserUser id from the last writer's JWT (sub).
sourcestringProvenance tag — defaults to 'edm'.
source_typeenumfrontend | backend | server | system | apiWhere the write originated. Defaults to 'api'.
is_deletedbooleanSoft-delete flag. Excluded from default list queries.
deleted_atdate-timeStamped when soft-deleted; null otherwise.
deleted_byuuidFK → UserUser id who soft-deleted; null otherwise.
schema_versionnumberDocument schema version. Bumped on incompatible writes.
policy_id*uuidFK → PolicyThe policy under review.
reviewer_iduuidFK → UserAssigned reviewer (user id).
due_at*date-timeWhen the review is due.
completed_atdate-timeWhen the review was completed. Null if still pending.
statusenumscheduled | in_progress | completed | overdueReview lifecycle state.
outcomeenumno_change | minor_revision | major_revision | retireResult of the review. Set via the complete action.
notesstringReviewer notes — e.g. what was changed and why.

API

client.policies.reviews.*
Loading manifest…