Skip to main content

Create access policy

MethodPath
POST/v1/slim/policy

Authentication · Access policies

Creates an access policy (role) in your project and assigns it to the listed practitioners. Use it to define a new role.

Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant AccessPolicy:create and ProjectMembership:update (project admins skip this check). Scope: The policy is created in the caller's project (from the token).

Behaviour​

  • You cannot create a policy above your own rank. Ranks come from the policy name or its basedOn display: System Owner is the highest, then Admin, then every other policy. Project admins rank as System Owner.
  • Ovok adds interactions the apps rely on:
    • Consent: read, search, create, update, always;
    • DeviceUseStatement and EpisodeOfCare: read, search, create, update, when the policy may create or update Patient;
    • Provenance and AuditEvent: read, search, when the policy is named Admin or System Owner.
  • members are profile references such as Practitioner/<id>. Each listed member's membership in your project now points to the new policy, replacing the policy it held before. A member with no membership in your project is skipped.
  • You cannot list a member whose current role ranks above yours. A member ranks as every policy their membership holds now (accessPolicy and any access entries), each ranked by its name. A project admin (admin: true) ranks as System Owner.
  • The policy and the membership changes commit together. Past 49 membership changes they are written in two steps.
  • The policy is then copied by name into each direct child project. A failed copy does not fail the request.
  • Returns the created policy with its members, as in GET /v1/slim/policy/{id}.

Example​

curl -X POST 'https://api.sandbox.ovok.com/v1/slim/policy' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"policy": {
"resourceType": "AccessPolicy",
"name": "Night shift",
"resource": [{ "resourceType": "Patient", "interaction": ["read", "search"] }]
},
"members": [{ "reference": "Practitioner/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21", "display": "Example project" }]
}'

Successful response​

201 — Access policy created successfully.

Errors​

StatusMeaning
400The session carries no project or profile, or Medplum refused the write.
401The bearer token is missing or invalid.
403The session is not a practitioner, admin or System Owner session, its access policy lacks a required interaction, the policy ranks above the caller, a member holds a role above the caller, or a membership to change is outside the caller's project.
409A membership change lost a write conflict, or the commit conflicted.
422The body fails validation.