Create access policy
| Method | Path |
|---|---|
POST | /v1/slim/policy |
Authentication · Access policies
Creates an access policy (role) in your project and assigns it to the listed practitioners. Use it to define a new role.
Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant AccessPolicy:create and ProjectMembership:update (project admins skip this check).
Scope: The policy is created in the caller's project (from the token).
Behaviour
- You cannot create a policy above your own rank. Ranks come from the policy name or its
basedOndisplay:System Owneris the highest, thenAdmin, then every other policy. Project admins rank as System Owner. - Ovok adds interactions the apps rely on:
Consent:read,search,create,update, always;DeviceUseStatementandEpisodeOfCare:read,search,create,update, when the policy may create or updatePatient;ProvenanceandAuditEvent:read,search, when the policy is namedAdminorSystem Owner.
membersare profile references such asPractitioner/<id>. Each listed member's membership in your project now points to the new policy, replacing the policy it held before. A member with no membership in your project is skipped.- You cannot list a member whose current role ranks above yours. A member ranks as every policy their membership holds now (
accessPolicyand anyaccessentries), each ranked by its name. A project admin (admin: true) ranks as System Owner. - The policy and the membership changes commit together. Past 49 membership changes they are written in two steps.
- The policy is then copied by name into each direct child project. A failed copy does not fail the request.
- Returns the created policy with its members, as in
GET /v1/slim/policy/{id}.
Example
curl -X POST 'https://api.sandbox.ovok.com/v1/slim/policy' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"policy": {
"resourceType": "AccessPolicy",
"name": "Night shift",
"resource": [{ "resourceType": "Patient", "interaction": ["read", "search"] }]
},
"members": [{ "reference": "Practitioner/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21", "display": "Example project" }]
}'
Successful response
201 — Access policy created successfully.
Errors
| Status | Meaning |
|---|---|
400 | The session carries no project or profile, or Medplum refused the write. |
401 | The bearer token is missing or invalid. |
403 | The session is not a practitioner, admin or System Owner session, its access policy lacks a required interaction, the policy ranks above the caller, a member holds a role above the caller, or a membership to change is outside the caller's project. |
409 | A membership change lost a write conflict, or the commit conflicted. |
422 | The body fails validation. |