Skip to main content

Delete access policy

MethodPath
DELETE/v1/slim/policy/:id

Authentication · Access policies

Deletes an access policy (role) of your project and detaches it from everyone who holds it.

Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant AccessPolicy:delete and ProjectMembership:update (project admins skip this check). Scope: The policy must belong to the caller's project (from the token).

Behaviour​

  • A policy is not deleted while a holder would be left with no role (no access entry, not a project admin): the request answers 409 until they are moved to another role, because Medplum reads a membership with no policy as full access. Other holders are detached.
  • You cannot delete a policy you hold yourself.
  • You cannot delete a policy held by anyone whose role ranks above yours (a project admin ranks as System Owner), since that takes their role away.
  • Detaching the members and deleting the policy commit together. Past 49 membership changes they are written in two steps.
  • The policy's copies of the same name in direct child projects are then deleted. A failed copy delete does not fail the request.
  • Returns an empty body.

Example​

curl -X DELETE 'https://api.sandbox.ovok.com/v1/slim/policy/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

200 — Access policy deleted successfully.

Errors​

StatusMeaning
400You hold the policy yourself, the detach or delete failed, or the session carries no project or profile.
401The bearer token is missing or invalid.
403The session is not a practitioner, admin or System Owner session, its access policy lacks a required interaction, the policy or a membership to detach is not in the caller's project, or a holder's role ranks above the caller.
404No access policy has this id.
409Someone still holds the policy and would be left with no role: move them to another role first.
422id is not a UUID.