Delete access policy
| Method | Path |
|---|---|
DELETE | /v1/slim/policy/:id |
Authentication · Access policies
Deletes an access policy (role) of your project and detaches it from everyone who holds it.
Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant AccessPolicy:delete and ProjectMembership:update (project admins skip this check).
Scope: The policy must belong to the caller's project (from the token).
Behaviour
- A policy is not deleted while a holder would be left with no role (no
accessentry, not a project admin): the request answers 409 until they are moved to another role, because Medplum reads a membership with no policy as full access. Other holders are detached. - You cannot delete a policy you hold yourself.
- You cannot delete a policy held by anyone whose role ranks above yours (a project admin ranks as System Owner), since that takes their role away.
- Detaching the members and deleting the policy commit together. Past 49 membership changes they are written in two steps.
- The policy's copies of the same name in direct child projects are then deleted. A failed copy delete does not fail the request.
- Returns an empty body.
Example
curl -X DELETE 'https://api.sandbox.ovok.com/v1/slim/policy/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}"
Successful response
200 — Access policy deleted successfully.
Errors
| Status | Meaning |
|---|---|
400 | You hold the policy yourself, the detach or delete failed, or the session carries no project or profile. |
401 | The bearer token is missing or invalid. |
403 | The session is not a practitioner, admin or System Owner session, its access policy lacks a required interaction, the policy or a membership to detach is not in the caller's project, or a holder's role ranks above the caller. |
404 | No access policy has this id. |
409 | Someone still holds the policy and would be left with no role: move them to another role first. |
422 | id is not a UUID. |