Update access policy
| Method | Path |
|---|---|
PUT | /v1/slim/policy/:id |
Authentication · Access policies
Replaces an access policy (role) of your project and sets exactly which practitioners hold it.
Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant Practitioner:create, the right to invite users (project admins skip this check).
Scope: The policy must belong to the caller's project (from the token). Policies of parent or child projects can be read but not updated here.
Behaviour
policy.idmust equal theidin the path.- The policy body is replaced with
policy. The same interactions as on create are added (Consent;DeviceUseStatementandEpisodeOfCarefor policies that create or updatePatient;ProvenanceandAuditEventforAdminandSystem Ownerpolicies). - You cannot update a policy that ranks above you, nor rename one to a rank above you. Ranks:
System Owner, thenAdmin, then every other policy. - You cannot add or remove a member whose current role ranks above yours. A member ranks as every policy their membership holds now (
accessPolicyand anyaccessentries), each ranked by its name. A project admin (admin: true) ranks as System Owner. membersis the complete list of holders, as references such asPractitioner/<id>:- a listed member's membership in your project now points to this policy, replacing the one it held;
- a current holder not listed loses the policy. Medplum reads a membership with no policy as full access, so if that would leave them with none (no
accessentries, not a project admin), the request answers 409: move them to another role first; - you cannot remove yourself.
- The policy and the membership changes commit together. Past 49 membership changes they are written in two steps.
- The updated policy is then copied by name into each direct child project, also when it was renamed. A failed copy does not fail the request.
- Returns the updated policy with its members.
Example
curl -X PUT 'https://api.sandbox.ovok.com/v1/slim/policy/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"policy": {
"resourceType": "AccessPolicy",
"id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"name": "Night shift",
"resource": [{ "resourceType": "Patient", "interaction": ["read", "search", "update"] }]
},
"members": [{ "reference": "Practitioner/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21" }]
}'
Successful response
200 — Access policy updated successfully.
Errors
| Status | Meaning |
|---|---|
400 | policy.id differs from the path, you would remove yourself, the session carries no project or profile, or Medplum refused the write. |
401 | The bearer token is missing or invalid. |
403 | The session is not a practitioner, admin or System Owner session, its access policy lacks Practitioner:create, the policy is not in the caller's project, the policy ranks above the caller before or after the change, or a member added or removed holds a role above the caller. |
404 | No access policy has this id. |
409 | A member you remove would be left with no role (move them to another role first), a membership change lost a write conflict, or the commit conflicted. |
422 | id is not a UUID, or the body fails validation. |