Skip to main content

Update access policy

MethodPath
PUT/v1/slim/policy/:id

Authentication · Access policies

Replaces an access policy (role) of your project and sets exactly which practitioners hold it.

Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant Practitioner:create, the right to invite users (project admins skip this check). Scope: The policy must belong to the caller's project (from the token). Policies of parent or child projects can be read but not updated here.

Behaviour​

  • policy.id must equal the id in the path.
  • The policy body is replaced with policy. The same interactions as on create are added (Consent; DeviceUseStatement and EpisodeOfCare for policies that create or update Patient; Provenance and AuditEvent for Admin and System Owner policies).
  • You cannot update a policy that ranks above you, nor rename one to a rank above you. Ranks: System Owner, then Admin, then every other policy.
  • You cannot add or remove a member whose current role ranks above yours. A member ranks as every policy their membership holds now (accessPolicy and any access entries), each ranked by its name. A project admin (admin: true) ranks as System Owner.
  • members is the complete list of holders, as references such as Practitioner/<id>:
    • a listed member's membership in your project now points to this policy, replacing the one it held;
    • a current holder not listed loses the policy. Medplum reads a membership with no policy as full access, so if that would leave them with none (no access entries, not a project admin), the request answers 409: move them to another role first;
    • you cannot remove yourself.
  • The policy and the membership changes commit together. Past 49 membership changes they are written in two steps.
  • The updated policy is then copied by name into each direct child project, also when it was renamed. A failed copy does not fail the request.
  • Returns the updated policy with its members.

Example​

curl -X PUT 'https://api.sandbox.ovok.com/v1/slim/policy/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"policy": {
"resourceType": "AccessPolicy",
"id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"name": "Night shift",
"resource": [{ "resourceType": "Patient", "interaction": ["read", "search", "update"] }]
},
"members": [{ "reference": "Practitioner/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21" }]
}'

Successful response​

200 — Access policy updated successfully.

Errors​

StatusMeaning
400policy.id differs from the path, you would remove yourself, the session carries no project or profile, or Medplum refused the write.
401The bearer token is missing or invalid.
403The session is not a practitioner, admin or System Owner session, its access policy lacks Practitioner:create, the policy is not in the caller's project, the policy ranks above the caller before or after the change, or a member added or removed holds a role above the caller.
404No access policy has this id.
409A member you remove would be left with no role (move them to another role first), a membership change lost a write conflict, or the commit conflicted.
422id is not a UUID, or the body fails validation.