Skip to content
Proud to collaborate with Microsoft for Startups

appdata.instance.ensure-app-owned-policies ​

Apply owner-only write policies to an app's app-owned tables on its own instance; idempotent, and a no-op for apps on the shared plane

Close cross-owner writes on an app's app-owned tables, on its instance.

Before virtual-engine's split policies an app-owned table carried one FOR ALL policy that admitted any end-user of the app, and its live view's soft-delete rule ran as the superuser and ignored policies altogether. So any end-user could update or delete every app-owned row, directly through the Data API or through this library's own instance path.

structure.apply emits the fixed shape, but only when the owning org re-applies, and a structure cannot be replayed. This applies just the policies, the delete rule and the owner defaults (compile_app_owned_rls_ddl) to every app-owned table the catalog knows, one table per statement batch so a catalog table that never reached the instance is reported instead of failing the rest.

Idempotent: DROP/CREATE POLICY and RULE, ALTER COLUMN SET DEFAULT.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-appdata
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID
identity_app_uuiduuidYes—Identity app the credential reads; must own an appdata namespace in this organization
request_idstringNo—Caller request id for audit correlation
actorstringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
identity_app_uuiduuidYes——
backend_kindstringYes—shared
statements_appliedintegerNo—DDL statements executed on the instance
tables_securedlistNo—App-owned tables now carrying the owner-only write policies
tables_skippedlistNo—App-owned tables in the catalog with no table on the instance
failure_reasonstringNo—Engine-stamped failure reason
failed_at_statestringNo—State when the workflow failed
failed_stepstringNo—Failed DAG step name
failed_layerintegerNo—Failed DAG layer index
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completeEnsure credential
completedNoYesYes—Credential ensured
failedNoYesNo—Ensure failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
ensuredSUCCESSApply owner-only write policies to an app's app-owned tables on its own instance; idempotent, and a no-op for apps on the shared planebackend_kind, statements_applied, tables_secured
failedFAILUREAppdata workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "appdata.instance.ensure-app-owned-policies",
  "initial_data": {
    "organization_uuid": "value",
    "identity_app_uuid": "value"
  }
}