policy.decision.evaluate
Evaluate whether an end-user is allowed a capability
Evaluate whether an end-user is allowed a capability (capability stage, v1).
Inputs:
- identity_app_uuid: the app tenant (required)
- end_user_uuid: the subject end-user (required)
- capability: the capability string, e.g. data:property:write | vw❌invoke (required)
- resource_ref: optional concrete resource id (echoed, for audit)
- actor: caller principal (required)
- source: delegated subject source (optional, default "token"; token|schedule|staff) — GOV-4
- context: optional decision context {cross_app?, risk?, mask_fields?, feature_flag?/module?, plan_gate?/entitlement?, terms_key?/requires_terms?, ...} — GOV-3/SUPPORT + GOV-2 FLAG/PLAN/TERMS gate keys
Outputs (terminal state_data):
- decision: "allow" | "deny"
- allow: boolean mirror of decision
- reason: ok | capability_missing | no_role | resolve_error | support_cross_app_forbidden | flag_off | plan_exceeded | terms_unaccepted
- context.feature_flag / context.module: the FLAG stage gate key (GOV-2); flag OFF -> deny flag_off
- context.plan_gate / context.entitlement: the PLAN stage entitlement key (GOV-2); plan lacks it -> deny plan_exceeded
- context.terms_key / context.requires_terms: the TERMS stage key (GOV-2); subject hasn't accepted -> deny terms_unaccepted
- source: the (echoed) delegated subject source — every decision is attributable
- obligations: non-blocking follow-ups on allow (audit always; require_approval; mask_fields:<comma-joined>); [] on deny
- role, capability, resource_ref
Overview
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-identity |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
actor | string | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
end_user_uuid | uuid | Yes | — | — |
capability | string | Yes | — | — |
resource_ref | string | No | — | — |
source | string | No | — | — |
context | dict | No | — | — |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
decision | string | Yes | — | — |
allow | boolean | Yes | — | — |
reason | string | Yes | — | — |
source | string | No | — | — |
obligations | list | No | — | — |
role | string | No | — | — |
capability | string | No | — | — |
resource_ref | string | No | — | — |
identity_app_uuid | uuid | No | — | — |
end_user_uuid | uuid | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "policy.decision.evaluate",
"initial_data": {
"actor": "value",
"identity_app_uuid": "value",
"end_user_uuid": "value",
"capability": "value"
}
}