Skip to content
Proud to collaborate with Microsoft for Startups

policy.decision.evaluate ​

Evaluate whether an end-user is allowed a capability

Evaluate whether an end-user is allowed a capability (capability stage, v1).

Inputs:

  • identity_app_uuid: the app tenant (required)
  • end_user_uuid: the subject end-user (required)
  • capability: the capability string, e.g. data:property:write | vw❌invoke (required)
  • resource_ref: optional concrete resource id (echoed, for audit)
  • actor: caller principal (required)
  • source: delegated subject source (optional, default "token"; token|schedule|staff) — GOV-4
  • context: optional decision context {cross_app?, risk?, mask_fields?, feature_flag?/module?, plan_gate?/entitlement?, terms_key?/requires_terms?, ...} — GOV-3/SUPPORT + GOV-2 FLAG/PLAN/TERMS gate keys

Outputs (terminal state_data):

  • decision: "allow" | "deny"
  • allow: boolean mirror of decision
  • reason: ok | capability_missing | no_role | resolve_error | support_cross_app_forbidden | flag_off | plan_exceeded | terms_unaccepted
  • context.feature_flag / context.module: the FLAG stage gate key (GOV-2); flag OFF -> deny flag_off
  • context.plan_gate / context.entitlement: the PLAN stage entitlement key (GOV-2); plan lacks it -> deny plan_exceeded
  • context.terms_key / context.requires_terms: the TERMS stage key (GOV-2); subject hasn't accepted -> deny terms_unaccepted
  • source: the (echoed) delegated subject source — every decision is attributable
  • obligations: non-blocking follow-ups on allow (audit always; require_approval; mask_fields:<comma-joined>); [] on deny
  • role, capability, resource_ref

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes——
identity_app_uuiduuidYes——
end_user_uuiduuidYes——
capabilitystringYes——
resource_refstringNo——
sourcestringNo——
contextdictNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
decisionstringYes——
allowbooleanYes——
reasonstringYes——
sourcestringNo——
obligationslistNo——
rolestringNo——
capabilitystringNo——
resource_refstringNo——
identity_app_uuiduuidNo——
end_user_uuiduuidNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "policy.decision.evaluate",
  "initial_data": {
    "actor": "value",
    "identity_app_uuid": "value",
    "end_user_uuid": "value",
    "capability": "value"
  }
}