policy.decision.evaluate-batch ​
Evaluate many capabilities for one end-user in one call
Evaluate many capabilities for one end-user in a single call (GOV-10).
Resolves the subject's role + capabilities ONCE and decides each capability — so a page/sidebar can authorize a whole action-set in one round trip. Same fail-closed semantics as policy.decision.evaluate.
Inputs: actor, identity_app_uuid, end_user_uuid, capabilities (list) — required; source (GOV-4, optional, default "token"), context (GOV-3, optional). The shared context may also carry the GOV-2 gate keys (feature_flag/module, plan_gate/entitlement, terms_key/requires_terms); each gate is resolved once and, when it denies, applies to every capability in the call. Outputs: role, count, source (echoed), results [{capability, decision, allow, reason, obligations}]. Per-result reason ∈ ok | no_role | capability_missing | flag_off | plan_exceeded | terms_unaccepted.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-identity |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
actor | string | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
end_user_uuid | uuid | Yes | — | — |
capabilities | list | Yes | — | — |
source | string | No | — | — |
context | dict | No | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
results | list | Yes | — | — |
role | string | No | — | — |
count | integer | No | — | — |
source | string | No | — | — |
identity_app_uuid | uuid | No | — | — |
end_user_uuid | uuid | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "policy.decision.evaluate-batch",
"initial_data": {
"actor": "value",
"identity_app_uuid": "value",
"end_user_uuid": "value",
"capabilities": "value"
}
}