Skip to content
Proud to collaborate with Microsoft for Startups

policy.decision.evaluate-batch ​

Evaluate many capabilities for one end-user in one call

Evaluate many capabilities for one end-user in a single call (GOV-10).

Resolves the subject's role + capabilities ONCE and decides each capability — so a page/sidebar can authorize a whole action-set in one round trip. Same fail-closed semantics as policy.decision.evaluate.

Inputs: actor, identity_app_uuid, end_user_uuid, capabilities (list) — required; source (GOV-4, optional, default "token"), context (GOV-3, optional). The shared context may also carry the GOV-2 gate keys (feature_flag/module, plan_gate/entitlement, terms_key/requires_terms); each gate is resolved once and, when it denies, applies to every capability in the call. Outputs: role, count, source (echoed), results [{capability, decision, allow, reason, obligations}]. Per-result reason ∈ ok | no_role | capability_missing | flag_off | plan_exceeded | terms_unaccepted.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes——
identity_app_uuiduuidYes——
end_user_uuiduuidYes——
capabilitieslistYes——
sourcestringNo——
contextdictNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
resultslistYes——
rolestringNo——
countintegerNo——
sourcestringNo——
identity_app_uuiduuidNo——
end_user_uuiduuidNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "policy.decision.evaluate-batch",
  "initial_data": {
    "actor": "value",
    "identity_app_uuid": "value",
    "end_user_uuid": "value",
    "capabilities": "value"
  }
}