Skip to content
Proud to collaborate with Microsoft for Startups

policy.entitlement.query ​

Thin read of an app's plan entitlement over subscription.*

Read whether an app's plan unlocks a given entitlement (GOV-8, thin read).

Inputs: actor, organization_uuid, identity_app_uuid, entitlement (required). entitlement is the planGate key a module/action declares (e.g. "operational"). Outputs: entitled (bool), entitlement, plan (nullable), reason, source.

v1 returns entitled=False with source="unwired" (fail-closed) — the actual read over subscription.* is a marked TODO (see module docstring / design §8). The contract is stable so callers integrate now and gain real plan data later with no change.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-policy
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes——
organization_uuiduuidYes——
identity_app_uuiduuidYes——
entitlementstringYes——

Output Schema ​

FieldTypeRequiredDefaultDescription
entitledbooleanNo——
entitlementstringNo——
planstringNo——
sourcestringNo——
identity_app_uuiduuidNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_layerstringNo——
failed_stepstringNo——
errorstringNo——
error_typestringNo——
reasonstringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "policy.entitlement.query",
  "initial_data": {
    "actor": "value",
    "organization_uuid": "value",
    "identity_app_uuid": "value",
    "entitlement": "value"
  }
}