Skip to content

Policies

client.policies manages the tenant’s own rules on top of the floor that Seald Healthcare enforces. The floor is fixed per rule. Nobody can loosen it. A tenant’s overlay narrows the floor further, or leaves it as is. Every change goes through a version:

  1. An author submits the version.
  2. A different Owner or Admin approves it and sets the time it takes effect.

Only one version is active at a time.

The calls

The samples use the allowed helper from Access decisions.

const floor = await client.policies.floor();
// [{ rule, floor, tenantMay }, ...]
const active = await client.policies.active();
const versions = await client.policies.versions();
const currentOverlay = await client.policies.overlay(active.versionId);
const submitted = await allowed(await client.policies.submit(overlay));
if (submitted?.kind === 'refused') renderFloorRows(submitted.floorRows);
else if (submitted?.kind === 'pending') tell(`Version ${submitted.version.number} waits for approval`);
// the approver, who is never the author
await allowed(await client.policies.approve(versionId, new Date('2026-10-01T06:00:00Z')));
await allowed(await client.policies.reject(versionId, 'Overlay narrows access below what the floor names'));
// the author, before approval
await allowed(await client.policies.withdraw(versionId));
// the caller holds the Owner role, before the approved version takes effect
await allowed(await client.policies.cancel(versionId));

Each FloorRow names a rule, the floor Seald Healthcare does not go below, and tenantMay: what the overlay may add on top of it.

The overlay format

An Overlay is a JSON document. It states, in order:

  1. named rules that resolve to an outcome
  2. an offline lease limit
  3. the tenant’s session lifetimes
{
"version": 1,
"rules": [
{ "id": "after-hours-phi", "when": { "classification": "phi", "hours": "outside" }, "then": "challenge" },
{ "id": "contractor-imaging", "when": { "role": "contractor", "dataset": "imaging" }, "then": "deny", "reason": "not-entitled" },
{ "id": "unmanaged-device", "when": { "device": "unmanaged" }, "then": "deny", "reason": "device" }
],
"offlineLease": { "roles": ["employee"], "maxHours": 72 },
"sessions": { "inactivity": 900, "overall": 43200 }
}
FieldMeaning
versionThe overlay’s own schema version, distinct from the PolicyVersion.number the Seald Healthcare Cloud assigns on submission
rulesAn ordered list of named rules. The first whose when matches decides the outcome
rules[].idA short, unique name for the rule, shown in PolicyVersion.difference and in the audit trail
rules[].whenThe conditions that must all hold: a classification, an hours window (outside or inside), a role, a dataset, or a device state (unmanaged)
rules[].thenThe outcome the rule produces: allow, deny or challenge
rules[].reasonRequired when then is deny: a DenyReason such as not-entitled or device
offlineLease.rolesThe roles the tenant grants an offline lease to
offlineLease.maxHoursHow long an offline lease may run before the device must reconnect
sessions.inactivitySeconds of inactivity before a session moves to inactive and needs session.resume()
sessions.overallSeconds after which a session ends outright, however active it was

Seald Healthcare checks every submitted overlay against the floor. Seald Healthcare refuses an overlay with a rule that relaxes a floored outcome. It also refuses a session or offline lease limit above the floor’s own. The refusal names the floorRows that stand in the way. No overlay can give a PolicyVersion a state the floor forbids.

What the SDK does for you

  • Signs an approve or reject with a fresh multi-factor sign-in, over the version’s hash and the approval time.
  • Refuses to let the author of a version approve their own submission.
  • Assigns each accepted submission the next PolicyVersion.number, computes its hash, and records the difference from the version before it.
  • Once a version is approved, moves it on its own to active at effectiveAt. The version it replaces becomes superseded.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
refused (a Submitted.kind)The overlay would go below one or more floorRows.Loosen the named rules or limits and submit again.
deny on approveThe caller is the version’s own author.Ask another Owner or Admin to approve.
challengeThe caller’s multi-factor sign-in is no longer fresh.Call stepUp(), or use the allowed helper.
A version stuck in pendingNobody with the role to approve has reviewed it.Check versions() for its author and ask an Owner or Admin.
withdrawn (a PolicyVersion.state)The author withdrew a pending version.Submit a fresh overlay.

PolicyVersion.state also reaches rejected when an approver declines it, and canceled when an Owner cancels an approved version before its effectiveAt.

Next