Policies
client.policies manages the tenant’s own rules on top of the floor that Seald Healthcare enforces. The floor is fixed per rule. Nobody can loosen it. A tenant’s overlay narrows the floor further, or leaves it as is. Every change goes through a version:
- An author submits the version.
- A different Owner or Admin approves it and sets the time it takes effect.
Only one version is active at a time.
The calls
The samples use the allowed helper from Access decisions.
const floor = await client.policies.floor();// [{ rule, floor, tenantMay }, ...]
const active = await client.policies.active();const versions = await client.policies.versions();const currentOverlay = await client.policies.overlay(active.versionId);
const submitted = await allowed(await client.policies.submit(overlay));if (submitted?.kind === 'refused') renderFloorRows(submitted.floorRows);else if (submitted?.kind === 'pending') tell(`Version ${submitted.version.number} waits for approval`);
// the approver, who is never the authorawait allowed(await client.policies.approve(versionId, new Date('2026-10-01T06:00:00Z')));await allowed(await client.policies.reject(versionId, 'Overlay narrows access below what the floor names'));
// the author, before approvalawait allowed(await client.policies.withdraw(versionId));// the caller holds the Owner role, before the approved version takes effectawait allowed(await client.policies.cancel(versionId));let floor = try await client.policies.floor()let active = try await client.policies.active()let versions = try await client.policies.versions()let currentOverlay = try await client.policies.overlay(active.versionId)
let submitted = try await allowed(client.policies.submit(overlay))switch submitted {case .refused(let floorRows): renderFloorRows(floorRows)case .pending(let version): tell("Version \(version.number) waits for approval")case .none: break}
_ = try await allowed(client.policies.approve(versionId, effectiveAt: Date("2026-10-01T06:00:00Z")))_ = try await allowed(client.policies.reject(versionId, reason: "Overlay narrows access below what the floor names"))_ = try await allowed(client.policies.withdraw(versionId))_ = try await allowed(client.policies.cancel(versionId))val floor = client.policies.floor()val active = client.policies.active()val versions = client.policies.versions()val currentOverlay = client.policies.overlay(active.versionId)
when (val submitted = allowed(client.policies.submit(overlay))) { is Submitted.Refused -> renderFloorRows(submitted.floorRows) is Submitted.Pending -> tell("Version ${submitted.version.number} waits for approval") null -> {}}
allowed(client.policies.approve(versionId, effectiveAt = Instant.parse("2026-10-01T06:00:00Z")))allowed(client.policies.reject(versionId, reason = "Overlay narrows access below what the floor names"))allowed(client.policies.withdraw(versionId))allowed(client.policies.cancel(versionId))Each FloorRow names a rule, the floor Seald Healthcare does not go below, and tenantMay: what the overlay may add on top of it.
The overlay format
An Overlay is a JSON document. It states, in order:
- named rules that resolve to an outcome
- an offline lease limit
- the tenant’s session lifetimes
{ "version": 1, "rules": [ { "id": "after-hours-phi", "when": { "classification": "phi", "hours": "outside" }, "then": "challenge" }, { "id": "contractor-imaging", "when": { "role": "contractor", "dataset": "imaging" }, "then": "deny", "reason": "not-entitled" }, { "id": "unmanaged-device", "when": { "device": "unmanaged" }, "then": "deny", "reason": "device" } ], "offlineLease": { "roles": ["employee"], "maxHours": 72 }, "sessions": { "inactivity": 900, "overall": 43200 }}| Field | Meaning |
|---|---|
version | The overlay’s own schema version, distinct from the PolicyVersion.number the Seald Healthcare Cloud assigns on submission |
rules | An ordered list of named rules. The first whose when matches decides the outcome |
rules[].id | A short, unique name for the rule, shown in PolicyVersion.difference and in the audit trail |
rules[].when | The conditions that must all hold: a classification, an hours window (outside or inside), a role, a dataset, or a device state (unmanaged) |
rules[].then | The outcome the rule produces: allow, deny or challenge |
rules[].reason | Required when then is deny: a DenyReason such as not-entitled or device |
offlineLease.roles | The roles the tenant grants an offline lease to |
offlineLease.maxHours | How long an offline lease may run before the device must reconnect |
sessions.inactivity | Seconds of inactivity before a session moves to inactive and needs session.resume() |
sessions.overall | Seconds after which a session ends outright, however active it was |
Seald Healthcare checks every submitted overlay against the floor. Seald Healthcare refuses an overlay with a rule that relaxes a floored outcome. It also refuses a session or offline lease limit above the floor’s own. The refusal names the floorRows that stand in the way. No overlay can give a PolicyVersion a state the floor forbids.
What the SDK does for you
- Signs an
approveorrejectwith a fresh multi-factor sign-in, over the version’shashand the approval time. - Refuses to let the author of a version approve their own submission.
- Assigns each accepted submission the next
PolicyVersion.number, computes itshash, and records thedifferencefrom the version before it. - Once a version is approved, moves it on its own to
activeateffectiveAt. The version it replaces becomessuperseded.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
refused (a Submitted.kind) | The overlay would go below one or more floorRows. | Loosen the named rules or limits and submit again. |
deny on approve | The caller is the version’s own author. | Ask another Owner or Admin to approve. |
challenge | The caller’s multi-factor sign-in is no longer fresh. | Call stepUp(), or use the allowed helper. |
A version stuck in pending | Nobody with the role to approve has reviewed it. | Check versions() for its author and ask an Owner or Admin. |
withdrawn (a PolicyVersion.state) | The author withdrew a pending version. | Submit a fresh overlay. |
PolicyVersion.state also reaches rejected when an approver declines it, and canceled when an Owner cancels an approved version before its effectiveAt.