Skip to content

policies

client.policies manages the tenant’s policies. It:

  • reads the floor, which no overlay may loosen
  • reads the tenant’s active policy version and its history
  • submits, approves, rejects, withdraws or cancels a change

floor

floor returns the tenant’s floor.

floor(): Promise<FloorRow[]>;

Returns: Every FloorRow of the tenant’s floor.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

active

active returns the policy version in effect now.

active(): Promise<PolicyVersion>;

Returns: The PolicyVersion in effect now.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

versions

versions returns every policy version the tenant has had.

versions(): Promise<PolicyVersion[]>;

Returns: Every PolicyVersion the tenant has had, pending ones included.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

overlay

overlay returns one version’s overlay document.

overlay(versionId?: string): Promise<Overlay>;
ParameterTypeDescription
versionIdstring, optionalOne version’s overlay. When absent, the active version’s overlay.

Returns: The Overlay document. Policies describes its format.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

submit

submit submits a proposed overlay. Seald Healthcare checks it against the floor. A valid overlay becomes the next version, pending approval.

submit(overlay: Overlay): Promise<Decided<Submitted>>;
ParameterTypeDescription
overlayOverlayThe proposed overlay document. Policies describes its format.

Returns: A Decided<Submitted>: on allow, Submitted reports either the pending version or, when the overlay would loosen the floor, the floor rows it failed.

Records: Submit Policy. See Audit actions.

Errors: no-session, unreachable.

approve

approve approves a pending version. After a fresh multi-factor sign-in, the approver signs the version’s hash and the time.

approve(versionId: string, effectiveAt?: Date): Promise<Decided<{}>>;
ParameterTypeDescription
versionIdstringThe version to approve.
effectiveAtdate, optionalWhen it takes effect. When absent, immediately.

Returns: A Decided<{}>.

Records: Approve Policy. See Audit actions.

Who may call it: An Owner or Admin who is not the version’s author.

Errors: no-session, unreachable, canceled, not-found.

reject

reject rejects a pending version, with a reason for the author.

reject(versionId: string, reason: string): Promise<Decided<{}>>;
ParameterTypeDescription
versionIdstringThe version to reject.
reasonstringShown to the author.

Returns: A Decided<{}>.

Records: One decision and one access event.

Errors: no-session, unreachable, not-found.

withdraw

withdraw withdraws a pending version. Only its author may call it.

withdraw(versionId: string): Promise<Decided<{}>>;
ParameterTypeDescription
versionIdstringThe pending version to withdraw.

Returns: A Decided<{}>.

Records: One decision and one access event.

Who may call it: The version’s author.

Errors: no-session, unreachable, not-found.

cancel

cancel cancels an approved version before it takes effect.

cancel(versionId: string): Promise<Decided<{}>>;
ParameterTypeDescription
versionIdstringThe approved, not-yet-effective version to cancel.

Returns: A Decided<{}>.

Records: One decision and one access event.

Who may call it: The Owner role.

Errors: no-session, unreachable, not-found.

Types

FloorRow

interface FloorRow {
rule: string;
floor: string;
tenantMay: string;
}
FieldTypeDescription
rulestringThe rule the floor sets.
floorstringWhat the floor fixes.
tenantMaystringWhat the tenant’s overlay may still narrow.

Overlay

Overlay is the tenant’s overlay as a document. Only the Seald Healthcare Cloud reads it. Policies describes its format.

type Overlay = unknown;

PolicyVersion

interface PolicyVersion {
versionId: string;
number: number;
hash: string;
state: 'pending' | 'approved' | 'active' | 'superseded' | 'rejected' | 'withdrawn' | 'canceled';
author: RecipientId;
approver?: RecipientId;
submittedAt: Date;
effectiveAt?: Date;
difference: string;
}
FieldTypeDescription
versionIdstringIdentifies the version.
numbernumberThe version’s sequence number.
hashstringThe hash an approval signs.
stateone of the seven statesWhere the version stands.
authorRecipientIdWho submitted it.
approverRecipientId, optionalWho approved it, once approved.
submittedAtdateWhen it was submitted.
effectiveAtdate, optionalWhen it takes or took effect.
differencestringThe difference from the version before it.

Submitted

type Submitted = { kind: 'pending'; version: PolicyVersion } | { kind: 'refused'; floorRows: FloorRow[] };
CasePayloadDescription
pendingversionThe overlay validated. This is the next version, pending approval.
refusedfloorRowsThe overlay would loosen the floor. No version was created. These are the rows it failed.