API

Check Access authorization

Check Access authorization. This applies the validated business action to the selected tenant or platform resource.

POST/api/authorization/check-access
Preview

Check Access authorization. This applies the validated business action to the selected tenant or platform resource.

Operation ID postapiAuthorizationCheckAccess

Operation details

Purpose

Check Access authorization. This applies the validated business action to the selected tenant or platform resource.

When to use it

Use this when the documented business action or resource creation is the intended next step.

When not to use it

Do not repeat the request blindly after an uncertain outcome. Read the resulting resource or background operation state first.

Contract

Availability

Product version
Next Product release
Licence
An active Product licence is required except for health, authentication, and licence remediation operations.
Entitlements
None
Service roles
core
Deployment
customer managed installation
Feature state
preview

Security

Access

Sign in: Use a session cookie or Bearer session token.

Actor
Authenticated Pūnaha actor authorised for the selected tenant and resource
Permission
None
Resource
Tenant rule
Tenant scoped unless the selected actor is performing an explicitly documented platform action. The x organization id header or authenticated session context selects the tenant. It does not grant access.
Explicit deny
An applicable explicit deny overrides an allow. Knowing or supplying a resource identifier never grants access.

Address, query and header fields

FieldLocationPresenceTypeMeaningLimits and example
x-request-idheaderOptionalstringOptional caller supplied correlation identifier. Pūnaha returns the effective value in the response header.Minimum length: 1. Maximum length: 200. Example: example request 001

Request body

Content type: application/json. Presence: Required.

Operation request. Every property documents omission, null, sensitivity, source, mutability, availability, access, and lifecycle semantics through JSON Schema and x punaha-* annotations.

Request fields6 documented fields

Request fields

FieldPresenceTypeMeaningEmpty and defaultLimits and exampleAccess, sensitivity and lifecycle
actionrequiredstringThe action associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
permissionoptionalJSON valueA JSON value whose structure is defined by the selected operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
resourceIdrequiredstringThe resource id associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
resourceTyperequiredstringThe resource type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
subjectIdrequiredstringThe subject id associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
subjectTyperequiredstringThe subject type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
Complete representative request using synthetic data
{
  "action": "example-value",
  "permission": "example-value",
  "resourceId": "example-value",
  "resourceType": "example-value",
  "subjectId": "example-value",
  "subjectType": "example-value"
}
Smallest schema valid request
{
  "action": "example-value",
  "resourceId": "example-value",
  "resourceType": "example-value",
  "subjectId": "example-value",
  "subjectType": "example-value"
}

Responses

StatusMeaning and correction boundaryBody
200The operation completed and the response contains the current operation specific representation.application/json, object
400The operation failed with HTTP 400. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
401The operation failed with HTTP 401. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
403The operation failed with HTTP 403. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
404The operation failed with HTTP 404. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
409The operation failed with HTTP 409. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
423The operation failed with HTTP 423. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
500The operation failed with HTTP 500. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
503The operation failed with HTTP 503. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
200 response fields63 documented fields

200 response fields

FieldPresenceTypeMeaningEmpty and defaultLimits and exampleAccess, sensitivity and lifecycle
datarequiredHttpapicheckAccessResponseResponseThe operation specific result.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.No additional schema limit is listedInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.actionrequiredHttpapieffectiveAccessActionResponseThe action associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.No additional schema limit is listedInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.allowedrequiredbooleanThe allowed associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.coderequiredstringA stable machine readable code for the represented condition.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.descriptionrequiredstringThe description associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.labelrequiredstringThe label associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.messagerequiredstringA human readable explanation intended to help understand the result.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.reasonrequiredone of explicit_deny, inherited_access, matching_allow, no_matching_access, platform_administrator, role_and_grant, role_permission, system_ownerThe reason associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Allowed: explicit_deny, inherited_access, matching_allow, no_matching_access, platform_administrator, role_and_grant, role_permission, system_owner. Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sourcesrequiredlist of HttpapieffectiveAccessSourceResponseThe sources associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].actionMatchoptionalstringThe action match associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].assignmentIdoptionalstringThe assignment id associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].detailoptionalstringThe detail associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].determinesResultrequiredbooleanThe determines result associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].effectrequiredstringThe effect associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].expiresAtoptionalstring in date-time format or nullThe expires at associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: 2026 08 28T00:00:00ZInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].inheritedrequiredbooleanThe inherited associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].namerequiredstringThe name associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].overriddenrequiredbooleanThe overridden associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].relationshipoptionalstringThe relationship associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].resourceMatchoptionalstringThe resource match associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].scoperequiredstringThe scope associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].sourceTyperequiredstringThe source type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].statusrequiredstringThe current lifecycle or processing state.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.action.sources[].warningoptionalstringThe warning associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resourcerequiredHttpapieffectiveAccessResourceResponseThe resource associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.No additional schema limit is listedInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actionsrequiredlist of HttpapieffectiveAccessActionResponseThe actions associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].allowedrequiredbooleanThe allowed associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].coderequiredstringA stable machine readable code for the represented condition.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].descriptionrequiredstringThe description associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].labelrequiredstringThe label associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].messagerequiredstringA human readable explanation intended to help understand the result.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].reasonrequiredone of explicit_deny, inherited_access, matching_allow, no_matching_access, platform_administrator, role_and_grant, role_permission, system_ownerThe reason associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Allowed: explicit_deny, inherited_access, matching_allow, no_matching_access, platform_administrator, role_and_grant, role_permission, system_owner. Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sourcesrequiredlist of HttpapieffectiveAccessSourceResponseThe sources associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].actionMatchoptionalstringThe action match associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].assignmentIdoptionalstringThe assignment id associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].detailoptionalstringThe detail associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].determinesResultrequiredbooleanThe determines result associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].effectrequiredstringThe effect associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].expiresAtoptionalstring in date-time format or nullThe expires at associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: 2026 08 28T00:00:00ZInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].inheritedrequiredbooleanThe inherited associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].namerequiredstringThe name associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].overriddenrequiredbooleanThe overridden associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: YesInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].relationshipoptionalstringThe relationship associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].resourceMatchoptionalstringThe resource match associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].scoperequiredstringThe scope associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].sourceTyperequiredstringThe source type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].statusrequiredstringThe current lifecycle or processing state.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.actions[].sources[].warningoptionalstringThe warning associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.arearequiredstringThe area associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.descriptionoptionalstringThe description associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.namerequiredstringThe name associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.parentoptionalHttpapiaccessResourceParentResponse or nullThe parent associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.No additional schema limit is listedInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.resourceIdrequiredstringThe resource id associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.resourceTyperequiredstringThe resource type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.statusrequiredstringThe current lifecycle or processing state.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.resource.warningoptionalstringThe warning associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subjectrequiredHttpapiaccessExplanationSubjectResponseThe subject associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.No additional schema limit is listedInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.detailoptionalstringThe detail associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.idrequiredstringThe stable identifier of this resource.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.namerequiredstringThe name associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.roleoptionalstringThe role associated with this resource or operation.The field may be omitted. Omission is different from null, an empty string, an empty collection, zero, or false. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.statusrequiredstringThe current lifecycle or processing state.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
data.subject.typerequiredstringThe type associated with this resource or operation.The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present.Example: example valueInherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release.
Successful response using synthetic data
{
  "data": {
    "action": {
      "allowed": true,
      "code": "example-value",
      "description": "example-value",
      "label": "example-value",
      "message": "example-value",
      "reason": "example-value",
      "sources": [
        {
          "actionMatch": "example-value",
          "assignmentId": "example-value",
          "detail": "example-value",
          "determinesResult": true,
          "effect": "example-value",
          "expiresAt": "2026-08-28T00:00:00Z",
          "inherited": true,
          "name": "example-value",
          "overridden": true,
          "relationship": "example-value",
          "resourceMatch": "example-value",
          "scope": "example-value",
          "sourceType": "example-value",
          "status": "example-value",
          "warning": "example-value"
        }
      ]
    },
    "resource": {
      "actions": [
        {
          "allowed": true,
          "code": "example-value",
          "description": "example-value",
          "label": "example-value",
          "message": "example-value",
          "reason": "example-value",
          "sources": [
            {
              "actionMatch": "example-value",
              "assignmentId": "example-value",
              "detail": "example-value",
              "determinesResult": true,
              "effect": "example-value",
              "expiresAt": "2026-08-28T00:00:00Z",
              "inherited": true,
              "name": "example-value",
              "overridden": true,
              "relationship": "example-value",
              "resourceMatch": "example-value",
              "scope": "example-value",
              "sourceType": "example-value",
              "status": "example-value",
              "warning": "example-value"
            }
          ]
        }
      ],
      "area": "example-value",
      "description": "example-value",
      "name": "example-value",
      "parent": {
        "id": "example-value",
        "name": "example-value",
        "resourceType": "example-value"
      },
      "resourceId": "example-value",
      "resourceType": "example-value",
      "status": "example-value",
      "warning": "example-value"
    },
    "subject": {
      "detail": "example-value",
      "id": "example-value",
      "name": "example-value",
      "role": "example-value",
      "status": "example-value",
      "type": "example-value"
    }
  }
}

Effects

Behaviour and other effects

Changes
Validates access and input, then applies the operation specific state change. A failed validation or authorisation check does not intentionally apply the requested change.
Audit events
authorization.access.checked
Background work
No background work is inferred. The success response represents completion of the HTTP action.
External effects
No external call is inferred from the route name. Operation specific service behaviour remains authoritative.
Transaction boundary
The HTTP success or error describes the synchronous boundary. Background operations have their own observable lifecycle and may outlive the request.

Operation

Reliability

Idempotent
No
Retry
Do not retry automatically after a timeout or lost response. Read current state first.
Concurrency
Use documented If Match or resource revision fields where exposed. Otherwise read current state before changing it and handle HTTP 409 conflicts.
Consistency
The response reflects the synchronous operation boundary. Background and provider backed state can converge later and must be read through its status operation.
Timeout
Client timeouts do not cancel completed or already started server work unless the operation explicitly supports cancellation.
Request ID
Send or record x request id and retain the returned value for diagnosis.

Errors and corrections

StatusCodeCauseCorrectionRetryablePartial work
400ACCESS_ACTION_UNSUPPORTEDChoose an action available for this resource type.Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help.No unchanged retryNo requested mutation is expected before this failure boundary.
400ACCESS_RESOURCE_REQUIREDChoose a resource to check.Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help.No unchanged retryNo requested mutation is expected before this failure boundary.
400ACCESS_RESOURCE_TYPE_UNSUPPORTEDChoose a resource type from the permission catalogue.Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help.No unchanged retryNo requested mutation is expected before this failure boundary.
400INVALID_REQUEST_BODYThe request body or supplied field values are invalid.Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help.No unchanged retryNo requested mutation is expected before this failure boundary.
401AUTHENTICATION_REQUIREDA valid authenticated session or supported token is required.Authenticate again using a supported mechanism and confirm that the credential is current.No unchanged retryNo requested mutation is expected before this failure boundary.
403PERMISSION_REQUIREDThe authenticated actor does not have the exact permission or resource action.Select the correct tenant and resource, then ask an authorised administrator to grant the exact documented action if appropriate.No unchanged retryNo requested mutation is expected before this failure boundary.
404ACCESS_RESOURCE_NOT_AVAILABLEThat resource is unavailable or outside your access management scope.Obtain the identifier from the related list or create operation and confirm the selected tenant.No unchanged retryNo requested mutation is expected before this failure boundary.
409STATE_CONFLICTCurrent resource state or a dependency prevents the requested change.Read current state, resolve the named dependency or lifecycle conflict, and submit a deliberate new request.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
423LICENCE_REMEDIATION_REQUIREDThe installation is restricted and permits only licence remediation actions.Complete the indicated licence or membership remediation before retrying Product work.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
500INTERNAL_ERRORPūnaha could not complete the operation because of an unexpected internal failure.Retain x request id and the stable error code, avoid blind retries, and investigate the operation or contact support. Code: INTERNAL_ERROR.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
503DEPENDENCY_UNAVAILABLEA required node, database, provider, or service is temporarily unavailable.Retain x request id, check health and the named dependency, then retry with bounded backoff when safe.Yes, with the documented safeguardsThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.

Code examples

Use a supported credential and synthetic data. Do not disable TLS checks or retry a request that changes state blindly.

cURL example
curl --request POST "$PUNAHA_URL/api/authorization/check-access" \
  --header "Authorization: Bearer $PUNAHA_TOKEN" \
  --header "x-request-id: example-request-001" \
  --header "Content-Type: application/json" \
  --data '{"action":"example-value","permission":"example-value","resourceId":"example-value","resourceType":"example-value","subjectId":"example-value","subjectType":"example-value"}'

Version history

  • Next Product release: Operation documented from the current registered Go route and handler contract.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot