Skip to main content
GET
Describe a Ruleset

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

ruleset
string
required

Policy Ruleset ID

Query Parameters

include
enum<string>[]
Available options:
ruleset-users,
ruleset-users-count,
ruleset-users-exists,
manifest-users,
manifest-users-count,
manifest-users-exists,
qualified-users,
qualified-users-count,
qualified-users-exists
filter
string

Response

PolicyRulesetDetailedResponseData

id
string
required
Example:

"poset_01hq8xyzabc123def456ghi789"

state
enum<string>
required

The state of the policy ruleset and whether the group or resource is being managed

Available options:
unmanaged,
monitored,
managed,
deactivated
resource_type
enum<string>
required

The type of resource that this policy ruleset applies to

Available options:
directory_attribute,
google_workspace_group,
okta_group
Example:

"directory_attribute"

resource_id
string
required

The ID of the resource that this policy ruleset applies to

Examples:

"dratr_01hq8xyzabc123def456ghi789"

"glgrp_01hq8xyzabc123def456ghi789"

"glprj_01hq8xyzabc123def456ghi789"

"gddoc_01hq8xyzabc123def456ghi789"

"gdfil_01hq8xyzabc123def456ghi789"

"gdfol_01hq8xyzabc123def456ghi789"

"gddck_01hq8xyzabc123def456ghi789"

"gdsht_01hq8xyzabc123def456ghi789"

"gigrp_01hq8xyzabc123def456ghi789"

"gwdrv_01hq8xyzabc123def456ghi789"

"gwgrp_01hq8xyzabc123def456ghi789"

"okgrp_01hq8xyzabc123def456ghi789"

"slgrp_01hq8xyzabc123def456ghi789"

"slprv_01hq8xyzabc123def456ghi789"

"slpub_01hq8xyzabc123def456ghi789"

resource_parent
string
required

The parent name of the resource that this policy ruleset applies to

Example:

"Department"

resource_name
string
required

The name of the resource that this policy ruleset applies to

Example:

"Engineering"

resource_handle
string
required

The handle of the resource that this policy ruleset applies to

Example:

"eng"

is_authoritative
boolean
required

Whether this ruleset is authoritative for managing users on the resource. If true, only users that match a Provisionr policy rule will remain a member of the group or resource, and unmanaged users will be removed during each sync. If false, users added outside of Provisionr will not be removed

Example:

false

expires_after_days
integer
required

This shows the value for the parent attribute or resource.

Users will be automatically deprecated if they no longer qualify for at least one rule in the ruleset.

The expires_after_days value determines how many days after they no longer qualify that they still have access for a graceful transition period when users change job roles.

The value is inherited from the Workspace > Dimension > Ruleset > Rule and can be overridden at any level to provide shorter revoke time controls when needed.

If the value is 0, this skips the grace period and revokes access immediately after expires_at

Example:

30

count
object
required

Counts of related resources

included
object
required

Included related resources

API hyperlinks related to the policy ruleset record