Create an assignment
Binds a definition to an actor and optionally provides parameter values for that actor.
The scopeType determines which actor field is required:
| Scope type | Required field | Persisted RLS behavior |
|---|---|---|
ALL_TENANTS | (none) | Activates the policy for all tenant actors and may supply broad values |
TENANT | tenantId | Activates the policy for one tenant and may supply tenant-specific values |
TENANT_USER | tenantUserId | Activates the policy for one tenant user and may supply user-specific values |
ORG_USER | orgUserId | Activates the policy directly for one organization user |
You cannot assign the same definition to the same actor twice.
Authorization
UnifiedSecurityBearerAuth A project-scoped access token generated for an organization Admin.
Generate one with the Token API using
the Admin's orgUserId. The token project must match the request path,
and the user must currently be active and belong to the project
organization. Dashboard tokens and tenant-user project tokens are not
accepted.
In: header
Path Parameters
Your Semaphor project ID.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X post "https://semaphor.cloud/api/management/v1/projects/string/unified-security/assignments" \ -H "Content-Type: application/json" \ -d '{ "definitionId": "usd_123", "scopeType": "TENANT", "tenantId": "tenant_123", "params": { "region": "us" } }'{
"ok": true,
"data": {
"assignment": {
"id": "string",
"definitionId": "string",
"scopeType": "ALL_TENANTS",
"orgUserId": "string",
"tenantId": "string",
"tenantUserId": "string",
"params": {
"property1": "string",
"property2": "string"
},
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
},
"diagnostics": [
{
"code": "RLS_CONFIG_SHAPE_INVALID",
"severity": "ERROR",
"title": "string",
"message": "string",
"location": {
"resourceType": "DEFINITION",
"resourceId": "string",
"resourceName": "string",
"subjectType": "RULE",
"fieldPath": "string",
"parameterName": "string"
},
"remediations": [
{
"code": "REAUTHOR_LEGACY_RLS",
"label": "string",
"target": {
"resourceType": "DEFINITION",
"resourceId": "string"
}
}
],
"requiresUserDecision": true,
"retryable": true
}
],
"impact": {
"type": "ALL_TENANTS_BASELINE_CHANGE",
"allOtherTenantActorsRemainActive": true,
"parameters": [
{
"parameterName": "string",
"oldValue": {
"state": "OMITTED"
},
"newValue": {
"state": "OMITTED"
},
"tenantOverrideAssignmentCount": 0,
"tenantUserOverrideAssignmentCount": 0
}
]
}
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"requestId": "string",
"issues": [
{
"code": "INVALID_JSON",
"fieldPath": "string",
"message": "string"
}
],
"retryable": true
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"details": {}
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"details": {}
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"requestId": "string",
"issues": [
{
"code": "INVALID_JSON",
"fieldPath": "string",
"message": "string"
}
],
"retryable": true
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"requestId": "string",
"issues": [
{
"code": "INVALID_JSON",
"fieldPath": "string",
"message": "string"
}
],
"retryable": true
}
}{
"ok": false,
"error": {
"code": "RLS_CONFIGURATION_INVALID",
"message": "string",
"diagnostics": [
{
"code": "RLS_CONFIG_SHAPE_INVALID",
"severity": "ERROR",
"title": "string",
"message": "string",
"location": {
"resourceType": "DEFINITION",
"resourceId": "string",
"resourceName": "string",
"subjectType": "RULE",
"fieldPath": "string",
"parameterName": "string"
},
"remediations": [
{
"code": "REAUTHOR_LEGACY_RLS",
"label": "string",
"target": {
"resourceType": "DEFINITION",
"resourceId": "string"
}
}
],
"requiresUserDecision": true,
"retryable": true
}
],
"requestId": "string"
}
}{
"ok": false,
"error": {
"code": "INVALID_REQUEST",
"message": "string",
"requestId": "string",
"issues": [
{
"code": "INVALID_JSON",
"fieldPath": "string",
"message": "string"
}
],
"retryable": true
}
}