Get generic request approval config
GET/generic-request-approval-config/v1
This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.
Returns the approval configuration document for one scope.
Scope rules for Phase II agent requests:
| targetType | Allowed actions | targetId | sourceId |
|---|---|---|---|
| RESOURCE | ACTIVATE, DEACTIVATE | Required. Connector resource id, not the std:* type. Resolved resource type must be std:agent. | Required |
| GLOBAL | ACTIVATE, DEACTIVATE | Derived (tenant id). Omit. | Must be omitted |
DELETE_AT_SOURCE is not returned and cannot be configured on this API.
A scope that has never been saved still returns 200. Every allowed action is
present. Unset actions are {} (no config at this scope; submit uses RESOURCE, then GLOBAL,
then org-level). The first successful GET
materializes a row so the response id can be used on PATCH.
Unknown source, missing or invalid query params, a RESOURCE targetId the source
does not advertise, or a resource whose type is not std:agent return 400.
Product not licensed returns 404. Flag off, missing experimental header, or
insufficient rights return 403.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 429
- 500
Approval configuration document for the requested scope.
Client Error - Returned if the request body is invalid.
Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.
Forbidden - Returned if the user you are running as, doesn't have access to this end-point.
Not Found - returned if the request URL refers to a resource or object that does not exist
Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.
Internal Server Error - Returned if there is an unexpected error.