Skip to main content
PATCH
Update a control rule

Authorizations

Authorization
string
header
required

Management API authentication. Pass an op-mak-… management token as a Bearer token. Runtime op-… API keys are rejected with 403 — they belong on the data-plane endpoints. Mint a management key from the platform UI under Settings → API keys.

Path Parameters

uuid
string<uuid>
required

Rule id

Body

application/json
config
comply.budget · object

Config for the rule kind. Replaces the full config on update. Read existing rules and get_rule_vocabulary before changing it; organization constraints remain in force. Use schema_version=2 for provider company allowlists. Opper retention_days and upstream handling.max_retention_days are separate controls.

confirm_file_deletion
boolean

Explicit acknowledgement after a 409 warning: enabling zero-day retention or ZDR permanently deletes existing files in scope. Never set speculatively.

enabled
boolean

Whether the rule is enforced. Omitted on create means false.

name
string | null

Display name; null clears it.

schema_version
integer

Config schema version. Omit on create for version 1. Version 2 comply allowlists identify providers by company slug.

Required range: 1 <= x <= 2

Response

Successful response

data
object
meta
object

Empty for a single resource. Endpoint-specific context appears here rather than as a sibling of data.

Last modified on September 17, 2026