Update AI policies
PUT/ai/policies
Replaces the tenant's AI governance policy bundle. Supply the complete desired policy state for action_policies and policy_settings. Missing keys revert to platform defaults. Changes are audit-logged and take effect immediately for subsequent copilot queries.
Request
Request body
Content type application/json (required).
| Field | Type | Required | Description |
|---|---|---|---|
action_policies | array of object | No | Per-action permission rules that govern what the AI Copilot is allowed to do. |
action_policies[].action | string | Yes | The AI action identifier (e.g. "send_email", "read_crm_data"). |
action_policies[].allowed | boolean | Yes | Whether the action is permitted. |
action_policies[].requires_approval | boolean | No | When true, the action is queued for human approval before execution. Default: |
policy_settings | object | No | Key-value configuration parameters for AI content safety and behaviour. |
Example
{
"action_policies": [
{
"action": "send_email",
"allowed": false,
"requires_approval": true
},
{
"action": "read_crm_data",
"allowed": true,
"requires_approval": false
}
],
"policy_settings": {
"content_filter_level": "strict",
"max_response_tokens": 1024,
"allow_external_urls": false,
"pii_redaction": true
}
}
Responses
200 AI policy bundle updated
Content type application/json, object · AiPolicyBundleV1.
| Field | Type | Required | Description |
|---|---|---|---|
action_policies | array of object | No | Per-action permission rules that govern what the AI Copilot is allowed to do. |
action_policies[].action | string | Yes | The AI action identifier (e.g. "send_email", "read_crm_data"). |
action_policies[].allowed | boolean | Yes | Whether the action is permitted. |
action_policies[].requires_approval | boolean | No | When true, the action is queued for human approval before execution. Default: |
policy_settings | object | No | Key-value configuration parameters for AI content safety and behaviour. |
422 Validation failed — check action names or policy_settings keys
Example request
curl -X PUT "https://{tenant}.faciotech.net/api/v1/ai/policies" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"action_policies": [{"action": "send_email", "allowed": false, "requires_approval": true}, {"action": "read_crm_data", "allowed": true, "requires_approval": false}], "policy_settings": {"content_filter_level": "strict", "max_response_tokens": 1024, "allow_external_urls": false, "pii_redaction": true}}'