> ## Documentation Index
> Fetch the complete documentation index at: https://docs.abliteration.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage policies

> Create policy drafts, publish immutable versions, and inspect the policies applied to a project.

The Administration API uses the same policies as the Abliteration Console.
Create or edit a draft, then publish it when the change is ready to affect
inference requests.

## Policy lifecycle

1. Create a draft with `POST /v1/organization/policies`.
2. Edit selected draft fields with `PATCH /v1/organization/policies/{policy_id}`.
3. Publish the draft with `POST /v1/organization/policies/{policy_id}/publish`.
4. Pause or resume the published version without creating another version.

Every policy response includes a `revision`. Send the latest revision with an
update or lifecycle action. If another caller changes the policy first, the API
returns `409 policy_revision_conflict` instead of overwriting that change.

## Create a draft

Policy rules are yes-or-no questions ending in a question mark.

```bash theme={"system"}
curl https://api.abliteration.ai/v1/organization/policies \
  -X POST \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: policy-create-20260930-01" \
  -d '{
    "name": "Protect credentials",
    "description": "",
    "rule": "Does the response reveal a reusable authentication credential?",
    "direction": "response",
    "mode": "monitoring",
    "scope": "projects",
    "project_ids": ["proj_example"],
    "match_threshold_basis_points": 9000
  }'
```

`direction` is `request`, `response`, or `both`. `mode` is `monitoring` or
`enforcing`. `scope` is one of:

| Scope | Behavior |
| - | - |
| `organization` | Applies automatically to every project in the organization |
| `projects` | Applies automatically to the projects in `project_ids` |
| `unattached` | Runs only when an inference request selects the policy by ID |

`match_threshold_basis_points` is optional. For example, `9000` means 90
percent. Omit it to use the platform default.

## Edit the draft

`PATCH` changes only the fields you include. It does not change the published
version. Set `match_threshold_basis_points` to `null` to return to the platform
default.

```bash theme={"system"}
curl https://api.abliteration.ai/v1/organization/policies/pol_example \
  -X PATCH \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "revision": 1,
    "mode": "enforcing",
    "match_threshold_basis_points": null
  }'
```

When changing a policy to `scope: "projects"`, include at least one project ID.
Changing it to `organization` or `unattached` clears its project selection.

## Publish the draft

Publishing creates the next immutable version and makes it the current
published version.

```bash theme={"system"}
curl https://api.abliteration.ai/v1/organization/policies/pol_example/publish \
  -X POST \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{"revision":2}'
```

Editing a published policy creates unpublished draft changes. Inference keeps
using the current published version until you publish again.

## Pause or resume a policy

Pausing stops the policy from applying automatically. Resuming restores the
same published version and mode.

```bash theme={"system"}
curl https://api.abliteration.ai/v1/organization/policies/pol_example/pause \
  -X POST \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{"revision":3}'
```

Use the corresponding `/resume` path and the latest revision to resume it.
Pausing a draft or resuming an active policy returns
`409 policy_state_conflict`.

## Read versions and effective policies

```bash theme={"system"}
# List published versions
curl "https://api.abliteration.ai/v1/organization/policies/pol_example/versions?limit=20" \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY"

# Retrieve version 1
curl https://api.abliteration.ai/v1/organization/policies/pol_example/versions/1 \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY"

# List active policies applied automatically to a project
curl https://api.abliteration.ai/v1/organization/projects/proj_example/effective_policies \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY"
```

The effective-policy response excludes paused, draft-only, and `unattached`
policies. See [Policies in API requests](/api/policy-endpoints) to select an
`unattached` policy for one inference request.

## Delete a policy

Deletion requires the latest revision and removes the policy from list,
retrieve, and runtime resolution operations.

```bash theme={"system"}
curl "https://api.abliteration.ai/v1/organization/policies/pol_example?revision=4" \
  -X DELETE \
  -H "Authorization: Bearer $ABLITERATION_ADMIN_KEY"
```
