List Actions
GET /policies/{policyId}/grids/{gridId}/actions
Returns all row-level actions the caller's role may execute on the specified grid. Actions whose requiredRoles the caller does not hold are automatically omitted, inaccessible actions are never leaked.
Authentication
Requires a valid Guardian JWT bearer token. The caller must hold at least one of:
POLICIES_POLICY_EXECUTEPOLICIES_POLICY_MANAGE
Request
Path Parameters
policyId
string
Yes
MongoDB ObjectId of the running policy
Response
Success Response
Status: 200 OK
label
string
Human-readable action label
requiredRoles
array
Policy roles that may execute this action
appliesTo
string
Always "row" — actions target individual records
inputSchema
object
JSON Schema describing the action's request body. Shape depends on the underlying block type:
inputSchema by action type:
Selector / button (e.g. Approve, Reject)
{} (empty)
inputSchema.properties is empty — no body needed
Dropdown (e.g. assigning an entity to a record)
{ "value": "<choice>" }
inputSchema.properties.value.enum lists the currently valid values, resolved live (e.g. from registered entities); .options pairs each value with a human-readable name
Request-VC-document (e.g. submitting a form that mints a new VC)
{ "document": { ... } }
inputSchema.properties.document.description names the schema IRI the submitted fields must conform to
See Execute Action for full request/response examples of each shape.
Error Responses
401 Unauthorized
JWT token missing or invalid
403 Forbidden
Insufficient permissions
404 Not Found
gridId not found in this policy
503 Service Unavailable
Policy instance not running, or grid not available to the caller's role
500 Internal Server Error
Unexpected server failure
Last updated
Was this helpful?