Returns the policy in force for this reviewer's tenant.
A tenant with no published policy is under Esectra’s strict default, and
the route says so rather than answering 404: there is always a policy,
and “none published” is a fact about the tenant, not a missing resource.
Errors
Returns 401 without a session, 403 for an API key - which acts for a
tenant rather than a person - and 503 when the policy store cannot be
read. The 503 names what is still true: sessions keep being evaluated,
under the strict default, until the store answers again.
Authorizations
A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.
Response
The effective policy: the tenant's own, or Esectra's default
The effective policy, as a reviewer may read it.
What the policy governs.
The checks a verification session must satisfy, in the order they are evaluated.
Who may change the policy. ESECTRA_MANAGED during the pilot.
What each outcome leads to.
Whether this is the tenant's own policy or Esectra's default.
ESECTRA_DEFAULT, ORGANIZATION Always ACTIVE: the policy this route returns is the one in force.
The version decisions cite.
When this version was published. Absent for the default, which has been in force since the deployment existed.

