> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Returns the policy in force for this reviewer's tenant.

> A tenant with no published policy is under Esectra's strict default, and
the route says so rather than answering `404`: there is always a policy,
and "none published" is a fact about the tenant, not a missing resource.

# Errors

Returns `401` without a session, `403` for an API key - which acts for a
tenant rather than a person - and `503` when the policy store cannot be
read. The `503` names what is still true: sessions keep being evaluated,
under the strict default, until the store answers again.



## OpenAPI

````yaml /openapi.json get /v1/control/policy
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/policy:
    get:
      tags:
        - Control
      summary: Returns the policy in force for this reviewer's tenant.
      description: |-
        A tenant with no published policy is under Esectra's strict default, and
        the route says so rather than answering `404`: there is always a policy,
        and "none published" is a fact about the tenant, not a missing resource.

        # Errors

        Returns `401` without a session, `403` for an API key - which acts for a
        tenant rather than a person - and `503` when the policy store cannot be
        read. The `503` names what is still true: sessions keep being evaluated,
        under the strict default, until the store answers again.
      operationId: effective_policy_handler
      responses:
        '200':
          description: 'The effective policy: the tenant''s own, or Esectra''s default'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EffectivePolicyBody'
        '401':
          description: No usable credentials
        '403':
          description: An API key, which acts for a tenant rather than a person
        '503':
          description: The policy store could not be read
      security:
        - session_cookie: []
components:
  schemas:
    EffectivePolicyBody:
      type: object
      description: The effective policy, as a reviewer may read it.
      required:
        - version
        - source
        - status
        - applies_to
        - checks
        - outcomes
        - customization
      properties:
        applies_to:
          type: string
          description: What the policy governs.
        checks:
          type: array
          items:
            $ref: '#/components/schemas/RequiredCheckBody'
          description: >-
            The checks a verification session must satisfy, in the order they
            are

            evaluated.
        customization:
          type: string
          description: Who may change the policy. `ESECTRA_MANAGED` during the pilot.
        effective_from:
          type:
            - string
            - 'null'
          description: |-
            When this version was published. Absent for the default, which has
            been in force since the deployment existed.
        outcomes:
          $ref: '#/components/schemas/OutcomesBody'
          description: What each outcome leads to.
        source:
          $ref: '#/components/schemas/PolicySource'
          description: Whether this is the tenant's own policy or Esectra's default.
        status:
          type: string
          description: 'Always `ACTIVE`: the policy this route returns is the one in force.'
        version:
          type: string
          description: The version decisions cite.
    RequiredCheckBody:
      type: object
      description: One check the policy requires.
      required:
        - check
        - required
      properties:
        check:
          type: string
          description: >-
            The check, as `CheckKind` codes it: `FACE_MATCH`, `LIVENESS`, and so
            on.
        required:
          type: boolean
          description: >-
            Always true here. Present so the shape can later carry optional
            checks

            without every client reading absence as "not required".
    OutcomesBody:
      type: object
      description: What each outcome of a session leads to.
      required:
        - pass
        - review
        - fail
        - review_queue
        - case_opened_for
        - missing_reference
      properties:
        case_opened_for:
          type: array
          items:
            type: string
          description: The statuses that open a review case for a person.
        fail:
          type: string
          description: 'The decision when a required check failed: `BLOCK`.'
        missing_reference:
          type: string
          description: |-
            What happens when a face match is required and nothing is on file to
            compare against: `REVIEW` or `FAIL`. Never a pass.
        pass:
          type: string
          description: 'The decision when every required check is satisfied: `ALLOW`.'
        review:
          type: string
          description: >-
            The decision when a check could not be resolved, or an optional
            check

            objected: `REVIEW_REQUIRED`, and a person looks at it.
        review_queue:
          type: string
          description: The queue a review case is opened in.
    PolicySource:
      type: string
      description: Where the effective policy came from.
      enum:
        - ESECTRA_DEFAULT
        - ORGANIZATION
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````