> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Compile policy

> Checks the document against the workspace's catalogs. A document with errors still compiles as far as it can. Nothing is saved.



## OpenAPI

````yaml /openapi-public.json post /policies/compile
openapi: 3.1.1
info:
  title: Klef API
  description: Klef's multi-tenant HRIS sync platform API.
  version: v1
servers:
  - url: https://{workspace}.klef.ai/api
    variables:
      workspace:
        default: acme
        description: Your workspace's subdomain.
security: []
tags:
  - name: Users
  - name: Connections
  - name: Adoption
  - name: Policy resources
  - name: Audit
  - name: Catalog
  - name: Sync
  - name: Search
  - name: SyncPlans
  - name: Agent
  - name: Auth
  - name: Workspaces
  - name: Billing
  - name: Invitations
  - name: FirstSignIns
  - name: Connection accounts
  - name: Policies
  - name: Secrets
  - name: Lookup tables
  - name: Scripts
  - name: Segments
  - name: ApiKeys
  - name: Members
  - name: Workers
  - name: Inbox
  - name: Notifications
paths:
  /policies/compile:
    post:
      tags:
        - Policies
      summary: Compile policy
      description: >-
        Checks the document against the workspace's catalogs. A document with
        errors still compiles as far as it can. Nothing is saved.
      operationId: CompilePolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CompilePolicyRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponseOfCompilePolicyResponse'
        '400':
          description: Validation or business-rule error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
      security:
        - cookieAuth: []
        - apiKeyAuth: []
components:
  schemas:
    CompilePolicyRequest:
      required:
        - source
      type: object
      properties:
        source:
          minLength: 1
          type: string
        policyId:
          type:
            - 'null'
            - string
          format: uuid
      description: "PolicyId names the policy the document would be saved over, so the answer\r\ncan say what the save changes; leave it out for a document that is not saved anywhere."
    ApiResponseOfCompilePolicyResponse:
      required:
        - result
        - errors
      type: object
      properties:
        result:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/CompilePolicyResponse'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ApiError'
      description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
    CompilePolicyResponse:
      required:
        - succeeded
        - diagnostics
        - policy
        - formatted
        - edits
      type: object
      properties:
        succeeded:
          type: boolean
        diagnostics:
          type: array
          items:
            $ref: '#/components/schemas/PolicyDiagnosticResponse'
        policy:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/CompiledPolicyResponse'
        formatted:
          type:
            - 'null'
            - string
        edits:
          $ref: '#/components/schemas/PolicyEditsResponse'
      description: "What the document means. Policy is `null` when the\r\ndocument could not be understood well enough to describe one."
    ApiError:
      required:
        - errorCode
        - errorMessage
      type: object
      properties:
        errorCode:
          $ref: '#/components/schemas/ApiErrorCode'
        errorMessage:
          type: string
        target:
          type:
            - 'null'
            - string
      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
    PolicyDiagnosticResponse:
      required:
        - code
        - severity
        - message
        - start
        - end
        - candidates
        - unresolved
      type: object
      properties:
        code:
          type: string
        severity:
          $ref: '#/components/schemas/PolicyDiagnosticSeverity'
        message:
          type: string
        start:
          type: integer
          format: int32
        end:
          type: integer
          format: int32
        candidates:
          type: array
          items:
            type: string
        unresolved:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/PolicyReferenceKind'
      description: "One problem found in the document. Start and End are\r\nUTF-16 offsets into the source the caller posted, and Candidates holds what\r\ncould have been written instead, so an editor can offer one as a fix. Unresolved\r\nis the kind of resource the document names and the workspace does not hold, when that is the\r\nproblem."
    CompiledPolicyResponse:
      required:
        - name
        - category
        - segmentId
        - states
      type: object
      properties:
        name:
          type: string
        category:
          type: string
        segmentId:
          type:
            - 'null'
            - string
        states:
          type: array
          items:
            $ref: '#/components/schemas/CompiledState'
      description: A compiled policy in the shape the policy save takes.
    PolicyEditsResponse:
      required:
        - values
        - entries
        - blocks
      type: object
      properties:
        values:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/PolicySpanResponse'
          description: The span a replacement value is written over, keyed by path.
        entries:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/PolicySpanResponse'
          description: "The span removing an entry cuts out, keyed by the same path as its value, plus one per target\r\nunder `target|stage|system|object`."
        blocks:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/PolicyInsertionResponse'
          description: Where a new entry goes, keyed by the path prefix a block shares.
      description: "Where every editable part of the document sits, so an editor changes text in place and leaves\r\nthe author's comments and spacing alone."
    ApiErrorCode:
      enum:
        - validation_error
        - unauthorized
        - forbidden
        - not_found
        - internal_error
        - error
        - precondition_required
        - precondition_failed
        - invalid_if_match
        - worker_not_found
        - worker_version_not_found
        - connection_not_found
        - policy_not_found
        - policy_revision_not_found
        - lookup_table_not_found
        - script_not_found
        - segment_not_found
        - workspace_secret_not_found
        - member_not_found
        - invitation_not_found
        - user_not_found
        - workspace_not_found
        - api_key_not_found
        - inbox_item_not_found
        - sync_plan_not_found
        - connection_account_not_found
        - managed_account_not_found
        - adoption_run_not_found
        - sync_plan_not_ready
        - sync_plan_stale
        - sync_plan_already_applying
        - subdomain_taken
        - invalid_subdomain
        - invalid_invite
        - last_owner_protected
        - owner_protected
        - already_member
        - already_invited
        - role_not_assignable
        - invalid_email
        - email_required
        - email_mismatch
        - invitation_gone
        - invalid_connector_credentials
        - wrong_connector_type
        - connection_not_syncable
        - connector_o_auth_not_configured
        - connector_authorization_failed
        - salesforce_manage_users_required
        - box_admin_required
        - linear_admin_required
        - dropbox_admin_required
        - invalid_match_rule
        - adoption_run_composed
        - adoption_run_empty
        - adoption_selection_refused
        - invalid_policy
        - policy_does_not_compile
        - policy_secret_missing
        - policy_lookup_table_missing
        - policy_script_missing
        - policy_segment_missing
        - policy_edit_target_missing
        - policy_secret_disclosure_forbidden
        - notification_send_failed
        - invalid_workspace_secret
        - workspace_secret_referenced
        - workspace_secret_name_conflict
        - invalid_lookup_table
        - lookup_table_referenced
        - lookup_table_name_conflict
        - invalid_script
        - script_name_conflict
        - script_referenced
        - invalid_segment
        - segment_name_conflict
        - segment_referenced
        - segment_worker_missing
        - api_key_scope_not_granted
        - api_key_limit_reached
        - subscription_required
        - already_subscribed
        - no_billing_customer
        - workspace_pending_deletion
        - workspace_deletion_confirmation_mismatch
        - workspace_deletion_already_scheduled
        - workspace_deletion_not_scheduled
        - workspace_export_expired
        - workspace_export_not_found
        - agent_conversation_not_found
        - agent_proposal_not_found
        - agent_proposal_outdated
        - agent_proposal_expired
        - agent_proposal_already_applied
        - agent_proposal_rejected
        - notification_kind_unsupported
        - first_sign_in_not_found
        - first_sign_in_gone
        - first_sign_in_not_a_recipient
        - first_sign_in_recipient_unknown
        - first_sign_in_locked
        - first_sign_in_code_refused
        - first_sign_in_proof_invalid
        - password_reset_unsupported
        - invalid_password_rules
        - avatar_not_owned
        - unsupported_image_type
        - image_too_large
      description: The central catalog of every error returned by the API.
    PolicyDiagnosticSeverity:
      enum:
        - error
        - warning
        - info
      description: How much a diagnostic matters.
    PolicyReferenceKind:
      enum:
        - segment
        - lookup
        - script
        - secret
      description: The kinds of workspace resource a document reaches by identifier.
    CompiledState:
      required:
        - stage
        - targets
        - notifications
      type: object
      properties:
        stage:
          $ref: '#/components/schemas/PolicyStage'
        targets:
          type: array
          items:
            $ref: '#/components/schemas/CompiledTarget'
        notifications:
          type: array
          items:
            $ref: '#/components/schemas/CompiledNotification'
    PolicySpanResponse:
      required:
        - start
        - end
      type: object
      properties:
        start:
          type: integer
          format: int32
        end:
          type: integer
          format: int32
      description: A range of the source the caller posted, in UTF-16 offsets.
    PolicyInsertionResponse:
      required:
        - offset
        - prefix
        - suffix
      type: object
      properties:
        offset:
          type: integer
          format: int32
        prefix:
          type: string
        suffix:
          type: string
      description: "Where a new entry belongs in a block. The caller splices Prefix + its text +\r\nSuffix in at Offset."
    PolicyStage:
      enum:
        - pre_start
        - active
        - leave
        - suspended
        - departing
        - terminated
        - released
      description: "A stage a policy authors a block for: one of the worker's lifecycle stages, or\r\nPolicyStage.Released, which is relative to the policy rather than to the worker."
    CompiledTarget:
      required:
        - system
        - objectType
        - maps
      type: object
      properties:
        system:
          $ref: '#/components/schemas/ConnectorExternalSystem'
        objectType:
          type: string
        maps:
          type: object
          additionalProperties:
            oneOf:
              - type: 'null'
              - $ref: '#/components/schemas/CompiledMapping'
    CompiledNotification:
      required:
        - name
        - send
        - content
      type: object
      properties:
        name:
          type: string
          description: >-
            The notification's identifier, unique across the workspace's
            policies.
        send:
          $ref: '#/components/schemas/NotificationSend'
        content:
          $ref: '#/components/schemas/CompiledContent'
    ConnectorExternalSystem:
      enum:
        - adp_workforce_now
        - oracle_fusion
        - microsoft_entra
        - gusto
        - microsoft365
        - google_workspace
        - oracle_oci
        - worker_model
        - aws
        - azure
        - aws_identity_center
        - bamboo_hr
        - slack
        - github
        - github_enterprise
        - salesforce
        - hubspot
        - box
        - linear
        - dropbox
        - openai
        - anthropic
        - one_password
        - keeper
        - bitwarden
        - atlassian
        - notion
      description: An external system a workspace can connect to.
    CompiledMapping:
      required:
        - kind
      type: object
      anyOf:
        - $ref: '#/components/schemas/CompiledMappingCompiledDirect'
        - $ref: '#/components/schemas/CompiledMappingCompiledFrom'
        - $ref: '#/components/schemas/CompiledMappingCompiledConstant'
        - $ref: '#/components/schemas/CompiledMappingCompiledPreset'
        - $ref: '#/components/schemas/CompiledMappingCompiledLookup'
        - $ref: '#/components/schemas/CompiledMappingCompiledScript'
        - $ref: '#/components/schemas/CompiledMappingCompiledList'
      description: "How one target field gets its value. An unmanaged field is not one of these: the language spells\r\nit `unmanaged` and the compiler carries it as `null`, because the engine\r\ndecides managed, cleared and unmanaged by whether a key is present in the payload at all."
      discriminator:
        propertyName: kind
        mapping:
          direct:
            $ref: '#/components/schemas/CompiledMappingCompiledDirect'
          from:
            $ref: '#/components/schemas/CompiledMappingCompiledFrom'
          constant:
            $ref: '#/components/schemas/CompiledMappingCompiledConstant'
          preset:
            $ref: '#/components/schemas/CompiledMappingCompiledPreset'
          lookup:
            $ref: '#/components/schemas/CompiledMappingCompiledLookup'
          script:
            $ref: '#/components/schemas/CompiledMappingCompiledScript'
          list:
            $ref: '#/components/schemas/CompiledMappingCompiledList'
    NotificationSend:
      enum:
        - once
        - always
      description: How often a notification fires for a worker.
    CompiledContent:
      required:
        - kind
      type: object
      anyOf:
        - $ref: '#/components/schemas/CompiledContentCompiledEmail'
        - $ref: '#/components/schemas/CompiledContentCompiledSlack'
        - $ref: '#/components/schemas/CompiledContentCompiledHttp'
        - $ref: '#/components/schemas/CompiledContentCompiledTeams'
      discriminator:
        propertyName: kind
        mapping:
          email:
            $ref: '#/components/schemas/CompiledContentCompiledEmail'
          slack:
            $ref: '#/components/schemas/CompiledContentCompiledSlack'
          http:
            $ref: '#/components/schemas/CompiledContentCompiledHttp'
          teams:
            $ref: '#/components/schemas/CompiledContentCompiledTeams'
    CompiledMappingCompiledDirect:
      required:
        - head
        - sourceKey
      properties:
        kind:
          enum:
            - direct
          type: string
        head:
          type: string
        sourceKey:
          type: string
    CompiledMappingCompiledFrom:
      required:
        - system
        - sourceKey
      properties:
        kind:
          enum:
            - from
          type: string
        system:
          $ref: '#/components/schemas/ConnectorExternalSystem'
        sourceKey:
          type: string
    CompiledMappingCompiledConstant:
      required:
        - value
      properties:
        kind:
          enum:
            - constant
          type: string
        value:
          type: string
    CompiledMappingCompiledPreset:
      required:
        - values
      properties:
        kind:
          enum:
            - preset
          type: string
        values:
          type: array
          items:
            type: string
    CompiledMappingCompiledLookup:
      required:
        - head
        - sourceKey
        - tableId
      properties:
        kind:
          enum:
            - lookup
          type: string
        head:
          type: string
        sourceKey:
          type: string
        tableId:
          type:
            - 'null'
            - string
    CompiledMappingCompiledScript:
      required:
        - scriptId
      properties:
        kind:
          enum:
            - script
          type: string
        scriptId:
          type:
            - 'null'
            - string
    CompiledMappingCompiledList:
      required:
        - entries
      properties:
        kind:
          enum:
            - list
          type: string
        entries:
          type: array
          items:
            $ref: '#/components/schemas/CompiledEntry'
      description: >-
        A list of records, mixing what the author wrote with what a
        comprehension expands.
    CompiledContentCompiledEmail:
      required:
        - subject
        - body
        - title
        - aggregation
      properties:
        kind:
          enum:
            - email
          type: string
        subject:
          type: string
        body:
          type: string
        recipients:
          type: array
          items:
            $ref: '#/components/schemas/CompiledEmailRecipient'
        title:
          type: string
        aggregation:
          $ref: '#/components/schemas/NotificationAggregation'
    CompiledContentCompiledSlack:
      required:
        - text
        - title
        - aggregation
      properties:
        kind:
          enum:
            - slack
          type: string
        text:
          type: string
        webhookSecretIds:
          type: array
          items:
            type: string
        title:
          type: string
        aggregation:
          $ref: '#/components/schemas/NotificationAggregation'
    CompiledContentCompiledHttp:
      required:
        - uri
        - title
        - aggregation
      properties:
        kind:
          enum:
            - http
          type: string
        method:
          $ref: '#/components/schemas/HttpRequestMethod'
        uri:
          type: string
        body:
          type:
            - 'null'
            - string
        headers:
          type: array
          items:
            $ref: '#/components/schemas/CompiledHeader'
        title:
          type: string
        aggregation:
          $ref: '#/components/schemas/NotificationAggregation'
    CompiledContentCompiledTeams:
      required:
        - text
        - title
        - aggregation
      properties:
        kind:
          enum:
            - teams
          type: string
        text:
          type: string
        webhookSecretIds:
          type: array
          items:
            type: string
        title:
          type: string
        aggregation:
          $ref: '#/components/schemas/NotificationAggregation'
    CompiledEntry:
      required:
        - kind
      type: object
      anyOf:
        - $ref: '#/components/schemas/CompiledEntryCompiledRecord'
        - $ref: '#/components/schemas/CompiledEntryCompiledEach'
      discriminator:
        propertyName: kind
        mapping:
          record:
            $ref: '#/components/schemas/CompiledEntryCompiledRecord'
          collection:
            $ref: '#/components/schemas/CompiledEntryCompiledEach'
    CompiledEmailRecipient:
      required:
        - recipient
        - kind
      type: object
      properties:
        recipient:
          $ref: '#/components/schemas/CompiledRecipient'
        kind:
          $ref: '#/components/schemas/EmailRecipientKind'
    NotificationAggregation:
      enum:
        - worker
        - run
      description: >-
        Whether a notification fires once per affected worker or once per sync
        run.
    HttpRequestMethod:
      enum:
        - get
        - post
        - put
        - patch
        - delete
        - null
    CompiledHeader:
      required:
        - name
        - value
      type: object
      properties:
        name:
          type: string
        value:
          type:
            - 'null'
            - string
        secretId:
          type:
            - 'null'
            - string
    CompiledEntryCompiledRecord:
      required:
        - maps
      properties:
        kind:
          enum:
            - record
          type: string
        maps:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/CompiledMapping'
    CompiledEntryCompiledEach:
      required:
        - sourceKey
        - binding
        - select
        - itemMaps
      properties:
        kind:
          enum:
            - collection
          type: string
        sourceKey:
          type: string
        binding:
          type: string
        select:
          $ref: '#/components/schemas/CompiledSelect'
        itemMaps:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/CompiledMapping'
    CompiledRecipient:
      required:
        - kind
      type: object
      anyOf:
        - $ref: '#/components/schemas/CompiledRecipientCompiledPathRecipient'
        - $ref: '#/components/schemas/CompiledRecipientCompiledManagerRecipient'
        - $ref: '#/components/schemas/CompiledRecipientCompiledMemberRecipient'
        - $ref: '#/components/schemas/CompiledRecipientCompiledStaticRecipient'
      description: >-
        Who a notification addresses, named the way the engine resolves them at
        send time.
      discriminator:
        propertyName: kind
        mapping:
          path:
            $ref: '#/components/schemas/CompiledRecipientCompiledPathRecipient'
          manager:
            $ref: '#/components/schemas/CompiledRecipientCompiledManagerRecipient'
          member:
            $ref: '#/components/schemas/CompiledRecipientCompiledMemberRecipient'
          static:
            $ref: '#/components/schemas/CompiledRecipientCompiledStaticRecipient'
    EmailRecipientKind:
      enum:
        - to
        - cc
        - bcc
      description: Which header an email recipient is addressed on.
    CompiledSelect:
      required:
        - match
        - clauses
      type: object
      properties:
        match:
          $ref: '#/components/schemas/ConditionMatch'
        clauses:
          type: array
          items:
            $ref: '#/components/schemas/CompiledClause'
      description: An empty clause list keeps every record.
    CompiledRecipientCompiledPathRecipient:
      required:
        - key
      properties:
        kind:
          enum:
            - path
          type: string
        key:
          type: string
      description: An address read from the worker model, at Key.
    CompiledRecipientCompiledManagerRecipient:
      required:
        - level
      properties:
        kind:
          enum:
            - manager
          type: string
        level:
          type: integer
          format: int32
    CompiledRecipientCompiledMemberRecipient:
      required:
        - userId
      properties:
        kind:
          enum:
            - member
          type: string
        userId:
          type: string
    CompiledRecipientCompiledStaticRecipient:
      required:
        - value
      properties:
        kind:
          enum:
            - static
          type: string
        value:
          type: string
    ConditionMatch:
      enum:
        - all
        - any
      description: How a condition node combines its clauses.
    CompiledClause:
      required:
        - left
        - operator
        - values
      type: object
      properties:
        left:
          $ref: '#/components/schemas/ConditionOperand'
        operator:
          $ref: '#/components/schemas/ConditionOperator'
        values:
          type: array
          items:
            $ref: '#/components/schemas/ConditionOperand'
    ConditionOperand:
      required:
        - kind
        - value
      type: object
      properties:
        kind:
          $ref: '#/components/schemas/ConditionOperandKind'
        value:
          type: string
      description: "One side of a condition clause. string ConditionOperand.Value is the literal text when ConditionOperandKind ConditionOperand.Kind\r\nis ConditionOperandKind.Literal, or the reference path otherwise (resolved against\r\nthe run-time context, which does not exist yet)."
    ConditionOperator:
      enum:
        - equals
        - not_equals
        - greater_than
        - less_than
        - greater_than_or_equal
        - less_than_or_equal
        - in
        - not_in
        - contains
        - starts_with
        - ends_with
      description: >-
        The comparison a condition clause applies between its left operand and
        its value(s).
    ConditionOperandKind:
      enum:
        - literal
        - worker_attribute
        - target_field
      description: >-
        What a condition operand holds: a constant, or a reference resolved at
        run time.
  securitySchemes:
    cookieAuth:
      type: apiKey
      description: >-
        Cookie-based session. Obtain by completing the `/auth/login/{provider}`
        OAuth flow; the `/auth/callback` response sets the `klef.session` cookie
        that subsequent requests send automatically.
      name: klef.session
      in: cookie
    apiKeyAuth:
      type: http
      description: >-
        An API key from **Settings > API keys**, sent as `Authorization: Bearer
        klef_sk_…`. A key works only on its own workspace's subdomain, and only
        with the permissions its scopes grant.
      scheme: bearer
      bearerFormat: klef_sk_…

````