read scope for discovery and reports, and write scope for mutations.
Endpoints
Configuration schemas
Theconfig object is validated against checkType; unknown configuration keys are rejected. Arrays are limited to 200 items, with each item at most 200 characters. Terms must have at least two characters. Regex patterns are validated for syntax and unsafe repetition.
Each non-custom check type can exist once per agent, even when disabled. Up to 10 custom policies can exist per agent.
Channel scope
sources accepts unique channel names: ui, widget, standalone, testsuite, replay, api, intercom, zendesk, salesforce, gorgias, front, hubspot, livechat, slack, discord, freshdesk, freshchat, deskpro, microsoft365, and email. Accepted source identifiers do not guarantee that every delivery path is enabled in your workspace.
An omitted or empty array on creation means all channels; responses represent that scope as null. On update, omit sources to preserve it or send an empty array to clear the restriction. Standalone maps to widget for matching. Dashboard, Test Suite, and replay evaluation bypass channel filtering.
Shared response and error behavior
Policy responses includeid, companyId, botId, checkType, config, enabled, sources, createdAt, and updatedAt. List endpoints return arrays directly. Run responses redact originalContent and rewriteReason to null for workspace API callers.
Invalid configuration or query values return 400. A missing agent or policy in the authenticated workspace returns 404. Creating a duplicate non-custom type returns 409. Exceeding the custom-policy limit returns 400.
