Skip to content

Update a business policy

Request

🔒 Private label — contact sales. Requires a private-label entitlement on your API client.

Updates rules, workflow, status, or other fields of an existing business policy. Pass status: "DISABLED" to disable the policy.

Security
oauth2ClientCredentials(Required scopes: business-policies:write)
Path
businessPolicyIdstringrequired

Business policy document ID

Example:6a3ebb7893bb2649e19cb8a6
Headers
business_idstringrequired

Business identifier for the request

Bodyapplication/jsonrequired
_idstring

Business policy MongoDB ObjectId

Example:"6a3ebb7893bb2649e19cb8a6"
statusstring

Policy status

Enum:"ACTIVE""DISABLED""INACTIVE""DELETED"
Example:"ACTIVE"
policystring

Parent policy group ID or object

Example:"66788b3e2805e9ffbda6dcf7"
businessstring

Business MongoDB ObjectId

Example:"631b067a46830ae81217f860"
policy_typestring

Policy scope type (e.g. business, budget)

Example:"business"
employeesArray of strings

Employee IDs this policy is scoped to

teamsArray of strings

Team IDs this policy is scoped to

budgetsArray of strings

Budget IDs this policy is scoped to

prioritynumber

Priority order among policies of the same type

Example:1
workflowobject or null

Approval workflow ID or null when no approval is required

Example:"6a3e6c5387ee44d7d52a3092"
rulesArray of objects(PolicyRuleV1Dto)

Rules defining the conditions and actions of this policy

namestring

Human-readable name for the policy

Example:"Test"
descriptionstring

Optional description for the policy

Example:"test"
require_tax_compliant_receiptboolean

Whether tax-compliant receipts are required (legacy top-level field)

curl -i -X PUT \
  https://developer.boyahq.com/_mock/v2/openapi/business-policies/6a3ebb7893bb2649e19cb8a6 \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: application/json' \
  -H 'business_id: string' \
  -d '{
    "_id": "6a3ebb7893bb2649e19cb8a6",
    "status": "ACTIVE",
    "policy": "66788b3e2805e9ffbda6dcf7",
    "business": "631b067a46830ae81217f860",
    "policy_type": "business",
    "employees": [
      "string"
    ],
    "teams": [
      "string"
    ],
    "budgets": [
      "string"
    ],
    "priority": 1,
    "workflow": "6a3e6c5387ee44d7d52a3092",
    "rules": [
      {
        "conditions": [
          {
            "field": "string",
            "operator": "string",
            "value": {},
            "value_id": "string"
          }
        ],
        "action": "string",
        "period_unit": "TRANSACTION",
        "period": 0,
        "kick_off_date": "string",
        "target": "string",
        "target_employees": [
          "string"
        ],
        "exempt_employees": [
          "string"
        ],
        "target_teams": [
          "string"
        ],
        "exempt_teams": [
          "string"
        ],
        "target_sub_categories": [
          "string"
        ],
        "exempt_sub_categories": [
          "string"
        ],
        "target_channels": [
          "string"
        ],
        "target_roles": [
          "string"
        ],
        "require_tax_compliant_receipt": true,
        "funding_source_strategy": "string",
        "exempt_wallet_types": [
          "string"
        ]
      }
    ],
    "name": "Test",
    "description": "test",
    "require_tax_compliant_receipt": true
  }'

Responses

Business policy updated successfully

Bodyapplication/json
_idstring

Business policy MongoDB ObjectId

statusstring

Policy status

Enum:"ACTIVE""DISABLED""DELETED"
policyobject(PolicyRefV1Dto)

Parent policy group — either a MongoDB ObjectId string or an expanded PolicyRefV1Dto object

businessstring

Business MongoDB ObjectId this policy belongs to

policy_typestring

Policy scope (e.g. business, budget)

policy_codestring

Policy code inherited from the parent policy group

employeesArray of strings

Employee IDs this policy is scoped to

teamsArray of strings

Team IDs this policy is scoped to

budgetsArray of strings

Budget IDs this policy is scoped to

prioritynumber

Priority order among policies of the same type (lower = higher priority)

workflowobject or null

Approval workflow attached to this policy — null when no approval is required

rulesArray of objects(PolicyRuleV1Dto)

Rules defining the conditions and actions of this policy

namestring

Human-readable name for this business policy

descriptionstring

Optional description for this business policy

createdAtstring

ISO 8601 creation timestamp

updatedAtstring

ISO 8601 last-updated timestamp

Response
{ "_id": "string", "status": "ACTIVE", "policy": { "_id": "string", "status": "ACTIVE", "description": "string", "policy_code": "string" }, "business": "string", "policy_type": "string", "policy_code": "string", "employees": [ "string" ], "teams": [ "string" ], "budgets": [ "string" ], "priority": 0, "workflow": {}, "rules": [ {} ], "name": "string", "description": "string", "createdAt": "string", "updatedAt": "string" }