curl -X PUT "https://app.runtm.com/api/cloud/organizations/org_abc123/allowlist-policy" \
-H "Authorization: Bearer runtm_xxx" \
-H "X-Organization-Id: org_abc123" \
-H "Content-Type: application/json" \
-d '{
"default_policy": "deny"
}'
import requests
org_id = "org_abc123"
resp = requests.put(
f"https://app.runtm.com/api/cloud/organizations/{org_id}/allowlist-policy",
headers={
"Authorization": "Bearer runtm_xxx",
"X-Organization-Id": org_id,
"Content-Type": "application/json",
},
json={"default_policy": "deny"},
)
print(resp.json())
const orgId = "org_abc123";
const resp = await fetch(
`https://app.runtm.com/api/cloud/organizations/${orgId}/allowlist-policy`,
{
method: "PUT",
headers: {
Authorization: "Bearer runtm_xxx",
"X-Organization-Id": orgId,
"Content-Type": "application/json",
},
body: JSON.stringify({ default_policy: "deny" }),
}
);
const data = await resp.json();
{
"organization_id": "org_abc123",
"default_policy": "deny",
"updated_at": "2026-05-09T18:00:00Z"
}
Guardrails
Set Allowlist Policy
Set the default allowlist policy for an organization.
PUT
/
api
/
organizations
/
{org_id}
/
allowlist-policy
curl -X PUT "https://app.runtm.com/api/cloud/organizations/org_abc123/allowlist-policy" \
-H "Authorization: Bearer runtm_xxx" \
-H "X-Organization-Id: org_abc123" \
-H "Content-Type: application/json" \
-d '{
"default_policy": "deny"
}'
import requests
org_id = "org_abc123"
resp = requests.put(
f"https://app.runtm.com/api/cloud/organizations/{org_id}/allowlist-policy",
headers={
"Authorization": "Bearer runtm_xxx",
"X-Organization-Id": org_id,
"Content-Type": "application/json",
},
json={"default_policy": "deny"},
)
print(resp.json())
const orgId = "org_abc123";
const resp = await fetch(
`https://app.runtm.com/api/cloud/organizations/${orgId}/allowlist-policy`,
{
method: "PUT",
headers: {
Authorization: "Bearer runtm_xxx",
"X-Organization-Id": orgId,
"Content-Type": "application/json",
},
body: JSON.stringify({ default_policy: "deny" }),
}
);
const data = await resp.json();
{
"organization_id": "org_abc123",
"default_policy": "deny",
"updated_at": "2026-05-09T18:00:00Z"
}
Updates the organization’s default allowlist policy that controls how tools and commands are handled.
Required scope:
guardrails:write
string
required
The organization ID.
string
required
Bearer token.
Authorization: Bearer runtm_xxxstring
required
Must match the
org_id path parameter.string
required
The default policy. One of
allow, ask, or deny.string
The organization ID.
string
The updated policy value.
string
ISO 8601 timestamp of the update.
curl -X PUT "https://app.runtm.com/api/cloud/organizations/org_abc123/allowlist-policy" \
-H "Authorization: Bearer runtm_xxx" \
-H "X-Organization-Id: org_abc123" \
-H "Content-Type: application/json" \
-d '{
"default_policy": "deny"
}'
import requests
org_id = "org_abc123"
resp = requests.put(
f"https://app.runtm.com/api/cloud/organizations/{org_id}/allowlist-policy",
headers={
"Authorization": "Bearer runtm_xxx",
"X-Organization-Id": org_id,
"Content-Type": "application/json",
},
json={"default_policy": "deny"},
)
print(resp.json())
const orgId = "org_abc123";
const resp = await fetch(
`https://app.runtm.com/api/cloud/organizations/${orgId}/allowlist-policy`,
{
method: "PUT",
headers: {
Authorization: "Bearer runtm_xxx",
"X-Organization-Id": orgId,
"Content-Type": "application/json",
},
body: JSON.stringify({ default_policy: "deny" }),
}
);
const data = await resp.json();
{
"organization_id": "org_abc123",
"default_policy": "deny",
"updated_at": "2026-05-09T18:00:00Z"
}