For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/api/latest/org-groups/update-an-org-group-policy.md. A documentation index is available at /llms.txt.

Update an org group policy

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

PATCH https://api.ap1.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}https://api.ap2.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}https://api.datadoghq.eu/api/v2/org_group_policies/{org_group_policy_id}https://api.ddog-gov.com/api/v2/org_group_policies/{org_group_policy_id}https://api.us2.ddog-gov.com/api/v2/org_group_policies/{org_group_policy_id}https://api.uk1.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}https://api.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}https://api.us3.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}https://api.us5.datadoghq.com/api/v2/org_group_policies/{org_group_policy_id}

Overview

Update an existing organization group policy. This endpoint requires the org_group_write permission.

Arguments

Path Parameters

Name

Type

Description

org_group_policy_id [required]

string

The ID of the org group policy.

Request

Body Data (required)

Expand All

Field

Type

Description

data [required]

object

Data for updating an org group policy.

attributes [required]

object

Attributes for updating an org group policy. policy_name, content, and enforcement_tier may be omitted individually to leave them unchanged.

content

object

The policy content as key-value pairs. For org_config policies, an arbitrary key-value map (for example, {"value": "UTC"}). For role policies, a permissions key containing an array of permission UUIDs (for example, {"permissions": ["<uuid>", ...]}).

enforcement_tier

enum

The enforcement tier of the policy. OVERRIDE_ALLOWED means the policy is set but member orgs may mutate it. GROUP_MANAGED means the policy is strictly controlled and mutations are blocked for affected orgs. DELEGATE means each member org controls its own value. role policies only support GROUP_MANAGED and DELEGATEOVERRIDE_ALLOWED is rejected for this policy type. Transitioning a role policy to DELEGATE (disabling it) is one-way — the policy cannot be transitioned back to GROUP_MANAGED afterward. Allowed enum values: OVERRIDE_ALLOWED,GROUP_MANAGED,DELEGATE

policy_name

string

The name of the policy. This becomes the name of the resource created across orgs in the group (for example, for role policies, the name of the created role). Omit to leave unchanged.

id [required]

uuid

The ID of the policy.

type [required]

enum

Org group policies resource type. Allowed enum values: org_group_policies

{
  "data": {
    "attributes": {
      "content": {
        "value": "UTC"
      },
      "enforcement_tier": "OVERRIDE_ALLOWED",
      "policy_name": "monitor_timezone"
    },
    "id": "1a2b3c4d-5e6f-7890-abcd-ef0123456789",
    "type": "org_group_policies"
  }
}

Response

OK

Response containing a single org group policy.

Expand All

Field

Type

Description

data [required]

object

An org group policy resource.

attributes [required]

object

Attributes of an org group policy.

content

object

The policy content as key-value pairs. For org_config policies, an arbitrary key-value map (for example, {"value": "UTC"}). For role policies, a permissions key containing an array of permission UUIDs (for example, {"permissions": ["<uuid>", ...]}).

enforcement_tier [required]

enum

The enforcement tier of the policy. OVERRIDE_ALLOWED means the policy is set but member orgs may mutate it. GROUP_MANAGED means the policy is strictly controlled and mutations are blocked for affected orgs. DELEGATE means each member org controls its own value. role policies only support GROUP_MANAGED and DELEGATEOVERRIDE_ALLOWED is rejected for this policy type. Transitioning a role policy to DELEGATE (disabling it) is one-way — the policy cannot be transitioned back to GROUP_MANAGED afterward. Allowed enum values: OVERRIDE_ALLOWED,GROUP_MANAGED,DELEGATE

modified_at [required]

date-time

Timestamp when the policy was last modified.

policy_name [required]

string

The name of the policy. This becomes the name of the resource created across orgs in the group (for example, for role policies, the name of the created role).

policy_type [required]

enum

The type of the policy. org_config indicates a policy backed by an organization configuration setting. role indicates a policy backed by a Datadog custom role. Allowed enum values: org_config,role

default: org_config

id [required]

uuid

The ID of the org group policy.

relationships

object

Relationships of an org group policy.

org_group

object

Relationship to a single org group.

data [required]

object

A reference to an org group.

id [required]

uuid

The ID of the org group.

type [required]

enum

Org groups resource type. Allowed enum values: org_groups

type [required]

enum

Org group policies resource type. Allowed enum values: org_group_policies

{
  "data": {
    "attributes": {
      "content": {
        "value": "UTC"
      },
      "enforcement_tier": "OVERRIDE_ALLOWED",
      "modified_at": "2024-01-15T10:30:00Z",
      "policy_name": "monitor_timezone",
      "policy_type": "org_config"
    },
    "id": "1a2b3c4d-5e6f-7890-abcd-ef0123456789",
    "relationships": {
      "org_group": {
        "data": {
          "id": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
          "type": "org_groups"
        }
      }
    },
    "type": "org_group_policies"
  }
}

Bad Request

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Unauthorized

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Forbidden

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Not Found

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Too many requests

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Code Example

                  ## org_config
# 

# Path parameters
export org_group_policy_id="1a2b3c4d-5e6f-7890-abcd-ef0123456789"
# Curl command
curl -X PATCH "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/org_group_policies/${org_group_policy_id}" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "content": { "value": "US/Eastern" }, "enforcement_tier": "GROUP_MANAGED", "policy_name": "monitor_timezone" }, "id": "1a2b3c4d-5e6f-7890-abcd-ef0123456789", "type": "org_group_policies" } } EOF
## role #
# Path parameters
export org_group_policy_id="1a2b3c4d-5e6f-7890-abcd-ef0123456789"
# Curl command
curl -X PATCH "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/org_group_policies/${org_group_policy_id}" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "content": { "permissions": [ "1a2b3c4d-5e6f-7890-abcd-ef0123456789", "2b3c4d5e-6f78-90ab-cdef-0123456789ab" ] }, "enforcement_tier": "GROUP_MANAGED" }, "id": "1a2b3c4d-5e6f-7890-abcd-ef0123456789", "type": "org_group_policies" } } EOF
"""
Update an org group policy returns "OK" response
"""

from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.org_groups_api import OrgGroupsApi
from datadog_api_client.v2.model.org_group_policy_enforcement_tier import OrgGroupPolicyEnforcementTier
from datadog_api_client.v2.model.org_group_policy_type import OrgGroupPolicyType
from datadog_api_client.v2.model.org_group_policy_update_attributes import OrgGroupPolicyUpdateAttributes
from datadog_api_client.v2.model.org_group_policy_update_data import OrgGroupPolicyUpdateData
from datadog_api_client.v2.model.org_group_policy_update_request import OrgGroupPolicyUpdateRequest
from uuid import UUID

body = OrgGroupPolicyUpdateRequest(
    data=OrgGroupPolicyUpdateData(
        attributes=OrgGroupPolicyUpdateAttributes(
            content=dict([("value", "UTC")]),
            enforcement_tier=OrgGroupPolicyEnforcementTier.OVERRIDE_ALLOWED,
        ),
        id=UUID("1a2b3c4d-5e6f-7890-abcd-ef0123456789"),
        type=OrgGroupPolicyType.ORG_GROUP_POLICIES,
    ),
)

configuration = Configuration()
configuration.unstable_operations["update_org_group_policy"] = True
with ApiClient(configuration) as api_client:
    api_instance = OrgGroupsApi(api_client)
    response = api_instance.update_org_group_policy(
        org_group_policy_id=UUID("1a2b3c4d-5e6f-7890-abcd-ef0123456789"), body=body
    )

    print(response)

Instructions

First install the library and its dependencies and then save the example to example.py and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" python3 "example.py"
# Update an org group policy returns "OK" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.update_org_group_policy".to_sym] = true
end
api_instance = DatadogAPIClient::V2::OrgGroupsAPI.new

body = DatadogAPIClient::V2::OrgGroupPolicyUpdateRequest.new({
  data: DatadogAPIClient::V2::OrgGroupPolicyUpdateData.new({
    attributes: DatadogAPIClient::V2::OrgGroupPolicyUpdateAttributes.new({
      content: {
        "value": "UTC",
      },
      enforcement_tier: DatadogAPIClient::V2::OrgGroupPolicyEnforcementTier::OVERRIDE_ALLOWED,
      policy_name: "monitor_timezone",
    }),
    id: "1a2b3c4d-5e6f-7890-abcd-ef0123456789",
    type: DatadogAPIClient::V2::OrgGroupPolicyType::ORG_GROUP_POLICIES,
  }),
})
p api_instance.update_org_group_policy("1a2b3c4d-5e6f-7890-abcd-ef0123456789", body)

Instructions

First install the library and its dependencies and then save the example to example.rb and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" rb "example.rb"
// Update an org group policy returns "OK" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
	"github.com/google/uuid"
)

func main() {
	body := datadogV2.OrgGroupPolicyUpdateRequest{
		Data: datadogV2.OrgGroupPolicyUpdateData{
			Attributes: datadogV2.OrgGroupPolicyUpdateAttributes{
				Content: map[string]interface{}{
					"value": "UTC",
				},
				EnforcementTier: datadogV2.ORGGROUPPOLICYENFORCEMENTTIER_OVERRIDE_ALLOWED.Ptr(),
			},
			Id:   uuid.MustParse("1a2b3c4d-5e6f-7890-abcd-ef0123456789"),
			Type: datadogV2.ORGGROUPPOLICYTYPE_ORG_GROUP_POLICIES,
		},
	}
	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.UpdateOrgGroupPolicy", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewOrgGroupsApi(apiClient)
	resp, r, err := api.UpdateOrgGroupPolicy(ctx, uuid.MustParse("1a2b3c4d-5e6f-7890-abcd-ef0123456789"), body)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `OrgGroupsApi.UpdateOrgGroupPolicy`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `OrgGroupsApi.UpdateOrgGroupPolicy`:\n%s\n", responseContent)
}

Instructions

First install the library and its dependencies and then save the example to main.go and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" go run "main.go"
// Update an org group policy returns "OK" response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.OrgGroupsApi;
import com.datadog.api.client.v2.model.OrgGroupPolicyEnforcementTier;
import com.datadog.api.client.v2.model.OrgGroupPolicyResponse;
import com.datadog.api.client.v2.model.OrgGroupPolicyType;
import com.datadog.api.client.v2.model.OrgGroupPolicyUpdateAttributes;
import com.datadog.api.client.v2.model.OrgGroupPolicyUpdateData;
import com.datadog.api.client.v2.model.OrgGroupPolicyUpdateRequest;
import java.util.Map;
import java.util.UUID;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled("v2.updateOrgGroupPolicy", true);
    OrgGroupsApi apiInstance = new OrgGroupsApi(defaultClient);

    OrgGroupPolicyUpdateRequest body =
        new OrgGroupPolicyUpdateRequest()
            .data(
                new OrgGroupPolicyUpdateData()
                    .attributes(
                        new OrgGroupPolicyUpdateAttributes()
                            .content(Map.ofEntries(Map.entry("value", "UTC")))
                            .enforcementTier(OrgGroupPolicyEnforcementTier.OVERRIDE_ALLOWED))
                    .id(UUID.fromString("1a2b3c4d-5e6f-7890-abcd-ef0123456789"))
                    .type(OrgGroupPolicyType.ORG_GROUP_POLICIES));

    try {
      OrgGroupPolicyResponse result =
          apiInstance.updateOrgGroupPolicy(
              UUID.fromString("1a2b3c4d-5e6f-7890-abcd-ef0123456789"), body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling OrgGroupsApi#updateOrgGroupPolicy");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}

Instructions

First install the library and its dependencies and then save the example to Example.java and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" java "Example.java"
// Update an org group policy returns "OK" response
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_org_groups::OrgGroupsAPI;
use datadog_api_client::datadogV2::model::OrgGroupPolicyEnforcementTier;
use datadog_api_client::datadogV2::model::OrgGroupPolicyType;
use datadog_api_client::datadogV2::model::OrgGroupPolicyUpdateAttributes;
use datadog_api_client::datadogV2::model::OrgGroupPolicyUpdateData;
use datadog_api_client::datadogV2::model::OrgGroupPolicyUpdateRequest;
use serde_json::Value;
use std::collections::BTreeMap;
use uuid::Uuid;

#[tokio::main]
async fn main() {
    let body = OrgGroupPolicyUpdateRequest::new(OrgGroupPolicyUpdateData::new(
        OrgGroupPolicyUpdateAttributes::new()
            .content(BTreeMap::from([("value".to_string(), Value::from("UTC"))]))
            .enforcement_tier(OrgGroupPolicyEnforcementTier::OVERRIDE_ALLOWED),
        Uuid::parse_str("1a2b3c4d-5e6f-7890-abcd-ef0123456789").expect("invalid UUID"),
        OrgGroupPolicyType::ORG_GROUP_POLICIES,
    ));
    let mut configuration = datadog::Configuration::new();
    configuration.set_unstable_operation_enabled("v2.UpdateOrgGroupPolicy", true);
    let api = OrgGroupsAPI::with_config(configuration);
    let resp = api
        .update_org_group_policy(
            Uuid::parse_str("1a2b3c4d-5e6f-7890-abcd-ef0123456789").expect("invalid UUID"),
            body,
        )
        .await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}

Instructions

First install the library and its dependencies and then save the example to src/main.rs and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" cargo run
/**
 * Update an org group policy returns "OK" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations["v2.updateOrgGroupPolicy"] = true;
const apiInstance = new v2.OrgGroupsApi(configuration);

const params: v2.OrgGroupsApiUpdateOrgGroupPolicyRequest = {
  body: {
    data: {
      attributes: {
        content: {
          value: "UTC",
        },
        enforcementTier: "OVERRIDE_ALLOWED",
      },
      id: "1a2b3c4d-5e6f-7890-abcd-ef0123456789",
      type: "org_group_policies",
    },
  },
  orgGroupPolicyId: "1a2b3c4d-5e6f-7890-abcd-ef0123456789",
};

apiInstance
  .updateOrgGroupPolicy(params)
  .then((data: v2.OrgGroupPolicyResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));

Instructions

First install the library and its dependencies and then save the example to example.ts and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" tsc "example.ts"