Skip to content
OpenAppPhysical access, simplified
Login

Policy catalog

Policies are administrative limits that layer on top of roles. A policy never grants access; it only narrows what someone could already do. For the three-tier model (org / integration / device) and how rows combine, see the policies architecture guide.

Use the catalog below to find a policy by name, category, when it is enforced, or tier. Categories start collapsed — expand one to see its policies. Machine policy_type keys are on each type page. Each card opens a page with every argument, allowed values, and an example config.

These fields exist on every policy row, not only in config:

FieldValuesMeaning
enforcementenforce, require_approval, audit_onlyenforce blocks. require_approval opens an admin inbox (when the type supports it). audit_only records and never blocks.
enabledbooleanDisabled rows are ignored.
applies_toagent, api_key, invitation, member, resident, admin, allOptional principal-kind bind. Defaults differ by type — see each page.
outputstring or integerOptional channel / output id. Omitted means every output of the tier target.
capabilityinvitations, users_admin, switchable, or unsetOptional column scope. Unset applies everywhere.

Author org policies on Settings → Policies, integration policies on the integration Policies tab, and device-tier policies (PalGate steward) on the device Policies tab.

Category
Enforced at
Tier

40 policies

Invitations

Guest invites — duration, uses, who may create them, and which doors they can cover.

19 policies

Invitation curfew

Blocks invitation-based opens during a forbidden time window (for example nights). Admins and residents are never curfewed; existing invitations are evaluated live, not modified.

Access-timeOrgIntegrationDevice

Max invitation duration

Caps how long each invitation schedule slot may last. Longer create or update requests are rejected, not shortened.

Authoring-timeOrgIntegrationDevice

Max share duration

Caps how long a short-term share (TTL invitation) may last. Combined with max invitation duration as the stricter of the two. Longer create requests are rejected, not shortened.

Authoring-timeOrgIntegrationDevice

Default share uses

When the author omits a use count on a share, store this default. The system default is 1 when this policy is not configured.

Authoring-timeOrgIntegrationDevice

Max share uses

Ceiling on how many times a share may be used. Unlimited shares require allow_unlimited on every applicable row and no invitation_max_uses.

Authoring-timeOrgIntegrationDevice

Max invitation uses

Requires a finite use count and rejects unlimited invitations or counts above the cap.

Authoring-timeOrgIntegrationDevice

Max invitation devices

Caps the number of unique guest browsers or app installations that may register an invitation.

Authoring-timeOrgIntegrationDevice

Max active invitations per user

Caps how many enabled, unexpired invitations one person may have at once.

Authoring-timeOrgIntegrationDevice

Require invitation expiry

Forbids open-ended recurring invitations that never end.

Authoring-timeOrgIntegrationDevice

Allowed entry kinds

Limits which portal types (door, gate, boom-gate) an invitation may grant. Combination intersects allowed sets.

Authoring-timeOrgIntegrationDevice

Require invitation justification

Requires a non-empty creation justification when creating or updating an invitation.

Authoring-timeOrgIntegrationDevice

Max doors per invitation

Caps how many unique portals a single invitation may grant.

Authoring-timeOrgIntegrationDevice

Own-apartment doors only

Invitations may only grant doors the author can open as a resident of an allowed apartment. Org/integration admins are exempt unless applies_to says otherwise. PalGate-only sites with no apartments fail for residents.

Authoring-timeOrgIntegrationDevice

Prohibit master-door invitations

Rejects an invitation if any granted portal’s door is a listed OpenApp device id (union of ids; never client-forged hardware ids).

Authoring-timeOrgIntegrationDevice

Who may invite

Literal allow-list of roles that may create invitations. Combination intersects lists; empty intersection means nobody. Not admin-exempt. Compose with user_sharing (both must pass).

Authoring-timeOrgIntegrationDevice

No invitation re-share

When the row binds the actor, invite create/update is rejected. Org/integration default bind is resident (invitees), not generic members. Device-tier without applies_to binds everyone.

Authoring-timeOrgIntegrationDevice

Require invitation identity

Requires a host PIN, a host-attached photo, and/or a verified invitee phone before an invitation can be created or used.

Authoring-timeOrgIntegrationDevice

Invitation allowed days

Limits invitation-based opens to listed weekdays, minus blackout dates and optional holiday-calendar dates. Existing invitations are evaluated live, not modified.

Access-timeOrgIntegrationDevice

Holiday calendar

Lists organization-local ISO dates that invitation allowed-days can treat as holidays. This type does not deny access by itself.

Access-timeOrgIntegrationDevice

Holds

Door hold-open and hold-closed — who may set a hold and for how long.

5 policies

Sharing

Who may share access or manage linked users outside invitations.

4 policies

Lifecycle

Move-out and idle membership — revoke leftover invites without deleting the user.

2 policies

Agent safety

Time windows, throttles, and extra confirmation for agents, API keys, and guests.

4 policies

Operational

Site-wide lockdown and notifications when a policy denies access.

6 policies