Prohibit master-door invitations
- Type
- prohibit_master_door_invites
- Category
- Invitations
- Enforced atWhen this policy is checked: while someone tries to open, while they create or change an invitation or hold, or after a denial (notify only).
- Authoring-time
- TiersWhere an admin can set this policy: the whole organization, one integration, or the physical device when the connector supports a device steward.
- OrgIntegrationDevice
- EnforcementHow a configured row behaves. Enforce blocks. Require approval opens an admin inbox when the type supports it. Audit only records and never blocks.
- Enforce
- DefaultWhat happens when no row of this type is configured.
- Not configured — master doors may be granted on invitations.
Rejects create or update if any granted portal resolves to a listed OpenApp device id. Ids are OpenApp device ULIDs, never client-forged hardware identifiers. Combination unions the id lists so a parent can name building master doors that no child can invite to.
When it is enforced
Evaluated when someone creates or updates an invitation, hold, or share. Requests that would exceed the limit are rejected — they are not silently rewritten.
Where to set it
Settings → Policies (org), the integration Policies tab, or — on PalGate — the device steward Policies tab.
Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.
Arguments
The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.
| Name | Type | Required | Values | Description |
|---|---|---|---|---|
| master_door_ids | string[] | Yes | — | Non-empty array of OpenApp device ULIDs that invitations must not grant. |
| output | string or integer | No | — | Optional channel or output id. When set, the policy binds only that output. When omitted, it binds every output of the tier target. A scoped row does not apply when the acting output is unknown. |
How overlapping rows combine
Union of master_door_ids across applicable rows. Reject, do not drop doors.
Example
An invitation that includes the building’s listed master door is rejected even if other doors on the invite are allowed.
{ "master_door_ids": [ "01ARZ3NDEKTSV4RRFFQ69G5FAV" ]}Integrations
This type is documented on these connectors:
- Home Assistant (home_assistant)
- KNX (knx)
- MQTT (mqtt)
- PalGate Cloud (palgate_cloud)
- Shelly Cloud (shelly_cloud)
- Shelly Websocket (shelly_websocket)
- Tasmota (tasmota)
- Virtual Access (virtual_access)
- Virtual Demo Devices (virtual_demo)
- Waveshare (waveshare)
Related
- Policy catalog
- Policies architecture guide
- Own-apartment doors only (restrict_to_own_apartment_doors)
- Max doors per invitation (max_doors_per_invite)
Typed configuration
Section titled “Typed configuration”The OpenAPI contract names this object ProhibitMasterDoorInvitesPolicyConfig:
{ "master_door_ids": ["01ARZ3NDEKTSV4RRFFQ69G5FAV"], "output": "main"}master_door_ids is a non-empty list of OpenApp device ULIDs. An invitation granting any listed door is rejected.