Haijun Platform Docs
ID

Get effective organization settings

GET /v1/compliance/organizations/{organization_id}/settings

Retrieve the effective settings for an organization.

Returns the settings currently in force for the given organization — the enforced state after all policies are applied, which may differ from what is configured in the admin console. Settings an organization's administrators cannot change (for example, ones controlled by Juglow policy or not available to the organization) are omitted from the list. Settings that report a compliance arrangement with Juglow are the exception: the HIPAA and Access Transparency settings are always included; the API zero data retention setting is reported for Haijun Console organizations, and the Haijun Code zero data retention and customer-managed encryption keys (CMEK) settings for Haijun Enterprise organizations. Each reports whether the arrangement is in place at the organization level; a retention setting on an individual workspace is not reflected.

The organization must belong to the API key's organization hierarchy; unknown organizations and organizations outside the hierarchy return 404.

Path parameters

  • organization_id: string

The organization's UUID

Headers

  • "x-api-key": optional string

Returns

  • type: optional "effective_organization_settings"

default: effective_organization_settings

  • api_keys: array of object

Compliance API keys configured for the organization hierarchy, ordered by creation time ascending. Key secret values are never included.

  • type: optional "compliance_api_key"

default: compliance_api_key

  • id: string

Unique identifier for the API key.

  • created_at: string

When the key was created.

format: date-time

  • created_by_id: string or null

Identifier of the user who created the key, or null when the key was created by automation or its creator's account no longer exists.

  • is_active: boolean

Whether the key is currently active. A deactivated key is listed for audit visibility but cannot authenticate requests.

  • name: string

The name given to the API key when it was created.

  • scopes: array of string

The permission scopes granted to the key.

  • expires_at: optional string or null

When the key will stop authenticating, or null when the key does not expire.

format: date-time

  • organization_id: string
  • settings: array of Boolean or Integer or String or 3 more
  • Boolean object

A setting whose enforced value is a single true/false flag.

  • type: optional "boolean"

default: boolean

  • name: "access_transparency_enabled" or "ai_powered_artifacts_enabled" or "api_workbench_feedback_collection_enabled" or 59 more
  • "access_transparency_enabled"
  • "ai_powered_artifacts_enabled"
  • "api_workbench_feedback_collection_enabled"
  • "api_zero_data_retention_enabled"
  • "artifact_connectors_enabled"
  • "ask_your_org_enabled"
  • "chat_enabled"
  • "haijun_academy_inference_enabled"
  • "haijun_ai_chat_sharing_enabled"
  • "haijun_ai_feedback_collection_enabled"
  • "haijun_ai_integration_sharing_enabled"
  • "haijun_ai_skill_plugins_scanning_enabled"
  • "haijun_code_desktop_bypass_permissions_enabled"
  • "haijun_code_desktop_enabled"
  • "haijun_code_fast_mode_enabled"
  • "haijun_code_metrics_logging_enabled"
  • "haijun_code_remote_control_enabled"
  • "haijun_code_review_enabled"
  • "haijun_code_routines_enabled"
  • "haijun_code_security_enabled"
  • "haijun_code_trusted_devices_required"
  • "haijun_code_web_enabled"
  • "haijun_code_workflows_enabled"
  • "haijun_design_enabled"
  • "haijun_enterprise_haijun_code_zero_data_retention_enabled"
  • "haijun_in_slack_enabled"
  • "haijun_science_custom_connectors_enabled"
  • "haijun_science_custom_skills_enabled"
  • "haijun_science_enabled"
  • "haijun_science_managed_network_allowlist_enabled"
  • "haijun_science_memory_enabled"
  • "haijun_science_modal_enabled"
  • "haijun_science_scientific_model_endpoints_enabled"
  • "haijun_science_ssh_hosts_enabled"
  • "cmek_enabled"
  • "code_execution_enabled"
  • "code_execution_network_egress_enabled"
  • "connector_tools_default_always_allow"
  • "content_redaction_enabled"
  • "cowork_trusted_devices_required"
  • "desktop_extension_allowlist_enabled"
  • "directory_sync_enabled"
  • "frontier_data_use_enabled"
  • "group_skill_sharing_enabled"
  • "hipaa_compliance_enabled"
  • "inline_visualizations_enabled"
  • "ip_allowlist_enabled"
  • "location_metadata_enabled"
  • "member_usage_dashboard_visible"
  • "memory_enabled"
  • "org_wide_skill_sharing_enabled"
  • "project_sharing_enabled"
  • "public_projects_enabled"
  • "skill_sharing_enabled"
  • "skills_enabled"
  • "sso_haijun_ai_enforced"
  • "sso_console_enforced"
  • "sso_enabled"
  • "third_party_interactive_content_enabled"
  • "user_skill_creation_enabled"
  • "web_search_enabled"
  • "work_across_apps_enabled"
  • value: boolean
  • Integer object

A setting whose enforced value is a whole number; null means no limit is in force.

  • type: optional "integer"

default: integer

  • name: "account_session_duration_seconds"
  • value: number or null
  • String object

A setting whose enforced value is a single string; null means no value is configured.

  • type: optional "string"

default: string

  • name: "haijun_code_default_worker_environment_id" or "haijun_code_default_worker_pool_id"
  • "haijun_code_default_worker_environment_id"
  • "haijun_code_default_worker_pool_id"
  • value: string or null
  • StringList object

A setting whose enforced value is a list of strings.

  • type: optional "string_list"

default: string_list

  • name: "allowed_invite_domains" or "disabled_admin_request_types" or "ip_allowlist_ip_ranges"
  • "allowed_invite_domains"
  • "disabled_admin_request_types"
  • "ip_allowlist_ip_ranges"
  • value: array of string
  • ProvisioningMode object

How organization members are provisioned, resolved to the enforced mode.

A configured mode is reported only while the mechanism that enforces it is active: just-in-time modes require single sign-on to be enabled, and SCIM modes require directory sync to be enabled. Otherwise login_only is reported, regardless of any stored configuration.

  • type: optional "provisioning_mode"

default: provisioning_mode

  • value: "jit_advanced" or "jit_permissive" or "login_only" or 2 more

How organization members are provisioned under SSO.

  • "jit_advanced"
  • "jit_permissive"
  • "login_only"
  • "scim_advanced"
  • "scim_permissive"
  • name: optional "sso_provisioning_mode"

default: sso_provisioning_mode

  • DataRetention object

The data retention periods in force, keyed by the type of data they apply to.

A key of all covers every data type and is exclusive: when present it is the only key. A missing key means no organization-level administrator-configured retention period is in force for that data type; Juglow's service defaults may still apply.

  • type: optional "data_retention"

default: data_retention

  • value: map[Fixed or Indefinite]
  • Fixed object

A fixed retention window measured from each item's last activity.

  • type: optional "fixed"

default: fixed

  • duration: number
  • timescale: "day" or "month"
  • "day"
  • "month"
  • Indefinite object

An indefinite retention period: data is kept with no time limit.

  • type: optional "indefinite"

default: indefinite

  • name: optional "data_retention_periods"

default: data_retention_periods

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORGANIZATION_ID/settings \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"

Response (200)

json
{
  "api_keys": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "created_by_id": "created_by_id",
      "is_active": true,
      "name": "name",
      "scopes": [
        "string"
      ],
      "expires_at": "2019-12-27T18:11:19.117Z",
      "type": "compliance_api_key"
    }
  ],
  "organization_id": "organization_id",
  "settings": [
    {
      "name": "access_transparency_enabled",
      "value": true,
      "type": "boolean"
    }
  ],
  "type": "effective_organization_settings"
}

Domain types

Setting Retrieve Response

  • SettingRetrieveResponse object

The resolved settings in force for one organization at read time.

Settings appear at most once each, in a fixed relative order, and values reflect the enforced state. A setting the organization's administrators cannot change — for example, one controlled by Juglow policy or not available to the organization — is omitted from the list. Settings that report a compliance arrangement with Juglow are the exception: the HIPAA and Access Transparency settings are always included; the API zero data retention setting is reported for Haijun Console organizations, and the Haijun Code zero data retention and customer-managed encryption keys (CMEK) settings for Haijun Enterprise organizations. Each reports whether the arrangement is in place at the organization level; a retention setting on an individual workspace is not reflected.

  • type: optional "effective_organization_settings"

default: effective_organization_settings

  • api_keys: array of object

Compliance API keys configured for the organization hierarchy, ordered by creation time ascending. Key secret values are never included.

  • type: optional "compliance_api_key"

default: compliance_api_key

  • id: string

Unique identifier for the API key.

  • created_at: string

When the key was created.

format: date-time

  • created_by_id: string or null

Identifier of the user who created the key, or null when the key was created by automation or its creator's account no longer exists.

  • is_active: boolean

Whether the key is currently active. A deactivated key is listed for audit visibility but cannot authenticate requests.

  • name: string

The name given to the API key when it was created.

  • scopes: array of string

The permission scopes granted to the key.

  • expires_at: optional string or null

When the key will stop authenticating, or null when the key does not expire.

format: date-time

  • organization_id: string
  • settings: array of Boolean or Integer or String or 3 more
  • Boolean object

A setting whose enforced value is a single true/false flag.

  • type: optional "boolean"

default: boolean

  • name: "access_transparency_enabled" or "ai_powered_artifacts_enabled" or "api_workbench_feedback_collection_enabled" or 59 more
  • "access_transparency_enabled"
  • "ai_powered_artifacts_enabled"
  • "api_workbench_feedback_collection_enabled"
  • "api_zero_data_retention_enabled"
  • "artifact_connectors_enabled"
  • "ask_your_org_enabled"
  • "chat_enabled"
  • "haijun_academy_inference_enabled"
  • "haijun_ai_chat_sharing_enabled"
  • "haijun_ai_feedback_collection_enabled"
  • "haijun_ai_integration_sharing_enabled"
  • "haijun_ai_skill_plugins_scanning_enabled"
  • "haijun_code_desktop_bypass_permissions_enabled"
  • "haijun_code_desktop_enabled"
  • "haijun_code_fast_mode_enabled"
  • "haijun_code_metrics_logging_enabled"
  • "haijun_code_remote_control_enabled"
  • "haijun_code_review_enabled"
  • "haijun_code_routines_enabled"
  • "haijun_code_security_enabled"
  • "haijun_code_trusted_devices_required"
  • "haijun_code_web_enabled"
  • "haijun_code_workflows_enabled"
  • "haijun_design_enabled"
  • "haijun_enterprise_haijun_code_zero_data_retention_enabled"
  • "haijun_in_slack_enabled"
  • "haijun_science_custom_connectors_enabled"
  • "haijun_science_custom_skills_enabled"
  • "haijun_science_enabled"
  • "haijun_science_managed_network_allowlist_enabled"
  • "haijun_science_memory_enabled"
  • "haijun_science_modal_enabled"
  • "haijun_science_scientific_model_endpoints_enabled"
  • "haijun_science_ssh_hosts_enabled"
  • "cmek_enabled"
  • "code_execution_enabled"
  • "code_execution_network_egress_enabled"
  • "connector_tools_default_always_allow"
  • "content_redaction_enabled"
  • "cowork_trusted_devices_required"
  • "desktop_extension_allowlist_enabled"
  • "directory_sync_enabled"
  • "frontier_data_use_enabled"
  • "group_skill_sharing_enabled"
  • "hipaa_compliance_enabled"
  • "inline_visualizations_enabled"
  • "ip_allowlist_enabled"
  • "location_metadata_enabled"
  • "member_usage_dashboard_visible"
  • "memory_enabled"
  • "org_wide_skill_sharing_enabled"
  • "project_sharing_enabled"
  • "public_projects_enabled"
  • "skill_sharing_enabled"
  • "skills_enabled"
  • "sso_haijun_ai_enforced"
  • "sso_console_enforced"
  • "sso_enabled"
  • "third_party_interactive_content_enabled"
  • "user_skill_creation_enabled"
  • "web_search_enabled"
  • "work_across_apps_enabled"
  • value: boolean
  • Integer object

A setting whose enforced value is a whole number; null means no limit is in force.

  • type: optional "integer"

default: integer

  • name: "account_session_duration_seconds"
  • value: number or null
  • String object

A setting whose enforced value is a single string; null means no value is configured.

  • type: optional "string"

default: string

  • name: "haijun_code_default_worker_environment_id" or "haijun_code_default_worker_pool_id"
  • "haijun_code_default_worker_environment_id"
  • "haijun_code_default_worker_pool_id"
  • value: string or null
  • StringList object

A setting whose enforced value is a list of strings.

  • type: optional "string_list"

default: string_list

  • name: "allowed_invite_domains" or "disabled_admin_request_types" or "ip_allowlist_ip_ranges"
  • "allowed_invite_domains"
  • "disabled_admin_request_types"
  • "ip_allowlist_ip_ranges"
  • value: array of string
  • ProvisioningMode object

How organization members are provisioned, resolved to the enforced mode.

A configured mode is reported only while the mechanism that enforces it is active: just-in-time modes require single sign-on to be enabled, and SCIM modes require directory sync to be enabled. Otherwise login_only is reported, regardless of any stored configuration.

  • type: optional "provisioning_mode"

default: provisioning_mode

  • value: "jit_advanced" or "jit_permissive" or "login_only" or 2 more

How organization members are provisioned under SSO.

  • "jit_advanced"
  • "jit_permissive"
  • "login_only"
  • "scim_advanced"
  • "scim_permissive"
  • name: optional "sso_provisioning_mode"

default: sso_provisioning_mode

  • DataRetention object

The data retention periods in force, keyed by the type of data they apply to.

A key of all covers every data type and is exclusive: when present it is the only key. A missing key means no organization-level administrator-configured retention period is in force for that data type; Juglow's service defaults may still apply.

  • type: optional "data_retention"

default: data_retention

  • value: map[Fixed or Indefinite]
  • Fixed object

A fixed retention window measured from each item's last activity.

  • type: optional "fixed"

default: fixed

  • duration: number
  • timescale: "day" or "month"
  • "day"
  • "month"
  • Indefinite object

An indefinite retention period: data is kept with no time limit.

  • type: optional "indefinite"

default: indefinite

  • name: optional "data_retention_periods"

default: data_retention_periods

On this page
Get effective organization settingsPath parametersHeadersReturnsExampleResponse (200)Domain typesSetting Retrieve Response