# PolicyConstraints Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/policyconstraints/

Schema for the `PolicyConstraints` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`policy_id`** _(string)_
  The provider's own identifier for the policy.
- **`policy_name`** _(string)_
  The policy name as the provider names it.
- **`display_name`** _(string)_
  A friendlier name, distinct from policy_name, where the provider provides one. AWS service control policies have none, so this falls back to policy_name.
- **`policy_type`** _(string)_
  Which preventative policy mechanism this is, as the provider names it.
- **`effect`** _(string)_
  Whether the policy blocks, allows, or merely audits the action. AWS SCPs support only allow/deny (never audit) and effect is per statement, not per policy, since one policy can mix both.
  Allowed: `deny`, `allow`, `audit`, `modify`, `mixed`, `unknown`
- **`supports_audit_mode`** _(boolean)_
  Whether this policy mechanism can express a report-only mode at all. False here means audit mode doesn't exist for it, not that the customer chose not to use it.
- **`scope_type`** _(string)_
  The level this row's scope node sits at.
  Allowed: `organisation`, `grouping`, `account`, `resource`, `unknown`
- **`scope_id`** _(string)_
  The node this row reports the policy as applying to.
- **`inherited_from`** _(object)_
  The node the policy is actually attached to, when that differs from the node this row reports it for.
  - **`id`** _(string)_
    The target's `id`.
- **`is_inherited`** _(boolean)_
  Whether this row is an inherited application rather than a direct attachment.
- **`parameters`** _(object)_
  Parameter values supplied when the policy is instantiated per assignment. Null with not_supported_by_provider for AWS service control policies, which are never parameterized.
- **`allowed_values`** _(array<string>)_
  Values the policy permits, where the provider exposes them as structured data. Null (not guessed) for AWS service control policies, which don't expose this.
- **`denied_values`** _(array<string>)_
  Values the policy forbids, on the same terms as allowed_values.
- **`enforced`** _(boolean)_
  Whether the policy is actually in force. AWS has no enabled toggle; this is derived from the policy type being enabled at the org root and the policy having at least one target.
- **`has_local_override`** _(boolean)_
  Whether a sub-account has opted out of an organisation-wide rule. Always false for AWS service control policies, which intersect and never allow a child to relax a parent.
- **`policy_document`** _(string)_
  The raw policy document, in the provider's native encoding. AWS SCP content is plain JSON (unlike IAM policy documents); decoding it as IAM will mangle it.

## Methods

- [GET /unified/cloud-infrastructure/policy_constraints](/docs/api-reference/unified-cloud-infrastructure-api/policyconstraints/list) — List Policy constraints
