> ## Documentation Index
> Fetch the complete documentation index at: https://mintlify.com/Falasefemi2/companyflow/llms.txt
> Use this file to discover all available pages before exploring further.

# Assign Permissions

> Replace all permissions for a role

Replace all existing permissions for a role with a new set of permissions. This operation will remove any existing permissions and set only the provided ones. Requires Super Admin or HR Manager permissions.

<Warning>
  This endpoint replaces ALL existing permissions. Any permissions not included in the request will be removed.
</Warning>

## Path Parameters

<ParamField path="role_id" type="string" required>
  The unique identifier of the role (UUID format)

  **Example:** `"550e8400-e29b-41d4-a716-446655440000"`
</ParamField>

## Request Body

The request body should be an array of permission objects.

<ParamField body="action" type="string" required>
  The action that can be performed (e.g., "read", "write", "delete")

  **Example:** `"read"`
</ParamField>

<ParamField body="resource" type="string" required>
  The resource the permission applies to (e.g., "employees", "departments")

  **Example:** `"employees"`
</ParamField>

<ParamField body="conditions" type="object">
  Optional conditions that must be met for the permission to apply

  **Example:** `{"department": "engineering"}`
</ParamField>

## Response

<ResponseField name="success" type="boolean">
  Indicates if the request was successful
</ResponseField>

<ResponseField name="data" type="object">
  The updated role object with new permissions

  <Expandable title="Role Object">
    <ResponseField name="id" type="string">
      Unique identifier for the role
    </ResponseField>

    <ResponseField name="company_id" type="string">
      The company this role belongs to
    </ResponseField>

    <ResponseField name="name" type="string">
      Name of the role
    </ResponseField>

    <ResponseField name="description" type="string">
      Description of the role
    </ResponseField>

    <ResponseField name="is_system_role" type="boolean">
      Whether this is a system-defined role
    </ResponseField>

    <ResponseField name="permissions_cache" type="string[]">
      Array of cached permission strings
    </ResponseField>

    <ResponseField name="created_at" type="string">
      ISO 8601 timestamp of when the role was created
    </ResponseField>

    <ResponseField name="updated_at" type="string">
      ISO 8601 timestamp of when the role was last updated
    </ResponseField>
  </Expandable>
</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST https://api.companyflow.com/roles/550e8400-e29b-41d4-a716-446655440000/permissions \
    -H "Authorization: Bearer YOUR_TOKEN" \
    -H "Content-Type: application/json" \
    -d '[
      {
        "action": "read",
        "resource": "employees"
      },
      {
        "action": "write",
        "resource": "employees",
        "conditions": {"department": "engineering"}
      },
      {
        "action": "read",
        "resource": "departments"
      }
    ]'
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch(
    'https://api.companyflow.com/roles/550e8400-e29b-41d4-a716-446655440000/permissions',
    {
      method: 'POST',
      headers: {
        'Authorization': 'Bearer YOUR_TOKEN',
        'Content-Type': 'application/json'
      },
      body: JSON.stringify([
        {
          action: 'read',
          resource: 'employees'
        },
        {
          action: 'write',
          resource: 'employees',
          conditions: { department: 'engineering' }
        },
        {
          action: 'read',
          resource: 'departments'
        }
      ])
    }
  );

  const data = await response.json();
  ```

  ```python Python theme={null}
  import requests

  url = "https://api.companyflow.com/roles/550e8400-e29b-41d4-a716-446655440000/permissions"
  headers = {
      "Authorization": "Bearer YOUR_TOKEN",
      "Content-Type": "application/json"
  }
  payload = [
      {
          "action": "read",
          "resource": "employees"
      },
      {
          "action": "write",
          "resource": "employees",
          "conditions": {"department": "engineering"}
      },
      {
          "action": "read",
          "resource": "departments"
      }
  ]

  response = requests.post(url, json=payload, headers=headers)
  data = response.json()
  ```
</RequestExample>

<ResponseExample>
  ```json 200 - Success theme={null}
  {
    "success": true,
    "data": {
      "id": "550e8400-e29b-41d4-a716-446655440000",
      "company_id": "123e4567-e89b-12d3-a456-426614174000",
      "name": "Senior Developer",
      "description": "Senior-level software development position",
      "is_system_role": false,
      "permissions_cache": [
        "employees:read",
        "employees:write",
        "departments:read"
      ],
      "created_at": "2024-01-15T10:30:00Z",
      "updated_at": "2024-01-15T16:20:00Z"
    }
  }
  ```

  ```json 400 - Bad Request theme={null}
  {
    "success": false,
    "message": "invalid role_id"
  }
  ```

  ```json 401 - Unauthorized theme={null}
  {
    "success": false,
    "message": "unauthorized"
  }
  ```
</ResponseExample>
