OrgIPPolicy

Per-org IP allowlist policy: mode and the canonical CIDR list applied to authenticated requests.

  • Resource type identifier

  • Unique identifier for the policy.

  • Organization this policy belongs to

  • Enforcement mode: disabled skips evaluation, enforce rejects off-list requests, dry_run allows them but emits an audit event.

  • Canonical, deduplicated CIDR list. Bare IPs submitted on PATCH are stored as /32 (IPv4) or /128 (IPv6).

  • Actor (session user, personal API key, or org API key) that last updated the policy. Omitted for the never-seeded defensive fallback row.

    Properties: 6
  • When the policy row was created.

  • When the policy row was last updated.