AB-2001 policy_denied
| Class | Policy |
| HTTP status | 403 |
| Retryable | no |
When it happens
A Cedar policy forbade the action. details.policy_id is the deciding policy, details.effect is forbid or no_permit.
Hint
Policy
{policy_id}denies{source}sending{type}to{to}. Runagentbus policy simulate --from {source} --to {to} --type {type}to see the evaluation, or ask a workspace admin.
Troubleshooting
- Simulate. 2. If
no_permit, there is no allow rule: the agents are probably in different workspaces and need a grant (post-MVP) or the recipient moved. 3. Ifforbid, read the policy name in the console.