# SECURITY TEMPLATES Invoke the Security Templates API to retrieve, create, update, and delete Security Templates. A Security Template combines Security Roles and User Groups to define access to Assets and other objects in the platform. ## Retrieve Security Templates - [GET /security/template](https://api.tenovos.com/openapi/v1.5/security-templates/getsecuritytemplates.md): User will get the list of Security Templates available to them. The user submitting the request must have administrator rights to view Security Templates. In response user will get a list, containing template names and their corresponding template id. Average Response Time: 243ms ## (NEW!) List Security Templates (Paginated) - [GET /security/templates](https://api.tenovos.com/openapi/v1.5/security-templates/listsecuritytemplates.md): Retrieve an offset-paginated list of security, rights, or access templates for the authenticated customer. Each row is a lightweight summary — group and permission counts, not group contents — suited to an admin browse/list screen. Defaults: - type defaults to security-template. - from defaults to 0. - limit defaults to 100. - sortField defaults to templateName. - order defaults to asc. Business Rules: - searchTerm is trimmed and, when non-empty, matched as a case-insensitive substring against template name. It is trimmed before use, so a blank or whitespace-only value is treated as if omitted. Literal % and _ are treated as text, not SQL wildcards. - Results are ordered by the requested sortField/order. Template id is used as a deterministic secondary sort field, using the same order as the primary sort field. - groupCount and permissionCount are returned as first-class fields without returning the underlying group or permission objects. The user submitting the request must have the Security Template Management admin privilege. ## (NEW!) Create Security Template - [POST /security/templates](https://api.tenovos.com/openapi/v1.5/security-templates/createsecuritytemplate.md): Create a security, rights, or access template for the authenticated customer. Business Rules: - name must be trimmed, non-empty, and unique per customer. - type is set only at creation and is immutable thereafter. - Every groups[].id and permissionIds[] entry must be a well-formed UUID and must exist for the customer (groups) or in the permission catalog (permissions). Unknown ids are rejected with 422, not silently dropped. - Duplicate group ids in the same request are rejected. Defaults: - type defaults to security-template. - groups defaults to []. The response body is returned in the same shape as GET /security/templates/{id}, so the UI can render the created template with no follow-up read. The user submitting the request must have the Security Template Management admin privilege. ## (NEW!) List Security Templates Available to Current User - [GET /security/templates/user](https://api.tenovos.com/openapi/v1.5/security-templates/listusersecuritytemplates.md): Retrieve the security, rights, or access templates the authenticated user may act on — either templates the user can view, or templates that grant the user a specific permission. Returns only id and name, suited to populating a template picker for ingest, edit, or delete flows. Business Rules: - When permissionId is omitted, returns templates the user has view access to (resolved from the user's group membership). - When permissionId is provided, returns only templates where at least one of the user's groups is granted that permission. - Templates with no visible groups, and groups with no remaining permissions after filtering, are excluded. Defaults: - type defaults to security-template. - from defaults to 0. - limit defaults to 100. The requesting user must be authenticated. ## (NEW!) Get Security Template - [GET /security/templates/{templateId}](https://api.tenovos.com/openapi/v1.5/security-templates/getsecuritytemplate.md): Retrieve full detail for a single security, rights, or access template — header fields plus a paginated page of its groups, each with its permissions. Defaults: - includePermissions defaults to true. - groupLimit defaults to 100. Pagination: - Loop on groups.pageInfo.nextCursor, passing it back as groupCursor, until groups.pageInfo.hasNextPage is false. The user submitting the request must have the Security Template Management admin privilege. ## (NEW!) Update Security Template - [PATCH /security/templates/{templateId}](https://api.tenovos.com/openapi/v1.5/security-templates/updatesecuritytemplate.md): Partially update a security, rights, or access template. Only the fields present in the body are changed. Business Rules: - type is not an updatable field. If present in the body, the request is rejected with 400. Type is fixed at creation because assets and metadata templates reference the template by id and assume its type. - At least one of name or groups must be present, or the request is rejected with 400. Unknown fields are also rejected with 400. - When groups is present, it is a full replacement of the template's group/permission set — omitted groups are removed, not left alone. - Every groups[].id and permissionIds[] entry must be a well-formed UUID and must exist for the customer (groups) or in the permission catalog (permissions). Unknown ids are rejected with 422. - name, if changed, is re-checked for uniqueness per customer. Optimistic Concurrency: - Opt-in via expectedLastUpdatedEpoch. If provided, it is compared against the template's current lastUpdatedEpoch; a mismatch is rejected with 409 and code: STALE_UPDATE. If omitted, the update proceeds last-write-wins. The response body is returned in the same shape as GET /security/templates/{id}. The user submitting the request must have the Security Template Management admin privilege. ## (NEW!) Delete Security Template - [DELETE /security/templates/{templateId}](https://api.tenovos.com/openapi/v1.5/security-templates/deletesecuritytemplate.md): Permanently delete a security, rights, or access template the authenticated customer owns. Delete Rules: - Template must exist for the authenticated customer. - Deletion is blocked when the template is still referenced: either it has stored dependencies, or it is applied somewhere — for access-template, the count of metadata templates using it; otherwise, the count of assets using it. - There is no force-delete option. An in-use template can only be removed directly against the database, outside this API. - On success, the deletion is recorded in tenovos_delete_history for the security-template type. This action is permanent and cannot be undone. The user submitting the request must have the Security Template Management admin privilege.