Update a compliance catalog entry

posthttps://api.expiryedge.com/v1/updateCompliance
editor or admin60/minJede Methode
Anfrage
curl -X POST 'https://api.expiryedge.com/v1/updateCompliance?id=cm_9Pq4zR' \
  -H "Authorization: Bearer $EXPIRYEDGE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "notes": "Updated after the September review."
}'
Antwort
{
  "message": "Compliance updated successfully.",
  "compliance": {
    "id": "cm_9Pq4zR",
    "name": "HIPAA Security Risk Assessment",
    "description": "Annual security risk analysis required under the HIPAA Security Rule.",
    "category": "Data Privacy",
    "customCategory": "",
    "renewalFrequency": "Annually",
    "notes": "Keep the signed report for six years.",
    "status": "Active",
    "customFields": {
      "regulator": "HHS OCR"
    },
    "isArchived": false,
    "archivedAt": null,
    "organization_id": "org_northwind",
    "user_id": "u_71bXq",
    "createdAt": "2026-09-27T14:05:00.000Z",
    "updatedAt": "2026-09-27T14:05:00.000Z"
  }
}

Partial update: only the fields you send are changed. id goes in the query string.

Query-Parameter

  • idstringerforderlich
    Compliance id.

Body-Parameter

application/json
  • namestring
    Required on create; cannot be blank on update.
  • descriptionstring
  • categorystring
    Any other value is stored as Other.
    ErlaubtData PrivacySafetyFinancialEnvironmentalLaborQualitySecurityRegulatoryOther
  • customCategorystring
    Only kept when category is Other.
  • renewalFrequencystring
    Any other value is stored as One-Time.
    ErlaubtOne-TimeMonthlyQuarterlyAnnuallyBiennially
  • notesstring
  • statusstring
    Any other value is stored as Active.
    ErlaubtActiveInactive
  • customFieldsmap of string
    Free-form key/value pairs. Keys are trimmed; values are stored as strings.

Rückgabe

200
Updated.
  • messagestring
  • complianceobject
    A compliance requirement in the organization catalog.

Fehler

400
The request is missing required fields or contains invalid values.
401
Missing, expired or invalid bearer token.
403
Authenticated, but your role or organization does not allow this action.
404
The record does not exist or is not in your organization.
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.