## Access Policy for User or User Group

### Schema

## Elements

| Name             | Required | Type                                          | Description                                                                                                                                                      |
| ---------------- | -------- | --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| name             |          | string                                        | Details<br>A name associated with the AccessPolicy.                                                                                                           |
| basedOn         |          | Reference<[AccessPolicy](/content/docs/api/fhir/medplum/accesspolicy/index.html)>[] | Details<br>Other access policies used to derive this access policy.                                                                                           |
| compartment      |          | Reference<>                                   | Details<br>Optional compartment for newly created resources. If this field is set, any resources created by a user with this access policy will automatically be included in the specified compartment. |
| resource         |          | AccessPolicyResource[]                       | Details<br>Access details for a resource type.                                                                                                                |
| resourceType     | ✓        | string                                        | Details<br>The resource type.                                                                                                                                 |
| compartment      |          | Reference<>                                   | Details<br>@deprecated Optional compartment restriction for the resource type.                                                                                  |
| criteria         |          | string                                        | Details<br>The rules that the server should use to determine which resources to allow.<br>The rules are search criteria (without the [base] part). Like Bundle.entry.request.url, it has no leading "/".                                                  |
| readonly         |          | boolean                                       | Details<br>@deprecated Use AccessPolicy.resource.interaction = ['search', 'read', 'vread', 'history']                                                        |
| interaction      |          | code[]                                       | Details<br>Permitted FHIR interactions with this resource type                                                                                                   |
| hiddenFields     |          | string[]                                     | Details<br>Optional list of hidden fields. Hidden fields are not readable or writable.                                                                          |
| readonlyFields   |          | string[]                                     | Details<br>Optional list of read-only fields. Read-only fields are readable but not writable.                                                                  |
| writeConstraint   |          | [Expression](/content/docs/api/fhir/datatypes/expression/index.html)[] | Details<br>Invariants that must be satisfied for the resource to be written. Can include %before and %after placeholders to refer to the resource before and after the updates are applied.     |
| ipAccessRule     |          | AccessPolicyIpAccessRule[]                   | Details<br>Use IP Access Rules to allowlist, block, and challenge traffic based on the visitor IP address.                                                     |
| name             |          | string                                        | Details<br>Friendly name that will make it easy for you to identify the IP Access Rule in the future.                                                          |
| value            | ✓        | string                                        | Details<br>An IP Access rule will apply a certain action to incoming traffic based on the visitor IP address or IP range.                                       |
| action           | ✓        | code                                         | Details<br>Access rule can perform one of the following actions: "allow" | "block".                                                                                                      |

## Search Parameters

| Name  | Type   | Description                    | Expression                                   |
| ----- | ------ | ------------------------------ | --------------------------------------------- |
| name  | string | The name of the access policy  | AccessPolicy.name                             |

## Inherited Elements

| Name                | Required | Type                                          | Description                                                                                                                                                      |
| ------------------- | -------- | --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| id                  |          | string                                        | Logical id of this artifact<br>Details<br>The logical id of the resource, as used in the URL for the resource. Once assigned, this value never changes.         |
| meta                |          | [Meta](/content/docs/api/fhir/datatypes/meta/index.html) | Details<br>The metadata about the resource. This is content that is maintained by the infrastructure. Changes to the content might not always be associated with version changes to the resource.                             |
| implicitRules       |          | uri                                           | Details<br>A reference to a set of rules that were followed when the resource was constructed, and which must be understood when processing the content. Often, this is a reference to an implementation guide that defines the special rules along with other profiles etc. | 
| language            |          | code                                          | Details<br>The base language in which the resource is written.                                                                                                   |
| text                |          | [Narrative](/content/docs/api/fhir/datatypes/narrative/index.html)   | Details<br>A human-readable narrative that contains a summary of the resource and can be used to represent the content of the resource to a human.                 |
| contained           |          | Resource[]                                   | Details<br>These resources do not have an independent existence apart from the resource that contains them - they cannot be identified independently, and nor can they have their own independent transaction scope. |
| extension           |          | [Extension](/content/docs/api/fhir/datatypes/extension/index.html)[] | Details<br>May be used to represent additional information that is not part of the basic definition of the resource. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. |
| modifierExtension    |          | [Extension](/content/docs/api/fhir/datatypes/extension/index.html)[] | Details<br>May be used to represent additional information that is not part of the basic definition of the resource and that modifies the understanding of the element that contains it and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification.
