# Preview an organization allowlist policy's blast radius **POST /api/v1/organizations/{id}/policies/preview** Returns the projects whose effective allowlist would become empty if the given organization allowlist policy is saved, so an admin is warned before tightening a tool or model allowlist to a disjoint set. Non-allowlist or disabled policies have no blast radius. ## Servers - https://agentengine.mongodb.com: https://agentengine.mongodb.com () ## Authentication methods - Bearer auth ## Parameters ### Path parameters - **id** (string) Organization ID ### Body: application/json (object) Proposed org policy - **enabled** (boolean) Whether the proposed policy would be enforced. Defaults to true when omitted, matching policy creation. - **string_list** (array[string]) - **type** (string) ## Responses ### 406 Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence. #### Body: application/json (object) - **badRequestDetail** (object) Optional validation details defined by the standard error schema; API negotiation errors do not emit this field. - **detail** (string) Human-readable error details. - **error** (integer) HTTP status code. - **errorCode** (string) Machine-readable error code. - **parameters** (array[string]) Request parameter names associated with the error; omitted when none apply. - **reason** (string) HTTP status reason phrase. ### 200 OK #### Body: application/json (object) - **affected_projects** (array[object]) ### 400 Bad Request #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 403 Forbidden #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 500 Internal Server Error #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) [Powered by Bump.sh](https://bump.sh)