Skip to content

Retrieves the ingested access control list (ACL) for a specific document in a knowledge base

Description

Retrieves the ingested access control list (ACL) for a specific document in a knowledge base. Use this operation to inspect the allow and deny lists that were ingested for a document to troubleshoot access control issues. To use this operation, you must have the bedrock:GetIngestedDocumentAcl permission.

Usage

bedrockagentruntime_get_ingested_document_acl(dataSourceId, documentId,
  knowledgeBaseId)

Arguments

  • dataSourceId

[required] The unique identifier of the data source that contains the document.

  • documentId

[required] The unique identifier of the document to retrieve the ingested access control list (ACL) for.

  • knowledgeBaseId

[required] The unique identifier of the knowledge base that contains the document.

Value

A list with the following syntax:

list(
  documentAcl = list(
    allowList = list(
      conditions = list(
        list(
          conditionOperator = "AND"|"OR",
          groups = list(
            list(
              id = "string",
              type = "KNOWLEDGE_BASE"|"DATA_SOURCE"
            )
          ),
          users = list(
            list(
              id = "string",
              type = "KNOWLEDGE_BASE"|"DATA_SOURCE"
            )
          )
        )
      ),
      memberRelation = "AND"|"OR"
    ),
    denyList = list(
      conditions = list(
        list(
          conditionOperator = "AND"|"OR",
          groups = list(
            list(
              id = "string",
              type = "KNOWLEDGE_BASE"|"DATA_SOURCE"
            )
          ),
          users = list(
            list(
              id = "string",
              type = "KNOWLEDGE_BASE"|"DATA_SOURCE"
            )
          )
        )
      ),
      memberRelation = "AND"|"OR"
    )
  )
)

Request syntax

svc$get_ingested_document_acl(
  dataSourceId = "string",
  documentId = "string",
  knowledgeBaseId = "string"
)