---
title: "List compliance policies"
method: GET
path: "/v1/policies"
tags: ["Policies"]
---

# List compliance policies

`GET /v1/policies`

Lists active compliance policies by default. Use includeArchived=true to include archived rows and excludeContent=true when you only need policy metadata.

## Query parameters

- `excludeContent` boolean
- `includeArchived` boolean

## Headers

- `X-Organization-Id` string

## Response `200`

Policies retrieved successfully

- object
  - `data` PolicyResponseDto[], required — Array of policies
    - `id` string, required — The policy ID
    - `name` string, required — Name of the policy
    - `description` string, nullable, required — Description of the policy
    - `status` 'draft' | 'published' | 'needs_review', required — Status of the policy
    - `content` object[], required — Content of the policy as TipTap JSON (array of nodes)
    - `frequency` 'monthly' | 'quarterly' | 'yearly', nullable, required — Review frequency of the policy
    - `department` string, nullable, required — Department this policy applies to. May be one of the built-in values (none, admin, gov, hr, it, itsm, qms) or a custom department name.
    - `isRequiredToSign` boolean, required — Whether this policy requires a signature
    - `signedBy` string[], required — List of user IDs who have signed this policy
    - `reviewDate` string, date-time, nullable, required — Review date for the policy
    - `isArchived` boolean, required — Whether this policy is archived
    - `archivedAt` string, date-time, nullable, required — When the policy was archived by framework sync
    - `createdAt` string, date-time, required — When the policy was created
    - `updatedAt` string, date-time, required — When the policy was last updated
    - `lastArchivedAt` string, date-time, nullable, required — When the policy was last archived
    - `lastPublishedAt` string, date-time, nullable, required — When the policy was last published
    - `organizationId` string, required — Organization ID this policy belongs to
    - `assigneeId` string, nullable, required — ID of the user assigned to this policy
    - `approverId` string, nullable, required — ID of the user who approved this policy
    - `policyTemplateId` string, nullable, required — ID of the policy template this policy is based on
  - `authType` 'api-key' | 'session', required — How the request was authenticated
  - `authenticatedUser` object — Authenticated user information (only present for session auth)
    - `id` string — User ID
    - `email` string — User email

## Other responses

- `401` — Unauthorized - Invalid authentication or insufficient permissions

---

[API](https://skmtc.net/trycompai/apis/comp-ai-api.md) · [All operations](https://skmtc.net/trycompai/apis/comp-ai-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/trycompai/comp-ai-api/versions/726b9523fb22/schema)
