# Get organization-level effective access

> Organization-level effective access API for retrieving a principal's roles and assignments across active tenants in Automation Cloud.

Retrieves effective access for a user, group, or external application across an organization. The response combines organization-scoped assignments with tenant-level assignments from every active tenant. Folder-level assignment details are not included.

## API endpoint

`POST {accessURL}/{organizationName}/pdp_/api/geteffectiveaccess`

Replace `{accessURL}` with the base URL for your cloud platform:

| Cloud platform | Access URL |
| --- | --- |
| Automation Cloud | `https://cloud.uipath.com` |
| Automation Cloud Public Sector | `https://govcloud.uipath.us` |
| Automation Cloud Dedicated | `https://{customURL}.dedicated.uipath.com` |

## Permissions

For requests made with a user access token, the caller must be an Organization Administrator. Tenant Administrators receive a `403 Forbidden` response.

## Request headers

```text
Authorization: Bearer {access_token}
Content-Type: application/json
```

For information about obtaining an access token, see [Authentication methods](authentication-methods.md).

## Query parameters

| Query parameter | Data type | Description |
| --- | --- | --- |
| `top` | Integer | Maximum number of role-assignment groups to return. The default is `10`, and the maximum is `50`. The value cannot be negative. |
| `skip` | Integer | Number of role-assignment groups to skip. The default is `0`, and the value cannot be negative. |

## Request body

The following example retrieves organization-level effective access for one security principal:

```json
{
  "securityPrincipalId": "00000000-0000-0000-0000-000000000001",
  "scopeIdentifier": {
    "scopeType": "Organization"
  }
}
```

| Property | Data type | Description |
| --- | --- | --- |
| `securityPrincipalId` | String (GUID) | Identifier of the user, group, or external application whose effective access is returned. |
| `scopeIdentifier.scopeType` | String | Must be `Organization` for organization-level results. The value is case-insensitive. |
| `scopeIdentifier.value.id` | String (GUID) | Optional organization identifier. If included, it must match the caller's organization. |
| `serviceName` | String | Optional service-name filter. Only assignments for the specified service are returned. |
| `roleNameStartsWith` | String | Optional role-name prefix filter. Only assignments whose role name starts with the specified value are returned. |

## Responses

### 200 OK

Returns the effective access information for the requested security principal.

| Response property | Description |
| --- | --- |
| `roleAssignments` | Paginated assignment groups, keyed by tenant and role. Groups without a `tenantId` contain organization-scoped assignments. Organization-scoped groups appear before tenant-scoped groups. |
| `grantedServicesMetadata` | Non-paginated organization-wide list of services for which the principal has a role assignment. |
| `grantedRolesMetadata` | Non-paginated organization-wide list of roles granted to the principal. |

### 400 Bad Request

Returned when pagination values are invalid or when `scopeIdentifier.value.id` does not match the caller's organization.

### 401 Unauthorized

Returned when the bearer token is missing or invalid.

### 403 Forbidden

Returned when a user-token caller is not an Organization Administrator.

## Example request

```text
curl --location --request POST 'https://cloud.uipath.com/{organizationName}/pdp_/api/geteffectiveaccess?top=10&skip=0' \
--header 'Authorization: Bearer {access_token}' \
--header 'Content-Type: application/json' \
--data-raw '{
  "securityPrincipalId": "00000000-0000-0000-0000-000000000001",
  "scopeIdentifier": {
    "scopeType": "Organization"
  }
}'
```
