# resolvePolicyValue

query · in the family [Operating policy](/reference/operating-policy/)

## What it does

What policy value applies right now (or at a chosen moment) for a location or organization.

Resolve the EFFECTIVE policy value for (scope × key) at an instant. 'at' ABSENT = the server's now (past instants are legal — historical reconstruction is a READ). What this quotes is EXACTLY what the platform applies. An unknown key refuses naming the registry roster. Requires authentication; the org + LF are tenant-scoped server-side. Template class A18_POLICY (sensitive config — owner/manager).

## What happens

Reads only — exactly the value the platform applies: the location’s own window, else its organization’s, else the platform default.

## Who may call it

Capability area: **Operating policy** — The operational policies and thresholds your organization runs by.

- Owner
- Manager
- An API key whose scope allows `api:resolvePolicyValue`

## Arguments

| Name | Type | Required | Notes |
| --- | --- | --- | --- |
| `key` | [String](/types/#scalars) `String!` | yes | No further notes. |
| `organizationId` | [ID](/types/#scalars) `ID!` | yes | No further notes. |
| `logicalFacilityId` | [ID](/types/#scalars) | no | No further notes. |
| `at` | [String](/types/#scalars) | no | No further notes. |

## Returns

[PolicyResolution](/types/PolicyResolution/) `PolicyResolution!` — The EFFECTIVE resolved policy value for one (scope × key) at one instant: the WINNING nearest-ancestor record's identity + window, or the registry-default floor (source = default, record fields null). Resolution NEVER misses.

## Example request

```graphql
query ExampleResolvePolicyValue($key: String!, $organizationId: ID!, $logicalFacilityId: ID) {
  resolvePolicyValue(key: $key, organizationId: $organizationId, logicalFacilityId: $logicalFacilityId) {
    key
    valueInt
    source
    recordId
    level
    startAt
    endAt
  }
}
```

Variables:

```json
{
  "key": "<key>",
  "organizationId": "01900000-0000-7000-8000-44b781470000",
  "logicalFacilityId": "01900000-0000-7000-8000-8026f71c0000"
}
```

## Example response

```json
{
  "data": {
    "resolvePolicyValue": {
      "key": "<key>",
      "valueInt": 1,
      "source": "<source>",
      "recordId": "01900000-0000-7000-8000-ea0d77e10000",
      "level": "<level>",
      "startAt": "2027-01-31T00:00:00.000Z",
      "endAt": "2027-01-31T00:00:00.000Z"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": null,
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

## Errors this call can answer

- `VALIDATION/INVALID` — Something in the request is not valid. ([VALIDATION](/errors/VALIDATION/))
- `AUTHN/REQUIRED` — Sign in to do this. ([AUTHN](/errors/AUTHN/))
- `AUTHZ/FORBIDDEN` — Your role does not allow this action. ([AUTHZ](/errors/AUTHZ/))
- `RATE_LIMIT/THROTTLED` — Too many requests in a short time. ([RATE_LIMIT](/errors/RATE_LIMIT/))
- `NOT_FOUND/*` — That record could not be found. ([NOT_FOUND](/errors/NOT_FOUND/))

## Used in

- [Set a policy value — thresholds and limits](/use-cases/set-a-policy-value/)
