> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wfa.team/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a decision

> Record an approval, rejection, cancellation or pending decision.

`POST /rwa_update`

<Accordion title="Decision rules">
  | Status | Required actor |
  | - | - |
  | Pending | No decision-maker identifier required. |
  | Manager Approved | managerId is required. |
  | Compliance Approved | complianceTeamMemberId is required. The staff member must belong to the company and have completed account activation. |
  | Rejected | managerId or complianceTeamMemberId is required. |
  | Canceled | cancelledByStaffId is required. |

  The employee ID comes from the saved assessment. The legacy `Approved` alias represents compliance approval. Retry deduplication is pending verification.
</Accordion>

## Authorization

<ParamField header="Authorization" type="string" required>
  Company Bearer token. Keep it on your server.
</ParamField>

## Body parameters

<ParamField body="assessmentId" type="string" required>
  Assessment identifier returned by the create endpoint.
</ParamField>

<ParamField body="status" type="string" required>
  Decision status; see the decision rules below.
</ParamField>

<ParamField body="complianceTeamMemberId" type="string">
  Registered, activated compliance Staff ID in the token’s company. Required for the applicable decision status.
</ParamField>

<ParamField body="note" type="string">
  Note to accompany the decision.
</ParamField>

<ParamField body="externalEventId" type="string">
  Your event identifier. Retry deduplication has not been verified. Required by the current test client; the upstream requirement needs verification.
</ParamField>

<ParamField body="managerId" type="string">
  External manager Staff ID. Required for the applicable decision status.
</ParamField>

<ParamField body="cancelledByStaffId" type="string">
  Company Staff ID of the person cancelling the assessment. Required for the applicable decision status.
</ParamField>

## Error responses

| Message or field | When returned |
| - | - |
| `Invalid Auth` | Company authorization did not match. |
| `RWA not found for this company` | The assessment was not found for the authenticated company. |
| `managerId` | Manager ID is required for Manager Approved |
| `approverId` | Manager ID or Compliance Team Member ID is required for Rejected |
| `complianceTeamMemberId` | Compliance Team Member ID is required for Compliance Approved |
| `complianceTeamMemberId` | Compliance Team Member ID must match a registered, activated staff account in this company. The team member must complete account setup using their invitation before acting on an assessment. |
| `status` | Status must be Pending, Manager Approved, Compliance Approved, Rejected, or Canceled. Approved is also accepted as a legacy alias for Compliance Approved. |

A nonempty `complianceTeamMemberId` is checked for an activated staff account in the company, including when supplied with another status. The staff member must complete setup from their invitation before acting on an assessment.

## Response

The documented success message is `RWA decision and note updated`.

<Note>
  Check the JSON response as well as HTTP status. HTTP 200 can contain an API error. If a request times out, check the assessment before retrying. Retry deduplication is not verified.
</Note>

<RequestExample>
  ```bash cURL theme={null}
  curl --request POST \
    'https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_update' \
    --header "Authorization: Bearer $WFA_COMPANY_TOKEN" \
    --header 'Content-Type: application/json' \
    --data '{
    "assessmentId": "YOUR_TEST_ASSESSMENT_ID",
    "status": "Compliance Approved",
    "complianceTeamMemberId": "COMPLIANCE-001",
    "note": "Reviewed by the compliance team",
    "externalEventId": "decision-001"
  }'
  ```

  ```javascript JavaScript theme={null}
  // Run on your server. Set WFA_COMPANY_TOKEN in its environment.
  const response = await fetch('https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_update', {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.WFA_COMPANY_TOKEN}`,
      'Content-Type': 'application/json'
    },
    body: JSON.stringify({
      "assessmentId": "YOUR_TEST_ASSESSMENT_ID",
      "status": "Compliance Approved",
      "complianceTeamMemberId": "COMPLIANCE-001",
      "note": "Reviewed by the compliance team",
      "externalEventId": "decision-001"
    })
  });
  const result = await response.json();
  // Check the JSON body as well as the HTTP status.
  console.log(result);
  ```

  ```python Python theme={null}
  # Run on your server. Set WFA_COMPANY_TOKEN in its environment.
  import os
  import requests

  response = requests.post(
      'https://wfa-team-tool-v1.bubbleapps.io/version-test/api/1.1/wf/rwa_update',
      headers={
          'Authorization': f"Bearer {os.environ['WFA_COMPANY_TOKEN']}",
          'Content-Type': 'application/json',
      },
      json={
        "assessmentId": "YOUR_TEST_ASSESSMENT_ID",
        "status": "Compliance Approved",
        "complianceTeamMemberId": "COMPLIANCE-001",
        "note": "Reviewed by the compliance team",
        "externalEventId": "decision-001"
      },
      timeout=45,
  )
  # Check the JSON body as well as the HTTP status.
  print(response.json())
  ```
</RequestExample>

<ResponseExample>
  ```json Success theme={null}
  {
    "status": "success",
    "success": true,
    "message": "RWA decision and note updated"
  }
  ```

  ```json Invalid auth theme={null}
  {
    "status": "error",
    "success": false,
    "message": "Invalid Auth"
  }
  ```

  ```json Not found theme={null}
  {
    "status": "error",
    "success": false,
    "message": "RWA not found for this company"
  }
  ```

  ```json Manager ID required theme={null}
  {
    "status": "error",
    "success": false,
    "errors": [
      {
        "field": "managerId",
        "message": "Manager ID is required for Manager Approved"
      }
    ]
  }
  ```

  ```json Decision actor required theme={null}
  {
    "status": "error",
    "success": false,
    "errors": [
      {
        "field": "approverId",
        "message": "Manager ID or Compliance Team Member ID is required for Rejected"
      }
    ]
  }
  ```

  ```json Compliance ID required theme={null}
  {
    "status": "error",
    "success": false,
    "errors": [
      {
        "field": "complianceTeamMemberId",
        "message": "Compliance Team Member ID is required for Compliance Approved"
      }
    ]
  }
  ```

  ```json Inactive or unknown staff theme={null}
  {
    "status": "error",
    "success": false,
    "errors": [
      {
        "field": "complianceTeamMemberId",
        "message": "Compliance Team Member ID must match a registered, activated staff account in this company. The team member must complete account setup using their invitation before acting on an assessment."
      }
    ]
  }
  ```

  ```json Invalid status theme={null}
  {
    "status": "error",
    "success": false,
    "errors": [
      {
        "field": "status",
        "message": "Status must be Pending, Manager Approved, Compliance Approved, Rejected, or Canceled. Approved is also accepted as a legacy alias for Compliance Approved."
      }
    ]
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.