All four resources share list/create/get/update/delete (bodies take {name, description}); departments and user-groups add an activate/deactivate toggle. The operations below use departments as the exemplar — substitute any resource from the table.
List departments
Parameters
| Name | In | Type | Required | Description |
|---|
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
| page | query | integer | optional | Page number to retrieve (1-based); integer, minimum 1, defaults to 1. |
| limit | query | integer | optional | Page size (number of records per page); integer, minimum 1, maximum 100, defaults to 25. |
Responses
200Paginated items.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).
Create (managers+)
Parameters
| Name | In | Type | Required | Description |
|---|
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
| page | query | integer | optional | Page number to retrieve (1-based); integer, minimum 1, defaults to 1. |
| limit | query | integer | optional | Page size (number of records per page); integer, minimum 1, maximum 100, defaults to 25. |
Request body object (required, application/json)
Responses
201Created.400Request body/params failed validation.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).409Conflict.429Rate limit exceeded.
Get a departments item
Parameters
| Name | In | Type | Required | Description |
|---|
| id | path | string | required | |
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
Responses
200The item.400Request body/params failed validation.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).404Not found (or not in the caller's org).
Update (managers+)
Parameters
| Name | In | Type | Required | Description |
|---|
| id | path | string | required | |
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
Request body object (required, application/json)
Responses
200Updated.400Request body/params failed validation.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).404Not found (or not in the caller's org).409Conflict.429Rate limit exceeded.
Delete (managers+)
Parameters
| Name | In | Type | Required | Description |
|---|
| id | path | string | required | |
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
Responses
204Deleted.400Request body/params failed validation.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).404Not found (or not in the caller's org).429Rate limit exceeded.
Activate/deactivate (managers+)
Parameters
| Name | In | Type | Required | Description |
|---|
| id | path | string | required | |
| X-Organization-Id | header | string | optional | Target organization ObjectId; required for APP_ADMIN and SUPPLIER callers and ignored (must match the caller's own org) for org admins, managers, and users. |
Request body object (required, application/json)
Responses
200Updated.401Missing/invalid token.403Authenticated but not allowed (role or cross-org).404Not found (or not in the caller's org).429Rate limit exceeded.