# Lock a column on a board

Names who may SEE one column's values on a custom board and who may CHANGE them, by audience. Takes the workspace ADMIN seat as well as manage on the board, and the Enterprise plan — the seat is checked first, so a member of a broker workspace hears 403 rather than an invitation to buy a control they still could not use.

Access class: `workspace:admin`.

## Endpoint

`PUT /v1/boards/{id}/column-policies/{column}`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| id | path | string | Yes |
| column | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "editableBy": {
      "mode": "string",
      "roles": [
        "string"
      ]
    },
    "visibleTo": {
      "mode": "string",
      "roles": [
        "string"
      ]
    }
  },
  "params": {
    ":column": "string",
    ":id": "string"
  },
  "query": {}
}
```

## Responses

### 200

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "columnId": "",
    "editableBy": {
      "accountIds": [
        "string"
      ],
      "mode": "string",
      "roles": [
        "string"
      ],
      "teamIds": [
        "string"
      ]
    },
    "updatedAt": "string",
    "updatedBy": "string",
    "visibleTo": {
      "accountIds": [
        "string"
      ],
      "mode": "string",
      "roles": [
        "string"
      ],
      "teamIds": [
        "string"
      ]
    }
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
