# Sign off, reject or reopen a run

Admin only, and an APPEND: signing off a run that is already signed off adds a second line rather than overwriting the first, because two admins signing the same quarter is a fact worth keeping. decision is signed_off, rejected or reopened, and rejecting must say why. The signer's name is recorded as it stands now, so the trail still reads correctly after the person is renamed. The database refuses any edit to what is already there.

Access class: `workspace:admin`.

## Endpoint

`POST /v1/workspace/compliance/runs/{runId}/decisions`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| runId | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "decision": "string",
    "note": "string"
  },
  "params": {
    ":runId": ""
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "checksRun": [
      "string"
    ],
    "decisions": [
      {
        "decidedAt": "string",
        "decision": "string",
        "id": "",
        "note": "string",
        "signerName": "string",
        "signerUserId": ""
      }
    ],
    "failed": 1,
    "id": "",
    "outcome": "string",
    "passed": 1,
    "ranAt": "string",
    "ranBy": 1,
    "reportId": "",
    "reportName": "string",
    "standing": "string",
    "subjects": 1
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
