# Lock or unlock a column

Locks one column, or replaces the lock on it — who may see it and who may write it, stated whole. A PUT rather than a patch because a policy is only meaningful entire: 'I cleared the editing restriction' and 'I did not mention it' must not look the same. A body that restricts NOTHING deletes the policy and answers the unrestricted one, so unrestricted has exactly one spelling. Workspace admin, and on the enterprise tier — the reads stay open on every plan so a policy already set keeps applying.

Access class: `def:admin`.

## Endpoint

`PUT /v1/definitions/{key}/column-policies/{column}`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| key | path | string | Yes |
| column | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "editableBy": {
      "mode": "string",
      "roles": [
        "string"
      ]
    },
    "visibleTo": {
      "mode": "string",
      "roles": [
        "string"
      ]
    }
  },
  "params": {
    ":column": "string",
    ":key": "string"
  },
  "query": {}
}
```

## Responses

### 200

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "columnId": "",
    "editableBy": {
      "accountIds": [
        "string"
      ],
      "mode": "string",
      "roles": [
        "string"
      ],
      "teamIds": [
        "string"
      ]
    },
    "updatedAt": "string",
    "updatedBy": "string",
    "visibleTo": {
      "accountIds": [
        "string"
      ],
      "mode": "string",
      "roles": [
        "string"
      ],
      "teamIds": [
        "string"
      ]
    }
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
