> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Dismiss RLS recommendation

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Removes one entity's row-level security recommendation from the app's latest security scan result. Get `entity_name` from `rls_recommendations` in [Get security scan](/api-reference/get-security-scan).

The call changes only the scan result, never the entity's rules. There are two ways to use it:
- To record a fix, apply the rules with [Update entity schema](/api-reference/update-entity-schema) first, then send the same rules as `applied_rule`. Base44 records them as you send them and doesn't check them against the entity.
- To dismiss the recommendation without changing anything, leave `applied_rule` out.

Either way the recommendation moves into the scan's resolved history, along with who resolved it, when, and the recommendation as it stood.

The next scan that checks row-level security judges every entity again and clears that history, so a recommendation can come back if the entity's rules still need to change.

The call is rejected when the latest result no longer holds a recommendation for the entity. That happens when the app has no scan result, when the result came from an earlier version of the scanner, when the recommendation was already resolved, or when a newer scan replaced it. Read the result again with Get security scan before you retry.

This is limited to 30 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json delete /api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}:
    delete:
      summary: Dismiss RLS recommendation
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Removes one entity's row-level security recommendation from the app's
        latest security scan result. Get `entity_name` from
        `rls_recommendations` in [Get security
        scan](/api-reference/get-security-scan).


        The call changes only the scan result, never the entity's rules. There
        are two ways to use it:

        - To record a fix, apply the rules with [Update entity
        schema](/api-reference/update-entity-schema) first, then send the same
        rules as `applied_rule`. Base44 records them as you send them and
        doesn't check them against the entity.

        - To dismiss the recommendation without changing anything, leave
        `applied_rule` out.


        Either way the recommendation moves into the scan's resolved history,
        along with who resolved it, when, and the recommendation as it stood.


        The next scan that checks row-level security judges every entity again
        and clears that history, so a recommendation can come back if the
        entity's rules still need to change.


        The call is rejected when the latest result no longer holds a
        recommendation for the entity. That happens when the app has no scan
        result, when the result came from an earlier version of the scanner,
        when the recommendation was already resolved, or when a newer scan
        replaced it. Read the result again with Get security scan before you
        retry.


        This is limited to 30 requests a minute per caller for each app. Some
        workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: >-
        dismiss_rls_recommendation_api_apps__app_id__security_scan_rls_recommendation__entity_name__delete
      parameters:
        - name: entity_name
          in: path
          required: true
          schema:
            type: string
            description: >-
              Entity whose recommendation to remove, as returned in
              `rls_recommendations` by [Get security
              scan](/api-reference/get-security-scan). It contains only letters,
              digits, and underscores.
            title: Entity Name
          description: >-
            Entity whose recommendation to remove, as returned in
            `rls_recommendations` by [Get security
            scan](/api-reference/get-security-scan). It contains only letters,
            digits, and underscores.
          example: Order
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        content:
          application/json:
            schema:
              title: DismissRlsRecommendation
              type: object
              properties:
                applied_rule:
                  anyOf:
                    - type: object
                      properties:
                        create:
                          anyOf:
                            - type: boolean
                            - additionalProperties: true
                              type: object
                            - type: 'null'
                          description: >-
                            Rule you applied for creating a record. `true`
                            allows it for everyone, `false` blocks it outright,
                            `null` leaves it unset, and an object is a filter
                            matched against the record and the signed-in app
                            user.
                          example: true
                        read:
                          anyOf:
                            - type: boolean
                            - additionalProperties: true
                              type: object
                            - type: 'null'
                          description: >-
                            Rule you applied for reading records. `true` allows
                            it for everyone, `false` blocks it outright, `null`
                            leaves it unset, and an object is a filter matched
                            against the record and the signed-in app user.
                          example:
                            created_by: '{{user.email}}'
                        update:
                          anyOf:
                            - type: boolean
                            - additionalProperties: true
                              type: object
                            - type: 'null'
                          description: >-
                            Rule you applied for updating a record. `true`
                            allows it for everyone, `false` blocks it outright,
                            `null` leaves it unset, and an object is a filter
                            matched against the record and the signed-in app
                            user.
                          example:
                            created_by: '{{user.email}}'
                        delete:
                          anyOf:
                            - type: boolean
                            - additionalProperties: true
                              type: object
                            - type: 'null'
                          description: >-
                            Rule you applied for deleting a record. `true`
                            allows it for everyone, `false` blocks it outright,
                            `null` leaves it unset, and an object is a filter
                            matched against the record and the signed-in app
                            user.
                          example:
                            $or:
                              - created_by: '{{user.email}}'
                              - user_condition:
                                  role: admin
                        write:
                          anyOf:
                            - type: boolean
                            - additionalProperties: true
                              type: object
                            - type: 'null'
                          description: >-
                            Legacy rule for updating and deleting, used for
                            whichever of the two has no rule of its own. `true`
                            allows it for everyone, `false` blocks it outright,
                            `null` leaves it unset, and an object is a filter
                            matched against the record and the signed-in app
                            user.
                          example:
                            created_by: '{{user.email}}'
                    - type: 'null'
                  description: >-
                    The rules you applied to the entity, keyed by operation in
                    the same format as the entity's `rls`. Send it to record the
                    call as a fix. Leave it out, or send `null` or an empty
                    object, to record a plain dismissal. Keys other than the
                    five operations are rejected.


                    A filter can use only the query operators `$eq`, `$ne`,
                    `$gt`, `$gte`, `$lt`, `$lte`, `$in`, `$nin`, `$and`, `$or`,
                    `$not`, `$nor`, `$exists`, `$type`, `$all`, `$elemMatch`,
                    `$size`, `$regex`, `$options`, `$text`, `$search`, `$near`,
                    `$nearSphere`, `$geoIntersects`, and `$geoWithin`. `$and`,
                    `$or`, and `$nor` take a list. `$in`, `$nin`, and `$all`
                    take a list or a template string such as
                    `{{user.data.departments}}`. `user_condition` takes an
                    object.


                    The whole value can be up to 20,000 bytes as compact JSON,
                    nest up to 8 levels deep, and hold up to 200 keys in total.
                    Lists can hold up to 50 items, keys up to 200 characters,
                    and strings up to 2,000 characters. The keys `__proto__`,
                    `constructor`, and `prototype` aren't allowed.
                  example:
                    create: true
                    read:
                      created_by: '{{user.email}}'
                    update:
                      created_by: '{{user.email}}'
                    delete:
                      $or:
                        - created_by: '{{user.email}}'
                        - user_condition:
                            role: admin
            example:
              applied_rule:
                create: true
                read:
                  created_by: '{{user.email}}'
                update:
                  created_by: '{{user.email}}'
                delete:
                  $or:
                    - created_by: '{{user.email}}'
                    - user_condition:
                        role: admin
        required: false
      responses:
        '200':
          description: The recommendation left the scan result.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityRlsRecommendationDismissed'
        '400':
          description: '`entity_name` isn''t a valid entity name.'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '409':
          description: >-
            The latest scan result has no recommendation for this entity, so
            nothing was recorded. The detail is `RLS recommendation was not
            dismissed. Refresh scan results and try again.`
        '422':
          description: >-
            The body isn't a JSON object, has fields other than `applied_rule`,
            or `applied_rule` breaks one of the limits described on the field.
        '429':
          description: Too many dismissals for this app from you in the last minute.
components:
  schemas:
    SecurityRlsRecommendationDismissed:
      properties:
        status:
          type: string
          title: Status
          description: Always `ok`. The recommendation is no longer in the scan result.
          example: ok
      type: object
      required:
        - status
      title: SecurityRlsRecommendationDismissed
      description: Confirms that the recommendation left the scan result.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````