# Remove the scope from the Access group.

Endpoint: DELETE /access-groups/{accessGroupId}/scopes/{scopeId}
Version: 3.30.0
Security: ApiKeyAuth

## Security:

  - `ApiKeyAuth` (unknown)
    apiKey in header Authorization

## Path parameters:

  - `accessGroupId` (string, required)
    The ID of the Access group.

  - `scopeId` (string, required)
    The ID of the Access group scope.

## Response 200:

  - `200` (unknown)
    The updated Access group.

## Response 200 fields (application/json):

  - `id` (string)
    The Access group ID.

  - `name` (string, required)
    The Access group name

  - `single_account` (boolean)
    Indicates that this Access group defines the permissions of a single account, and thus account and account tags cannot be modified. Instead create a new Access group to manage permissions of multiple accounts.

  - `account_ids` (array)
    List of accounts ids included individually (as opposed to added by tags) in the Access group.

  - `tagged_account_ids` (array)
    List of accounts ids included by tags in the Access group.

  - `account_tags` (array)
    List of account tags. Accounts matching any of these tags will be automatically added to the Access group.

  - `account_tags.key` (string, required)
    Key of the tag
    Example: key-1

  - `account_tags.value` (string, required)
    Value of the tag
    Example: value-1

  - `scopes` (array)
    The Access group scopes.

  - `scopes.id` (string)
    The Access group scope ID.

  - `scopes.name` (string)
    The Access group scope name.

  - `scopes.role_id` (string, required)
    The Access group role id.

  - `scopes.scope_type` (string)
    Specifies the type of the scope. Scope of type SIMPLE would grant access to all DCT objects. Scope of type SCOPED would grant access to all objects based on objects and object-tags and permissions defined in linked role. Scope of type ADVANCED would grant access to DCT objects based on objects and object-tags and the individual permissions.
    Enum: "SIMPLE", "SCOPED", "ADVANCED"

  - `scopes.object_tags` (array)
    The permissions in this access group scope will be granted to all DCT objects tagged with tags matching this property. This is cumulative with objects defined in the 'objects' property, and mutually exclusive with scope_type 'SIMPLE'.

  - `scopes.object_tags.key` (string, required)
    Key of the tag
    Example: key-1

  - `scopes.object_tags.value` (string, required)
    Value of the tag
    Example: value-1

  - `scopes.object_tags.object_type` (string)
    Type of the DCT object.
    Enum: "ALGORITHM", "ACCESS_GROUP", "ACCOUNT", "AI_SERVICE", "ROLE", "BOOKMARK", "CDB", "CLASSIFIER", "DATA_CLASS", "DATABASE_TEMPLATE", "DISCOVERY_EXPRESSION", "DISCOVERY_POLICY", "DSOURCE", "ENGINE", "ENVIRONMENT", "COMPLIANCE_JOB_COLLECTION", "MASKING_ENVIRONMENT", "MASKING_FILE_UPLOAD", "MASKING_JOB", "MASKING_JOB_SET", "REPORT_SCHEDULE", "RULE_SET", "SOURCE", "VCDB", "VDB", "VDB_GROUP", "CONNECTOR", "VIRTUALIZATION_POLICY", "DATASET_GROUP", "ENGINE_VAULT", "KERBEROS_CONFIG", "TIMEFLOW", "MASKING_PLUGIN", "HYPERSCALE_INSTANCE", "HYPERSCALE_CONNECTOR", "HYPERSCALE_DATASET", "TOOLKIT", "REPLICATION_PROFILE", "NAMESPACE", "STAGING_SOURCE", "DATA_LAYOUT", "SNAPSHOT", "VIRTUALIZATION_POLICY_TARGET", "DATA_CONNECTION", "HOOK_TEMPLATE", "JOB_ORCHESTRATOR", "STAGING_CDB", "SYNTHETIC_APPLICATION", "SYNTHETIC_DATASET", "SYNTHETIC_GENERATOR_FRAMEWORK", "SYNTHETIC_CONNECTOR", "SYNTHETIC_JOB", "SYNTHETIC_FILE", "SYNTHETIC_EXECUTION", "SYNTHETIC_EXECUTION_COMPONENT", "SYNTHETIC_SEED_LIST_FILE", "SYNTHETIC_GENERATOR_INSTANCE", "CLOUD_ACCOUNT", "PAAS_DATABASE", "CDB_DSOURCE", "PAAS_INSTANCE", "PAAS_SNAPSHOT", "SYNTHETIC_JDBC_DRIVER", "MOUNT_INFORMATION", "LLM_PROVIDER", "SSH_KEY", "COMPLIANCE_JDBC_DRIVER", "COMPLIANCE_PASSWORD_VAULT", "COMPLIANCE_CREDENTIAL_PATH", "FILE_FORMAT", "MAINFRAME_DATASET_FORMAT", "FEATURE_ASSIGNMENT", "STANDALONE_SERVICE"

  - `scopes.object_tags.permission` (string)
    Type of the permission on DCT object.
    Enum: "READ", "UPDATE", "DELETE", "EXECUTE", "CANCEL", "MIGRATE", "REFRESH", "DISABLE", "ENABLE", "ABANDON", "VALIDATE", "START", "STOP", "SNAPSHOT", "COPY", "REMOVE_JOB", "PASSWORD_RESET", "UNDO_IMPORT", "IMPORT", "PROVISION_FROM_BOOKMARK", "PROVISION", "REFRESH_FROM_BOOKMARK", "REFRESH_FROM_SNAPSHOT", "REFRESH_FROM_TIMESTAMP", "REFRESH_FROM_LOCATION", "CREATE_ENVIRONMENT", "CREATE_BOOKMARK", "CREATE_VDBGROUP", "MANAGE_TAGS", "LINK", "REPLICATE", "REPLICATE_TO", "CONVERT_AND_DROP", "IMPORT_BOOKMARKS", "FAILOVER", "COMMIT_FAILOVER", "FAILBACK", "DISCARD", "LOCK", "UNLOCK", "FORCE_UNLOCK", "LOCK_FOR_OTHER_ACCOUNT", "UPDATE_TIMEFLOW", "SNAPSHOT_DELETE", "SWITCH_TIMEFLOW", "DELETE_TIMEFLOW", "SNAPSHOT_UPDATE", "IMPORT_ACCOUNTS", "DETACH_SOURCE", "ATTACH_SOURCE", "RESOLVE", "RESOLVE_ALL", "RESOLVE_OR_IGNORE", "API_KEY_RESET", "API_KEY_DELETE", "READ_STORAGE_CAPACITY_DATA", "READ_DATASET_PERF_ANALYTICS", "CREATE_TOOLKIT", "REALIGN", "DELETE_BOOKMARK", "UPDATE_BOOKMARK", "READ_BOOKMARK", "CONVERT_AND_DROP_BOOKMARKS", "GLOBAL_SYNC_ENGINES", "ADD_ENGINE_TO_HYPERSCALE", "CONFIGURE_CUSTOM_AUTO_TAGGING", "CONFIGURE_PREDEFINED_AUTO_TAGGING", "APPLY", "UNAPPLY", "UNDO_REFRESH", "CONVERT", "DELETE_HELDSPACE", "REPAIR_TIMEFLOW", "EXPORT", "EXECUTE_NETWORK_TEST", "READ_NETWORK_TEST", "READ_HOOKS", "MANAGE_HOOKS", "REFRESH_LOGS", "VIEW_LOGS", "GENERATE_SUPPORT_BUNDLE", "RESTORE_FROM_RECYCLE_BIN", "DOWNLOAD_SUPPORT_BUNDLE", "SYNC", "EMPTY_RECYCLE_BIN", "PURGE_LOGS", "REPAVE_PREPARE", "REPAVE_APPLY", "IMPORT_SYNTHETIC_GENERATORS_PACK", "MIGRATE_COMPLIANCE_JOBS"

  - `scopes.objects` (array)
    The permissions in this access group scope will be granted to all DCT objects with matching object id and object type, mutually exclusive with  scope_type 'SIMPLE'.

  - `scopes.objects.object_id` (string, required)
    ID of the object
    Example: 1-VDB-OBJECT-ID

  - `scopes.always_allowed_permissions` (array)
    An array of always allowed permissions which can be used to specify object type and permission. An object with same object type and permission can not be added in 'objects' array.

