---
title: "Workspaces backfill and its undo (Greentally staff only)"
method: POST
path: "/internal/workspace-ops/backfill"
tags: ["PlatformOps"]
---

# Workspaces backfill and its undo (Greentally staff only)

`POST /internal/workspace-ops/backfill`

Requires the platform capability workspace.ops; a customer organization role never grants
it (403 PLATFORM_CAPABILITY_REQUIRED). 404 while workspaces are off.

mode "apply" (the default), per business organization in its own transaction: creates the
default "All data" workspace unless one exists, stamps every NULL workspace_id of the
workspace-owned artifacts with it, and writes a default-workspace grant for every member.
Idempotent. mode "undo" reverses exactly one real apply run (runId), skipping an
organization whose default was modified since. dryRun runs the same statements and rolls
them back, so its counts are the real ones. Every call is recorded in the platform audit
trail. Organizations are taken in id order, at most limit per call. Without organizationIds
a call takes the organizations still pending (apply: no default row yet and no active
workspace named "All data"; undo: not yet undone for runId), so repeat the call until it
returns no items. organizationIds names organizations explicitly, whatever their state.

## Request body

- WorkspaceBackfillRequest
  - `dryRun` boolean, required
  - `limit` integer
  - `mode` 'apply' | 'undo'
  - `organizationIds` string[]
  - `reason` string, required
  - `runId` string — The apply run to reverse; required when mode is undo

## Response `200`

The run's per-organization results

- WorkspaceBackfillResponse
  - `data` object, required
    - `dryRun` boolean, required
    - `items` WorkspaceBackfillItem[], required
      - `created` boolean, required
      - `defaultWorkspaceId` string, required — The default workspace's external id; empty when there is none
      - `grants` integer, required — Grants written (apply) or removed (undo)
      - `organizationId` string, required
      - `skipped` string — Why the call left the organization alone: apply, when an active workspace is already named All data; undo, when it was already undone or its default was modified since the run
      - `stamped` WorkspaceBackfillStamped, required
        - `assistantThreads` integer, required
        - `baselines` integer, required
        - `dashboardGenerations` integer, required
        - `dashboardLayouts` integer, required
        - `manualInventories` integer, required
        - `reports` integer, required
        - `targetSets` integer, required
    - `mode` 'apply' | 'undo', required
    - `runId` string, required

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found

## Changes

- **2026-10-02** `766c2a40e369` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/greentally/apis/esgai-api/changes/internal/workspace-ops/backfill/post.md)

---

[API](https://skmtc.dev/greentally/apis/esgai-api.md) · [All operations](https://skmtc.dev/greentally/apis/esgai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/greentally/apis/esgai-api/revisions/4189686230ca?raw)
