> ## Documentation Index
> Fetch the complete documentation index at: https://docs.interchange.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Get organization posture

> Returns the authenticated human principal's posture for the organisation-settings surface (buyers and sellers). Gated by the `organization-settings-in-place` feature flag; returns 403 only when the flag evaluation is definitively false (the account is not enrolled), or 503 when flag evaluation is indeterminate or any backing dependency is temporarily unavailable. The posture value describes the caller's relationship to the org boundary: `direct_parent_admin` (ADMIN on the parent org or non-impersonated SUPER_ADMIN), `child_standalone` (direct non-propagated child member without org-admin authority), `standalone` (PARENT or STANDALONE — the account is its own org boundary), or `ineligible` (service token, workload, advertiser-scoped, impersonated, or other excluded principal class). The value drives which UI slice to render and never confers additional write authority — every write retains its own explicit-target authorisation.



## OpenAPI

````yaml /v2/buyer-api-v2.yaml get /accounts/organization-posture
openapi: 3.0.0
info:
  title: Scope3 Buyer API
  version: 2.0.0
  description: |-
    REST API for advertisers to manage advertisers, campaigns, and reporting.

    ## Authentication

    All endpoints require a Bearer token in the Authorization header:
    ```
    Authorization: Bearer your-api-key
    ```

    ## Base URL

    `https://api.interchange.io/api/v2/buyer`

    ## For AI Agents

    AI agents can use the MCP endpoint at `/mcp/v2/buyer` with three tools:
    - `initialize`: Start an MCP session
    - `api_call`: Make REST API calls
    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.interchange.io/api/v2/buyer
    description: Production server
security: []
tags:
  - name: Signup
    description: Request reviewed access to Interchange
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Asks
    description: >-
      What you are waiting on Scope3 for — support, product, and supply asks in
      one list
  - name: Advertisers
    description: Manage advertisers
  - name: Product Discovery
    description: Discover and select products
  - name: Campaigns
    description: Manage advertising campaigns
  - name: Creatives
    description: Build, manage, and sync campaign creatives via AdCP Creative Protocol
  - name: Reporting
    description: Access performance metrics
  - name: Event Sources
    description: >-
      Manage event source configurations and log conversion/marketing events for
      attribution
  - name: Property Lists
    description: Validate property lists against AAO registry
  - name: Sales Agents
    description: View and connect sales agents
  - name: Measurement
    description: Measurement sources, records, context, and freshness
  - name: Syndication
    description: Syndicate resources to ADCP agents
  - name: Tasks
    description: Track async operation status
  - name: Buyer Billing
    description: >-
      Consolidated invoicing for buyers — invoices and pending invoice items
      issued by Scope3 across the buyer customer.
  - name: MCP
    description: Model Context Protocol endpoints for AI agents
paths:
  /accounts/organization-posture:
    servers:
      - url: https://api.interchange.io/api/v2
        description: Production server
    get:
      tags:
        - Account
      summary: Get organization posture
      description: >-
        Returns the authenticated human principal's posture for the
        organisation-settings surface (buyers and sellers). Gated by the
        `organization-settings-in-place` feature flag; returns 403 only when the
        flag evaluation is definitively false (the account is not enrolled), or
        503 when flag evaluation is indeterminate or any backing dependency is
        temporarily unavailable. The posture value describes the caller's
        relationship to the org boundary: `direct_parent_admin` (ADMIN on the
        parent org or non-impersonated SUPER_ADMIN), `child_standalone` (direct
        non-propagated child member without org-admin authority), `standalone`
        (PARENT or STANDALONE — the account is its own org boundary), or
        `ineligible` (service token, workload, advertiser-scoped, impersonated,
        or other excluded principal class). The value drives which UI slice to
        render and never confers additional write authority — every write
        retains its own explicit-target authorisation.
      operationId: getOrganizationPosture
      responses:
        '200':
          description: Get organization posture
          content:
            application/json:
              schema:
                type: object
                properties:
                  authorityCustomerId:
                    type: integer
                    minimum: 0
                    exclusiveMinimum: true
                    maximum: 9007199254740991
                  authorityEpoch:
                    type: string
                    pattern: ^[0-9a-f]{16}$
                  posture:
                    type: string
                    enum:
                      - direct_parent_admin
                      - child_standalone
                      - standalone
                      - ineligible
                required:
                  - authorityCustomerId
                  - authorityEpoch
                  - posture
                additionalProperties: false
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            FEATURE_NOT_ENABLED — the `organization-settings-in-place` flag
            evaluation returned a definitive false (account not enrolled); or
            ACCESS_DENIED when no customer context is present.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            SERVICE_UNAVAILABLE — indeterminate flag evaluation (PostHog
            unreachable or partial inheritance failure), or a retryable
            topology/backing failure prevented posture resolution. The response
            body contains only a stable generic message; diagnostic detail is
            logged server-side. The client should retry with backoff.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
      description: Standard error response
    ApiError:
      type: object
      properties:
        code:
          type: string
          description: Machine-readable error code
        message:
          type: string
          description: Human-readable error message
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
      description: Structured error object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````