ScreeningPolicyRules
Customer rules, { preScreen, postScreen }, per the vendor's own rule schema
(TrmPolicyRules or ChainalysisPolicyRules). Typed as a free-form object
rather than a oneOf over the two: the vendor is a path parameter, no
OpenAPI construct selects a body schema from one, and oneOf generates SDK
models that do not compile. The server validates the blob against the
vendor's schema before writing, so a TRM policy naming a chainalysis.*
field is a 400. Clients should validate against those two schemas before
submitting.
Neither the sanctions floor nor the terminal ALLOW appears here. Both are generated from code on every screen, so there is nothing to author, edit, or read back, and no request body can weaken them.