# Get Rule Set Proxy

`GET /api/2.0/preview/accounts/access-control/rule-sets`

Get a rule set by its name. A rule set is always attached to a resource and contains a list of access rules on the
 said resource. Currently only a default rule set for each resource is supported.

API scopes: access-management

## Query parameters

- `account_id` (string, optional)
  <Databricks> account ID.
- `name` (string, optional)
  The ruleset name associated with the request.
  
   Examples | Summary
   :--- | :---
   `name=accounts/<ACCOUNT_ID>/ruleSets/default` | A name for a rule set on the account.
   `name=accounts/<ACCOUNT_ID>/groups/<GROUP_ID>/ruleSets/default` | A name for a rule set on the group.
   `name=accounts/<ACCOUNT_ID>/servicePrincipals/<SERVICE_PRINCIPAL_APPLICATION_ID>/ruleSets/default` | A name for a rule set on the service principal.
   `name=accounts/<ACCOUNT_ID>/tagPolicies/<TAG_POLICY_ID>/ruleSets/default` | A name for a rule set on the tag policy.
- `etag` (string, optional)
  Etag used for versioning. The response is at least as fresh as the eTag provided. Etag is used for optimistic
   concurrency control as a way to help prevent simultaneous updates of a rule set from overwriting each other. It is
   strongly suggested that systems make use of the etag in the read -> modify -> write pattern to perform rule set
   updates in order to avoid race conditions that is get an etag from a GET rule set request, and pass it with the
   PUT update request to identify the rule set version you are updating.
  
   Examples | Summary
   :--- | :---
   `etag=` | An empty etag can only be used in GET to indicate no freshness requirements.
   `etag=RENUAAABhSweA4NvVmmUYdiU717H3Tgy0UJdor3gE4a+mq/oj9NjAf8ZsQ==` | An etag encoded a specific version of the rule set to get or to be updated.

## Returns

- `name` (string, optional)
  Name of the rule set.
- `etag` (string, optional)
  Identifies the version of the rule set returned.
   Etag used for versioning. The response is at least as fresh as the eTag provided.
   Etag is used for optimistic concurrency control as a way to help prevent simultaneous
   updates of a rule set from overwriting each other. It is strongly suggested that systems
   make use of the etag in the read -> modify -> write pattern to perform rule set updates in
   order to avoid race conditions that is get an etag from a GET rule set request, and pass it
   with the PUT update request to identify the rule set version you are updating.
- `grant_rules` (array of object, optional)
  - `principals` (array of string, optional)
    Principals this grant rule applies to.
     A principal can be a user (for end users), a service principal (for applications and
     compute workloads), or an account group. Each principal has its own identifier format:
     * users/<USERNAME>
     * groups/<GROUP_NAME>
     * servicePrincipals/<SERVICE_PRINCIPAL_APPLICATION_ID>
  - `role` (string, optional)
    Role that is assigned to the list of principals.

## Response

```json
{
  "name": "string",
  "etag": "string",
  "grant_rules": [
    {
      "principals": [
        "string"
      ],
      "role": "string"
    }
  ]
}
```

