Access-list CRUD Access lists are owner-scoped resources with a stable name and metadata identity. The api_payload field carries NPM-specific access-list fields. Proxy hosts can reference access lists by access_list_ref.