{"openapi":"3.1.0","info":{"title":"gardai labs","description":"Enterprise AI governance platform for authorizing, auditing, and enforcing AI agent policies","version":"1.0.0"},"paths":{"/systems":{"post":{"tags":["AI system registry"],"summary":"Create","description":"Requires the `systems:write` permission.\n\nRegister an AI system. Nothing is governed until it is registered, and the caller's tenant is bound to it here.","operationId":"create_systems_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AISystemCreate"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AISystemRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:write"},"get":{"tags":["AI system registry"],"summary":"List All","description":"Requires the `systems:read` permission.\n\nList the AI systems in the caller's organization.","operationId":"list_all_systems_get","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/AISystemRead"},"title":"Response List All Systems Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:read"}},"/systems/{system_id}":{"get":{"tags":["AI system registry"],"summary":"Get One","description":"Requires the `systems:read` permission.\n\nRead one AI system. A system in another tenant answers as if it does not exist.","operationId":"get_one_systems__system_id__get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AISystemRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:read"},"patch":{"tags":["AI system registry"],"summary":"Update","description":"Requires the `systems:write` permission.\n\nAmend a registration. Promotion to production is refused unless the latest evaluation passed.","operationId":"update_systems__system_id__patch","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AISystemUpdate"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AISystemRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:write"},"delete":{"tags":["AI system registry"],"summary":"Delete","description":"Requires the `systems:delete` permission.\n\nRemove a registration. Its audit evidence is append-only and stays.","operationId":"delete_systems__system_id__delete","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"204":{"description":"Successful Response"},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:delete"}},"/systems/{system_id}/tools":{"put":{"tags":["AI system registry"],"summary":"Declare","description":"Requires the `systems:write` permission.\n\nDeclare a tool's argument contract. Calls are validated against this schema before a model is reached.","operationId":"declare_systems__system_id__tools_put","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ToolDefinitionCreate"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ToolDefinitionRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:write"},"get":{"tags":["AI system registry"],"summary":"List Tool Contracts","description":"Requires the `systems:read` permission.\n\nList the tool contracts declared for this system.","operationId":"list_tool_contracts_systems__system_id__tools_get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ToolDefinitionRead"},"title":"Response List Tool Contracts Systems  System Id  Tools Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"systems:read"}},"/policies/{system_id}":{"get":{"tags":["Policies"],"summary":"Get Effective","description":"Requires the `policies:read` permission.\n\nResolve the controls in force for this system, after risk tier and organization overrides.","operationId":"get_effective_policies__system_id__get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/EffectivePolicy"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"policies:read"}},"/evaluations/{system_id}":{"post":{"tags":["Evaluation gates"],"summary":"Submit","description":"Requires the `evaluations:write` permission.\n\nSubmit detector coverage as release-gate evidence. The verdict is derived from the metrics; a status sent by the caller is overwritten.","operationId":"submit_evaluations__system_id__post","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/EvaluationSubmission"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/EvaluationCoverageRow-Output"},"title":"Response Submit Evaluations  System Id  Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"evaluations:write"},"get":{"tags":["Evaluation gates"],"summary":"History","description":"Requires the `evaluations:read` permission.\n\nEvery evaluation run recorded for this system, newest first.","operationId":"history_evaluations__system_id__get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/EvaluationRunRead"},"title":"Response History Evaluations  System Id  Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"evaluations:read"}},"/evaluations/{system_id}/run":{"post":{"tags":["Evaluation gates"],"summary":"Run Dataset","description":"Requires the `evaluations:write` permission.\n\nRun a packaged dataset through the detectors and record the result as evidence.","operationId":"run_dataset_evaluations__system_id__run_post","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/EvaluationDatasetRequest"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/EvaluationRunRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"evaluations:write"}},"/v1/chat/completions":{"post":{"tags":["Model gateway"],"summary":"Complete","description":"Requires the `gateway:invoke` permission.\n\nSend a governed request to a model. In shadow mode the response also reports what enforcing would have done.","operationId":"complete_v1_chat_completions_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ChatCompletionRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ChatCompletionResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"gateway:invoke"}},"/audits/{system_id}":{"get":{"tags":["Audit evidence"],"summary":"List For System","description":"Requires the `audits:read` permission.\n\nThe decision records for one system, newest first.","operationId":"list_for_system_audits__system_id__get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/AuditRead"},"title":"Response List For System Audits  System Id  Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"audits:read"}},"/audits/{system_id}/export":{"get":{"tags":["Audit evidence"],"summary":"Export For Siem","description":"Requires the `audits:read` permission.\n\nExport evidence as JSONL or CEF for a SIEM.","operationId":"export_for_siem_audits__system_id__export_get","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"format","in":"query","required":false,"schema":{"type":"string","pattern":"^(cef|jsonl)$","default":"cef","title":"Format"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response"},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"audits:read"}},"/audits/admin/events":{"get":{"tags":["Audit evidence"],"summary":"Administrative Events","description":"Requires the `audits:read` permission.\n\nWho changed the control plane. Scoped to the caller's own tenant.","operationId":"administrative_events_audits_admin_events_get","parameters":[{"name":"operation","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Operation"}},{"name":"actor","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Actor"}},{"name":"resource_id","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Resource Id"}},{"name":"limit","in":"query","required":false,"schema":{"type":"integer","maximum":500,"minimum":1,"default":100,"title":"Limit"}},{"name":"offset","in":"query","required":false,"schema":{"type":"integer","minimum":0,"default":0,"title":"Offset"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/AdminEventRead"},"title":"Response Administrative Events Audits Admin Events Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"audits:read"}},"/audits/integrity/verify":{"get":{"tags":["Audit evidence"],"summary":"Verify Integrity","description":"Requires the `audit-integrity:verify` permission.\n\nRecompute both chains and report the first record that does not reconcile.\n\nDetects after the fact; it cannot prevent a privileged operator from editing\nthe database. Publishing the head digest externally is what would.","operationId":"verify_integrity_audits_integrity_verify_get","parameters":[{"name":"organization_id","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Verify Integrity Audits Integrity Verify Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"audit-integrity:verify"}},"/audits/siem/deliveries":{"get":{"tags":["Audit evidence"],"summary":"Siem Deliveries","description":"Requires the `siem:read` permission.\n\nDelivery state, so a silently failing SIEM is visible rather than assumed.","operationId":"siem_deliveries_audits_siem_deliveries_get","parameters":[{"name":"status","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Status"}},{"name":"limit","in":"query","required":false,"schema":{"type":"integer","maximum":500,"minimum":1,"default":50,"title":"Limit"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Siem Deliveries Audits Siem Deliveries Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"siem:read"}},"/audits/siem/deliveries/{delivery_id}/replay":{"post":{"tags":["Audit evidence"],"summary":"Replay Delivery","description":"Requires the `siem:replay` permission.\n\nRequeue a dead-lettered event once its destination is healthy again.","operationId":"replay_delivery_audits_siem_deliveries__delivery_id__replay_post","parameters":[{"name":"delivery_id","in":"path","required":true,"schema":{"type":"string","format":"uuid","title":"Delivery Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Replay Delivery Audits Siem Deliveries  Delivery Id  Replay Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"siem:replay"}},"/v1/authorize":{"post":{"tags":["Agent authorization"],"summary":"Authorize","description":"Requires the `authorize:call` permission.\n\nAsk for a policy decision without sending model traffic through gardai labs. The decision is audited either way.","operationId":"authorize_v1_authorize_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuthorizationRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuthorizationDecision"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"authorize:call"}},"/v1/inspect":{"post":{"tags":["Agent authorization"],"summary":"Inspect","description":"Requires the `authorize:call` permission.\n\nCheck model input or output against the system's policy, without calling a model.\n\n`direction: input` runs prompt-injection detection and sensitive-data\nredaction on what is about to be sent; `direction: output` runs\nharmful-content classification and redaction on what came back. These are\nthe detectors `/v1/chat/completions` runs, applied only for the controls the\nsystem's risk tier requires.\n\nIn `enforce` mode the decision is `deny` (do not use the content), `redact`\n(use `redacted_messages` instead) or `allow`. In `shadow` mode the content is\nalways allowed and the decision says what enforcing would have done\n(`would_deny`, `would_redact`). Every decision is written to the audit trail;\nthe message text is not.","operationId":"inspect_v1_inspect_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InspectionRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/InspectionDecision"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"authorize:call"}},"/v1/audit-events":{"post":{"tags":["Audit evidence"],"summary":"Record Audit Events","description":"Requires the `audit-events:write` permission.\n\nAppend runtime events (a model or tool call and how it ended) to the audit trail.\n\nEach event is chained into the same tamper-evident trail as gardai's own\ndecisions, under the tenant of the system it names; a system outside the\ncaller's tenant is refused as not found. A list is written atomically: if\nany event is refused, none is recorded. Records carry `action_taken:\nrecorded`, distinguishing what a runtime reported from what gardai decided.","operationId":"record_audit_events_v1_audit_events_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"anyOf":[{"$ref":"#/components/schemas/AuditEventCreate"},{"type":"array","items":{"$ref":"#/components/schemas/AuditEventCreate"},"minItems":1,"maxItems":100}],"description":"One event, or a list of 1 to 100.","title":"Payload"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuditEventsAccepted"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"audit-events:write"}},"/v1/approvals":{"post":{"tags":["Approvals"],"summary":"Request Approval","description":"Requires the `approvals:request` permission.\n\nRaise an approval for a tool that requires one. It is bound to the exact arguments and expires.","operationId":"request_approval_v1_approvals_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalCreate"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"approvals:request"}},"/v1/approvals/{approval_id}":{"get":{"tags":["Approvals"],"summary":"Read","description":"Requires the `approvals:read` permission.\n\nRead one approval and its current status.","operationId":"read_v1_approvals__approval_id__get","parameters":[{"name":"approval_id","in":"path","required":true,"schema":{"type":"string","format":"uuid","title":"Approval Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"approvals:read"}},"/v1/approvals/{approval_id}/approve":{"post":{"tags":["Approvals"],"summary":"Approve","description":"Requires the `approvals:decide` permission.\n\nClear an approval. The approver must be someone other than the requester.","operationId":"approve_v1_approvals__approval_id__approve_post","parameters":[{"name":"approval_id","in":"path","required":true,"schema":{"type":"string","format":"uuid","title":"Approval Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalDecision"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"approvals:decide"}},"/v1/approvals/{approval_id}/reject":{"post":{"tags":["Approvals"],"summary":"Reject","description":"Requires the `approvals:decide` permission.\n\nRefuse an approval. A decided approval cannot be decided again.","operationId":"reject_v1_approvals__approval_id__reject_post","parameters":[{"name":"approval_id","in":"path","required":true,"schema":{"type":"string","format":"uuid","title":"Approval Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalDecision"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApprovalRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"approvals:decide"}},"/v1/notifications":{"get":{"tags":["notifications"],"summary":"List Notifications","description":"Requires the `notifications:read` permission.\n\nThe delivery queue, newest first.","operationId":"list_notifications_v1_notifications_get","parameters":[{"name":"status","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Status"}},{"name":"event_type","in":"query","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Event Type"}},{"name":"limit","in":"query","required":false,"schema":{"type":"integer","maximum":500,"minimum":1,"default":50,"title":"Limit"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response List Notifications V1 Notifications Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"notifications:read"}},"/v1/notifications/{notification_id}/retry":{"post":{"tags":["notifications"],"summary":"Retry Notification","description":"Requires the `notifications:retry` permission.\n\nRequeue a dead message. Delivered ones are left alone.","operationId":"retry_notification_v1_notifications__notification_id__retry_post","parameters":[{"name":"notification_id","in":"path","required":true,"schema":{"type":"string","format":"uuid","title":"Notification Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Retry Notification V1 Notifications  Notification Id  Retry Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"notifications:retry"}},"/v1/red-team/corpus":{"get":{"tags":["red-team"],"summary":"Corpus","description":"Requires the `evaluations:read` permission.\n\nThe attacks that will be run, and the control each one targets.","operationId":"corpus_v1_red_team_corpus_get","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Corpus V1 Red Team Corpus Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"evaluations:read"}},"/v1/red-team/{system_id}":{"post":{"tags":["red-team"],"summary":"Run","description":"Requires the `evaluations:write` permission.\n\nRun every attack against one system's own resolved controls.\n\nNothing reaches a model provider: these are attacks, and having one answered\nproves nothing that inspecting it does not. A case targeting a control the\nsystem is not required to run is reported as out of scope, not as a failure.","operationId":"run_v1_red_team__system_id__post","parameters":[{"name":"system_id","in":"path","required":true,"schema":{"type":"string","title":"System Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Run V1 Red Team  System Id  Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"evaluations:write"}},"/organizations":{"post":{"tags":["Organizations"],"summary":"Create","description":"Requires the `organizations:write` permission.\n\nOnboard a tenant, with its own enforcement default, thresholds and quota.","operationId":"create_organizations_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationCreate"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"},"get":{"tags":["Organizations"],"summary":"List All","description":"Requires the `organizations:read` permission.\n\nList organizations. A tenant-bound caller sees only its own.","operationId":"list_all_organizations_get","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/OrganizationRead"},"title":"Response List All Organizations Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"}},"/organizations/{organization_id}":{"get":{"tags":["Organizations"],"summary":"Get One","description":"Requires the `organizations:read` permission.\n\nRead one organization.","operationId":"get_one_organizations__organization_id__get","parameters":[{"name":"organization_id","in":"path","required":true,"schema":{"type":"string","title":"Organization Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"},"patch":{"tags":["Organizations"],"summary":"Update","description":"Requires the `organizations:write` permission.\n\nAmend a tenant's configuration. Setting status to suspended stops all of its traffic at once.","operationId":"update_organizations__organization_id__patch","parameters":[{"name":"organization_id","in":"path","required":true,"schema":{"type":"string","title":"Organization Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationUpdate"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/organizations/{organization_id}/configuration":{"get":{"tags":["Organizations"],"summary":"Configuration","description":"Requires the `organizations:read` permission.\n\nShow what is actually in force, not just what was overridden.","operationId":"configuration_organizations__organization_id__configuration_get","parameters":[{"name":"organization_id","in":"path","required":true,"schema":{"type":"string","title":"Organization Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigurationRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"}},"/auth/login":{"post":{"tags":["Session"],"summary":"Login","description":"Exchange a verified credential for a session cookie.\n\nThe credential is presented once, here. Every later request carries the\ncookie instead, so the console never has to hold the secret.","operationId":"login_auth_login_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/session":{"get":{"tags":["Session"],"summary":"Current","description":"Who the caller is, what they may do, and which tenants they can act for.","operationId":"current_auth_session_get","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/logout":{"post":{"tags":["Session"],"summary":"Logout","description":"Revoke the session server-side, then clear the cookie.\n\nRevoking first matters: clearing only the cookie would leave a token that\nstill works for anyone who captured it.","operationId":"logout_auth_logout_post","responses":{"204":{"description":"Successful Response"}}}},"/auth/session/organization":{"put":{"tags":["Session"],"summary":"Choose Organization","description":"Switch which organization the session acts for, among those the caller may reach.","operationId":"choose_organization_auth_session_organization_put","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrganizationSelection"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/password/login":{"post":{"tags":["Session"],"summary":"Password Login","description":"Sign in with an email and password, and receive a session cookie.\n\nAccounts are the console users stored in the database (Argon2id hashes).\nThe hardcoded demo users are accepted only when DEMO_MODE=true.","operationId":"password_login_auth_password_login_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PasswordLogin"}}},"required":true},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/password/reset":{"post":{"tags":["Session"],"summary":"Request Password Reset","description":"Begin a reset.\n\nAlways answers the same way. Whether an address has an account is precisely\nwhat an attacker is probing for, so the response cannot depend on it.","operationId":"request_password_reset_auth_password_reset_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PasswordResetRequest"}}},"required":true},"responses":{"202":{"description":"Successful Response","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object","title":"Response Request Password Reset Auth Password Reset Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/password/reset/confirm":{"post":{"tags":["Session"],"summary":"Confirm Password Reset","description":"Set a new password and end every existing session for that user.","operationId":"confirm_password_reset_auth_password_reset_confirm_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PasswordResetConfirm"}}},"required":true},"responses":{"204":{"description":"Successful Response"},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/password/change":{"post":{"tags":["Session"],"summary":"Change Own Password","description":"Change your own password. Every existing session for the account is revoked.","operationId":"change_own_password_auth_password_change_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PasswordChange"}}}},"responses":{"204":{"description":"Successful Response"},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/auth/users":{"post":{"tags":["Session"],"summary":"Add User","description":"Requires the `organizations:write` permission.\n\nCreate a console user. Tenant-bound callers may only add to their own.","operationId":"add_user_auth_users_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UserCreate"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/UserRead"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/health/status":{"get":{"tags":["Status"],"summary":"Get Status","description":"Application status: version, licence and which feature switches are on.\n\nUnauthenticated, so it carries only booleans from Settings.features(),\nnever a URL, token or other configured value.","operationId":"get_status_health_status_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object","title":"Response Get Status Health Status Get"}}}}}}},"/health/license":{"get":{"tags":["Status"],"summary":"License Info","description":"Get current license status","operationId":"license_info_health_license_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object","title":"Response License Info Health License Get"}}}}}}},"/v1/webhooks":{"post":{"tags":["Webhooks"],"summary":"Create Webhook","description":"Requires the `organizations:write` permission.\n\nCreate a new SIEM webhook configuration","operationId":"create_webhook_v1_webhooks_post","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateWebhookRequest"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebhookConfig"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"},"get":{"tags":["Webhooks"],"summary":"List Webhooks","description":"Requires the `organizations:read` permission.\n\nList all webhooks for the organization","operationId":"list_webhooks_v1_webhooks_get","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/WebhookConfig"},"title":"Response List Webhooks V1 Webhooks Get"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"}},"/v1/webhooks/{webhook_id}":{"get":{"tags":["Webhooks"],"summary":"Get Webhook","description":"Requires the `organizations:read` permission.\n\nGet a specific webhook configuration","operationId":"get_webhook_v1_webhooks__webhook_id__get","parameters":[{"name":"webhook_id","in":"path","required":true,"schema":{"type":"string","title":"Webhook Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebhookConfig"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"},"put":{"tags":["Webhooks"],"summary":"Update Webhook","description":"Requires the `organizations:write` permission.\n\nUpdate a webhook configuration","operationId":"update_webhook_v1_webhooks__webhook_id__put","parameters":[{"name":"webhook_id","in":"path","required":true,"schema":{"type":"string","title":"Webhook Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateWebhookRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebhookConfig"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"},"delete":{"tags":["Webhooks"],"summary":"Delete Webhook","description":"Requires the `organizations:write` permission.\n\nDelete a webhook configuration","operationId":"delete_webhook_v1_webhooks__webhook_id__delete","parameters":[{"name":"webhook_id","in":"path","required":true,"schema":{"type":"string","title":"Webhook Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"204":{"description":"Successful Response"},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/v1/webhooks/{webhook_id}/test":{"post":{"tags":["Webhooks"],"summary":"Test Webhook","description":"Requires the `organizations:read` permission.\n\nTest a webhook by sending a test event","operationId":"test_webhook_v1_webhooks__webhook_id__test_post","parameters":[{"name":"webhook_id","in":"path","required":true,"schema":{"type":"string","title":"Webhook Id"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebhookTestRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Test Webhook V1 Webhooks  Webhook Id  Test Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:read"}},"/v1/webhooks/splunk/configure":{"post":{"tags":["Webhooks"],"summary":"Configure Splunk","description":"Requires the `organizations:write` permission.\n\nConfigure Splunk integration","operationId":"configure_splunk_v1_webhooks_splunk_configure_post","parameters":[{"name":"splunk_host","in":"query","required":true,"schema":{"type":"string","title":"Splunk Host"}},{"name":"splunk_port","in":"query","required":true,"schema":{"type":"integer","title":"Splunk Port"}},{"name":"hec_token","in":"query","required":true,"schema":{"type":"string","title":"Hec Token"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Configure Splunk V1 Webhooks Splunk Configure Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/v1/webhooks/sentinel/configure":{"post":{"tags":["Webhooks"],"summary":"Configure Sentinel","description":"Requires the `organizations:write` permission.\n\nConfigure Microsoft Sentinel integration","operationId":"configure_sentinel_v1_webhooks_sentinel_configure_post","parameters":[{"name":"workspace_id","in":"query","required":true,"schema":{"type":"string","title":"Workspace Id"}},{"name":"shared_key","in":"query","required":true,"schema":{"type":"string","title":"Shared Key"}},{"name":"log_type","in":"query","required":false,"schema":{"type":"string","default":"GardaiSecurityEvents","title":"Log Type"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Configure Sentinel V1 Webhooks Sentinel Configure Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/v1/webhooks/slack/configure":{"post":{"tags":["Webhooks"],"summary":"Configure Slack","description":"Requires the `organizations:write` permission.\n\nConfigure Slack approval notifications","operationId":"configure_slack_v1_webhooks_slack_configure_post","parameters":[{"name":"workspace_id","in":"query","required":true,"schema":{"type":"string","title":"Workspace Id"}},{"name":"bot_token","in":"query","required":true,"schema":{"type":"string","title":"Bot Token"}},{"name":"authorization","in":"header","required":false,"schema":{"type":"string","default":"","title":"Authorization"}},{"name":"x-api-key","in":"header","required":false,"schema":{"type":"string","default":"","title":"X-Api-Key"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"title":"Response Configure Slack V1 Webhooks Slack Configure Post"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"x-gardai-permission":"organizations:write"}},"/health/live":{"get":{"tags":["Operations"],"summary":"Health","description":"Liveness only: is the process running. Never touches a dependency.","operationId":"health_health_live_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"additionalProperties":{"type":"string"},"type":"object","title":"Response Health Health Live Get"}}}}}}},"/health":{"get":{"tags":["Operations"],"summary":"Health","description":"Liveness only: is the process running. Never touches a dependency.","operationId":"health_health_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"additionalProperties":{"type":"string"},"type":"object","title":"Response Health Health Get"}}}}}}},"/health/security":{"get":{"tags":["Operations"],"summary":"Security Health","description":"Security status: verify license, code integrity, and security checks.","operationId":"security_health_health_security_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{}}}}}}},"/health/ready":{"get":{"tags":["Operations"],"summary":"Readiness","description":"Readiness: can this replica actually serve a request.\n\nKubernetes routes on this, so it fails when a dependency is unreachable\nrather than reporting healthy and black-holing traffic.","operationId":"readiness_health_ready_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{}}}}}}}},"components":{"schemas":{"AISystemCreate":{"properties":{"system_id":{"type":"string","pattern":"^[a-zA-Z0-9][a-zA-Z0-9_.-]{1,127}$","title":"System Id"},"organization_id":{"anyOf":[{"type":"string","maxLength":128},{"type":"null"}],"title":"Organization Id"},"owner":{"type":"string","maxLength":256,"minLength":1,"title":"Owner"},"business_purpose":{"type":"string","maxLength":4000,"minLength":1,"title":"Business Purpose"},"models":{"items":{"type":"string"},"type":"array","minItems":1,"title":"Models"},"data_classes":{"items":{"type":"string"},"type":"array","title":"Data Classes"},"tools":{"items":{"type":"string"},"type":"array","title":"Tools"},"risk_tier":{"$ref":"#/components/schemas/RiskTier"},"jurisdictions":{"items":{"type":"string"},"type":"array","title":"Jurisdictions"},"deployment":{"$ref":"#/components/schemas/Deployment","default":"development"},"is_rag_backed":{"type":"boolean","title":"Is Rag Backed","default":false},"enforcement_mode":{"$ref":"#/components/schemas/EnforcementMode","default":"shadow"},"last_reviewed_at":{"type":"string","format":"date-time","title":"Last Reviewed At"},"policy_version":{"type":"string","maxLength":64,"minLength":1,"title":"Policy Version","default":"1.0"},"onboarding_evidence":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Onboarding Evidence"}},"type":"object","required":["system_id","owner","business_purpose","models","risk_tier"],"title":"AISystemCreate"},"AISystemRead":{"properties":{"system_id":{"type":"string","pattern":"^[a-zA-Z0-9][a-zA-Z0-9_.-]{1,127}$","title":"System Id"},"organization_id":{"anyOf":[{"type":"string","maxLength":128},{"type":"null"}],"title":"Organization Id"},"owner":{"type":"string","maxLength":256,"minLength":1,"title":"Owner"},"business_purpose":{"type":"string","maxLength":4000,"minLength":1,"title":"Business Purpose"},"models":{"items":{"type":"string"},"type":"array","minItems":1,"title":"Models"},"data_classes":{"items":{"type":"string"},"type":"array","title":"Data Classes"},"tools":{"items":{"type":"string"},"type":"array","title":"Tools"},"risk_tier":{"$ref":"#/components/schemas/RiskTier"},"jurisdictions":{"items":{"type":"string"},"type":"array","title":"Jurisdictions"},"deployment":{"$ref":"#/components/schemas/Deployment","default":"development"},"is_rag_backed":{"type":"boolean","title":"Is Rag Backed","default":false},"enforcement_mode":{"$ref":"#/components/schemas/EnforcementMode","default":"shadow"},"last_reviewed_at":{"type":"string","format":"date-time","title":"Last Reviewed At"},"policy_version":{"type":"string","maxLength":64,"minLength":1,"title":"Policy Version","default":"1.0"},"onboarding_evidence":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Onboarding Evidence"},"registered_at":{"type":"string","format":"date-time","title":"Registered At"},"evaluation_status":{"$ref":"#/components/schemas/EvaluationStatus"}},"type":"object","required":["system_id","owner","business_purpose","models","risk_tier","registered_at","evaluation_status"],"title":"AISystemRead"},"AISystemUpdate":{"properties":{"owner":{"anyOf":[{"type":"string","maxLength":256,"minLength":1},{"type":"null"}],"title":"Owner"},"business_purpose":{"anyOf":[{"type":"string","maxLength":4000,"minLength":1},{"type":"null"}],"title":"Business Purpose"},"models":{"anyOf":[{"items":{"type":"string"},"type":"array","minItems":1},{"type":"null"}],"title":"Models"},"data_classes":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Data Classes"},"tools":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Tools"},"risk_tier":{"anyOf":[{"$ref":"#/components/schemas/RiskTier"},{"type":"null"}]},"jurisdictions":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Jurisdictions"},"deployment":{"anyOf":[{"$ref":"#/components/schemas/Deployment"},{"type":"null"}]},"is_rag_backed":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Is Rag Backed"},"enforcement_mode":{"anyOf":[{"$ref":"#/components/schemas/EnforcementMode"},{"type":"null"}]},"last_reviewed_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Last Reviewed At"},"policy_version":{"anyOf":[{"type":"string","maxLength":64,"minLength":1},{"type":"null"}],"title":"Policy Version"},"onboarding_evidence":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Onboarding Evidence"}},"type":"object","title":"AISystemUpdate"},"AdminEventRead":{"properties":{"event_id":{"type":"string","format":"uuid","title":"Event Id"},"timestamp":{"type":"string","format":"date-time","title":"Timestamp"},"request_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Request Id"},"actor_subject":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Actor Subject"},"actor_method":{"type":"string","title":"Actor Method"},"actor_roles":{"items":{"type":"string"},"type":"array","title":"Actor Roles"},"organization_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"},"operation":{"type":"string","title":"Operation"},"resource_type":{"type":"string","title":"Resource Type"},"resource_id":{"type":"string","title":"Resource Id"},"before":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Before"},"after":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"After"},"result":{"type":"string","title":"Result"},"detail":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Detail"}},"type":"object","required":["event_id","timestamp","request_id","actor_subject","actor_method","actor_roles","organization_id","operation","resource_type","resource_id","before","after","result","detail"],"title":"AdminEventRead"},"ApprovalCreate":{"properties":{"system_id":{"type":"string","title":"System Id"},"tool_name":{"type":"string","maxLength":128,"title":"Tool Name"},"arguments":{"additionalProperties":true,"type":"object","title":"Arguments"},"requester":{"type":"string","maxLength":256,"minLength":1,"title":"Requester"}},"type":"object","required":["system_id","tool_name","requester"],"title":"ApprovalCreate"},"ApprovalDecision":{"properties":{"approver":{"type":"string","maxLength":256,"minLength":1,"title":"Approver"}},"type":"object","required":["approver"],"title":"ApprovalDecision"},"ApprovalRead":{"properties":{"approval_id":{"type":"string","format":"uuid","title":"Approval Id"},"system_id":{"type":"string","title":"System Id"},"tool_name":{"type":"string","title":"Tool Name"},"action_hash":{"type":"string","title":"Action Hash"},"requester":{"type":"string","title":"Requester"},"approver":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Approver"},"status":{"type":"string","enum":["pending","approved","rejected","expired","consumed"],"title":"Status"},"created_at":{"type":"string","format":"date-time","title":"Created At"},"expires_at":{"type":"string","format":"date-time","title":"Expires At"},"decided_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Decided At"},"consumed_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Consumed At"}},"type":"object","required":["approval_id","system_id","tool_name","action_hash","requester","approver","status","created_at","expires_at","decided_at","consumed_at"],"title":"ApprovalRead"},"AuditEventCreate":{"properties":{"system_id":{"type":"string","maxLength":128,"minLength":1,"title":"System Id"},"kind":{"type":"string","enum":["model","tool"],"title":"Kind"},"name":{"type":"string","maxLength":256,"minLength":1,"title":"Name"},"subject":{"anyOf":[{"type":"string","maxLength":256},{"type":"null"}],"title":"Subject"},"decision":{"anyOf":[{"type":"string","maxLength":64},{"type":"null"}],"title":"Decision"},"outcome":{"additionalProperties":true,"type":"object","title":"Outcome"},"occurred_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Occurred At"}},"type":"object","required":["system_id","kind","name"],"title":"AuditEventCreate","description":"Something a runtime did (a model or tool call) and how it ended."},"AuditEventsAccepted":{"properties":{"accepted":{"type":"integer","title":"Accepted"},"audit_ids":{"items":{"type":"string","format":"uuid"},"type":"array","title":"Audit Ids"}},"type":"object","required":["accepted","audit_ids"],"title":"AuditEventsAccepted"},"AuditRead":{"properties":{"audit_id":{"type":"string","format":"uuid","title":"Audit Id"},"system_id":{"type":"string","title":"System Id"},"timestamp":{"type":"string","format":"date-time","title":"Timestamp"},"policy_version":{"type":"string","title":"Policy Version"},"detectors_run":{"items":{"additionalProperties":true,"type":"object"},"type":"array","title":"Detectors Run"},"enforcement_mode":{"$ref":"#/components/schemas/EnforcementMode"},"action_taken":{"type":"string","enum":["allowed","redacted","blocked","recorded"],"title":"Action Taken"},"latency_ms":{"type":"number","title":"Latency Ms"}},"type":"object","required":["audit_id","system_id","timestamp","policy_version","detectors_run","enforcement_mode","action_taken","latency_ms"],"title":"AuditRead"},"AuthorizationDecision":{"properties":{"decision_id":{"type":"string","format":"uuid","title":"Decision Id"},"system_id":{"type":"string","title":"System Id"},"allowed":{"type":"boolean","title":"Allowed"},"denied_tools":{"items":{"type":"string"},"type":"array","title":"Denied Tools"},"enforcement_mode":{"$ref":"#/components/schemas/EnforcementMode"},"decision":{"type":"string","enum":["allow","deny","would_deny","require_approval"],"title":"Decision"},"policy_version":{"type":"string","title":"Policy Version"},"violations":{"items":{"$ref":"#/components/schemas/ToolViolation"},"type":"array","title":"Violations"},"pending_approvals":{"items":{"$ref":"#/components/schemas/PendingApproval"},"type":"array","title":"Pending Approvals"}},"type":"object","required":["decision_id","system_id","allowed","denied_tools","enforcement_mode","decision","policy_version"],"title":"AuthorizationDecision"},"AuthorizationRequest":{"properties":{"system_id":{"type":"string","title":"System Id"},"requested_tool_calls":{"items":{"$ref":"#/components/schemas/ToolRequest"},"type":"array","minItems":1,"title":"Requested Tool Calls"},"subject":{"anyOf":[{"type":"string","maxLength":256},{"type":"null"}],"title":"Subject"},"context":{"additionalProperties":true,"type":"object","title":"Context"},"approval_id":{"anyOf":[{"type":"string","format":"uuid"},{"type":"null"}],"title":"Approval Id"}},"type":"object","required":["system_id","requested_tool_calls"],"title":"AuthorizationRequest"},"ChatChoice":{"properties":{"index":{"type":"integer","title":"Index","default":0},"message":{"$ref":"#/components/schemas/ChatMessage"},"finish_reason":{"type":"string","title":"Finish Reason","default":"stop"}},"type":"object","required":["message"],"title":"ChatChoice"},"ChatCompletionRequest":{"properties":{"system_id":{"type":"string","title":"System Id"},"model":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Model"},"messages":{"items":{"$ref":"#/components/schemas/ChatMessage"},"type":"array","maxItems":200,"minItems":1,"title":"Messages"},"context":{"anyOf":[{"type":"string","maxLength":200000},{"type":"null"}],"title":"Context"},"requested_tool_calls":{"items":{"$ref":"#/components/schemas/ToolRequest"},"type":"array","maxItems":32,"title":"Requested Tool Calls"},"tool_results":{"items":{"$ref":"#/components/schemas/ToolResult"},"type":"array","maxItems":32,"title":"Tool Results"},"temperature":{"anyOf":[{"type":"number","maximum":2.0,"minimum":0.0},{"type":"null"}],"title":"Temperature"},"max_tokens":{"anyOf":[{"type":"integer","exclusiveMinimum":0.0},{"type":"null"}],"title":"Max Tokens"}},"type":"object","required":["system_id","messages"],"title":"ChatCompletionRequest"},"ChatCompletionResponse":{"properties":{"id":{"type":"string","title":"Id"},"object":{"type":"string","title":"Object","default":"chat.completion"},"created":{"type":"integer","title":"Created"},"model":{"type":"string","title":"Model"},"choices":{"items":{"$ref":"#/components/schemas/ChatChoice"},"type":"array","title":"Choices"},"governance":{"additionalProperties":true,"type":"object","title":"Governance"}},"type":"object","required":["id","created","model","choices","governance"],"title":"ChatCompletionResponse"},"ChatMessage":{"properties":{"role":{"type":"string","enum":["system","user","assistant","tool"],"title":"Role"},"content":{"type":"string","maxLength":32000,"title":"Content"}},"type":"object","required":["role","content"],"title":"ChatMessage"},"ConfigurationRead":{"properties":{"organization_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"},"enforcement_default":{"type":"string","title":"Enforcement Default"},"grounding_threshold":{"type":"number","title":"Grounding Threshold"},"approval_ttl_seconds":{"type":"integer","title":"Approval Ttl Seconds"},"oidc_issuer":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Issuer"},"oidc_audience":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Audience"},"policy_overrides":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Policy Overrides"},"request_quota_per_minute":{"type":"integer","title":"Request Quota Per Minute"}},"type":"object","required":["organization_id","enforcement_default","grounding_threshold","approval_ttl_seconds","oidc_issuer","oidc_audience","policy_overrides","request_quota_per_minute"],"title":"ConfigurationRead","description":"The values in force for a tenant, after overrides resolve against defaults."},"CreateWebhookRequest":{"properties":{"name":{"type":"string","title":"Name"},"url":{"type":"string","maxLength":2083,"minLength":1,"format":"uri","title":"Url"},"webhook_type":{"type":"string","title":"Webhook Type","default":"custom"},"event_types":{"items":{"type":"string"},"type":"array","title":"Event Types","default":["approval.requested","approval.decided"]},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"title":"Headers"}},"type":"object","required":["name","url"],"title":"CreateWebhookRequest","description":"Request to create a webhook"},"Deployment":{"type":"string","enum":["development","staging","production"],"title":"Deployment"},"EffectivePolicy":{"properties":{"system_id":{"type":"string","title":"System Id"},"risk_tier":{"$ref":"#/components/schemas/RiskTier"},"policy_version":{"type":"string","title":"Policy Version"},"required_controls":{"items":{"type":"string"},"type":"array","title":"Required Controls"},"precedence":{"items":{"type":"string"},"type":"array","title":"Precedence"}},"type":"object","required":["system_id","risk_tier","policy_version","required_controls"],"title":"EffectivePolicy"},"EnforcementMode":{"type":"string","enum":["shadow","enforce"],"title":"EnforcementMode"},"EvaluationCase":{"properties":{"risk_category":{"type":"string","enum":["pii","prompt-injection","harmful-output"],"title":"Risk Category"},"text":{"type":"string","title":"Text"},"expected_flagged":{"type":"boolean","title":"Expected Flagged"}},"type":"object","required":["risk_category","text","expected_flagged"],"title":"EvaluationCase"},"EvaluationCoverageRow-Input":{"properties":{"risk_category":{"type":"string","title":"Risk Category"},"dataset":{"type":"string","title":"Dataset"},"cases":{"type":"integer","minimum":0.0,"title":"Cases"},"recall":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Recall"},"precision":{"anyOf":[{"type":"number","maximum":1.0,"minimum":0.0},{"type":"null"}],"title":"Precision"},"required":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Required"},"status":{"type":"string","enum":["pass","fail"],"title":"Status","default":"fail"}},"type":"object","required":["risk_category","dataset","cases","recall","required"],"title":"EvaluationCoverageRow","description":"One risk category's coverage.\n\n`status` is derived from the reported metrics by the server and ignored on\ninput: a submitter that could declare its own verdict could clear the\nproduction gate with any numbers at all."},"EvaluationCoverageRow-Output":{"properties":{"risk_category":{"type":"string","title":"Risk Category"},"dataset":{"type":"string","title":"Dataset"},"cases":{"type":"integer","minimum":0.0,"title":"Cases"},"recall":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Recall"},"required":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Required"},"status":{"type":"string","enum":["pass","fail"],"title":"Status","default":"fail"}},"type":"object","required":["risk_category","dataset","cases","recall","required"],"title":"EvaluationCoverageRow","description":"One risk category's coverage.\n\n`status` is derived from the reported metrics by the server and ignored on\ninput: a submitter that could declare its own verdict could clear the\nproduction gate with any numbers at all."},"EvaluationDatasetRequest":{"properties":{"dataset":{"type":"string","maxLength":256,"minLength":1,"title":"Dataset"},"required":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Required","default":0.8},"cases":{"items":{"$ref":"#/components/schemas/EvaluationCase"},"type":"array","minItems":1,"title":"Cases"}},"type":"object","required":["dataset","cases"],"title":"EvaluationDatasetRequest"},"EvaluationRunRead":{"properties":{"run_id":{"type":"string","format":"uuid","title":"Run Id"},"system_id":{"type":"string","title":"System Id"},"created_at":{"type":"string","format":"date-time","title":"Created At"},"status":{"type":"string","enum":["pass","fail"],"title":"Status"},"rows":{"items":{"$ref":"#/components/schemas/EvaluationCoverageRow-Output"},"type":"array","title":"Rows"}},"type":"object","required":["run_id","system_id","created_at","status","rows"],"title":"EvaluationRunRead"},"EvaluationStatus":{"type":"string","enum":["pass","fail","not_evaluated"],"title":"EvaluationStatus"},"EvaluationSubmission":{"properties":{"rows":{"items":{"$ref":"#/components/schemas/EvaluationCoverageRow-Input"},"type":"array","minItems":1,"title":"Rows"}},"type":"object","required":["rows"],"title":"EvaluationSubmission"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"type":"array","title":"Detail"}},"type":"object","title":"HTTPValidationError"},"InspectionDecision":{"properties":{"decision_id":{"type":"string","format":"uuid","title":"Decision Id"},"system_id":{"type":"string","title":"System Id"},"decision":{"type":"string","enum":["allow","redact","deny","would_redact","would_deny"],"title":"Decision"},"allowed":{"type":"boolean","title":"Allowed"},"redacted_messages":{"anyOf":[{"items":{"$ref":"#/components/schemas/ChatMessage"},"type":"array"},{"type":"null"}],"title":"Redacted Messages"},"violations":{"items":{"$ref":"#/components/schemas/InspectionViolation"},"type":"array","title":"Violations"},"enforcement_mode":{"$ref":"#/components/schemas/EnforcementMode"},"policy_version":{"type":"string","title":"Policy Version"},"detectors":{"items":{"additionalProperties":true,"type":"object"},"type":"array","title":"Detectors"}},"type":"object","required":["decision_id","system_id","decision","allowed","enforcement_mode","policy_version"],"title":"InspectionDecision"},"InspectionRequest":{"properties":{"system_id":{"type":"string","maxLength":128,"minLength":1,"title":"System Id"},"direction":{"type":"string","enum":["input","output"],"title":"Direction"},"messages":{"items":{"$ref":"#/components/schemas/ChatMessage"},"type":"array","maxItems":200,"minItems":1,"title":"Messages"},"subject":{"anyOf":[{"type":"string","maxLength":256},{"type":"null"}],"title":"Subject"},"context":{"additionalProperties":true,"type":"object","title":"Context"}},"type":"object","required":["system_id","direction","messages"],"title":"InspectionRequest","description":"Content to check before (input) or after (output) a model call the caller makes itself."},"InspectionViolation":{"properties":{"control":{"type":"string","title":"Control"},"reason":{"type":"string","title":"Reason"},"detail":{"type":"string","title":"Detail"}},"type":"object","required":["control","reason","detail"],"title":"InspectionViolation"},"OrganizationCreate":{"properties":{"organization_id":{"type":"string","pattern":"^[a-z0-9][a-z0-9_-]{1,127}$","title":"Organization Id"},"name":{"type":"string","maxLength":256,"minLength":1,"title":"Name"},"status":{"type":"string","enum":["active","suspended"],"title":"Status","default":"active"},"enforcement_default":{"$ref":"#/components/schemas/EnforcementMode","default":"shadow"},"grounding_threshold":{"anyOf":[{"type":"number","maximum":1.0,"minimum":0.0},{"type":"null"}],"title":"Grounding Threshold"},"approval_ttl_seconds":{"anyOf":[{"type":"integer","maximum":86400.0,"exclusiveMinimum":0.0},{"type":"null"}],"title":"Approval Ttl Seconds"},"oidc_issuer":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Issuer"},"oidc_audience":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Audience"},"policy_overrides":{"anyOf":[{"additionalProperties":{"items":{"type":"string"},"type":"array"},"propertyNames":{"$ref":"#/components/schemas/RiskTier"},"type":"object"},{"type":"null"}],"title":"Policy Overrides"},"request_quota_per_minute":{"anyOf":[{"type":"integer","maximum":1000000.0,"minimum":0.0},{"type":"null"}],"title":"Request Quota Per Minute"}},"type":"object","required":["organization_id","name"],"title":"OrganizationCreate"},"OrganizationRead":{"properties":{"organization_id":{"type":"string","pattern":"^[a-z0-9][a-z0-9_-]{1,127}$","title":"Organization Id"},"name":{"type":"string","maxLength":256,"minLength":1,"title":"Name"},"status":{"type":"string","enum":["active","suspended"],"title":"Status","default":"active"},"enforcement_default":{"$ref":"#/components/schemas/EnforcementMode","default":"shadow"},"grounding_threshold":{"anyOf":[{"type":"number","maximum":1.0,"minimum":0.0},{"type":"null"}],"title":"Grounding Threshold"},"approval_ttl_seconds":{"anyOf":[{"type":"integer","maximum":86400.0,"exclusiveMinimum":0.0},{"type":"null"}],"title":"Approval Ttl Seconds"},"oidc_issuer":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Issuer"},"oidc_audience":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Audience"},"policy_overrides":{"anyOf":[{"additionalProperties":{"items":{"type":"string"},"type":"array"},"propertyNames":{"$ref":"#/components/schemas/RiskTier"},"type":"object"},{"type":"null"}],"title":"Policy Overrides"},"request_quota_per_minute":{"anyOf":[{"type":"integer","maximum":1000000.0,"minimum":0.0},{"type":"null"}],"title":"Request Quota Per Minute"},"created_at":{"type":"string","format":"date-time","title":"Created At"}},"type":"object","required":["organization_id","name","created_at"],"title":"OrganizationRead"},"OrganizationSelection":{"properties":{"organization_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"}},"type":"object","title":"OrganizationSelection"},"OrganizationUpdate":{"properties":{"name":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Name"},"status":{"anyOf":[{"type":"string","enum":["active","suspended"]},{"type":"null"}],"title":"Status"},"enforcement_default":{"anyOf":[{"$ref":"#/components/schemas/EnforcementMode"},{"type":"null"}]},"grounding_threshold":{"anyOf":[{"type":"number","maximum":1.0,"minimum":0.0},{"type":"null"}],"title":"Grounding Threshold"},"approval_ttl_seconds":{"anyOf":[{"type":"integer","maximum":86400.0,"exclusiveMinimum":0.0},{"type":"null"}],"title":"Approval Ttl Seconds"},"oidc_issuer":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Issuer"},"oidc_audience":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Oidc Audience"},"policy_overrides":{"anyOf":[{"additionalProperties":{"items":{"type":"string"},"type":"array"},"propertyNames":{"$ref":"#/components/schemas/RiskTier"},"type":"object"},{"type":"null"}],"title":"Policy Overrides"},"request_quota_per_minute":{"anyOf":[{"type":"integer","maximum":1000000.0,"minimum":0.0},{"type":"null"}],"title":"Request Quota Per Minute"}},"type":"object","title":"OrganizationUpdate"},"PasswordChange":{"properties":{"current_password":{"type":"string","maxLength":1024,"minLength":1,"title":"Current Password"},"new_password":{"type":"string","maxLength":1024,"minLength":1,"title":"New Password"}},"type":"object","required":["current_password","new_password"],"title":"PasswordChange"},"PasswordLogin":{"properties":{"email":{"type":"string","maxLength":320,"minLength":3,"title":"Email"},"password":{"type":"string","maxLength":1024,"minLength":1,"title":"Password"}},"type":"object","required":["email","password"],"title":"PasswordLogin"},"PasswordResetConfirm":{"properties":{"token":{"type":"string","maxLength":256,"minLength":10,"title":"Token"},"new_password":{"type":"string","maxLength":1024,"minLength":1,"title":"New Password"}},"type":"object","required":["token","new_password"],"title":"PasswordResetConfirm"},"PasswordResetRequest":{"properties":{"email":{"type":"string","maxLength":320,"minLength":3,"title":"Email"}},"type":"object","required":["email"],"title":"PasswordResetRequest"},"PendingApproval":{"properties":{"tool_name":{"type":"string","title":"Tool Name"},"action_hash":{"type":"string","title":"Action Hash"}},"type":"object","required":["tool_name","action_hash"],"title":"PendingApproval","description":"A consequential call the model proposed that a second person must clear."},"RiskTier":{"type":"string","enum":["low","medium","high","critical"],"title":"RiskTier"},"SessionRead":{"properties":{"subject":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Subject"},"method":{"type":"string","title":"Method"},"roles":{"items":{"type":"string"},"type":"array","title":"Roles"},"permissions":{"items":{"type":"string"},"type":"array","title":"Permissions"},"home_organization":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Home Organization"},"active_organization":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Active Organization"},"available_organizations":{"items":{"type":"string"},"type":"array","title":"Available Organizations"},"expires_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Expires At"},"must_change_password":{"type":"boolean","title":"Must Change Password","default":false}},"type":"object","required":["subject","method","roles","permissions","home_organization","active_organization","available_organizations","expires_at"],"title":"SessionRead"},"ToolDefinitionCreate":{"properties":{"name":{"type":"string","maxLength":128,"minLength":1,"pattern":"^[a-zA-Z0-9][a-zA-Z0-9_.-]*$","title":"Name"},"json_schema":{"additionalProperties":true,"type":"object","title":"Json Schema"},"risk_level":{"type":"string","enum":["low","medium","high"],"title":"Risk Level","default":"low"},"requires_approval":{"type":"boolean","title":"Requires Approval","default":false}},"type":"object","required":["name","json_schema"],"title":"ToolDefinitionCreate"},"ToolDefinitionRead":{"properties":{"system_id":{"type":"string","title":"System Id"},"name":{"type":"string","title":"Name"},"json_schema":{"additionalProperties":true,"type":"object","title":"Json Schema"},"risk_level":{"type":"string","title":"Risk Level"},"requires_approval":{"type":"boolean","title":"Requires Approval"}},"type":"object","required":["system_id","name","json_schema","risk_level","requires_approval"],"title":"ToolDefinitionRead"},"ToolRequest":{"properties":{"name":{"type":"string","maxLength":128,"minLength":1,"title":"Name"},"arguments":{"additionalProperties":true,"type":"object","title":"Arguments"}},"type":"object","required":["name"],"title":"ToolRequest"},"ToolResult":{"properties":{"name":{"type":"string","maxLength":128,"minLength":1,"title":"Name"},"content":{"type":"string","maxLength":200000,"title":"Content"},"server":{"anyOf":[{"type":"string","maxLength":253},{"type":"null"}],"title":"Server"}},"type":"object","required":["name","content"],"title":"ToolResult","description":"What a tool or MCP server handed back, on its way into the model.\n\nInspected before it is trusted. A tool result is attacker-influenced input\nthe moment the tool reads anything the attacker can write - a ticket body, a\nweb page, a file - and it arrives with the authority of the caller's own\ninfrastructure, which is exactly what makes it worth checking."},"ToolViolation":{"properties":{"name":{"type":"string","title":"Name"},"reason":{"type":"string","title":"Reason"},"detail":{"type":"string","title":"Detail"}},"type":"object","required":["name","reason","detail"],"title":"ToolViolation"},"UserCreate":{"properties":{"email":{"type":"string","maxLength":320,"minLength":3,"title":"Email"},"display_name":{"type":"string","maxLength":256,"title":"Display Name","default":""},"password":{"type":"string","maxLength":1024,"minLength":1,"title":"Password"},"roles":{"items":{"type":"string"},"type":"array","title":"Roles"},"organization_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"}},"type":"object","required":["email","password"],"title":"UserCreate"},"UserRead":{"properties":{"user_id":{"type":"string","format":"uuid","title":"User Id"},"email":{"type":"string","title":"Email"},"display_name":{"type":"string","title":"Display Name"},"organization_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Organization Id"},"roles":{"items":{"type":"string"},"type":"array","title":"Roles"},"status":{"type":"string","title":"Status"},"must_change_password":{"type":"boolean","title":"Must Change Password"},"created_at":{"type":"string","format":"date-time","title":"Created At"},"last_login_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Last Login At"}},"type":"object","required":["user_id","email","display_name","organization_id","roles","status","must_change_password","created_at","last_login_at"],"title":"UserRead"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"type":"array","title":"Location"},"msg":{"type":"string","title":"Message"},"type":{"type":"string","title":"Error Type"},"input":{"title":"Input"},"ctx":{"type":"object","title":"Context"}},"type":"object","required":["loc","msg","type"],"title":"ValidationError"},"WebhookConfig":{"properties":{"webhook_id":{"type":"string","title":"Webhook Id"},"name":{"type":"string","title":"Name"},"url":{"type":"string","title":"Url"},"type":{"type":"string","title":"Type"},"enabled":{"type":"boolean","title":"Enabled"},"event_types":{"items":{"type":"string"},"type":"array","title":"Event Types"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"title":"Headers"},"created_at":{"type":"string","title":"Created At"},"organization_id":{"type":"string","title":"Organization Id"}},"type":"object","required":["webhook_id","name","url","type","enabled","event_types","created_at","organization_id"],"title":"WebhookConfig","description":"SIEM webhook configuration"},"WebhookTestRequest":{"properties":{"test_event_type":{"type":"string","title":"Test Event Type","default":"test"}},"type":"object","title":"WebhookTestRequest","description":"Request to test a webhook"}}}}