{
  "components": {
    "schemas": {
      "AiAdditionalLibraryRisk": {
        "description": "A risk from the library added by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "customizedFields": {
            "description": "Array of field names that were customized (title, description).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "description": {
            "description": "Description (may be same as original or customized).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was added and any customizations (for internal review only).",
            "type": "string"
          },
          "originalDescription": {
            "description": "Exact description from the risk library input (snapshot).",
            "type": "string"
          },
          "originalTitle": {
            "description": "Exact title from the risk library input (snapshot).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from the library.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Title (may be same as original or customized).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "originalTitle",
          "originalDescription",
          "customizedFields",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiCompanyResearchStatus": {
        "description": "Status of the AI company research workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "CANCELLED"
        ],
        "type": "string"
      },
      "AiCustomizedRiskRecommendation": {
        "description": "A base recommendation that was customized by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "customizedFields": {
            "description": "Array of field names that were changed (title, description, suggestedImpact, suggestedLikelihood).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "description": {
            "description": "Description (may be same as original or customized).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of what was customized and why (for internal review only).",
            "type": "string"
          },
          "originalDescription": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "originalSuggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "originalSuggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "originalTitle": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Title (may be same as original or customized).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "originalTitle",
          "originalDescription",
          "customizedFields",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiExcludedRisk": {
        "description": "A base recommendation that AI determined should be excluded.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was excluded (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk is not relevant (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations to exclude.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "title": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiNovelRisk": {
        "description": "A new risk created by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "AI-generated description.",
            "type": "string"
          },
          "id": {
            "description": "AI-generated ID (e.g., 'novel-1').",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this novel risk was created (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "AI-generated title following library conventions.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiPolicyReviewStatus": {
        "description": "Status of the AI policy review workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "CANCELLED"
        ],
        "type": "string"
      },
      "AiRiskPersonalizationConfidence": {
        "description": "How confident the AI is in an assessment.",
        "enum": [
          "LOW",
          "MEDIUM",
          "HIGH"
        ],
        "type": "string"
      },
      "AiRiskPersonalizationResults": {
        "description": "Results from the AI risk personalization workflow.",
        "properties": {
          "additionalLibraryRisks": {
            "description": "Risks from the library added by AI.",
            "items": {
              "$ref": "#/components/schemas/AiAdditionalLibraryRisk"
            },
            "type": "array"
          },
          "customizedRecommendations": {
            "description": "Base risk recommendations with customized fields.",
            "items": {
              "$ref": "#/components/schemas/AiCustomizedRiskRecommendation"
            },
            "type": "array"
          },
          "excludedRisks": {
            "description": "Base risk recommendations AI determined should be excluded.",
            "items": {
              "$ref": "#/components/schemas/AiExcludedRisk"
            },
            "type": "array"
          },
          "novelRisks": {
            "description": "New risks created by AI.",
            "items": {
              "$ref": "#/components/schemas/AiNovelRisk"
            },
            "type": "array"
          },
          "personalizationSummary": {
            "deprecated": true,
            "description": "Deprecated. Overview of how the risk assessment was personalized, retained for backward compatibility with results generated before riskAssessmentSummary was introduced. Use riskAssessmentSummary going forward.",
            "type": "string"
          },
          "researchSummary": {
            "deprecated": true,
            "description": "Deprecated. Summary of what AI learned from company website research, retained for backward compatibility with results generated before personalizationSummary existed. Use riskAssessmentSummary going forward.",
            "type": "string"
          },
          "riskAssessmentSummary": {
            "description": "Client-facing executive summary of the company's risk assessment — the dominant risk themes, why they matter to the company, and the overall risk posture.",
            "type": "string"
          },
          "riskResponseAssessments": {
            "description": "Risk response assessments from the AI (only present if tenant has controls).",
            "items": {
              "$ref": "#/components/schemas/AiRiskResponseAssessment"
            },
            "type": "array"
          },
          "unchangedRecommendations": {
            "description": "Base risk recommendations that were not modified (snapshot).",
            "items": {
              "$ref": "#/components/schemas/AiUnchangedRiskRecommendation"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "AiRiskPersonalizationStatus": {
        "description": "Status of the AI risk personalization workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED"
        ],
        "type": "string"
      },
      "AiRiskResponseAssessment": {
        "description": "AI assessment of how to respond to a risk, including control linking, response recommendation, and residual risk.",
        "properties": {
          "riskId": {
            "description": "Risk ID matching a risk from the personalization output.",
            "type": "string"
          },
          "suggestedAdditionalMeasures": {
            "description": "Advisory recommendations for additional measures the company could consider beyond current controls.",
            "type": "string"
          },
          "suggestedControls": {
            "description": "Controls from the tenant's program that address this risk (empty array if none).",
            "items": {
              "$ref": "#/components/schemas/AiSuggestedControl"
            },
            "type": "array"
          },
          "suggestedControlsRationale": {
            "description": "Client-facing explanation of why these controls were linked, or why no controls are relevant.",
            "type": "string"
          },
          "suggestedHasResidualRisk": {
            "description": "Whether residual risk remains after the response.",
            "type": "boolean"
          },
          "suggestedHasResidualRiskConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedHasResidualRiskRationale": {
            "description": "Client-facing explanation of why residual risk is eliminated (only when suggestedHasResidualRisk is false).",
            "type": "string"
          },
          "suggestedResidualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedResidualImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualImpactRationale": {
            "description": "Client-facing explanation of why this residual impact level (only when suggestedHasResidualRisk is true).",
            "type": "string"
          },
          "suggestedResidualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedResidualLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualLikelihoodRationale": {
            "description": "Client-facing explanation of why this residual likelihood level (only when suggestedHasResidualRisk is true).",
            "type": "string"
          },
          "suggestedResponse": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "suggestedResponseAdequacy": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResponseAdequacyRationale": {
            "description": "Client-facing assessment of what's well-covered and what gaps remain.",
            "type": "string"
          },
          "suggestedResponseDetails": {
            "description": "Client-facing details on what the company is currently doing to address the risk (written in first person).",
            "type": "string"
          },
          "suggestedResponseRationale": {
            "description": "Client-facing explanation of why this response type is the best choice.",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "suggestedControls",
          "suggestedControlsRationale",
          "suggestedResponse",
          "suggestedResponseRationale",
          "suggestedResponseAdequacy",
          "suggestedResponseAdequacyRationale",
          "suggestedResponseDetails",
          "suggestedHasResidualRisk"
        ],
        "type": "object"
      },
      "AiSuggestedControl": {
        "description": "A control suggested for linking to a risk.",
        "properties": {
          "controlTypeId": {
            "description": "The control type identifier.",
            "type": "string"
          },
          "title": {
            "description": "The control's title (snapshot at the time of assessment).",
            "type": "string"
          }
        },
        "required": [
          "controlTypeId",
          "title"
        ],
        "type": "object"
      },
      "AiUnchangedRiskRecommendation": {
        "description": "A base recommendation that was not modified by AI (snapshot).",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was kept unchanged (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "Asset": {
        "properties": {
          "assetInstanceId": {
            "description": "The instance ID of the asset.",
            "type": "string"
          },
          "assetType": {
            "$ref": "#/components/schemas/AssetType"
          },
          "assetTypeId": {
            "description": "The ID of the asset type associated with this asset.",
            "type": "string"
          },
          "connection": {
            "$ref": "#/components/schemas/Connection"
          },
          "connectionId": {
            "description": "The ID of the connection associated with this asset.",
            "type": "string"
          },
          "createdAt": {
            "description": "The date and time the asset was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The date and time the asset was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the asset.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the asset.",
            "type": "string"
          },
          "snoozedAt": {
            "description": "The date and time when the asset was globally snoozed, if it is globally snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the asset, if the asset is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for globally snoozing this asset, if it is globally snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the global snooze period ends for this asset, if it is globally snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStatus"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this asset.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the asset was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "assetInstanceId",
          "createdAt",
          "updatedAt",
          "name",
          "assetTypeId",
          "tenantId",
          "data",
          "connectionId"
        ]
      },
      "AssetType": {
        "properties": {
          "createdAt": {
            "description": "The date and time the asset type was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The date and time the asset type was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the asset type.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the asset type.",
            "type": "string"
          },
          "integrationType": {
            "$ref": "#/components/schemas/IntegrationType"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type associated with this asset type.",
            "type": "string"
          },
          "name": {
            "description": "The name of the asset type.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the asset type was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "description"
        ]
      },
      "AuditControlReviewAction": {
        "enum": [
          "approve",
          "reopen"
        ],
        "type": "string"
      },
      "AuditControlReviewActionPayload": {
        "properties": {
          "notes": {
            "minLength": 1,
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "AuditControlReviewStatus": {
        "enum": [
          "OPEN",
          "PENDING_EVIDENCE",
          "APPROVED"
        ],
        "type": "string"
      },
      "AuditMessage": {
        "properties": {
          "auditId": {
            "format": "uuid",
            "type": "string"
          },
          "auditorEvidenceRequestId": {
            "description": "Set when the message is a comment on an evidence request rather than a post in the audit-level thread.",
            "format": "uuid",
            "type": "string"
          },
          "content": {
            "type": "string"
          },
          "contentJson": {
            "description": "Serialized Tiptap document (JSON) carrying rich content such as @mention nodes. Absent on legacy plain-text messages; clients should fall back to content when not present.",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "senderId": {
            "format": "uuid",
            "type": "string"
          },
          "senderName": {
            "type": "string"
          },
          "senderRole": {
            "$ref": "#/components/schemas/AuditMessageSenderRole"
          }
        },
        "required": [
          "id",
          "auditId",
          "senderId",
          "senderName",
          "senderRole",
          "content",
          "createdAt"
        ],
        "type": "object"
      },
      "AuditMessageSenderRole": {
        "enum": [
          "AUDITOR",
          "SPM"
        ],
        "type": "string"
      },
      "AuditPolicyDetail": {
        "properties": {
          "currentVersion": {
            "$ref": "#/components/schemas/AuditPolicyVersion"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "file": {
            "$ref": "#/components/schemas/AuditPolicyFile"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isPdfGenerationPending": {
            "description": "Whether a PDF is still being generated from the current version's Markdown.",
            "type": "boolean"
          },
          "markdown": {
            "description": "The current version's Markdown. Null when the version is an uploaded file.",
            "nullable": true,
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "publishedVersions": {
            "description": "Every published version of the policy, newest first, including the current one.",
            "items": {
              "$ref": "#/components/schemas/AuditPolicyVersion"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "name",
          "currentVersion",
          "isPdfGenerationPending",
          "publishedVersions"
        ],
        "type": "object"
      },
      "AuditPolicyFile": {
        "description": "The current version's document. Either the file the author uploaded, or a PDF generated from the Markdown. Absent while a Markdown version has no PDF generated from it yet.",
        "properties": {
          "mimeType": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "sizeByteCount": {
            "format": "int64",
            "type": "integer"
          },
          "url": {
            "description": "Presigned link to the document. Valid for one hour and re-issued on every read, so read the policy again for a fresh link instead of storing this one.",
            "type": "string"
          }
        },
        "required": [
          "name",
          "mimeType",
          "sizeByteCount",
          "url"
        ],
        "type": "object"
      },
      "AuditPolicyList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/AuditPolicyListItem"
            },
            "type": "array"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "AuditPolicyListItem": {
        "properties": {
          "currentVersion": {
            "$ref": "#/components/schemas/AuditPolicyVersion"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "publishedVersionCount": {
            "minimum": 1,
            "type": "integer"
          }
        },
        "required": [
          "id",
          "name",
          "currentVersion",
          "publishedVersionCount"
        ],
        "type": "object"
      },
      "AuditPolicyUser": {
        "properties": {
          "name": {
            "description": "The user's name, or their email when they have no name.",
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "type": "object"
      },
      "AuditPolicyVersion": {
        "properties": {
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/AuditPolicyUser"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isCurrent": {
            "description": "Whether this is the policy's current version.",
            "type": "boolean"
          },
          "isReviewedWithEdits": {
            "description": "Whether the reviewer edited the version before approving it.",
            "type": "boolean"
          },
          "isUploadedFile": {
            "description": "Whether the version is an uploaded file rather than Markdown.",
            "type": "boolean"
          },
          "minorVersionNumber": {
            "type": "integer"
          },
          "publishedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "reviewedAt": {
            "description": "Set when the version was approved in review. Null for a direct publish.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "reviewedBy": {
            "$ref": "#/components/schemas/AuditPolicyUser"
          },
          "versionNumber": {
            "type": "integer"
          }
        },
        "required": [
          "id",
          "versionNumber",
          "minorVersionNumber",
          "createdAt",
          "createdBy",
          "isReviewedWithEdits",
          "isUploadedFile",
          "isCurrent"
        ],
        "type": "object"
      },
      "AuditPortalAuditSummary": {
        "description": "A firm-scoped summary of an audit, returned by the audit-firm service-key API. Deliberately lighter than AuditPortalAudit (no owner/auditor assignment or viewer-permission fields) — those are Oneleet-internal concepts an external integrator has no use for.",
        "properties": {
          "auditType": {
            "$ref": "#/components/schemas/AuditType"
          },
          "auditorStatus": {
            "$ref": "#/components/schemas/AuditorStatus"
          },
          "currentStage": {
            "$ref": "#/components/schemas/AuditStage"
          },
          "id": {
            "description": "The ID of the audit. Used as the auditId path parameter on other audit-portal endpoints.",
            "format": "uuid",
            "type": "string"
          },
          "observationPeriodEnd": {
            "description": "The end of the observation period.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "observationPeriodStart": {
            "description": "The start of the observation period.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "tenantComplianceFrameworkId": {
            "description": "The tenant compliance framework ID. Used as the tenantComplianceFrameworkId path parameter on the controls endpoints.",
            "format": "uuid",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant (client) being audited.",
            "format": "uuid",
            "type": "string"
          },
          "tenantName": {
            "description": "The name of the tenant (client) being audited.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "tenantId",
          "tenantName",
          "tenantComplianceFrameworkId",
          "auditType",
          "currentStage",
          "auditorStatus"
        ],
        "type": "object"
      },
      "AuditPortalAuditSummaryList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/AuditPortalListPagination"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/AuditPortalAuditSummary"
            },
            "type": "array"
          }
        },
        "required": [
          "rows",
          "pagination"
        ],
        "type": "object"
      },
      "AuditPortalControl": {
        "properties": {
          "assignedMember": {
            "$ref": "#/components/schemas/AuditPortalControlOwner"
          },
          "auditorReviewNotes": {
            "nullable": true,
            "type": "string"
          },
          "auditorReviewStatus": {
            "$ref": "#/components/schemas/AuditControlReviewStatus"
          },
          "auditorReviewedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "checks": {
            "items": {
              "$ref": "#/components/schemas/Check"
            },
            "nullable": true,
            "type": "array"
          },
          "content": {
            "$ref": "#/components/schemas/ControlContent"
          },
          "evidence": {
            "items": {
              "$ref": "#/components/schemas/Evidence"
            },
            "nullable": true,
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "monitorFindingsRollups": {
            "description": "Findings rollup per monitor check on this control, so the monitor list can be summarized without expanding each row.",
            "items": {
              "$ref": "#/components/schemas/AuditPortalMonitorFindings"
            },
            "nullable": true,
            "type": "array"
          },
          "reviewDetails": {
            "nullable": true,
            "type": "string"
          },
          "reviewStatus": {
            "$ref": "#/components/schemas/ControlReviewStatus"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenantComplianceRequirements": {
            "items": {
              "$ref": "#/components/schemas/AuditPortalControlRequirement"
            },
            "nullable": true,
            "type": "array"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "auditorReviewStatus",
          "content",
          "updatedAt"
        ],
        "type": "object"
      },
      "AuditPortalControlEvidence": {
        "properties": {
          "type": {
            "$ref": "#/components/schemas/EvidenceType"
          }
        },
        "required": [
          "type"
        ],
        "type": "object"
      },
      "AuditPortalControlListItem": {
        "properties": {
          "auditorReviewStatus": {
            "$ref": "#/components/schemas/AuditControlReviewStatus"
          },
          "checkSummary": {
            "$ref": "#/components/schemas/ControlCheckSummary"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "evidence": {
            "items": {
              "$ref": "#/components/schemas/AuditPortalControlEvidence"
            },
            "type": "array"
          },
          "evidenceRequestStatusCounts": {
            "$ref": "#/components/schemas/AuditorEvidenceRequestStatusCounts"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/AuditPortalControlOwner"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenantComplianceRequirements": {
            "items": {
              "$ref": "#/components/schemas/AuditPortalControlRequirement"
            },
            "nullable": true,
            "type": "array"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "status",
          "auditorReviewStatus",
          "evidenceRequestStatusCounts",
          "checkSummary",
          "evidence",
          "updatedAt"
        ],
        "type": "object"
      },
      "AuditPortalControlOwner": {
        "properties": {
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "AuditPortalControlRequirement": {
        "properties": {
          "frameworkName": {
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "referenceId": {
            "type": "string"
          },
          "tenantFrameworkId": {
            "format": "uuid",
            "type": "string"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "tenantFrameworkId",
          "referenceId",
          "title"
        ],
        "type": "object"
      },
      "AuditPortalListPagination": {
        "properties": {
          "limit": {
            "type": "integer"
          },
          "page": {
            "type": "integer"
          },
          "total": {
            "description": "Number of audits matching the current filters that the viewer can see.",
            "type": "integer"
          },
          "totalPages": {
            "type": "integer"
          }
        },
        "required": [
          "page",
          "limit",
          "total",
          "totalPages"
        ],
        "type": "object"
      },
      "AuditPortalMe": {
        "description": "Key-context for an audit-firm service key: the firm id and name it's scoped to. Lets an integrator resolve its own firm id via the API instead of copying it out of a browser network tab.",
        "properties": {
          "auditFirmId": {
            "description": "The ID of the audit firm this key belongs to.",
            "format": "uuid",
            "type": "string"
          },
          "auditFirmName": {
            "description": "The name of the audit firm this key belongs to.",
            "type": "string"
          }
        },
        "required": [
          "auditFirmId",
          "auditFirmName"
        ],
        "type": "object"
      },
      "AuditPortalMonitorFindings": {
        "description": "One control monitor's findings rollup over the audit observation window.",
        "properties": {
          "monitorId": {
            "format": "uuid",
            "type": "string"
          },
          "rollup": {
            "$ref": "#/components/schemas/MonitorFindingsRollup"
          }
        },
        "required": [
          "monitorId",
          "rollup"
        ],
        "type": "object"
      },
      "AuditSnapshot": {
        "description": "A background run that builds an offline archive of an audit, or of a single control of an audit when controlId is set. Poll the get-snapshot endpoint until status is COMPLETED, then download from downloadUrl. A FAILED run can be retried by creating a new snapshot.",
        "properties": {
          "auditId": {
            "format": "uuid",
            "type": "string"
          },
          "completedAt": {
            "format": "date-time",
            "type": "string"
          },
          "controlId": {
            "description": "Set when the archive covers a single control instead of the whole audit.",
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "downloadUrl": {
            "description": "Presigned link to the archive. Present only when status is COMPLETED. Valid for one hour and re-issued on every read, so poll again for a fresh link instead of storing this one.",
            "format": "uri",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "requestedById": {
            "description": "The user who requested the snapshot, or the creator of the service key that did.",
            "format": "uuid",
            "type": "string"
          },
          "startedAt": {
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/AuditSnapshotStatus"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "auditId",
          "status",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "AuditSnapshotStatus": {
        "enum": [
          "PENDING",
          "RUNNING",
          "COMPLETED",
          "FAILED"
        ],
        "type": "string"
      },
      "AuditStage": {
        "description": "The stage of the audit.",
        "enum": [
          "PREPARATION",
          "SCOPE_IDENTIFICATION",
          "MAINTENANCE_AND_IMPROVEMENT",
          "OBSERVATION_PERIOD",
          "INTERNAL_AUDIT",
          "STAGE_1_AUDIT",
          "STAGE_2_AUDIT",
          "AUDIT",
          "REPORT_READY"
        ],
        "type": "string"
      },
      "AuditType": {
        "properties": {
          "id": {
            "description": "The ID of the audit type.",
            "type": "string"
          },
          "name": {
            "description": "The title of the audit type.",
            "type": "string"
          },
          "stages": {
            "items": {
              "$ref": "#/components/schemas/AuditStage"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this audit type was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "updatedAt",
          "stages"
        ]
      },
      "AuditorEvidenceRequest": {
        "properties": {
          "attachmentFileName": {
            "nullable": true,
            "type": "string"
          },
          "attachmentUrl": {
            "description": "Short-lived presigned S3 URL for downloading the attachment",
            "nullable": true,
            "type": "string"
          },
          "auditId": {
            "format": "uuid",
            "type": "string"
          },
          "controlId": {
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "createdById": {
            "format": "uuid",
            "type": "string"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "dueDate": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "frameworkClause": {
            "description": "Free-text framework clause reference (e.g. \"SOC 2 · CC6.1\")",
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "platformEvidenceRequestId": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "rejectionReason": {
            "nullable": true,
            "type": "string"
          },
          "reviewedById": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/AuditorEvidenceRequestStatus"
          },
          "title": {
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "auditId",
          "controlId",
          "title",
          "status",
          "createdById",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "AuditorEvidenceRequestAction": {
        "enum": [
          "withdraw"
        ],
        "type": "string"
      },
      "AuditorEvidenceRequestActionPayload": {
        "properties": {
          "description": {
            "description": "Edited request description, applied by the SPM `approve` action before the request is minted into the client's workspace. When omitted, the existing description is minted verbatim. Ignored by other actions.",
            "maxLength": 5000,
            "type": "string"
          },
          "flaggedBadRequest": {
            "description": "Internal quality signal set by the SPM `reject` action, recording that the auditor's request was invalid / a bad request. Stored for internal auditor-performance tracking and never returned over the API. Ignored by other actions.",
            "type": "boolean"
          },
          "reason": {
            "description": "Rejection reason. Required by the SPM `reject` action; ignored by `approve`.",
            "minLength": 1,
            "type": "string"
          },
          "title": {
            "description": "Edited request title, applied by the SPM `approve` action before the request is minted into the client's workspace. When omitted, the existing title is minted verbatim. Ignored by other actions.",
            "minLength": 1,
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "AuditorEvidenceRequestAttachment": {
        "description": "One file recorded against an auditor evidence request state transition.",
        "properties": {
          "fileName": {
            "description": "The name of the file as the uploader supplied it.",
            "type": "string"
          },
          "fileSize": {
            "description": "The file size in bytes.",
            "format": "int64",
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "mimeType": {
            "type": "string"
          },
          "url": {
            "description": "Short-lived presigned S3 URL for downloading the attachment. Null when the URL could not be minted.",
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "id",
          "fileName",
          "mimeType",
          "fileSize"
        ],
        "type": "object"
      },
      "AuditorEvidenceRequestStateTransition": {
        "description": "One append-only entry in an auditor evidence request's status history. fromStatus is null on the initial entry. Only the four persisted statuses (PENDING_SPM_REVIEW, AWAITING_EVIDENCE, REJECTED_BY_SPM, WITHDRAWN) ever appear here — the remaining AuditorEvidenceRequestStatus values are derived at read time from the linked tenant evidence request and are never recorded as transitions.",
        "properties": {
          "attachments": {
            "description": "Files the acting user attached to this transition. Only the SPM `reject` action attaches any; empty on every other entry.",
            "items": {
              "$ref": "#/components/schemas/AuditorEvidenceRequestAttachment"
            },
            "type": "array"
          },
          "auditorEvidenceRequestId": {
            "format": "uuid",
            "type": "string"
          },
          "changedById": {
            "description": "Null for transitions applied by the system rather than a user.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "changedByName": {
            "description": "Display name of the acting user. Null when changedById is null, or when the acting user has since been deleted.",
            "nullable": true,
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "fromStatus": {
            "allOf": [
              {
                "$ref": "#/components/schemas/AuditorEvidenceRequestStatus"
              }
            ],
            "nullable": true
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "previousDescription": {
            "description": "The description before the SPM's approval-time edit. Set only on the approve entry that changed the description; null everywhere else.",
            "nullable": true,
            "type": "string"
          },
          "previousTitle": {
            "description": "The title before the SPM's approval-time edit. Set only on the approve entry that changed the title; null everywhere else.",
            "nullable": true,
            "type": "string"
          },
          "reason": {
            "description": "Rejection reason supplied by the SPM, when the action carried one.",
            "nullable": true,
            "type": "string"
          },
          "revisedDescription": {
            "description": "The description the SPM set on approval. Paired with previousDescription.",
            "nullable": true,
            "type": "string"
          },
          "revisedTitle": {
            "description": "The title the SPM set on approval. Paired with previousTitle.",
            "nullable": true,
            "type": "string"
          },
          "toStatus": {
            "$ref": "#/components/schemas/AuditorEvidenceRequestStatus"
          }
        },
        "required": [
          "id",
          "auditorEvidenceRequestId",
          "toStatus",
          "createdAt",
          "attachments"
        ],
        "type": "object"
      },
      "AuditorEvidenceRequestStatus": {
        "enum": [
          "PENDING_SPM_REVIEW",
          "REJECTED_BY_SPM",
          "AWAITING_EVIDENCE",
          "EVIDENCE_SUBMITTED",
          "EVIDENCE_APPROVED",
          "CHANGES_REQUESTED",
          "EVIDENCE_REQUEST_REMOVED",
          "WITHDRAWN",
          "CLOSED"
        ],
        "type": "string"
      },
      "AuditorEvidenceRequestStatusCounts": {
        "description": "Number of the audit's auditor evidence requests in each derived display\nstatus (see AuditorEvidenceRequestStatus). closed counts requests whose\ncontrol has an APPROVED AuditControlReview; withdrawn and\nevidenceRequestRemoved are terminal states that portal rollup UIs exclude.\n",
        "properties": {
          "awaitingEvidence": {
            "type": "integer"
          },
          "changesRequested": {
            "type": "integer"
          },
          "closed": {
            "type": "integer"
          },
          "evidenceApproved": {
            "type": "integer"
          },
          "evidenceRequestRemoved": {
            "type": "integer"
          },
          "evidenceSubmitted": {
            "type": "integer"
          },
          "pendingSpmReview": {
            "type": "integer"
          },
          "rejectedBySpm": {
            "type": "integer"
          },
          "withdrawn": {
            "type": "integer"
          }
        },
        "required": [
          "pendingSpmReview",
          "rejectedBySpm",
          "awaitingEvidence",
          "evidenceSubmitted",
          "changesRequested",
          "evidenceApproved",
          "closed",
          "withdrawn",
          "evidenceRequestRemoved"
        ],
        "type": "object"
      },
      "AuditorStatus": {
        "description": "Whether the assigned auditor has engaged with the audit. Forward-only:\nPENDING → IN_PROGRESS → COMPLETED. Once advanced, the status cannot move\nbackwards.\n",
        "enum": [
          "PENDING",
          "IN_PROGRESS",
          "COMPLETED"
        ],
        "type": "string"
      },
      "Check": {
        "properties": {
          "createdAt": {
            "description": "The time that this check was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integration": {
            "$ref": "#/components/schemas/Integration"
          },
          "integrationCategory": {
            "$ref": "#/components/schemas/IntegrationCategory"
          },
          "isDisabled": {
            "description": "Whether or not this check is disabled.",
            "type": "boolean"
          },
          "monitor": {
            "$ref": "#/components/schemas/Monitor"
          },
          "policy": {
            "$ref": "#/components/schemas/Policy"
          },
          "policyType": {
            "$ref": "#/components/schemas/PolicyType"
          },
          "scopeItem": {
            "$ref": "#/components/schemas/CheckScopeItem"
          },
          "status": {
            "$ref": "#/components/schemas/CheckStatus"
          },
          "type": {
            "$ref": "#/components/schemas/CheckType"
          },
          "updatedAt": {
            "description": "The time that this check was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "status",
          "isDisabled",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "CheckScopeItem": {
        "description": "The durable per-resource scope item behind a SCOPE_ITEM check (e.g. one business-critical vendor on the MFA-for-critical-services control). The item is satisfied either by monitor coverage (autoSatisfied) or by evidence attached during its current interval.\n",
        "properties": {
          "activeFrom": {
            "description": "Start of the item's current in-scope interval.",
            "format": "date-time",
            "type": "string"
          },
          "autoSatisfied": {
            "description": "True when existing monitor coverage already satisfies this item and no manual evidence is needed.\n",
            "type": "boolean"
          },
          "autoSatisfiedByIntegrationIcon": {
            "type": "string"
          },
          "autoSatisfiedByIntegrationName": {
            "type": "string"
          },
          "autoSatisfiedByMonitorId": {
            "format": "uuid",
            "type": "string"
          },
          "autoSatisfiedByMonitorName": {
            "type": "string"
          },
          "coveredByMonitorId": {
            "description": "Set whenever an enabled monitor observes this resource at all (superset of autoSatisfied). When the monitor is not passing, remediation in the monitor is the primary path and manual evidence is a fallback.\n",
            "format": "uuid",
            "type": "string"
          },
          "coveredByMonitorName": {
            "type": "string"
          },
          "coveredByMonitorStatus": {
            "description": "The covering monitor's live state (e.g. PASSING, ALERTING, BREACHING_SLA).",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "evidenceIds": {
            "description": "Ids of evidence attached during the item's current interval; join against the control's evidence list for details.\n",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "iconUrl": {
            "description": "Display icon of the scoped resource, when available.",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "kind": {
            "description": "What the scoped resource is; scopeRef is its id.",
            "enum": [
              "VENDOR",
              "MEMBER"
            ],
            "type": "string"
          },
          "resourceUrl": {
            "description": "URL of the scoped resource (VENDOR → the vendor's website), for brand-icon fallback and display.\n",
            "type": "string"
          },
          "scopeRef": {
            "description": "Id of the scoped resource, interpreted per kind (VENDOR → TenantVendor id, MEMBER → TenantMember id).\n",
            "type": "string"
          },
          "title": {
            "description": "Display name of the scoped resource (e.g. the vendor's name).",
            "type": "string"
          }
        },
        "required": [
          "id",
          "kind",
          "scopeRef",
          "title",
          "autoSatisfied",
          "evidenceIds"
        ],
        "type": "object"
      },
      "CheckStatus": {
        "enum": [
          "PENDING",
          "IN_PROGRESS",
          "INACTIVE",
          "PASSING",
          "FAILING",
          "NEEDS_CHANGES"
        ],
        "type": "string"
      },
      "CheckType": {
        "description": "The type of check.",
        "enum": [
          "INTEGRATION",
          "MONITOR",
          "POLICY",
          "ATTACHMENT",
          "SCOPE_ITEM"
        ],
        "type": "string"
      },
      "ComplianceFramework": {
        "properties": {
          "createdAt": {
            "description": "The time the framework was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the framework.",
            "type": "string"
          },
          "estimatedReadiness": {
            "description": "The percentage of controls that have already been completed in another framework that overlaps with the new framework.",
            "type": "number"
          },
          "estimatedTime": {
            "description": "The estimated time to complete the framework.",
            "type": "string"
          },
          "extends": {
            "$ref": "#/components/schemas/ComplianceFramework"
          },
          "extendsId": {
            "description": "The id of the framework that this framework extends.",
            "type": "string"
          },
          "icon": {
            "description": "The icon for the framework.",
            "type": "string"
          },
          "id": {
            "description": "The id of the framework.",
            "type": "string"
          },
          "internalName": {
            "description": "Internal name visible only to admins - notes to help select the correct framework variant.",
            "type": "string"
          },
          "isActive": {
            "description": "Whether the framework is available for users to use.",
            "type": "boolean"
          },
          "isVisibleToTenant": {
            "description": "Whether the framework is visible to tenants.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the framework.",
            "type": "string"
          },
          "requirements": {
            "description": "The requirements for the framework.",
            "items": {
              "$ref": "#/components/schemas/ComplianceRequirement"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time the framework was last updated",
            "format": "date-time",
            "type": "string"
          },
          "version": {
            "description": "The version of the framework.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "version",
          "description",
          "icon",
          "createdAt",
          "updatedAt",
          "estimatedReadiness"
        ],
        "type": "object"
      },
      "ComplianceRequirement": {
        "properties": {
          "createdAt": {
            "description": "The time the requirement was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the requirement.",
            "type": "string"
          },
          "framework": {
            "$ref": "#/components/schemas/ComplianceFramework"
          },
          "frameworkId": {
            "description": "The id of the framework that this requirement belongs to.",
            "type": "string"
          },
          "id": {
            "description": "The id of the requirement.",
            "type": "string"
          },
          "number": {
            "description": "The number of the requirement.",
            "type": "integer"
          },
          "referenceId": {
            "description": "A string that uniquely identifies the requirement in the framework document. The format of this can vary from framework to framework and may not always look exactly like a number.",
            "type": "string"
          },
          "title": {
            "description": "The title of the requirement.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the requirement was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "referenceId",
          "number",
          "title",
          "frameworkId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "Connection": {
        "properties": {
          "autofixesEnabled": {
            "description": "Whether Oneleet autofixes are enabled for this connection.",
            "type": "boolean"
          },
          "configuration": {
            "description": "The additional configuration of the connection.",
            "discriminator": {
              "mapping": {
                "aws_v1": "#/components/schemas/CreateAWSConnectionData",
                "aws_v2": "#/components/schemas/CreateAWSv2ConnectionData",
                "custom_v1": "#/components/schemas/CreateCustomConnectionData",
                "gitlab_v1": "#/components/schemas/CreateGitLabConnectionData",
                "slack_v1": "#/components/schemas/CreateSlackConnectionData"
              },
              "propertyName": "integrationTypeId"
            },
            "nullable": true,
            "oneOf": [
              {
                "$ref": "#/components/schemas/CreateAWSConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateAWSv2ConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateCustomConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateSlackConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateGitLabConnectionData"
              }
            ],
            "type": "object"
          },
          "createdAt": {
            "description": "The time that this connection was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the connection.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integration": {
            "$ref": "#/components/schemas/Integration"
          },
          "integrationId": {
            "description": "The ID of the integration.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "label": {
            "description": "User-created label for the connection; if not present, `readableId` is shown as a fallback.",
            "type": "string"
          },
          "readableId": {
            "description": "An alternative ID for the connection, which must be unique per tenant.\n\nThis is used as both a unique identifier in some of our integrations logic,\n*and* as a user-facing label for the connection.\n\nSome integrations populate this with a nice value, such as \"project name\" for GCP.\nDue to technical limitations, Nango-based integrations currently don't.\n",
            "type": "string"
          },
          "sshPublicKey": {
            "description": "Public half of the SSH keypair used to clone repositories over SSH (GitLab connections with cloneProtocol \"ssh\"). The customer installs this key on a GitLab service account.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ConnectionStatus"
          },
          "statusReason": {
            "description": "The reason for the connection status.",
            "type": "string"
          },
          "tenantVendorId": {
            "description": "For custom integration connections, the ID of the tenant vendor this connection is for.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this connection was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "integrationId",
          "readableId",
          "status",
          "autofixesEnabled"
        ],
        "type": "object"
      },
      "ConnectionStatus": {
        "description": "Status of a connection:\n- UNQUERIED: Not yet queried\n- SUCCEEDED: Last query succeeded\n- FAILED: Last query failed (requires user action)\n- RETRYING: Last query encountered a transient error and will retry automatically\n",
        "enum": [
          "UNQUERIED",
          "SUCCEEDED",
          "FAILED",
          "RETRYING"
        ],
        "type": "string"
      },
      "ControlCheckSummary": {
        "properties": {
          "allActiveChecksArePassing": {
            "type": "boolean"
          },
          "checksPassingPercentage": {
            "format": "float",
            "type": "number"
          },
          "enabledChecksCount": {
            "type": "integer"
          },
          "hasChecks": {
            "type": "boolean"
          },
          "inactiveChecksCount": {
            "type": "integer"
          },
          "passingChecksCount": {
            "type": "integer"
          },
          "totalChecksCount": {
            "type": "integer"
          }
        },
        "required": [
          "hasChecks",
          "allActiveChecksArePassing",
          "inactiveChecksCount",
          "enabledChecksCount",
          "passingChecksCount",
          "totalChecksCount",
          "checksPassingPercentage"
        ],
        "type": "object"
      },
      "ControlContent": {
        "properties": {
          "aiSuggestedEvidenceCriteria": {
            "description": "AI-generated evidence criteria (used as fallback when no custom or template criteria exist)",
            "items": {
              "$ref": "#/components/schemas/EvidenceCriterion"
            },
            "type": "array"
          },
          "description": {
            "description": "The control's description.",
            "maxLength": 6000,
            "type": "string"
          },
          "evidenceCriteria": {
            "description": "The effective evidence criteria (custom if set, otherwise template, otherwise AI-suggested)",
            "items": {
              "$ref": "#/components/schemas/EvidenceCriterion"
            },
            "type": "array"
          },
          "instructions": {
            "description": "The control's instructions.",
            "maxLength": 6000,
            "type": "string"
          },
          "title": {
            "description": "The control's title.",
            "maxLength": 255,
            "type": "string"
          }
        },
        "required": [
          "title",
          "description"
        ],
        "type": "object"
      },
      "ControlReviewStatus": {
        "description": "The review status of the control.",
        "enum": [
          "UNREVIEWED",
          "IN_REVIEW",
          "APPROVED",
          "REJECTED"
        ],
        "type": "string"
      },
      "ControlStatus": {
        "description": "The status of the control.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "IN_REVIEW",
          "NEEDS_CHANGES",
          "FAILING",
          "PASSING"
        ],
        "type": "string"
      },
      "ControlSummary": {
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "title"
        ],
        "type": "object"
      },
      "CreateAWSConnectionData": {
        "properties": {
          "assumeRoleArn": {
            "description": "The ARN of the role that shall be assumed.",
            "type": "string"
          },
          "externalId": {
            "description": "The external ID for the assume role. Oneleet derives this from the integration, so it can be omitted; when supplied it must match the value returned by `GET /api/v1/integrations/{integration}/aws-external-id`.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to use.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId",
          "assumeRoleArn"
        ]
      },
      "CreateAWSv2ConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "primaryRegion": {
            "description": "The primary AWS region to use.",
            "type": "string"
          },
          "randomKey": {
            "description": "Random identifier used to find the S3 object created for this template.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to use.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId",
          "randomKey",
          "primaryRegion",
          "selectedRegions"
        ]
      },
      "CreateAuditMessagePayload": {
        "properties": {
          "content": {
            "minLength": 1,
            "type": "string"
          },
          "contentJson": {
            "description": "Serialized Tiptap document (JSON) carrying rich content such as @mention nodes. Optional; content remains the authoritative plain-text body.",
            "type": "string"
          }
        },
        "required": [
          "content"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateAuditorEvidenceRequestPayload": {
        "description": "Creating an evidence request also submits it to the SPM for review in one action: the request is persisted directly in PENDING_SPM_REVIEW. There is no DRAFT step and no separate submit call.",
        "properties": {
          "attachmentFile": {
            "description": "Optional template file for tenant",
            "format": "binary",
            "type": "string"
          },
          "controlId": {
            "format": "uuid",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "dueDate": {
            "description": "RFC3339 timestamp. Plain string (not format date-time) because oapi-codegen multipart bind does not support time.Time fields.",
            "type": "string"
          },
          "frameworkClause": {
            "type": "string"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "controlId",
          "title"
        ],
        "type": "object"
      },
      "CreateCustomConnectionData": {
        "properties": {
          "authCredentials": {
            "description": "Auth credentials for the custom integration's API. They're stored encrypted and never returned.",
            "properties": {
              "apiKey": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "customConfig": {
            "description": "Configuration for the custom integration connection.",
            "type": "object"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "customConfig"
        ]
      },
      "CreateGitLabConnectionData": {
        "properties": {
          "accessTokenName": {
            "description": "Group, project, or personal access token name from the GitLab's interface.",
            "type": "string"
          },
          "accessTokenSecret": {
            "description": "Group, project, or personal access token secret from the GitLab's interface.",
            "type": "string"
          },
          "baseUrl": {
            "description": "Origin of a self-hosted GitLab instance (e.g. \"https://gitlab.acme.com\"). Leave empty for GitLab.com.",
            "format": "uri",
            "pattern": "^https://",
            "type": "string"
          },
          "cloneProtocol": {
            "description": "Protocol used to clone repositories for code scanning. Use \"ssh\" for groups that disable git access over HTTP(S). Defaults to \"https\".",
            "enum": [
              "https",
              "ssh"
            ],
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "accessTokenName",
          "accessTokenSecret"
        ]
      },
      "CreateSlackConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "scopes": {
            "description": "The Slack OAuth bot scopes granted at the most recent authorization.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "tier": {
            "description": "The Slack workspace plan tier selected at connect time.",
            "enum": [
              "standard",
              "enterprise"
            ],
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId"
        ]
      },
      "DashboardReport": {
        "description": "Minimal report information for dashboard display",
        "properties": {
          "engagementId": {
            "description": "The ID of the engagement.",
            "format": "uuid",
            "type": "string"
          },
          "id": {
            "description": "The ID of the report.",
            "format": "uuid",
            "type": "string"
          },
          "title": {
            "description": "The title of the report.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "engagementId"
        ],
        "type": "object"
      },
      "DocumentEditorBlock": {
        "properties": {
          "data": {
            "type": "object"
          },
          "id": {
            "description": "Unique identifier for the block",
            "type": "string"
          },
          "type": {
            "description": "Type of the block",
            "enum": [
              "table",
              "header",
              "paragraph",
              "list",
              "image",
              "checklist",
              "quote",
              "code",
              "inlineCode",
              "delimiter",
              "simpleImage",
              "marker"
            ],
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "data"
        ],
        "type": "object"
      },
      "DocumentEditorObject": {
        "properties": {
          "blocks": {
            "items": {
              "$ref": "#/components/schemas/DocumentEditorBlock"
            },
            "type": "array"
          },
          "time": {
            "description": "Timestamp in milliseconds",
            "format": "int64",
            "type": "integer"
          },
          "version": {
            "description": "Version of the editor",
            "type": "string"
          }
        },
        "required": [
          "blocks"
        ],
        "type": "object"
      },
      "Engagement": {
        "properties": {
          "createdAt": {
            "description": "The time that this engagement was created.",
            "format": "date-time",
            "type": "string"
          },
          "engagementScoping": {
            "$ref": "#/components/schemas/EngagementScoping"
          },
          "id": {
            "description": "The ID of the engagement.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "meta": {
            "$ref": "#/components/schemas/EngagementMeta"
          },
          "name": {
            "description": "The name of the engagement.",
            "type": "string"
          },
          "reports": {
            "description": "The reports associated with this engagement.",
            "items": {
              "$ref": "#/components/schemas/DashboardReport"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/EngagementStatus"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this engagement.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantName": {
            "description": "The name of the tenant associated with this engagement.",
            "type": "string"
          },
          "testers": {
            "description": "The testers associated with this engagement.",
            "items": {
              "$ref": "#/components/schemas/TenantTester"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this engagement was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "status",
          "tenantId"
        ],
        "type": "object"
      },
      "EngagementMeta": {
        "properties": {
          "actualFinishedAt": {
            "description": "The actual finish time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "actualStartedAt": {
            "description": "The actual start time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "hours": {
            "description": "The hours of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "period": {
            "description": "The period of the engagement.",
            "maxLength": 20,
            "minLength": 1,
            "type": "string"
          },
          "plannedFinishAt": {
            "description": "The planned finish time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "plannedStartAt": {
            "description": "The planned start time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "title": {
            "description": "The title of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          }
        },
        "type": "object"
      },
      "EngagementScoping": {
        "properties": {
          "details": {
            "description": "The details of the scoping call for the engagement.",
            "type": "string"
          },
          "scopingCallDate": {
            "description": "The date of the scoping call for the engagement.",
            "format": "date-time",
            "type": "string"
          },
          "scopingCallTime": {
            "description": "The time of the scoping call for the engagement.",
            "type": "string"
          }
        },
        "type": "object"
      },
      "EngagementStatus": {
        "enum": [
          "PENDING_SCOPING_CALL",
          "PLANNED",
          "ONGOING",
          "COMPLETED"
        ],
        "type": "string"
      },
      "Evidence": {
        "properties": {
          "aiReviewResults": {
            "$ref": "#/components/schemas/EvidenceAiAnalysis"
          },
          "aiReviewStatus": {
            "$ref": "#/components/schemas/EvidenceAiReviewStatus"
          },
          "aiSuggestedName": {
            "description": "The AI-suggested name for this evidence.",
            "type": "string"
          },
          "controlIds": {
            "description": "The IDs of linked controls.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time the evidence was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/UserPublic"
          },
          "fileMimeType": {
            "description": "The MIME type detected from the evidence file's contents, without parameters (e.g. application/pdf). Absent for evidence without a file.",
            "type": "string"
          },
          "fileName": {
            "description": "The evidence's file name.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the evidence.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "inAppDocument": {
            "$ref": "#/components/schemas/InAppDocument"
          },
          "inAppDocumentId": {
            "description": "The ID of the in-app document.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "link": {
            "description": "The evidence's link.",
            "type": "string"
          },
          "name": {
            "description": "The name of the evidence.",
            "type": "string"
          },
          "note": {
            "description": "The evidence's note.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant this evidence belongs to",
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/EvidenceType"
          },
          "updatedAt": {
            "description": "The time the evidence was last updated",
            "format": "date-time",
            "type": "string"
          },
          "vendorIds": {
            "description": "The IDs of linked vendors.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "type",
          "controlIds",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "EvidenceAiAnalysis": {
        "description": "AI analysis results for evidence",
        "properties": {
          "content_summary": {
            "description": "Summary of the content of the link evidence",
            "type": "string"
          },
          "content_type": {
            "description": "Content type of the link evidence",
            "type": "string"
          },
          "description": {
            "description": "Human-readable summary of the evidence",
            "type": "string"
          },
          "extracted_text": {
            "description": "Any readable text extracted from the image",
            "type": "string"
          },
          "image_type": {
            "description": "Type of image (screenshot, document, diagram, photo, etc.)",
            "type": "string"
          },
          "is_accessible": {
            "description": "Whether the link evidence is accessible to the AI",
            "type": "boolean"
          },
          "is_relevant": {
            "description": "Whether the evidence plausibly demonstrates the control(s) it is linked to, independent of formal validity — pristine evidence can still be irrelevant to its control.",
            "type": "boolean"
          },
          "is_settings_page": {
            "description": "Whether this screenshot shows a settings/configuration page",
            "type": "boolean"
          },
          "recommendation": {
            "description": "Actionable fix-it instruction for the uploader when the evidence is deficient (e.g. \"Re-take the screenshot with the URL bar visible\"); absent when the evidence passes.",
            "type": "string"
          },
          "relevance_reasoning": {
            "description": "Short justification for the relevance call",
            "type": "string"
          },
          "resource_identifier": {
            "$ref": "#/components/schemas/EvidenceResourceIdentifier"
          },
          "source": {
            "description": "Platform/vendor identifier (lowercase) or \"unknown\"",
            "type": "string"
          },
          "status_code": {
            "description": "HTTP status code of the link evidence",
            "type": "integer"
          },
          "suggested_name": {
            "description": "AI-suggested descriptive name for this evidence",
            "type": "string"
          },
          "timestamp_analysis": {
            "$ref": "#/components/schemas/EvidenceTimestampAnalysis"
          },
          "title": {
            "description": "Page title of the link evidence",
            "type": "string"
          },
          "visible_elements": {
            "description": "List of UI elements visible in the image",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "EvidenceAiReviewStatus": {
        "description": "The AI review status for evidence.",
        "enum": [
          "DISABLED",
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "INTERNAL_ERROR"
        ],
        "type": "string"
      },
      "EvidenceCriterion": {
        "properties": {
          "content": {
            "description": "The evidence criterion content",
            "maxLength": 6000,
            "type": "string"
          },
          "id": {
            "description": "Unique identifier for the evidence criterion (filename without .md extension)",
            "type": "string"
          },
          "label": {
            "description": "Display label for the evidence criterion",
            "type": "string"
          }
        },
        "required": [
          "id",
          "content"
        ],
        "type": "object"
      },
      "EvidenceDownloadUrlResponse": {
        "properties": {
          "url": {
            "description": "Presigned S3 URL valid for 1 hour",
            "type": "string"
          }
        },
        "required": [
          "url"
        ],
        "type": "object"
      },
      "EvidenceResourceIdentifier": {
        "description": "Resource identifier analysis from the evidence",
        "properties": {
          "identifier_text": {
            "description": "The exact text of the resource identifier",
            "type": "string"
          },
          "identifier_type": {
            "description": "Type of identifier detected",
            "enum": [
              "url",
              "hierarchical_path",
              "prefixed_code",
              "channel_name",
              "named_resource"
            ],
            "type": "string"
          },
          "is_valid": {
            "description": "Whether this appears to be a genuine resource identifier",
            "type": "boolean"
          },
          "location": {
            "description": "Where the identifier appears in the image",
            "enum": [
              "address_bar",
              "overlay",
              "header",
              "breadcrumb",
              "sidebar",
              "toolbar",
              "content"
            ],
            "type": "string"
          }
        },
        "type": "object"
      },
      "EvidenceTimestampAnalysis": {
        "description": "Timestamp analysis from the evidence",
        "properties": {
          "is_valid_absolute": {
            "description": "Whether this is a valid absolute timestamp (day+month+hour minimum)",
            "type": "boolean"
          },
          "raw_text": {
            "description": "The exact text of the timestamp as it appears in the image",
            "type": "string"
          },
          "rejection_reason": {
            "description": "If is_valid_absolute is false, explains why",
            "type": "string"
          },
          "timestamp_source": {
            "description": "Where the timestamp appears",
            "enum": [
              "system_ui",
              "overlay",
              "document_content"
            ],
            "type": "string"
          }
        },
        "type": "object"
      },
      "EvidenceType": {
        "description": "The type of evidence.",
        "enum": [
          "IMAGE",
          "FILE",
          "LINK",
          "NOTE",
          "IN_APP_DOCUMENT"
        ],
        "type": "string"
      },
      "Group": {
        "properties": {
          "createdAt": {
            "description": "The time the evidence was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the group.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the group.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "members": {
            "items": {
              "$ref": "#/components/schemas/GroupMember"
            },
            "type": "array"
          },
          "name": {
            "description": "The name of the group.",
            "type": "string"
          },
          "policies": {
            "items": {
              "$ref": "#/components/schemas/Policy"
            },
            "type": "array"
          },
          "tenantId": {
            "description": "The id of the tenant this group belongs to",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the evidence was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "members",
          "policies",
          "tenantId"
        ],
        "type": "object"
      },
      "GroupMember": {
        "description": "A lightweight tenant member representation for group membership lists.",
        "properties": {
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          }
        },
        "required": [
          "id",
          "name",
          "status"
        ],
        "type": "object"
      },
      "GroupShort": {
        "description": "A lightweight group representation with display-relevant fields only.",
        "properties": {
          "id": {
            "description": "The ID of the group.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the group.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant this group belongs to",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "tenantId"
        ],
        "type": "object"
      },
      "ImpactedPeriod": {
        "properties": {
          "alertingSince": {
            "description": "Original alerting time (for context)",
            "format": "date-time",
            "type": "string"
          },
          "endedAt": {
            "description": "When this specific status period ended (null if still ongoing)",
            "format": "date-time",
            "type": "string"
          },
          "reasons": {
            "description": "Reasons for this period",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "startedAt": {
            "description": "When this specific status period started",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          }
        },
        "required": [
          "status",
          "startedAt",
          "slaType",
          "alertingSince",
          "reasons"
        ],
        "type": "object"
      },
      "InAppDocument": {
        "properties": {
          "createdAt": {
            "description": "The time that this document was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "A description for the document.",
            "type": "string"
          },
          "editorJSBody": {
            "$ref": "#/components/schemas/DocumentEditorObject"
          },
          "id": {
            "description": "The id of the document.",
            "type": "string"
          },
          "template": {
            "$ref": "#/components/schemas/InAppDocumentTemplate"
          },
          "templateId": {
            "description": "The id of the template for the document.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant that owns the document.",
            "type": "string"
          },
          "title": {
            "description": "The title of the document.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this document was updated.",
            "format": "date-time",
            "type": "string"
          },
          "usedByEvidenceIds": {
            "description": "The evidence ids that use this document as control attachments.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "description",
          "editorJSBody",
          "user",
          "tenantId"
        ],
        "type": "object"
      },
      "InAppDocumentTemplate": {
        "properties": {
          "description": {
            "description": "A description for the document template.",
            "type": "string"
          },
          "editorJSBody": {
            "$ref": "#/components/schemas/DocumentEditorObject"
          },
          "id": {
            "description": "The id of the document template.",
            "type": "string"
          },
          "title": {
            "description": "The title of the document template.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "editorJSBody"
        ],
        "type": "object"
      },
      "Integration": {
        "properties": {
          "configuration": {
            "description": "The additional configuration of the integration.",
            "type": "object"
          },
          "connections": {
            "description": "The connections for this integration.",
            "items": {
              "$ref": "#/components/schemas/Connection"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this integration was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the integration.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integrationType": {
            "$ref": "#/components/schemas/IntegrationType"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "monitorCount": {
            "description": "The number of monitors for this integration.",
            "type": "integer"
          },
          "owner": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "ownerId": {
            "description": "The ID of the tenant member accountable for this integration.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "provider": {
            "$ref": "#/components/schemas/NangoProvider"
          },
          "statusUpdates": {
            "description": "Indicates which types of status messages are currently active for this integration.",
            "properties": {
              "degradation": {
                "description": "Whether there are any service degradation messages.",
                "type": "boolean"
              },
              "disruption": {
                "description": "Whether there are any service disruption messages.",
                "type": "boolean"
              },
              "permissionsUpdate": {
                "description": "Whether there are any permissions update messages.",
                "type": "boolean",
                "x-go-name": "PermissionsUpdate"
              }
            },
            "required": [
              "disruption",
              "degradation",
              "permissionsUpdate"
            ],
            "type": "object"
          },
          "tenantId": {
            "description": "The ID of the tenant that this integration belongs to.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this integration was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "tenantId",
          "integrationTypeId"
        ],
        "type": "object"
      },
      "IntegrationCategory": {
        "enum": [
          "INTERNAL",
          "ADMINISTRATION",
          "CLOUD_PROVIDER",
          "VERSION_CONTROL",
          "OBSERVABILITY",
          "MOBILE_DEVICE_MANAGEMENT",
          "VULNERABILITY_MANAGEMENT",
          "VPN",
          "SECRETS_MANAGEMENT",
          "COMMUNICATION",
          "PROJECT_MANAGEMENT",
          "FINANCIAL",
          "HUMAN_RESOURCES",
          "SPEND_MANAGEMENT",
          "AI_MODELS",
          "IDENTITY_PROVIDER",
          "CUSTOM"
        ],
        "type": "string"
      },
      "IntegrationType": {
        "properties": {
          "category": {
            "$ref": "#/components/schemas/IntegrationCategory"
          },
          "createdAt": {
            "description": "The time that this integration type was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the integration type.",
            "type": "string"
          },
          "formTag": {
            "description": "Form tag to choose the form to be rendered on the frontend",
            "type": "string"
          },
          "icon": {
            "description": "Icon to be rendered on the frontend",
            "type": "string"
          },
          "id": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "inspectorType": {
            "enum": [
              "GRAPHQL",
              "REST",
              "UNSUPPORTED"
            ],
            "type": "string"
          },
          "integrations": {
            "description": "The integrations for this integration type.",
            "items": {
              "$ref": "#/components/schemas/Integration"
            },
            "type": "array"
          },
          "isInTestingPhase": {
            "description": "Whether or not the integration type is in testing phase, and accessible by \"integration-tester\" flag.",
            "type": "boolean"
          },
          "isMarkedAsBeta": {
            "description": "Whether or not the integration type has a \"Beta\" label on the frontend.",
            "type": "boolean"
          },
          "isOneleetManaged": {
            "description": "Whether or not the integration type is managed by Oneleet.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the integration type.",
            "type": "string"
          },
          "requiresOAuth": {
            "description": "Whether or not the integration type requires OAuth.",
            "type": "boolean"
          },
          "supportsAutofixes": {
            "description": "Whether or not the integration type supports Oneleet autofixes.",
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this integration type was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "worksWithCodeSecurity": {
            "description": "Whether or not the integration type can be used with the Code Security module.",
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "description",
          "requiresOAuth",
          "inspectorType",
          "isOneleetManaged",
          "isInTestingPhase",
          "isMarkedAsBeta",
          "worksWithCodeSecurity",
          "supportsAutofixes",
          "formTag",
          "icon"
        ],
        "type": "object"
      },
      "MentionableUser": {
        "description": "A user that can be @mentioned in an audit's messages.",
        "properties": {
          "email": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "email"
        ],
        "type": "object"
      },
      "MentionableUserList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/MentionableUser"
            },
            "type": "array"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "Monitor": {
        "properties": {
          "alertingSince": {
            "description": "The time this monitor started alerting, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "breachesSlaAt": {
            "description": "The time this monitor will breach SLA, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "configuration": {
            "type": "object"
          },
          "controlSummaries": {
            "items": {
              "$ref": "#/components/schemas/ControlSummary"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "currentState": {
            "$ref": "#/components/schemas/MonitorState"
          },
          "disabledReason": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isEnabled": {
            "description": "Whether the monitor is enabled. Default is true.",
            "type": "boolean"
          },
          "latestRun": {
            "$ref": "#/components/schemas/MonitorRun"
          },
          "monitorType": {
            "$ref": "#/components/schemas/MonitorType"
          },
          "results": {
            "items": {
              "$ref": "#/components/schemas/MonitorAssetResult"
            },
            "type": "array"
          },
          "reviewRemindAt": {
            "description": "The time at which to re-review the monitor and potentially re-enable it.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedAt": {
            "description": "The date and time when the monitor was snoozed, if the monitor is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the monitor, if the monitor is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for snoozing the monitor, if the monitor is snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the monitor snooze period ends, if the monitor is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "stats": {
            "$ref": "#/components/schemas/MonitorStats"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStatus"
          },
          "statusChangedAt": {
            "description": "The time that this monitor's status last changed, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "tenantId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "isEnabled",
          "monitorType",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "MonitorAssetResult": {
        "properties": {
          "alertingSince": {
            "description": "The time that this monitor asset result started alerting, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "asset": {
            "$ref": "#/components/schemas/Asset"
          },
          "assetId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "breachesSlaAt": {
            "description": "The time that this monitor asset result will breach SLA, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this monitor result was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastRunAt": {
            "description": "The time that this monitor asset result was last run.",
            "format": "date-time",
            "type": "string"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "snoozedAt": {
            "description": "The date and time when the asset was snoozed, if the asset is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the asset, if the asset is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for snoozing the asset, if the asset is snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the asset snooze period ends, if the asset is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          },
          "statusChangedAt": {
            "description": "The time that this monitor asset result's status last changed.",
            "format": "date-time",
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "monitorId",
          "assetId",
          "status",
          "reasons",
          "slaType",
          "statusChangedAt",
          "lastRunAt",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "MonitorAssetResultStatus": {
        "description": "The status of a monitor asset result.",
        "enum": [
          "BREACHING_SLA",
          "ALERTING",
          "PASSING",
          "IGNORED",
          "SNOOZED"
        ],
        "type": "string"
      },
      "MonitorAssetStats": {
        "properties": {
          "count": {
            "description": "The total number of assets detected by this monitor.",
            "type": "integer"
          },
          "failingCount": {
            "description": "The number of assets failing this monitor.",
            "type": "integer"
          },
          "passingCount": {
            "description": "The number of assets passing this monitor.",
            "type": "integer"
          },
          "percentPassing": {
            "description": "The percentage of assets passing this monitor.",
            "type": "integer"
          }
        },
        "required": [
          "count",
          "passingCount",
          "failingCount",
          "percentPassing"
        ],
        "type": "object"
      },
      "MonitorCoveredAsset": {
        "description": "Current MonitorAssetResult snapshot for one asset covered by the monitor (status != IGNORED).",
        "properties": {
          "alertingSince": {
            "description": "When this asset started alerting; null if not alerting.",
            "format": "date-time",
            "type": "string"
          },
          "assetId": {
            "format": "uuid",
            "type": "string"
          },
          "assetName": {
            "type": "string"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "snooze": {
            "$ref": "#/components/schemas/MonitorCoveredAssetSnooze"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          },
          "statusChangedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "assetId",
          "assetName",
          "status",
          "statusChangedAt",
          "reasons"
        ],
        "type": "object"
      },
      "MonitorCoveredAssetSnooze": {
        "description": "Snooze metadata for a covered asset; present only when the asset is currently snoozed.",
        "properties": {
          "at": {
            "format": "date-time",
            "type": "string"
          },
          "byMemberName": {
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "until": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "until",
          "reason",
          "at"
        ],
        "type": "object"
      },
      "MonitorFinding": {
        "description": "One asset's contiguous run of impaired time, stitched across the MonitorState rows it spans — the same unit MonitorFindingsRollup counts. startedAt is the true start and may precede windowStart.\n",
        "properties": {
          "assetId": {
            "type": "string"
          },
          "assetInstanceId": {
            "type": "string"
          },
          "assetName": {
            "type": "string"
          },
          "endedAt": {
            "description": "Null while the finding is still open.",
            "format": "date-time",
            "type": "string"
          },
          "hasBreachedSla": {
            "description": "The asset was BREACHING_SLA at some point inside the window.",
            "type": "boolean"
          },
          "isOpenAtWindowEnd": {
            "type": "boolean"
          },
          "outcome": {
            "$ref": "#/components/schemas/MonitorFindingOutcome"
          },
          "periods": {
            "description": "The finding's status timeline, in order and contiguous: at least one period, the first starting at startedAt and the last ending at endedAt.\n",
            "items": {
              "$ref": "#/components/schemas/MonitorFindingPeriod"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "startedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "assetInstanceId",
          "assetId",
          "assetName",
          "startedAt",
          "hasBreachedSla",
          "isOpenAtWindowEnd",
          "outcome",
          "slaType",
          "periods"
        ],
        "type": "object"
      },
      "MonitorFindingOutcome": {
        "description": "Which of the four mutually exclusive rollup buckets a finding falls into.",
        "enum": [
          "REMEDIATED_WITHIN_SLA",
          "BREACHED_SLA",
          "STILL_OPEN_WITHIN_SLA",
          "STILL_OPEN_BREACHED_SLA"
        ],
        "type": "string"
      },
      "MonitorFindingPeriod": {
        "description": "One stretch of a finding spent at a single status.",
        "properties": {
          "endedAt": {
            "description": "Null while the period is still running.",
            "format": "date-time",
            "type": "string"
          },
          "reasons": {
            "description": "Why the asset was impaired during this period.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "startedAt": {
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          }
        },
        "required": [
          "status",
          "startedAt",
          "slaType",
          "reasons"
        ],
        "type": "object"
      },
      "MonitorFindingsRollup": {
        "description": "Summary of the monitor's findings over the audit observation window. A finding is one asset's contiguous run of impaired time, stitched across the MonitorState rows it spans, so an asset that alerts twice with a real gap counts twice. The four counts are mutually exclusive and sum to totalFindings.\n",
        "properties": {
          "breachedSla": {
            "description": "Findings that ended within the window and breached SLA while in it.",
            "type": "integer"
          },
          "remediatedWithinSla": {
            "description": "Findings that ended within the window without ever breaching SLA in it.",
            "type": "integer"
          },
          "stillOpenBreachedSla": {
            "description": "Findings still open at windowEnd that breached SLA.",
            "type": "integer"
          },
          "stillOpenWithinSla": {
            "description": "Findings still open at windowEnd that have not breached SLA.",
            "type": "integer"
          },
          "totalFindings": {
            "description": "Findings that overlap the window at all.",
            "type": "integer"
          },
          "windowEnd": {
            "description": "End of the observation window (exclusive); defaults to now for an in-progress audit.",
            "format": "date-time",
            "type": "string"
          },
          "windowStart": {
            "description": "Start of the observation window the counts were computed over.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "windowStart",
          "windowEnd",
          "totalFindings",
          "breachedSla",
          "remediatedWithinSla",
          "stillOpenWithinSla",
          "stillOpenBreachedSla"
        ],
        "type": "object"
      },
      "MonitorHistoryResponse": {
        "description": "Lifecycle history + current covered/ignored asset snapshot for a monitor, scoped to one audit.",
        "properties": {
          "coveredAssets": {
            "description": "Current MonitorAssetResult rows where status != IGNORED.",
            "items": {
              "$ref": "#/components/schemas/MonitorCoveredAsset"
            },
            "type": "array"
          },
          "findings": {
            "description": "Every finding overlapping the observation window, ordered by startedAt then assetInstanceId. Complete, never truncated, so its length always equals findingsRollup.totalFindings.\n",
            "items": {
              "$ref": "#/components/schemas/MonitorFinding"
            },
            "type": "array"
          },
          "findingsRollup": {
            "$ref": "#/components/schemas/MonitorFindingsRollup"
          },
          "ignoredAssets": {
            "description": "Current IgnoreAssetInstance rows for the monitor, followed by IGNORED MonitorAssetResult rows the monitor's check excluded. Check exclusions whose only reason is the generic not-applicable fallback are left out.\n",
            "items": {
              "$ref": "#/components/schemas/MonitorIgnoredAsset"
            },
            "type": "array"
          },
          "states": {
            "description": "Lifecycle states overlapping the audit observation window, chronological ascending.",
            "items": {
              "$ref": "#/components/schemas/MonitorStateHistoryEntry"
            },
            "type": "array"
          }
        },
        "required": [
          "states",
          "coveredAssets",
          "ignoredAssets",
          "findings",
          "findingsRollup"
        ],
        "type": "object"
      },
      "MonitorIgnoredAsset": {
        "description": "An asset the monitor doesn't evaluate, either because it was ignored on the monitor or because the monitor's check excluded it.\n",
        "properties": {
          "assetInstanceId": {
            "type": "string"
          },
          "assetName": {
            "type": "string"
          },
          "createdAt": {
            "description": "When the asset was ignored. Absent when source is CHECK.",
            "format": "date-time",
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "source": {
            "$ref": "#/components/schemas/MonitorIgnoredAssetSource"
          }
        },
        "required": [
          "assetInstanceId",
          "reason",
          "source"
        ],
        "type": "object"
      },
      "MonitorIgnoredAssetSource": {
        "description": "Who ignored an asset on a monitor. MANUAL means a person ignored it, AUTO means an integration's ignore rule did, and CHECK means the monitor's check excluded it.\n",
        "enum": [
          "MANUAL",
          "AUTO",
          "CHECK"
        ],
        "type": "string"
      },
      "MonitorRun": {
        "properties": {
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorRunStatus"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "status",
          "monitorId"
        ]
      },
      "MonitorRunStatus": {
        "description": "The status of a monitor run.",
        "enum": [
          "RUNNING",
          "SUCCEEDED",
          "FAILED",
          "INTERNAL_ERROR",
          "PERMISSIONS_ERROR",
          "TIMED_OUT",
          "CANCELED"
        ],
        "type": "string"
      },
      "MonitorState": {
        "properties": {
          "createdAt": {
            "description": "The time that this monitor state was created.",
            "format": "date-time",
            "type": "string"
          },
          "finishedAt": {
            "description": "The time that this monitor state finished.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "impactedAssets": {
            "description": "Assets that were impacted during this monitor state period",
            "items": {
              "$ref": "#/components/schemas/MonitorStateImpactedAsset"
            },
            "type": "array"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStateStatus"
          },
          "updatedAt": {
            "description": "The time that this monitor state was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "status",
          "monitorId",
          "reason"
        ]
      },
      "MonitorStateHistoryEntry": {
        "description": "A single entry in a monitor's lifecycle state history, windowed to an audit's observation period.",
        "properties": {
          "endedAt": {
            "description": "When this state ended; null if still active (MonitorState.finishedAt).",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "impactedAssetCount": {
            "description": "Number of assets impacted during this state.",
            "type": "integer"
          },
          "reason": {
            "type": "string"
          },
          "startedAt": {
            "description": "When this state began (MonitorState.createdAt).",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStateStatus"
          }
        },
        "required": [
          "id",
          "status",
          "reason",
          "startedAt",
          "impactedAssetCount"
        ],
        "type": "object"
      },
      "MonitorStateImpactedAsset": {
        "properties": {
          "assetId": {
            "description": "The ID of the asset",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "assetInstanceId": {
            "description": "The stable instance ID of the asset",
            "type": "string"
          },
          "assetName": {
            "description": "The name of the asset",
            "type": "string"
          },
          "connectionId": {
            "description": "The ID of the connection",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connectionLabel": {
            "description": "The label of the connection",
            "type": "string"
          },
          "connectionReadableId": {
            "description": "The human-readable connection identifier",
            "type": "string"
          },
          "impactedPeriods": {
            "description": "Time periods when this asset was impacted",
            "items": {
              "$ref": "#/components/schemas/ImpactedPeriod"
            },
            "type": "array"
          }
        },
        "required": [
          "assetId",
          "assetInstanceId",
          "assetName",
          "connectionId",
          "connectionReadableId",
          "impactedPeriods"
        ],
        "type": "object"
      },
      "MonitorStateStatus": {
        "description": "The status of a monitor.",
        "enum": [
          "INACTIVE",
          "PASSING",
          "ALERTING",
          "BREACHING_SLA",
          "SNOOZED"
        ],
        "type": "string"
      },
      "MonitorStats": {
        "properties": {
          "assets": {
            "$ref": "#/components/schemas/MonitorAssetStats"
          }
        },
        "required": [
          "assets"
        ],
        "type": "object"
      },
      "MonitorStatus": {
        "description": "The status of a monitor.",
        "enum": [
          "BREACHING_SLA",
          "ALERTING",
          "PASSING",
          "NO_APPLICABLE_ASSETS",
          "NOT_YET_RUN",
          "IGNORED",
          "SNOOZED",
          "DISABLED"
        ],
        "type": "string"
      },
      "MonitorType": {
        "properties": {
          "assetType": {
            "$ref": "#/components/schemas/AssetType"
          },
          "assetTypeId": {
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "maxLength": 100,
            "type": "string"
          },
          "isPassingByDefault": {
            "description": "Whether this monitor always passes because the provider guarantees the property; it cannot be configured and never alerts.",
            "type": "boolean"
          },
          "name": {
            "type": "string"
          },
          "rerunDisabled": {
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "createdAt",
          "updatedAt",
          "assetTypeId",
          "rerunDisabled",
          "isPassingByDefault"
        ],
        "type": "object"
      },
      "NangoProvider": {
        "description": "The provider we get from Nango for this specific integration. It's used to render the form for the integration.",
        "properties": {
          "authMode": {
            "description": "The auth mode for this provider.",
            "enum": [
              "API_KEY",
              "APP",
              "APP_STORE",
              "BASIC",
              "NONE",
              "OAUTH1",
              "OAUTH2",
              "OAUTH2_CC",
              "CUSTOM",
              "TBA",
              "TABLEAU",
              "JWT",
              "BILL",
              "TWO_STEP",
              "SIGNATURE"
            ],
            "type": "string"
          },
          "authType": {
            "description": "The authentication type for this provider.",
            "type": "string"
          },
          "connectionConfig": {
            "additionalProperties": {
              "$ref": "#/components/schemas/NangoProviderConnectionConfigField"
            },
            "type": "object"
          },
          "credentials": {
            "additionalProperties": {
              "$ref": "#/components/schemas/NangoProviderConnectionConfigField"
            },
            "type": "object"
          },
          "docs": {
            "description": "Documentation URL for this provider.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the provider.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "NangoProviderConnectionConfigField": {
        "description": "The connection config for the provider.",
        "properties": {
          "automated": {
            "description": "Whether this field is automatically handled by the system.",
            "type": "boolean"
          },
          "description": {
            "description": "Description of what this configuration field is for.",
            "type": "string"
          },
          "docSection": {
            "description": "Reference to a section in the documentation for this field.",
            "pattern": "^#[a-z0-9-]+$",
            "type": "string"
          },
          "example": {
            "description": "Example value for the configuration field.",
            "type": "string"
          },
          "format": {
            "description": "Format hint for the configuration field.",
            "enum": [
              "hostname",
              "uri",
              "uuid",
              "email"
            ],
            "type": "string"
          },
          "name": {
            "description": "The name of the configuration field.",
            "type": "string"
          },
          "optional": {
            "description": "Whether this field is optional.",
            "type": "boolean"
          },
          "order": {
            "description": "The order in which this field should appear in the form.",
            "type": "integer"
          },
          "pattern": {
            "description": "Regex pattern for validating the configuration field.",
            "type": "string"
          },
          "prefix": {
            "description": "Prefix text to display before the field value.",
            "type": "string"
          },
          "secret": {
            "description": "Whether this field contains secret information (like a password or API key).",
            "type": "boolean"
          },
          "suffix": {
            "description": "Suffix text to display after the field value.",
            "type": "string"
          },
          "title": {
            "description": "The human-readable title of the configuration field.",
            "type": "string"
          },
          "type": {
            "description": "The type of the configuration field.",
            "enum": [
              "string"
            ],
            "type": "string"
          }
        },
        "required": [
          "name",
          "type",
          "title",
          "description"
        ],
        "type": "object"
      },
      "OneleetRole": {
        "enum": [
          "SUPERADMIN",
          "ADMIN",
          "CLIENT",
          "PENTESTER",
          "PENTESTER_ADMIN",
          "CUSTOMER_EXPERIENCE",
          "AUDITOR"
        ],
        "type": "string"
      },
      "Policy": {
        "properties": {
          "aiReviewAcknowledgedAt": {
            "description": "When the tenant saw the most recent run's terminal outcome — by viewing a successful run's comments or dismissing a failed run's callout. Null while the outcome hasn't been seen; cleared when a new run starts.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewCompletedAt": {
            "description": "The time the most recent AI policy review run finished, whether it succeeded or failed. Null while it's in progress.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewNotes": {
            "description": "The most recent run's working notes: what it checked the draft against, what it considered raising and didn't, and why nothing was raised when that's the case. Null until the run succeeds.",
            "nullable": true,
            "type": "string"
          },
          "aiReviewStartedAt": {
            "description": "The time the most recent AI policy review run started.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewStatus": {
            "$ref": "#/components/schemas/AiPolicyReviewStatus"
          },
          "aiReviewVersionId": {
            "description": "The policy version the most recent run read. Null when that version was since deleted (e.g. a discarded draft).",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "aiReviewWorkflowRunId": {
            "description": "The Hatchet workflow run ID of the most recent AI policy review run.",
            "nullable": true,
            "type": "string"
          },
          "audience": {
            "$ref": "#/components/schemas/PolicyAudience"
          },
          "createdAt": {
            "description": "The time that this policy was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/User"
          },
          "currentVersion": {
            "$ref": "#/components/schemas/PolicyVersion"
          },
          "deletedAt": {
            "description": "The time that this policy was deleted. Absent for active policies.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the policy.",
            "type": "string"
          },
          "excludedGroups": {
            "description": "Groups that are excluded from needing to sign this policy",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "groups": {
            "description": "Groups that need to sign this policy, if the audience is GROUPS",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the policy.",
            "type": "string"
          },
          "name": {
            "description": "The name of the policy.",
            "type": "string"
          },
          "openCommentCount": {
            "description": "The number of open comments the policy's Comments tab displays: open comments whose anchors place onto the working draft or, without one, the latest published version. Open comments whose anchored text no longer exists there are excluded. Only set on the list read path.",
            "type": "integer"
          },
          "reviewer": {
            "$ref": "#/components/schemas/User"
          },
          "reviewerGroups": {
            "description": "Groups that are assigned to review changes when PolicyReviewerType is GROUPS.",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "reviewerRole": {
            "$ref": "#/components/schemas/TenantRole"
          },
          "reviewerType": {
            "$ref": "#/components/schemas/PolicyReviewerType"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this policy.",
            "type": "string"
          },
          "types": {
            "description": "The types of the policy.",
            "items": {
              "$ref": "#/components/schemas/PolicyType"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this policy was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "tenantId",
          "audience",
          "currentVersion",
          "createdAt",
          "updatedAt",
          "reviewerType"
        ]
      },
      "PolicyApplicableTenantMember": {
        "description": "A tenant member that needs to sign a policy.",
        "properties": {
          "hasSigned": {
            "description": "Whether or not this tenant member has signed this policy.",
            "type": "boolean"
          },
          "signature": {
            "$ref": "#/components/schemas/PolicySignature"
          },
          "tenantMember": {
            "$ref": "#/components/schemas/TenantMemberShort"
          }
        },
        "required": [
          "tenantMember",
          "hasSigned"
        ]
      },
      "PolicyAudience": {
        "enum": [
          "EVERYONE",
          "EMPLOYEES",
          "CONTRACTORS",
          "GROUPS"
        ],
        "type": "string"
      },
      "PolicyComment": {
        "description": "A durable review comment on a policy. Identity and lifecycle are stored on the policy; placement is computed per version — the anchor fields describe where the comment sits on the version it was read against.",
        "properties": {
          "anchorStatus": {
            "$ref": "#/components/schemas/PolicyCommentAnchorStatus"
          },
          "appliedSourceEnd": {
            "description": "Absolute offset where the applied text ends (exclusive).",
            "type": "integer"
          },
          "appliedSourceStart": {
            "description": "Absolute offset in the read version's markdown where an accepted suggestion's applied text starts. Present on resolved comments whose suggestion was applied on the read version and whose applied text still resolves in its content.",
            "type": "integer"
          },
          "author": {
            "$ref": "#/components/schemas/PolicyCommentAuthor"
          },
          "body": {
            "description": "The comment itself.",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "endBlockId": {
            "description": "The projected anchor's end block. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "string"
          },
          "endOffset": {
            "description": "Offset of the anchored span's end within the end block's text content.",
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isAiAuthored": {
            "description": "Whether an AI review run authored the comment.",
            "type": "boolean"
          },
          "isResolved": {
            "type": "boolean"
          },
          "lastHumanActivityAt": {
            "description": "When a human last acted on the comment (resolve, reopen, suggestion decision or edit, note edit). Never cleared; AI runs only touch comments this has never been set on.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "note": {
            "description": "Freeform context on the comment — why it isn't addressed yet, why it was resolved, anything the next reader (human or AI) should know.",
            "nullable": true,
            "type": "string"
          },
          "noteUpdatedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "noteUpdatedByUserId": {
            "description": "The human note author. Exactly one of the two note author fields is set when a note exists.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "noteWasUpdatedByAi": {
            "description": "Whether the note was last written by an AI review run.",
            "type": "boolean"
          },
          "originVersionId": {
            "description": "The policy version whose content the comment was created against. Comments render on that version and later ones, never earlier.",
            "format": "uuid",
            "type": "string"
          },
          "policyId": {
            "format": "uuid",
            "type": "string"
          },
          "quotedText": {
            "description": "The verbatim span of policy text the comment is about; never rewritten.",
            "type": "string"
          },
          "replies": {
            "description": "The comment's human reply thread, oldest first. Empty on AI-authored comments and for tenants without the review-enhancements rollout.",
            "items": {
              "$ref": "#/components/schemas/PolicyCommentReply"
            },
            "type": "array"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedByUserId": {
            "description": "The human resolver. Exactly one of the two resolver fields is set on a resolved comment.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "resolvedOnVersionId": {
            "description": "The version whose content the resolution happened against.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "sourceEnd": {
            "description": "Absolute offset of the anchored span's end in the read version's markdown (exclusive). Present when anchorStatus is ANCHORED or MOVED.",
            "type": "integer"
          },
          "sourceStart": {
            "description": "Absolute offset of the anchored span's start in the read version's markdown, computed from the stored block map. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "integer"
          },
          "sources": {
            "description": "Citations grounding the comment in tenant context.",
            "items": {
              "$ref": "#/components/schemas/PolicyCommentSource"
            },
            "type": "array"
          },
          "startBlockId": {
            "description": "The projected anchor's start block in the read version's block map. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "string"
          },
          "startOffset": {
            "description": "Offset of the anchored span's start within the start block's text content.",
            "type": "integer"
          },
          "suggestionContent": {
            "description": "The suggested replacement text. Null for DELETE suggestions and plain comments.",
            "nullable": true,
            "type": "string"
          },
          "suggestionEditedContent": {
            "description": "The reviewer's edit of the suggested content; when present it is what an accept applies.",
            "nullable": true,
            "type": "string"
          },
          "suggestionOperation": {
            "$ref": "#/components/schemas/PolicyCommentSuggestionOperation"
          },
          "suggestionStatus": {
            "$ref": "#/components/schemas/PolicyCommentSuggestionStatus"
          },
          "supersededByCommentId": {
            "description": "Set when a newer comment replaces this one (an AI run re-anchoring an outdated concern).",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "tldr": {
            "description": "One-sentence gist of the body, for compact views. Absent on comments created before the field existed; readers fall back to the body.",
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          },
          "wasResolvedByAi": {
            "description": "Whether an AI review run resolved the comment.",
            "type": "boolean"
          },
          "workflowRunId": {
            "description": "The Hatchet workflow run ID of the AI review run that authored the comment. Matches Policy.aiReviewWorkflowRunId for comments from the most recent run.",
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "id",
          "policyId",
          "originVersionId",
          "isAiAuthored",
          "quotedText",
          "body",
          "isResolved",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "PolicyCommentAnchorStatus": {
        "description": "How a comment's anchor places onto the version it was read against. ANCHORED means its block is unchanged; MOVED means the block changed but the quoted text was found uniquely elsewhere; OUTDATED means the quoted text is gone or ambiguous, so the comment cannot be placed.",
        "enum": [
          "ANCHORED",
          "MOVED",
          "OUTDATED"
        ],
        "type": "string"
      },
      "PolicyCommentAuthor": {
        "properties": {
          "id": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "type": "object"
      },
      "PolicyCommentReply": {
        "properties": {
          "author": {
            "$ref": "#/components/schemas/PolicyCommentAuthor"
          },
          "body": {
            "type": "string"
          },
          "commentId": {
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "id",
          "commentId",
          "author",
          "body",
          "createdAt"
        ],
        "type": "object"
      },
      "PolicyCommentSource": {
        "description": "A citation grounding a comment in a slice of tenant context.",
        "properties": {
          "excerpt": {
            "description": "Optional verbatim snippet from the source.",
            "nullable": true,
            "type": "string"
          },
          "label": {
            "description": "Human-facing name of the referenced entity.",
            "type": "string"
          },
          "referenceId": {
            "description": "The id of the referenced entity when one exists.",
            "nullable": true,
            "type": "string"
          },
          "type": {
            "description": "Which slice of tenant context the citation references (e.g. CONTROL, COMPANY_PROFILE).",
            "type": "string"
          }
        },
        "required": [
          "type",
          "label"
        ],
        "type": "object"
      },
      "PolicyCommentSuggestionOperation": {
        "description": "The kind of edit a comment's suggestion proposes against the quoted text.",
        "enum": [
          "REPLACE",
          "INSERT",
          "DELETE"
        ],
        "type": "string"
      },
      "PolicyCommentSuggestionStatus": {
        "description": "The suggestion's decision state. UNDECIDED is explicit — a comment without a suggestion has no status at all.",
        "enum": [
          "UNDECIDED",
          "ACCEPTED",
          "REJECTED"
        ],
        "type": "string"
      },
      "PolicyReviewerType": {
        "enum": [
          "NONE",
          "USER",
          "GROUPS",
          "ROLE"
        ],
        "type": "string"
      },
      "PolicySignature": {
        "description": "A policy signature.",
        "properties": {
          "createdAt": {
            "description": "The time that this policy signature was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the policy signature.",
            "type": "string"
          },
          "policyVersion": {
            "$ref": "#/components/schemas/PolicyVersion"
          },
          "policyVersionId": {
            "description": "The ID of the policy associated with this policy signature.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy signature was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/UserPublic"
          }
        },
        "required": [
          "id",
          "policyVersionId",
          "user",
          "createdAt",
          "updatedAt"
        ]
      },
      "PolicyType": {
        "properties": {
          "createdAt": {
            "description": "The time that this policy type was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "name": {
            "description": "The name of this policy type.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy type was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "PolicyVersion": {
        "description": "A policy version.",
        "properties": {
          "applicableSignatures": {
            "description": "Combined signatures and inherited signatures that count towards this policy version",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "applicableTenantMembers": {
            "description": "The tenant members that need to sign this policy version, including their signatures if they have signed.",
            "items": {
              "$ref": "#/components/schemas/PolicyApplicableTenantMember"
            },
            "type": "array"
          },
          "blocks": {
            "description": "The version's block index, present on markdown-backed versions whose block map has been computed.",
            "items": {
              "$ref": "#/components/schemas/PolicyVersionBlock"
            },
            "type": "array"
          },
          "comments": {
            "description": "The policy's review comments projected onto this version's content. Populated only on the single-version read, and only for comment render targets (the latest published version and the working draft) — historical versions carry an empty list.",
            "items": {
              "$ref": "#/components/schemas/PolicyComment"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this policy version was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/User"
          },
          "deletedAt": {
            "description": "The time that this policy version was deleted. Absent for active versions.",
            "format": "date-time",
            "type": "string"
          },
          "directSignatures": {
            "description": "The signatures associated with this policy version.",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "fileName": {
            "description": "The policy's file name.",
            "type": "string"
          },
          "fileUrl": {
            "description": "The policy's file url.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the policy version.",
            "type": "string"
          },
          "inheritedSignatures": {
            "description": "Signatures from previous minor versions that count towards this policy version.",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "isPublished": {
            "description": "Whether or not this policy version is published.",
            "type": "boolean"
          },
          "markdown": {
            "description": "The markdown content of the policy version.",
            "type": "string"
          },
          "minorVersionNumber": {
            "description": "The minor version number of the policy.",
            "type": "integer"
          },
          "pdfGenerationPending": {
            "description": "Whether PDF generation has been triggered for this version and is not yet complete.",
            "type": "boolean"
          },
          "policyId": {
            "description": "The ID of the policy associated with this policy version.",
            "type": "string"
          },
          "publishedAt": {
            "description": "The time that this policy version was published.",
            "format": "date-time",
            "type": "string"
          },
          "reviewNotes": {
            "description": "The review notes for this version.",
            "type": "string"
          },
          "reviewedAt": {
            "description": "The time at which that this policy version was reviewed.",
            "format": "date-time",
            "type": "string"
          },
          "reviewedBy": {
            "$ref": "#/components/schemas/User"
          },
          "reviewedWithEdits": {
            "description": "Whether the reviewer changed the version content as part of approval.",
            "type": "boolean"
          },
          "status": {
            "description": "The current status of the policy version.",
            "enum": [
              "DRAFT",
              "IN_REVIEW",
              "PUBLISHED"
            ],
            "type": "string"
          },
          "submittedMarkdown": {
            "description": "The markdown the author submitted, present only when the reviewer edited it on approval. Diffing it against markdown shows exactly what the reviewer changed, which reviewedWithEdits on its own cannot.",
            "nullable": true,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy version was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "versionNumber": {
            "description": "The version number of the policy.",
            "type": "integer"
          }
        },
        "required": [
          "id",
          "policyId",
          "versionNumber",
          "minorVersionNumber",
          "isPublished",
          "status",
          "createdAt",
          "updatedAt",
          "pdfGenerationPending",
          "reviewedWithEdits"
        ]
      },
      "PolicyVersionBlock": {
        "description": "One anchorable unit of a version's markdown. The block index lets a client clamp a text selection to the same spans the server anchors against, so a comment's quoted text never picks up markdown syntax the anchor excludes. Text is not repeated here — slice it out of the version's markdown with the offsets.",
        "properties": {
          "blockId": {
            "description": "Content hash of the block, stable while its words are unchanged.",
            "type": "string"
          },
          "sourceEnd": {
            "description": "Byte offset where it ends (exclusive).",
            "type": "integer"
          },
          "sourceStart": {
            "description": "Byte offset in the version's markdown where the block's anchorable text begins.",
            "type": "integer"
          },
          "type": {
            "description": "The block's kind (HEADING, PARAGRAPH, LIST_ITEM, CODE_BLOCK, BLOCKQUOTE, TABLE, HTML_BLOCK).",
            "type": "string"
          }
        },
        "required": [
          "blockId",
          "type",
          "sourceStart",
          "sourceEnd"
        ],
        "type": "object"
      },
      "RiskCategory": {
        "enum": [
          "SECURITY",
          "OPERATIONAL",
          "FINANCIAL",
          "LEGAL_AND_COMPLIANCE",
          "STRATEGIC_AND_MARKET",
          "FRAUD"
        ],
        "type": "string"
      },
      "RiskImpact": {
        "enum": [
          "NEGLIGIBLE",
          "MINOR",
          "MODERATE",
          "MAJOR",
          "DEVASTATING"
        ],
        "type": "string"
      },
      "RiskLikelihood": {
        "enum": [
          "REMOTE",
          "UNLIKELY",
          "POSSIBLE",
          "LIKELY",
          "ALMOST_CERTAIN"
        ],
        "type": "string"
      },
      "RiskResponse": {
        "enum": [
          "MITIGATE",
          "TRANSFER",
          "AVOID",
          "ACCEPT"
        ],
        "type": "string"
      },
      "SlaType": {
        "description": "The SLA type of a monitor asset result.",
        "enum": [
          "GENERAL",
          "POLICY_SIGNING",
          "SECURITY_TRAINING",
          "VENDOR_ASSESSMENT",
          "RISK_ASSESSMENT",
          "ACCESS_REVIEW",
          "INFORMATIONAL",
          "LOW_SEVERITY",
          "MEDIUM_SEVERITY",
          "HIGH_SEVERITY",
          "CRITICAL"
        ],
        "type": "string"
      },
      "Tenant": {
        "properties": {
          "aiCompanyResearch": {
            "description": "The deep multi-paragraph company research blob produced by the AI company research workflow. Consumed by downstream AI workflows as prompt context.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchDomainSnapshot": {
            "description": "The domain value the current company research outputs were generated against. Compared against the live domain to detect drift.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchError": {
            "description": "Prose explaining why the most recent AI company research run failed or was cancelled. Populated on FAILED or CANCELLED.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchGeneratedAt": {
            "description": "The time of the most recent successful AI company research generation.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchHints": {
            "description": "Free-text steering context curated by the security program manager, passed verbatim to the AI on the next research run.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchHintsSnapshot": {
            "description": "Snapshot of the AI research hints at the dispatch moment of the most recent successful run. Compared against the live hints to surface a drift indicator.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchNotes": {
            "description": "Human-facing meta-commentary about the most recent successful research run (coverage gaps, ambiguous sources, suspected-stale info). Distinct from the failure error, which describes why a run failed.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchStatus": {
            "$ref": "#/components/schemas/AiCompanyResearchStatus"
          },
          "aiCompanySummary": {
            "description": "The concise one-paragraph human-scannable company summary derived from the research in the same workflow run.",
            "nullable": true,
            "type": "string"
          },
          "aiRiskPersonalizationGeneratedAt": {
            "description": "The time of the most recent successful AI risk personalization, when the current results were generated.",
            "format": "date-time",
            "type": "string"
          },
          "aiRiskPersonalizationResults": {
            "$ref": "#/components/schemas/AiRiskPersonalizationResults"
          },
          "aiRiskPersonalizationStatus": {
            "$ref": "#/components/schemas/AiRiskPersonalizationStatus"
          },
          "companyAddress": {
            "description": "The registered address of the company.",
            "type": "string"
          },
          "companyProfile": {
            "description": "Company profile data filled by Oneleet admins.",
            "type": "object"
          },
          "companyProfileUpdatedAt": {
            "description": "The time that the company profile was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "completedOnboardingSteps": {
            "description": "List of onboarding step IDs that the tenant has completed (computed).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "complianceFrameworks": {
            "description": "The compliance frameworks this tenant has active.",
            "items": {
              "$ref": "#/components/schemas/ComplianceFramework"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this tenant was created.",
            "format": "date-time",
            "type": "string"
          },
          "deviceConfigDefaultsAcceptedAt": {
            "description": "When an admin completed the device-config secure-defaults opt-in (either applying the recommended baseline or choosing to configure manually). Null means the opt-in workflow hasn't been completed yet.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "enableAiFeatures": {
            "description": "Whether AI features are enabled for this tenant. Null means the user has not yet made a choice.",
            "nullable": true,
            "type": "boolean"
          },
          "enableChecklists": {
            "description": "Whether onboarding/offboarding checklists are enabled for this tenant. Null means not yet configured (defaults to enabled).",
            "nullable": true,
            "type": "boolean"
          },
          "engagements": {
            "description": "The engagements associated with this tenant.",
            "items": {
              "$ref": "#/components/schemas/Engagement"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "includeVersionHistoryInPolicyPdfs": {
            "description": "Whether policy versions are available in PDF format.",
            "type": "boolean"
          },
          "isAppInventoryEnabled": {
            "description": "Whether installed application inventory collection is enabled for this tenant.",
            "type": "boolean"
          },
          "isPreOnboardingTenant": {
            "description": "Whether the tenant was created before the onboarding flow was introduced (computed from createdAt).",
            "type": "boolean"
          },
          "legalName": {
            "description": "The registered legal name of the company.",
            "type": "string"
          },
          "members": {
            "description": "The members associated with this tenant.",
            "items": {
              "$ref": "#/components/schemas/TenantMember"
            },
            "type": "array"
          },
          "name": {
            "description": "The name of the tenant.",
            "type": "string"
          },
          "onboardingStatus": {
            "$ref": "#/components/schemas/TenantOnboardingStatus"
          },
          "policyOnboardingStatus": {
            "$ref": "#/components/schemas/TenantPolicyOnboardingStatus"
          },
          "pylonAccountId": {
            "description": "The Pylon account ID linked to this tenant. Absent when the tenant has not been synced to Pylon, or when the calling principal is not a superadmin.",
            "type": "string"
          },
          "recommendedSlug": {
            "description": "The suggested slug of the tenant.",
            "type": "string"
          },
          "skippedOnboardingSteps": {
            "description": "List of onboarding step IDs that the tenant has explicitly skipped.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaAccessReviewHours": {
            "description": "The service level agreement in hours for completing access reviews. omitted indicates disabled.",
            "type": "integer"
          },
          "slaCriticalHours": {
            "description": "The service level agreement in hours for resolving critical vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaGeneralHours": {
            "description": "The service level agreement in hours for resolving general vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaHighSeverityHours": {
            "description": "The service level agreement in hours for resolving high-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaInformationalHours": {
            "description": "The service level agreement in hours for resolving informational vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaLowSeverityHours": {
            "description": "The service level agreement in hours for resolving low-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaMediumSeverityHours": {
            "description": "The service level agreement in hours for resolving medium-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaPolicySigningHours": {
            "description": "The service level agreement in hours for signing policies. omitted indicates disabled.",
            "type": "integer"
          },
          "slaRiskAssessmentHours": {
            "description": "The service level agreement in hours for completing risk assessments. omitted indicates disabled.",
            "type": "integer"
          },
          "slaSecurityTrainingHours": {
            "description": "The service level agreement in hours for completing security training. omitted indicates disabled.",
            "type": "integer"
          },
          "slaVendorAssessmentHours": {
            "description": "The service level agreement in hours for completing vendor assessments. omitted indicates disabled.",
            "type": "integer"
          },
          "slug": {
            "description": "The slug of the tenant.",
            "type": "string"
          },
          "tenantOwnerScheduleCallUrl": {
            "description": "Scheduling-page URL (e.g. Calendly) of the Oneleet team member assigned\nto this tenant. Omitted when the tenant has no assigned owner or the\nowner has not configured a URL.\n",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this tenant was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "recommendedSlug",
          "onboardingStatus",
          "completedOnboardingSteps",
          "skippedOnboardingSteps",
          "isPreOnboardingTenant",
          "policyOnboardingStatus"
        ],
        "type": "object"
      },
      "TenantMember": {
        "properties": {
          "createdAt": {
            "description": "The time that this tenant member was created.",
            "format": "date-time",
            "type": "string"
          },
          "employmentEndDate": {
            "description": "The employment end date of the tenant member.",
            "format": "date-time",
            "type": "string"
          },
          "employmentStartDate": {
            "description": "The employment start date of the tenant member.",
            "format": "date-time",
            "type": "string"
          },
          "enableNotifications": {
            "description": "Whether or not to disable notifications for this tenant member.",
            "type": "boolean"
          },
          "groups": {
            "description": "The groups this tenant member is a part of.",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastTasksReminderSentAt": {
            "description": "The time that this tenant member was last reminded of tasks to complete.",
            "format": "date-time",
            "type": "string"
          },
          "managerId": {
            "description": "The tenant member this member reports to; omitted when unset.",
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/TenantRole"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          },
          "tenant": {
            "$ref": "#/components/schemas/Tenant"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/TenantMemberType"
          },
          "updatedAt": {
            "description": "The time that this tenant member was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/User"
          },
          "userPublic": {
            "$ref": "#/components/schemas/UserPublic"
          },
          "vendorAccounts": {
            "description": "The vendor accounts associated with this tenant member.",
            "items": {
              "$ref": "#/components/schemas/VendorAccountBase"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "name",
          "type",
          "role",
          "status",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "TenantMemberShort": {
        "description": "A lightweight tenant member representation with display-relevant fields only.",
        "properties": {
          "groups": {
            "description": "The groups this tenant member belongs to.",
            "items": {
              "$ref": "#/components/schemas/GroupShort"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "user": {
            "description": "The user associated with this tenant member.",
            "properties": {
              "email": {
                "description": "The email of the user.",
                "type": "string"
              }
            },
            "required": [
              "email"
            ],
            "type": "object"
          }
        },
        "required": [
          "id",
          "name",
          "user",
          "groups"
        ],
        "type": "object"
      },
      "TenantMemberStatus": {
        "enum": [
          "NOT_ONBOARDED",
          "ONBOARDING",
          "CURRENT",
          "OFFBOARDING",
          "FORMER"
        ],
        "type": "string"
      },
      "TenantMemberType": {
        "enum": [
          "EMPLOYEE",
          "CONTRACTOR",
          "GUEST"
        ],
        "type": "string"
      },
      "TenantOnboardingStatus": {
        "description": "The onboarding status of the tenant.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "COMPLETED",
          "SKIPPED",
          "DEMO_CREATED",
          "DEMO_READY"
        ],
        "type": "string"
      },
      "TenantPolicyOnboardingStatus": {
        "description": "The policy onboarding status of the tenant.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "COMPLETED"
        ],
        "type": "string"
      },
      "TenantRole": {
        "enum": [
          "ADMIN",
          "MEMBER",
          "AUDITOR",
          "EMPLOYEE",
          "INVITED",
          "FORMER_EMPLOYEE"
        ],
        "type": "string"
      },
      "TenantTester": {
        "properties": {
          "createdAt": {
            "description": "The time that this tenant tester was created.",
            "format": "date-time",
            "type": "string"
          },
          "engagementId": {
            "description": "The ID of the engagement that this tenant tester is associated with.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "description": "The ID of the tenant tester.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "unassigned": {
            "description": "Whether or not this tenant tester is unassigned.",
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this tenant tester was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/UserShort"
          },
          "version": {
            "description": "The version of the tenant tester.",
            "type": "number"
          }
        },
        "type": "object"
      },
      "UpdateAuditPortalAssignmentPayload": {
        "properties": {
          "additionalAuditorIds": {
            "description": "User IDs of the auditors staffed on the audit alongside the main auditor.\nWhen present it replaces the whole set; an empty array clears it. Absent\nleaves the set untouched.\n",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "auditId": {
            "description": "The ID of the audit to update.",
            "format": "uuid",
            "type": "string"
          },
          "auditorGroupId": {
            "description": "The ID of the audit firm group to assign.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "auditorId": {
            "description": "The ID of the audit firm auditor user to assign.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "clearAuditorGroupId": {
            "description": "Set to true to clear the auditor group assignment.",
            "type": "boolean"
          },
          "clearAuditorId": {
            "description": "Set to true to clear the auditor assignment.",
            "type": "boolean"
          }
        },
        "required": [
          "auditId"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "User": {
        "properties": {
          "changelogAcknowledgedAt": {
            "description": "The last changelog entry date the user acknowledged before entries were\ntracked individually. Entries dated on or before it count as seen. Null\nif never acknowledged.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "changelogSeenSlugs": {
            "description": "Slugs of the in-app changelog entries the user has viewed.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this user was created.",
            "format": "date-time",
            "type": "string"
          },
          "email": {
            "description": "The email address of the user.",
            "format": "email",
            "type": "string"
          },
          "emailVerified": {
            "description": "Whether the user has verified their email address.",
            "type": "boolean"
          },
          "id": {
            "description": "The ID of the user.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          },
          "oneleetRole": {
            "$ref": "#/components/schemas/OneleetRole"
          },
          "oneleetStaffScheduleCallUrl": {
            "description": "Scheduling-page URL (e.g. Calendly) for Oneleet staff. Shown to tenants\nthis user owns so they can book a call with their assigned Oneleet\ncontact. Omitted for non-staff users and staff without a configured URL.\n",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this user was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "email",
          "emailVerified",
          "oneleetRole"
        ],
        "type": "object"
      },
      "UserPublic": {
        "properties": {
          "email": {
            "description": "The email address of the user.",
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          }
        },
        "required": [
          "email",
          "name"
        ],
        "type": "object"
      },
      "UserShort": {
        "properties": {
          "email": {
            "description": "The email address of the user.",
            "format": "email",
            "type": "string"
          },
          "id": {
            "description": "The ID of the user.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          },
          "oneleetRole": {
            "$ref": "#/components/schemas/OneleetRole"
          }
        },
        "required": [
          "id",
          "name",
          "email",
          "oneleetRole"
        ],
        "type": "object"
      },
      "VendorAccountBase": {
        "properties": {
          "asset": {
            "$ref": "#/components/schemas/Asset"
          },
          "assetId": {
            "description": "The ID of the asset this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connection": {
            "$ref": "#/components/schemas/Connection"
          },
          "connectionId": {
            "description": "The ID of the connection this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this vendor account was created.",
            "format": "date-time",
            "type": "string"
          },
          "email": {
            "description": "The email of the user for this vendor account.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the vendor account.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "ignoreReason": {
            "description": "The reason the account was ignored, if it is ignored.",
            "type": "string"
          },
          "ignoredAt": {
            "description": "The time the account was ignored, if it is ignored.",
            "format": "date-time",
            "type": "string"
          },
          "ignoredById": {
            "description": "The ID of the tenant member who ignored the account, if it is ignored.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "image": {
            "description": "The profile image URL of the user for this vendor account.",
            "type": "string"
          },
          "isActive": {
            "description": "Whether the account is active or not.",
            "type": "boolean"
          },
          "isIgnored": {
            "description": "Whether the account has been ignored or not.",
            "type": "boolean"
          },
          "isMfaEnabled": {
            "description": "Whether the user is enabled for MFA.",
            "type": "boolean"
          },
          "isSnoozed": {
            "description": "Whether the account is currently snoozed, i.e. snoozedUntil is in the future. Snoozed accounts are hidden from detected-accounts review until the snooze ends.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the user for this vendor account.",
            "type": "string"
          },
          "roles": {
            "description": "The roles of the user for this vendor account.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "snoozedAt": {
            "description": "The time the account was snoozed, if it has been snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the account, if it has been snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason the account was snoozed, if it has been snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The time the snooze ends, if the account has been snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantMemberId": {
            "description": "The ID of the member this account belongs to, if null the account has not been linked to any member yet.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this vendor account was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "username": {
            "description": "The username of the user for this vendor account.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "tenantId",
          "connectionId",
          "isActive",
          "isIgnored",
          "isSnoozed"
        ],
        "type": "object"
      }
    },
    "securitySchemes": {
      "bearerAuth": {
        "description": "An audit-firm service key (service_\u003cid\u003e_\u003csecret\u003e) sent as Authorization: Bearer \u003cservice-key\u003e. Each operation names its required scope in x-service-key-scope and in its description. The key must belong to the audit firm in the request and hold the required scope. Tenant service keys and MCP OAuth access tokens aren't accepted.",
        "scheme": "bearer",
        "type": "http"
      },
      "cookieAuth": {
        "in": "cookie",
        "name": "oneleet",
        "type": "apiKey"
      }
    }
  },
  "info": {
    "description": "Operations an audit-firm service key can call. Each operation requires its documented AUDIT_PORTAL_* scope. Tenant service keys and MCP OAuth access tokens can't call these operations. Tenant integrations use the separate [public API reference](../api-reference). The Oneleet web application also uses internal routes that aren't part of this API and can change without notice.",
    "title": "Oneleet Auditor API",
    "version": "1.0.0"
  },
  "openapi": "3.0.3",
  "paths": {
    "/api/v1/audit-firms/{audit-firm}/audit-portal/assignment": {
      "patch": {
        "description": "Update the main auditor, additional auditors, and auditor group assignment for an audit from the audit portal.\n\n**Required scope:** `AUDIT_PORTAL_WRITE_AUDIT_STATUS`",
        "operationId": "AuditFirmUpdateAuditPortalAssignment",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateAuditPortalAssignmentPayload"
              }
            }
          },
          "required": true
        },
        "responses": {
          "204": {
            "description": "The audit assignment was updated"
          },
          "400": {
            "description": "The request was invalid"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "The audit, auditor, or auditor group does not exist"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Update audit portal assignment",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_AUDIT_STATUS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits": {
      "get": {
        "description": "List the audits engaged to an audit firm, for the audit-firm service-key API.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDITS`",
        "operationId": "AuditPortalListAudits",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Case-insensitive substring match against the audit type, tenant, and firm names.",
            "in": "query",
            "name": "search",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "The audit stages to filter by.",
            "in": "query",
            "name": "stages",
            "schema": {
              "items": {
                "$ref": "#/components/schemas/AuditStage"
              },
              "type": "array"
            }
          },
          {
            "description": "The auditor statuses to filter by.",
            "in": "query",
            "name": "statuses",
            "schema": {
              "items": {
                "$ref": "#/components/schemas/AuditorStatus"
              },
              "type": "array"
            }
          },
          {
            "description": "The field to sort by.",
            "in": "query",
            "name": "sortBy",
            "schema": {
              "default": "period",
              "enum": [
                "period",
                "client",
                "type",
                "stage",
                "status"
              ],
              "type": "string"
            }
          },
          {
            "description": "The sort direction.",
            "in": "query",
            "name": "sortOrder",
            "schema": {
              "default": "desc",
              "enum": [
                "asc",
                "desc"
              ],
              "type": "string"
            }
          },
          {
            "description": "Page number (1-indexed).",
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "maximum": 1000000,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "description": "Number of audits per page.",
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "maximum": 200,
              "minimum": 1,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditPortalAuditSummaryList"
                }
              }
            },
            "description": "A page of the firm's audits."
          },
          "400": {
            "description": "Invalid filter parameters"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List audits for a firm (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDITS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/evidence-requests": {
      "get": {
        "description": "List auditor evidence requests for an audit (audit portal)\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalListEvidenceRequests",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Filter by status.",
            "in": "query",
            "name": "status",
            "schema": {
              "items": {
                "$ref": "#/components/schemas/AuditorEvidenceRequestStatus"
              },
              "type": "array"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AuditorEvidenceRequest"
                  },
                  "type": "array"
                }
              }
            },
            "description": "List of auditor evidence requests"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List auditor evidence requests (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      },
      "post": {
        "description": "Create and submit an auditor evidence request for SPM review (audit portal)\n\n**Required scope:** `AUDIT_PORTAL_WRITE_EVIDENCE_REQUESTS`",
        "operationId": "AuditPortalCreateEvidenceRequests",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "multipart/form-data": {
              "schema": {
                "$ref": "#/components/schemas/CreateAuditorEvidenceRequestPayload"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditorEvidenceRequest"
                }
              }
            },
            "description": "Created and submitted for SPM review"
          },
          "400": {
            "description": "Invalid request"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Create and submit auditor evidence request (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_EVIDENCE_REQUESTS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/evidence-requests/{requestId}": {
      "get": {
        "description": "Get a single auditor evidence request (audit portal)\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalGetEvidenceRequest",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the evidence request.",
            "in": "path",
            "name": "requestId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditorEvidenceRequest"
                }
              }
            },
            "description": "The auditor evidence request"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get auditor evidence request (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/evidence-requests/{requestId}/actions/{action}": {
      "post": {
        "description": "Perform a state transition on an auditor evidence request\n\n**Required scope:** `AUDIT_PORTAL_WRITE_EVIDENCE_REQUESTS`",
        "operationId": "AuditPortalUpdateEvidenceRequestAction",
        "parameters": [
          {
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "path",
            "name": "requestId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "path",
            "name": "action",
            "required": true,
            "schema": {
              "$ref": "#/components/schemas/AuditorEvidenceRequestAction"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AuditorEvidenceRequestActionPayload"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Action applied"
          },
          "400": {
            "description": "Invalid state transition or missing required field"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Perform action on auditor evidence request (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_EVIDENCE_REQUESTS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/evidence-requests/{requestId}/messages": {
      "get": {
        "description": "List the comments on an auditor evidence request (audit portal, auditor side)\n\n**Required scope:** `AUDIT_PORTAL_READ_MESSAGES`",
        "operationId": "AuditPortalListEvidenceRequestMessages",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the evidence request.",
            "in": "path",
            "name": "requestId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AuditMessage"
                  },
                  "type": "array"
                }
              }
            },
            "description": "List of comments sorted newest first"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List evidence request comments (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_MESSAGES"
      },
      "post": {
        "description": "Comment on an auditor evidence request (audit portal, auditor side)\n\n**Required scope:** `AUDIT_PORTAL_WRITE_MESSAGES`",
        "operationId": "AuditPortalCreateEvidenceRequestMessages",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the evidence request.",
            "in": "path",
            "name": "requestId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateAuditMessagePayload"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditMessage"
                }
              }
            },
            "description": "Comment created"
          },
          "400": {
            "description": "Invalid request"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Comment on an evidence request (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_MESSAGES"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/evidence-requests/{requestId}/transitions": {
      "get": {
        "description": "List the status history of an auditor evidence request (audit portal)\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalListEvidenceRequestTransitions",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the evidence request.",
            "in": "path",
            "name": "requestId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AuditorEvidenceRequestStateTransition"
                  },
                  "type": "array"
                }
              }
            },
            "description": "State transitions sorted newest first"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List auditor evidence request history (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/mentionable-users": {
      "get": {
        "description": "List users that can be @mentioned in an audit's messages (audit portal, auditor side)\n\n**Required scope:** `AUDIT_PORTAL_READ_MESSAGES`",
        "operationId": "AuditPortalListMentionableUsers",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MentionableUserList"
                }
              }
            },
            "description": "List of mentionable users"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List mentionable users (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_MESSAGES"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/messages": {
      "get": {
        "description": "List messages for an audit (audit portal, auditor side)\n\n**Required scope:** `AUDIT_PORTAL_READ_MESSAGES`",
        "operationId": "AuditPortalListMessages",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AuditMessage"
                  },
                  "type": "array"
                }
              }
            },
            "description": "List of messages sorted newest first"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List audit messages (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_MESSAGES"
      },
      "post": {
        "description": "Send a message for an audit (audit portal, auditor side)\n\n**Required scope:** `AUDIT_PORTAL_WRITE_MESSAGES`",
        "operationId": "AuditPortalCreateMessages",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateAuditMessagePayload"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditMessage"
                }
              }
            },
            "description": "Message created"
          },
          "400": {
            "description": "Invalid request"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Send audit message (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_MESSAGES"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/policies": {
      "get": {
        "description": "List the policies in the audit's workspace whose current version is published, with that version's metadata. Policy documents, review notes and signatures aren't included.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalListPolicies",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditPolicyList"
                }
              }
            },
            "description": "Published policies, ordered by name"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List published policies for an audit (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/policies/{policyId}": {
      "get": {
        "description": "Read one published policy in the audit's workspace, with its current version's document and the metadata of every published version. Review notes, unpublished drafts and signatures aren't included.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalGetPolicy",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the policy.",
            "in": "path",
            "name": "policyId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditPolicyDetail"
                }
              }
            },
            "description": "The policy, its current version's document and its published version history"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit, firm or published policy not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get a published policy for an audit (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/snapshot": {
      "post": {
        "description": "Start generating an offline auditor_dump snapshot for an audit (audit\nportal, auditor side). The archive is built in the background: poll the\nget-snapshot endpoint with the returned id until status is COMPLETED, then\ndownload it from downloadUrl. While a snapshot for the audit is still\nPENDING or RUNNING, this returns that snapshot instead of starting another.\nThe snapshot includes the audit's evidence, policies, monitor states, the\nauditor \u003c\u003e SPM message thread, and evidence requests with their full state\nhistory + attachments. Only an auditor staffed on the firm may call this.\n\n\n**Required scope:** `AUDIT_PORTAL_WRITE_EVIDENCE_DUMP`",
        "operationId": "AuditPortalCreateSnapshot",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "202": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditSnapshot"
                }
              }
            },
            "description": "Snapshot generation accepted; poll the get-snapshot endpoint until status is COMPLETED."
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "The audit does not exist or is not visible to the current auditor."
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Start generating an audit snapshot (audit portal); poll the get-snapshot endpoint until COMPLETED",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_EVIDENCE_DUMP"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{auditId}/snapshots/{snapshotId}": {
      "get": {
        "description": "Get the status of an audit snapshot (audit portal, auditor side). Poll\nevery few seconds until status is COMPLETED, then download the archive\nfrom downloadUrl; the link is valid for one hour and re-issued on every\nread. Whole-audit and per-control snapshots are read through this same\nendpoint. Only an auditor staffed on the firm may call this.\n\n\n**Required scope:** `AUDIT_PORTAL_READ_EVIDENCE_DUMP`",
        "operationId": "AuditPortalGetSnapshot",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the audit.",
            "in": "path",
            "name": "auditId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the snapshot returned by the create endpoint.",
            "in": "path",
            "name": "snapshotId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditSnapshot"
                }
              }
            },
            "description": "The snapshot, with downloadUrl once it is COMPLETED."
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "The audit or snapshot does not exist or is not visible to the current auditor."
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get an audit snapshot's status (audit portal); poll until COMPLETED, then use downloadUrl",
        "x-service-key-scope": "AUDIT_PORTAL_READ_EVIDENCE_DUMP"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/controls": {
      "get": {
        "description": "List the controls in an audit's scope in the audit portal. For a SOC 2 audit that scope covers the tenant's in-scope Availability, Confidentiality, Processing Integrity and Privacy criteria as well as the Security framework the path identifies.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalListControls",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Optional audit ID. When provided, `evidenceRequestCount` on each control reflects AuditorEvidenceRequest rows scoped to this audit (excluding REJECTED_BY_SPM, WITHDRAWN). When omitted, all `evidenceRequestCount` values are 0.",
            "in": "query",
            "name": "auditId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AuditPortalControlListItem"
                  },
                  "type": "array"
                }
              }
            },
            "description": "List of controls for the audit"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit or firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "List controls for an audit (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/controls/{controlId}": {
      "get": {
        "description": "Get full detail for a single control in the audit portal.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalGetControl",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the control.",
            "in": "path",
            "name": "controlId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The audit whose per-control review status to attach. Resolves the exact audit the auditor is viewing (multiple audits can share a tenant compliance framework + firm). When omitted, falls back to the firm's audit for the framework.",
            "in": "query",
            "name": "auditId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditPortalControl"
                }
              }
            },
            "description": "Control detail"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Control or audit not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get control detail (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/controls/{controlId}/monitors/{monitorId}/history": {
      "get": {
        "description": "Get lifecycle history + current covered/ignored asset snapshot for a monitor scoped to a control on an audit (auditor portal).\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDIT_CONTENT`",
        "operationId": "AuditPortalGetMonitorHistory",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the control.",
            "in": "path",
            "name": "controlId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the monitor.",
            "in": "path",
            "name": "monitorId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MonitorHistoryResponse"
                }
              }
            },
            "description": "Monitor history"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Monitor, control, or audit not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get monitor history (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDIT_CONTENT"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/controls/{controlId}/review/actions/{action}": {
      "post": {
        "description": "Perform an auditor control-review action on a control in an audit (audit\nportal). `approve` closes the control out (no evidence required), `reopen`\nreturns it to OPEN. Distinct from evidence-request actions.\n\n\n**Required scope:** `AUDIT_PORTAL_WRITE_CONTROL_REVIEWS`",
        "operationId": "AuditPortalUpdateControlReviewAction",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the control.",
            "in": "path",
            "name": "controlId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The action to perform.",
            "in": "path",
            "name": "action",
            "required": true,
            "schema": {
              "$ref": "#/components/schemas/AuditControlReviewAction"
            }
          },
          {
            "description": "The audit the review is scoped to. Resolves the exact audit the auditor is viewing (multiple audits can share a tenant compliance framework + firm). When omitted, falls back to the firm's audit for the framework.",
            "in": "query",
            "name": "auditId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AuditControlReviewActionPayload"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Action applied"
          },
          "400": {
            "description": "Invalid state transition or missing required field"
          },
          "401": {
            "description": "Unauthorized (e.g. the auditor is not a member of the firm)"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Control or audit not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Perform auditor control-review action (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_CONTROL_REVIEWS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/controls/{controlId}/snapshot": {
      "post": {
        "description": "Start generating an offline snapshot scoped to a single control of an audit\n(audit portal, auditor side). The archive is built in the background: poll\nthe get-snapshot endpoint with the returned id and auditId until status is\nCOMPLETED, then download it from downloadUrl. While a snapshot for the\ncontrol is still PENDING or RUNNING, this returns that snapshot instead of\nstarting another. The snapshot includes the control's evidence, the\npolicies attached to its checks, its monitor history as CSV, and its\nevidence requests with their full state history + attachments. Only an\nauditor staffed on the firm may call this.\n\n\n**Required scope:** `AUDIT_PORTAL_WRITE_CONTROL_REVIEWS`",
        "operationId": "AuditPortalCreateControlSnapshot",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the control.",
            "in": "path",
            "name": "controlId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The audit to scope the snapshot to. Resolves the exact audit the auditor is viewing (multiple audits can share a tenant compliance framework + firm). When omitted, falls back to the firm's audit for the framework.",
            "in": "query",
            "name": "auditId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "202": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditSnapshot"
                }
              }
            },
            "description": "Snapshot generation accepted; poll the get-snapshot endpoint until status is COMPLETED."
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "The audit or control does not exist or is not visible to the current auditor."
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Start generating a per-control snapshot (audit portal); poll the get-snapshot endpoint until COMPLETED",
        "x-service-key-scope": "AUDIT_PORTAL_WRITE_CONTROL_REVIEWS"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/audits/{tenantComplianceFrameworkId}/evidence/{evidenceId}/download-url": {
      "get": {
        "description": "Get a fresh presigned download URL for an evidence file linked to a control in the audit portal.\n\n**Required scope:** `AUDIT_PORTAL_READ_EVIDENCE`",
        "operationId": "AuditPortalGetEvidenceDownloadUrl",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the tenant compliance framework.",
            "in": "path",
            "name": "tenantComplianceFrameworkId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "The ID of the evidence.",
            "in": "path",
            "name": "evidenceId",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/EvidenceDownloadUrlResponse"
                }
              }
            },
            "description": "Presigned download URL"
          },
          "400": {
            "description": "Evidence has no downloadable file"
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Evidence, control, or audit not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get evidence download URL (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_EVIDENCE"
      }
    },
    "/api/v1/audit-firms/{audit-firm}/audit-portal/me": {
      "get": {
        "description": "Returns the audit-firm id and name the calling service key is scoped to, so an integrator can resolve its own firm id through the API instead of copying it out of a browser network tab.\n\n**Required scope:** `AUDIT_PORTAL_READ_AUDITS`",
        "operationId": "AuditPortalGetMe",
        "parameters": [
          {
            "description": "The ID of the audit firm.",
            "in": "path",
            "name": "audit-firm",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditPortalMe"
                }
              }
            },
            "description": "The audit firm the calling key is scoped to."
          },
          "403": {
            "description": "Forbidden"
          },
          "404": {
            "description": "Audit firm not found"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get key context (audit portal)",
        "x-service-key-scope": "AUDIT_PORTAL_READ_AUDITS"
      }
    }
  },
  "security": [
    {
      "bearerAuth": []
    }
  ]
}