{
  "components": {
    "schemas": {
      "APIError": {
        "properties": {
          "code": {
            "description": "a custom Oneleet error code",
            "example": 1400,
            "format": "uint64",
            "type": "integer",
            "x-go-name": "Code",
            "x-oapi-codegen-extra-tags": {
              "json": "code,omitempty"
            }
          },
          "consent_decision": {
            "description": "for CONSENT_REQUIRED errors: the tenant's current decision (UNDECIDED or DECLINED)",
            "type": "string",
            "x-go-name": "ConsentDecision",
            "x-oapi-codegen-extra-tags": {
              "json": "consent_decision,omitempty"
            }
          },
          "consent_feature": {
            "description": "for CONSENT_REQUIRED errors: the AI feature that needs consent",
            "type": "string",
            "x-go-name": "ConsentFeature",
            "x-oapi-codegen-extra-tags": {
              "json": "consent_feature,omitempty"
            }
          },
          "consent_version": {
            "description": "for CONSENT_REQUIRED errors: the current disclosure version",
            "type": "string",
            "x-go-name": "ConsentVersion",
            "x-oapi-codegen-extra-tags": {
              "json": "consent_version,omitempty"
            }
          },
          "description": {
            "description": "a description for this error",
            "example": "Bad request (detailed error)",
            "type": "string",
            "x-go-name": "Description"
          },
          "docs_link": {
            "description": "a link to the documentation for this error, if it exists",
            "type": "string",
            "x-go-name": "DocsLink"
          },
          "type": {
            "allOf": [
              {
                "$ref": "#/components/schemas/ErrorType"
              }
            ],
            "description": "The type of error.",
            "x-oapi-codegen-extra-tags": {
              "json": "type,omitempty"
            }
          }
        },
        "required": [
          "code",
          "type",
          "description"
        ],
        "type": "object"
      },
      "AccessReview": {
        "properties": {
          "completedAt": {
            "description": "The completion date of the access review.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The time the access review was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "dueBy": {
            "description": "The due date of the access review.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the access review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "startedAt": {
            "description": "The start date of the access review.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/AccessReviewStatus"
          },
          "title": {
            "description": "The title of the access review.",
            "type": "string"
          },
          "vendors": {
            "description": "The vendors marked for review.",
            "items": {
              "$ref": "#/components/schemas/AccessReviewVendor"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "title",
          "status",
          "dueBy",
          "vendors"
        ],
        "type": "object"
      },
      "AccessReviewAccount": {
        "properties": {
          "accessReviewVendorId": {
            "description": "The ID of the vendor the account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connection": {
            "$ref": "#/components/schemas/AccessReviewAccountConnection"
          },
          "createdAt": {
            "description": "The date the access review account was created.",
            "format": "date-time",
            "type": "string"
          },
          "diff": {
            "$ref": "#/components/schemas/AccessReviewAccountDiff"
          },
          "email": {
            "description": "The email of the account.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the access review account.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isActive": {
            "description": "Whether the account is active.",
            "type": "boolean"
          },
          "isIgnored": {
            "description": "Whether the account is ignored.",
            "type": "boolean"
          },
          "isMfaEnabled": {
            "description": "Whether MFA is enabled for the account.",
            "type": "boolean"
          },
          "lastSyncedAt": {
            "description": "The date the underlying vendor account was last synced by the integration sync pipeline. Only present when the account is live (not snapshotted).",
            "format": "date-time",
            "type": "string"
          },
          "name": {
            "description": "The name of the account.",
            "type": "string"
          },
          "note": {
            "description": "Note on the account.",
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/AccessReviewAccountOwner"
          },
          "roles": {
            "description": "The roles of the account.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "sourceVendorAccountId": {
            "description": "The ID of the source vendor account (present when account is snapshotted after review).",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantVendorId": {
            "description": "The ID of the tenant vendor.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The date the access review account was updated.",
            "format": "date-time",
            "type": "string"
          },
          "username": {
            "description": "The username of the account.",
            "type": "string"
          },
          "vendor": {
            "$ref": "#/components/schemas/Vendor"
          },
          "vendorAccountId": {
            "description": "The ID of the vendor account being reviewed (present when account is live).",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "id",
          "accessReviewVendorId",
          "vendor",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "AccessReviewAccountConnection": {
        "description": "Connection and integration information for the account.",
        "properties": {
          "id": {
            "description": "The ID of the connection.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integration": {
            "$ref": "#/components/schemas/AccessReviewAccountIntegration"
          },
          "label": {
            "description": "The custom label of the connection.",
            "type": "string"
          },
          "readableId": {
            "description": "The readable ID of the connection.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "readableId",
          "integration"
        ],
        "type": "object"
      },
      "AccessReviewAccountDiff": {
        "properties": {
          "previousIsMfaEnabled": {
            "type": "boolean"
          },
          "previousRoles": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/AccessReviewAccountDiffStatus"
          }
        },
        "required": [
          "status"
        ],
        "type": "object"
      },
      "AccessReviewAccountDiffStatus": {
        "enum": [
          "NEW",
          "REMOVED",
          "EXISTING"
        ],
        "type": "string"
      },
      "AccessReviewAccountIntegration": {
        "description": "Integration type information.",
        "properties": {
          "id": {
            "description": "The ID of the integration.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "AccessReviewAccountOwner": {
        "description": "Information about the tenant member who owns the account.",
        "properties": {
          "email": {
            "description": "The email of the tenant member.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          },
          "type": {
            "$ref": "#/components/schemas/TenantMemberType"
          }
        },
        "required": [
          "id",
          "email",
          "name",
          "type",
          "status"
        ],
        "type": "object"
      },
      "AccessReviewCreated": {
        "properties": {
          "id": {
            "description": "The ID of the created access review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "type": "object"
      },
      "AccessReviewStatus": {
        "enum": [
          "PLANNED",
          "IN_PROGRESS",
          "COMPLETED"
        ],
        "type": "string"
      },
      "AccessReviewVendor": {
        "properties": {
          "accessReviewAccounts": {
            "description": "The accounts to review.",
            "items": {
              "$ref": "#/components/schemas/AccessReviewAccount"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the vendor to review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reviewAttachmentFilename": {
            "description": "Original filename of the review attachment.",
            "type": "string"
          },
          "reviewNote": {
            "description": "Note attached to the vendor review.",
            "type": "string"
          },
          "reviewedAt": {
            "description": "The date the vendor review was completed.",
            "format": "date-time",
            "type": "string"
          },
          "reviewedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "reviewer": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "risk": {
            "$ref": "#/components/schemas/TenantVendorRisk"
          },
          "status": {
            "$ref": "#/components/schemas/AccessReviewVendorStatus"
          },
          "tenantVendorId": {
            "description": "The ID of the tenant vendor (present both when vendor is linked or snapshotted).",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "vendor": {
            "$ref": "#/components/schemas/Vendor"
          }
        },
        "required": [
          "id",
          "vendor",
          "tenantVendorId",
          "status",
          "accessReviewAccounts"
        ],
        "type": "object"
      },
      "AccessReviewVendorReviewAttachmentDownloadUrlResponse": {
        "properties": {
          "url": {
            "description": "Presigned URL to download the review attachment.",
            "type": "string"
          }
        },
        "required": [
          "url"
        ],
        "type": "object"
      },
      "AccessReviewVendorStatus": {
        "enum": [
          "NOT_STARTED",
          "REVIEWED"
        ],
        "type": "string"
      },
      "Action": {
        "properties": {
          "actionStatus": {
            "$ref": "#/components/schemas/ActionStatus"
          },
          "actionType": {
            "description": "Internal action type for filtering and searching.",
            "minLength": 1,
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "Markdown description of the action.",
            "nullable": true,
            "type": "string"
          },
          "dueDate": {
            "description": "Deadline for the action.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "groups": {
            "items": {
              "$ref": "#/components/schemas/ActionGroup"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "members": {
            "items": {
              "$ref": "#/components/schemas/ActionMember"
            },
            "type": "array"
          },
          "resourceUrns": {
            "items": {
              "$ref": "#/components/schemas/ActionResourceUrn"
            },
            "type": "array"
          },
          "summary": {
            "description": "One-line summary of the action.",
            "minLength": 1,
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "summary",
          "actionType",
          "actionStatus",
          "members",
          "groups",
          "resourceUrns",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "ActionGroup": {
        "properties": {
          "actionId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "groupId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          }
        },
        "required": [
          "id",
          "actionId",
          "groupId",
          "role"
        ],
        "type": "object"
      },
      "ActionListResult": {
        "properties": {
          "actions": {
            "items": {
              "$ref": "#/components/schemas/Action"
            },
            "type": "array"
          },
          "pagination": {
            "$ref": "#/components/schemas/ActionPagination"
          }
        },
        "required": [
          "actions",
          "pagination"
        ],
        "type": "object"
      },
      "ActionMember": {
        "properties": {
          "actionId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          },
          "tenantMemberId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "id",
          "actionId",
          "tenantMemberId",
          "role"
        ],
        "type": "object"
      },
      "ActionMemberRole": {
        "enum": [
          "OWNER",
          "ASSIGNEE",
          "VIEWER"
        ],
        "type": "string"
      },
      "ActionPagination": {
        "properties": {
          "limit": {
            "type": "integer"
          },
          "page": {
            "type": "integer"
          },
          "total": {
            "type": "integer"
          },
          "totalPages": {
            "type": "integer"
          }
        },
        "required": [
          "page",
          "limit",
          "total",
          "totalPages"
        ],
        "type": "object"
      },
      "ActionResourceUrn": {
        "properties": {
          "actionId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "label": {
            "description": "Human-readable label for the linked resource.",
            "nullable": true,
            "type": "string"
          },
          "rel": {
            "$ref": "#/components/schemas/ActionResourceUrnRel"
          },
          "resourceId": {
            "description": "The resource ID portion of the URN.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resourceType": {
            "description": "The resource type portion of the URN.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "actionId",
          "resourceType",
          "resourceId",
          "rel"
        ],
        "type": "object"
      },
      "ActionResourceUrnRel": {
        "enum": [
          "TARGET",
          "CONTEXT",
          "EVIDENCE",
          "SOURCE"
        ],
        "type": "string"
      },
      "ActionStatus": {
        "enum": [
          "OPEN",
          "IN_PROGRESS",
          "VERIFYING",
          "DONE",
          "CANCELED"
        ],
        "type": "string"
      },
      "Activity": {
        "properties": {
          "content": {
            "description": "The action that was performed",
            "type": "string"
          },
          "controlId": {
            "description": "The id of the control",
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "description": "The date and time the activity was created",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The id of the activity",
            "format": "uuid",
            "type": "string"
          },
          "isAuthoredByOneleet": {
            "description": "Whether the activity was authored by OneLeet",
            "type": "boolean"
          },
          "tenantId": {
            "description": "The id of the tenant",
            "format": "uuid",
            "type": "string"
          },
          "tenantMember": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "type": {
            "$ref": "#/components/schemas/ActivityType"
          },
          "updatedAt": {
            "description": "The date and time the activity was updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "tenantId",
          "content",
          "type"
        ],
        "type": "object"
      },
      "ActivityList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Activity"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "type": "object"
      },
      "ActivityType": {
        "enum": [
          "COMMENT",
          "ACTION"
        ],
        "type": "string"
      },
      "AddActionGroupRequest": {
        "properties": {
          "groupId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          }
        },
        "required": [
          "groupId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "AddActionMemberRequest": {
        "properties": {
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          },
          "tenantMemberId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantMemberId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "AddActionResourceUrnRequest": {
        "properties": {
          "label": {
            "description": "Human-readable label for the linked resource.",
            "type": "string"
          },
          "rel": {
            "$ref": "#/components/schemas/ActionResourceUrnRel"
          },
          "resourceId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resourceType": {
            "minLength": 1,
            "type": "string"
          }
        },
        "required": [
          "resourceType",
          "resourceId",
          "rel"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "AgentInfo": {
        "properties": {
          "agentVersion": {
            "type": "string"
          },
          "firstSeenAt": {
            "format": "date-time",
            "type": "string"
          },
          "isLatestVersion": {
            "type": "boolean"
          },
          "lastPing": {
            "format": "date-time",
            "type": "string"
          },
          "targetVersion": {
            "description": "Version the updater will install on this device, used to assess the installed agent. The workspace override, else the global default, else the newest published release.",
            "type": "string"
          }
        },
        "required": [
          "firstSeenAt"
        ]
      },
      "AgentTaskStatus": {
        "description": "The execution status of an agent task.",
        "enum": [
          "PENDING",
          "IN_PROGRESS",
          "COMPLETED",
          "FAILED",
          "OUTDATED"
        ],
        "type": "string"
      },
      "AiAdditionalLibraryRisk": {
        "description": "A risk from the library added by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "customizedFields": {
            "description": "Array of field names that were customized (title, description).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "description": {
            "description": "Description (may be same as original or customized).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was added and any customizations (for internal review only).",
            "type": "string"
          },
          "originalDescription": {
            "description": "Exact description from the risk library input (snapshot).",
            "type": "string"
          },
          "originalTitle": {
            "description": "Exact title from the risk library input (snapshot).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from the library.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Title (may be same as original or customized).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "originalTitle",
          "originalDescription",
          "customizedFields",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiAssessment": {
        "description": "Complete AI assessment snapshot stored with a risk when created from AI personalization.",
        "properties": {
          "suggestedAdditionalMeasures": {
            "type": "string"
          },
          "suggestedControls": {
            "items": {
              "$ref": "#/components/schemas/AiSuggestedControl"
            },
            "type": "array"
          },
          "suggestedControlsRationale": {
            "type": "string"
          },
          "suggestedHasResidualRisk": {
            "type": "boolean"
          },
          "suggestedHasResidualRiskConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedHasResidualRiskRationale": {
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "type": "string"
          },
          "suggestedResidualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedResidualImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualImpactRationale": {
            "type": "string"
          },
          "suggestedResidualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedResidualLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualLikelihoodRationale": {
            "type": "string"
          },
          "suggestedResponse": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "suggestedResponseAdequacy": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResponseAdequacyRationale": {
            "type": "string"
          },
          "suggestedResponseDetails": {
            "type": "string"
          },
          "suggestedResponseRationale": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "AiCompanyResearchStatus": {
        "description": "Status of the AI company research workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "CANCELLED"
        ],
        "type": "string"
      },
      "AiConsent": {
        "description": "A tenant's current consent decision for a single AI feature.",
        "properties": {
          "consent_version": {
            "description": "the disclosure version the decision was made against",
            "type": "string",
            "x-go-name": "ConsentVersion",
            "x-oapi-codegen-extra-tags": {
              "json": "consent_version,omitempty"
            }
          },
          "decision": {
            "$ref": "#/components/schemas/AiConsentDecision"
          },
          "feature": {
            "$ref": "#/components/schemas/AiFeature"
          }
        },
        "required": [
          "feature",
          "decision"
        ],
        "type": "object"
      },
      "AiConsentDecision": {
        "description": "A tenant's consent decision for an AI feature.",
        "enum": [
          "ACCEPTED",
          "DECLINED"
        ],
        "type": "string"
      },
      "AiConsentListResponse": {
        "description": "The tenant's current AI consent decisions (one per decided feature).",
        "properties": {
          "items": {
            "items": {
              "$ref": "#/components/schemas/AiConsent"
            },
            "type": "array"
          }
        },
        "required": [
          "items"
        ],
        "type": "object"
      },
      "AiCustomizedRiskRecommendation": {
        "description": "A base recommendation that was customized by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "customizedFields": {
            "description": "Array of field names that were changed (title, description, suggestedImpact, suggestedLikelihood).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "description": {
            "description": "Description (may be same as original or customized).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of what was customized and why (for internal review only).",
            "type": "string"
          },
          "originalDescription": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "originalSuggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "originalSuggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "originalTitle": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Title (may be same as original or customized).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "originalTitle",
          "originalDescription",
          "customizedFields",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiExcludedRisk": {
        "description": "A base recommendation that AI determined should be excluded.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was excluded (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk is not relevant (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations to exclude.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "title": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiFeature": {
        "description": "A per-product AI capability a tenant can consent to independently.",
        "enum": [
          "DEPENDENCY_TRIAGE",
          "EVIDENCE_REVIEW",
          "CONTROL_REVIEW",
          "RISK_PERSONALIZATION",
          "COMPANY_RESEARCH",
          "VENDOR_ASSESSMENT",
          "INTERNAL_AUDIT_DRAFTING",
          "SECTION_3_GENERATION",
          "ONBOARDING_AI",
          "QUESTIONNAIRE_AI",
          "POLICY_REVIEW"
        ],
        "type": "string"
      },
      "AiNovelRisk": {
        "description": "A new risk created by AI.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "AI-generated description.",
            "type": "string"
          },
          "id": {
            "description": "AI-generated ID (e.g., 'novel-1').",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this novel risk was created (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "AI-generated title following library conventions.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "AiPolicyReviewStatus": {
        "description": "Status of the AI policy review workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "CANCELLED"
        ],
        "type": "string"
      },
      "AiRiskPersonalizationConfidence": {
        "description": "How confident the AI is in an assessment.",
        "enum": [
          "LOW",
          "MEDIUM",
          "HIGH"
        ],
        "type": "string"
      },
      "AiRiskPersonalizationResults": {
        "description": "Results from the AI risk personalization workflow.",
        "properties": {
          "additionalLibraryRisks": {
            "description": "Risks from the library added by AI.",
            "items": {
              "$ref": "#/components/schemas/AiAdditionalLibraryRisk"
            },
            "type": "array"
          },
          "customizedRecommendations": {
            "description": "Base risk recommendations with customized fields.",
            "items": {
              "$ref": "#/components/schemas/AiCustomizedRiskRecommendation"
            },
            "type": "array"
          },
          "excludedRisks": {
            "description": "Base risk recommendations AI determined should be excluded.",
            "items": {
              "$ref": "#/components/schemas/AiExcludedRisk"
            },
            "type": "array"
          },
          "novelRisks": {
            "description": "New risks created by AI.",
            "items": {
              "$ref": "#/components/schemas/AiNovelRisk"
            },
            "type": "array"
          },
          "personalizationSummary": {
            "deprecated": true,
            "description": "Deprecated. Overview of how the risk assessment was personalized, retained for backward compatibility with results generated before riskAssessmentSummary was introduced. Use riskAssessmentSummary going forward.",
            "type": "string"
          },
          "researchSummary": {
            "deprecated": true,
            "description": "Deprecated. Summary of what AI learned from company website research, retained for backward compatibility with results generated before personalizationSummary existed. Use riskAssessmentSummary going forward.",
            "type": "string"
          },
          "riskAssessmentSummary": {
            "description": "Client-facing executive summary of the company's risk assessment — the dominant risk themes, why they matter to the company, and the overall risk posture.",
            "type": "string"
          },
          "riskResponseAssessments": {
            "description": "Risk response assessments from the AI (only present if tenant has controls).",
            "items": {
              "$ref": "#/components/schemas/AiRiskResponseAssessment"
            },
            "type": "array"
          },
          "unchangedRecommendations": {
            "description": "Base risk recommendations that were not modified (snapshot).",
            "items": {
              "$ref": "#/components/schemas/AiUnchangedRiskRecommendation"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "AiRiskPersonalizationStatus": {
        "description": "Status of the AI risk personalization workflow.",
        "enum": [
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED"
        ],
        "type": "string"
      },
      "AiRiskResponseAssessment": {
        "description": "AI assessment of how to respond to a risk, including control linking, response recommendation, and residual risk.",
        "properties": {
          "riskId": {
            "description": "Risk ID matching a risk from the personalization output.",
            "type": "string"
          },
          "suggestedAdditionalMeasures": {
            "description": "Advisory recommendations for additional measures the company could consider beyond current controls.",
            "type": "string"
          },
          "suggestedControls": {
            "description": "Controls from the tenant's program that address this risk (empty array if none).",
            "items": {
              "$ref": "#/components/schemas/AiSuggestedControl"
            },
            "type": "array"
          },
          "suggestedControlsRationale": {
            "description": "Client-facing explanation of why these controls were linked, or why no controls are relevant.",
            "type": "string"
          },
          "suggestedHasResidualRisk": {
            "description": "Whether residual risk remains after the response.",
            "type": "boolean"
          },
          "suggestedHasResidualRiskConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedHasResidualRiskRationale": {
            "description": "Client-facing explanation of why residual risk is eliminated (only when suggestedHasResidualRisk is false).",
            "type": "string"
          },
          "suggestedResidualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedResidualImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualImpactRationale": {
            "description": "Client-facing explanation of why this residual impact level (only when suggestedHasResidualRisk is true).",
            "type": "string"
          },
          "suggestedResidualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedResidualLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResidualLikelihoodRationale": {
            "description": "Client-facing explanation of why this residual likelihood level (only when suggestedHasResidualRisk is true).",
            "type": "string"
          },
          "suggestedResponse": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "suggestedResponseAdequacy": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedResponseAdequacyRationale": {
            "description": "Client-facing assessment of what's well-covered and what gaps remain.",
            "type": "string"
          },
          "suggestedResponseDetails": {
            "description": "Client-facing details on what the company is currently doing to address the risk (written in first person).",
            "type": "string"
          },
          "suggestedResponseRationale": {
            "description": "Client-facing explanation of why this response type is the best choice.",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "suggestedControls",
          "suggestedControlsRationale",
          "suggestedResponse",
          "suggestedResponseRationale",
          "suggestedResponseAdequacy",
          "suggestedResponseAdequacyRationale",
          "suggestedResponseDetails",
          "suggestedHasResidualRisk"
        ],
        "type": "object"
      },
      "AiSuggestedControl": {
        "description": "A control suggested for linking to a risk.",
        "properties": {
          "controlTypeId": {
            "description": "The control type identifier.",
            "type": "string"
          },
          "title": {
            "description": "The control's title (snapshot at the time of assessment).",
            "type": "string"
          }
        },
        "required": [
          "controlTypeId",
          "title"
        ],
        "type": "object"
      },
      "AiUnchangedRiskRecommendation": {
        "description": "A base recommendation that was not modified by AI (snapshot).",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "description": {
            "description": "Exact description from the base recommendation input (snapshot).",
            "type": "string"
          },
          "internalNotes": {
            "description": "Internal explanation of why this risk was kept unchanged (for internal review only).",
            "type": "string"
          },
          "rationale": {
            "description": "Client-facing explanation of why this risk matters (uses \"you/your\" language).",
            "type": "string"
          },
          "riskId": {
            "description": "Risk ID from base recommendations.",
            "type": "string"
          },
          "suggestedImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "suggestedImpactConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedImpactRationale": {
            "description": "Client-facing explanation of why this impact level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "suggestedLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "suggestedLikelihoodConfidence": {
            "$ref": "#/components/schemas/AiRiskPersonalizationConfidence"
          },
          "suggestedLikelihoodRationale": {
            "description": "Client-facing explanation of why this likelihood level was chosen (including confidence reasoning).",
            "type": "string"
          },
          "title": {
            "description": "Exact title from the base recommendation input (snapshot).",
            "type": "string"
          }
        },
        "required": [
          "riskId",
          "title",
          "description",
          "category",
          "suggestedImpact",
          "suggestedLikelihood",
          "suggestedImpactConfidence",
          "suggestedLikelihoodConfidence",
          "suggestedImpactRationale",
          "suggestedLikelihoodRationale",
          "rationale",
          "internalNotes"
        ],
        "type": "object"
      },
      "Asset": {
        "properties": {
          "assetInstanceId": {
            "description": "The instance ID of the asset.",
            "type": "string"
          },
          "assetType": {
            "$ref": "#/components/schemas/AssetType"
          },
          "assetTypeId": {
            "description": "The ID of the asset type associated with this asset.",
            "type": "string"
          },
          "connection": {
            "$ref": "#/components/schemas/Connection"
          },
          "connectionId": {
            "description": "The ID of the connection associated with this asset.",
            "type": "string"
          },
          "createdAt": {
            "description": "The date and time the asset was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The date and time the asset was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the asset.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the asset.",
            "type": "string"
          },
          "snoozedAt": {
            "description": "The date and time when the asset was globally snoozed, if it is globally snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the asset, if the asset is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for globally snoozing this asset, if it is globally snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the global snooze period ends for this asset, if it is globally snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStatus"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this asset.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the asset was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "assetInstanceId",
          "createdAt",
          "updatedAt",
          "name",
          "assetTypeId",
          "tenantId",
          "data",
          "connectionId"
        ]
      },
      "AssetResultSnapshot": {
        "properties": {
          "assetId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "assetInstanceId": {
            "type": "string"
          },
          "assetName": {
            "type": "string"
          }
        },
        "required": [
          "assetId",
          "assetInstanceId",
          "assetName"
        ]
      },
      "AssetStatus": {
        "properties": {
          "assetTypeId": {
            "description": "The ID of the asset.",
            "maxLength": 50,
            "type": "string"
          },
          "rawExchanges": {
            "description": "For failing statuses, the raw requests/responses sent to and received from third party APIs.",
            "type": "object"
          },
          "reason": {
            "description": "The reason for the asset status.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/AssetStatusEnum"
          },
          "updatedAt": {
            "description": "The time that this asset status was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "updatedAt",
          "assetTypeId",
          "status",
          "reason"
        ],
        "type": "object"
      },
      "AssetStatusEnum": {
        "description": "Status of an asset type query:\n- UNQUERIED: Not yet queried\n- SUCCEEDED: Query succeeded\n- FAILED: Query failed (requires user action)\n- RETRYING: Query encountered a transient error and will retry automatically\n",
        "enum": [
          "UNQUERIED",
          "SUCCEEDED",
          "FAILED",
          "RETRYING"
        ],
        "type": "string"
      },
      "AssetStatusList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/AssetStatus"
            },
            "type": "array"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "AssetType": {
        "properties": {
          "createdAt": {
            "description": "The date and time the asset type was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The date and time the asset type was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the asset type.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the asset type.",
            "type": "string"
          },
          "integrationType": {
            "$ref": "#/components/schemas/IntegrationType"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type associated with this asset type.",
            "type": "string"
          },
          "name": {
            "description": "The name of the asset type.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the asset type was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "description"
        ]
      },
      "AttackSurfaceAssetType": {
        "description": "The type of the target",
        "enum": [
          "ORG_STUB",
          "DOMAIN",
          "SUBDOMAIN",
          "DNS_NAME",
          "ASN",
          "IP_ADDRESS",
          "OPEN_TCP_PORT",
          "SOCIAL",
          "CODE_REPOSITORY",
          "STORAGE_BUCKET",
          "AZURE_TENANT",
          "EMAIL_ADDRESS",
          "TECHNOLOGY",
          "URL",
          "PROTOCOL",
          "BAAS_INSTANCE"
        ],
        "type": "string"
      },
      "AuditLog": {
        "properties": {
          "actor": {
            "description": "The display name of the actor (user email or service key name).",
            "type": "string"
          },
          "actorId": {
            "description": "The ID of the actor (user ID or service key ID).",
            "type": "string"
          },
          "actorType": {
            "description": "The type of actor (user or service_key).",
            "type": "string"
          },
          "country": {
            "description": "The country associated with the audit log.",
            "type": "string"
          },
          "ip": {
            "description": "The IP address associated with the audit log.",
            "type": "string"
          },
          "metadata": {
            "description": "The metadata associated with the audit log.",
            "type": "string"
          },
          "operation": {
            "description": "The operation associated with the audit log.",
            "type": "string"
          },
          "parentResourceId": {
            "description": "The ID of the parent resource associated with the audit log.",
            "type": "string"
          },
          "parentResourceName": {
            "description": "The name of the parent resource associated with the audit log.",
            "type": "string"
          },
          "parentResourceType": {
            "description": "The type of the parent resource associated with the audit log.",
            "type": "string"
          },
          "resourceId": {
            "description": "The ID of the resource associated with the audit log.",
            "type": "string"
          },
          "resourceName": {
            "description": "The name of the resource associated with the audit log.",
            "type": "string"
          },
          "resourceType": {
            "description": "The type of resource associated with the audit log.",
            "type": "string"
          },
          "serviceKeyCreatedBy": {
            "description": "The email of the user who created the service key, if the actor is a service key.",
            "nullable": true,
            "type": "string"
          },
          "serviceKeyCreatedById": {
            "description": "The ID of the user who created the service key, if the actor is a service key.",
            "nullable": true,
            "type": "string"
          },
          "tenantRole": {
            "description": "The tenant role associated with the audit log.",
            "type": "string"
          },
          "timestamp": {
            "description": "The timestamp of the audit log.",
            "format": "date-time",
            "type": "string"
          },
          "userAgent": {
            "description": "The user agent associated with the audit log.",
            "type": "string"
          }
        },
        "required": [
          "timestamp",
          "actor",
          "actorId",
          "operation",
          "resourceType",
          "resourceId",
          "resourceName"
        ],
        "type": "object"
      },
      "AuditLogList": {
        "properties": {
          "cursor": {
            "description": "The cursor to use to get the next page of audit logs.",
            "type": "string"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/AuditLog"
            },
            "type": "array"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "AuditStage": {
        "description": "The stage of the audit.",
        "enum": [
          "PREPARATION",
          "SCOPE_IDENTIFICATION",
          "MAINTENANCE_AND_IMPROVEMENT",
          "OBSERVATION_PERIOD",
          "INTERNAL_AUDIT",
          "STAGE_1_AUDIT",
          "STAGE_2_AUDIT",
          "AUDIT",
          "REPORT_READY"
        ],
        "type": "string"
      },
      "AuditType": {
        "properties": {
          "id": {
            "description": "The ID of the audit type.",
            "type": "string"
          },
          "name": {
            "description": "The title of the audit type.",
            "type": "string"
          },
          "stages": {
            "items": {
              "$ref": "#/components/schemas/AuditStage"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this audit type was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "updatedAt",
          "stages"
        ]
      },
      "BulkAssignActionGroupRequest": {
        "properties": {
          "actionIds": {
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "maxItems": 100,
            "minItems": 1,
            "type": "array",
            "uniqueItems": true
          },
          "groupId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          }
        },
        "required": [
          "actionIds",
          "groupId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "BulkAssignActionMemberRequest": {
        "properties": {
          "actionIds": {
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "maxItems": 100,
            "minItems": 1,
            "type": "array",
            "uniqueItems": true
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          },
          "tenantMemberId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "actionIds",
          "tenantMemberId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "Check": {
        "properties": {
          "createdAt": {
            "description": "The time that this check was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integration": {
            "$ref": "#/components/schemas/Integration"
          },
          "integrationCategory": {
            "$ref": "#/components/schemas/IntegrationCategory"
          },
          "isDisabled": {
            "description": "Whether or not this check is disabled.",
            "type": "boolean"
          },
          "monitor": {
            "$ref": "#/components/schemas/Monitor"
          },
          "policy": {
            "$ref": "#/components/schemas/Policy"
          },
          "policyType": {
            "$ref": "#/components/schemas/PolicyType"
          },
          "scopeItem": {
            "$ref": "#/components/schemas/CheckScopeItem"
          },
          "status": {
            "$ref": "#/components/schemas/CheckStatus"
          },
          "type": {
            "$ref": "#/components/schemas/CheckType"
          },
          "updatedAt": {
            "description": "The time that this check was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "status",
          "isDisabled",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "CheckList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Check"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "CheckScopeItem": {
        "description": "The durable per-resource scope item behind a SCOPE_ITEM check (e.g. one business-critical vendor on the MFA-for-critical-services control). The item is satisfied either by monitor coverage (autoSatisfied) or by evidence attached during its current interval.\n",
        "properties": {
          "activeFrom": {
            "description": "Start of the item's current in-scope interval.",
            "format": "date-time",
            "type": "string"
          },
          "autoSatisfied": {
            "description": "True when existing monitor coverage already satisfies this item and no manual evidence is needed.\n",
            "type": "boolean"
          },
          "autoSatisfiedByIntegrationIcon": {
            "type": "string"
          },
          "autoSatisfiedByIntegrationName": {
            "type": "string"
          },
          "autoSatisfiedByMonitorId": {
            "format": "uuid",
            "type": "string"
          },
          "autoSatisfiedByMonitorName": {
            "type": "string"
          },
          "coveredByMonitorId": {
            "description": "Set whenever an enabled monitor observes this resource at all (superset of autoSatisfied). When the monitor is not passing, remediation in the monitor is the primary path and manual evidence is a fallback.\n",
            "format": "uuid",
            "type": "string"
          },
          "coveredByMonitorName": {
            "type": "string"
          },
          "coveredByMonitorStatus": {
            "description": "The covering monitor's live state (e.g. PASSING, ALERTING, BREACHING_SLA).",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "evidenceIds": {
            "description": "Ids of evidence attached during the item's current interval; join against the control's evidence list for details.\n",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "iconUrl": {
            "description": "Display icon of the scoped resource, when available.",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "kind": {
            "description": "What the scoped resource is; scopeRef is its id.",
            "enum": [
              "VENDOR",
              "MEMBER"
            ],
            "type": "string"
          },
          "resourceUrl": {
            "description": "URL of the scoped resource (VENDOR → the vendor's website), for brand-icon fallback and display.\n",
            "type": "string"
          },
          "scopeRef": {
            "description": "Id of the scoped resource, interpreted per kind (VENDOR → TenantVendor id, MEMBER → TenantMember id).\n",
            "type": "string"
          },
          "title": {
            "description": "Display name of the scoped resource (e.g. the vendor's name).",
            "type": "string"
          }
        },
        "required": [
          "id",
          "kind",
          "scopeRef",
          "title",
          "autoSatisfied",
          "evidenceIds"
        ],
        "type": "object"
      },
      "CheckStatus": {
        "enum": [
          "PENDING",
          "IN_PROGRESS",
          "INACTIVE",
          "PASSING",
          "FAILING",
          "NEEDS_CHANGES"
        ],
        "type": "string"
      },
      "CheckType": {
        "description": "The type of check.",
        "enum": [
          "INTEGRATION",
          "MONITOR",
          "POLICY",
          "ATTACHMENT",
          "SCOPE_ITEM"
        ],
        "type": "string"
      },
      "ChecklistItemStatus": {
        "enum": [
          "PENDING",
          "COMPLETED",
          "NOT_APPLICABLE"
        ],
        "type": "string"
      },
      "ChecklistType": {
        "enum": [
          "ONBOARDING",
          "OFFBOARDING"
        ],
        "type": "string"
      },
      "ClassicDashboard": {
        "properties": {
          "closedOrRejectedFindingsCount": {
            "description": "The number of closed findings associated with this tenant dashboard.",
            "type": "integer"
          },
          "findingsCount": {
            "description": "The number of findings associated with this tenant dashboard.",
            "type": "integer"
          },
          "reports": {
            "description": "The reports associated with this tenant dashboard.",
            "items": {
              "$ref": "#/components/schemas/DashboardReport"
            },
            "type": "array"
          },
          "type": {
            "type": "string"
          }
        },
        "required": [
          "type",
          "reports",
          "findingsCount",
          "closedOrRejectedFindingsCount"
        ]
      },
      "ClassificationImpact": {
        "enum": [
          "HIGH",
          "MEDIUM",
          "LOW",
          "NOTAVAILABLE"
        ],
        "type": "string"
      },
      "ClassificationProbability": {
        "enum": [
          "HIGH",
          "MEDIUM",
          "LOW",
          "NOTAVAILABLE"
        ],
        "type": "string"
      },
      "ClassificationRisk": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "NOTE"
        ],
        "type": "string"
      },
      "CodeReviewEvidenceProvider": {
        "description": "Source platform for a code-review evidence collection task.",
        "enum": [
          "github",
          "gitlab"
        ],
        "type": "string"
      },
      "CodeReviewEvidenceTask": {
        "description": "One queued collection task — one entry per provider that ran.",
        "properties": {
          "provider": {
            "$ref": "#/components/schemas/CodeReviewEvidenceProvider"
          }
        },
        "required": [
          "provider"
        ],
        "type": "object"
      },
      "CodeSecurityFinding": {
        "properties": {
          "codeSnippet": {
            "description": "The code snippet of the finding.",
            "nullable": true,
            "type": "string"
          },
          "createdAt": {
            "description": "The date and time the finding was created.",
            "format": "date-time",
            "type": "string"
          },
          "currentLocation": {
            "$ref": "#/components/schemas/CodeSecurityFindingLocation"
          },
          "id": {
            "description": "The unique identifier of the finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "issue": {
            "$ref": "#/components/schemas/CodeSecurityIssue"
          },
          "owner": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "resolution": {
            "$ref": "#/components/schemas/CodeSecurityFindingResolution"
          },
          "resolutionDescription": {
            "description": "User-specified description of how the finding was resolved.",
            "nullable": true,
            "type": "string"
          },
          "resolvedAt": {
            "description": "Time when the finding was first marked as resolved.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "status": {
            "$ref": "#/components/schemas/CodeSecurityFindingStatus"
          },
          "suppressed": {
            "description": "Whether the finding was suppressed.",
            "type": "boolean"
          },
          "suppressedReason": {
            "description": "User-specified description of why the finding was suppressed.",
            "nullable": true,
            "type": "string"
          },
          "title": {
            "description": "The title of the finding.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the finding was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "issue",
          "title",
          "currentLocation",
          "status",
          "suppressed"
        ]
      },
      "CodeSecurityFindingLocation": {
        "properties": {
          "branchName": {
            "description": "The name of the branch where the finding was found.",
            "type": "string"
          },
          "commitHash": {
            "description": "The hash of the commit where the finding was found.",
            "type": "string"
          },
          "createdAt": {
            "description": "The date and time the location was created.",
            "format": "date-time",
            "type": "string"
          },
          "endLine": {
            "description": "The end line of the finding.",
            "type": "integer"
          },
          "filePath": {
            "description": "The path of the file where the finding was found.",
            "type": "string"
          },
          "gitRepositoryId": {
            "description": "ID of the Git repository where the finding was found.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "description": "The unique identifier of the location.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "startLine": {
            "description": "The start line of the finding.",
            "type": "integer"
          },
          "updatedAt": {
            "description": "The date and time the location was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "gitRepositoryId",
          "branchName",
          "commitHash",
          "filePath"
        ]
      },
      "CodeSecurityFindingResolution": {
        "enum": [
          "FIXED",
          "FALSE_POSITIVE",
          "ACCEPTED_RISK",
          "MITIGATED",
          "REMOVED"
        ],
        "type": "string"
      },
      "CodeSecurityFindingStatus": {
        "enum": [
          "OPEN",
          "IN_PROGRESS",
          "RESOLVED",
          "SUPPRESSED"
        ],
        "type": "string"
      },
      "CodeSecurityIssue": {
        "properties": {
          "confidence": {
            "$ref": "#/components/schemas/CodeSecurityIssueConfidence"
          },
          "createdAt": {
            "description": "The date and time the issue was created.",
            "format": "date-time",
            "type": "string"
          },
          "findings": {
            "items": {
              "$ref": "#/components/schemas/CodeSecurityFinding"
            },
            "type": "array"
          },
          "helpUrl": {
            "description": "Link to documentation page for the issue.",
            "nullable": true,
            "type": "string"
          },
          "id": {
            "description": "The unique identifier of the issue.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "ignoreReason": {
            "description": "The reason the issue is ignored.",
            "nullable": true,
            "type": "string"
          },
          "ignored": {
            "description": "Whether the issue is ignored.",
            "type": "boolean"
          },
          "ignoredBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "ignoredById": {
            "nullable": true,
            "type": "string"
          },
          "severity": {
            "$ref": "#/components/schemas/CodeSecurityIssueSeverity"
          },
          "title": {
            "description": "The title of the issue.",
            "type": "string"
          },
          "toolAssignedId": {
            "type": "string"
          },
          "toolName": {
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the issue was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "toolName",
          "toolAssignedId",
          "title",
          "severity",
          "confidence",
          "findings",
          "ignored"
        ]
      },
      "CodeSecurityIssueConfidence": {
        "enum": [
          "HIGH",
          "MEDIUM",
          "LOW"
        ],
        "type": "string"
      },
      "CodeSecurityIssueSeverity": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFO"
        ],
        "type": "string"
      },
      "CodeSecurityScanInfo": {
        "properties": {
          "createdAt": {
            "description": "The date and time the scan info was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The unique identifier of the scan info.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isFirstRun": {
            "description": "Whether the scan has been run before.",
            "nullable": true,
            "type": "boolean"
          },
          "isScanning": {
            "description": "Whether the scan is currently running.",
            "type": "boolean"
          },
          "lastRun": {
            "description": "The date and time the scan was last run.",
            "format": "date-time",
            "type": "string"
          },
          "lastScanFailedErrorMessage": {
            "description": "Error message from the last failed scan (null when scan succeeds or hasn't failed).",
            "nullable": true,
            "type": "string"
          },
          "nextRun": {
            "description": "The date and time the scan is scheduled to run next.",
            "format": "date-time",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the scan info was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "isScanning"
        ]
      },
      "CodeSecurityScanInfoList": {
        "items": {
          "$ref": "#/components/schemas/CodeSecurityScanInfo"
        },
        "type": "array"
      },
      "CodeSecuritySettings": {
        "properties": {
          "codeSecuritySensitivity": {
            "$ref": "#/components/schemas/CodeSecurityIssueConfidence"
          }
        }
      },
      "ComplianceFramework": {
        "properties": {
          "createdAt": {
            "description": "The time the framework was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the framework.",
            "type": "string"
          },
          "estimatedReadiness": {
            "description": "The percentage of controls that have already been completed in another framework that overlaps with the new framework.",
            "type": "number"
          },
          "estimatedTime": {
            "description": "The estimated time to complete the framework.",
            "type": "string"
          },
          "extends": {
            "$ref": "#/components/schemas/ComplianceFramework"
          },
          "extendsId": {
            "description": "The id of the framework that this framework extends.",
            "type": "string"
          },
          "icon": {
            "description": "The icon for the framework.",
            "type": "string"
          },
          "id": {
            "description": "The id of the framework.",
            "type": "string"
          },
          "internalName": {
            "description": "Internal name visible only to admins - notes to help select the correct framework variant.",
            "type": "string"
          },
          "isActive": {
            "description": "Whether the framework is available for users to use.",
            "type": "boolean"
          },
          "isVisibleToTenant": {
            "description": "Whether the framework is visible to tenants.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the framework.",
            "type": "string"
          },
          "requirements": {
            "description": "The requirements for the framework.",
            "items": {
              "$ref": "#/components/schemas/ComplianceRequirement"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time the framework was last updated",
            "format": "date-time",
            "type": "string"
          },
          "version": {
            "description": "The version of the framework.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "version",
          "description",
          "icon",
          "createdAt",
          "updatedAt",
          "estimatedReadiness"
        ],
        "type": "object"
      },
      "ComplianceRequirement": {
        "properties": {
          "createdAt": {
            "description": "The time the requirement was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the requirement.",
            "type": "string"
          },
          "framework": {
            "$ref": "#/components/schemas/ComplianceFramework"
          },
          "frameworkId": {
            "description": "The id of the framework that this requirement belongs to.",
            "type": "string"
          },
          "id": {
            "description": "The id of the requirement.",
            "type": "string"
          },
          "number": {
            "description": "The number of the requirement.",
            "type": "integer"
          },
          "referenceId": {
            "description": "A string that uniquely identifies the requirement in the framework document. The format of this can vary from framework to framework and may not always look exactly like a number.",
            "type": "string"
          },
          "title": {
            "description": "The title of the requirement.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the requirement was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "referenceId",
          "number",
          "title",
          "frameworkId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "Connection": {
        "properties": {
          "autofixesEnabled": {
            "description": "Whether Oneleet autofixes are enabled for this connection.",
            "type": "boolean"
          },
          "configuration": {
            "description": "The additional configuration of the connection.",
            "discriminator": {
              "mapping": {
                "aws_v1": "#/components/schemas/CreateAWSConnectionData",
                "aws_v2": "#/components/schemas/CreateAWSv2ConnectionData",
                "custom_v1": "#/components/schemas/CreateCustomConnectionData",
                "gitlab_v1": "#/components/schemas/CreateGitLabConnectionData",
                "slack_v1": "#/components/schemas/CreateSlackConnectionData"
              },
              "propertyName": "integrationTypeId"
            },
            "nullable": true,
            "oneOf": [
              {
                "$ref": "#/components/schemas/CreateAWSConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateAWSv2ConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateCustomConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateSlackConnectionData"
              },
              {
                "$ref": "#/components/schemas/CreateGitLabConnectionData"
              }
            ],
            "type": "object"
          },
          "createdAt": {
            "description": "The time that this connection was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the connection.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integration": {
            "$ref": "#/components/schemas/Integration"
          },
          "integrationId": {
            "description": "The ID of the integration.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "label": {
            "description": "User-created label for the connection; if not present, `readableId` is shown as a fallback.",
            "type": "string"
          },
          "readableId": {
            "description": "An alternative ID for the connection, which must be unique per tenant.\n\nThis is used as both a unique identifier in some of our integrations logic,\n*and* as a user-facing label for the connection.\n\nSome integrations populate this with a nice value, such as \"project name\" for GCP.\nDue to technical limitations, Nango-based integrations currently don't.\n",
            "type": "string"
          },
          "sshPublicKey": {
            "description": "Public half of the SSH keypair used to clone repositories over SSH (GitLab connections with cloneProtocol \"ssh\"). The customer installs this key on a GitLab service account.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ConnectionStatus"
          },
          "statusReason": {
            "description": "The reason for the connection status.",
            "type": "string"
          },
          "tenantVendorId": {
            "description": "For custom integration connections, the ID of the tenant vendor this connection is for.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this connection was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "integrationId",
          "readableId",
          "status",
          "autofixesEnabled"
        ],
        "type": "object"
      },
      "ConnectionStatus": {
        "description": "Status of a connection:\n- UNQUERIED: Not yet queried\n- SUCCEEDED: Last query succeeded\n- FAILED: Last query failed (requires user action)\n- RETRYING: Last query encountered a transient error and will retry automatically\n",
        "enum": [
          "UNQUERIED",
          "SUCCEEDED",
          "FAILED",
          "RETRYING"
        ],
        "type": "string"
      },
      "Control": {
        "properties": {
          "assignedMember": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "assignedReviewer": {
            "$ref": "#/components/schemas/UserPublic"
          },
          "checks": {
            "description": "The checks associated with this control.",
            "items": {
              "$ref": "#/components/schemas/Check"
            },
            "type": "array"
          },
          "content": {
            "$ref": "#/components/schemas/ControlContent"
          },
          "controlType": {
            "$ref": "#/components/schemas/ControlType"
          },
          "controlTypeId": {
            "description": "The id of the control type.",
            "type": "string"
          },
          "createdAt": {
            "description": "The time the control was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The time the control was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "evidence": {
            "description": "This control's attached evidence",
            "items": {
              "$ref": "#/components/schemas/Evidence"
            },
            "type": "array"
          },
          "evidenceRequests": {
            "description": "The manually requested evidence for the control.",
            "items": {
              "$ref": "#/components/schemas/EvidenceRequest"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the control.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isDisabled": {
            "description": "Whether the control is disabled.",
            "type": "boolean"
          },
          "linkedEvidence": {
            "description": "The evidence linked to this control.",
            "items": {
              "$ref": "#/components/schemas/EvidenceToControl"
            },
            "type": "array"
          },
          "retiredScopeItems": {
            "description": "Scope items that left the control's resolved scope; kept visible so a shrunken scope remains reviewable.\n",
            "items": {
              "$ref": "#/components/schemas/RetiredScopeItem"
            },
            "type": "array"
          },
          "reviewDetails": {
            "description": "The content of the most recent review.",
            "type": "string"
          },
          "reviewRequestedAt": {
            "description": "The time at which the review was requested.",
            "format": "date-time",
            "type": "string"
          },
          "reviewStatus": {
            "$ref": "#/components/schemas/ControlReviewStatus"
          },
          "reviewedAt": {
            "description": "The time the control review was submitted.",
            "format": "date-time",
            "type": "string"
          },
          "reviewerName": {
            "description": "The name of the user who reviewed the control.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenant": {
            "$ref": "#/components/schemas/TenantBasicInfo"
          },
          "tenantComplianceRequirements": {
            "description": "The tenant compliance requirements associated with this control.",
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirement"
            },
            "type": "array"
          },
          "tenantId": {
            "description": "The id of the tenant.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the control was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "isDisabled",
          "createdAt",
          "updatedAt",
          "tenantId",
          "controlTypeId",
          "controlType",
          "content"
        ],
        "type": "object"
      },
      "ControlCategory": {
        "enum": [
          "ACCESS_CONTROL_AND_AUTHORIZATION",
          "EMAIL_SECURITY",
          "ENDPOINT_SECURITY",
          "INFRASTRUCTURE_SECURITY",
          "DATA_MANAGEMENT_AND_PROTECTION",
          "VULNERABILITY_MANAGEMENT",
          "MONITORING_AND_INCIDENT_RESPONSE",
          "DISASTER_RECOVERY",
          "RISK_MANAGEMENT",
          "ORGANIZATIONAL_SECURITY"
        ],
        "type": "string"
      },
      "ControlCheckSummary": {
        "properties": {
          "allActiveChecksArePassing": {
            "type": "boolean"
          },
          "checksPassingPercentage": {
            "format": "float",
            "type": "number"
          },
          "enabledChecksCount": {
            "type": "integer"
          },
          "hasChecks": {
            "type": "boolean"
          },
          "inactiveChecksCount": {
            "type": "integer"
          },
          "passingChecksCount": {
            "type": "integer"
          },
          "totalChecksCount": {
            "type": "integer"
          }
        },
        "required": [
          "hasChecks",
          "allActiveChecksArePassing",
          "inactiveChecksCount",
          "enabledChecksCount",
          "passingChecksCount",
          "totalChecksCount",
          "checksPassingPercentage"
        ],
        "type": "object"
      },
      "ControlContent": {
        "properties": {
          "aiSuggestedEvidenceCriteria": {
            "description": "AI-generated evidence criteria (used as fallback when no custom or template criteria exist)",
            "items": {
              "$ref": "#/components/schemas/EvidenceCriterion"
            },
            "type": "array"
          },
          "description": {
            "description": "The control's description.",
            "maxLength": 6000,
            "type": "string"
          },
          "evidenceCriteria": {
            "description": "The effective evidence criteria (custom if set, otherwise template, otherwise AI-suggested)",
            "items": {
              "$ref": "#/components/schemas/EvidenceCriterion"
            },
            "type": "array"
          },
          "instructions": {
            "description": "The control's instructions.",
            "maxLength": 6000,
            "type": "string"
          },
          "title": {
            "description": "The control's title.",
            "maxLength": 255,
            "type": "string"
          }
        },
        "required": [
          "title",
          "description"
        ],
        "type": "object"
      },
      "ControlList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Control"
            },
            "type": "array"
          }
        }
      },
      "ControlReviewStatus": {
        "description": "The review status of the control.",
        "enum": [
          "UNREVIEWED",
          "IN_REVIEW",
          "APPROVED",
          "REJECTED"
        ],
        "type": "string"
      },
      "ControlStatus": {
        "description": "The status of the control.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "IN_REVIEW",
          "NEEDS_CHANGES",
          "FAILING",
          "PASSING"
        ],
        "type": "string"
      },
      "ControlSummary": {
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "title"
        ],
        "type": "object"
      },
      "ControlType": {
        "properties": {
          "associatedComplianceRequirements": {
            "description": "The default compliance requirements this control type satisfies",
            "items": {
              "$ref": "#/components/schemas/ComplianceRequirement"
            },
            "type": "array"
          },
          "category": {
            "$ref": "#/components/schemas/ControlCategory"
          },
          "createdAt": {
            "description": "The time the control type was created.",
            "format": "date-time",
            "type": "string"
          },
          "deletedAt": {
            "description": "The time the control type was deleted.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The control type's description.",
            "type": "string"
          },
          "enabledOnFrameworkIds": {
            "description": "IDs of frameworks this control type is enabled on by default. When a framework is added to a tenant, only control types enabled for that framework are auto-created.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "evidenceCriteria": {
            "description": "Template evidence criteria for AI evaluation of evidence against this control",
            "items": {
              "$ref": "#/components/schemas/EvidenceCriterion"
            },
            "type": "array"
          },
          "frameworkNotes": {
            "description": "The control type's framework implementation notes",
            "items": {
              "$ref": "#/components/schemas/FrameworkNotes"
            },
            "type": "array"
          },
          "id": {
            "description": "The id of the control type.",
            "type": "string"
          },
          "inAppDocumentTemplates": {
            "items": {
              "$ref": "#/components/schemas/InAppDocumentTemplateMeta"
            },
            "type": "array"
          },
          "instructions": {
            "description": "The control type's instructions.",
            "type": "string"
          },
          "integrationCategories": {
            "description": "The integration categories associated with this control type.",
            "items": {
              "$ref": "#/components/schemas/IntegrationCategory"
            },
            "type": "array"
          },
          "monitorTypes": {
            "description": "The monitor types associated with this control type.",
            "items": {
              "$ref": "#/components/schemas/MonitorType"
            },
            "type": "array"
          },
          "policyTypes": {
            "description": "The policy types associated with this control type.",
            "items": {
              "$ref": "#/components/schemas/PolicyType"
            },
            "type": "array"
          },
          "title": {
            "description": "The control type's title.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the control type was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "description"
        ],
        "type": "object"
      },
      "CreateAWSConnectionData": {
        "properties": {
          "assumeRoleArn": {
            "description": "The ARN of the role that shall be assumed.",
            "type": "string"
          },
          "externalId": {
            "description": "The external ID for the assume role. Oneleet derives this from the integration, so it can be omitted; when supplied it must match the value returned by `GET /api/v1/integrations/{integration}/aws-external-id`.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to use.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId",
          "assumeRoleArn"
        ]
      },
      "CreateAWSv2ConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "primaryRegion": {
            "description": "The primary AWS region to use.",
            "type": "string"
          },
          "randomKey": {
            "description": "Random identifier used to find the S3 object created for this template.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to use.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId",
          "randomKey",
          "primaryRegion",
          "selectedRegions"
        ]
      },
      "CreateAccessReviewRequest": {
        "properties": {
          "dueBy": {
            "description": "The due date of the access review.",
            "format": "date-time",
            "type": "string"
          },
          "ownerId": {
            "description": "The ID of the tenant member who owns the access review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantVendors": {
            "description": "The tenant's vendors to review.",
            "items": {
              "$ref": "#/components/schemas/TenantVendorWithReviewer"
            },
            "type": "array"
          },
          "title": {
            "description": "The title of the access review.",
            "type": "string"
          }
        },
        "required": [
          "title",
          "ownerId",
          "dueBy",
          "tenantVendors"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateActionGroupRequest": {
        "properties": {
          "groupId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          }
        },
        "required": [
          "groupId",
          "role"
        ],
        "type": "object"
      },
      "CreateActionMemberRequest": {
        "properties": {
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          },
          "tenantMemberId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantMemberId",
          "role"
        ],
        "type": "object"
      },
      "CreateActionRequest": {
        "properties": {
          "actionStatus": {
            "$ref": "#/components/schemas/ActionStatus"
          },
          "actionType": {
            "description": "Internal action type for filtering and searching.",
            "minLength": 1,
            "type": "string"
          },
          "description": {
            "description": "Markdown description of the action.",
            "type": "string"
          },
          "dueDate": {
            "description": "Deadline for the action.",
            "format": "date-time",
            "type": "string"
          },
          "groups": {
            "description": "Groups to assign to the action.",
            "items": {
              "$ref": "#/components/schemas/CreateActionGroupRequest"
            },
            "type": "array"
          },
          "members": {
            "description": "Members to assign to the action.",
            "items": {
              "$ref": "#/components/schemas/CreateActionMemberRequest"
            },
            "type": "array"
          },
          "resourceUrns": {
            "description": "Resource URNs to link to the action.",
            "items": {
              "$ref": "#/components/schemas/CreateActionResourceUrnRequest"
            },
            "type": "array"
          },
          "summary": {
            "description": "One-line summary of the action.",
            "minLength": 1,
            "type": "string"
          }
        },
        "required": [
          "summary",
          "actionType"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateActionResourceUrnRequest": {
        "properties": {
          "label": {
            "description": "Human-readable label for the linked resource.",
            "type": "string"
          },
          "rel": {
            "$ref": "#/components/schemas/ActionResourceUrnRel"
          },
          "resourceId": {
            "description": "The resource ID portion of the URN.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resourceType": {
            "description": "The resource type portion of the URN.",
            "type": "string"
          }
        },
        "required": [
          "resourceType",
          "resourceId",
          "rel"
        ],
        "type": "object"
      },
      "CreateAzureConnectionData": {
        "properties": {
          "clientId": {
            "description": "The Azure client ID.",
            "type": "string"
          },
          "clientSecret": {
            "description": "The Azure client secret.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tenantId": {
            "description": "The Azure tenant ID.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tenantId",
          "clientId",
          "clientSecret"
        ]
      },
      "CreateBrexConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tokenName": {
            "description": "Descriptive name given to the API token.",
            "type": "string"
          },
          "tokenSecret": {
            "description": "API token generated by Brex.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tokenName",
          "tokenSecret"
        ]
      },
      "CreateCloudflareConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "selectedZones": {
            "description": "The Cloudflare zone(s) to monitor (leave empty to monitor all zones).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "tokenName": {
            "description": "Descriptive name given to the API token.",
            "type": "string"
          },
          "tokenSecret": {
            "description": "API token generated by Cloudflare.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tokenName",
          "tokenSecret"
        ]
      },
      "CreateConnectionRequest": {
        "discriminator": {
          "mapping": {
            "aikido_v1": "#/components/schemas/CreatePlainConnectionData",
            "aircall_v1": "#/components/schemas/CreatePlainConnectionData",
            "amplitude_v1": "#/components/schemas/CreatePlainConnectionData",
            "anthropic_v1": "#/components/schemas/CreatePlainConnectionData",
            "apollo_v1": "#/components/schemas/CreatePlainConnectionData",
            "atlassian_v1": "#/components/schemas/CreatePlainConnectionData",
            "aws_v1": "#/components/schemas/CreateAWSConnectionData",
            "aws_v2": "#/components/schemas/CreateAWSv2ConnectionData",
            "azure_v1": "#/components/schemas/CreateAzureConnectionData",
            "bitwarden_v1": "#/components/schemas/CreatePlainConnectionData",
            "brex_v1": "#/components/schemas/CreateBrexConnectionData",
            "callrail_v1": "#/components/schemas/CreatePlainConnectionData",
            "chorus_v1": "#/components/schemas/CreatePlainConnectionData",
            "circle_v1": "#/components/schemas/CreatePlainConnectionData",
            "clickhouse_v1": "#/components/schemas/CreatePlainConnectionData",
            "cloudflare_v1": "#/components/schemas/CreateCloudflareConnectionData",
            "coda_v1": "#/components/schemas/CreatePlainConnectionData",
            "custom_v1": "#/components/schemas/CreateCustomConnectionData",
            "dashlane_v1": "#/components/schemas/CreatePlainConnectionData",
            "databricksAccount_v1": "#/components/schemas/CreatePlainConnectionData",
            "databricks_v1": "#/components/schemas/CreatePlainConnectionData",
            "datadog_v1": "#/components/schemas/CreatePlainConnectionData",
            "digitalOcean_v1": "#/components/schemas/CreateDigitalOceanConnectionData",
            "discourse_v1": "#/components/schemas/CreatePlainConnectionData",
            "dixa_v1": "#/components/schemas/CreatePlainConnectionData",
            "doppler_v1": "#/components/schemas/CreateDopplerConnectionData",
            "expensify_v1": "#/components/schemas/CreatePlainConnectionData",
            "fleet_v1": "#/components/schemas/CreatePlainConnectionData",
            "flyio_v1": "#/components/schemas/CreateFlyioConnectionData",
            "freshdesk_v1": "#/components/schemas/CreatePlainConnectionData",
            "freshservice_v1": "#/components/schemas/CreatePlainConnectionData",
            "freshteam_v1": "#/components/schemas/CreatePlainConnectionData",
            "gcp_v1": "#/components/schemas/CreateGCPConnectionData",
            "gitlab_v1": "#/components/schemas/CreateGitLabConnectionData",
            "grafana_v1": "#/components/schemas/CreatePlainConnectionData",
            "greenhouseHarvest_v1": "#/components/schemas/CreatePlainConnectionData",
            "greenhouse_v1": "#/components/schemas/CreatePlainConnectionData",
            "hcpTerraform_v1": "#/components/schemas/CreatePlainConnectionData",
            "hetzner_v1": "#/components/schemas/CreatePlainConnectionData",
            "hibob_v1": "#/components/schemas/CreatePlainConnectionData",
            "insightly_v1": "#/components/schemas/CreatePlainConnectionData",
            "iru_v1": "#/components/schemas/CreatePlainConnectionData",
            "jetbrains_v1": "#/components/schemas/CreatePlainConnectionData",
            "jumpcloud_v1": "#/components/schemas/CreateJumpcloudConnectionData",
            "kustomer_v1": "#/components/schemas/CreatePlainConnectionData",
            "lattice_v1": "#/components/schemas/CreatePlainConnectionData",
            "launchdarkly_v1": "#/components/schemas/CreatePlainConnectionData",
            "lessonly_v1": "#/components/schemas/CreatePlainConnectionData",
            "lever_v1": "#/components/schemas/CreatePlainConnectionData",
            "mailgun_v1": "#/components/schemas/CreatePlainConnectionData",
            "manatal_v1": "#/components/schemas/CreatePlainConnectionData",
            "metabase_v1": "#/components/schemas/CreatePlainConnectionData",
            "mezmo_v1": "#/components/schemas/CreateMezmoConnectionData",
            "microsoftEntra_v1": "#/components/schemas/CreateMicrosoftEntraConnectionData",
            "missive_v1": "#/components/schemas/CreatePlainConnectionData",
            "mixpanel_v1": "#/components/schemas/CreatePlainConnectionData",
            "mongodbAtlas_v1": "#/components/schemas/CreatePlainConnectionData",
            "okta_v1": "#/components/schemas/CreatePlainConnectionData",
            "onepassword_v1": "#/components/schemas/CreatePlainConnectionData",
            "openai_v1": "#/components/schemas/CreatePlainConnectionData",
            "oracle_v1": "#/components/schemas/CreatePlainConnectionData",
            "payfit_v1": "#/components/schemas/CreatePlainConnectionData",
            "paylocity_v1": "#/components/schemas/CreatePlainConnectionData",
            "personio_v1": "#/components/schemas/CreatePlainConnectionData",
            "pingboard_v1": "#/components/schemas/CreatePlainConnectionData",
            "posthog_v1": "#/components/schemas/CreatePlainConnectionData",
            "pylon_v1": "#/components/schemas/CreatePlainConnectionData",
            "render_v1": "#/components/schemas/CreatePlainConnectionData",
            "rippling_v1": "#/components/schemas/CreatePlainConnectionData",
            "sendgrid_v1": "#/components/schemas/CreatePlainConnectionData",
            "sentinelOne_v1": "#/components/schemas/CreatePlainConnectionData",
            "shortcut_v1": "#/components/schemas/CreatePlainConnectionData",
            "smartrecruiters_v1": "#/components/schemas/CreatePlainConnectionData",
            "supabase_v1": "#/components/schemas/CreateSupabaseConnectionData",
            "tableau_v1": "#/components/schemas/CreatePlainConnectionData",
            "tailscale_v1": "#/components/schemas/CreateTailscaleConnectionData",
            "teamtailor_v1": "#/components/schemas/CreatePlainConnectionData",
            "temporalCloud_v1": "#/components/schemas/CreatePlainConnectionData",
            "vercel_v1": "#/components/schemas/CreateVercelConnectionData",
            "workday_v1": "#/components/schemas/CreatePlainConnectionData"
          },
          "propertyName": "integrationTypeId"
        },
        "oneOf": [
          {
            "$ref": "#/components/schemas/CreateGCPConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateAWSConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateAWSv2ConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateJumpcloudConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateCloudflareConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateGitLabConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateVercelConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateMezmoConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateAzureConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateTailscaleConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateDopplerConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateBrexConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateSupabaseConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateFlyioConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateDigitalOceanConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateCustomConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreateMicrosoftEntraConnectionData"
          },
          {
            "$ref": "#/components/schemas/CreatePlainConnectionData"
          }
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateCustomConnectionData": {
        "properties": {
          "authCredentials": {
            "description": "Auth credentials for the custom integration's API. They're stored encrypted and never returned.",
            "properties": {
              "apiKey": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "customConfig": {
            "description": "Configuration for the custom integration connection.",
            "type": "object"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "customConfig"
        ]
      },
      "CreateDigitalOceanConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tokenName": {
            "description": "Descriptive name given to the API token.",
            "type": "string"
          },
          "tokenSecret": {
            "description": "API token generated by DigitalOcean.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tokenName",
          "tokenSecret"
        ]
      },
      "CreateDopplerConnectionData": {
        "properties": {
          "auditToken": {
            "description": "The Doppler audit token for the connection.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "auditToken"
        ]
      },
      "CreateEvidenceFromUploadRequest": {
        "description": "Create an evidence row backed by a file that has already been uploaded to\nS3 via a presigned URL from `evidence:create-upload-url`.\n",
        "properties": {
          "controlId": {
            "description": "Optional control to link the evidence to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "evidenceRequestId": {
            "description": "Optional evidence request to link to. Requires controlId.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "filename": {
            "description": "Original filename to display for the evidence.",
            "maxLength": 255,
            "type": "string"
          },
          "name": {
            "description": "Optional human-readable name for the evidence.",
            "maxLength": 255,
            "type": "string"
          },
          "note": {
            "description": "Optional note for the evidence.",
            "maxLength": 10000,
            "type": "string"
          },
          "s3Key": {
            "description": "The S3 key returned by `evidence:create-upload-url`.",
            "type": "string"
          },
          "scopeItemId": {
            "description": "Optional control scope item to link to. Requires controlId.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "type": {
            "description": "Must be IMAGE or FILE.",
            "enum": [
              "IMAGE",
              "FILE"
            ],
            "type": "string"
          }
        },
        "required": [
          "s3Key",
          "type",
          "filename"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateEvidenceRequest": {
        "properties": {
          "controlId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "evidenceRequestId": {
            "description": "The id of the evidence request to link to, if applicable.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "inAppDocumentId": {
            "description": "The ID of the in-app document.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "link": {
            "description": "The evidence's link.",
            "maxLength": 2000,
            "type": "string"
          },
          "name": {
            "description": "The name of the evidence.",
            "maxLength": 255,
            "type": "string"
          },
          "note": {
            "description": "The evidence's note.",
            "maxLength": 10000,
            "type": "string"
          },
          "scopeItemId": {
            "description": "The id of the control scope item to link to, if applicable. Requires controlId.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/EvidenceType"
          },
          "upload": {
            "description": "Supported types are image/jpeg, image/png, image/webp, image/gif, text/csv, text/markdown, text/plain, application/yaml, application/x-yaml, text/yaml, text/x-yaml, application/pdf, application/msword,  application/vnd.ms-excel, application/vnd.ms-powerpoint, application/vnd.openxmlformats-officedocument.wordprocessingml.document, application/vnd.openxmlformats-officedocument.spreadsheetml.sheet, application/vnd.openxmlformats-officedocument.presentationml.presentation",
            "format": "binary",
            "type": "string"
          }
        },
        "required": [
          "type"
        ],
        "type": "object"
      },
      "CreateFieldworkDeliveryBody": {
        "description": "One message a Fieldwork workflow's delivery step asks the platform to send. Exactly one destination object is set.",
        "properties": {
          "deliveryId": {
            "description": "Fieldwork's id for the delivery. A repeat with an id the platform has already sent returns the recorded result without sending again.",
            "format": "uuid",
            "type": "string"
          },
          "email": {
            "$ref": "#/components/schemas/FieldworkEmailDeliveryBody"
          },
          "slack": {
            "$ref": "#/components/schemas/FieldworkSlackDeliveryBody"
          }
        },
        "required": [
          "deliveryId"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateFlyioConnectionData": {
        "properties": {
          "accessToken": {
            "description": "Access token generated by Fly.io.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "organizationSlug": {
            "description": "Organization identifier from Fly.io.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "accessToken",
          "organizationSlug"
        ]
      },
      "CreateGCPConnectionData": {
        "properties": {
          "gcpProjectId": {
            "description": "The ID of the GCP project.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tenantServiceAccountEmail": {
            "description": "The email of the Service Account created by tenant",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "gcpProjectId"
        ],
        "type": "object"
      },
      "CreateGitLabConnectionData": {
        "properties": {
          "accessTokenName": {
            "description": "Group, project, or personal access token name from the GitLab's interface.",
            "type": "string"
          },
          "accessTokenSecret": {
            "description": "Group, project, or personal access token secret from the GitLab's interface.",
            "type": "string"
          },
          "baseUrl": {
            "description": "Origin of a self-hosted GitLab instance (e.g. \"https://gitlab.acme.com\"). Leave empty for GitLab.com.",
            "format": "uri",
            "pattern": "^https://",
            "type": "string"
          },
          "cloneProtocol": {
            "description": "Protocol used to clone repositories for code scanning. Use \"ssh\" for groups that disable git access over HTTP(S). Defaults to \"https\".",
            "enum": [
              "https",
              "ssh"
            ],
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "accessTokenName",
          "accessTokenSecret"
        ]
      },
      "CreateIntegrationRequest": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateJumpcloudConnectionData": {
        "properties": {
          "apiKey": {
            "description": "The API key from the Jumpcloud console.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "jumpcloudAccountName": {
            "description": "The account name for Jumpcloud.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "jumpcloudAccountName",
          "apiKey"
        ]
      },
      "CreateMezmoConnectionData": {
        "properties": {
          "accessToken": {
            "description": "Access token generated by Mezmo.",
            "type": "string"
          },
          "connectionName": {
            "description": "Descriptive name given to the connection.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "connectionName",
          "accessToken"
        ]
      },
      "CreateMicrosoftEntraConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tenantId": {
            "description": "Microsoft Entra directory tenant ID.",
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tenantId"
        ]
      },
      "CreatePlainConnectionData": {
        "description": "Generic connect payload for integrations that authenticate via plain\ncredentials (e.g. API keys).\n",
        "properties": {
          "connectionConfig": {
            "additionalProperties": {
              "type": "string"
            },
            "description": "Optional per-provider connection config fields (e.g. `subdomain`, `organizationId`).",
            "type": "object"
          },
          "credentials": {
            "additionalProperties": {
              "type": "string"
            },
            "description": "Per-provider credential fields (e.g. `apiKey`, `username`, `password`).",
            "type": "object"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "credentials"
        ],
        "type": "object"
      },
      "CreateRiskAssessmentRequest": {
        "description": "Empty: creating a risk assessment always opens an untitled active register, defaulting its title to the fixed internal placeholder \"Your active risks\" -- there's only ever one open register, so a real, user-facing name can only be set when taking a snapshot (see UpdateRiskAssessmentRequest.title).",
        "x-mcp-fields": true
      },
      "CreateRiskRequest": {
        "properties": {
          "aiAssessment": {
            "$ref": "#/components/schemas/AiAssessment"
          },
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "controls": {
            "description": "Controls to link to the risk.",
            "items": {
              "$ref": "#/components/schemas/LinkRiskControl"
            },
            "type": "array"
          },
          "description": {
            "description": "The description of the risk.",
            "type": "string"
          },
          "hasResidualRisk": {
            "description": "Whether the risk has a residual risk.",
            "type": "boolean"
          },
          "impact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "likelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "note": {
            "description": "Additional notes or comments about the risk.",
            "type": "string"
          },
          "ownerId": {
            "description": "The ID of the owner associated with this risk.",
            "type": "string"
          },
          "residualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "residualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "response": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "responseDetails": {
            "description": "The details of the risk response.",
            "type": "string"
          },
          "title": {
            "description": "The title of the risk.",
            "type": "string"
          }
        },
        "required": [
          "title",
          "category"
        ],
        "x-mcp-fields": true
      },
      "CreateSlackConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "scopes": {
            "description": "The Slack OAuth bot scopes granted at the most recent authorization.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "tier": {
            "description": "The Slack workspace plan tier selected at connect time.",
            "enum": [
              "standard",
              "enterprise"
            ],
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId"
        ]
      },
      "CreateSupabaseConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "tokenSecret": {
            "description": "API token generated by Supabase.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "tokenSecret"
        ]
      },
      "CreateTailscaleConnectionData": {
        "properties": {
          "clientId": {
            "description": "The OAuth client ID for the Tailscale connection.",
            "type": "string"
          },
          "clientSecret": {
            "description": "The OAuth client secret for the Tailscale connection.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "clientId",
          "clientSecret"
        ]
      },
      "CreateVendorDataInventoryItem": {
        "properties": {
          "description": {
            "description": "What data the vendor holds, for example \"Customer emails\". At most 3000 characters.",
            "maxLength": 3000,
            "minLength": 1,
            "type": "string"
          },
          "sensitivityLevel": {
            "allOf": [
              {
                "$ref": "#/components/schemas/DataSensitivityLevel"
              }
            ],
            "description": "How sensitive the data is."
          },
          "tagIds": {
            "description": "Ids of the data inventory tags to attach; get them from the data inventory tag list. Both system tags and the tenant's own tags are accepted; unknown ids are rejected. The system PII and PHI tags mark the vendor as processing personal data.",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "description",
          "sensitivityLevel",
          "tagIds"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateVendorDataInventoryTag": {
        "properties": {
          "name": {
            "description": "Name of the new tag, at most 100 characters. Names are unique per tenant, ignoring case and surrounding whitespace.",
            "maxLength": 100,
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "CreateVercelConnectionData": {
        "properties": {
          "accessToken": {
            "description": "Vercel Access Token.",
            "type": "string"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "teamId": {
            "description": "Vercel Team ID.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "teamId",
          "accessToken"
        ]
      },
      "DashboardAudit": {
        "description": "Minimal audit information for dashboard display",
        "properties": {
          "auditType": {
            "$ref": "#/components/schemas/AuditType"
          },
          "currentStage": {
            "$ref": "#/components/schemas/AuditStage"
          },
          "frameworkId": {
            "description": "The ID of the framework.",
            "format": "uuid",
            "type": "string"
          },
          "hasSection3": {
            "description": "Whether this audit has a Section 3 system description available to view.",
            "type": "boolean"
          },
          "id": {
            "description": "The ID of the audit.",
            "format": "uuid",
            "type": "string"
          },
          "observationPeriodEnd": {
            "description": "The end of the observation period.",
            "format": "date-time",
            "type": "string"
          },
          "observationPeriodStart": {
            "description": "The start of the observation period.",
            "format": "date-time",
            "type": "string"
          },
          "reportUrl": {
            "description": "The URL of the report.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "frameworkId",
          "auditType",
          "currentStage"
        ],
        "type": "object"
      },
      "DashboardControlStatus": {
        "description": "One control in a framework's status grid.",
        "properties": {
          "category": {
            "$ref": "#/components/schemas/ControlCategory"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "title": {
            "description": "Effective control title (custom override falling back to ControlType title).",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "status"
        ],
        "type": "object"
      },
      "DashboardFramework": {
        "description": "Minimal framework information for dashboard display",
        "properties": {
          "framework": {
            "$ref": "#/components/schemas/DashboardFrameworkInfo"
          },
          "frameworkId": {
            "description": "The ID of the framework",
            "type": "string"
          },
          "id": {
            "description": "The ID of the tenant framework",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantComplianceFrameworkStatus"
          }
        },
        "required": [
          "frameworkId",
          "framework",
          "status"
        ],
        "type": "object"
      },
      "DashboardFrameworkInfo": {
        "description": "Minimal framework info containing only fields used in dashboard",
        "properties": {
          "icon": {
            "description": "The icon URL for the framework",
            "type": "string"
          },
          "id": {
            "description": "The ID of the framework",
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "type": "object"
      },
      "DashboardIssueDetection": {
        "description": "One recently detected security issue, for the dashboard's\nlatest-detections feed. Carries the same source-specific deep-link ids as\nDashboardSecurityIssueListItem: pentest findings get\nengagement/report/finding ids, dependency vulnerabilities the\nvulnerability id, code security issues deep-link via their identifier,\nand attack surface issues via their title.\n",
        "properties": {
          "detectedAt": {
            "description": "When the tool first detected the issue.",
            "format": "date-time",
            "type": "string"
          },
          "engagementId": {
            "description": "Pentest engagement id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "findingId": {
            "description": "Pentest finding id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "identifier": {
            "description": "Short well-known identifier when the tool provides one (e.g. CWE-79, CVE-2024-1234, or a scanner rule id).",
            "type": "string"
          },
          "reportId": {
            "description": "Pentest report id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "severity": {
            "$ref": "#/components/schemas/DashboardSecuritySeverity"
          },
          "source": {
            "$ref": "#/components/schemas/DashboardSecuritySource"
          },
          "title": {
            "description": "Human-readable issue title.",
            "type": "string"
          },
          "vulnerabilityId": {
            "description": "Software package vulnerability id, present on DEPENDENCIES items.",
            "type": "string"
          }
        },
        "required": [
          "source",
          "severity",
          "title",
          "detectedAt"
        ],
        "type": "object"
      },
      "DashboardMonitorStats": {
        "description": "How many of the tenant's monitors currently need attention, using the same\ncomputed status as the monitors page and the journey's alerting lists.\nALERTING and BREACHING_SLA are reported separately so the dashboard can\nescalate SLA breaches.\n",
        "properties": {
          "alertingCount": {
            "description": "The number of monitors currently ALERTING",
            "type": "integer"
          },
          "breachingSlaCount": {
            "description": "The number of monitors currently BREACHING_SLA",
            "type": "integer"
          }
        },
        "required": [
          "alertingCount",
          "breachingSlaCount"
        ],
        "type": "object"
      },
      "DashboardOpenIssueCounts": {
        "description": "One security tool's open issues bucketed by severity.",
        "properties": {
          "counts": {
            "$ref": "#/components/schemas/DashboardSeverityCounts"
          },
          "source": {
            "$ref": "#/components/schemas/DashboardSecuritySource"
          }
        },
        "required": [
          "source",
          "counts"
        ],
        "type": "object"
      },
      "DashboardReport": {
        "description": "Minimal report information for dashboard display",
        "properties": {
          "engagementId": {
            "description": "The ID of the engagement.",
            "format": "uuid",
            "type": "string"
          },
          "id": {
            "description": "The ID of the report.",
            "format": "uuid",
            "type": "string"
          },
          "title": {
            "description": "The title of the report.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "engagementId"
        ],
        "type": "object"
      },
      "DashboardSecurityIssueList": {
        "description": "One source × severity bucket of open issues, for the dashboard's open-issues drill-down.",
        "properties": {
          "issues": {
            "description": "Open issues in the bucket, newest first, capped server-side.",
            "items": {
              "$ref": "#/components/schemas/DashboardSecurityIssueListItem"
            },
            "type": "array"
          },
          "totalCount": {
            "description": "Total open issues in the bucket (may exceed the capped issues length).",
            "type": "integer"
          }
        },
        "required": [
          "issues",
          "totalCount"
        ],
        "type": "object"
      },
      "DashboardSecurityIssueListItem": {
        "description": "One open issue inside a source × severity bucket. Fields beyond the title\nare source-specific and power per-issue deep links: pentest findings carry\nengagement/report/finding ids, dependency vulnerabilities carry the\nvulnerability id, code security issues deep-link via their identifier, and\nattack surface issues via their title.\n",
        "properties": {
          "detectedAt": {
            "description": "When the tool first detected the issue.",
            "format": "date-time",
            "type": "string"
          },
          "engagementId": {
            "description": "Pentest engagement id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "findingId": {
            "description": "Pentest finding id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "identifier": {
            "description": "Short well-known identifier when the tool provides one (e.g. CWE-79, CVE-2024-1234, or a scanner rule id).",
            "type": "string"
          },
          "reportId": {
            "description": "Pentest report id, present on PENTEST_FINDINGS items.",
            "type": "string"
          },
          "title": {
            "description": "Human-readable issue title.",
            "type": "string"
          },
          "vulnerabilityId": {
            "description": "Software package vulnerability id, present on DEPENDENCIES items.",
            "type": "string"
          }
        },
        "required": [
          "title",
          "detectedAt"
        ],
        "type": "object"
      },
      "DashboardSecurityIssues": {
        "description": "Cross-tool security issue summary for the tenant dashboard. Sources the\ntenant doesn't have enabled are omitted from openIssues entirely, so the\ndashboard only renders rows for tools that are actually active.\n",
        "properties": {
          "latestDetections": {
            "description": "Issues first detected in the last 30 days across all enabled tools that\nare still open, newest first, capped server-side.\n",
            "items": {
              "$ref": "#/components/schemas/DashboardIssueDetection"
            },
            "type": "array"
          },
          "newDetectionCount": {
            "description": "Total number of detections in the 30-day window (may exceed the capped latestDetections length).",
            "type": "integer"
          },
          "openIssues": {
            "description": "Per-tool open-issue counts bucketed by severity, in a stable source order.",
            "items": {
              "$ref": "#/components/schemas/DashboardOpenIssueCounts"
            },
            "type": "array"
          }
        },
        "required": [
          "openIssues",
          "latestDetections",
          "newDetectionCount"
        ],
        "type": "object"
      },
      "DashboardSecuritySeverity": {
        "description": "Unified severity scale the dashboard maps every security tool onto.\nDEPENDENCIES issues are bucketed by the vulnerability's post-triage risk\nlevel (the dependency-scanning page's `riskLevel`), not its CVSS severity.\n",
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "DashboardSecuritySource": {
        "description": "The security tool an issue was detected by.",
        "enum": [
          "CODE_SECURITY",
          "ATTACK_SURFACE",
          "EXPOSED_ACCOUNTS",
          "PENTEST_FINDINGS",
          "DEPENDENCIES"
        ],
        "type": "string"
      },
      "DashboardSeverityCounts": {
        "description": "Open-issue counts bucketed by unified severity.",
        "properties": {
          "critical": {
            "type": "integer"
          },
          "high": {
            "type": "integer"
          },
          "informational": {
            "type": "integer"
          },
          "low": {
            "type": "integer"
          },
          "medium": {
            "type": "integer"
          }
        },
        "required": [
          "critical",
          "high",
          "medium",
          "low",
          "informational"
        ],
        "type": "object"
      },
      "DashboardStats": {
        "properties": {
          "audits": {
            "items": {
              "$ref": "#/components/schemas/DashboardAudit"
            },
            "type": "array"
          },
          "devices": {
            "$ref": "#/components/schemas/DeviceStats"
          },
          "frameworks": {
            "items": {
              "$ref": "#/components/schemas/FrameworkStats"
            },
            "type": "array"
          },
          "monitors": {
            "$ref": "#/components/schemas/DashboardMonitorStats"
          },
          "people": {
            "$ref": "#/components/schemas/PeopleStats"
          }
        },
        "required": [
          "devices",
          "people",
          "monitors",
          "frameworks",
          "audits"
        ],
        "type": "object"
      },
      "DastApplication": {
        "properties": {
          "attackSurfaceServiceId": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "authMethod": {
            "enum": [
              "BROWSER"
            ],
            "nullable": true,
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "excludeURLs": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "gitRepositoryId": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "hasAuthConfig": {
            "description": "Whether auth config is configured (actual config is never returned)",
            "type": "boolean"
          },
          "headers": {
            "additionalProperties": {
              "type": "string"
            },
            "nullable": true,
            "type": "object"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "includeURLs": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "name": {
            "type": "string"
          },
          "preflight": {
            "$ref": "#/components/schemas/DastApplicationPreflight"
          },
          "primaryURL": {
            "type": "string"
          },
          "scanScheduleDayOfWeek": {
            "nullable": true,
            "type": "integer"
          },
          "scanScheduleEnabled": {
            "type": "boolean"
          },
          "scanScheduleTimeUTC": {
            "nullable": true,
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "type": "object"
      },
      "DastApplicationIssueCounts": {
        "description": "Counts of open DAST issues for an application, broken down by severity.",
        "properties": {
          "high": {
            "type": "integer"
          },
          "informational": {
            "type": "integer"
          },
          "low": {
            "type": "integer"
          },
          "medium": {
            "type": "integer"
          }
        },
        "required": [
          "high",
          "medium",
          "low",
          "informational"
        ],
        "type": "object"
      },
      "DastApplicationListItem": {
        "properties": {
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "hasAuthConfig": {
            "type": "boolean"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "issueCounts": {
            "$ref": "#/components/schemas/DastApplicationIssueCounts"
          },
          "name": {
            "type": "string"
          },
          "preflight": {
            "$ref": "#/components/schemas/DastApplicationPreflight"
          },
          "primaryURL": {
            "type": "string"
          },
          "scanScheduleDayOfWeek": {
            "nullable": true,
            "type": "integer"
          },
          "scanScheduleEnabled": {
            "type": "boolean"
          },
          "scanScheduleTimeUTC": {
            "nullable": true,
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "primaryURL",
          "hasAuthConfig",
          "scanScheduleEnabled",
          "issueCounts",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "DastApplicationListResult": {
        "description": "A list of DAST applications with their open issue counts.",
        "items": {
          "$ref": "#/components/schemas/DastApplicationListItem"
        },
        "type": "array"
      },
      "DastApplicationPreflight": {
        "properties": {
          "completedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "result": {
            "$ref": "#/components/schemas/DastPreflightResult"
          },
          "scanId": {
            "format": "uuid",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/DastScanStatus"
          }
        },
        "required": [
          "scanId",
          "status"
        ],
        "type": "object"
      },
      "DastFinding": {
        "properties": {
          "applicationId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "applicationName": {
            "type": "string"
          },
          "attack": {
            "nullable": true,
            "type": "string"
          },
          "detectedAt": {
            "format": "date-time",
            "type": "string"
          },
          "evidence": {
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "issueId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastSeenAt": {
            "format": "date-time",
            "type": "string"
          },
          "method": {
            "nullable": true,
            "type": "string"
          },
          "nodeName": {
            "description": "Stable identifier for the affected endpoint.",
            "type": "string"
          },
          "otherInfo": {
            "nullable": true,
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/DastFindingOwner"
          },
          "param": {
            "nullable": true,
            "type": "string"
          },
          "request": {
            "nullable": true,
            "type": "string"
          },
          "resolution": {
            "$ref": "#/components/schemas/DastFindingResolution"
          },
          "resolutionDescription": {
            "nullable": true,
            "type": "string"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedBy": {
            "$ref": "#/components/schemas/DastFindingOwner"
          },
          "response": {
            "nullable": true,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/DastFindingStatus"
          },
          "suppressedByRuleId": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "uri": {
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "id",
          "issueId",
          "applicationId",
          "applicationName",
          "nodeName",
          "status",
          "detectedAt",
          "lastSeenAt"
        ],
        "type": "object"
      },
      "DastFindingOwner": {
        "description": "Tenant member assigned to a finding.",
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "DastFindingResolution": {
        "description": "How a finding was resolved. Only set when status is RESOLVED.\n",
        "enum": [
          "FIXED",
          "FALSE_POSITIVE",
          "ACCEPTED_RISK",
          "MITIGATED",
          "NOT_APPLICABLE"
        ],
        "type": "string"
      },
      "DastFindingStatus": {
        "description": "Triage state of a finding.\n",
        "enum": [
          "OPEN",
          "IN_PROGRESS",
          "RESOLVED",
          "SUPPRESSED"
        ],
        "type": "string"
      },
      "DastFindingSummary": {
        "description": "Slim view of a DAST finding for the issue list response.\n",
        "properties": {
          "applicationId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "applicationName": {
            "type": "string"
          },
          "detectedAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastSeenAt": {
            "format": "date-time",
            "type": "string"
          },
          "method": {
            "nullable": true,
            "type": "string"
          },
          "nodeName": {
            "description": "Stable identifier for the affected endpoint.",
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/DastFindingOwner"
          },
          "param": {
            "nullable": true,
            "type": "string"
          },
          "resolution": {
            "$ref": "#/components/schemas/DastFindingResolution"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedBy": {
            "$ref": "#/components/schemas/DastFindingOwner"
          },
          "status": {
            "$ref": "#/components/schemas/DastFindingStatus"
          },
          "suppressedByRuleId": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "uri": {
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "id",
          "applicationId",
          "applicationName",
          "nodeName",
          "status",
          "detectedAt",
          "lastSeenAt"
        ],
        "type": "object"
      },
      "DastIssue": {
        "properties": {
          "confidence": {
            "$ref": "#/components/schemas/DastIssueConfidence"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "cweId": {
            "nullable": true,
            "type": "string"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "findings": {
            "items": {
              "$ref": "#/components/schemas/DastFindingSummary"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "otherInfo": {
            "nullable": true,
            "type": "string"
          },
          "references": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "remediation": {
            "nullable": true,
            "type": "string"
          },
          "severity": {
            "$ref": "#/components/schemas/DastIssueSeverity"
          },
          "systemic": {
            "type": "boolean"
          },
          "title": {
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "severity",
          "confidence",
          "references",
          "systemic",
          "findings",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "DastIssueConfidence": {
        "enum": [
          "HIGH",
          "MEDIUM",
          "LOW"
        ],
        "type": "string"
      },
      "DastIssueListResult": {
        "description": "List of DAST issues with their findings nested.\n",
        "items": {
          "$ref": "#/components/schemas/DastIssue"
        },
        "type": "array"
      },
      "DastIssueSeverity": {
        "enum": [
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "DastPagination": {
        "properties": {
          "limit": {
            "type": "integer"
          },
          "page": {
            "type": "integer"
          },
          "total": {
            "type": "integer"
          },
          "totalPages": {
            "type": "integer"
          }
        },
        "required": [
          "page",
          "limit",
          "total",
          "totalPages"
        ],
        "type": "object"
      },
      "DastPreflightAuthDiagnostics": {
        "properties": {
          "postLogin": {
            "items": {
              "$ref": "#/components/schemas/DastPreflightAuthStep"
            },
            "type": "array"
          },
          "steps": {
            "items": {
              "$ref": "#/components/schemas/DastPreflightAuthStep"
            },
            "type": "array"
          }
        },
        "required": [
          "steps"
        ],
        "type": "object"
      },
      "DastPreflightAuthStep": {
        "properties": {
          "description": {
            "type": "string"
          },
          "screenshotUrl": {
            "description": "Signed CDN URL for the step screenshot, when available.",
            "nullable": true,
            "type": "string"
          },
          "url": {
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "description"
        ],
        "type": "object"
      },
      "DastPreflightOutcome": {
        "description": "Overall result of a completed preflight, aggregated from its phase statuses.",
        "enum": [
          "passed",
          "warning",
          "failed"
        ],
        "type": "string"
      },
      "DastPreflightPhase": {
        "properties": {
          "key": {
            "description": "reachability | authentication | crawl",
            "type": "string"
          },
          "signals": {
            "items": {
              "$ref": "#/components/schemas/DastPreflightSignal"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/DastPreflightPhaseStatus"
          }
        },
        "required": [
          "key",
          "status",
          "signals"
        ],
        "type": "object"
      },
      "DastPreflightPhaseStatus": {
        "enum": [
          "passed",
          "warning",
          "failed",
          "skipped"
        ],
        "type": "string"
      },
      "DastPreflightResult": {
        "properties": {
          "auth": {
            "$ref": "#/components/schemas/DastPreflightAuthDiagnostics"
          },
          "errors": {
            "description": "Run failures (the preflight itself failed); present instead of phases.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "outcome": {
            "$ref": "#/components/schemas/DastPreflightOutcome"
          },
          "phases": {
            "items": {
              "$ref": "#/components/schemas/DastPreflightPhase"
            },
            "type": "array"
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "DastPreflightSeverity": {
        "description": "critical marks its phase as failed; warning is noteworthy but doesn't fail the phase.",
        "enum": [
          "warning",
          "critical"
        ],
        "type": "string"
      },
      "DastPreflightSignal": {
        "properties": {
          "code": {
            "type": "string"
          },
          "severity": {
            "$ref": "#/components/schemas/DastPreflightSeverity"
          }
        },
        "required": [
          "code",
          "severity"
        ],
        "type": "object"
      },
      "DastScan": {
        "properties": {
          "applicationId": {
            "format": "uuid",
            "type": "string"
          },
          "completedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "highIssuesFound": {
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "infoIssuesFound": {
            "type": "integer"
          },
          "lowIssuesFound": {
            "type": "integer"
          },
          "mediumIssuesFound": {
            "type": "integer"
          },
          "startedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/DastScanStatus"
          },
          "totalFindingsFound": {
            "type": "integer"
          },
          "totalIssuesFound": {
            "type": "integer"
          },
          "type": {
            "$ref": "#/components/schemas/DastScanType"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "applicationId",
          "type",
          "status",
          "totalFindingsFound",
          "totalIssuesFound",
          "highIssuesFound",
          "mediumIssuesFound",
          "lowIssuesFound",
          "infoIssuesFound",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "DastScanListResult": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/DastPagination"
          },
          "scans": {
            "items": {
              "$ref": "#/components/schemas/DastScan"
            },
            "type": "array"
          }
        },
        "required": [
          "scans",
          "pagination"
        ],
        "type": "object"
      },
      "DastScanStatus": {
        "enum": [
          "PENDING",
          "RUNNING",
          "COMPLETED",
          "FAILED"
        ],
        "type": "string"
      },
      "DastScanType": {
        "enum": [
          "VULNERABILITY",
          "PREFLIGHT"
        ],
        "type": "string"
      },
      "DataSensitivityLevel": {
        "enum": [
          "PUBLIC",
          "INTERNAL",
          "CONFIDENTIAL",
          "SECRET"
        ],
        "type": "string"
      },
      "DependencyScanInfo": {
        "properties": {
          "createdAt": {
            "description": "The date and time the repository was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The id of the scanned git repository.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isScanning": {
            "description": "Whether a scan is currently running.",
            "type": "boolean"
          },
          "lastRun": {
            "description": "The date and time the scan was last run.",
            "format": "date-time",
            "type": "string"
          },
          "lastScanFailedErrorMessage": {
            "description": "Error message from the last failed scan (null when scan succeeds or hasn't failed).",
            "nullable": true,
            "type": "string"
          },
          "nextRun": {
            "description": "The date and time the scan is scheduled to run next.",
            "format": "date-time",
            "type": "string"
          },
          "updatedAt": {
            "description": "The date and time the latest scan was created.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "isScanning"
        ]
      },
      "DependencyScanInfoList": {
        "items": {
          "$ref": "#/components/schemas/DependencyScanInfo"
        },
        "type": "array"
      },
      "DeviceInfo": {
        "properties": {
          "hardwareName": {
            "type": "string"
          },
          "hardwareSpecs": {
            "type": "string"
          },
          "isOnline": {
            "type": "boolean"
          },
          "isVirtualMachine": {
            "type": "boolean"
          },
          "mdmEnrollment": {
            "$ref": "#/components/schemas/DeviceMdmEnrollment"
          },
          "osBuild": {
            "type": "string"
          },
          "osVersion": {
            "type": "string"
          },
          "serial": {
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/DeviceType"
          }
        },
        "required": [
          "serial",
          "hardwareName",
          "type",
          "osVersion",
          "osBuild",
          "isVirtualMachine",
          "isOnline"
        ]
      },
      "DeviceMdmEnrollment": {
        "description": "MDM enrollment as observed on the device by the Oneleet agent. Omitted\nentirely when the agent has not reported it — an agent predating the\ncollector, or a platform with no collector (currently everything but\nmacOS). An omitted value means unknown, not \"not enrolled\".\n",
        "properties": {
          "enrolledViaDep": {
            "description": "Whether the device was enrolled through Apple's Device Enrollment Program (Automated Device Enrollment).",
            "type": "boolean"
          },
          "isDepAssignedWithoutEnrollment": {
            "description": "True when the device reports a DEP assignment but holds no MDM\nenrollment. Such a device looks unmanaged today, yet the Apple Business\nManager assignment survives a wipe and will re-enroll it into whichever\nMDM owns that assignment.\n",
            "type": "boolean"
          },
          "isEnrolled": {
            "type": "boolean"
          },
          "isOneleet": {
            "description": "True when the enrollment is Oneleet's own MDM. When this is false and\nisEnrolled is true, the device is managed by a third-party product and\ncannot be enrolled into Oneleet MDM until it is released.\n",
            "type": "boolean"
          },
          "isUserApproved": {
            "type": "boolean"
          },
          "serverUrl": {
            "type": "string"
          },
          "vendor": {
            "description": "Display name of the MDM, derived from the enrollment server URL\n(e.g. \"Jamf Pro\"). Falls back to the server hostname when the vendor\nis not recognized.\n",
            "type": "string"
          }
        },
        "required": [
          "isEnrolled",
          "isOneleet",
          "vendor",
          "serverUrl",
          "enrolledViaDep",
          "isUserApproved",
          "isDepAssignedWithoutEnrollment"
        ],
        "type": "object"
      },
      "DeviceMonitor": {
        "properties": {
          "assetResult": {
            "$ref": "#/components/schemas/MonitorAssetResult"
          },
          "autoFixAvailable": {
            "description": "Whether the agent supports auto-fixing this monitor.",
            "type": "boolean"
          },
          "autoFixTaskCreatedAt": {
            "description": "The creation time of the latest auto-fix task for this monitor, if one exists.",
            "format": "date-time",
            "type": "string"
          },
          "autoFixTaskStatus": {
            "$ref": "#/components/schemas/AgentTaskStatus"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "monitor": {
            "$ref": "#/components/schemas/Monitor"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStatus"
          }
        },
        "required": [
          "id",
          "monitor",
          "status"
        ]
      },
      "DeviceMonitorList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/DeviceMonitor"
            },
            "type": "array"
          }
        }
      },
      "DeviceStats": {
        "properties": {
          "compliantCount": {
            "description": "The number of devices that are compliant",
            "type": "integer"
          },
          "count": {
            "description": "The total number of devices",
            "type": "integer"
          },
          "nonCompliantCount": {
            "description": "The number of devices that are not compliant",
            "type": "integer"
          }
        },
        "required": [
          "compliantCount",
          "nonCompliantCount",
          "count"
        ]
      },
      "DeviceStatus": {
        "enum": [
          "NON_COMPLIANT",
          "COMPLIANT",
          "SNOOZED",
          "INACTIVE",
          "PENDING",
          "UNASSIGNED",
          "OUT_OF_SCOPE",
          "ARCHIVED"
        ],
        "type": "string"
      },
      "DeviceType": {
        "enum": [
          "MACOS",
          "LINUX",
          "WINDOWS"
        ],
        "type": "string"
      },
      "DigestFrequency": {
        "description": "Frequency of receiving the digest email.",
        "enum": [
          "DAILY",
          "WEEKLY",
          "BIWEEKLY",
          "MONTHLY"
        ],
        "type": "string"
      },
      "DigestSection": {
        "description": "A section in the digest email that corresponds to an application feature.",
        "enum": [
          "MONITORS",
          "ATTACK_SURFACE",
          "CODE_SECURITY",
          "DEPENDENCY_SCANNING"
        ],
        "type": "string"
      },
      "DocumentEditorBlock": {
        "properties": {
          "data": {
            "type": "object"
          },
          "id": {
            "description": "Unique identifier for the block",
            "type": "string"
          },
          "type": {
            "description": "Type of the block",
            "enum": [
              "table",
              "header",
              "paragraph",
              "list",
              "image",
              "checklist",
              "quote",
              "code",
              "inlineCode",
              "delimiter",
              "simpleImage",
              "marker"
            ],
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "data"
        ],
        "type": "object"
      },
      "DocumentEditorObject": {
        "properties": {
          "blocks": {
            "items": {
              "$ref": "#/components/schemas/DocumentEditorBlock"
            },
            "type": "array"
          },
          "time": {
            "description": "Timestamp in milliseconds",
            "format": "int64",
            "type": "integer"
          },
          "version": {
            "description": "Version of the editor",
            "type": "string"
          }
        },
        "required": [
          "blocks"
        ],
        "type": "object"
      },
      "Engagement": {
        "properties": {
          "createdAt": {
            "description": "The time that this engagement was created.",
            "format": "date-time",
            "type": "string"
          },
          "engagementScoping": {
            "$ref": "#/components/schemas/EngagementScoping"
          },
          "id": {
            "description": "The ID of the engagement.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "meta": {
            "$ref": "#/components/schemas/EngagementMeta"
          },
          "name": {
            "description": "The name of the engagement.",
            "type": "string"
          },
          "reports": {
            "description": "The reports associated with this engagement.",
            "items": {
              "$ref": "#/components/schemas/DashboardReport"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/EngagementStatus"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this engagement.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantName": {
            "description": "The name of the tenant associated with this engagement.",
            "type": "string"
          },
          "testers": {
            "description": "The testers associated with this engagement.",
            "items": {
              "$ref": "#/components/schemas/TenantTester"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this engagement was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "status",
          "tenantId"
        ],
        "type": "object"
      },
      "EngagementMeta": {
        "properties": {
          "actualFinishedAt": {
            "description": "The actual finish time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "actualStartedAt": {
            "description": "The actual start time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "hours": {
            "description": "The hours of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "period": {
            "description": "The period of the engagement.",
            "maxLength": 20,
            "minLength": 1,
            "type": "string"
          },
          "plannedFinishAt": {
            "description": "The planned finish time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "plannedStartAt": {
            "description": "The planned start time of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          },
          "title": {
            "description": "The title of the engagement.",
            "maxLength": 255,
            "minLength": 1,
            "type": "string"
          }
        },
        "type": "object"
      },
      "EngagementResourceSnapshot": {
        "properties": {
          "createdAt": {
            "description": "The time that this snapshot was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the snapshot.",
            "format": "uuid",
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/EngagementResourceSnapshotKind"
          },
          "kindId": {
            "description": "The ID of the kind of the snapshot.",
            "type": "string"
          },
          "operationKind": {
            "$ref": "#/components/schemas/EngagementResourceSnapshotOperationKind"
          },
          "updateData": {
            "description": "Json with the update data of the snapshot.",
            "type": "string"
          },
          "userDisplayName": {
            "description": "The display name of the user that created the snapshot.",
            "type": "string"
          },
          "userEmail": {
            "description": "The email of the user that created the snapshot.",
            "type": "string"
          }
        }
      },
      "EngagementResourceSnapshotKind": {
        "enum": [
          "FINDING"
        ],
        "type": "string"
      },
      "EngagementResourceSnapshotOperationKind": {
        "enum": [
          "CREATE",
          "UPDATE",
          "DELETE"
        ],
        "type": "string"
      },
      "EngagementScoping": {
        "properties": {
          "details": {
            "description": "The details of the scoping call for the engagement.",
            "type": "string"
          },
          "scopingCallDate": {
            "description": "The date of the scoping call for the engagement.",
            "format": "date-time",
            "type": "string"
          },
          "scopingCallTime": {
            "description": "The time of the scoping call for the engagement.",
            "type": "string"
          }
        },
        "type": "object"
      },
      "EngagementStatus": {
        "enum": [
          "PENDING_SCOPING_CALL",
          "PLANNED",
          "ONGOING",
          "COMPLETED"
        ],
        "type": "string"
      },
      "ErrorType": {
        "description": "The type of error.",
        "enum": [
          "SLUG_ALREADY_EXISTS",
          "MEMBER_ALREADY_EXISTS",
          "EMPLOYEE_ALREADY_EXISTS",
          "INVITE_ALREADY_EXISTS",
          "VENDOR_ACCOUNT_ALREADY_EXISTS",
          "DOMAIN_ALREADY_ADDED",
          "DOMAIN_ALREADY_VERIFIED",
          "TXT_RECORD_NOT_FOUND",
          "TRUST_REQUEST_ALREADY_SUBMITTED",
          "EVIDENCE_ALREADY_LINKED",
          "GROUP_ALREADY_LINKED",
          "CURRENT_EMAIL_DOMAIN_NOT_VERIFIED",
          "NEW_EMAIL_DOMAIN_NOT_VERIFIED",
          "EMAIL_ALREADY_EXISTS_CONFLICT",
          "MEMBER_NEVER_LOGGED_IN",
          "RECIPIENT_EMAIL_SUPPRESSED",
          "SLACK_NOTIFICATION_FAILED",
          "INTEGRATION_NOT_SUPPORTED",
          "INTEGRATION_MISSING_REQUIRED_PARAMETERS",
          "CONSENT_REQUIRED"
        ],
        "example": "RECORD_ALREADY_EXISTS",
        "type": "string"
      },
      "Evidence": {
        "properties": {
          "aiReviewResults": {
            "$ref": "#/components/schemas/EvidenceAiAnalysis"
          },
          "aiReviewStatus": {
            "$ref": "#/components/schemas/EvidenceAiReviewStatus"
          },
          "aiSuggestedName": {
            "description": "The AI-suggested name for this evidence.",
            "type": "string"
          },
          "controlIds": {
            "description": "The IDs of linked controls.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time the evidence was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/UserPublic"
          },
          "fileMimeType": {
            "description": "The MIME type detected from the evidence file's contents, without parameters (e.g. application/pdf). Absent for evidence without a file.",
            "type": "string"
          },
          "fileName": {
            "description": "The evidence's file name.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the evidence.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "inAppDocument": {
            "$ref": "#/components/schemas/InAppDocument"
          },
          "inAppDocumentId": {
            "description": "The ID of the in-app document.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "link": {
            "description": "The evidence's link.",
            "type": "string"
          },
          "name": {
            "description": "The name of the evidence.",
            "type": "string"
          },
          "note": {
            "description": "The evidence's note.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant this evidence belongs to",
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/EvidenceType"
          },
          "updatedAt": {
            "description": "The time the evidence was last updated",
            "format": "date-time",
            "type": "string"
          },
          "vendorIds": {
            "description": "The IDs of linked vendors.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "type",
          "controlIds",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "EvidenceAiAnalysis": {
        "description": "AI analysis results for evidence",
        "properties": {
          "content_summary": {
            "description": "Summary of the content of the link evidence",
            "type": "string"
          },
          "content_type": {
            "description": "Content type of the link evidence",
            "type": "string"
          },
          "description": {
            "description": "Human-readable summary of the evidence",
            "type": "string"
          },
          "extracted_text": {
            "description": "Any readable text extracted from the image",
            "type": "string"
          },
          "image_type": {
            "description": "Type of image (screenshot, document, diagram, photo, etc.)",
            "type": "string"
          },
          "is_accessible": {
            "description": "Whether the link evidence is accessible to the AI",
            "type": "boolean"
          },
          "is_relevant": {
            "description": "Whether the evidence plausibly demonstrates the control(s) it is linked to, independent of formal validity — pristine evidence can still be irrelevant to its control.",
            "type": "boolean"
          },
          "is_settings_page": {
            "description": "Whether this screenshot shows a settings/configuration page",
            "type": "boolean"
          },
          "recommendation": {
            "description": "Actionable fix-it instruction for the uploader when the evidence is deficient (e.g. \"Re-take the screenshot with the URL bar visible\"); absent when the evidence passes.",
            "type": "string"
          },
          "relevance_reasoning": {
            "description": "Short justification for the relevance call",
            "type": "string"
          },
          "resource_identifier": {
            "$ref": "#/components/schemas/EvidenceResourceIdentifier"
          },
          "source": {
            "description": "Platform/vendor identifier (lowercase) or \"unknown\"",
            "type": "string"
          },
          "status_code": {
            "description": "HTTP status code of the link evidence",
            "type": "integer"
          },
          "suggested_name": {
            "description": "AI-suggested descriptive name for this evidence",
            "type": "string"
          },
          "timestamp_analysis": {
            "$ref": "#/components/schemas/EvidenceTimestampAnalysis"
          },
          "title": {
            "description": "Page title of the link evidence",
            "type": "string"
          },
          "visible_elements": {
            "description": "List of UI elements visible in the image",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "EvidenceAiReviewStatus": {
        "description": "The AI review status for evidence.",
        "enum": [
          "DISABLED",
          "IN_PROGRESS",
          "SUCCEEDED",
          "FAILED",
          "INTERNAL_ERROR"
        ],
        "type": "string"
      },
      "EvidenceCreateUploadUrlRequest": {
        "description": "Request a presigned URL for uploading an evidence file directly to S3.\nThe returned URL is bound to the supplied MIME type and size — the client\nmust PUT the file with matching Content-Type and Content-Length headers,\nor S3 will reject the upload with a signature mismatch.\n",
        "properties": {
          "mimeType": {
            "description": "MIME type of the file. Must be one of the supported evidence MIME types\n(image/jpeg, image/png, image/webp, image/gif, text/csv, text/markdown,\ntext/plain, application/pdf, application/msword, application/vnd.ms-excel,\napplication/vnd.ms-powerpoint, application/vnd.openxmlformats-* office\nformats, application/yaml, application/json, application/xml).\n",
            "type": "string"
          },
          "sizeBytes": {
            "description": "Size of the file in bytes. Must be greater than 0 and at most 41943040 (40 MiB).",
            "format": "int64",
            "type": "integer"
          }
        },
        "required": [
          "mimeType",
          "sizeBytes"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "EvidenceCriterion": {
        "properties": {
          "content": {
            "description": "The evidence criterion content",
            "maxLength": 6000,
            "type": "string"
          },
          "id": {
            "description": "Unique identifier for the evidence criterion (filename without .md extension)",
            "type": "string"
          },
          "label": {
            "description": "Display label for the evidence criterion",
            "type": "string"
          }
        },
        "required": [
          "id",
          "content"
        ],
        "type": "object"
      },
      "EvidenceDownloadUrlResponse": {
        "properties": {
          "url": {
            "description": "Presigned S3 URL valid for 1 hour",
            "type": "string"
          }
        },
        "required": [
          "url"
        ],
        "type": "object"
      },
      "EvidenceRequest": {
        "properties": {
          "activeAt": {
            "description": "If set, defines the date this request becomes active, and when evidence can then be submitted.",
            "format": "date-time",
            "type": "string"
          },
          "controlId": {
            "description": "Identifier for the related control",
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "description": "When this evidence request was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "Description of the evidence being requested.",
            "nullable": true,
            "type": "string"
          },
          "evidence": {
            "items": {
              "$ref": "#/components/schemas/Evidence"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the requested evidence.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/EvidenceRequestStatus"
          },
          "title": {
            "description": "Title of the evidence being requested.",
            "type": "string"
          },
          "updatedAt": {
            "description": "When this evidence request was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "controlId",
          "status"
        ],
        "type": "object"
      },
      "EvidenceRequestStatus": {
        "description": "The computed status of an evidence request based on review status and linked evidence.",
        "enum": [
          "INACTIVE",
          "PENDING",
          "READY_FOR_REVIEW",
          "IN_REVIEW",
          "APPROVED",
          "NEEDS_CHANGES"
        ],
        "type": "string"
      },
      "EvidenceResourceIdentifier": {
        "description": "Resource identifier analysis from the evidence",
        "properties": {
          "identifier_text": {
            "description": "The exact text of the resource identifier",
            "type": "string"
          },
          "identifier_type": {
            "description": "Type of identifier detected",
            "enum": [
              "url",
              "hierarchical_path",
              "prefixed_code",
              "channel_name",
              "named_resource"
            ],
            "type": "string"
          },
          "is_valid": {
            "description": "Whether this appears to be a genuine resource identifier",
            "type": "boolean"
          },
          "location": {
            "description": "Where the identifier appears in the image",
            "enum": [
              "address_bar",
              "overlay",
              "header",
              "breadcrumb",
              "sidebar",
              "toolbar",
              "content"
            ],
            "type": "string"
          }
        },
        "type": "object"
      },
      "EvidenceTimestampAnalysis": {
        "description": "Timestamp analysis from the evidence",
        "properties": {
          "is_valid_absolute": {
            "description": "Whether this is a valid absolute timestamp (day+month+hour minimum)",
            "type": "boolean"
          },
          "raw_text": {
            "description": "The exact text of the timestamp as it appears in the image",
            "type": "string"
          },
          "rejection_reason": {
            "description": "If is_valid_absolute is false, explains why",
            "type": "string"
          },
          "timestamp_source": {
            "description": "Where the timestamp appears",
            "enum": [
              "system_ui",
              "overlay",
              "document_content"
            ],
            "type": "string"
          }
        },
        "type": "object"
      },
      "EvidenceToControl": {
        "description": "Represents the link between evidence and a control",
        "properties": {
          "aiEvaluationResults": {
            "$ref": "#/components/schemas/EvidenceToControlEvaluationResults"
          },
          "aiEvaluationStatus": {
            "$ref": "#/components/schemas/EvidenceToControlEvaluationStatus"
          },
          "controlId": {
            "description": "The ID of the linked control",
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "description": "When the link was created",
            "format": "date-time",
            "type": "string"
          },
          "evidenceId": {
            "description": "The ID of the linked evidence",
            "format": "uuid",
            "type": "string"
          },
          "id": {
            "description": "The ID of the evidence-to-control link",
            "format": "uuid",
            "type": "string"
          },
          "note": {
            "description": "Optional note for this link",
            "type": "string"
          },
          "updatedAt": {
            "description": "When the link was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "controlId",
          "evidenceId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "EvidenceToControlCriteriaEvaluation": {
        "description": "Evaluation result for a single criterion",
        "properties": {
          "confidence": {
            "$ref": "#/components/schemas/EvidenceToControlEvaluationConfidence"
          },
          "criteria_hash": {
            "description": "SHA256 hash of criterion id + content for change detection",
            "type": "string"
          },
          "criteria_label": {
            "description": "Human-readable label of the criterion being evaluated",
            "type": "string"
          },
          "reasoning": {
            "description": "Explanation of the evaluation result",
            "type": "string"
          },
          "result": {
            "$ref": "#/components/schemas/EvidenceToControlEvaluationResultType"
          }
        },
        "required": [
          "criteria_hash",
          "result",
          "reasoning"
        ],
        "type": "object"
      },
      "EvidenceToControlEvaluationConfidence": {
        "description": "Confidence level of the AI evaluation.",
        "enum": [
          "LOW",
          "MEDIUM",
          "HIGH"
        ],
        "type": "string"
      },
      "EvidenceToControlEvaluationResultType": {
        "description": "The result of evaluating evidence against a single criterion.",
        "enum": [
          "PASS",
          "FAIL",
          "ERROR"
        ],
        "type": "string"
      },
      "EvidenceToControlEvaluationResults": {
        "description": "AI evaluation results for evidence against control criteria",
        "properties": {
          "error": {
            "description": "Error message if evaluation failed",
            "type": "string"
          },
          "has_error": {
            "description": "True if evaluation completely failed",
            "type": "boolean"
          },
          "model": {
            "description": "The AI model used for evaluation",
            "type": "string"
          },
          "results": {
            "additionalProperties": {
              "$ref": "#/components/schemas/EvidenceToControlCriteriaEvaluation"
            },
            "description": "Map of criteria_id to evaluation result",
            "type": "object"
          }
        },
        "type": "object"
      },
      "EvidenceToControlEvaluationStatus": {
        "description": "The AI evaluation status for evidence linked to a control.",
        "enum": [
          "DISABLED",
          "IN_PROGRESS",
          "SUCCESS",
          "FAILED"
        ],
        "type": "string"
      },
      "EvidenceType": {
        "description": "The type of evidence.",
        "enum": [
          "IMAGE",
          "FILE",
          "LINK",
          "NOTE",
          "IN_APP_DOCUMENT"
        ],
        "type": "string"
      },
      "EvidenceUploadUrl": {
        "description": "A presigned PUT URL for uploading an evidence file to S3.",
        "properties": {
          "expiresAt": {
            "description": "When the presigned URL expires.",
            "format": "date-time",
            "type": "string"
          },
          "requiredHeaders": {
            "additionalProperties": {
              "type": "string"
            },
            "description": "Headers that must be set on the PUT request. The signature includes\nContent-Type and Content-Length, so they cannot be changed after the URL is minted.\n",
            "type": "object"
          },
          "s3Key": {
            "description": "The opaque S3 key for the uploaded file. Pass this back in a subsequent\n`evidence:create-from-upload` call to attach the upload to a new evidence row.\n",
            "type": "string"
          },
          "uploadUrl": {
            "description": "The presigned PUT URL. Issue an HTTP PUT to this URL with the bytes of\nthe file as the body and the headers in `requiredHeaders`.\n",
            "type": "string"
          }
        },
        "required": [
          "uploadUrl",
          "s3Key",
          "requiredHeaders",
          "expiresAt"
        ],
        "type": "object"
      },
      "Export": {
        "description": "A bulk export file. It is prepared in the background: while status is PENDING or RUNNING, call the same endpoint again until it is COMPLETED, then download from downloadUrl within one hour. A FAILED export without a failureReason is retried by the next call; one with a failureReason cannot succeed as requested, so change the request instead of calling again.",
        "properties": {
          "completedAt": {
            "format": "date-time",
            "type": "string"
          },
          "downloadUrl": {
            "description": "Signed download URL valid for one hour, set once the export is COMPLETED. Anyone with the link can download the file.",
            "format": "uri",
            "type": "string"
          },
          "failureReason": {
            "$ref": "#/components/schemas/ExportFailureReason"
          },
          "fileName": {
            "description": "The download file name, set once the export is COMPLETED.",
            "type": "string"
          },
          "recordCount": {
            "description": "The number of records in the file, set once the export is COMPLETED.",
            "minimum": 0,
            "type": "integer"
          },
          "requestedAt": {
            "format": "date-time",
            "type": "string"
          },
          "startedAt": {
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ExportJobStatus"
          }
        },
        "required": [
          "status",
          "requestedAt"
        ],
        "type": "object"
      },
      "ExportFailureReason": {
        "description": "Why a FAILED export cannot succeed as requested. TOO_LARGE means the export exceeds the record or size limit and the request must be narrowed. INVALID_PARAMETERS means the request was rejected while building. UNAVAILABLE means this export kind is not available in this deployment.",
        "enum": [
          "TOO_LARGE",
          "INVALID_PARAMETERS",
          "UNAVAILABLE"
        ],
        "type": "string"
      },
      "ExportJobStatus": {
        "enum": [
          "PENDING",
          "RUNNING",
          "COMPLETED",
          "FAILED"
        ],
        "type": "string"
      },
      "FeatureFlag": {
        "properties": {
          "dependsOn": {
            "description": "IDs of the feature flags this flag depends on.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the feature flag.",
            "type": "string"
          },
          "intent": {
            "$ref": "#/components/schemas/FeatureFlagIntent"
          },
          "label": {
            "description": "The label of the feature flag.",
            "type": "string"
          },
          "rolloutPhase": {
            "$ref": "#/components/schemas/FeatureFlagRolloutPhase"
          }
        },
        "required": [
          "id",
          "label",
          "intent",
          "rolloutPhase",
          "dependsOn"
        ]
      },
      "FeatureFlagGroup": {
        "properties": {
          "featureFlagIds": {
            "description": "IDs of the feature flags in this group.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the feature flag group.",
            "type": "string"
          },
          "name": {
            "description": "The display name of the feature flag group.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "featureFlagIds"
        ]
      },
      "FeatureFlagIntent": {
        "enum": [
          "ENTITLEMENT",
          "CUSTOMER_TOGGLEABLE",
          "ROLLOUT_ONLY"
        ],
        "type": "string"
      },
      "FeatureFlagList": {
        "properties": {
          "groups": {
            "description": "Feature flag groups. Only returned by the global feature flag catalog.",
            "items": {
              "$ref": "#/components/schemas/FeatureFlagGroup"
            },
            "type": "array",
            "x-go-name": "Groups"
          },
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/FeatureFlag"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "FeatureFlagRolloutPhase": {
        "enum": [
          "INTERNAL_ONLY",
          "ALPHA",
          "CLOSED_BETA",
          "GENERALLY_AVAILABLE"
        ],
        "type": "string"
      },
      "FieldworkDelivery": {
        "properties": {
          "deliveryId": {
            "format": "uuid",
            "type": "string"
          },
          "error": {
            "description": "What didn't go through, when the outcome isn't delivered.",
            "nullable": true,
            "type": "string"
          },
          "externalRef": {
            "description": "For email, the provider's message ids for the copies that were sent, comma separated. For Slack, the posted message's timestamp.",
            "nullable": true,
            "type": "string"
          },
          "outcome": {
            "$ref": "#/components/schemas/FieldworkDeliveryOutcome"
          },
          "recipients": {
            "items": {
              "$ref": "#/components/schemas/FieldworkDeliveryRecipient"
            },
            "type": "array"
          }
        },
        "required": [
          "deliveryId",
          "outcome",
          "recipients"
        ],
        "type": "object"
      },
      "FieldworkDeliveryAttachment": {
        "description": "A file to attach, read from the platform's evidence store so its bytes never pass through the request. The evidence must belong to the tenant and hold a file of at most 7 MB.",
        "properties": {
          "evidenceId": {
            "description": "The evidence record whose file is attached.",
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "evidenceId"
        ],
        "type": "object"
      },
      "FieldworkDeliveryOutcome": {
        "description": "partial means some recipients were sent the message and others weren't. failed means none were. unknown means some outcomes are unconfirmed; known provider references are retained and the delivery isn't retried.",
        "enum": [
          "delivered",
          "partial",
          "failed",
          "unknown"
        ],
        "type": "string"
      },
      "FieldworkDeliveryRecipient": {
        "properties": {
          "address": {
            "type": "string"
          },
          "error": {
            "description": "Why the copy for this recipient wasn't sent.",
            "nullable": true,
            "type": "string"
          },
          "isDelivered": {
            "type": "boolean"
          },
          "messageId": {
            "description": "The email provider's id for the copy sent to this recipient.",
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "address",
          "isDelivered"
        ],
        "type": "object"
      },
      "FieldworkDeliverySlackChannel": {
        "description": "A Slack channel a delivery can post to.",
        "properties": {
          "id": {
            "type": "string"
          },
          "isBotMember": {
            "description": "Whether the Oneleet app is in the channel. It can only post to a channel it was invited to.",
            "type": "boolean"
          },
          "isPrivate": {
            "type": "boolean"
          },
          "name": {
            "type": "string"
          },
          "workspace": {
            "description": "The workspace's Slack subdomain.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "workspace",
          "isPrivate",
          "isBotMember"
        ],
        "type": "object"
      },
      "FieldworkEmailDeliveryBody": {
        "description": "An email sent through the platform's email notification sender. Each recipient gets their own copy, so recipients don't see each other.",
        "properties": {
          "attachment": {
            "$ref": "#/components/schemas/FieldworkDeliveryAttachment"
          },
          "htmlBody": {
            "maxLength": 1000000,
            "minLength": 1,
            "type": "string"
          },
          "subject": {
            "maxLength": 500,
            "minLength": 1,
            "type": "string"
          },
          "to": {
            "items": {
              "format": "email",
              "maxLength": 320,
              "type": "string"
            },
            "maxItems": 20,
            "minItems": 1,
            "type": "array"
          }
        },
        "required": [
          "to",
          "subject",
          "htmlBody"
        ],
        "type": "object"
      },
      "FieldworkSlackDeliveryBody": {
        "description": "A message posted to a channel in a Slack workspace the tenant connected, with the connection's own bot token.",
        "properties": {
          "channelId": {
            "description": "The channel asset instance id, as listed by tenant:get:slack-channels.",
            "maxLength": 128,
            "minLength": 1,
            "type": "string"
          },
          "text": {
            "description": "The message, in Slack's mrkdwn.",
            "maxLength": 40000,
            "minLength": 1,
            "type": "string"
          }
        },
        "required": [
          "channelId",
          "text"
        ],
        "type": "object"
      },
      "Finding": {
        "properties": {
          "classification": {
            "$ref": "#/components/schemas/FindingClassification"
          },
          "createdAt": {
            "description": "The time that this finding was created.",
            "format": "date-time",
            "type": "string"
          },
          "discoveryDate": {
            "description": "The date that the finding was discovered.",
            "format": "date-time",
            "type": "string"
          },
          "engagementId": {
            "description": "The ID of the engagement that this finding is linked to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "findingText": {
            "$ref": "#/components/schemas/FindingText"
          },
          "id": {
            "description": "The ID of the finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/FindingKind"
          },
          "lastRequestAssistanceAt": {
            "description": "The date that the finding was last requested assistance.",
            "format": "date-time",
            "type": "string"
          },
          "priority": {
            "$ref": "#/components/schemas/FindingPriority"
          },
          "readableId": {
            "description": "The readable ID of the finding.",
            "type": "string"
          },
          "reportId": {
            "description": "The ID of the report that this finding is linked to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reviewReason": {
            "$ref": "#/components/schemas/FindingCloseReason"
          },
          "reviewReasonText": {
            "description": "Additional text that a tester can add for the review.",
            "type": "string"
          },
          "snapshots": {
            "items": {
              "$ref": "#/components/schemas/EngagementResourceSnapshot"
            },
            "type": "array"
          },
          "source": {
            "$ref": "#/components/schemas/FindingSource"
          },
          "state": {
            "$ref": "#/components/schemas/FindingState"
          },
          "targets": {
            "items": {
              "$ref": "#/components/schemas/Target"
            },
            "type": "array",
            "x-go-name": "Targets"
          },
          "testerId": {
            "description": "The ID of the tester that generated this finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "testerName": {
            "description": "The name of the tester that generated this finding.",
            "type": "string"
          },
          "title": {
            "description": "The title of the finding.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this finding was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "readableId",
          "discoveryDate",
          "title",
          "kind",
          "state",
          "source",
          "priority",
          "reportId",
          "engagementId"
        ],
        "type": "object"
      },
      "FindingClassification": {
        "properties": {
          "cvssBaseScore": {
            "description": "The CVSS base score of the finding.",
            "type": "number"
          },
          "cvssBaseSeverity": {
            "description": "The CVSS base severity of the finding.",
            "type": "string"
          },
          "cvssVector": {
            "description": "The CVSS vector of the finding.",
            "type": "string"
          },
          "cvssVersion": {
            "description": "The CVSS version of the finding.",
            "type": "string"
          },
          "cwe": {
            "description": "The CWE of the finding.",
            "type": "string"
          },
          "findingId": {
            "description": "The ID of the finding that this finding classification is linked to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "description": "The ID of the finding classification.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "impact": {
            "$ref": "#/components/schemas/ClassificationImpact"
          },
          "owasp": {
            "description": "The OWASP of the finding.",
            "type": "string"
          },
          "probability": {
            "$ref": "#/components/schemas/ClassificationProbability"
          },
          "risk": {
            "$ref": "#/components/schemas/ClassificationRisk"
          }
        },
        "required": [
          "id",
          "findingId",
          "risk",
          "probability",
          "impact"
        ]
      },
      "FindingCloseReason": {
        "enum": [
          "TEST_FOR_REMEDIATION",
          "REJECTED",
          "ACCEPTED_RISK",
          "FALSE_POSITIVE",
          "CLOSED_OTHER"
        ],
        "type": "string"
      },
      "FindingKind": {
        "enum": [
          "VULNERABILITY",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "FindingList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Finding"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "FindingPriority": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "FindingSource": {
        "enum": [
          "PENTEST",
          "BUGBOUNTY",
          "VULN_SCAN",
          "ATTACK_SURFACE_SCAN",
          "STATIC_CODE_ANALYSIS"
        ],
        "type": "string"
      },
      "FindingState": {
        "enum": [
          "DRAFT",
          "OPEN",
          "REMEDIATED",
          "IN_REVIEW",
          "IN_PROGRESS",
          "REJECTED",
          "DUPLICATE",
          "ACCEPTED_RISK",
          "FALSE_POSITIVE",
          "IGNORED"
        ],
        "type": "string"
      },
      "FindingText": {
        "properties": {
          "additionalInfo": {
            "description": "The additional info of the finding.",
            "type": "string"
          },
          "businessImpact": {
            "description": "The business impact of the finding.",
            "type": "string"
          },
          "findingId": {
            "description": "The ID of the finding that this finding text is linked to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "generalDescription": {
            "description": "The general description of the finding.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the finding text.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "references": {
            "description": "The references of the finding.",
            "type": "string"
          },
          "remediation": {
            "description": "The remediation of the finding.",
            "type": "string"
          },
          "reproductionSteps": {
            "description": "The reproduction steps of the finding.",
            "type": "string"
          },
          "specificDescription": {
            "description": "The specific description of the finding.",
            "type": "string"
          },
          "technicalDescription": {
            "description": "The technical description of the finding.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "findingId",
          "generalDescription"
        ]
      },
      "FrameworkControlStats": {
        "properties": {
          "count": {
            "description": "The total number of controls",
            "type": "integer"
          },
          "failingCount": {
            "description": "The number of controls that are failing",
            "type": "integer"
          },
          "inProgressCount": {
            "description": "The number of controls that are in progress",
            "type": "integer"
          },
          "inReviewCount": {
            "description": "The number of controls that are in review",
            "type": "integer"
          },
          "needChangesCount": {
            "description": "The number of controls that need changes",
            "type": "integer"
          },
          "notStartedCount": {
            "description": "The number of controls that are not started",
            "type": "integer"
          },
          "passingCount": {
            "description": "The number of controls that are passing",
            "type": "integer"
          }
        },
        "required": [
          "count",
          "passingCount",
          "inReviewCount",
          "inProgressCount",
          "failingCount",
          "needChangesCount",
          "notStartedCount"
        ]
      },
      "FrameworkDesignation": {
        "description": "Assessment level/type of a tenant's framework. SOC 2 frameworks use SOC2_TYPE_*, HITRUST uses HITRUST_*, all others are UNSET.",
        "enum": [
          "UNSET",
          "SOC2_TYPE_1",
          "SOC2_TYPE_2",
          "HITRUST_E1",
          "HITRUST_I1",
          "HITRUST_R2"
        ],
        "type": "string"
      },
      "FrameworkNotes": {
        "properties": {
          "frameworkId": {
            "description": "The framework the note is associated with",
            "type": "string"
          },
          "note": {
            "description": "Implementation details for this framework",
            "type": "string"
          }
        },
        "type": "object"
      },
      "FrameworkRequirementStats": {
        "properties": {
          "count": {
            "description": "The total number of requirements",
            "type": "integer"
          },
          "metCount": {
            "description": "The number of requirements that have been met",
            "type": "integer"
          }
        },
        "required": [
          "count",
          "metCount"
        ]
      },
      "FrameworkStats": {
        "properties": {
          "controlStatuses": {
            "description": "Every control in the framework with its computed status, ordered by\ntitle. Derived by the same status computation as `controls`, so the\nstatus grid always agrees with the counts.\n",
            "items": {
              "$ref": "#/components/schemas/DashboardControlStatus"
            },
            "type": "array"
          },
          "controls": {
            "$ref": "#/components/schemas/FrameworkControlStats"
          },
          "id": {
            "description": "The ID of the framework",
            "type": "string"
          },
          "name": {
            "description": "The name of the framework",
            "type": "string"
          },
          "requirements": {
            "$ref": "#/components/schemas/FrameworkRequirementStats"
          },
          "tenantFramework": {
            "$ref": "#/components/schemas/DashboardFramework"
          }
        },
        "required": [
          "id",
          "name",
          "controls",
          "controlStatuses"
        ]
      },
      "GetCodeSecurityScanInfoBody": {
        "properties": {
          "repositoryIds": {
            "description": "List of repository ids. If omitted, scan info for all of the tenant's repositories is returned.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array",
            "uniqueItems": true
          }
        },
        "x-mcp-fields": true
      },
      "GetControlsByTenantComplianceRequirementsRequest": {
        "properties": {
          "requirementIds": {
            "description": "The tenant compliance requirement IDs to fetch controls for.",
            "items": {
              "description": "A tenant compliance requirement ID.",
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "maxItems": 200,
            "minItems": 1,
            "type": "array",
            "uniqueItems": true
          }
        },
        "required": [
          "requirementIds"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "GetDependencyScanInfoBody": {
        "properties": {
          "repositoryIds": {
            "description": "List of repository ids. If omitted, scan info for all of the tenant's repositories is returned.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array",
            "uniqueItems": true
          }
        },
        "x-mcp-fields": true
      },
      "GetPrEvidenceRequest": {
        "description": "Trigger asynchronous collection of code review evidence (merged GitHub\npull requests and/or GitLab merge requests) for a date range. The server\nenqueues one Hatchet task per configured provider and returns immediately;\neach resulting CSV evidence row is attached to the supplied control once\nthe corresponding task finishes.\n",
        "properties": {
          "connectionId": {
            "description": "Optional connection to restrict collection to. When set, only the\nprovider that owns this connection runs. Defaults to running every\nprovider that has at least one connection for the tenant.\n",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "from": {
            "description": "Inclusive lower bound on `merged_at`.",
            "format": "date-time",
            "type": "string"
          },
          "repos": {
            "description": "Optional list of \"owner/name\" (GitHub) or \"namespace/path\" (GitLab)\nrepository identifiers to include. Case-insensitive. Applied to\nwhichever providers run. Defaults to every repo visible to each\nconnection.\n",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "to": {
            "description": "Exclusive upper bound on `merged_at`. Must be after `from`, and the window must be at most one year.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "from",
          "to"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "GetPrEvidenceResponse": {
        "description": "Acknowledgement that one or more collection tasks have been enqueued. A\ntenant configured for both GitHub and GitLab will receive two tasks.\n",
        "properties": {
          "status": {
            "description": "Indicates that the tasks have been enqueued.",
            "enum": [
              "QUEUED"
            ],
            "type": "string"
          },
          "tasks": {
            "description": "One entry per provider that was dispatched.",
            "items": {
              "$ref": "#/components/schemas/CodeReviewEvidenceTask"
            },
            "type": "array"
          }
        },
        "required": [
          "status",
          "tasks"
        ],
        "type": "object"
      },
      "GitHubSecurityAdvisory": {
        "properties": {
          "description": {
            "description": "Full description of the advisory from the GitHub Advisory Database.",
            "nullable": true,
            "type": "string"
          },
          "ghsaId": {
            "description": "GitHub Security Advisory identifier.",
            "type": "string"
          },
          "references": {
            "description": "URLs to related advisories, issues, and commits.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "vulnerabilities": {
            "description": "Affected packages with version ranges and patched versions.",
            "items": {
              "$ref": "#/components/schemas/GitHubSecurityAdvisoryVulnerability"
            },
            "type": "array"
          }
        },
        "required": [
          "ghsaId"
        ],
        "type": "object"
      },
      "GitHubSecurityAdvisoryBatchRequest": {
        "properties": {
          "ghsaIds": {
            "description": "List of GHSA IDs to fetch advisories for.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "ghsaIds"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "GitHubSecurityAdvisoryBatchResponse": {
        "additionalProperties": {
          "$ref": "#/components/schemas/GitHubSecurityAdvisory"
        },
        "description": "Map from GHSA ID to advisory data. Missing entries indicate the advisory could not be fetched.",
        "type": "object"
      },
      "GitHubSecurityAdvisoryVulnerability": {
        "properties": {
          "firstPatchedVersion": {
            "description": "First version with a fix, e.g. \"5.2.4.3\".",
            "nullable": true,
            "type": "string"
          },
          "packageEcosystem": {
            "nullable": true,
            "type": "string"
          },
          "packageName": {
            "nullable": true,
            "type": "string"
          },
          "vulnerableVersionRange": {
            "description": "Version range affected, e.g. \"\u003e= 5.0.0, \u003c= 5.2.4.2\".",
            "nullable": true,
            "type": "string"
          }
        },
        "type": "object"
      },
      "Group": {
        "properties": {
          "createdAt": {
            "description": "The time the evidence was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the group.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the group.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "members": {
            "items": {
              "$ref": "#/components/schemas/GroupMember"
            },
            "type": "array"
          },
          "name": {
            "description": "The name of the group.",
            "type": "string"
          },
          "policies": {
            "items": {
              "$ref": "#/components/schemas/Policy"
            },
            "type": "array"
          },
          "tenantId": {
            "description": "The id of the tenant this group belongs to",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the evidence was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "members",
          "policies",
          "tenantId"
        ],
        "type": "object"
      },
      "GroupMember": {
        "description": "A lightweight tenant member representation for group membership lists.",
        "properties": {
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          }
        },
        "required": [
          "id",
          "name",
          "status"
        ],
        "type": "object"
      },
      "GroupShort": {
        "description": "A lightweight group representation with display-relevant fields only.",
        "properties": {
          "id": {
            "description": "The ID of the group.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the group.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant this group belongs to",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "tenantId"
        ],
        "type": "object"
      },
      "ImpactedPeriod": {
        "properties": {
          "alertingSince": {
            "description": "Original alerting time (for context)",
            "format": "date-time",
            "type": "string"
          },
          "endedAt": {
            "description": "When this specific status period ended (null if still ongoing)",
            "format": "date-time",
            "type": "string"
          },
          "reasons": {
            "description": "Reasons for this period",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "startedAt": {
            "description": "When this specific status period started",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          }
        },
        "required": [
          "status",
          "startedAt",
          "slaType",
          "alertingSince",
          "reasons"
        ],
        "type": "object"
      },
      "InAppDocument": {
        "properties": {
          "createdAt": {
            "description": "The time that this document was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "A description for the document.",
            "type": "string"
          },
          "editorJSBody": {
            "$ref": "#/components/schemas/DocumentEditorObject"
          },
          "id": {
            "description": "The id of the document.",
            "type": "string"
          },
          "template": {
            "$ref": "#/components/schemas/InAppDocumentTemplate"
          },
          "templateId": {
            "description": "The id of the template for the document.",
            "type": "string"
          },
          "tenantId": {
            "description": "The id of the tenant that owns the document.",
            "type": "string"
          },
          "title": {
            "description": "The title of the document.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this document was updated.",
            "format": "date-time",
            "type": "string"
          },
          "usedByEvidenceIds": {
            "description": "The evidence ids that use this document as control attachments.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "description",
          "editorJSBody",
          "user",
          "tenantId"
        ],
        "type": "object"
      },
      "InAppDocumentTemplate": {
        "properties": {
          "description": {
            "description": "A description for the document template.",
            "type": "string"
          },
          "editorJSBody": {
            "$ref": "#/components/schemas/DocumentEditorObject"
          },
          "id": {
            "description": "The id of the document template.",
            "type": "string"
          },
          "title": {
            "description": "The title of the document template.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "editorJSBody"
        ],
        "type": "object"
      },
      "InAppDocumentTemplateMeta": {
        "properties": {
          "description": {
            "description": "A description for the document template.",
            "type": "string"
          },
          "id": {
            "description": "The id of the document template.",
            "type": "string"
          },
          "title": {
            "description": "The title of the document template.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description"
        ],
        "type": "object"
      },
      "Integration": {
        "properties": {
          "configuration": {
            "description": "The additional configuration of the integration.",
            "type": "object"
          },
          "connections": {
            "description": "The connections for this integration.",
            "items": {
              "$ref": "#/components/schemas/Connection"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this integration was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the integration.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "integrationType": {
            "$ref": "#/components/schemas/IntegrationType"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "monitorCount": {
            "description": "The number of monitors for this integration.",
            "type": "integer"
          },
          "owner": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "ownerId": {
            "description": "The ID of the tenant member accountable for this integration.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "provider": {
            "$ref": "#/components/schemas/NangoProvider"
          },
          "statusUpdates": {
            "description": "Indicates which types of status messages are currently active for this integration.",
            "properties": {
              "degradation": {
                "description": "Whether there are any service degradation messages.",
                "type": "boolean"
              },
              "disruption": {
                "description": "Whether there are any service disruption messages.",
                "type": "boolean"
              },
              "permissionsUpdate": {
                "description": "Whether there are any permissions update messages.",
                "type": "boolean",
                "x-go-name": "PermissionsUpdate"
              }
            },
            "required": [
              "disruption",
              "degradation",
              "permissionsUpdate"
            ],
            "type": "object"
          },
          "tenantId": {
            "description": "The ID of the tenant that this integration belongs to.",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this integration was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "tenantId",
          "integrationTypeId"
        ],
        "type": "object"
      },
      "IntegrationCategory": {
        "enum": [
          "INTERNAL",
          "ADMINISTRATION",
          "CLOUD_PROVIDER",
          "VERSION_CONTROL",
          "OBSERVABILITY",
          "MOBILE_DEVICE_MANAGEMENT",
          "VULNERABILITY_MANAGEMENT",
          "VPN",
          "SECRETS_MANAGEMENT",
          "COMMUNICATION",
          "PROJECT_MANAGEMENT",
          "FINANCIAL",
          "HUMAN_RESOURCES",
          "SPEND_MANAGEMENT",
          "AI_MODELS",
          "IDENTITY_PROVIDER",
          "CUSTOM"
        ],
        "type": "string"
      },
      "IntegrationHasApplicableMonitorsResponse": {
        "properties": {
          "hasApplicableMonitors": {
            "description": "Whether any of the integration's monitor types apply to the tenant's current compliance frameworks",
            "type": "boolean"
          }
        },
        "required": [
          "hasApplicableMonitors"
        ],
        "type": "object"
      },
      "IntegrationList": {
        "properties": {
          "isPartial": {
            "description": "Whether the response may be incomplete due to service degradation.",
            "type": "boolean"
          },
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Integration"
            },
            "type": "array"
          }
        },
        "required": [
          "isPartial"
        ]
      },
      "IntegrationStatusUpdate": {
        "properties": {
          "createdAt": {
            "description": "The time that this status update was created",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the status update",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "links": {
            "description": "Optional external links related to the status update",
            "items": {
              "$ref": "#/components/schemas/IntegrationStatusUpdateLink"
            },
            "type": "array"
          },
          "message": {
            "description": "The update content",
            "type": "string"
          },
          "resolutionNote": {
            "description": "An optional note explaining the resolution of the status update",
            "type": "string"
          },
          "resolvedAt": {
            "description": "The time that this status update was resolved",
            "format": "date-time",
            "type": "string"
          },
          "title": {
            "description": "The title of the status update",
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/IntegrationStatusUpdateType"
          }
        },
        "required": [
          "id",
          "createdAt",
          "type",
          "message"
        ],
        "type": "object"
      },
      "IntegrationStatusUpdateLink": {
        "properties": {
          "label": {
            "description": "The label for the link",
            "type": "string"
          },
          "url": {
            "description": "The URL for the link",
            "type": "string"
          }
        },
        "required": [
          "label",
          "url"
        ],
        "type": "object"
      },
      "IntegrationStatusUpdateList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/IntegrationStatusUpdate"
            },
            "type": "array",
            "x-go-type": "[]IntegrationStatusUpdate"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "IntegrationStatusUpdateType": {
        "enum": [
          "disruption",
          "degradation",
          "permissions-update"
        ],
        "type": "string"
      },
      "IntegrationType": {
        "properties": {
          "category": {
            "$ref": "#/components/schemas/IntegrationCategory"
          },
          "createdAt": {
            "description": "The time that this integration type was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the integration type.",
            "type": "string"
          },
          "formTag": {
            "description": "Form tag to choose the form to be rendered on the frontend",
            "type": "string"
          },
          "icon": {
            "description": "Icon to be rendered on the frontend",
            "type": "string"
          },
          "id": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "inspectorType": {
            "enum": [
              "GRAPHQL",
              "REST",
              "UNSUPPORTED"
            ],
            "type": "string"
          },
          "integrations": {
            "description": "The integrations for this integration type.",
            "items": {
              "$ref": "#/components/schemas/Integration"
            },
            "type": "array"
          },
          "isInTestingPhase": {
            "description": "Whether or not the integration type is in testing phase, and accessible by \"integration-tester\" flag.",
            "type": "boolean"
          },
          "isMarkedAsBeta": {
            "description": "Whether or not the integration type has a \"Beta\" label on the frontend.",
            "type": "boolean"
          },
          "isOneleetManaged": {
            "description": "Whether or not the integration type is managed by Oneleet.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the integration type.",
            "type": "string"
          },
          "requiresOAuth": {
            "description": "Whether or not the integration type requires OAuth.",
            "type": "boolean"
          },
          "supportsAutofixes": {
            "description": "Whether or not the integration type supports Oneleet autofixes.",
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this integration type was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "worksWithCodeSecurity": {
            "description": "Whether or not the integration type can be used with the Code Security module.",
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "description",
          "requiresOAuth",
          "inspectorType",
          "isOneleetManaged",
          "isInTestingPhase",
          "isMarkedAsBeta",
          "worksWithCodeSecurity",
          "supportsAutofixes",
          "formTag",
          "icon"
        ],
        "type": "object"
      },
      "IntegrationTypeList": {
        "properties": {
          "isPartial": {
            "description": "Whether the response may be incomplete due to service degradation.",
            "type": "boolean"
          },
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/IntegrationType"
            },
            "type": "array"
          }
        },
        "required": [
          "isPartial"
        ]
      },
      "JourneyAuditControl": {
        "properties": {
          "evidenceRequests": {
            "items": {
              "$ref": "#/components/schemas/JourneyAuditEvidenceRequest"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "title": {
            "description": "Effective control title (custom override falling back to ControlType title).",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "title",
          "evidenceRequests"
        ],
        "type": "object"
      },
      "JourneyAuditEvidenceRequest": {
        "properties": {
          "activeAt": {
            "description": "If set and in the future, the request is upcoming — evidence isn't\nexpected yet. If null or in the past, the request is live.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "hasEvidence": {
            "description": "Whether the tenant has attached anything yet. Combined with status,\nthis is what tells the client who owes the next move: a live request\nis still the tenant's if it has no evidence or was rejected\n(NEEDS_CHANGES), and is with the auditor otherwise. Status alone\ncan't answer that — IN_REVIEW is inherited from the owning control,\nso an untouched request reports IN_REVIEW once its control is in\nreview.\n",
            "type": "boolean"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/EvidenceRequestStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "status",
          "hasEvidence"
        ],
        "type": "object"
      },
      "JourneyAuditProgress": {
        "properties": {
          "controls": {
            "description": "Controls in the framework that have at least one open (non-APPROVED)\nevidence request. Sorted by the control's updatedAt descending. Each\ncontrol's evidence requests are sorted with active-now requests first\n(by updatedAt desc) and upcoming requests (activeAt \u003e now) after,\nsorted by activeAt ascending. Frontend can distinguish upcoming\nrequests by checking activeAt against the current time.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyAuditControl"
            },
            "type": "array"
          },
          "type": {
            "enum": [
              "AUDIT"
            ],
            "type": "string"
          }
        },
        "required": [
          "type",
          "controls"
        ],
        "type": "object"
      },
      "JourneyInternalAuditProgress": {
        "properties": {
          "type": {
            "enum": [
              "INTERNAL_AUDIT"
            ],
            "type": "string"
          }
        },
        "required": [
          "type"
        ],
        "type": "object"
      },
      "JourneyObservationAction": {
        "properties": {
          "assignedTo": {
            "description": "Display name of the responsible tenant member, if any.",
            "type": "string"
          },
          "dueAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The id of the underlying domain object (e.g. access review id), used\nby the frontend to route to the action's detail page.\n",
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/JourneyObservationActionKind"
          },
          "status": {
            "description": "The source-specific status of the underlying domain object, opaque\nto the frontend's rendering (e.g. \"PLANNED\" or \"IN_PROGRESS\" for\nACCESS_REVIEW).\n",
            "type": "string"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "kind",
          "id",
          "title",
          "status"
        ],
        "type": "object"
      },
      "JourneyObservationActionKind": {
        "description": "Discriminator on JourneyObservationAction. The frontend switches on this\nvalue to pick the destination route and the visual treatment for the\naction row.\n",
        "enum": [
          "ACCESS_REVIEW"
        ],
        "type": "string"
      },
      "JourneyObservationPeriodProgress": {
        "properties": {
          "alertingMonitors": {
            "description": "Monitors that need attention, ordered by severity: BREACHING_SLA\nfirst, then ALERTING by soonest projected breach, then by\nlongest-alerting. Capped server-side.\n",
            "items": {
              "$ref": "#/components/schemas/Monitor"
            },
            "type": "array"
          },
          "controls": {
            "description": "Controls in the program's framework with at least one open\n(non-APPROVED) evidence request — the same rollup the AUDIT stage\nrenders. The bulk evidence-request flow schedules requests with an\nactiveAt inside the observation window, so this includes both\nrequests that are live now and ones that go live later in the\nperiod; the client separates them by activeAt.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyAuditControl"
            },
            "type": "array"
          },
          "endAt": {
            "description": "End of the tenant's current observation window, sourced from the\nactive audit. Omitted when the audit hasn't had its observation\nperiod dates configured yet.\n",
            "format": "date-time",
            "type": "string"
          },
          "startAt": {
            "description": "Start of the tenant's current observation window, sourced from the\nactive audit. Omitted when the audit hasn't had its observation\nperiod dates configured yet.\n",
            "format": "date-time",
            "type": "string"
          },
          "type": {
            "enum": [
              "OBSERVATION_PERIOD"
            ],
            "type": "string"
          },
          "upcomingActions": {
            "description": "Periodic compliance actions the tenant still needs to complete\nduring the observation period (access reviews today; more kinds in\nthe future). Ordered by due date ascending. Capped server-side.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyObservationAction"
            },
            "type": "array"
          }
        },
        "required": [
          "type",
          "alertingMonitors",
          "upcomingActions",
          "controls"
        ],
        "type": "object"
      },
      "JourneyPreparationChapter": {
        "properties": {
          "badge": {
            "type": "string"
          },
          "completedCount": {
            "type": "integer"
          },
          "description": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "steps": {
            "items": {
              "$ref": "#/components/schemas/JourneyPreparationStep"
            },
            "type": "array"
          },
          "title": {
            "type": "string"
          },
          "totalCount": {
            "type": "integer"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "badge",
          "steps",
          "completedCount",
          "totalCount"
        ],
        "type": "object"
      },
      "JourneyPreparationProgress": {
        "properties": {
          "chapters": {
            "items": {
              "$ref": "#/components/schemas/JourneyPreparationChapter"
            },
            "type": "array"
          },
          "type": {
            "enum": [
              "PREPARATION"
            ],
            "type": "string"
          }
        },
        "required": [
          "type",
          "chapters"
        ],
        "type": "object"
      },
      "JourneyPreparationStep": {
        "properties": {
          "description": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/JourneyStepStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "description",
          "status"
        ],
        "type": "object"
      },
      "JourneyProgram": {
        "description": "One selectable entry in the journey switcher — a compliance program the\ntenant has a journey for.\n",
        "properties": {
          "createdAt": {
            "description": "When the program's audit was created, which is also what orders AUDIT\nprograms (newest first). The switcher shows its year so repeated audits\nof the same type (e.g. one SOC 2 Type 2 per year) can be told apart.\nAbsent for FRAMEWORK programs, which have no audit.\n",
            "format": "date-time",
            "type": "string"
          },
          "currentStage": {
            "$ref": "#/components/schemas/JourneyStage"
          },
          "framework": {
            "description": "Compliance framework type ID of this program (e.g. \"soc2_v2\",\n\"iso27001_v1\").\n",
            "type": "string"
          },
          "id": {
            "description": "The value to pass back to the journey endpoint to view this program: an\nauditId when kind is AUDIT, a frameworkId (TenantComplianceFramework id)\nwhen kind is FRAMEWORK.\n",
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/JourneyProgramKind"
          },
          "label": {
            "description": "Human-readable program name — the audit type name (e.g. \"SOC 2 Type 2\")\nfor AUDIT, or the framework name (e.g. \"HIPAA\") for FRAMEWORK.\n",
            "type": "string"
          }
        },
        "required": [
          "kind",
          "id",
          "label",
          "framework",
          "currentStage"
        ],
        "type": "object"
      },
      "JourneyProgramKind": {
        "description": "How a journey program is selected: AUDIT programs are selected by an audit\nid, FRAMEWORK programs by a TenantComplianceFramework id.\n",
        "enum": [
          "AUDIT",
          "FRAMEWORK"
        ],
        "type": "string"
      },
      "JourneyReportReadyProgress": {
        "properties": {
          "auditId": {
            "description": "ID of the audit whose report is ready.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "auditTypeName": {
            "description": "Display name of the audit type (e.g. \"SOC 2 Type II\"). Used to label\nthe audit when adding it as a trust-page document.\n",
            "type": "string"
          },
          "reportFileName": {
            "description": "Original filename of the uploaded report, when available.",
            "type": "string"
          },
          "reportUrl": {
            "description": "Direct download URL for the audit report PDF. Absent if the audit has\nno report attached yet — frontend should disable the download action\nin that case.\n",
            "type": "string"
          },
          "type": {
            "enum": [
              "REPORT_READY"
            ],
            "type": "string"
          }
        },
        "required": [
          "type",
          "auditId",
          "auditTypeName"
        ],
        "type": "object"
      },
      "JourneyResponse": {
        "properties": {
          "currentStage": {
            "$ref": "#/components/schemas/JourneyStage"
          },
          "framework": {
            "description": "Compliance framework type ID of the active audit's framework — either\n\"soc2_v1\" or \"soc2_v2\".\n",
            "type": "string"
          },
          "progress": {
            "description": "Stage-specific payload. Discriminated union keyed on `type` —\nalways equal to the wrapper's `currentStage`. Frontend code should\nswitch on `progress.type` for compile-time exhaustive narrowing.\n",
            "discriminator": {
              "mapping": {
                "AUDIT": "#/components/schemas/JourneyAuditProgress",
                "INTERNAL_AUDIT": "#/components/schemas/JourneyInternalAuditProgress",
                "OBSERVATION_PERIOD": "#/components/schemas/JourneyObservationPeriodProgress",
                "PREPARATION": "#/components/schemas/JourneyPreparationProgress",
                "REPORT_READY": "#/components/schemas/JourneyReportReadyProgress",
                "STAGE_1_AUDIT": "#/components/schemas/JourneyStage1AuditProgress",
                "STAGE_2_AUDIT": "#/components/schemas/JourneyStage2AuditProgress"
              },
              "propertyName": "type"
            },
            "oneOf": [
              {
                "$ref": "#/components/schemas/JourneyPreparationProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyInternalAuditProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyObservationPeriodProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyStage1AuditProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyStage2AuditProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyAuditProgress"
              },
              {
                "$ref": "#/components/schemas/JourneyReportReadyProgress"
              }
            ]
          },
          "stages": {
            "description": "The full ordered list of stages for this program, used to render the\njourney stepper. Derived from the audit type's stages for audit-backed\nprograms. The frontend renders the tracker from this rather than\nhardcoding a per-framework stage order, so new programs (e.g. HIPAA,\nGDPR) are a backend-only change.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyStage"
            },
            "type": "array"
          },
          "tenantComplianceFrameworkId": {
            "description": "ID of the active audit's TenantComplianceFramework — the tenant's own\ninstance of `framework`. Used to scope per-framework lookups (such as\nthe controls rollup behind the \"remaining controls\" step) to this\naudit's framework rather than the whole tenant. May be an empty string\nif the audit has no TenantComplianceFramework.\n",
            "type": "string"
          }
        },
        "required": [
          "framework",
          "tenantComplianceFrameworkId",
          "currentStage",
          "stages",
          "progress"
        ],
        "type": "object"
      },
      "JourneyStage": {
        "description": "A stage a compliance journey can render, in audit-type order. Audit-backed\nprograms (SOC 2, ISO 27001) derive their ordered stage list from the audit\ntype's stages, so the frontend renders the stepper from `stages` rather than\nhardcoding a per-framework order. Framework-driven programs without an audit\n(HIPAA) currently render a single PREPARATION stage. The backend normalizes\nany stage it doesn't yet render to PREPARATION before returning `currentStage`.\n",
        "enum": [
          "PREPARATION",
          "INTERNAL_AUDIT",
          "OBSERVATION_PERIOD",
          "STAGE_1_AUDIT",
          "STAGE_2_AUDIT",
          "AUDIT",
          "REPORT_READY"
        ],
        "type": "string"
      },
      "JourneyStage1AuditProgress": {
        "description": "Stage 1 audit payload (ISO 27001). Combines the auditor's outstanding\nevidence requests (grouped by control, exactly like the AUDIT stage) with\nthe tenant's alerting monitors (exactly like the observation period). Both\nsections are scoped to the audit's framework.\n",
        "properties": {
          "alertingMonitors": {
            "description": "Monitors that need attention, ordered by severity: BREACHING_SLA first,\nthen ALERTING by soonest projected breach. Same shape as the observation\nperiod's alertingMonitors. Capped server-side.\n",
            "items": {
              "$ref": "#/components/schemas/Monitor"
            },
            "type": "array"
          },
          "controls": {
            "description": "Controls in the audit's framework that have at least one open\n(non-APPROVED) evidence request. Same shape and ordering as the AUDIT\nstage's controls.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyAuditControl"
            },
            "type": "array"
          },
          "type": {
            "enum": [
              "STAGE_1_AUDIT"
            ],
            "type": "string"
          }
        },
        "required": [
          "type",
          "controls",
          "alertingMonitors"
        ],
        "type": "object"
      },
      "JourneyStage2AuditProgress": {
        "description": "Stage 2 audit payload (ISO 27001). Identical in shape to the Stage 1 audit —\nthe auditor's outstanding evidence requests plus the tenant's alerting\nmonitors, both scoped to the audit's framework — since the client actions are\nthe same. Only what the auditor reviews differs: the implementation and\noperation of the ISMS, vs Stage 1's design and documentation review.\n",
        "properties": {
          "alertingMonitors": {
            "description": "Monitors that need attention, ordered by severity: BREACHING_SLA first,\nthen ALERTING by soonest projected breach. Same shape as the observation\nperiod's alertingMonitors. Capped server-side.\n",
            "items": {
              "$ref": "#/components/schemas/Monitor"
            },
            "type": "array"
          },
          "controls": {
            "description": "Controls in the audit's framework that have at least one open\n(non-APPROVED) evidence request. Same shape and ordering as the AUDIT\nstage's controls.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyAuditControl"
            },
            "type": "array"
          },
          "type": {
            "enum": [
              "STAGE_2_AUDIT"
            ],
            "type": "string"
          }
        },
        "required": [
          "type",
          "controls",
          "alertingMonitors"
        ],
        "type": "object"
      },
      "JourneyStepStatus": {
        "description": "Most steps cycle through NOT_STARTED → IN_PROGRESS → COMPLETE based on a\nprogrammatic signal. INFORMATIONAL is reserved for steps the system can\nsurface but can't programmatically verify (the user has to act in a\nplace we can't observe); the frontend should render these without a\nstatus indicator and exclude them from chapter progress totals.\n",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "COMPLETE",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "JourneySummary": {
        "description": "The dashboard's condensed view of one journey program: the program's\nidentity and stage position plus a small stage-appropriate teaser payload.\nAt most one of preparation / observation / audit / report is present — the\none matching currentStage (INTERNAL_AUDIT has no payload). Deliberately\nflat optional objects rather than a discriminated union: the dashboard\nrenders every program side by side and reads these with optional chaining.\n",
        "properties": {
          "audit": {
            "$ref": "#/components/schemas/JourneySummaryAudit"
          },
          "currentStage": {
            "$ref": "#/components/schemas/JourneyStage"
          },
          "framework": {
            "description": "Compliance framework type ID of this program (e.g. \"soc2_v2\",\n\"iso27001_v1\"), for icon lookup and matching against the tenant's\ncompliance frameworks.\n",
            "type": "string"
          },
          "id": {
            "description": "The value to pass to the journey endpoint/page to open this program:\nan auditId when kind is AUDIT, a frameworkId\n(TenantComplianceFramework id) when kind is FRAMEWORK.\n",
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/JourneyProgramKind"
          },
          "label": {
            "description": "Human-readable program name — the audit type name (e.g. \"SOC 2 Type 2\")\nfor AUDIT, or the framework name (e.g. \"HIPAA\") for FRAMEWORK.\n",
            "type": "string"
          },
          "observation": {
            "$ref": "#/components/schemas/JourneySummaryObservation"
          },
          "preparation": {
            "$ref": "#/components/schemas/JourneySummaryPreparation"
          },
          "report": {
            "$ref": "#/components/schemas/JourneySummaryReport"
          },
          "stages": {
            "description": "The full ordered stage list for this program, for rendering a compact\nstage tracker. Same derivation as JourneyResponse.stages.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyStage"
            },
            "type": "array"
          },
          "tenantComplianceFrameworkId": {
            "description": "ID of the program's TenantComplianceFramework, for framework-scoped\nactions (e.g. the auditor evidence export). Absent when an audit-backed\nprogram has no TenantComplianceFramework. For FRAMEWORK programs this\nequals `id`.\n",
            "type": "string"
          }
        },
        "required": [
          "kind",
          "id",
          "label",
          "framework",
          "currentStage",
          "stages"
        ],
        "type": "object"
      },
      "JourneySummaryAudit": {
        "description": "Condensed auditor-facing stage (AUDIT, STAGE_1_AUDIT, STAGE_2_AUDIT):\nhow much still needs attention while the auditor is engaged.\n",
        "properties": {
          "alertingMonitorCount": {
            "description": "Total monitors currently BREACHING_SLA or ALERTING. Present for the\nISO stages (STAGE_1_AUDIT, STAGE_2_AUDIT), which surface monitors on\nthe journey page; absent for SOC 2's AUDIT stage, which doesn't.\n",
            "type": "integer"
          },
          "openControlCount": {
            "description": "Number of controls in the program's framework with at least one open\n(non-APPROVED) evidence request.\n",
            "type": "integer"
          }
        },
        "required": [
          "openControlCount"
        ],
        "type": "object"
      },
      "JourneySummaryObservation": {
        "description": "Condensed observation period: the window dates, how many monitors\ncurrently need attention, the next periodic actions coming due, and how\nmuch auditor-requested evidence is outstanding.\n",
        "properties": {
          "actionableEvidenceRequestCount": {
            "description": "Evidence requests that are live now (activeAt absent or in the past)\nAND still owed by the tenant. Excludes requests scheduled for later\nin the observation window, so the card doesn't nag about work that\nisn't due yet, and ones already submitted to the auditor, which\naren't the tenant's to act on.\n",
            "type": "integer"
          },
          "alertingMonitorCount": {
            "description": "Total monitors currently BREACHING_SLA or ALERTING — the same\npredicate as the journey page's alerting list, but uncapped.\n",
            "type": "integer"
          },
          "endAt": {
            "description": "Omitted when the observation window isn't configured yet.",
            "format": "date-time",
            "type": "string"
          },
          "startAt": {
            "description": "Omitted when the observation window isn't configured yet.",
            "format": "date-time",
            "type": "string"
          },
          "upcomingActionCount": {
            "description": "Total upcoming actions before the teaser cap, so the dashboard can\nsay \"and N more\".\n",
            "type": "integer"
          },
          "upcomingActions": {
            "description": "The next periodic compliance actions coming due, ordered by due date\nascending. Capped server-side to a small teaser.\n",
            "items": {
              "$ref": "#/components/schemas/JourneyObservationAction"
            },
            "type": "array"
          }
        },
        "required": [
          "alertingMonitorCount",
          "upcomingActionCount",
          "upcomingActions",
          "actionableEvidenceRequestCount"
        ],
        "type": "object"
      },
      "JourneySummaryPreparation": {
        "description": "Condensed preparation checklist: the overall step tally (informational\nsteps excluded, matching the journey page's chapter totals), the furthest\ncompleted step, and the next few incomplete steps in playbook order. Steps\nhave no persisted completion timestamp, so \"latest completed\" means the\nfurthest step in the playbook sequence, not most recent in wall-clock time.\n",
        "properties": {
          "completedStepCount": {
            "type": "integer"
          },
          "latestCompletedStep": {
            "$ref": "#/components/schemas/JourneySummaryStep"
          },
          "nextSteps": {
            "description": "The next incomplete (NOT_STARTED or IN_PROGRESS) steps in playbook\norder. Capped server-side to a small teaser; the journey page has the\nfull checklist.\n",
            "items": {
              "$ref": "#/components/schemas/JourneySummaryStep"
            },
            "type": "array"
          },
          "totalStepCount": {
            "type": "integer"
          }
        },
        "required": [
          "completedStepCount",
          "totalStepCount",
          "nextSteps"
        ],
        "type": "object"
      },
      "JourneySummaryReport": {
        "description": "Condensed REPORT_READY payload: what the dashboard needs to offer report\ndownload for a completed program.\n",
        "properties": {
          "auditId": {
            "description": "ID of the audit whose report is ready.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "auditTypeName": {
            "description": "Display name of the audit type (e.g. \"SOC 2 Type II\").",
            "type": "string"
          },
          "reportFileName": {
            "description": "Original filename of the uploaded report, when available.",
            "type": "string"
          },
          "reportUrl": {
            "description": "Direct download URL for the audit report PDF. Absent if the audit has\nno report attached yet.\n",
            "type": "string"
          }
        },
        "required": [
          "auditId",
          "auditTypeName"
        ],
        "type": "object"
      },
      "JourneySummaryStep": {
        "description": "A preparation step teaser, carrying its chapter so the dashboard can label\nit and deep-link the journey page to the right place.\n",
        "properties": {
          "chapterId": {
            "type": "string"
          },
          "chapterTitle": {
            "type": "string"
          },
          "id": {
            "description": "Stable step ID, the same value as JourneyPreparationStep.id.",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/JourneyStepStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "status",
          "chapterId",
          "chapterTitle"
        ],
        "type": "object"
      },
      "LinkEvidenceRequest": {
        "properties": {
          "controlId": {
            "description": "The id of the control to link to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "evidenceRequestId": {
            "description": "The id of the evidence request to link to, if applicable.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "scopeItemId": {
            "description": "The id of the control scope item to link to, if applicable.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "controlId"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "LinkRiskControl": {
        "properties": {
          "controlId": {
            "description": "The ID of the control to link to the risk.",
            "format": "uuid",
            "type": "string"
          },
          "link": {
            "description": "True if the control is linked to the risk, false if it is unlinked.",
            "type": "boolean"
          }
        },
        "required": [
          "controlId",
          "link"
        ]
      },
      "MCPConnectContinuation": {
        "properties": {
          "redirectUrl": {
            "type": "string"
          }
        },
        "required": [
          "redirectUrl"
        ],
        "type": "object"
      },
      "MCPConnectContinuationRequest": {
        "properties": {
          "sessionToken": {
            "type": "string"
          },
          "state": {
            "type": "string"
          },
          "tenantId": {
            "type": "string"
          }
        },
        "required": [
          "sessionToken",
          "state"
        ],
        "type": "object"
      },
      "MCPConnectPickerSession": {
        "properties": {
          "clientName": {
            "type": "string"
          },
          "email": {
            "type": "string"
          },
          "preselectedTenantId": {
            "type": "string"
          },
          "tenants": {
            "items": {
              "$ref": "#/components/schemas/MCPConnectTenant"
            },
            "type": "array"
          },
          "unavailableReason": {
            "description": "Set when `tenants` is empty. `no_memberships` means the user isn't a member of any workspace. `mcp_oauth_disabled` means none of the user's workspaces have MCP OAuth enabled.",
            "enum": [
              "no_memberships",
              "mcp_oauth_disabled"
            ],
            "type": "string"
          }
        },
        "required": [
          "clientName",
          "email",
          "tenants"
        ],
        "type": "object"
      },
      "MCPConnectPickerSessionRequest": {
        "properties": {
          "sessionToken": {
            "type": "string"
          }
        },
        "required": [
          "sessionToken"
        ],
        "type": "object"
      },
      "MCPConnectTenant": {
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "MarkAccessReviewVendorAsReviewedRequest": {
        "properties": {
          "file": {
            "description": "Optional evidence file to attach to the vendor review.",
            "format": "binary",
            "type": "string"
          },
          "note": {
            "description": "Optional note attached to the vendor review.",
            "type": "string"
          }
        },
        "type": "object"
      },
      "MemberChecklist": {
        "properties": {
          "checklistTemplateId": {
            "description": "The ID of the checklist template this checklist was created from.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "createdAt": {
            "description": "When this checklist was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the checklist.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "items": {
            "items": {
              "$ref": "#/components/schemas/MemberChecklistItem"
            },
            "type": "array"
          },
          "type": {
            "$ref": "#/components/schemas/ChecklistType"
          },
          "updatedAt": {
            "description": "When this checklist was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "createdAt",
          "updatedAt",
          "checklistTemplateId",
          "items"
        ]
      },
      "MemberChecklistItem": {
        "properties": {
          "completedAt": {
            "description": "When this checklist item was marked completed. Null unless the item is currently completed.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "createdAt": {
            "description": "When this checklist item was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the checklist item.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the checklist item.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "label": {
            "description": "The label of the checklist item.",
            "type": "string"
          },
          "link": {
            "description": "The link associated with the checklist item.",
            "type": "string"
          },
          "memberChecklistId": {
            "description": "The ID of the checklist this item belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ChecklistItemStatus"
          },
          "updatedAt": {
            "description": "When this checklist item was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "label",
          "status",
          "memberChecklistId",
          "link",
          "description"
        ]
      },
      "MemberChecklists": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/MemberChecklist"
            },
            "type": "array"
          }
        }
      },
      "Monitor": {
        "properties": {
          "alertingSince": {
            "description": "The time this monitor started alerting, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "breachesSlaAt": {
            "description": "The time this monitor will breach SLA, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "configuration": {
            "type": "object"
          },
          "controlSummaries": {
            "items": {
              "$ref": "#/components/schemas/ControlSummary"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "currentState": {
            "$ref": "#/components/schemas/MonitorState"
          },
          "disabledReason": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isEnabled": {
            "description": "Whether the monitor is enabled. Default is true.",
            "type": "boolean"
          },
          "latestRun": {
            "$ref": "#/components/schemas/MonitorRun"
          },
          "monitorType": {
            "$ref": "#/components/schemas/MonitorType"
          },
          "results": {
            "items": {
              "$ref": "#/components/schemas/MonitorAssetResult"
            },
            "type": "array"
          },
          "reviewRemindAt": {
            "description": "The time at which to re-review the monitor and potentially re-enable it.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedAt": {
            "description": "The date and time when the monitor was snoozed, if the monitor is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the monitor, if the monitor is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for snoozing the monitor, if the monitor is snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the monitor snooze period ends, if the monitor is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "stats": {
            "$ref": "#/components/schemas/MonitorStats"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStatus"
          },
          "statusChangedAt": {
            "description": "The time that this monitor's status last changed, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "tenantId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "isEnabled",
          "monitorType",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "MonitorAssetResult": {
        "properties": {
          "alertingSince": {
            "description": "The time that this monitor asset result started alerting, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "asset": {
            "$ref": "#/components/schemas/Asset"
          },
          "assetId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "breachesSlaAt": {
            "description": "The time that this monitor asset result will breach SLA, if applicable.",
            "format": "date-time",
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this monitor result was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastRunAt": {
            "description": "The time that this monitor asset result was last run.",
            "format": "date-time",
            "type": "string"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "snoozedAt": {
            "description": "The date and time when the asset was snoozed, if the asset is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the asset, if the asset is snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason for snoozing the asset, if the asset is snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the asset snooze period ends, if the asset is snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          },
          "statusChangedAt": {
            "description": "The time that this monitor asset result's status last changed.",
            "format": "date-time",
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "monitorId",
          "assetId",
          "status",
          "reasons",
          "slaType",
          "statusChangedAt",
          "lastRunAt",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "MonitorAssetResultConnection": {
        "description": "A connection that at least one of the monitor's asset results belongs to.",
        "properties": {
          "count": {
            "description": "Number of the connection's asset results that match the status and search filters.",
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "readableId": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "readableId",
          "count"
        ],
        "type": "object"
      },
      "MonitorAssetResultList": {
        "properties": {
          "connections": {
            "description": "Every connection the monitor's asset results belong to, whatever the filters. A connection with no results matching the status and search filters has a count of 0.",
            "items": {
              "$ref": "#/components/schemas/MonitorAssetResultConnection"
            },
            "type": "array"
          },
          "matchingStatusCounts": {
            "allOf": [
              {
                "$ref": "#/components/schemas/MonitorAssetResultStatusCounts"
              }
            ],
            "description": "Counts of the results that match the connection and search filters. The status filter isn't applied."
          },
          "pagination": {
            "$ref": "#/components/schemas/MonitorAssetResultPagination"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/MonitorAssetResultListItem"
            },
            "type": "array"
          },
          "statusCounts": {
            "allOf": [
              {
                "$ref": "#/components/schemas/MonitorAssetResultStatusCounts"
              }
            ],
            "description": "Counts across the whole monitor, independent of any list filters."
          }
        },
        "required": [
          "rows",
          "pagination",
          "statusCounts",
          "matchingStatusCounts",
          "connections"
        ],
        "type": "object"
      },
      "MonitorAssetResultListItem": {
        "description": "One MonitorAssetResult row joined with its asset and connection, as served by the paginated monitor asset results list.",
        "properties": {
          "alertingSince": {
            "description": "When this asset started alerting; absent if not alerting.",
            "format": "date-time",
            "type": "string"
          },
          "assetId": {
            "format": "uuid",
            "type": "string"
          },
          "assetInstanceId": {
            "description": "The tenant-unique instance ID of the asset.",
            "type": "string"
          },
          "assetName": {
            "type": "string"
          },
          "breachesSlaAt": {
            "description": "When this asset breaches (or breached) its SLA; absent if no SLA applies.",
            "format": "date-time",
            "type": "string"
          },
          "connectionId": {
            "format": "uuid",
            "type": "string"
          },
          "connectionReadableId": {
            "description": "The human-readable ID of the connection the asset belongs to.",
            "type": "string"
          },
          "globalSnooze": {
            "$ref": "#/components/schemas/MonitorCoveredAssetSnooze"
          },
          "id": {
            "description": "The ID of the monitor asset result.",
            "format": "uuid",
            "type": "string"
          },
          "linkUrl": {
            "description": "Page with more detail on this asset, e.g. the alert in the source system or the finding in Oneleet.",
            "format": "uri",
            "type": "string"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaType": {
            "$ref": "#/components/schemas/SlaType"
          },
          "snooze": {
            "$ref": "#/components/schemas/MonitorCoveredAssetSnooze"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorAssetResultStatus"
          },
          "statusChangedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "assetId",
          "assetInstanceId",
          "assetName",
          "connectionId",
          "connectionReadableId",
          "status",
          "reasons",
          "slaType",
          "statusChangedAt"
        ],
        "type": "object"
      },
      "MonitorAssetResultPagination": {
        "properties": {
          "limit": {
            "type": "integer"
          },
          "page": {
            "type": "integer"
          },
          "total": {
            "description": "Total number of rows matching the current filters.",
            "type": "integer"
          },
          "totalPages": {
            "type": "integer"
          }
        },
        "required": [
          "page",
          "limit",
          "total",
          "totalPages"
        ],
        "type": "object"
      },
      "MonitorAssetResultStatus": {
        "description": "The status of a monitor asset result.",
        "enum": [
          "BREACHING_SLA",
          "ALERTING",
          "PASSING",
          "IGNORED",
          "SNOOZED"
        ],
        "type": "string"
      },
      "MonitorAssetResultStatusCounts": {
        "description": "Number of the monitor's asset results per status.",
        "properties": {
          "alerting": {
            "type": "integer"
          },
          "breachingSla": {
            "type": "integer"
          },
          "ignored": {
            "type": "integer"
          },
          "passing": {
            "type": "integer"
          },
          "snoozed": {
            "type": "integer"
          }
        },
        "required": [
          "breachingSla",
          "alerting",
          "passing",
          "ignored",
          "snoozed"
        ],
        "type": "object"
      },
      "MonitorAssetStats": {
        "properties": {
          "count": {
            "description": "The total number of assets detected by this monitor.",
            "type": "integer"
          },
          "failingCount": {
            "description": "The number of assets failing this monitor.",
            "type": "integer"
          },
          "passingCount": {
            "description": "The number of assets passing this monitor.",
            "type": "integer"
          },
          "percentPassing": {
            "description": "The percentage of assets passing this monitor.",
            "type": "integer"
          }
        },
        "required": [
          "count",
          "passingCount",
          "failingCount",
          "percentPassing"
        ],
        "type": "object"
      },
      "MonitorCoveredAssetSnooze": {
        "description": "Snooze metadata for a covered asset; present only when the asset is currently snoozed.",
        "properties": {
          "at": {
            "format": "date-time",
            "type": "string"
          },
          "byMemberName": {
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "until": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "until",
          "reason",
          "at"
        ],
        "type": "object"
      },
      "MonitorList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Monitor"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "MonitorRun": {
        "properties": {
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorRunStatus"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "status",
          "monitorId"
        ]
      },
      "MonitorRunList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/MonitorRun"
            },
            "type": "array"
          }
        }
      },
      "MonitorRunStatus": {
        "description": "The status of a monitor run.",
        "enum": [
          "RUNNING",
          "SUCCEEDED",
          "FAILED",
          "INTERNAL_ERROR",
          "PERMISSIONS_ERROR",
          "TIMED_OUT",
          "CANCELED"
        ],
        "type": "string"
      },
      "MonitorSnooze": {
        "properties": {
          "reason": {
            "description": "The reason for snoozing the monitor",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the snooze period ends",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "snoozedUntil",
          "reason"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "MonitorSnoozeAssets": {
        "properties": {
          "assetIds": {
            "description": "List of asset IDs to snooze",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "reason": {
            "description": "The reason for snoozing the assets",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The date and time when the snooze period ends",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "assetIds",
          "snoozedUntil",
          "reason"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "MonitorState": {
        "properties": {
          "createdAt": {
            "description": "The time that this monitor state was created.",
            "format": "date-time",
            "type": "string"
          },
          "finishedAt": {
            "description": "The time that this monitor state finished.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "impactedAssets": {
            "description": "Assets that were impacted during this monitor state period",
            "items": {
              "$ref": "#/components/schemas/MonitorStateImpactedAsset"
            },
            "type": "array"
          },
          "monitorId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "reason": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/MonitorStateStatus"
          },
          "updatedAt": {
            "description": "The time that this monitor state was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "status",
          "monitorId",
          "reason"
        ]
      },
      "MonitorStateImpactedAsset": {
        "properties": {
          "assetId": {
            "description": "The ID of the asset",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "assetInstanceId": {
            "description": "The stable instance ID of the asset",
            "type": "string"
          },
          "assetName": {
            "description": "The name of the asset",
            "type": "string"
          },
          "connectionId": {
            "description": "The ID of the connection",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connectionLabel": {
            "description": "The label of the connection",
            "type": "string"
          },
          "connectionReadableId": {
            "description": "The human-readable connection identifier",
            "type": "string"
          },
          "impactedPeriods": {
            "description": "Time periods when this asset was impacted",
            "items": {
              "$ref": "#/components/schemas/ImpactedPeriod"
            },
            "type": "array"
          }
        },
        "required": [
          "assetId",
          "assetInstanceId",
          "assetName",
          "connectionId",
          "connectionReadableId",
          "impactedPeriods"
        ],
        "type": "object"
      },
      "MonitorStateList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/MonitorState"
            },
            "type": "array"
          }
        }
      },
      "MonitorStateStatus": {
        "description": "The status of a monitor.",
        "enum": [
          "INACTIVE",
          "PASSING",
          "ALERTING",
          "BREACHING_SLA",
          "SNOOZED"
        ],
        "type": "string"
      },
      "MonitorStats": {
        "properties": {
          "assets": {
            "$ref": "#/components/schemas/MonitorAssetStats"
          }
        },
        "required": [
          "assets"
        ],
        "type": "object"
      },
      "MonitorStatus": {
        "description": "The status of a monitor.",
        "enum": [
          "BREACHING_SLA",
          "ALERTING",
          "PASSING",
          "NO_APPLICABLE_ASSETS",
          "NOT_YET_RUN",
          "IGNORED",
          "SNOOZED",
          "DISABLED"
        ],
        "type": "string"
      },
      "MonitorType": {
        "properties": {
          "assetType": {
            "$ref": "#/components/schemas/AssetType"
          },
          "assetTypeId": {
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this monitor was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "maxLength": 100,
            "type": "string"
          },
          "isPassingByDefault": {
            "description": "Whether this monitor always passes because the provider guarantees the property; it cannot be configured and never alerts.",
            "type": "boolean"
          },
          "name": {
            "type": "string"
          },
          "rerunDisabled": {
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this monitor was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "createdAt",
          "updatedAt",
          "assetTypeId",
          "rerunDisabled",
          "isPassingByDefault"
        ],
        "type": "object"
      },
      "MonitorUnsnoozeAssets": {
        "properties": {
          "assetIds": {
            "description": "List of asset IDs to unsnooze",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "assetIds"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "MonitorUpdateEnabled": {
        "properties": {
          "disabledReason": {
            "type": "string"
          },
          "enabled": {
            "type": "boolean"
          },
          "reviewRemindAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "enabled"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "MonitorUpdateIgnoreStatusForAssets": {
        "properties": {
          "assetsToIgnore": {
            "description": "List of assetInstanceId",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "assetsToUnignore": {
            "description": "List of assetInstanceId",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "reasonToIgnore": {
            "type": "string"
          }
        },
        "required": [
          "assetsToIgnore",
          "reasonToIgnore",
          "assetsToUnignore"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "NangoProvider": {
        "description": "The provider we get from Nango for this specific integration. It's used to render the form for the integration.",
        "properties": {
          "authMode": {
            "description": "The auth mode for this provider.",
            "enum": [
              "API_KEY",
              "APP",
              "APP_STORE",
              "BASIC",
              "NONE",
              "OAUTH1",
              "OAUTH2",
              "OAUTH2_CC",
              "CUSTOM",
              "TBA",
              "TABLEAU",
              "JWT",
              "BILL",
              "TWO_STEP",
              "SIGNATURE"
            ],
            "type": "string"
          },
          "authType": {
            "description": "The authentication type for this provider.",
            "type": "string"
          },
          "connectionConfig": {
            "additionalProperties": {
              "$ref": "#/components/schemas/NangoProviderConnectionConfigField"
            },
            "type": "object"
          },
          "credentials": {
            "additionalProperties": {
              "$ref": "#/components/schemas/NangoProviderConnectionConfigField"
            },
            "type": "object"
          },
          "docs": {
            "description": "Documentation URL for this provider.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the provider.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "NangoProviderConnectionConfigField": {
        "description": "The connection config for the provider.",
        "properties": {
          "automated": {
            "description": "Whether this field is automatically handled by the system.",
            "type": "boolean"
          },
          "description": {
            "description": "Description of what this configuration field is for.",
            "type": "string"
          },
          "docSection": {
            "description": "Reference to a section in the documentation for this field.",
            "pattern": "^#[a-z0-9-]+$",
            "type": "string"
          },
          "example": {
            "description": "Example value for the configuration field.",
            "type": "string"
          },
          "format": {
            "description": "Format hint for the configuration field.",
            "enum": [
              "hostname",
              "uri",
              "uuid",
              "email"
            ],
            "type": "string"
          },
          "name": {
            "description": "The name of the configuration field.",
            "type": "string"
          },
          "optional": {
            "description": "Whether this field is optional.",
            "type": "boolean"
          },
          "order": {
            "description": "The order in which this field should appear in the form.",
            "type": "integer"
          },
          "pattern": {
            "description": "Regex pattern for validating the configuration field.",
            "type": "string"
          },
          "prefix": {
            "description": "Prefix text to display before the field value.",
            "type": "string"
          },
          "secret": {
            "description": "Whether this field contains secret information (like a password or API key).",
            "type": "boolean"
          },
          "suffix": {
            "description": "Suffix text to display after the field value.",
            "type": "string"
          },
          "title": {
            "description": "The human-readable title of the configuration field.",
            "type": "string"
          },
          "type": {
            "description": "The type of the configuration field.",
            "enum": [
              "string"
            ],
            "type": "string"
          }
        },
        "required": [
          "name",
          "type",
          "title",
          "description"
        ],
        "type": "object"
      },
      "NgAttackSurfaceAssetInfo": {
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/AttackSurfaceAssetType"
          }
        },
        "required": [
          "id",
          "name",
          "type"
        ],
        "type": "object"
      },
      "NgAttackSurfaceFinding": {
        "properties": {
          "affectedUrl": {
            "nullable": true,
            "type": "string"
          },
          "asset": {
            "$ref": "#/components/schemas/NgAttackSurfaceAssetInfo"
          },
          "detectedAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "issueId": {
            "format": "uuid",
            "type": "string"
          },
          "issueTitle": {
            "type": "string"
          },
          "lastSeenAt": {
            "format": "date-time",
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/NgAttackSurfaceOwner"
          },
          "resolution": {
            "$ref": "#/components/schemas/NgAttackSurfaceFindingResolution"
          },
          "resolutionDescription": {
            "nullable": true,
            "type": "string"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedBy": {
            "$ref": "#/components/schemas/NgAttackSurfaceOwner"
          },
          "service": {
            "$ref": "#/components/schemas/NgAttackSurfaceServiceInfo"
          },
          "severity": {
            "$ref": "#/components/schemas/NgAttackSurfaceSeverity"
          },
          "status": {
            "$ref": "#/components/schemas/NgAttackSurfaceIssueStatus"
          }
        },
        "required": [
          "id",
          "issueId",
          "issueTitle",
          "severity",
          "status",
          "detectedAt",
          "lastSeenAt"
        ],
        "type": "object"
      },
      "NgAttackSurfaceFindingDetail": {
        "allOf": [
          {
            "$ref": "#/components/schemas/NgAttackSurfaceFinding"
          },
          {
            "properties": {
              "evidence": {
                "$ref": "#/components/schemas/NgAttackSurfaceFindingEvidence"
              },
              "issue": {
                "$ref": "#/components/schemas/NgAttackSurfaceIssueDetail"
              },
              "remediationNote": {
                "nullable": true,
                "type": "string"
              }
            },
            "type": "object"
          }
        ]
      },
      "NgAttackSurfaceFindingEvidence": {
        "properties": {
          "curlCommand": {
            "type": "string"
          },
          "extractedResults": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "matcherName": {
            "type": "string"
          },
          "request": {
            "type": "string"
          },
          "response": {
            "type": "string"
          }
        },
        "type": "object"
      },
      "NgAttackSurfaceFindingListResult": {
        "properties": {
          "facets": {
            "properties": {
              "severity": {
                "additionalProperties": {
                  "type": "integer"
                },
                "type": "object"
              },
              "status": {
                "additionalProperties": {
                  "type": "integer"
                },
                "type": "object"
              }
            },
            "type": "object"
          },
          "findings": {
            "items": {
              "$ref": "#/components/schemas/NgAttackSurfaceFinding"
            },
            "type": "array"
          },
          "pagination": {
            "$ref": "#/components/schemas/NgAttackSurfacePagination"
          }
        },
        "required": [
          "findings",
          "pagination",
          "facets"
        ],
        "type": "object"
      },
      "NgAttackSurfaceFindingResolution": {
        "enum": [
          "FIXED",
          "FALSE_POSITIVE",
          "ACCEPTED_RISK",
          "MITIGATED",
          "NOT_APPLICABLE"
        ],
        "type": "string"
      },
      "NgAttackSurfaceIssue": {
        "properties": {
          "affectedUrl": {
            "nullable": true,
            "type": "string"
          },
          "asset": {
            "$ref": "#/components/schemas/NgAttackSurfaceAssetInfo"
          },
          "cveId": {
            "nullable": true,
            "type": "string"
          },
          "cvssScore": {
            "nullable": true,
            "type": "number"
          },
          "cvssVector": {
            "nullable": true,
            "type": "string"
          },
          "cweId": {
            "nullable": true,
            "type": "string"
          },
          "description": {
            "nullable": true,
            "type": "string"
          },
          "detectedAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "lastSeenAt": {
            "format": "date-time",
            "type": "string"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "service": {
            "$ref": "#/components/schemas/NgAttackSurfaceServiceInfo"
          },
          "severity": {
            "$ref": "#/components/schemas/NgAttackSurfaceSeverity"
          },
          "status": {
            "$ref": "#/components/schemas/NgAttackSurfaceIssueStatus"
          },
          "templateId": {
            "nullable": true,
            "type": "string"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "severity",
          "status",
          "detectedAt",
          "lastSeenAt"
        ],
        "type": "object"
      },
      "NgAttackSurfaceIssueCounts": {
        "properties": {
          "critical": {
            "type": "integer"
          },
          "high": {
            "type": "integer"
          },
          "info": {
            "type": "integer"
          },
          "low": {
            "type": "integer"
          },
          "medium": {
            "type": "integer"
          }
        },
        "required": [
          "critical",
          "high",
          "medium",
          "low",
          "info"
        ],
        "type": "object"
      },
      "NgAttackSurfaceIssueDetail": {
        "allOf": [
          {
            "$ref": "#/components/schemas/NgAttackSurfaceIssue"
          },
          {
            "properties": {
              "evidence": {
                "nullable": true,
                "properties": {
                  "request": {
                    "type": "string"
                  },
                  "response": {
                    "type": "string"
                  },
                  "screenshot": {
                    "type": "string"
                  }
                },
                "type": "object"
              },
              "remediation": {
                "nullable": true,
                "type": "string"
              },
              "remediationNote": {
                "nullable": true,
                "type": "string"
              },
              "template": {
                "nullable": true,
                "properties": {
                  "description": {
                    "type": "string"
                  },
                  "id": {
                    "type": "string"
                  },
                  "knownExploit": {
                    "type": "boolean"
                  },
                  "references": {
                    "items": {
                      "type": "string"
                    },
                    "type": "array"
                  },
                  "remediation": {
                    "nullable": true,
                    "type": "string"
                  },
                  "title": {
                    "type": "string"
                  }
                },
                "type": "object"
              }
            },
            "type": "object"
          }
        ]
      },
      "NgAttackSurfaceIssueListResult": {
        "properties": {
          "facets": {
            "properties": {
              "severity": {
                "additionalProperties": {
                  "type": "integer"
                },
                "type": "object"
              },
              "status": {
                "additionalProperties": {
                  "type": "integer"
                },
                "type": "object"
              }
            },
            "type": "object"
          },
          "groups": {
            "items": {
              "properties": {
                "count": {
                  "type": "integer"
                },
                "cveId": {
                  "nullable": true,
                  "type": "string"
                },
                "cvssScore": {
                  "nullable": true,
                  "type": "number"
                },
                "issues": {
                  "items": {
                    "$ref": "#/components/schemas/NgAttackSurfaceIssue"
                  },
                  "type": "array"
                },
                "severity": {
                  "$ref": "#/components/schemas/NgAttackSurfaceSeverity"
                },
                "templateId": {
                  "type": "string"
                },
                "title": {
                  "type": "string"
                }
              },
              "type": "object"
            },
            "nullable": true,
            "type": "array"
          },
          "issues": {
            "items": {
              "$ref": "#/components/schemas/NgAttackSurfaceIssue"
            },
            "type": "array"
          },
          "pagination": {
            "$ref": "#/components/schemas/NgAttackSurfacePagination"
          }
        },
        "required": [
          "issues",
          "pagination",
          "facets"
        ],
        "type": "object"
      },
      "NgAttackSurfaceIssueStatus": {
        "enum": [
          "OPEN",
          "IN_PROGRESS",
          "RESOLVED",
          "ACCEPTED_RISK",
          "FALSE_POSITIVE"
        ],
        "type": "string"
      },
      "NgAttackSurfaceOwner": {
        "properties": {
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "NgAttackSurfacePagination": {
        "properties": {
          "limit": {
            "type": "integer"
          },
          "page": {
            "type": "integer"
          },
          "total": {
            "type": "integer"
          },
          "totalPages": {
            "type": "integer"
          }
        },
        "required": [
          "page",
          "limit",
          "total",
          "totalPages"
        ],
        "type": "object"
      },
      "NgAttackSurfaceScan": {
        "properties": {
          "completedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "criticalIssuesFound": {
            "type": "integer"
          },
          "durationMinutes": {
            "nullable": true,
            "type": "integer"
          },
          "errorMessage": {
            "nullable": true,
            "type": "string"
          },
          "highIssuesFound": {
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "lowIssuesFound": {
            "type": "integer"
          },
          "mediumIssuesFound": {
            "type": "integer"
          },
          "name": {
            "nullable": true,
            "type": "string"
          },
          "startedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/NgAttackSurfaceScanStatus"
          },
          "targetDomains": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "totalAssetsFound": {
            "type": "integer"
          },
          "totalFindingsFound": {
            "type": "integer"
          },
          "totalIssuesFound": {
            "type": "integer"
          },
          "totalServicesAffected": {
            "description": "Services with findings (vuln) or history events (discovery) for this scan",
            "type": "integer"
          },
          "totalServicesFound": {
            "type": "integer"
          },
          "type": {
            "$ref": "#/components/schemas/NgAttackSurfaceScanType"
          }
        },
        "required": [
          "id",
          "type",
          "status",
          "targetDomains",
          "totalAssetsFound",
          "totalServicesFound",
          "totalServicesAffected",
          "totalFindingsFound",
          "totalIssuesFound",
          "criticalIssuesFound",
          "highIssuesFound",
          "mediumIssuesFound",
          "lowIssuesFound"
        ],
        "type": "object"
      },
      "NgAttackSurfaceScanDetail": {
        "allOf": [
          {
            "$ref": "#/components/schemas/NgAttackSurfaceScan"
          },
          {
            "properties": {
              "affectedServicesCount": {
                "type": "integer"
              },
              "domainsScanned": {
                "type": "integer"
              },
              "issuesBySeverity": {
                "$ref": "#/components/schemas/NgAttackSurfaceIssueCounts"
              },
              "newAssetsCount": {
                "type": "integer"
              },
              "servicesFound": {
                "type": "integer"
              },
              "templatesUsed": {
                "nullable": true,
                "type": "integer"
              }
            },
            "required": [
              "issuesBySeverity",
              "newAssetsCount",
              "affectedServicesCount",
              "domainsScanned",
              "servicesFound"
            ],
            "type": "object"
          }
        ]
      },
      "NgAttackSurfaceScanListResult": {
        "properties": {
          "groups": {
            "items": {
              "properties": {
                "count": {
                  "type": "integer"
                },
                "displayName": {
                  "type": "string"
                },
                "month": {
                  "type": "string"
                },
                "scans": {
                  "items": {
                    "$ref": "#/components/schemas/NgAttackSurfaceScan"
                  },
                  "type": "array"
                }
              },
              "type": "object"
            },
            "nullable": true,
            "type": "array"
          },
          "nextScheduled": {
            "properties": {
              "discovery": {
                "format": "date-time",
                "nullable": true,
                "type": "string"
              },
              "vulnerability": {
                "format": "date-time",
                "nullable": true,
                "type": "string"
              }
            },
            "type": "object"
          },
          "pagination": {
            "$ref": "#/components/schemas/NgAttackSurfacePagination"
          },
          "scans": {
            "items": {
              "$ref": "#/components/schemas/NgAttackSurfaceScan"
            },
            "type": "array"
          }
        },
        "required": [
          "scans",
          "pagination",
          "nextScheduled"
        ],
        "type": "object"
      },
      "NgAttackSurfaceScanStatus": {
        "enum": [
          "PENDING",
          "RUNNING",
          "COMPLETED",
          "FAILED"
        ],
        "type": "string"
      },
      "NgAttackSurfaceScanType": {
        "enum": [
          "DISCOVERY",
          "VULNERABILITY",
          "VULNERABILITY_RETEST",
          "FULL"
        ],
        "type": "string"
      },
      "NgAttackSurfaceServiceInfo": {
        "properties": {
          "faviconUrl": {
            "nullable": true,
            "type": "string"
          },
          "hostname": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "port": {
            "type": "integer"
          }
        },
        "required": [
          "id",
          "hostname",
          "port"
        ],
        "type": "object"
      },
      "NgAttackSurfaceSeverity": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFORMATIONAL"
        ],
        "type": "string"
      },
      "NotificationChannel": {
        "description": "Delivery channel for a notification. EMAIL is the only channel honored\nby the dispatcher today; SLACK is declared in the schema for future\nrouting without an enum migration.\n",
        "enum": [
          "EMAIL",
          "SLACK"
        ],
        "type": "string"
      },
      "NotificationDefaultEntry": {
        "description": "One notification's catalog metadata plus its per-role default values for the tenant.",
        "properties": {
          "byRole": {
            "additionalProperties": {
              "$ref": "#/components/schemas/NotificationDefaultValue"
            },
            "description": "Per-role values, keyed by TenantRole. Always contains keys for the\nadmin-visible roles (ADMIN, MEMBER, AUDITOR, EMPLOYEE).\n",
            "type": "object"
          },
          "category": {
            "description": "The category this notification belongs to",
            "example": "Monitoring",
            "type": "string"
          },
          "description": {
            "description": "Description of what this notification is for",
            "type": "string"
          },
          "displayName": {
            "description": "Human-readable name for the notification",
            "example": "Monitor Alerts",
            "type": "string"
          },
          "notificationName": {
            "description": "The name of the notification (example \"monitor_alerting\")",
            "example": "monitor_alerting",
            "type": "string"
          },
          "respectsPreference": {
            "description": "When false, the dispatcher does not consult NotificationPreference\nor TenantNotificationDefault at send time for this notification\n(invite flows pre-membership, security alerts delivered regardless\nof preference). Admins can still set defaults, but they have no\neffect today; the UI surfaces an info badge for these entries.\n",
            "type": "boolean"
          }
        },
        "required": [
          "notificationName",
          "displayName",
          "description",
          "category",
          "respectsPreference",
          "byRole"
        ],
        "type": "object"
      },
      "NotificationDefaultValue": {
        "properties": {
          "channels": {
            "description": "Resolved channel mix for this (tenant, role, notification). Today\nevery entry is [EMAIL]; the storage shape accommodates [EMAIL, SLACK]\nonce the dispatcher honors channels.\n",
            "items": {
              "$ref": "#/components/schemas/NotificationChannel"
            },
            "type": "array"
          },
          "hasOverride": {
            "description": "True when a TenantNotificationDefault row exists for this\n(tenant, role, notification). Used by the admin UI to distinguish\n\"explicitly set\" from \"inherits catalog default\".\n",
            "type": "boolean"
          },
          "isEnabled": {
            "description": "Resolved default value for this (tenant, role, notification). If\nhasOverride is true, this reflects the stored tenant override;\notherwise it reflects the hardcoded catalog default.\n",
            "type": "boolean"
          }
        },
        "required": [
          "isEnabled",
          "hasOverride",
          "channels"
        ],
        "type": "object"
      },
      "OneleetRole": {
        "enum": [
          "SUPERADMIN",
          "ADMIN",
          "CLIENT",
          "PENTESTER",
          "PENTESTER_ADMIN",
          "CUSTOMER_EXPERIENCE",
          "AUDITOR"
        ],
        "type": "string"
      },
      "PackageFindingInvestigation": {
        "properties": {
          "createdAt": {
            "description": "When the investigation was created.",
            "format": "date-time",
            "type": "string"
          },
          "currentMemberFeedback": {
            "$ref": "#/components/schemas/PackageFindingInvestigationFeedback"
          },
          "exploitabilityConclusion": {
            "$ref": "#/components/schemas/PackageFindingInvestigationExploitabilityConclusion"
          },
          "exploitabilityRationale": {
            "description": "Reason for the exploitability conclusion, as described by the agent that assigned it.",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "remediationStrategies": {
            "items": {
              "$ref": "#/components/schemas/PackageFindingInvestigationRemediationStrategy"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "createdAt",
          "exploitabilityConclusion",
          "exploitabilityRationale",
          "remediationStrategies"
        ]
      },
      "PackageFindingInvestigationExploitabilityConclusion": {
        "enum": [
          "EXPLOITABLE",
          "NOT_EXPLOITABLE",
          "INCONCLUSIVE"
        ],
        "type": "string"
      },
      "PackageFindingInvestigationFeedback": {
        "properties": {
          "badReason": {
            "$ref": "#/components/schemas/PackageFindingInvestigationFeedbackBadReason"
          },
          "rating": {
            "$ref": "#/components/schemas/PackageFindingInvestigationFeedbackRating"
          }
        },
        "required": [
          "rating"
        ]
      },
      "PackageFindingInvestigationFeedbackBadReason": {
        "enum": [
          "INCORRECT_CONCLUSION",
          "INCORRECT_DESCRIPTION_OR_REASONING",
          "INCOMPLETE_DESCRIPTION_OR_REASONING"
        ],
        "type": "string"
      },
      "PackageFindingInvestigationFeedbackRating": {
        "enum": [
          "GOOD",
          "BAD"
        ],
        "type": "string"
      },
      "PackageFindingInvestigationRemediationStrategy": {
        "properties": {
          "currentMemberFeedback": {
            "$ref": "#/components/schemas/PackageFindingInvestigationRemediationStrategyFeedback"
          },
          "id": {
            "description": "Unique identifier for the remediation strategy.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "instructions": {
            "description": "Brief instructions describing how to remediate the vulnerability.",
            "type": "string"
          },
          "preference": {
            "$ref": "#/components/schemas/PackageFindingRemediationStrategyPreference"
          },
          "rationale": {
            "description": "Why the remediation strategy would work, as described by the agent that recommended it.",
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/PackageFindingRemediationStrategyType"
          }
        },
        "required": [
          "id",
          "type",
          "preference",
          "instructions",
          "rationale"
        ]
      },
      "PackageFindingInvestigationRemediationStrategyFeedback": {
        "properties": {
          "badReason": {
            "$ref": "#/components/schemas/PackageFindingInvestigationRemediationStrategyFeedbackBadReason"
          },
          "rating": {
            "$ref": "#/components/schemas/PackageFindingInvestigationRemediationStrategyFeedbackRating"
          }
        },
        "required": [
          "rating"
        ]
      },
      "PackageFindingInvestigationRemediationStrategyFeedbackBadReason": {
        "enum": [
          "INCORRECT_REMEDIATION_STRATEGY",
          "INCORRECT_DESCRIPTION_OR_REASONING",
          "INCOMPLETE_DESCRIPTION_OR_REASONING"
        ],
        "type": "string"
      },
      "PackageFindingInvestigationRemediationStrategyFeedbackRating": {
        "enum": [
          "GOOD",
          "BAD"
        ],
        "type": "string"
      },
      "PackageFindingRemediationStrategyPreference": {
        "enum": [
          "REASONABLE",
          "RECOMMENDED"
        ],
        "type": "string"
      },
      "PackageFindingRemediationStrategyType": {
        "enum": [
          "UPDATE_DEPENDENCY",
          "REMOVE_DEPENDENCY",
          "MITIGATE",
          "ACCEPT_RISK"
        ],
        "type": "string"
      },
      "PackageFindingResolution": {
        "enum": [
          "CONFIRMED_NOT_EXPLOITABLE",
          "UPDATED_DEPENDENCY",
          "REMOVED_DEPENDENCY",
          "ACCEPTED_RISK",
          "MITIGATED"
        ],
        "type": "string"
      },
      "PaginationResponse": {
        "example": {
          "current_page": 2,
          "next_page": 3,
          "num_pages": 10
        },
        "properties": {
          "current_page": {
            "description": "the current page",
            "example": 2,
            "format": "int64",
            "type": "integer",
            "x-go-name": "CurrentPage"
          },
          "next_page": {
            "description": "the next page",
            "example": 3,
            "format": "int64",
            "type": "integer",
            "x-go-name": "NextPage"
          },
          "num_pages": {
            "description": "the total number of pages for listing",
            "example": 10,
            "format": "int64",
            "type": "integer",
            "x-go-name": "NumPages"
          }
        },
        "required": [
          "current_page",
          "num_pages",
          "next_page"
        ],
        "type": "object"
      },
      "PeopleStats": {
        "properties": {
          "compliantCount": {
            "description": "The number of people that are compliant",
            "type": "integer"
          },
          "count": {
            "description": "The total number of people",
            "type": "integer"
          },
          "nonCompliantCount": {
            "description": "The number of people that are not compliant",
            "type": "integer"
          }
        },
        "required": [
          "compliantCount",
          "nonCompliantCount",
          "count"
        ]
      },
      "Policy": {
        "properties": {
          "aiReviewAcknowledgedAt": {
            "description": "When the tenant saw the most recent run's terminal outcome — by viewing a successful run's comments or dismissing a failed run's callout. Null while the outcome hasn't been seen; cleared when a new run starts.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewCompletedAt": {
            "description": "The time the most recent AI policy review run finished, whether it succeeded or failed. Null while it's in progress.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewNotes": {
            "description": "The most recent run's working notes: what it checked the draft against, what it considered raising and didn't, and why nothing was raised when that's the case. Null until the run succeeds.",
            "nullable": true,
            "type": "string"
          },
          "aiReviewStartedAt": {
            "description": "The time the most recent AI policy review run started.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiReviewStatus": {
            "$ref": "#/components/schemas/AiPolicyReviewStatus"
          },
          "aiReviewVersionId": {
            "description": "The policy version the most recent run read. Null when that version was since deleted (e.g. a discarded draft).",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "aiReviewWorkflowRunId": {
            "description": "The Hatchet workflow run ID of the most recent AI policy review run.",
            "nullable": true,
            "type": "string"
          },
          "audience": {
            "$ref": "#/components/schemas/PolicyAudience"
          },
          "createdAt": {
            "description": "The time that this policy was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/User"
          },
          "currentVersion": {
            "$ref": "#/components/schemas/PolicyVersion"
          },
          "deletedAt": {
            "description": "The time that this policy was deleted. Absent for active policies.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the policy.",
            "type": "string"
          },
          "excludedGroups": {
            "description": "Groups that are excluded from needing to sign this policy",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "groups": {
            "description": "Groups that need to sign this policy, if the audience is GROUPS",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the policy.",
            "type": "string"
          },
          "name": {
            "description": "The name of the policy.",
            "type": "string"
          },
          "openCommentCount": {
            "description": "The number of open comments the policy's Comments tab displays: open comments whose anchors place onto the working draft or, without one, the latest published version. Open comments whose anchored text no longer exists there are excluded. Only set on the list read path.",
            "type": "integer"
          },
          "reviewer": {
            "$ref": "#/components/schemas/User"
          },
          "reviewerGroups": {
            "description": "Groups that are assigned to review changes when PolicyReviewerType is GROUPS.",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "reviewerRole": {
            "$ref": "#/components/schemas/TenantRole"
          },
          "reviewerType": {
            "$ref": "#/components/schemas/PolicyReviewerType"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this policy.",
            "type": "string"
          },
          "types": {
            "description": "The types of the policy.",
            "items": {
              "$ref": "#/components/schemas/PolicyType"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this policy was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "tenantId",
          "audience",
          "currentVersion",
          "createdAt",
          "updatedAt",
          "reviewerType"
        ]
      },
      "PolicyApplicableTenantMember": {
        "description": "A tenant member that needs to sign a policy.",
        "properties": {
          "hasSigned": {
            "description": "Whether or not this tenant member has signed this policy.",
            "type": "boolean"
          },
          "signature": {
            "$ref": "#/components/schemas/PolicySignature"
          },
          "tenantMember": {
            "$ref": "#/components/schemas/TenantMemberShort"
          }
        },
        "required": [
          "tenantMember",
          "hasSigned"
        ]
      },
      "PolicyAudience": {
        "enum": [
          "EVERYONE",
          "EMPLOYEES",
          "CONTRACTORS",
          "GROUPS"
        ],
        "type": "string"
      },
      "PolicyComment": {
        "description": "A durable review comment on a policy. Identity and lifecycle are stored on the policy; placement is computed per version — the anchor fields describe where the comment sits on the version it was read against.",
        "properties": {
          "anchorStatus": {
            "$ref": "#/components/schemas/PolicyCommentAnchorStatus"
          },
          "appliedSourceEnd": {
            "description": "Absolute offset where the applied text ends (exclusive).",
            "type": "integer"
          },
          "appliedSourceStart": {
            "description": "Absolute offset in the read version's markdown where an accepted suggestion's applied text starts. Present on resolved comments whose suggestion was applied on the read version and whose applied text still resolves in its content.",
            "type": "integer"
          },
          "author": {
            "$ref": "#/components/schemas/PolicyCommentAuthor"
          },
          "body": {
            "description": "The comment itself.",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "endBlockId": {
            "description": "The projected anchor's end block. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "string"
          },
          "endOffset": {
            "description": "Offset of the anchored span's end within the end block's text content.",
            "type": "integer"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isAiAuthored": {
            "description": "Whether an AI review run authored the comment.",
            "type": "boolean"
          },
          "isResolved": {
            "type": "boolean"
          },
          "lastHumanActivityAt": {
            "description": "When a human last acted on the comment (resolve, reopen, suggestion decision or edit, note edit). Never cleared; AI runs only touch comments this has never been set on.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "note": {
            "description": "Freeform context on the comment — why it isn't addressed yet, why it was resolved, anything the next reader (human or AI) should know.",
            "nullable": true,
            "type": "string"
          },
          "noteUpdatedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "noteUpdatedByUserId": {
            "description": "The human note author. Exactly one of the two note author fields is set when a note exists.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "noteWasUpdatedByAi": {
            "description": "Whether the note was last written by an AI review run.",
            "type": "boolean"
          },
          "originVersionId": {
            "description": "The policy version whose content the comment was created against. Comments render on that version and later ones, never earlier.",
            "format": "uuid",
            "type": "string"
          },
          "policyId": {
            "format": "uuid",
            "type": "string"
          },
          "quotedText": {
            "description": "The verbatim span of policy text the comment is about; never rewritten.",
            "type": "string"
          },
          "replies": {
            "description": "The comment's human reply thread, oldest first. Empty on AI-authored comments and for tenants without the review-enhancements rollout.",
            "items": {
              "$ref": "#/components/schemas/PolicyCommentReply"
            },
            "type": "array"
          },
          "resolvedAt": {
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "resolvedByUserId": {
            "description": "The human resolver. Exactly one of the two resolver fields is set on a resolved comment.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "resolvedOnVersionId": {
            "description": "The version whose content the resolution happened against.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "sourceEnd": {
            "description": "Absolute offset of the anchored span's end in the read version's markdown (exclusive). Present when anchorStatus is ANCHORED or MOVED.",
            "type": "integer"
          },
          "sourceStart": {
            "description": "Absolute offset of the anchored span's start in the read version's markdown, computed from the stored block map. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "integer"
          },
          "sources": {
            "description": "Citations grounding the comment in tenant context.",
            "items": {
              "$ref": "#/components/schemas/PolicyCommentSource"
            },
            "type": "array"
          },
          "startBlockId": {
            "description": "The projected anchor's start block in the read version's block map. Present when anchorStatus is ANCHORED or MOVED.",
            "type": "string"
          },
          "startOffset": {
            "description": "Offset of the anchored span's start within the start block's text content.",
            "type": "integer"
          },
          "suggestionContent": {
            "description": "The suggested replacement text. Null for DELETE suggestions and plain comments.",
            "nullable": true,
            "type": "string"
          },
          "suggestionEditedContent": {
            "description": "The reviewer's edit of the suggested content; when present it is what an accept applies.",
            "nullable": true,
            "type": "string"
          },
          "suggestionOperation": {
            "$ref": "#/components/schemas/PolicyCommentSuggestionOperation"
          },
          "suggestionStatus": {
            "$ref": "#/components/schemas/PolicyCommentSuggestionStatus"
          },
          "supersededByCommentId": {
            "description": "Set when a newer comment replaces this one (an AI run re-anchoring an outdated concern).",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "tldr": {
            "description": "One-sentence gist of the body, for compact views. Absent on comments created before the field existed; readers fall back to the body.",
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          },
          "wasResolvedByAi": {
            "description": "Whether an AI review run resolved the comment.",
            "type": "boolean"
          },
          "workflowRunId": {
            "description": "The Hatchet workflow run ID of the AI review run that authored the comment. Matches Policy.aiReviewWorkflowRunId for comments from the most recent run.",
            "nullable": true,
            "type": "string"
          }
        },
        "required": [
          "id",
          "policyId",
          "originVersionId",
          "isAiAuthored",
          "quotedText",
          "body",
          "isResolved",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "PolicyCommentAnchorStatus": {
        "description": "How a comment's anchor places onto the version it was read against. ANCHORED means its block is unchanged; MOVED means the block changed but the quoted text was found uniquely elsewhere; OUTDATED means the quoted text is gone or ambiguous, so the comment cannot be placed.",
        "enum": [
          "ANCHORED",
          "MOVED",
          "OUTDATED"
        ],
        "type": "string"
      },
      "PolicyCommentAuthor": {
        "properties": {
          "id": {
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "type": "object"
      },
      "PolicyCommentReply": {
        "properties": {
          "author": {
            "$ref": "#/components/schemas/PolicyCommentAuthor"
          },
          "body": {
            "type": "string"
          },
          "commentId": {
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "id",
          "commentId",
          "author",
          "body",
          "createdAt"
        ],
        "type": "object"
      },
      "PolicyCommentSource": {
        "description": "A citation grounding a comment in a slice of tenant context.",
        "properties": {
          "excerpt": {
            "description": "Optional verbatim snippet from the source.",
            "nullable": true,
            "type": "string"
          },
          "label": {
            "description": "Human-facing name of the referenced entity.",
            "type": "string"
          },
          "referenceId": {
            "description": "The id of the referenced entity when one exists.",
            "nullable": true,
            "type": "string"
          },
          "type": {
            "description": "Which slice of tenant context the citation references (e.g. CONTROL, COMPANY_PROFILE).",
            "type": "string"
          }
        },
        "required": [
          "type",
          "label"
        ],
        "type": "object"
      },
      "PolicyCommentSuggestionOperation": {
        "description": "The kind of edit a comment's suggestion proposes against the quoted text.",
        "enum": [
          "REPLACE",
          "INSERT",
          "DELETE"
        ],
        "type": "string"
      },
      "PolicyCommentSuggestionStatus": {
        "description": "The suggestion's decision state. UNDECIDED is explicit — a comment without a suggestion has no status at all.",
        "enum": [
          "UNDECIDED",
          "ACCEPTED",
          "REJECTED"
        ],
        "type": "string"
      },
      "PolicyList": {
        "description": "A list of policies.",
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Policy"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "PolicyReviewerType": {
        "enum": [
          "NONE",
          "USER",
          "GROUPS",
          "ROLE"
        ],
        "type": "string"
      },
      "PolicySignature": {
        "description": "A policy signature.",
        "properties": {
          "createdAt": {
            "description": "The time that this policy signature was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the policy signature.",
            "type": "string"
          },
          "policyVersion": {
            "$ref": "#/components/schemas/PolicyVersion"
          },
          "policyVersionId": {
            "description": "The ID of the policy associated with this policy signature.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy signature was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/UserPublic"
          }
        },
        "required": [
          "id",
          "policyVersionId",
          "user",
          "createdAt",
          "updatedAt"
        ]
      },
      "PolicySignatureList": {
        "description": "A list of policy signatures.",
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "PolicyTemplate": {
        "properties": {
          "createdAt": {
            "description": "The time that this policy template was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the policy template.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the policy template.",
            "type": "string"
          },
          "markdown": {
            "description": "The markdown content of the policy template.",
            "type": "string"
          },
          "name": {
            "description": "The name of the policy template.",
            "type": "string"
          },
          "sortOrder": {
            "description": "The sort order of the policy template.",
            "type": "integer"
          },
          "tone": {
            "$ref": "#/components/schemas/PolicyTemplateTone"
          },
          "types": {
            "description": "The types of the policy template.",
            "items": {
              "$ref": "#/components/schemas/PolicyType"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "The time that this policy template was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "tone",
          "types",
          "description",
          "markdown",
          "sortOrder",
          "createdAt",
          "updatedAt"
        ]
      },
      "PolicyTemplateList": {
        "description": "A list of policy templates.",
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/PolicyTemplate"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "PolicyTemplateTone": {
        "description": "The tone of the policy template, distinguishing essential from comprehensive templates.",
        "enum": [
          "NONE",
          "ESSENTIAL",
          "COMPREHENSIVE"
        ],
        "type": "string"
      },
      "PolicyType": {
        "properties": {
          "createdAt": {
            "description": "The time that this policy type was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "name": {
            "description": "The name of this policy type.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy type was updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "PolicyTypeList": {
        "description": "A list of policy types.",
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/PolicyType"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "PolicyVersion": {
        "description": "A policy version.",
        "properties": {
          "applicableSignatures": {
            "description": "Combined signatures and inherited signatures that count towards this policy version",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "applicableTenantMembers": {
            "description": "The tenant members that need to sign this policy version, including their signatures if they have signed.",
            "items": {
              "$ref": "#/components/schemas/PolicyApplicableTenantMember"
            },
            "type": "array"
          },
          "blocks": {
            "description": "The version's block index, present on markdown-backed versions whose block map has been computed.",
            "items": {
              "$ref": "#/components/schemas/PolicyVersionBlock"
            },
            "type": "array"
          },
          "comments": {
            "description": "The policy's review comments projected onto this version's content. Populated only on the single-version read, and only for comment render targets (the latest published version and the working draft) — historical versions carry an empty list.",
            "items": {
              "$ref": "#/components/schemas/PolicyComment"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this policy version was created.",
            "format": "date-time",
            "type": "string"
          },
          "createdBy": {
            "$ref": "#/components/schemas/User"
          },
          "deletedAt": {
            "description": "The time that this policy version was deleted. Absent for active versions.",
            "format": "date-time",
            "type": "string"
          },
          "directSignatures": {
            "description": "The signatures associated with this policy version.",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "fileName": {
            "description": "The policy's file name.",
            "type": "string"
          },
          "fileUrl": {
            "description": "The policy's file url.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the policy version.",
            "type": "string"
          },
          "inheritedSignatures": {
            "description": "Signatures from previous minor versions that count towards this policy version.",
            "items": {
              "$ref": "#/components/schemas/PolicySignature"
            },
            "type": "array"
          },
          "isPublished": {
            "description": "Whether or not this policy version is published.",
            "type": "boolean"
          },
          "markdown": {
            "description": "The markdown content of the policy version.",
            "type": "string"
          },
          "minorVersionNumber": {
            "description": "The minor version number of the policy.",
            "type": "integer"
          },
          "pdfGenerationPending": {
            "description": "Whether PDF generation has been triggered for this version and is not yet complete.",
            "type": "boolean"
          },
          "policyId": {
            "description": "The ID of the policy associated with this policy version.",
            "type": "string"
          },
          "publishedAt": {
            "description": "The time that this policy version was published.",
            "format": "date-time",
            "type": "string"
          },
          "reviewNotes": {
            "description": "The review notes for this version.",
            "type": "string"
          },
          "reviewedAt": {
            "description": "The time at which that this policy version was reviewed.",
            "format": "date-time",
            "type": "string"
          },
          "reviewedBy": {
            "$ref": "#/components/schemas/User"
          },
          "reviewedWithEdits": {
            "description": "Whether the reviewer changed the version content as part of approval.",
            "type": "boolean"
          },
          "status": {
            "description": "The current status of the policy version.",
            "enum": [
              "DRAFT",
              "IN_REVIEW",
              "PUBLISHED"
            ],
            "type": "string"
          },
          "submittedMarkdown": {
            "description": "The markdown the author submitted, present only when the reviewer edited it on approval. Diffing it against markdown shows exactly what the reviewer changed, which reviewedWithEdits on its own cannot.",
            "nullable": true,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this policy version was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "versionNumber": {
            "description": "The version number of the policy.",
            "type": "integer"
          }
        },
        "required": [
          "id",
          "policyId",
          "versionNumber",
          "minorVersionNumber",
          "isPublished",
          "status",
          "createdAt",
          "updatedAt",
          "pdfGenerationPending",
          "reviewedWithEdits"
        ]
      },
      "PolicyVersionBlock": {
        "description": "One anchorable unit of a version's markdown. The block index lets a client clamp a text selection to the same spans the server anchors against, so a comment's quoted text never picks up markdown syntax the anchor excludes. Text is not repeated here — slice it out of the version's markdown with the offsets.",
        "properties": {
          "blockId": {
            "description": "Content hash of the block, stable while its words are unchanged.",
            "type": "string"
          },
          "sourceEnd": {
            "description": "Byte offset where it ends (exclusive).",
            "type": "integer"
          },
          "sourceStart": {
            "description": "Byte offset in the version's markdown where the block's anchorable text begins.",
            "type": "integer"
          },
          "type": {
            "description": "The block's kind (HEADING, PARAGRAPH, LIST_ITEM, CODE_BLOCK, BLOCKQUOTE, TABLE, HTML_BLOCK).",
            "type": "string"
          }
        },
        "required": [
          "blockId",
          "type",
          "sourceStart",
          "sourceEnd"
        ],
        "type": "object"
      },
      "PolicyVersionList": {
        "description": "A list of policy versions.",
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/PolicyVersion"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "ProgramControl": {
        "properties": {
          "assignedMember": {
            "$ref": "#/components/schemas/ProgramControlAssignedMember"
          },
          "category": {
            "$ref": "#/components/schemas/ControlCategory"
          },
          "checkSummary": {
            "$ref": "#/components/schemas/ControlCheckSummary"
          },
          "controlTypeId": {
            "description": "The control type this control instantiates (e.g. statementOfApplicabilityCompleted_v1).",
            "type": "string"
          },
          "evidence": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlEvidence"
            },
            "type": "array"
          },
          "evidenceRequests": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlEvidenceRequest"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenantComplianceRequirements": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlRequirement"
            },
            "type": "array"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "controlTypeId",
          "status",
          "checkSummary",
          "evidence",
          "evidenceRequests",
          "tenantComplianceRequirements"
        ],
        "type": "object"
      },
      "ProgramControlAssignedMember": {
        "properties": {
          "email": {
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          }
        },
        "required": [
          "id",
          "name",
          "status"
        ],
        "type": "object"
      },
      "ProgramControlList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/ProgramControl"
            },
            "type": "array"
          }
        }
      },
      "ReadinessCheckClass": {
        "description": "How a readiness activity comes due.\n  - TIME_BASED: recurs on a cadence, e.g. a yearly penetration test.\n  - EVENT_DRIVEN: due within a grace period after something happens, e.g.\n    policy signatures after a new hire starts.\n",
        "enum": [
          "TIME_BASED",
          "EVENT_DRIVEN"
        ],
        "type": "string"
      },
      "ReadinessGroup": {
        "description": "One readiness activity, rolled up across every subject it covers.\n\nThe grain is the catalog definition, not the individual check: a per-hire\nactivity on a large tenant is one row carrying its subject count, not forty\nrows. Framework variants of the same activity are already collapsed by the\nengine, so a control covered by both SOC 2 and ISO 27001 appears once, at\nwhichever variant has the tightest deadline.\n",
        "properties": {
          "checkIds": {
            "description": "Every open check rolled into this row. Escalation emails link a check,\nnot an activity, so a surface highlighting a deep-linked check needs to\nbe able to find which row it belongs to.\n",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "definitionId": {
            "description": "Catalog definition id, e.g. \"pentest\".",
            "type": "string"
          },
          "description": {
            "description": "Longer statement of what the activity requires.",
            "type": "string"
          },
          "dueAt": {
            "description": "Earliest due date among the group's open checks. Absent when none of\nthem has resolved a due date yet — which happens before a tenant's\naudit window is known, not as an error state.\n",
            "format": "date-time",
            "type": "string"
          },
          "pending": {
            "description": "The activity is already in flight — a pentest has been requested, or an\nengagement is underway without a published report — so the row is\nwaiting on completion rather than on someone starting it. Read on\ndemand from the tenant's live records, never stored on the check:\n`status`, `dueAt`, the ordering, and the escalation emails all ignore\nit. Only activities with such a notion can ever be pending; the rest\nare always false.\n",
            "type": "boolean"
          },
          "responsibleName": {
            "description": "Display name of the member who owes the activity. Present only when\nevery subject in the group resolves to the same person; a group spread\nacross several owners omits it and lets `subjects` carry the detail.\n",
            "type": "string"
          },
          "scopeNoun": {
            "description": "Plural noun for this group's subjects, for count phrasing: \"team\nmembers\", \"vendors\", or \"items\".\n",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ReadinessStatus"
          },
          "subjects": {
            "description": "Per-subject breakdown, earliest due first. Empty for control-scoped\nactivities, which have exactly one subject — the control itself — and\nso have no meaningful list behind them.\n",
            "items": {
              "$ref": "#/components/schemas/ReadinessSubject"
            },
            "type": "array"
          },
          "summary": {
            "description": "Imperative one-line statement of the activity, e.g. \"Schedule a\npenetration test\". Safe to render as a task title.\n",
            "type": "string"
          },
          "unassigned": {
            "description": "No subject in this group resolved a responsible member, so nobody was\nreminded and it escalates straight to the tenant admins. Worth\nsurfacing: an unassigned overdue item is a gap in the escalation chain,\nnot just a late task.\n",
            "type": "boolean"
          }
        },
        "required": [
          "definitionId",
          "summary",
          "description",
          "status",
          "scopeNoun",
          "unassigned",
          "pending",
          "subjects",
          "checkIds"
        ],
        "type": "object"
      },
      "ReadinessNextUp": {
        "description": "The soonest activity that is not actionable yet, for the on-track state to\nname what is coming rather than saying nothing.\n",
        "properties": {
          "dueAt": {
            "format": "date-time",
            "type": "string"
          },
          "summary": {
            "type": "string"
          }
        },
        "required": [
          "summary",
          "dueAt"
        ],
        "type": "object"
      },
      "ReadinessSetting": {
        "description": "One readiness activity's timing for a tenant: the activity's defaults, the\ntenant's own values where set, and the values that apply. A TIME_BASED\nactivity carries the cadence fields and null grace fields; an EVENT_DRIVEN\nactivity carries the grace fields and null cadence fields.\n",
        "properties": {
          "class": {
            "$ref": "#/components/schemas/ReadinessCheckClass"
          },
          "defaultGraceDays": {
            "description": "The activity's default grace period in days. Null when the activity has no grace period.",
            "nullable": true,
            "type": "integer"
          },
          "definitionId": {
            "description": "Catalog definition id, e.g. \"pentest\".",
            "type": "string"
          },
          "description": {
            "description": "Longer statement of what the activity requires, rendered with the values that apply.",
            "type": "string"
          },
          "effectiveFrequencyDays": {
            "description": "The cadence that applies, in days. Null when the activity has no cadence.",
            "nullable": true,
            "type": "integer"
          },
          "effectiveGraceDays": {
            "description": "The grace period that applies, in days. Null when the activity has no grace period.",
            "nullable": true,
            "type": "integer"
          },
          "frequencyDays": {
            "description": "The tenant's cadence in days. Null when the tenant uses the default or the activity has no cadence.",
            "nullable": true,
            "type": "integer"
          },
          "graceDays": {
            "description": "The tenant's grace period in days. Null when the tenant uses the default or the activity has no grace period.",
            "nullable": true,
            "type": "integer"
          },
          "requiredFrequencyDays": {
            "description": "The longest cadence the activity allows, in days. The tenant's cadence\ncan't exceed it. Null when the activity has no cadence.\n",
            "nullable": true,
            "type": "integer"
          },
          "summary": {
            "description": "Imperative one-line statement of the activity, rendered with the values that apply.",
            "type": "string"
          }
        },
        "required": [
          "definitionId",
          "summary",
          "description",
          "class",
          "requiredFrequencyDays",
          "frequencyDays",
          "effectiveFrequencyDays",
          "defaultGraceDays",
          "graceDays",
          "effectiveGraceDays"
        ],
        "type": "object"
      },
      "ReadinessStatus": {
        "description": "Where an activity sits against its deadline. Computed server-side by the\ndaily readiness sweep and stored on the check, so every surface — this API,\nthe escalation emails, the weekly digest — agrees on the tier.\n\nOnly the three open tiers reach this API; SATISFIED and NOT_APPLICABLE\nchecks are counted, never listed.\n  - DUE_SOON: inside the activity's reminder window, or never yet done.\n  - OVERDUE: past its due date, still inside the tenant's SLA window.\n  - BREACHING: past the SLA window too, so the SLA is breached. The only\n    tier the UI is expected to render in red.\n",
        "enum": [
          "DUE_SOON",
          "OVERDUE",
          "BREACHING"
        ],
        "type": "string"
      },
      "ReadinessSubject": {
        "description": "One subject behind a readiness group — the person or entity a single\ninstance of the activity is about.\n",
        "properties": {
          "checkIds": {
            "description": "This subject's open check ids, for resolving a deep-linked check down to\na single row inside the group.\n",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "dueAt": {
            "description": "Earliest due date among this subject's open checks. Absent when none of\nthem has resolved a due date yet.\n",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The subject's own id, e.g. the TenantMember id for a per-hire activity.\n",
            "format": "uuid",
            "type": "string"
          },
          "label": {
            "description": "Display name of the subject. Falls back to a generic label (\"Former\nteam member\") when the underlying row has been deleted — the queue\nstill has to be able to name every item it counts.\n",
            "type": "string"
          }
        },
        "required": [
          "id",
          "label",
          "checkIds"
        ],
        "type": "object"
      },
      "ReadinessSummary": {
        "description": "The tenant's audit-readiness rollup: the queue of activities still needing\nattention, plus the counts behind the on-track state.\n\nReadiness checks are the recurring activities an audit examines — scheduling\na penetration test, collecting policy signatures, recording employment\ndates. They run against the audit window rather than any one journey stage,\nwhich is why this is a tenant-level rollup rather than something nested in a\nstage payload.\n\nA tenant without the `readiness-checks` feature flag gets an empty summary\n(zero counts, no groups) rather than an error.\n",
        "properties": {
          "groups": {
            "description": "Activities needing attention, most urgent first: breaching, then\noverdue, then due soon; within a tier, soonest due first. Empty when\nthe tenant is fully on track.\n",
            "items": {
              "$ref": "#/components/schemas/ReadinessGroup"
            },
            "type": "array"
          },
          "nextUp": {
            "$ref": "#/components/schemas/ReadinessNextUp"
          },
          "satisfiedCount": {
            "description": "How many of `totalCount` are currently satisfied.",
            "type": "integer"
          },
          "totalCount": {
            "description": "Every active, applicable check on the tenant. Suppressed (snoozed,\ndisabled) and not-applicable checks are excluded — they are not work\nthe tenant owes, so they do not belong in the denominator.\n",
            "type": "integer"
          }
        },
        "required": [
          "totalCount",
          "satisfiedCount",
          "groups"
        ],
        "type": "object"
      },
      "RemoveActionGroupRequest": {
        "properties": {
          "groupId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          }
        },
        "required": [
          "groupId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "RemoveActionMemberRequest": {
        "properties": {
          "role": {
            "$ref": "#/components/schemas/ActionMemberRole"
          },
          "tenantMemberId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantMemberId",
          "role"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "RemoveActionResourceUrnRequest": {
        "properties": {
          "rel": {
            "$ref": "#/components/schemas/ActionResourceUrnRel"
          },
          "resourceId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resourceType": {
            "minLength": 1,
            "type": "string"
          }
        },
        "required": [
          "resourceType",
          "resourceId",
          "rel"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "ResultSnapshot": {
        "properties": {
          "assetResultSnapshot": {
            "$ref": "#/components/schemas/AssetResultSnapshot"
          },
          "connectionId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connectionReadableId": {
            "type": "string"
          },
          "reasons": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/ResultSnapshotStatus"
          }
        },
        "required": [
          "connectionId",
          "connectionReadableId",
          "status",
          "reasons"
        ]
      },
      "ResultSnapshotList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/ResultSnapshot"
            },
            "type": "array"
          }
        }
      },
      "ResultSnapshotStatus": {
        "description": "The status of a result snapshot.",
        "enum": [
          "SUCCEEDED",
          "FAILED",
          "IGNORED"
        ],
        "type": "string"
      },
      "RetiredScopeItem": {
        "description": "A control scope item that left the control's resolved scope. It no longer projects a check, but stays visible (with the evidence from its in-scope interval) so a shrunken scope remains reviewable.\n",
        "properties": {
          "activeFrom": {
            "description": "Start of the item's final in-scope interval.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "evidenceIds": {
            "description": "Ids of evidence attached during the in-scope interval.",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "kind": {
            "enum": [
              "VENDOR",
              "MEMBER"
            ],
            "type": "string"
          },
          "retiredAt": {
            "description": "When the item left scope.",
            "format": "date-time",
            "type": "string"
          },
          "retiredReason": {
            "type": "string"
          },
          "scopeRef": {
            "type": "string"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "kind",
          "scopeRef",
          "title",
          "activeFrom",
          "retiredAt",
          "evidenceIds"
        ],
        "type": "object"
      },
      "Risk": {
        "properties": {
          "aiAssessment": {
            "$ref": "#/components/schemas/AiAssessment"
          },
          "archivedAt": {
            "description": "The time that this risk was archived.",
            "format": "date-time",
            "type": "string"
          },
          "assessedAt": {
            "description": "The time that this risk was assessed.",
            "format": "date-time",
            "type": "string"
          },
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "controls": {
            "items": {
              "$ref": "#/components/schemas/RiskLinkedControl"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this risk was created.",
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "description": "The description of the risk.",
            "type": "string"
          },
          "hasResidualRisk": {
            "description": "Whether the risk has a residual risk.",
            "type": "boolean"
          },
          "id": {
            "description": "The ID of the risk.",
            "format": "uuid",
            "type": "string"
          },
          "impact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "likelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "note": {
            "description": "Additional notes or comments about the risk.",
            "type": "string"
          },
          "owner": {
            "$ref": "#/components/schemas/RiskMember"
          },
          "ownerId": {
            "description": "The ID of the owner associated with this risk.",
            "format": "uuid",
            "type": "string"
          },
          "previousRiskId": {
            "description": "The ID of the previous risk associated with this risk.",
            "format": "uuid",
            "type": "string"
          },
          "rating": {
            "$ref": "#/components/schemas/RiskRating"
          },
          "residualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "residualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "residualRating": {
            "$ref": "#/components/schemas/RiskRating"
          },
          "response": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "responseDetails": {
            "description": "The details of the risk response.",
            "type": "string"
          },
          "riskAssessment": {
            "$ref": "#/components/schemas/RiskAssessment"
          },
          "riskAssessmentId": {
            "description": "The ID of the risk assessment associated with this risk.",
            "format": "uuid",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this risk.",
            "format": "uuid",
            "type": "string"
          },
          "title": {
            "description": "The title of the risk.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this risk was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "category",
          "tenantId",
          "riskAssessmentId"
        ]
      },
      "RiskAssessment": {
        "properties": {
          "completedAt": {
            "description": "The time that this risk assessment was completed.",
            "format": "date-time",
            "type": "string"
          },
          "completedBy": {
            "$ref": "#/components/schemas/RiskMember"
          },
          "completedById": {
            "description": "The ID of the member who completed this risk assessment.",
            "format": "uuid",
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this risk assessment was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the risk assessment.",
            "format": "uuid",
            "type": "string"
          },
          "riskMatrixSize": {
            "$ref": "#/components/schemas/RiskMatrixSize"
          },
          "risks": {
            "items": {
              "$ref": "#/components/schemas/Risk"
            },
            "type": "array"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this risk assessment.",
            "format": "uuid",
            "type": "string"
          },
          "title": {
            "description": "The title of the risk assessment.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this risk assessment was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "title",
          "tenantId",
          "riskMatrixSize"
        ]
      },
      "RiskCategory": {
        "enum": [
          "SECURITY",
          "OPERATIONAL",
          "FINANCIAL",
          "LEGAL_AND_COMPLIANCE",
          "STRATEGIC_AND_MARKET",
          "FRAUD"
        ],
        "type": "string"
      },
      "RiskImpact": {
        "enum": [
          "NEGLIGIBLE",
          "MINOR",
          "MODERATE",
          "MAJOR",
          "DEVASTATING"
        ],
        "type": "string"
      },
      "RiskLikelihood": {
        "enum": [
          "REMOTE",
          "UNLIKELY",
          "POSSIBLE",
          "LIKELY",
          "ALMOST_CERTAIN"
        ],
        "type": "string"
      },
      "RiskLinkedControl": {
        "properties": {
          "assignedMember": {
            "$ref": "#/components/schemas/RiskMember"
          },
          "controlType": {
            "$ref": "#/components/schemas/RiskLinkedControlType"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenantComplianceRequirements": {
            "items": {
              "$ref": "#/components/schemas/RiskLinkedTenantComplianceRequirement"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "status",
          "controlType"
        ],
        "type": "object"
      },
      "RiskLinkedControlType": {
        "properties": {
          "title": {
            "type": "string"
          }
        },
        "required": [
          "title"
        ],
        "type": "object"
      },
      "RiskLinkedFramework": {
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "RiskLinkedTenantComplianceRequirement": {
        "properties": {
          "id": {
            "type": "string"
          },
          "tenantFramework": {
            "$ref": "#/components/schemas/RiskLinkedTenantFramework"
          }
        },
        "required": [
          "id"
        ],
        "type": "object"
      },
      "RiskLinkedTenantFramework": {
        "properties": {
          "framework": {
            "$ref": "#/components/schemas/RiskLinkedFramework"
          }
        },
        "type": "object"
      },
      "RiskMatrixSize": {
        "enum": [
          "THREE_BY_THREE",
          "FIVE_BY_FIVE"
        ],
        "type": "string"
      },
      "RiskMember": {
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          },
          "user": {
            "$ref": "#/components/schemas/RiskMemberUser"
          }
        },
        "required": [
          "id",
          "name",
          "status"
        ],
        "type": "object"
      },
      "RiskMemberUser": {
        "properties": {
          "email": {
            "type": "string"
          }
        },
        "required": [
          "email"
        ],
        "type": "object"
      },
      "RiskRating": {
        "enum": [
          "NONE",
          "TRIVIAL",
          "LOW",
          "MEDIUM",
          "HIGH",
          "EXTREME"
        ],
        "type": "string"
      },
      "RiskResponse": {
        "enum": [
          "MITIGATE",
          "TRANSFER",
          "AVOID",
          "ACCEPT"
        ],
        "type": "string"
      },
      "SlaType": {
        "description": "The SLA type of a monitor asset result.",
        "enum": [
          "GENERAL",
          "POLICY_SIGNING",
          "SECURITY_TRAINING",
          "VENDOR_ASSESSMENT",
          "RISK_ASSESSMENT",
          "ACCESS_REVIEW",
          "INFORMATIONAL",
          "LOW_SEVERITY",
          "MEDIUM_SEVERITY",
          "HIGH_SEVERITY",
          "CRITICAL"
        ],
        "type": "string"
      },
      "SoftwarePackage": {
        "properties": {
          "createdAt": {
            "description": "Date and time the package was created.",
            "format": "date-time",
            "type": "string"
          },
          "gitRepositoryDependencies": {
            "items": {
              "$ref": "#/components/schemas/SoftwarePackageGitRepositoryDependency"
            },
            "type": "array"
          },
          "homepageUrl": {
            "description": "URL for the package's homepage.",
            "type": "string"
          },
          "id": {
            "description": "Unique identifier for the package.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "licenseExpression": {
            "description": "SPDX license expression for the package.",
            "nullable": true,
            "type": "string"
          },
          "licenses": {
            "description": "List of licenses associated with the package (SPDX identifiers or license names).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "packageName": {
            "description": "Friendly name of the package.",
            "type": "string"
          },
          "packageUrlType": {
            "description": "Package URL (purl) type, which usually corresponds to a package manager, file format, or distribution channel (e.g., npm, pip, maven, go, deb, rpm).",
            "type": "string"
          },
          "packageVersions": {
            "description": "In-use versions of the package, ordered from oldest to newest.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "Date and time the package was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "packageName",
          "packageVersions",
          "packageUrlType",
          "gitRepositoryDependencies"
        ]
      },
      "SoftwarePackageGitRepositoryDependency": {
        "properties": {
          "firstSeenAt": {
            "description": "Date and time the package dependency was first seen in the Git repository.",
            "format": "date-time",
            "type": "string"
          },
          "gitRepositoryId": {
            "description": "ID of the Git repository that depends on the package.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isDirectDependency": {
            "description": "Whether the Git repository depends on the package as a direct (or transitive) dependency.",
            "type": "boolean"
          },
          "manifestFilePath": {
            "description": "Path to the manifest file in the Git repository that depends on the package.",
            "type": "string"
          },
          "packageVersion": {
            "description": "Version of the package that the Git repository depends on.",
            "type": "string"
          }
        },
        "required": [
          "gitRepositoryId",
          "manifestFilePath",
          "packageVersion",
          "firstSeenAt",
          "isDirectDependency"
        ]
      },
      "SoftwarePackageListItem": {
        "properties": {
          "createdAt": {
            "description": "Date and time the package was created.",
            "format": "date-time",
            "type": "string"
          },
          "gitRepositoryIds": {
            "items": {
              "description": "IDs of Git repositories that depend on this package.",
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          },
          "homepageUrl": {
            "description": "URL for the package's homepage.",
            "type": "string"
          },
          "id": {
            "description": "Unique identifier for the package.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isDirectDependency": {
            "description": "Whether the tenant uses this package as a direct (or transitive) dependency.",
            "type": "boolean"
          },
          "licenseExpression": {
            "description": "SPDX license expression for the package.",
            "nullable": true,
            "type": "string"
          },
          "licenses": {
            "description": "List of licenses associated with the package (SPDX identifiers or license names).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "packageName": {
            "description": "Friendly name of the package.",
            "type": "string"
          },
          "packageUrlType": {
            "description": "Package URL (purl) type, which usually corresponds to a package manager, file format, or distribution channel (e.g., npm, pip, maven, go, deb, rpm).",
            "type": "string"
          },
          "packageVersions": {
            "description": "In-use versions of the package, ordered from oldest to newest.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "updatedAt": {
            "description": "Date and time the package was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "packageName",
          "packageVersions",
          "packageUrlType",
          "gitRepositoryIds",
          "isDirectDependency"
        ]
      },
      "SoftwarePackageListResult": {
        "properties": {
          "packages": {
            "items": {
              "$ref": "#/components/schemas/SoftwarePackageListItem"
            },
            "type": "array"
          },
          "pagination": {
            "$ref": "#/components/schemas/SoftwarePackagePagination"
          }
        },
        "required": [
          "packages",
          "pagination"
        ],
        "type": "object"
      },
      "SoftwarePackagePagination": {
        "properties": {
          "hasNext": {
            "description": "Whether there are more results after this page.",
            "type": "boolean"
          },
          "nextCursor": {
            "description": "Opaque pagination cursor. Pass as cursor in the next request.",
            "type": "string"
          },
          "total": {
            "description": "Total number of matching packages across all pages. Only present on the first page, when no cursor is provided.\nThis is always an estimate; the total may change before reaching the last page if items are added or\nremoved in the meantime.\n",
            "type": "integer"
          }
        },
        "required": [
          "hasNext"
        ],
        "type": "object"
      },
      "SoftwarePackageVulnerability": {
        "properties": {
          "createdAt": {
            "description": "Date and time the vulnerability was created.",
            "format": "date-time",
            "type": "string"
          },
          "cveVulnerabilityId": {
            "description": "Common Vulnerabilities and Exposures identifier (CVE-\u003cyear\u003e-\u003cnumber\u003e).",
            "nullable": true,
            "type": "string"
          },
          "cvssSeverity": {
            "$ref": "#/components/schemas/SoftwarePackageVulnerabilitySeverity"
          },
          "cvssSeverityScore": {
            "description": "Best available CVSS score (0-10) as a measure of vulnerability severity.",
            "maximum": 10,
            "minimum": 0,
            "nullable": true,
            "type": "number"
          },
          "cvssVersion": {
            "description": "Version of the CVSS standard used to compute the best available CVSS score.",
            "nullable": true,
            "type": "string"
          },
          "cwes": {
            "description": "Common Weakness Enumerations (CWEs) associated with the vulnerability.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "epssPercentile": {
            "description": "EPSS percentile of exploitation probability (0-1) among scored CVEs.",
            "maximum": 1,
            "minimum": 0,
            "nullable": true,
            "type": "number"
          },
          "epssProbability": {
            "description": "EPSS probability that the vulnerability will be exploited in the wild in the next 30 days (0-1).",
            "maximum": 1,
            "minimum": 0,
            "nullable": true,
            "type": "number"
          },
          "ghsaVulnerabilityId": {
            "description": "GitHub Security Advisory identifier.",
            "nullable": true,
            "type": "string"
          },
          "gitRepositoryFindings": {
            "items": {
              "$ref": "#/components/schemas/SoftwarePackageVulnerabilityGitRepositoryFinding"
            },
            "type": "array"
          },
          "id": {
            "description": "Unique identifier for the vulnerability.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "isInKevCatalog": {
            "description": "Whether the vulnerability is in the CISA KEV catalog.",
            "type": "boolean"
          },
          "package": {
            "$ref": "#/components/schemas/SoftwarePackage"
          },
          "primaryVulnerabilityId": {
            "description": "The primary vulnerability ID (canonical identifier, usually a CVE or GHSA).",
            "type": "string"
          },
          "riskLevel": {
            "$ref": "#/components/schemas/SoftwarePackageVulnerabilityRisk"
          },
          "riskScore": {
            "description": "Vulnerability risk score, derived from the Grype risk score and the results of AI issue investigations (if any).",
            "type": "number"
          },
          "shortDescription": {
            "description": "Short description of how the package is vulnerable, suitable as a title.",
            "nullable": true,
            "type": "string"
          },
          "updatedAt": {
            "description": "Date and time the vulnerability was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "primaryVulnerabilityId",
          "cwes",
          "cvssSeverity",
          "isInKevCatalog",
          "riskScore",
          "riskLevel",
          "package",
          "gitRepositoryFindings"
        ]
      },
      "SoftwarePackageVulnerabilityGitRepositoryFinding": {
        "properties": {
          "gitRepositoryId": {
            "description": "ID of the Git repository that is affected by the vulnerability.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "description": "Unique identifier for the finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "investigations": {
            "items": {
              "$ref": "#/components/schemas/PackageFindingInvestigation"
            },
            "type": "array"
          },
          "manifestFilePath": {
            "description": "Path to the manifest file in the Git repository that depends on the package.",
            "type": "string"
          },
          "ownerId": {
            "description": "ID of the tenant member assigned as the owner of the finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "packageVersion": {
            "description": "Version of the package that the Git repository depends on.",
            "type": "string"
          },
          "resolution": {
            "$ref": "#/components/schemas/PackageFindingResolution"
          },
          "resolvedAt": {
            "description": "When the finding was resolved.",
            "format": "date-time",
            "type": "string"
          },
          "resolvedById": {
            "description": "ID of the tenant member who resolved the finding. Absent when the finding was resolved via the API/MCP or automatically by a scan.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resolvedByServiceKeyName": {
            "description": "Name of the service key that resolved the finding, for resolutions made via the API/MCP. Absent when the finding was resolved by a tenant member or automatically by a scan.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "gitRepositoryId",
          "manifestFilePath",
          "packageVersion",
          "investigations"
        ]
      },
      "SoftwarePackageVulnerabilityRisk": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFO"
        ],
        "type": "string"
      },
      "SoftwarePackageVulnerabilitySeverity": {
        "enum": [
          "CRITICAL",
          "HIGH",
          "MEDIUM",
          "LOW",
          "INFO",
          "UNKNOWN"
        ],
        "type": "string"
      },
      "Target": {
        "properties": {
          "filepath": {
            "description": "The filepath of the target.",
            "type": "string"
          },
          "findingId": {
            "description": "The ID of the finding that this target is linked to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "hostPort": {
            "description": "The host:port of the target.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the target.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/TargetKind"
          }
        },
        "required": [
          "id",
          "findingId",
          "kind"
        ],
        "type": "object"
      },
      "TargetKind": {
        "enum": [
          "SUBDOMAINPORT",
          "HOSTPORT",
          "FILEPATH"
        ],
        "type": "string"
      },
      "Tenant": {
        "properties": {
          "aiCompanyResearch": {
            "description": "The deep multi-paragraph company research blob produced by the AI company research workflow. Consumed by downstream AI workflows as prompt context.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchDomainSnapshot": {
            "description": "The domain value the current company research outputs were generated against. Compared against the live domain to detect drift.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchError": {
            "description": "Prose explaining why the most recent AI company research run failed or was cancelled. Populated on FAILED or CANCELLED.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchGeneratedAt": {
            "description": "The time of the most recent successful AI company research generation.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchHints": {
            "description": "Free-text steering context curated by the security program manager, passed verbatim to the AI on the next research run.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchHintsSnapshot": {
            "description": "Snapshot of the AI research hints at the dispatch moment of the most recent successful run. Compared against the live hints to surface a drift indicator.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchNotes": {
            "description": "Human-facing meta-commentary about the most recent successful research run (coverage gaps, ambiguous sources, suspected-stale info). Distinct from the failure error, which describes why a run failed.",
            "nullable": true,
            "type": "string"
          },
          "aiCompanyResearchStatus": {
            "$ref": "#/components/schemas/AiCompanyResearchStatus"
          },
          "aiCompanySummary": {
            "description": "The concise one-paragraph human-scannable company summary derived from the research in the same workflow run.",
            "nullable": true,
            "type": "string"
          },
          "aiRiskPersonalizationGeneratedAt": {
            "description": "The time of the most recent successful AI risk personalization, when the current results were generated.",
            "format": "date-time",
            "type": "string"
          },
          "aiRiskPersonalizationResults": {
            "$ref": "#/components/schemas/AiRiskPersonalizationResults"
          },
          "aiRiskPersonalizationStatus": {
            "$ref": "#/components/schemas/AiRiskPersonalizationStatus"
          },
          "companyAddress": {
            "description": "The registered address of the company.",
            "type": "string"
          },
          "companyProfile": {
            "description": "Company profile data filled by Oneleet admins.",
            "type": "object"
          },
          "companyProfileUpdatedAt": {
            "description": "The time that the company profile was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "completedOnboardingSteps": {
            "description": "List of onboarding step IDs that the tenant has completed (computed).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "complianceFrameworks": {
            "description": "The compliance frameworks this tenant has active.",
            "items": {
              "$ref": "#/components/schemas/ComplianceFramework"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this tenant was created.",
            "format": "date-time",
            "type": "string"
          },
          "deviceConfigDefaultsAcceptedAt": {
            "description": "When an admin completed the device-config secure-defaults opt-in (either applying the recommended baseline or choosing to configure manually). Null means the opt-in workflow hasn't been completed yet.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "enableAiFeatures": {
            "description": "Whether AI features are enabled for this tenant. Null means the user has not yet made a choice.",
            "nullable": true,
            "type": "boolean"
          },
          "enableChecklists": {
            "description": "Whether onboarding/offboarding checklists are enabled for this tenant. Null means not yet configured (defaults to enabled).",
            "nullable": true,
            "type": "boolean"
          },
          "engagements": {
            "description": "The engagements associated with this tenant.",
            "items": {
              "$ref": "#/components/schemas/Engagement"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "includeVersionHistoryInPolicyPdfs": {
            "description": "Whether policy versions are available in PDF format.",
            "type": "boolean"
          },
          "isAppInventoryEnabled": {
            "description": "Whether installed application inventory collection is enabled for this tenant.",
            "type": "boolean"
          },
          "isPreOnboardingTenant": {
            "description": "Whether the tenant was created before the onboarding flow was introduced (computed from createdAt).",
            "type": "boolean"
          },
          "legalName": {
            "description": "The registered legal name of the company.",
            "type": "string"
          },
          "members": {
            "description": "The members associated with this tenant.",
            "items": {
              "$ref": "#/components/schemas/TenantMember"
            },
            "type": "array"
          },
          "name": {
            "description": "The name of the tenant.",
            "type": "string"
          },
          "onboardingStatus": {
            "$ref": "#/components/schemas/TenantOnboardingStatus"
          },
          "policyOnboardingStatus": {
            "$ref": "#/components/schemas/TenantPolicyOnboardingStatus"
          },
          "pylonAccountId": {
            "description": "The Pylon account ID linked to this tenant. Absent when the tenant has not been synced to Pylon, or when the calling principal is not a superadmin.",
            "type": "string"
          },
          "recommendedSlug": {
            "description": "The suggested slug of the tenant.",
            "type": "string"
          },
          "skippedOnboardingSteps": {
            "description": "List of onboarding step IDs that the tenant has explicitly skipped.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "slaAccessReviewHours": {
            "description": "The service level agreement in hours for completing access reviews. omitted indicates disabled.",
            "type": "integer"
          },
          "slaCriticalHours": {
            "description": "The service level agreement in hours for resolving critical vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaGeneralHours": {
            "description": "The service level agreement in hours for resolving general vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaHighSeverityHours": {
            "description": "The service level agreement in hours for resolving high-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaInformationalHours": {
            "description": "The service level agreement in hours for resolving informational vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaLowSeverityHours": {
            "description": "The service level agreement in hours for resolving low-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaMediumSeverityHours": {
            "description": "The service level agreement in hours for resolving medium-severity vulnerabilities. omitted indicates disabled.",
            "type": "integer"
          },
          "slaPolicySigningHours": {
            "description": "The service level agreement in hours for signing policies. omitted indicates disabled.",
            "type": "integer"
          },
          "slaRiskAssessmentHours": {
            "description": "The service level agreement in hours for completing risk assessments. omitted indicates disabled.",
            "type": "integer"
          },
          "slaSecurityTrainingHours": {
            "description": "The service level agreement in hours for completing security training. omitted indicates disabled.",
            "type": "integer"
          },
          "slaVendorAssessmentHours": {
            "description": "The service level agreement in hours for completing vendor assessments. omitted indicates disabled.",
            "type": "integer"
          },
          "slug": {
            "description": "The slug of the tenant.",
            "type": "string"
          },
          "tenantOwnerScheduleCallUrl": {
            "description": "Scheduling-page URL (e.g. Calendly) of the Oneleet team member assigned\nto this tenant. Omitted when the tenant has no assigned owner or the\nowner has not configured a URL.\n",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this tenant was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "recommendedSlug",
          "onboardingStatus",
          "completedOnboardingSteps",
          "skippedOnboardingSteps",
          "isPreOnboardingTenant",
          "policyOnboardingStatus"
        ],
        "type": "object"
      },
      "TenantBasicInfo": {
        "description": "A lightweight tenant representation with only identifying fields.",
        "properties": {
          "id": {
            "description": "The ID of the tenant.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name"
        ],
        "type": "object"
      },
      "TenantComplianceDashboard": {
        "properties": {
          "closedOrRejectedFindingsCount": {
            "description": "The number of closed findings associated with this tenant dashboard.",
            "type": "integer"
          },
          "completedControlsCount": {
            "description": "The number of completed controls associated with this tenant dashboard.",
            "type": "integer"
          },
          "dashboardStats": {
            "$ref": "#/components/schemas/DashboardStats"
          },
          "totalControlsCount": {
            "description": "The number of controls associated with this tenant dashboard.",
            "type": "integer"
          },
          "totalFindingsCount": {
            "description": "The number of findings associated with this tenant dashboard.",
            "type": "integer"
          },
          "type": {
            "type": "string"
          }
        },
        "required": [
          "type",
          "closedOrRejectedFindingsCount",
          "frameworkProgress",
          "totalControlsCount",
          "completedControlsCount"
        ]
      },
      "TenantComplianceFramework": {
        "properties": {
          "createdAt": {
            "description": "The time the tenant compliance framework was created.",
            "format": "date-time",
            "type": "string"
          },
          "designation": {
            "$ref": "#/components/schemas/FrameworkDesignation"
          },
          "framework": {
            "$ref": "#/components/schemas/ComplianceFramework"
          },
          "frameworkId": {
            "description": "The id of the framework associated with this tenant compliance framework.",
            "type": "string"
          },
          "id": {
            "description": "The id of the tenant compliance framework.",
            "type": "string"
          },
          "isVisibleOnTrustPage": {
            "description": "Whether the compliance framework is shown on the tenant's trust page.",
            "type": "boolean"
          },
          "progress": {
            "properties": {
              "metRequirementCount": {
                "description": "The number of requirements that have been met.",
                "type": "integer"
              },
              "percentComplete": {
                "description": "What percent complete the framework is, ranging from 0 (0%) to 100 (100%).",
                "maximum": 100,
                "minimum": 0,
                "type": "integer"
              }
            },
            "required": [
              "metRequirementCount",
              "percentComplete"
            ],
            "type": "object"
          },
          "requirements": {
            "description": "The tenant requirements for this tenant compliance framework.",
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirement"
            },
            "type": "array"
          },
          "status": {
            "$ref": "#/components/schemas/TenantComplianceFrameworkStatus"
          },
          "tenantId": {
            "description": "The id of the tenant this tenant compliance framework belongs to.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the tenant compliance framework record was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "status",
          "isVisibleOnTrustPage",
          "progress",
          "tenantId",
          "frameworkId",
          "framework",
          "createdAt",
          "updatedAt",
          "designation"
        ],
        "type": "object"
      },
      "TenantComplianceFrameworkList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceFramework"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "TenantComplianceFrameworkStatus": {
        "enum": [
          "IN_PROGRESS",
          "COMPLIANT"
        ],
        "type": "string"
      },
      "TenantComplianceRequirement": {
        "properties": {
          "createdAt": {
            "description": "The time the requirement was created.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The id of the tenant compliance requirement.",
            "type": "string"
          },
          "progress": {
            "properties": {
              "controlCount": {
                "description": "The number of controls associated with this requirement.",
                "type": "integer"
              },
              "isMet": {
                "description": "Whether the requirement has been met",
                "type": "boolean"
              },
              "passingControlCount": {
                "description": "The number of controls that are passing",
                "type": "integer"
              },
              "percentMet": {
                "description": "What percent met the requirement is, ranging from 0 (0%) to 100 (100%).",
                "maximum": 100,
                "minimum": 0,
                "type": "integer"
              }
            },
            "required": [
              "controlCount",
              "passingControlCount",
              "percentMet",
              "isMet"
            ],
            "type": "object"
          },
          "requirement": {
            "$ref": "#/components/schemas/ComplianceRequirement"
          },
          "requirementId": {
            "description": "The id of the requirement associated with this tenant compliance requirement.",
            "type": "string"
          },
          "tenantFramework": {
            "$ref": "#/components/schemas/TenantComplianceFramework"
          },
          "tenantFrameworkId": {
            "description": "The id of the tenant framework that this requirement belongs to.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time the requirement was last updated",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "progress",
          "tenantFrameworkId",
          "requirementId",
          "requirement",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControl": {
        "properties": {
          "assignedMember": {
            "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlAssignedMember"
          },
          "checkSummary": {
            "$ref": "#/components/schemas/ControlCheckSummary"
          },
          "checks": {
            "description": "Deprecated. Use checkSummary instead.",
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlCheck"
            },
            "type": "array"
          },
          "evidence": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlEvidence"
            },
            "type": "array"
          },
          "evidenceRequests": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlEvidenceRequest"
            },
            "type": "array"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "tenantComplianceRequirements": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlRequirement"
            },
            "type": "array"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "status",
          "checks",
          "checkSummary",
          "evidence",
          "evidenceRequests",
          "tenantComplianceRequirements"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControlAssignedMember": {
        "properties": {
          "email": {
            "nullable": true,
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControlCheck": {
        "properties": {
          "status": {
            "$ref": "#/components/schemas/CheckStatus"
          }
        },
        "required": [
          "status"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControlEvidence": {
        "properties": {
          "type": {
            "$ref": "#/components/schemas/EvidenceType"
          }
        },
        "required": [
          "type"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControlEvidenceRequest": {
        "properties": {
          "activeAt": {
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/EvidenceRequestStatus"
          }
        },
        "required": [
          "status"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementBatchControlList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControl"
            },
            "type": "array"
          }
        }
      },
      "TenantComplianceRequirementBatchControlRequirement": {
        "properties": {
          "frameworkName": {
            "nullable": true,
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "referenceId": {
            "type": "string"
          },
          "tenantFrameworkId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "id",
          "tenantFrameworkId",
          "referenceId"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementControlList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementControls"
            },
            "type": "array"
          }
        }
      },
      "TenantComplianceRequirementControlSummary": {
        "properties": {
          "id": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/ControlStatus"
          },
          "title": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title",
          "status"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementControlSummaryGroup": {
        "properties": {
          "controls": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementControlSummary"
            },
            "type": "array"
          },
          "tenantComplianceRequirementId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantComplianceRequirementId",
          "controls"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementControlSummaryList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementControlSummaryGroup"
            },
            "type": "array"
          }
        }
      },
      "TenantComplianceRequirementControls": {
        "properties": {
          "controls": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirementBatchControl"
            },
            "type": "array"
          },
          "tenantComplianceRequirementId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantComplianceRequirementId",
          "controls"
        ],
        "type": "object"
      },
      "TenantComplianceRequirementList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantComplianceRequirement"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "TenantDashboard": {
        "properties": {
          "data": {
            "discriminator": {
              "mapping": {
                "CLASSIC_DASHBOARD": "#/components/schemas/ClassicDashboard",
                "COMPLIANCE_DASHBOARD": "#/components/schemas/TenantComplianceDashboard"
              },
              "propertyName": "type"
            },
            "oneOf": [
              {
                "$ref": "#/components/schemas/ClassicDashboard"
              },
              {
                "$ref": "#/components/schemas/TenantComplianceDashboard"
              }
            ]
          },
          "type": {
            "enum": [
              "COMPLIANCE_DASHBOARD",
              "CLASSIC_DASHBOARD"
            ],
            "type": "string"
          }
        }
      },
      "TenantDevice": {
        "properties": {
          "agentInfo": {
            "$ref": "#/components/schemas/AgentInfo"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "ddmEnrolledAt": {
            "description": "First accepted status report for the current DDM enrollment, or null.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "ddmLastSeenAt": {
            "description": "Most recent accepted DDM status report, or null.",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "deviceInfo": {
            "$ref": "#/components/schemas/DeviceInfo"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isArchived": {
            "type": "boolean"
          },
          "isDdmEnrolled": {
            "description": "Whether a status report has been persisted for this workspace's current DDM enrollment.",
            "type": "boolean"
          },
          "isInScope": {
            "type": "boolean"
          },
          "issueCount": {
            "type": "integer"
          },
          "mdmBootstrapTokenCheckedAt": {
            "description": "When Oneleet MDM last checked the bootstrap token for the current\nenrollment, or null when it hasn't checked yet. A check time with a\nnull mdmBootstrapTokenEscrowedAt means the Mac had no token when\nchecked.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "mdmBootstrapTokenEscrowedAt": {
            "description": "When Oneleet MDM stored the Mac's bootstrap token for its current\nenrollment in this workspace, or null when it holds none or hasn't\nchecked yet. Null when another workspace owns the enrollment.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "mdmEnrolledAt": {
            "description": "When this device most recently (re-)enrolled in Apple MDM, or null if\nit has never enrolled. Unlike mdmTenantId, this is never cleared on\nunenrollment, so it remains a historical record even after the device\nchecks out of MDM.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "mdmTenantId": {
            "description": "Tenant that owns this device's Apple MDM enrollment, or null when the\ndevice is not enrolled. The UI uses this to gate MDM-only actions\n(e.g. MDM wipe) — if this is null or does not match the current\ntenant, the device cannot be controlled via MDM from this tenant.\n",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          },
          "mdmUnenrolledAt": {
            "description": "When this device most recently checked out of Apple MDM, or null if\nit has never unenrolled. Like mdmEnrolledAt, this is never cleared —\nit's a historical record, not a \"currently unenrolled\" flag. If\nmdmTenantId is set and this is non-null, the device unenrolled at\nsome point before its current enrollment, i.e. this is a\nre-enrollment rather than a first-time one.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "ownerId": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/DeviceStatus"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "isDdmEnrolled",
          "ddmEnrolledAt",
          "ddmLastSeenAt",
          "id",
          "name",
          "isInScope",
          "isArchived",
          "deviceInfo",
          "agentInfo",
          "status",
          "createdAt",
          "updatedAt"
        ]
      },
      "TenantDeviceList": {
        "properties": {
          "nextCursor": {
            "description": "Present only when another page is available. Pass as cursor with the same tenant.",
            "format": "uuid",
            "type": "string"
          },
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantDevice"
            },
            "type": "array"
          }
        }
      },
      "TenantDigestDefaultValue": {
        "properties": {
          "frequency": {
            "$ref": "#/components/schemas/DigestFrequency"
          },
          "hasOverride": {
            "description": "True when a TenantDigestDefault row exists for this (tenant, role).\n",
            "type": "boolean"
          },
          "isEnabled": {
            "type": "boolean"
          },
          "sections": {
            "items": {
              "$ref": "#/components/schemas/DigestSection"
            },
            "type": "array"
          }
        },
        "required": [
          "frequency",
          "sections",
          "isEnabled",
          "hasOverride"
        ],
        "type": "object"
      },
      "TenantDigestDefaults": {
        "description": "All digest defaults for a tenant in a single response. byRole always contains a key for every admin-visible role; values reflect stored rows where present, otherwise hardcoded defaults.",
        "properties": {
          "byRole": {
            "additionalProperties": {
              "$ref": "#/components/schemas/TenantDigestDefaultValue"
            },
            "type": "object"
          },
          "tenantId": {
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "tenantId",
          "byRole"
        ],
        "type": "object"
      },
      "TenantInvite": {
        "properties": {
          "createdAt": {
            "description": "The time that this tenant invite was created.",
            "format": "date-time",
            "type": "string"
          },
          "expires": {
            "description": "The time that this tenant invite expires.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the tenant invite.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "inviteeEmail": {
            "description": "The email address of the person who was invited.",
            "format": "email",
            "type": "string"
          },
          "inviteeName": {
            "description": "The name of the person who was invited.",
            "type": "string"
          },
          "inviterEmail": {
            "description": "The email address of the tenant member that created this invite.",
            "format": "email",
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/TenantRole"
          },
          "sentAt": {
            "description": "The time that this tenant invite was sent.",
            "format": "date-time",
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TenantInviteStatus"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this tenant invite.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantMemberId": {
            "description": "The ID of the tenant member associated with this tenant invite.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantName": {
            "description": "The name of the tenant this invite belongs to.",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this tenant invite was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "sentAt",
          "createdAt",
          "updatedAt",
          "inviterEmail",
          "inviteeEmail",
          "expires",
          "role",
          "tenantId",
          "status"
        ],
        "type": "object"
      },
      "TenantInviteList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantInvite"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "TenantInviteStatus": {
        "enum": [
          "PENDING",
          "ACCEPTED",
          "REJECTED",
          "DISABLED"
        ],
        "type": "string"
      },
      "TenantMember": {
        "properties": {
          "createdAt": {
            "description": "The time that this tenant member was created.",
            "format": "date-time",
            "type": "string"
          },
          "employmentEndDate": {
            "description": "The employment end date of the tenant member.",
            "format": "date-time",
            "type": "string"
          },
          "employmentStartDate": {
            "description": "The employment start date of the tenant member.",
            "format": "date-time",
            "type": "string"
          },
          "enableNotifications": {
            "description": "Whether or not to disable notifications for this tenant member.",
            "type": "boolean"
          },
          "groups": {
            "description": "The groups this tenant member is a part of.",
            "items": {
              "$ref": "#/components/schemas/Group"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "lastTasksReminderSentAt": {
            "description": "The time that this tenant member was last reminded of tasks to complete.",
            "format": "date-time",
            "type": "string"
          },
          "managerId": {
            "description": "The tenant member this member reports to; omitted when unset.",
            "format": "uuid",
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "role": {
            "$ref": "#/components/schemas/TenantRole"
          },
          "status": {
            "$ref": "#/components/schemas/TenantMemberStatus"
          },
          "tenant": {
            "$ref": "#/components/schemas/Tenant"
          },
          "tenantId": {
            "description": "The ID of the tenant associated with this tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/TenantMemberType"
          },
          "updatedAt": {
            "description": "The time that this tenant member was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/User"
          },
          "userPublic": {
            "$ref": "#/components/schemas/UserPublic"
          },
          "vendorAccounts": {
            "description": "The vendor accounts associated with this tenant member.",
            "items": {
              "$ref": "#/components/schemas/VendorAccountBase"
            },
            "type": "array"
          }
        },
        "required": [
          "id",
          "name",
          "type",
          "role",
          "status",
          "tenantId",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "TenantMemberList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantMember"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "TenantMemberShort": {
        "description": "A lightweight tenant member representation with display-relevant fields only.",
        "properties": {
          "groups": {
            "description": "The groups this tenant member belongs to.",
            "items": {
              "$ref": "#/components/schemas/GroupShort"
            },
            "type": "array"
          },
          "id": {
            "description": "The ID of the tenant member.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the tenant member.",
            "type": "string"
          },
          "user": {
            "description": "The user associated with this tenant member.",
            "properties": {
              "email": {
                "description": "The email of the user.",
                "type": "string"
              }
            },
            "required": [
              "email"
            ],
            "type": "object"
          }
        },
        "required": [
          "id",
          "name",
          "user",
          "groups"
        ],
        "type": "object"
      },
      "TenantMemberStatus": {
        "enum": [
          "NOT_ONBOARDED",
          "ONBOARDING",
          "CURRENT",
          "OFFBOARDING",
          "FORMER"
        ],
        "type": "string"
      },
      "TenantMemberType": {
        "enum": [
          "EMPLOYEE",
          "CONTRACTOR",
          "GUEST"
        ],
        "type": "string"
      },
      "TenantNotificationDefaults": {
        "description": "All notification defaults for a tenant in a single response. One entry per catalog notification; each entry carries values for every admin-visible role.",
        "properties": {
          "data": {
            "items": {
              "$ref": "#/components/schemas/NotificationDefaultEntry"
            },
            "type": "array"
          },
          "tenantId": {
            "format": "uuid",
            "type": "string"
          }
        },
        "required": [
          "tenantId",
          "data"
        ],
        "type": "object"
      },
      "TenantOnboardingStatus": {
        "description": "The onboarding status of the tenant.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "COMPLETED",
          "SKIPPED",
          "DEMO_CREATED",
          "DEMO_READY"
        ],
        "type": "string"
      },
      "TenantPolicyOnboardingStatus": {
        "description": "The policy onboarding status of the tenant.",
        "enum": [
          "NOT_STARTED",
          "IN_PROGRESS",
          "COMPLETED"
        ],
        "type": "string"
      },
      "TenantRole": {
        "enum": [
          "ADMIN",
          "MEMBER",
          "AUDITOR",
          "EMPLOYEE",
          "INVITED",
          "FORMER_EMPLOYEE"
        ],
        "type": "string"
      },
      "TenantTester": {
        "properties": {
          "createdAt": {
            "description": "The time that this tenant tester was created.",
            "format": "date-time",
            "type": "string"
          },
          "engagementId": {
            "description": "The ID of the engagement that this tenant tester is associated with.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "id": {
            "description": "The ID of the tenant tester.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "unassigned": {
            "description": "Whether or not this tenant tester is unassigned.",
            "type": "boolean"
          },
          "updatedAt": {
            "description": "The time that this tenant tester was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "user": {
            "$ref": "#/components/schemas/UserShort"
          },
          "version": {
            "description": "The version of the tenant tester.",
            "type": "number"
          }
        },
        "type": "object"
      },
      "TenantVendor": {
        "properties": {
          "assignedToMember": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "assignedToMemberId": {
            "description": "The ID of the member assigned to this vendor.",
            "type": "string"
          },
          "canEditVendorBranding": {
            "description": "Whether this tenant may set the vendor's logo and website through customVendorUrl. True only for a custom (unverified) vendor whose catalog row is this tenant's alone. Oneleet owns the branding of verified vendors, and of the vendors its discovery catalog suggests, whose one row several tenants link. Returned when reading a single tenant vendor; absent from list responses.",
            "type": "boolean"
          },
          "createdAt": {
            "description": "The time that this tenant vendor was created.",
            "format": "date-time",
            "type": "string"
          },
          "data": {
            "anyOf": [
              {
                "description": "JSON array of categorized risk assessment data for the tenant vendor.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              {
                "description": "JSON object with version number and categorized risk assessment data for the tenant vendor.",
                "type": "object"
              }
            ]
          },
          "deletedAt": {
            "description": "The time that this tenant vendor was soft-deleted. Absent for active vendors. A soft-deleted vendor is hidden from lists by default and can be restored.",
            "format": "date-time",
            "type": "string"
          },
          "evidence": {
            "description": "Evidence documents and files associated with this vendor.",
            "items": {
              "$ref": "#/components/schemas/Evidence"
            },
            "type": "array"
          },
          "hasCustomIntegrationConnection": {
            "description": "Whether the tenant vendor has a custom integration connection.",
            "type": "boolean"
          },
          "id": {
            "description": "The unique identifier of the tenant vendor.",
            "format": "uuid",
            "type": "string"
          },
          "integrationSkippedAt": {
            "description": "The time an admin skipped the vendor's Oneleet integration on the compliance journey. A skipped vendor is left out of the \"Connect your supported integrations\" step. Absent while the integration isn't skipped.",
            "format": "date-time",
            "type": "string"
          },
          "isCompleted": {
            "description": "Whether the vendor data is completely filled.",
            "type": "boolean"
          },
          "notes": {
            "description": "The notes for the tenant vendor.",
            "type": "string"
          },
          "processesPii": {
            "description": "If true, indicates this vendor processes personally identifiable information.",
            "type": "boolean"
          },
          "processingLocations": {
            "description": "An array of countries in which this vendor processes personal data",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "reviewedAt": {
            "description": "The time the vendor's risk assessment review was last completed. Absent while the review is not currently complete.",
            "format": "date-time",
            "type": "string"
          },
          "reviewedBy": {
            "$ref": "#/components/schemas/TenantMember"
          },
          "risk": {
            "$ref": "#/components/schemas/TenantVendorRisk"
          },
          "services": {
            "description": "An array of services this vendor provides",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "showAsSubprocessorInTrustCenter": {
            "description": "Whether this vendor is published as a subprocessor on the tenant's public trust page.",
            "type": "boolean"
          },
          "subprocessorDescription": {
            "description": "Free-form text shown next to services and locations on the public trust page.",
            "type": "string"
          },
          "tenantVendorDiscovery": {
            "$ref": "#/components/schemas/TenantVendorDiscovery"
          },
          "trustCenterServiceCount": {
            "description": "How many of the entries in `services` are published on the public trust page. Data Inventory vendors publish only the entries flagged to show on the trust center, so this can be lower than the length of `services`; for every other vendor all of them are published.",
            "type": "integer"
          },
          "updatedAt": {
            "description": "The time that this tenant vendor was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "usesDataInventory": {
            "description": "Whether this vendor has been migrated to the Data Inventory UI.",
            "type": "boolean"
          },
          "vendor": {
            "$ref": "#/components/schemas/Vendor"
          },
          "vendorAccounts": {
            "description": "The vendor accounts linked to the vendor.",
            "items": {
              "$ref": "#/components/schemas/VendorAccountBase"
            },
            "type": "array"
          },
          "vendorUrl": {
            "description": "URL of the vendor's website.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "vendor",
          "impact",
          "isCompleted",
          "hasCustomIntegrationConnection",
          "usesDataInventory",
          "showAsSubprocessorInTrustCenter",
          "trustCenterServiceCount"
        ],
        "type": "object"
      },
      "TenantVendorAssessment": {
        "properties": {
          "isCompleted": {
            "description": "Whether every applicable question is answered.",
            "type": "boolean"
          },
          "items": {
            "description": "Every questionnaire item, in display order.",
            "items": {
              "$ref": "#/components/schemas/TenantVendorAssessmentItem"
            },
            "type": "array"
          },
          "questionnaireVersion": {
            "description": "The questionnaire revision this vendor is on. Legacy questionnaires use a different set of item ids than current ones.",
            "type": "string"
          },
          "usesDataInventory": {
            "description": "Whether this vendor's data-storage details are managed by the data inventory instead of the questionnaire.",
            "type": "boolean"
          }
        },
        "required": [
          "questionnaireVersion",
          "isCompleted",
          "usesDataInventory",
          "items"
        ],
        "type": "object"
      },
      "TenantVendorAssessmentItem": {
        "properties": {
          "answer": {
            "anyOf": [
              {
                "description": "The selected option id or free-form text.",
                "type": "string"
              },
              {
                "description": "The selected option ids or country codes.",
                "items": {
                  "type": "string"
                },
                "type": "array"
              }
            ],
            "description": "The current answer. Absent when the question is unanswered."
          },
          "applicable": {
            "description": "Whether the question currently applies to this vendor. Inapplicable questions are hidden in the UI and excluded from completion; their answers are preserved and they can become applicable again when the answers gating them change.",
            "type": "boolean"
          },
          "category": {
            "description": "Title of the questionnaire category this item belongs to.",
            "type": "string"
          },
          "description": {
            "description": "Additional guidance for answering the question.",
            "type": "string"
          },
          "disabledInTemplate": {
            "description": "Whether the question is managed by the vendor's data inventory when data inventory is active for this vendor.",
            "type": "boolean"
          },
          "id": {
            "description": "The item id used as the key when updating answers.",
            "type": "string"
          },
          "options": {
            "description": "The selectable options. Absent for CountriesItem and TextItem, whose answers are not constrained to a list.",
            "items": {
              "$ref": "#/components/schemas/TenantVendorAssessmentOption"
            },
            "type": "array"
          },
          "shortLabel": {
            "description": "Short label for the question.",
            "type": "string"
          },
          "title": {
            "description": "The question text.",
            "type": "string"
          },
          "type": {
            "description": "The item type, which determines the answer value shape: YesNoItem/RadioItem/HighMediumLowItem take a single option id, MultiSelectItem takes an array of option ids, CountriesItem takes an array of uppercase ISO 3166-1 alpha-2 country codes, and TextItem takes a free-form string.",
            "enum": [
              "YesNoItem",
              "RadioItem",
              "HighMediumLowItem",
              "MultiSelectItem",
              "CountriesItem",
              "TextItem"
            ],
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "category",
          "applicable"
        ],
        "type": "object"
      },
      "TenantVendorAssessmentOption": {
        "properties": {
          "id": {
            "description": "The option id to use as the answer value.",
            "type": "string"
          },
          "label": {
            "description": "Human-readable label for the option.",
            "type": "string"
          },
          "risk": {
            "$ref": "#/components/schemas/TenantVendorRisk"
          }
        },
        "required": [
          "id"
        ],
        "type": "object"
      },
      "TenantVendorDiscovery": {
        "properties": {
          "category": {
            "description": "The category of the vendor.",
            "type": "string"
          },
          "id": {
            "description": "The unique identifier of the discovery.",
            "type": "string"
          },
          "integrationId": {
            "description": "The unique identifier of the integration which created this record.",
            "type": "string"
          },
          "oauthAccounts": {
            "description": "The OAuth accounts detected from the vendor.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "originalIcon": {
            "description": "The icon URL of the vendor.",
            "type": "string"
          },
          "originalName": {
            "description": "The name of the vendor.",
            "type": "string"
          },
          "originalUrl": {
            "description": "The URL of the vendor.",
            "type": "string"
          },
          "originalVendorId": {
            "description": "The custom vendor id even if a custom vendor wasn't made.",
            "type": "string"
          },
          "tenantId": {
            "description": "The unique identifier of the tenant which created this record.",
            "type": "string"
          },
          "vendor": {
            "$ref": "#/components/schemas/Vendor"
          },
          "vendorAccounts": {
            "description": "The vendor accounts linked to the vendor.",
            "items": {
              "$ref": "#/components/schemas/VendorAccountBase"
            },
            "type": "array"
          },
          "vendorId": {
            "description": "The identifier for the associated vendor.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "vendorId",
          "integrationId",
          "tenantId",
          "originalVendorId",
          "originalName"
        ],
        "type": "object"
      },
      "TenantVendorDiscoveryList": {
        "properties": {
          "discoveries": {
            "items": {
              "$ref": "#/components/schemas/TenantVendorDiscovery"
            },
            "type": "array",
            "x-go-name": "Discoveries"
          },
          "integrationTypes": {
            "items": {
              "$ref": "#/components/schemas/IntegrationType"
            },
            "type": "array",
            "x-go-name": "IntegrationTypes"
          },
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          }
        },
        "required": [
          "discoveries",
          "integrationTypes"
        ]
      },
      "TenantVendorList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/TenantVendor"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "required": [
          "rows"
        ]
      },
      "TenantVendorRisk": {
        "enum": [
          "LOW",
          "MEDIUM",
          "HIGH"
        ],
        "type": "string"
      },
      "TenantVendorStatus": {
        "enum": [
          "PROSPECTIVE",
          "TRACKED",
          "DENIED",
          "ARCHIVED"
        ],
        "type": "string"
      },
      "TenantVendorWithReviewer": {
        "properties": {
          "reviewerId": {
            "description": "The ID of the tenant member who is the reviewer.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantVendorId": {
            "description": "The ID of the vendor to review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "required": [
          "tenantVendorId",
          "reviewerId"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "TriggerDependencyScanBody": {
        "properties": {
          "repositoryIds": {
            "description": "List of repository ids. If omitted, all repositories with scanning enabled will be scanned.",
            "items": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            },
            "type": "array"
          }
        },
        "x-mcp-fields": true
      },
      "TrustDocument": {
        "properties": {
          "auditId": {
            "description": "The audit ID of the trust page document.",
            "type": "string"
          },
          "downloadUrl": {
            "description": "Presigned download URL; populated on authenticated surfaces only.",
            "type": "string"
          },
          "downloadable": {
            "description": "Whether a file can be downloaded via GET /api/v1/tenants/{slug}/trust/documents/{trust-document}/download-url.",
            "type": "boolean"
          },
          "evidenceId": {
            "description": "The evidence ID of the trust page document.",
            "type": "string"
          },
          "fileExtension": {
            "description": "The extension of the document's underlying file, without the leading dot.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the trust page document.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the trust page document.",
            "type": "string"
          },
          "order": {
            "description": "The order of the trust page document.",
            "type": "integer"
          },
          "pentestReportId": {
            "description": "The pentest report ID of the trust page document.",
            "type": "string"
          },
          "policyId": {
            "description": "The policy ID of the trust page document.",
            "type": "string"
          },
          "rawMarkdownToRender": {
            "description": "The raw markdown the browser can use to render a downloadable PDF.",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "type": {
            "$ref": "#/components/schemas/TrustDocumentType"
          },
          "visibility": {
            "$ref": "#/components/schemas/TrustDocumentVisibility"
          }
        },
        "required": [
          "id",
          "tenantId",
          "name",
          "type",
          "visibility",
          "order",
          "downloadable"
        ],
        "type": "object"
      },
      "TrustDocumentResponse": {
        "properties": {
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "document": {
            "$ref": "#/components/schemas/TrustDocument"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "requesterCompany": {
            "type": "string"
          },
          "requesterEmail": {
            "type": "string"
          },
          "requesterName": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TrustDocumentStatus"
          }
        },
        "required": [
          "id",
          "status",
          "createdAt",
          "requesterName",
          "requesterEmail",
          "requesterCompany"
        ],
        "type": "object"
      },
      "TrustDocumentStatus": {
        "enum": [
          "PENDING",
          "DENIED",
          "APPROVED"
        ],
        "type": "string"
      },
      "TrustDocumentType": {
        "enum": [
          "POLICY",
          "PENTEST_REPORT",
          "EVIDENCE_LIBRARY",
          "AUDIT_REPORT"
        ],
        "type": "string"
      },
      "TrustDocumentVisibility": {
        "enum": [
          "PUBLIC",
          "REQUEST_ONLY"
        ],
        "type": "string"
      },
      "TrustFaq": {
        "properties": {
          "answer": {
            "description": "The FAQ answer (markdown content).",
            "type": "string"
          },
          "createdAt": {
            "description": "The creation timestamp.",
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "description": "The ID of the trust FAQ.",
            "format": "uuid",
            "type": "string"
          },
          "question": {
            "description": "The FAQ question.",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant.",
            "format": "uuid",
            "type": "string"
          },
          "updatedAt": {
            "description": "The last update timestamp.",
            "format": "date-time",
            "type": "string"
          },
          "visibility": {
            "$ref": "#/components/schemas/TrustFaqVisibility"
          }
        },
        "required": [
          "id",
          "tenantId",
          "question",
          "answer",
          "visibility",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "TrustFaqVisibility": {
        "enum": [
          "PUBLIC",
          "PRIVATE"
        ],
        "type": "string"
      },
      "TrustPageConfigsResponse": {
        "properties": {
          "accentColor": {
            "type": "string"
          },
          "backlink": {
            "format": "uri",
            "type": "string"
          },
          "customDescription": {
            "type": "string"
          },
          "customPageName": {
            "type": "string"
          },
          "customTitle": {
            "type": "string"
          },
          "displaySubprocessors": {
            "type": "boolean"
          },
          "displayVdp": {
            "type": "boolean"
          },
          "email": {
            "type": "string"
          },
          "favicon": {
            "type": "string"
          },
          "headerColor": {
            "type": "string"
          },
          "isPublished": {
            "type": "boolean"
          },
          "logo": {
            "type": "string"
          },
          "statusPageLink": {
            "format": "uri",
            "type": "string"
          },
          "subprocessorTenantVendorIds": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "vdpAcceptedReports": {
            "type": "string"
          },
          "vdpDisclosurePolicy": {
            "type": "string"
          },
          "vdpHallOfFame": {
            "type": "string"
          },
          "vdpScope": {
            "type": "string"
          }
        },
        "required": [
          "isPublished"
        ],
        "type": "object"
      },
      "TrustSecurityIssueResponse": {
        "properties": {
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "reporterCompany": {
            "type": "string"
          },
          "reporterEmail": {
            "type": "string"
          },
          "reporterName": {
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/TrustSecurityIssueStatus"
          }
        },
        "required": [
          "id",
          "status",
          "createdAt",
          "reporterName",
          "reporterEmail",
          "reporterCompany",
          "description"
        ],
        "type": "object"
      },
      "TrustSecurityIssueStatus": {
        "enum": [
          "OPEN",
          "RESOLVED"
        ],
        "type": "string"
      },
      "UpdateAWSConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to monitor. Send an empty array to monitor all regions.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId"
        ]
      },
      "UpdateAWSv2ConnectionData": {
        "properties": {
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          },
          "selectedRegions": {
            "description": "The AWS region(s) to monitor. Send an empty array to monitor all regions.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "integrationTypeId"
        ]
      },
      "UpdateAccessReviewAccountRequest": {
        "properties": {
          "note": {
            "description": "Note on the account.",
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateAccessReviewRequest": {
        "properties": {
          "dueBy": {
            "description": "The due date of the access review.",
            "format": "date-time",
            "type": "string"
          },
          "ownerId": {
            "description": "The ID of the tenant member who owns the access review.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "status": {
            "$ref": "#/components/schemas/AccessReviewStatus"
          },
          "title": {
            "description": "The title of the access review.",
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateAccessReviewVendorRequest": {
        "properties": {
          "reviewNote": {
            "description": "Note attached to the vendor review.",
            "type": "string"
          },
          "reviewerId": {
            "description": "The ID of the tenant member who is the reviewer for this access review vendor.",
            "format": "uuid",
            "nullable": true,
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateActionRequest": {
        "properties": {
          "actionStatus": {
            "$ref": "#/components/schemas/ActionStatus"
          },
          "actionType": {
            "description": "Internal action type for filtering and searching.",
            "minLength": 1,
            "type": "string"
          },
          "addResourceUrns": {
            "description": "Resource URNs to link to the action. Applied in the same transaction as the field update so the edit is all-or-nothing.",
            "items": {
              "$ref": "#/components/schemas/AddActionResourceUrnRequest"
            },
            "type": "array"
          },
          "clearDescription": {
            "description": "Set to true to clear the description field.",
            "type": "boolean"
          },
          "clearDueDate": {
            "description": "Set to true to clear the due date field.",
            "type": "boolean"
          },
          "description": {
            "description": "Markdown description of the action.",
            "type": "string"
          },
          "dueDate": {
            "description": "Deadline for the action.",
            "format": "date-time",
            "type": "string"
          },
          "removeResourceUrns": {
            "description": "Resource URNs to unlink from the action, applied in the same transaction as the field update.",
            "items": {
              "$ref": "#/components/schemas/RemoveActionResourceUrnRequest"
            },
            "type": "array"
          },
          "summary": {
            "description": "One-line summary of the action.",
            "minLength": 1,
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateConnectionConfigurationData": {
        "discriminator": {
          "mapping": {
            "aws_v1": "#/components/schemas/UpdateAWSConnectionData",
            "aws_v2": "#/components/schemas/UpdateAWSv2ConnectionData",
            "custom_v1": "#/components/schemas/UpdateCustomConnectionData"
          },
          "propertyName": "integrationTypeId"
        },
        "oneOf": [
          {
            "$ref": "#/components/schemas/UpdateCustomConnectionData"
          },
          {
            "$ref": "#/components/schemas/UpdateAWSConnectionData"
          },
          {
            "$ref": "#/components/schemas/UpdateAWSv2ConnectionData"
          }
        ],
        "type": "object"
      },
      "UpdateConnectionConfigurationRequest": {
        "properties": {
          "configuration": {
            "$ref": "#/components/schemas/UpdateConnectionConfigurationData"
          },
          "label": {
            "description": "User-created label for the connection",
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateCustomConnectionData": {
        "properties": {
          "authCredentials": {
            "description": "New auth credentials. Omit to keep existing credentials.",
            "properties": {
              "apiKey": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "customConfig": {
            "description": "The full custom integration config (non-sensitive fields).",
            "type": "object"
          },
          "integrationTypeId": {
            "description": "The ID of the integration type.",
            "type": "string"
          }
        },
        "required": [
          "integrationTypeId",
          "customConfig"
        ]
      },
      "UpdateGitRepositoryPackageFindingBody": {
        "properties": {
          "clear": {
            "description": "Fields to clear/unset.",
            "properties": {
              "ownerId": {
                "description": "Set to true to clear the owner assignment.",
                "type": "boolean"
              },
              "resolution": {
                "description": "Set to true to clear the resolution.",
                "type": "boolean"
              }
            },
            "type": "object"
          },
          "ownerId": {
            "description": "The ID of the tenant member to assign as the owner of the finding.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "resolution": {
            "$ref": "#/components/schemas/PackageFindingResolution"
          }
        },
        "x-mcp-fields": true
      },
      "UpdateIntegrationRequest": {
        "properties": {
          "clear": {
            "description": "An object containing any fields that should be cleared.",
            "properties": {
              "ownerId": {
                "description": "If true, removes the integration's owner.",
                "type": "boolean"
              }
            },
            "type": "object"
          },
          "ownerId": {
            "description": "The ID of the tenant member to make accountable for this integration.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateRiskAssessmentRequest": {
        "properties": {
          "completedAt": {
            "description": "The time that this risk assessment was completed.",
            "format": "date-time",
            "type": "string"
          },
          "riskMatrixSize": {
            "$ref": "#/components/schemas/RiskMatrixSize"
          },
          "title": {
            "description": "Required when set alongside completedAt for the first time: names the snapshot being taken (recommended default: \"\u003cMonth Year\u003e Risk Assessment\"). Omitting it on a completing request is a 400. Not required, and has no effect, on a plain update that doesn't complete the assessment. The register opened automatically after completion always gets the same fixed \"Your active risks\" placeholder as any other open register -- it has no name of its own until it, in turn, is completed.",
            "type": "string"
          }
        },
        "x-mcp-fields": true
      },
      "UpdateRiskRequest": {
        "properties": {
          "category": {
            "$ref": "#/components/schemas/RiskCategory"
          },
          "clear": {
            "description": "An object containing any fields that should be cleared.",
            "properties": {
              "hasResidualRisk": {
                "description": "If true, clears the has residual risk value.",
                "type": "boolean"
              },
              "impact": {
                "description": "If true, clears the impact value.",
                "type": "boolean"
              },
              "likelihood": {
                "description": "If true, clears the likelihood value.",
                "type": "boolean"
              },
              "note": {
                "description": "If true, clears the note value.",
                "type": "boolean"
              },
              "residualImpact": {
                "description": "If true, clears the residual impact value.",
                "type": "boolean"
              },
              "residualLikelihood": {
                "description": "If true, clears the residual likelihood value.",
                "type": "boolean"
              },
              "response": {
                "description": "If true, clears the response value.",
                "type": "boolean"
              }
            },
            "type": "object"
          },
          "controls": {
            "items": {
              "$ref": "#/components/schemas/LinkRiskControl"
            },
            "type": "array"
          },
          "description": {
            "description": "The description of the risk.",
            "type": "string"
          },
          "hasResidualRisk": {
            "description": "Whether the risk has a residual risk.",
            "type": "boolean"
          },
          "impact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "likelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "note": {
            "description": "Additional notes or comments about the risk.",
            "type": "string"
          },
          "ownerId": {
            "description": "The ID of the owner associated with this risk.",
            "type": "string"
          },
          "residualImpact": {
            "$ref": "#/components/schemas/RiskImpact"
          },
          "residualLikelihood": {
            "$ref": "#/components/schemas/RiskLikelihood"
          },
          "response": {
            "$ref": "#/components/schemas/RiskResponse"
          },
          "responseDetails": {
            "description": "The details of the risk response.",
            "type": "string"
          },
          "title": {
            "description": "The title of the risk.",
            "type": "string"
          }
        },
        "x-mcp-fields": true
      },
      "UpdateTenantVendorAssessmentRequest": {
        "properties": {
          "answers": {
            "additionalProperties": {},
            "description": "Map of item id to answer value. Value shape depends on the item type: a single option id string for YesNoItem/RadioItem/HighMediumLowItem, an array of option ids for MultiSelectItem, an array of uppercase ISO 3166-1 alpha-2 country codes for CountriesItem, or a free-form string for TextItem. Send null (or an empty string / empty array) to clear an answer.",
            "minProperties": 1,
            "type": "object"
          }
        },
        "required": [
          "answers"
        ],
        "type": "object",
        "x-mcp-fields": true
      },
      "UpdateVendorDataInventoryItem": {
        "properties": {
          "description": {
            "description": "What data the vendor holds. At most 3000 characters. Omit to keep the current value.",
            "maxLength": 3000,
            "minLength": 1,
            "type": "string"
          },
          "sensitivityLevel": {
            "allOf": [
              {
                "$ref": "#/components/schemas/DataSensitivityLevel"
              }
            ],
            "description": "How sensitive the data is. Omit to keep the current value."
          },
          "tagIds": {
            "description": "Replaces the item's whole tag set. Omit to keep the current tags; send an empty array to remove every tag. Unknown ids are rejected.",
            "items": {
              "format": "uuid",
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object",
        "x-mcp-fields": true
      },
      "User": {
        "properties": {
          "changelogAcknowledgedAt": {
            "description": "The last changelog entry date the user acknowledged before entries were\ntracked individually. Entries dated on or before it count as seen. Null\nif never acknowledged.\n",
            "format": "date-time",
            "nullable": true,
            "type": "string"
          },
          "changelogSeenSlugs": {
            "description": "Slugs of the in-app changelog entries the user has viewed.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "createdAt": {
            "description": "The time that this user was created.",
            "format": "date-time",
            "type": "string"
          },
          "email": {
            "description": "The email address of the user.",
            "format": "email",
            "type": "string"
          },
          "emailVerified": {
            "description": "Whether the user has verified their email address.",
            "type": "boolean"
          },
          "id": {
            "description": "The ID of the user.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          },
          "oneleetRole": {
            "$ref": "#/components/schemas/OneleetRole"
          },
          "oneleetStaffScheduleCallUrl": {
            "description": "Scheduling-page URL (e.g. Calendly) for Oneleet staff. Shown to tenants\nthis user owns so they can book a call with their assigned Oneleet\ncontact. Omitted for non-staff users and staff without a configured URL.\n",
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this user was last updated.",
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "name",
          "email",
          "emailVerified",
          "oneleetRole"
        ],
        "type": "object"
      },
      "UserPublic": {
        "properties": {
          "email": {
            "description": "The email address of the user.",
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          }
        },
        "required": [
          "email",
          "name"
        ],
        "type": "object"
      },
      "UserShort": {
        "properties": {
          "email": {
            "description": "The email address of the user.",
            "format": "email",
            "type": "string"
          },
          "id": {
            "description": "The ID of the user.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "name": {
            "description": "The name of the user.",
            "type": "string"
          },
          "oneleetRole": {
            "$ref": "#/components/schemas/OneleetRole"
          }
        },
        "required": [
          "id",
          "name",
          "email",
          "oneleetRole"
        ],
        "type": "object"
      },
      "Vendor": {
        "properties": {
          "assessmentTemplate": {
            "description": "The vendor's pre-defined risk assessment template.",
            "type": "object"
          },
          "category": {
            "description": "The category of the vendor.",
            "type": "string"
          },
          "complianceData": {
            "items": {
              "$ref": "#/components/schemas/VendorComplianceData"
            },
            "type": "array"
          },
          "icon": {
            "description": "The icon URL of the vendor.",
            "type": "string"
          },
          "id": {
            "description": "The unique identifier of the vendor.",
            "type": "string"
          },
          "integrationType": {
            "$ref": "#/components/schemas/IntegrationType"
          },
          "name": {
            "description": "The name of the vendor.",
            "type": "string"
          },
          "supportsAccountDetection": {
            "description": "Whether this vendor supports automatic account detection through a Oneleet integration.",
            "type": "boolean"
          },
          "url": {
            "description": "The URL of the vendor.",
            "type": "string"
          },
          "verified": {
            "description": "Whether the vendor is verified.",
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "name",
          "verified"
        ]
      },
      "VendorAccount": {
        "allOf": [
          {
            "$ref": "#/components/schemas/VendorAccountBase"
          },
          {
            "properties": {
              "tenantMember": {
                "$ref": "#/components/schemas/TenantMember"
              }
            },
            "type": "object"
          }
        ]
      },
      "VendorAccountBase": {
        "properties": {
          "asset": {
            "$ref": "#/components/schemas/Asset"
          },
          "assetId": {
            "description": "The ID of the asset this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "connection": {
            "$ref": "#/components/schemas/Connection"
          },
          "connectionId": {
            "description": "The ID of the connection this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "createdAt": {
            "description": "The time that this vendor account was created.",
            "format": "date-time",
            "type": "string"
          },
          "email": {
            "description": "The email of the user for this vendor account.",
            "type": "string"
          },
          "id": {
            "description": "The ID of the vendor account.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "ignoreReason": {
            "description": "The reason the account was ignored, if it is ignored.",
            "type": "string"
          },
          "ignoredAt": {
            "description": "The time the account was ignored, if it is ignored.",
            "format": "date-time",
            "type": "string"
          },
          "ignoredById": {
            "description": "The ID of the tenant member who ignored the account, if it is ignored.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "image": {
            "description": "The profile image URL of the user for this vendor account.",
            "type": "string"
          },
          "isActive": {
            "description": "Whether the account is active or not.",
            "type": "boolean"
          },
          "isIgnored": {
            "description": "Whether the account has been ignored or not.",
            "type": "boolean"
          },
          "isMfaEnabled": {
            "description": "Whether the user is enabled for MFA.",
            "type": "boolean"
          },
          "isSnoozed": {
            "description": "Whether the account is currently snoozed, i.e. snoozedUntil is in the future. Snoozed accounts are hidden from detected-accounts review until the snooze ends.",
            "type": "boolean"
          },
          "name": {
            "description": "The name of the user for this vendor account.",
            "type": "string"
          },
          "roles": {
            "description": "The roles of the user for this vendor account.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "snoozedAt": {
            "description": "The time the account was snoozed, if it has been snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "snoozedById": {
            "description": "The ID of the tenant member who snoozed the account, if it has been snoozed.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "snoozedReason": {
            "description": "The reason the account was snoozed, if it has been snoozed.",
            "type": "string"
          },
          "snoozedUntil": {
            "description": "The time the snooze ends, if the account has been snoozed.",
            "format": "date-time",
            "type": "string"
          },
          "tenantId": {
            "description": "The ID of the tenant this vendor account belongs to.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "tenantMemberId": {
            "description": "The ID of the member this account belongs to, if null the account has not been linked to any member yet.",
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          },
          "updatedAt": {
            "description": "The time that this vendor account was last updated.",
            "format": "date-time",
            "type": "string"
          },
          "username": {
            "description": "The username of the user for this vendor account.",
            "type": "string"
          }
        },
        "required": [
          "id",
          "createdAt",
          "updatedAt",
          "tenantId",
          "connectionId",
          "isActive",
          "isIgnored",
          "isSnoozed"
        ],
        "type": "object"
      },
      "VendorAccountList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/VendorAccount"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        }
      },
      "VendorComplianceData": {
        "properties": {
          "id": {
            "description": "The compliance framework ID",
            "type": "string"
          },
          "name": {
            "description": "The name of the compliance framework",
            "type": "string"
          },
          "reportUrl": {
            "description": "The URL to request the compliance report from the vendor",
            "type": "string"
          },
          "url": {
            "description": "The URL of the vendor's compliance data",
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "url"
        ],
        "type": "object"
      },
      "VendorDataInventoryItem": {
        "properties": {
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "description": {
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "sensitivityLevel": {
            "$ref": "#/components/schemas/DataSensitivityLevel"
          },
          "showOnTrustCenter": {
            "type": "boolean"
          },
          "tags": {
            "items": {
              "$ref": "#/components/schemas/VendorDataInventoryTag"
            },
            "type": "array"
          },
          "tenantVendorId": {
            "format": "uuid",
            "type": "string"
          },
          "updatedAt": {
            "format": "date-time",
            "type": "string"
          }
        },
        "required": [
          "id",
          "tenantVendorId",
          "description",
          "sensitivityLevel",
          "showOnTrustCenter",
          "tags",
          "createdAt",
          "updatedAt"
        ],
        "type": "object"
      },
      "VendorDataInventoryItemList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/VendorDataInventoryItem"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "VendorDataInventoryTag": {
        "properties": {
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isSystemTag": {
            "type": "boolean"
          },
          "name": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "name",
          "isSystemTag"
        ],
        "type": "object"
      },
      "VendorDataInventoryTagList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/VendorDataInventoryTag"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      },
      "VendorList": {
        "properties": {
          "pagination": {
            "$ref": "#/components/schemas/PaginationResponse"
          },
          "rows": {
            "items": {
              "$ref": "#/components/schemas/Vendor"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "required": [
          "rows"
        ]
      },
      "VendorRequest": {
        "properties": {
          "businessJustification": {
            "type": "string"
          },
          "createdAt": {
            "format": "date-time",
            "type": "string"
          },
          "dataDescription": {
            "type": "string"
          },
          "decidedAt": {
            "format": "date-time",
            "type": "string"
          },
          "id": {
            "format": "uuid",
            "type": "string"
          },
          "isAssessmentComplete": {
            "description": "Whether the vendor's risk assessment is answered in full. Only sent to the reviewer queue.",
            "type": "boolean"
          },
          "isAssessmentStarted": {
            "description": "Whether any question in the vendor's risk assessment has been answered. Only sent to the reviewer queue.",
            "type": "boolean"
          },
          "requesterId": {
            "format": "uuid",
            "type": "string"
          },
          "reviewedAt": {
            "description": "When the vendor's risk assessment was last reviewed. Only sent to the reviewer queue.",
            "format": "date-time",
            "type": "string"
          },
          "reviewedById": {
            "description": "Who last reviewed the vendor's risk assessment. Only sent to the reviewer queue.",
            "format": "uuid",
            "type": "string"
          },
          "risk": {
            "$ref": "#/components/schemas/TenantVendorRisk"
          },
          "status": {
            "$ref": "#/components/schemas/TenantVendorStatus"
          },
          "statusReason": {
            "description": "Why the current status was set, for example a denial reason",
            "type": "string"
          },
          "tenantVendorId": {
            "format": "uuid",
            "type": "string"
          },
          "vendorName": {
            "type": "string"
          },
          "vendorUrl": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "tenantVendorId",
          "requesterId",
          "vendorName",
          "businessJustification",
          "dataDescription",
          "status",
          "createdAt"
        ],
        "type": "object"
      },
      "VendorRequestList": {
        "properties": {
          "rows": {
            "items": {
              "$ref": "#/components/schemas/VendorRequest"
            },
            "type": "array",
            "x-go-name": "Rows"
          }
        },
        "required": [
          "rows"
        ],
        "type": "object"
      }
    },
    "securitySchemes": {
      "bearerAuth": {
        "description": "A tenant service key (service_\u003cid\u003e_\u003csecret\u003e) or an MCP OAuth access token. Each operation names the scope the credential must hold in its x-service-key-scope extension and under Required scope in its description. A service key holds the scopes an administrator grants it; an OAuth access token holds the scopes approved on the consent screen and is further limited by the user's role.",
        "scheme": "bearer",
        "type": "http"
      },
      "cookieAuth": {
        "in": "cookie",
        "name": "oneleet",
        "type": "apiKey"
      }
    }
  },
  "info": {
    "description": "Operations a tenant service key or an MCP OAuth access token can call, and the MCP OAuth sign-in endpoints, which authenticate with the signed session token in the request body. The same host also serves the routes behind the Oneleet web application. Those routes aren't part of the public API: they aren't listed here, they can change without notice, and they answer a service key or an OAuth access token with 401. Audit-firm integrations use the separate [Auditor API reference](./auditor/api-reference).",
    "title": "Oneleet Public API",
    "version": "1.0.0"
  },
  "openapi": "3.0.3",
  "paths": {
    "/api/v1/access-review-accounts/{access-review-account}": {
      "patch": {
        "description": "Update access review account status.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewAccountUpdate",
        "parameters": [
          {
            "description": "The id of the access review account",
            "in": "path",
            "name": "access-review-account",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateAccessReviewAccountRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update access review account status.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-review-vendors/{access-review-vendor}": {
      "delete": {
        "description": "Remove a vendor from access review.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorDelete",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Remove a vendor from access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      },
      "get": {
        "description": "Get an access review vendor with its accounts and diff data comparing against the previous completed review for the same vendor.\n\n**Required scope:** `READ_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorGet",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AccessReviewVendor"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get access review vendor details with diff data.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "READ_ACCESSREVIEWS"
      },
      "patch": {
        "description": "Update an access review vendor\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorUpdate",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateAccessReviewVendorRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update an access review vendor",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-review-vendors/{access-review-vendor}/mark-as-reviewed": {
      "post": {
        "description": "Mark an access review vendor as reviewed, snapshotting all linked accounts.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorUpdateMarkAsReviewed",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "multipart/form-data": {
              "schema": {
                "$ref": "#/components/schemas/MarkAccessReviewVendorAsReviewedRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Mark an access review vendor as reviewed.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-review-vendors/{access-review-vendor}/mark-as-unreviewed": {
      "post": {
        "description": "Mark an access review vendor as unreviewed, restoring live account links.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorUpdateMarkAsUnreviewed",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Success - Vendor was re-opened"
          },
          "204": {
            "description": "No Content - Vendor was deleted because the source tenant vendor no longer exists"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Mark an access review vendor as unreviewed.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-review-vendors/{access-review-vendor}/review-attachment/download-url": {
      "get": {
        "description": "Get a fresh presigned download URL for the review attachment on an access review vendor.\n\n**Required scope:** `READ_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorGetReviewAttachmentDownloadUrl",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AccessReviewVendorReviewAttachmentDownloadUrlResponse"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Review attachment not found"
          }
        },
        "summary": "Get a presigned download URL for an access review vendor attachment.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "READ_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-review-vendors/{access-review-vendor}/sync-accounts": {
      "post": {
        "description": "Trigger an on-demand sync of user account data from the source integration for the vendor being reviewed.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorUpdateSyncAccounts",
        "parameters": [
          {
            "description": "The id of the access review vendor",
            "in": "path",
            "name": "access-review-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Sync triggered successfully"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "422": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Unprocessable entity"
          }
        },
        "summary": "Sync accounts for an access review vendor.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-reviews/{access-review}": {
      "delete": {
        "description": "Delete access review.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewDelete",
        "parameters": [
          {
            "description": "The id of the access review",
            "in": "path",
            "name": "access-review",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Delete access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      },
      "get": {
        "description": "Get access review details.\n\n**Required scope:** `READ_ACCESSREVIEWS`",
        "operationId": "AccessReviewGet",
        "parameters": [
          {
            "description": "The id of the access review",
            "in": "path",
            "name": "access-review",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AccessReview"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get access review details.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "READ_ACCESSREVIEWS"
      },
      "patch": {
        "description": "Update access review.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewUpdate",
        "parameters": [
          {
            "description": "The id of the access review",
            "in": "path",
            "name": "access-review",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateAccessReviewRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-reviews/{access-review}/create-vendor": {
      "post": {
        "description": "Add a vendor to access review.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewVendorCreate",
        "parameters": [
          {
            "description": "The id of the access review",
            "in": "path",
            "name": "access-review",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TenantVendorWithReviewer"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Add a vendor to access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/access-reviews/{access-review}/restore": {
      "post": {
        "description": "Restore a soft-deleted access review.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewUpdateRestore",
        "parameters": [
          {
            "description": "The id of the access review to restore",
            "in": "path",
            "name": "access-review",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "No Content"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Restore an access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/actions/{action-id}": {
      "delete": {
        "description": "Delete an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionDelete",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Delete an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      },
      "get": {
        "description": "Get action details including members, groups, and resource URNs.\n\n**Required scope:** `READ_ACTIONS`",
        "operationId": "ActionGet",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Get action details.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "READ_ACTIONS"
      },
      "patch": {
        "description": "Update action fields (summary, description, status, etc).\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdate",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateActionRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Update an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/add-group": {
      "post": {
        "description": "Add a group with a role to an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateAddGroup",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AddActionGroupRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Add a group to an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/add-member": {
      "post": {
        "description": "Add a tenant member with a role to an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateAddMember",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AddActionMemberRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Add a member to an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/add-resource-urn": {
      "post": {
        "description": "Link a resource to an action with a relationship type.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateAddResourceUrn",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AddActionResourceUrnRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Add a resource URN to an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/remove-group": {
      "post": {
        "description": "Remove a group with a specific role from an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateRemoveGroup",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveActionGroupRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Remove a group from an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/remove-member": {
      "post": {
        "description": "Remove a tenant member with a specific role from an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateRemoveMember",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveActionMemberRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Remove a member from an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/actions/{action-id}/remove-resource-urn": {
      "post": {
        "description": "Unlink a resource from an action.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateRemoveResourceUrn",
        "parameters": [
          {
            "description": "The id of the action",
            "in": "path",
            "name": "action-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveActionResourceUrnRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Action not found"
          }
        },
        "summary": "Remove a resource URN from an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/connections/{connection}": {
      "delete": {
        "description": "Delete an integration connection\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "ConnectionDelete",
        "parameters": [
          {
            "description": "The connection id",
            "in": "path",
            "name": "connection",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Connection successfully deleted"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Delete connection",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      },
      "patch": {
        "description": "Update an integration connection configuration\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "ConnectionUpdateConfiguration",
        "parameters": [
          {
            "description": "The connection id",
            "in": "path",
            "name": "connection",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateConnectionConfigurationRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Connection successfully updated"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update connection configuration",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      },
      "put": {
        "description": "Reconnect an integration's connection\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "ConnectionUpdateReconnect",
        "parameters": [
          {
            "description": "The connection id",
            "in": "path",
            "name": "connection",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateConnectionRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Connection successfully updated"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Reconnect the connection",
        "tags": [
          "Integration"
        ],
        "x-feature-flag": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      }
    },
    "/api/v1/connections/{connection}/asset-statuses": {
      "get": {
        "description": "List asset statuses for a connection\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "ConnectionGetAssetStatuses",
        "parameters": [
          {
            "description": "The connection id",
            "in": "path",
            "name": "connection",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AssetStatusList"
                }
              }
            },
            "description": "A list of asset statuses for this connection"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List connection asset statuses",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      }
    },
    "/api/v1/controls/{control}": {
      "get": {
        "description": "Get a control by id.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlGet",
        "parameters": [
          {
            "description": "The id of the control to get",
            "in": "path",
            "name": "control",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Control"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Control not found"
          }
        },
        "summary": "Get a control by id.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/controls/{control}/activities": {
      "get": {
        "description": "List activities for a control.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlGetActivities",
        "parameters": [
          {
            "description": "The id of the control to get activities for",
            "in": "path",
            "name": "control",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityList"
                }
              }
            },
            "description": "Successfully listed activities"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List activities for a control.",
        "tags": [
          "Control"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/controls/{control}/checks": {
      "get": {
        "description": "List checks for a control.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "CheckList",
        "parameters": [
          {
            "description": "The id of the control to get checks for",
            "in": "path",
            "name": "control",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CheckList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List control checks.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/evidence/{evidence}": {
      "get": {
        "description": "Get an evidence by id.\n\n**Required scope:** `READ_EVIDENCE`",
        "operationId": "EvidenceGet",
        "parameters": [
          {
            "description": "The id of the evidence to get",
            "in": "path",
            "name": "evidence",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Evidence"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Evidence not found"
          }
        },
        "summary": "Get an evidence by id.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_EVIDENCE"
      }
    },
    "/api/v1/evidence/{evidence}/download-url": {
      "get": {
        "description": "Get a fresh presigned download URL for a file or image evidence.\n\n**Required scope:** `READ_EVIDENCE`",
        "operationId": "EvidenceGetDownloadUrl",
        "parameters": [
          {
            "description": "The id of the evidence to get a download URL for",
            "in": "path",
            "name": "evidence",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/EvidenceDownloadUrlResponse"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Evidence not found"
          }
        },
        "summary": "Get a presigned download URL for an evidence file.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_EVIDENCE"
      }
    },
    "/api/v1/evidence/{evidence}/link": {
      "post": {
        "description": "Link an evidence to a control and optionally an evidence request.\n\n**Required scope:** `WRITE_EVIDENCE`",
        "operationId": "EvidenceUpdateLink",
        "parameters": [
          {
            "description": "The id of the evidence to link",
            "in": "path",
            "name": "evidence",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/LinkEvidenceRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Evidence"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Evidence not found"
          }
        },
        "summary": "Link an evidence to a control and optionally an evidence request.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_EVIDENCE"
      }
    },
    "/api/v1/git-repository/{git-repository}/code-security-scans": {
      "post": {
        "description": "Queue a code security scan of the git repository's default branch\n\n**Required scope:** `WRITE_GIT_REPOSITORY_CONTENTS`",
        "operationId": "GitRepositoryCreateCodeSecurityScan",
        "parameters": [
          {
            "description": "Git repository id",
            "in": "path",
            "name": "git-repository",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "202": {
            "description": "Successfully queued a code security scan"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Git repository not found"
          }
        },
        "summary": "Queue a code security scan",
        "tags": [
          "Git Repositories"
        ],
        "x-feature-flags": [
          "code-security"
        ],
        "x-service-key-scope": "WRITE_GIT_REPOSITORY_CONTENTS"
      }
    },
    "/api/v1/git-repository/{git-repository}/pull-requests": {
      "post": {
        "description": "Create a pull request from a patch for a git repository\n\n**Required scope:** `WRITE_GIT_REPOSITORY_CONTENTS`",
        "operationId": "GitRepositoryCreatePullRequest",
        "parameters": [
          {
            "description": "Git repository id",
            "in": "path",
            "name": "git-repository",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "properties": {
                  "commitMessage": {
                    "description": "Commit message for the patch commit",
                    "maxLength": 65536,
                    "minLength": 1,
                    "type": "string"
                  },
                  "description": {
                    "description": "Body/description of the pull request",
                    "maxLength": 65536,
                    "type": "string"
                  },
                  "patchToken": {
                    "description": "Opaque token identifying the patch to apply",
                    "maxLength": 220,
                    "minLength": 1,
                    "pattern": "^[_a-z0-9][-_a-z0-9]{0,219}$",
                    "type": "string"
                  },
                  "title": {
                    "description": "Title of the pull request",
                    "maxLength": 256,
                    "minLength": 1,
                    "type": "string"
                  }
                },
                "required": [
                  "patchToken",
                  "commitMessage",
                  "title"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "pullRequestUrl": {
                      "description": "URL of the created pull request",
                      "type": "string"
                    }
                  },
                  "required": [
                    "pullRequestUrl"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Successfully created the pull request"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Git repository or patch not found"
          }
        },
        "summary": "Create a pull request from a patch",
        "tags": [
          "Git Repositories"
        ],
        "x-feature-flags": [
          "code-security",
          "autofixes"
        ],
        "x-service-key-scope": "WRITE_GIT_REPOSITORY_CONTENTS"
      }
    },
    "/api/v1/integrations/{integration}": {
      "delete": {
        "description": "Delete an integration by id\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "IntegrationDelete",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Integration successfully deleted"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Delete integration",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      },
      "get": {
        "description": "Get an integration by id\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationGet",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Integration"
                }
              }
            },
            "description": "Integration successfully fetched"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get integration",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      },
      "patch": {
        "description": "Update an integration's basic fields. Omitted fields keep their current value.\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "IntegrationUpdate",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateIntegrationRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "204": {
            "description": "Integration successfully updated"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Integration not found"
          }
        },
        "summary": "Update integration",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      }
    },
    "/api/v1/integrations/{integration}/connections": {
      "post": {
        "description": "Create a new integration connection\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "ConnectionCreate",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateConnectionRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Connection"
                }
              }
            },
            "description": "Connection successfully created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The integration already has a connection for this account"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Internal server error"
          }
        },
        "summary": "Create connection",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      }
    },
    "/api/v1/integrations/{integration}/has-applicable-monitors": {
      "get": {
        "description": "Check if an integration has monitor types that apply to the tenant's current compliance frameworks\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationGetHasApplicableMonitors",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntegrationHasApplicableMonitorsResponse"
                }
              }
            },
            "description": "Whether the integration has applicable monitors"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Check if integration has applicable monitors",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      }
    },
    "/api/v1/integrations/{integration}/status-updates": {
      "get": {
        "description": "List status updates for an integration\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationListStatusMessages",
        "parameters": [
          {
            "description": "The integration id",
            "in": "path",
            "name": "integration",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntegrationStatusUpdateList"
                }
              }
            },
            "description": "A list of status updates"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List status updates",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      }
    },
    "/api/v1/mcp/connect/continuation": {
      "post": {
        "description": "Validates the session token and the user's membership in the selected tenant, then returns the Auth0 /continue redirect URL carrying a signed continuation token. Called without a tenant when the user has no memberships, which yields a signed denial for the Action to reject the login with.",
        "operationId": "McpConnectCreateContinuation",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MCPConnectContinuationRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MCPConnectContinuation"
                }
              }
            },
            "description": "Auth0 /continue URL carrying the signed continuation token"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A tenant selection is required for this user"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Invalid or expired session token"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The user is not a member of the selected tenant"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "MCP OAuth is not enabled on this instance"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The source IP has used up its request budget for the tenant-picker endpoints",
            "headers": {
              "Retry-After": {
                "description": "Seconds until the source IP can retry",
                "schema": {
                  "type": "integer"
                }
              }
            }
          }
        },
        "security": [],
        "summary": "Issue a signed MCP tenant-picker continuation",
        "tags": [
          "MCP"
        ],
        "x-public-api-reference": true
      }
    },
    "/api/v1/mcp/connect/picker-session": {
      "post": {
        "description": "Validates the signed session token from the Auth0 redirect Action and returns the picker context for the signing-in user - the OAuth client requesting access, the tenants the user may bind it to, and why there are none when the list is empty.",
        "operationId": "McpConnectCreatePickerSession",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MCPConnectPickerSessionRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MCPConnectPickerSession"
                }
              }
            },
            "description": "Picker context for the session"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Invalid or expired session token"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "MCP OAuth is not enabled on this instance"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The source IP has used up its request budget for the tenant-picker endpoints",
            "headers": {
              "Retry-After": {
                "description": "Seconds until the source IP can retry",
                "schema": {
                  "type": "integer"
                }
              }
            }
          }
        },
        "security": [],
        "summary": "Resolve MCP tenant-picker session context",
        "tags": [
          "MCP"
        ],
        "x-public-api-reference": true
      }
    },
    "/api/v1/monitors/{monitor}": {
      "get": {
        "description": "Get a monitor\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorGet",
        "parameters": [
          {
            "description": "The ID of the monitor to get",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Monitor"
                }
              }
            },
            "description": "Successfully got the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get a monitor",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/asset-result-snapshots/latest": {
      "get": {
        "description": "Get the latest asset result snapshots for a monitor\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorResultSnapshotList",
        "parameters": [
          {
            "description": "The ID of the monitor to get the latest results for",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ResultSnapshotList"
                }
              }
            },
            "description": "Successfully got the latest result snapshots for the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get the latest asset results for a monitor",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/asset-results": {
      "get": {
        "description": "List the monitor's asset results from the MonitorAssetResult table, paginated and filterable.\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorAssetResultList",
        "parameters": [
          {
            "description": "The ID of the monitor to list asset results for",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Filter by asset result status.",
            "in": "query",
            "name": "status",
            "schema": {
              "$ref": "#/components/schemas/MonitorAssetResultStatus"
            }
          },
          {
            "description": "Comma-separated list of connection IDs to filter by.",
            "in": "query",
            "name": "connectionIds",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Case-insensitive substring match against asset name or connection readable ID.",
            "in": "query",
            "name": "search",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Row ordering. \"status\" orders by severity (breaching SLA first), \"connection\" by connection readable ID, \"name\" by asset name; asset name is always the tiebreaker.",
            "in": "query",
            "name": "sortBy",
            "schema": {
              "default": "status",
              "enum": [
                "status",
                "connection",
                "name"
              ],
              "type": "string"
            }
          },
          {
            "description": "Orders rows within the sortBy ordering by when they breach their SLA. \"most-urgent\" puts the earliest breach time first; rows with no SLA clock sort last (reversed for \"least-urgent\").",
            "in": "query",
            "name": "urgencySort",
            "schema": {
              "default": "most-urgent",
              "enum": [
                "most-urgent",
                "least-urgent"
              ],
              "type": "string"
            }
          },
          {
            "description": "Page number (1-indexed).",
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "description": "Number of results per page.",
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "maximum": 200,
              "minimum": 1,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MonitorAssetResultList"
                }
              }
            },
            "description": "Successfully listed the monitor's asset results"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List a monitor's asset results",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/controls": {
      "get": {
        "description": "List all controls for a monitor\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorGetControls",
        "parameters": [
          {
            "description": "The ID of the monitor",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ControlList"
                }
              }
            },
            "description": "Successfully fetched the list of associated controls for the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List all controls for a monitor",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/enabled": {
      "post": {
        "description": "Update the monitor to be enabled or disabled\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateEnabled",
        "parameters": [
          {
            "description": "The ID of the monitor to update the enabled status for",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MonitorUpdateEnabled"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Successfully updated the monitor's enabled status"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update the enabled status of a monitor",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/rerun": {
      "post": {
        "description": "Rerun a monitor\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateRerun",
        "parameters": [
          {
            "description": "The ID of the monitor to rerun",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Successfully reran the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Rerun a monitor",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/runs": {
      "get": {
        "description": "List recent monitor runs\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorGetRuns",
        "parameters": [
          {
            "description": "The ID of the monitor to get",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MonitorRunList"
                }
              }
            },
            "description": "Successfully listed the monitor's runs"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List recent monitor runs",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/snooze": {
      "post": {
        "description": "Snooze a monitor until a specified date and time\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateSnooze",
        "parameters": [
          {
            "description": "The ID of the monitor to snooze",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MonitorSnooze"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Successfully snoozed the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Snooze a monitor",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/snooze-assets": {
      "post": {
        "description": "Snooze specific assets for a monitor\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateSnoozeAssets",
        "parameters": [
          {
            "description": "The ID of the monitor",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MonitorSnoozeAssets"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Successfully snoozed the assets"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Snooze monitor assets",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/states": {
      "get": {
        "description": "List monitor states\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorStateList",
        "parameters": [
          {
            "description": "The ID of the monitor to get",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MonitorStateList"
                }
              }
            },
            "description": "Successfully listed the monitor's states"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List monitor states",
        "tags": [
          "Monitors"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/unsnooze": {
      "post": {
        "description": "Unsnooze a monitor\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateUnsnooze",
        "parameters": [
          {
            "description": "The ID of the monitor to unsnooze",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Successfully unsnoozed the monitor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Unsnooze a monitor",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/unsnooze-assets": {
      "post": {
        "description": "Unsnooze specific assets for a monitor\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateUnsnoozeAssets",
        "parameters": [
          {
            "description": "The ID of the monitor",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MonitorUnsnoozeAssets"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Successfully unsnoozed the assets"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Unsnooze monitor assets",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/monitors/{monitor}/update-assets-ignore-status": {
      "post": {
        "description": "Update ignore status for assets\n\n**Required scope:** `WRITE_MONITORS`",
        "operationId": "MonitorUpdateIgnoreStatusForAssets",
        "parameters": [
          {
            "description": "The ID of the monitor to update ignore status for assets",
            "in": "path",
            "name": "monitor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MonitorUpdateIgnoreStatusForAssets"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "Successfully updated the monitor to ignore an asset instance"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Update ignore status for assets",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_MONITORS"
      }
    },
    "/api/v1/policies/{policy}": {
      "get": {
        "description": "Gets a policy.\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyGet",
        "parameters": [
          {
            "description": "The ID of the policy to get",
            "in": "path",
            "name": "policy",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Policy"
                }
              }
            },
            "description": "Success"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policy",
        "tags": [
          "Policy"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/policies/{policy}/versions": {
      "get": {
        "description": "Gets the list of versions for a policy\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyVersionList",
        "parameters": [
          {
            "description": "The ID of the policy to get versions for",
            "in": "path",
            "name": "policy",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicyVersionList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policy versions",
        "tags": [
          "Policy",
          "Policy Version"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/policy-types": {
      "get": {
        "description": "Gets a list of policy types\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyTypeList",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicyTypeList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policy types",
        "tags": [
          "Policy Type"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/policy-versions/{policy-version}": {
      "get": {
        "description": "Gets a policy version\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyVersionGet",
        "parameters": [
          {
            "description": "The ID of the policy version to get",
            "in": "path",
            "name": "policy-version",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicyVersion"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policy version",
        "tags": [
          "Policy Version"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/policy-versions/{policy-version}/signatures": {
      "get": {
        "description": "List all signatures for a policy.\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicySignatureList",
        "parameters": [
          {
            "description": "The ID of the policy to get signatures for",
            "in": "path",
            "name": "policy-version",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicySignatureList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get signatures for a policy",
        "tags": [
          "Policy Version",
          "Policy Signature"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/risks-assessments/{risk-assessment}": {
      "get": {
        "description": "Get a risk assessment by id\n\n**Required scope:** `READ_RISKS`",
        "operationId": "RiskAssessmentGet",
        "parameters": [
          {
            "description": "The ID of the risk assessment to get.",
            "in": "path",
            "name": "risk-assessment",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RiskAssessment"
                }
              }
            },
            "description": "Risk assessment"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "description": "The tenant or risk assessment does not exist"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get risk assessment",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "READ_RISKS"
      },
      "patch": {
        "description": "Update a risk assessment\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskAssessmentUpdate",
        "parameters": [
          {
            "description": "The ID of the tenant.",
            "in": "path",
            "name": "risk-assessment",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateRiskAssessmentRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RiskAssessment"
                }
              }
            },
            "description": "The risk assessment was updated"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant or risk assessment does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An error occurred"
          }
        },
        "summary": "Update a risk assessment",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/risks-assessments/{risk-assessment}/risks": {
      "post": {
        "description": "Create a new risk for a risk assessment\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskCreate",
        "parameters": [
          {
            "description": "The ID of the risk assessment.",
            "in": "path",
            "name": "risk-assessment",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateRiskRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "The risk was created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant or risk assessment does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Create a risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/risks/{risk}": {
      "delete": {
        "description": "Delete a risk from a risk assessment\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskDelete",
        "parameters": [
          {
            "description": "The ID of the risk to update.",
            "in": "path",
            "name": "risk",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "The risk was deleted"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant, risk assessment or risk does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Delete a risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      },
      "get": {
        "description": "Get a risk by id\n\n**Required scope:** `READ_RISKS`",
        "operationId": "RiskGet",
        "parameters": [
          {
            "description": "The ID of the risk to get.",
            "in": "path",
            "name": "risk",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Risk"
                }
              }
            },
            "description": "Risk"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "description": "The tenant does not exist"
          },
          "500": {
            "description": "An error occurred"
          }
        },
        "summary": "Get risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "READ_RISKS"
      },
      "patch": {
        "description": "Update a risk for a risk assessment\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskUpdate",
        "parameters": [
          {
            "description": "The ID of the risk to update.",
            "in": "path",
            "name": "risk",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateRiskRequest"
              }
            }
          }
        },
        "responses": {
          "204": {
            "description": "The risk was updated"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant, risk assessment or risk does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Update a risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/risks/{risk}/archive": {
      "post": {
        "description": "Archive a risk, marking it as no longer relevant\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskUpdateArchive",
        "parameters": [
          {
            "description": "The ID of the risk to archive.",
            "in": "path",
            "name": "risk",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "The risk was archived"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The risk does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Archive a risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/risks/{risk}/unarchive": {
      "post": {
        "description": "Unarchive a risk, marking it as relevant again\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskUpdateUnarchive",
        "parameters": [
          {
            "description": "The ID of the risk to unarchive.",
            "in": "path",
            "name": "risk",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "The risk was unarchived"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The risk does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Unarchive a risk",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/tenant-compliance-framework/{tenant-compliance-framework}/controls": {
      "get": {
        "deprecated": true,
        "description": "List controls for a tenant compliance framework.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlListTenantComplianceFramework",
        "parameters": [
          {
            "description": "The id of the tenant compliance framework to get controls for",
            "in": "path",
            "name": "tenant-compliance-framework",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ControlList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List controls for a tenant compliance framework.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenant-compliance-frameworks/{tenant-compliance-framework}": {
      "get": {
        "description": "Get a tenant compliance framework by id.\n\n**Required scope:** `READ_TENANTCOMPLIANCEFRAMEWORKS`",
        "operationId": "TenantComplianceFrameworkGet",
        "parameters": [
          {
            "description": "The id of the tenant compliance framework",
            "in": "path",
            "name": "tenant-compliance-framework",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceFramework"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get a tenant compliance framework.",
        "tags": [
          "TenantComplianceFramework"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANTCOMPLIANCEFRAMEWORKS"
      }
    },
    "/api/v1/tenant-compliance-frameworks/{tenant-compliance-framework}/requirements": {
      "get": {
        "description": "List all tenant compliance requirements for a tenant framework.\n\n**Required scope:** `READ_TENANTCOMPLIANCEFRAMEWORKS`",
        "operationId": "TenantComplianceRequirementList",
        "parameters": [
          {
            "description": "The id of the tenant compliance framework to get requirements for",
            "in": "path",
            "name": "tenant-compliance-framework",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceRequirementList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get requirements for a tenant framework.",
        "tags": [
          "TenantComplianceRequirement"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANTCOMPLIANCEFRAMEWORKS"
      }
    },
    "/api/v1/tenant-compliance-requirements/{tenant-compliance-requirement}": {
      "get": {
        "description": "Get a tenant compliance requirement by id.\n\n**Required scope:** `READ_TENANTCOMPLIANCEFRAMEWORKS`",
        "operationId": "TenantComplianceRequirementGet",
        "parameters": [
          {
            "description": "The id of the tenant compliance requirement",
            "in": "path",
            "name": "tenant-compliance-requirement",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceRequirement"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get a tenant compliance requirement.",
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANTCOMPLIANCEFRAMEWORKS"
      }
    },
    "/api/v1/tenant-compliance-requirements/{tenant-compliance-requirement}/controls": {
      "get": {
        "description": "List controls for a tenant compliance requirement.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlListTenantComplianceRequirement",
        "parameters": [
          {
            "description": "The id of the tenant compliance requirement to get controls for",
            "in": "path",
            "name": "tenant-compliance-requirement",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceRequirementBatchControlList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List controls for a tenant compliance requirement.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenant-devices/{tenant-device}": {
      "get": {
        "description": "Read device details including agentInfo.agentVersion and agentInfo.lastPing. These are reported values, not proof of auto-update health.\n\n**Required scope:** `READ_DEVICES`",
        "operationId": "TenantDeviceGet",
        "parameters": [
          {
            "description": "The tenant device ID",
            "in": "path",
            "name": "tenant-device",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantDevice"
                }
              }
            },
            "description": "Successfully fetched device"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "tags": [
          "Device Management"
        ],
        "x-feature-flags": [
          "oneleet-agent"
        ],
        "x-service-key-scope": "READ_DEVICES"
      }
    },
    "/api/v1/tenant-devices/{tenant-device}/monitors": {
      "get": {
        "description": "List monitors for a tenant device\n\n**Required scope:** `READ_DEVICES`",
        "operationId": "TenantDeviceGetMonitors",
        "parameters": [
          {
            "description": "The tenant device ID",
            "in": "path",
            "name": "tenant-device",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeviceMonitorList"
                }
              }
            },
            "description": "Successfully listed monitors for the tenant device"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List monitors for a device",
        "tags": [
          "Device Management"
        ],
        "x-feature-flags": [
          "oneleet-agent"
        ],
        "x-service-key-scope": "READ_DEVICES"
      }
    },
    "/api/v1/tenant-members/{tenant-member}/checklists": {
      "get": {
        "description": "Lists all checklist templates for a tenant member\n\n**Required scope:** `READ_TENANTMEMBERS`",
        "operationId": "MemberChecklistList",
        "parameters": [
          {
            "description": "The tenant member id",
            "in": "path",
            "name": "tenant-member",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MemberChecklists"
                }
              }
            },
            "description": "Successfully listed the checklists for the tenant member"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          }
        },
        "summary": "Get tenant member checklists",
        "tags": [
          "MemberChecklist"
        ],
        "x-service-key-scope": "READ_TENANTMEMBERS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}": {
      "delete": {
        "description": "Soft-delete a tenant vendor. The vendor is hidden from lists but its assessment data, notes, evidence links, and access-review references are preserved; it can be brought back with the restore operation.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorDelete",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendor"
                }
              }
            },
            "description": "A vendor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Delete tenant vendor (soft delete, restorable)",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      },
      "get": {
        "description": "Get tenant vendor\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantVendorGet",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendor"
                }
              }
            },
            "description": "A vendor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get tenant vendor",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}/assessment": {
      "get": {
        "description": "Get a vendor's risk assessment questionnaire: every question with its item id, type, options, current answer, and whether it currently applies. Vendors that have not started an assessment return their vendor-specific template or the default questionnaire, so this always reflects the questions an update would answer. Fetch this before updating answers to discover item ids and option ids — older vendors may be on a Legacy questionnaire with a different item set.\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantVendorGetAssessment",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendorAssessment"
                }
              }
            },
            "description": "The vendor's risk assessment questionnaire"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The stored assessment data or the vendor's assessment template is malformed and must be repaired before the questionnaire can be used"
          }
        },
        "summary": "Get vendor risk assessment questionnaire",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      },
      "patch": {
        "description": "Update vendor risk assessment answers by item id. The server owns the questionnaire structure: only the answers you send change, and every question, title, and option is preserved exactly. Answer value shapes by item type — YesNoItem, RadioItem, and HighMediumLowItem take a single option id string (e.g. \"yes\"); MultiSelectItem takes an array of option ids; CountriesItem takes an array of uppercase ISO 3166-1 alpha-2 country codes (e.g. [\"US\", \"DE\"]); TextItem takes a free-form string. Send null, an empty string, or an empty array to clear an answer. Unknown item ids and values outside the item's options are rejected. For vendors using the data inventory, questions marked disabledInTemplate are managed there and cannot be answered here — add or edit the vendor's data inventory items instead (create/update data inventory item) — except CountriesItem questions, which stay answerable in every mode. First fetch the questionnaire (get assessment) to discover item ids, option ids, and current answers — older vendors may be on a Legacy questionnaire with a different item set. You can answer a gating question (e.g. stores_data) and the questions it unlocks in the same request. Returns the updated questionnaire.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorUpdateAssessment",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateTenantVendorAssessmentRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendorAssessment"
                }
              }
            },
            "description": "The updated risk assessment questionnaire"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The stored assessment data or the vendor's assessment template is malformed and must be repaired before answers can be updated"
          }
        },
        "summary": "Update vendor risk assessment answers",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}/data-inventory/{data-inventory-item}": {
      "delete": {
        "description": "Delete a data inventory item\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorDataInventoryDelete",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The data inventory item id",
            "in": "path",
            "name": "data-inventory-item",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Data inventory item not found"
          }
        },
        "summary": "Delete a data inventory item; removing the last item makes a data-storing vendor's assessment incomplete again",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      },
      "patch": {
        "description": "Partially update a data inventory item. Omitted fields keep their current values.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorDataInventoryUpdate",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The data inventory item id",
            "in": "path",
            "name": "data-inventory-item",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateVendorDataInventoryItem"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorDataInventoryItem"
                }
              }
            },
            "description": "The updated data inventory item"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Data inventory item not found"
          }
        },
        "summary": "Partially update a data inventory item; omitted fields keep their values, tagIds replaces the whole tag set ([] removes all)",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}/restore": {
      "post": {
        "description": "Restore a soft-deleted tenant vendor, making it visible in lists again with its assessment data, notes, and links intact.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorUpdateRestore",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendor"
                }
              }
            },
            "description": "The restored vendor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Restore a soft-deleted tenant vendor",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}/skip-integration": {
      "post": {
        "description": "Skip the vendor's Oneleet integration. The vendor stays in the vendor directory, but the compliance journey's \"Connect your supported integrations\" step no longer counts it. Use this when the integration can't be connected, for example because the plan with the vendor doesn't include API access. Undo it with tenant-vendor:update:unskip-integration.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorUpdateSkipIntegration",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "The vendor's integration is skipped"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant vendor not found"
          }
        },
        "summary": "Skip a vendor's integration on the compliance journey",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenant-vendors/{tenant-vendor}/unskip-integration": {
      "post": {
        "description": "Undo a skipped integration so the compliance journey's \"Connect your supported integrations\" step counts the vendor again.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorUpdateUnskipIntegration",
        "parameters": [
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "The vendor's integration counts toward the step again"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant vendor not found"
          }
        },
        "summary": "Undo a skipped vendor integration on the compliance journey",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}": {
      "get": {
        "description": "Gets a tenant by id.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGet",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Tenant"
                }
              }
            },
            "description": "Successfully got the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get tenant",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/access-reviews": {
      "get": {
        "description": "List access reviews for tenant.\n\n**Required scope:** `READ_ACCESSREVIEWS`",
        "operationId": "AccessReviewList",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Page of results to return, starting at 1. Only valid together with limit, and defaults to 1 when limit is set. Request the next page until one comes back with fewer access reviews than the limit.",
            "in": "query",
            "name": "page",
            "schema": {
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "description": "Maximum number of access reviews to return. Access reviews are ordered by due date, latest first, and each one includes all of its vendors and accounts, so set a limit to keep the response small and use page to fetch the rest. When limit is omitted, every access review is returned.",
            "in": "query",
            "name": "limit",
            "schema": {
              "maximum": 200,
              "minimum": 1,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/AccessReview"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List access reviews.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "READ_ACCESSREVIEWS"
      },
      "post": {
        "description": "Create access review for tenant.\n\n**Required scope:** `WRITE_ACCESSREVIEWS`",
        "operationId": "AccessReviewCreate",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateAccessReviewRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AccessReviewCreated"
                }
              }
            },
            "description": "Created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create access review.",
        "tags": [
          "Access Reviews"
        ],
        "x-service-key-scope": "WRITE_ACCESSREVIEWS"
      }
    },
    "/api/v1/tenants/{tenant}/actions": {
      "get": {
        "description": "List actions for tenant with pagination, optionally filtered by status or action type.\n\n**Required scope:** `READ_ACTIONS`",
        "operationId": "ActionList",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Filter by action status.",
            "in": "query",
            "name": "status",
            "schema": {
              "$ref": "#/components/schemas/ActionStatus"
            }
          },
          {
            "description": "Filter by action type.",
            "in": "query",
            "name": "actionType",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Filter by linked resource type (e.g. evidenceRequest, codeSecurityFinding).",
            "in": "query",
            "name": "resourceType",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Filter by linked resource ID. Typically used with resourceType.",
            "in": "query",
            "name": "resourceId",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Filter by resource URN relationship type.",
            "in": "query",
            "name": "rel",
            "schema": {
              "$ref": "#/components/schemas/ActionResourceUrnRel"
            }
          },
          {
            "description": "Filter by tenant member ID who is an OWNER (directly or via group membership).",
            "in": "query",
            "name": "owner",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Filter by tenant member ID who is an ASSIGNEE (directly or via group membership).",
            "in": "query",
            "name": "assignee",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Filter by tenant member ID who is a VIEWER (directly or via group membership).",
            "in": "query",
            "name": "viewer",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Field to sort results by.",
            "in": "query",
            "name": "sortBy",
            "schema": {
              "default": "createdAt",
              "enum": [
                "actionStatus",
                "actionType",
                "dueDate",
                "createdAt",
                "summary"
              ],
              "type": "string"
            }
          },
          {
            "description": "Sort direction.",
            "in": "query",
            "name": "sortOrder",
            "schema": {
              "default": "desc",
              "enum": [
                "asc",
                "desc"
              ],
              "type": "string"
            }
          },
          {
            "description": "Page number (1-indexed).",
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "description": "Number of results per page.",
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "maximum": 200,
              "minimum": 1,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActionListResult"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List actions.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "READ_ACTIONS"
      },
      "post": {
        "description": "Create a new action for a tenant.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionCreate",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateActionRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Action"
                }
              }
            },
            "description": "Created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create an action.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/tenants/{tenant}/actions/bulk-assign-group": {
      "post": {
        "description": "Replace existing groups with a given role across multiple actions with a new group.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateBulkAssignGroup",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BulkAssignActionGroupRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "204": {
            "description": "Successfully assigned group to all actions"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Bulk assign a group to actions.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/tenants/{tenant}/actions/bulk-assign-member": {
      "post": {
        "description": "Replace existing members with a given role across multiple actions with a new member.\n\n**Required scope:** `WRITE_ACTIONS`",
        "operationId": "ActionUpdateBulkAssignMember",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BulkAssignActionMemberRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "204": {
            "description": "Successfully assigned member to all actions"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Bulk assign a member to actions.",
        "tags": [
          "Actions"
        ],
        "x-service-key-scope": "WRITE_ACTIONS"
      }
    },
    "/api/v1/tenants/{tenant}/ai-consent": {
      "get": {
        "description": "List the tenant's current AI consent decisions.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetAiConsent",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AiConsentListResponse"
                }
              }
            },
            "description": "The tenant's current AI consent decisions"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          }
        },
        "summary": "List AI consent decisions",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/audit-logs": {
      "get": {
        "description": "Get filtered audit logs, newest first. Reuse the same filters with each cursor. Restart pagination if a legacy cursor is rejected.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetAuditLogs",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The cursor to use to get the next page of audit logs",
            "in": "query",
            "name": "cursor",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Inclusive UTC start. Defaults to 30 days before endAt. Maximum range is 31 days.",
            "in": "query",
            "name": "startAt",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "Exclusive UTC end. Defaults to the time of the first request.",
            "in": "query",
            "name": "endAt",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "User or service-key IDs. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "actorIds",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Audit operation identifiers. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "operations",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Resource types. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "resourceTypes",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Resource IDs. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "resourceIds",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Target page size. A timestamp group may require up to 4999 rows to avoid splitting equal timestamps.",
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 100,
              "maximum": 1000,
              "minimum": 1,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AuditLogList"
                }
              }
            },
            "description": "Successfully got the audit logs for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "422": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Too many events share one timestamp; narrow the filters."
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The audit log backend is unavailable; retry later."
          }
        },
        "summary": "Get audit logs for a tenant",
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/audit-logs/export": {
      "get": {
        "description": "Get a gzip-compressed JSON Lines file of the matching audit logs. Uses the same filters and visibility as audit log listing. The file is prepared in the background; the call waits up to `wait` seconds for it and then answers with its status. While status is PENDING or RUNNING, call again with the same filters until it is COMPLETED, then download from downloadUrl within one hour and read the file locally instead of loading it into model context. A completed export is reused for one hour; a FAILED export is retried by the next call. Maximum range 31 days, 100000 records, and 100 MiB uncompressed; an export over a limit fails without a partial file.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetAuditLogExport",
        "parameters": [
          {
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Inclusive UTC start. Defaults to 30 days before endAt. Maximum range is 31 days.",
            "in": "query",
            "name": "startAt",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "Exclusive UTC end. Defaults to the time of the first request.",
            "in": "query",
            "name": "endAt",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "User or service-key IDs. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "actorIds",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Audit operation identifiers. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "operations",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Resource types. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "resourceTypes",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Resource IDs. Exact matches; OR within this filter, AND across filters.",
            "explode": true,
            "in": "query",
            "name": "resourceIds",
            "schema": {
              "items": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          },
          {
            "description": "Seconds to wait for an export still building before answering with its status. Defaults to 15.",
            "in": "query",
            "name": "wait",
            "schema": {
              "maximum": 25,
              "minimum": 0,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Export"
                }
              }
            },
            "description": "The export, with downloadUrl once it is COMPLETED"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Invalid filters"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Export storage is unavailable"
          }
        },
        "summary": "Get a compressed export of filtered audit logs",
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/code-security-findings": {
      "get": {
        "description": "List all code security findings for a tenant.\n\n**Required scope:** `READ_CODE_SECURITY`",
        "operationId": "CodeSecurityFindingList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/CodeSecurityFinding"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched code security findings for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get code security findings for a tenant",
        "tags": [
          "code_security_scanner"
        ],
        "x-feature-flags": [
          "code-security"
        ],
        "x-service-key-scope": "READ_CODE_SECURITY"
      }
    },
    "/api/v1/tenants/{tenant}/code-security-findings/{code-security-finding}/patch-workflow-runs": {
      "post": {
        "description": "Kick off a patch generation scan for a single code security finding.\n\n**Required scope:** `WRITE_GIT_REPOSITORY_CONTENTS`",
        "operationId": "CodeSecurityFindingCreatePatchWorkflowRun",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The finding id",
            "in": "path",
            "name": "code-security-finding",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "202": {
            "description": "Successfully started autofix workflow for the finding"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Finding not found"
          }
        },
        "summary": "Start autofix workflow: generate a patch for a code security finding and open a pull request",
        "tags": [
          "code_security_scanner"
        ],
        "x-feature-flags": [
          "code-security",
          "autofixes"
        ],
        "x-service-key-scope": "WRITE_GIT_REPOSITORY_CONTENTS"
      }
    },
    "/api/v1/tenants/{tenant}/code-security-findings/{code-security-finding}/patches": {
      "post": {
        "description": "Kick off a patch generation scan for a single code security finding.\n\n**Required scope:** `WRITE_GIT_REPOSITORY_CONTENTS`",
        "operationId": "CodeSecurityFindingCreatePatch",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The finding id",
            "in": "path",
            "name": "code-security-finding",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "202": {
            "description": "Successfully kicked off patch generation for the finding"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Finding not found"
          }
        },
        "summary": "Generate a patch for a code security finding",
        "tags": [
          "code_security_scanner"
        ],
        "x-feature-flags": [
          "code-security",
          "autofixes"
        ],
        "x-service-key-scope": "WRITE_GIT_REPOSITORY_CONTENTS"
      }
    },
    "/api/v1/tenants/{tenant}/code-security-scan-info": {
      "post": {
        "description": "Gets a list of all the repositories scan last run, next run and the status of the scan.\n\n**Required scope:** `READ_CODE_SECURITY`",
        "operationId": "TenantGetCodeSecurityScanInfo",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GetCodeSecurityScanInfoBody"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CodeSecurityScanInfoList"
                }
              }
            },
            "description": "Successfully fetched scan info for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get scan info for a tenant",
        "tags": [
          "code_security_scanner"
        ],
        "x-feature-flags": [
          "code-security"
        ],
        "x-service-key-scope": "READ_CODE_SECURITY"
      }
    },
    "/api/v1/tenants/{tenant}/code-security-settings": {
      "get": {
        "description": "Get the code health scanner settings for a tenant.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetCodeSecuritySettings",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CodeSecuritySettings"
                }
              }
            },
            "description": "Successfully got the code health scanner settings"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get the code health scanner settings for a tenant.",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/controls": {
      "get": {
        "description": "List controls for a tenant.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlList",
        "parameters": [
          {
            "description": "The id of the tenant to get controls for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ControlList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List controls for a tenant.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenants/{tenant}/controls/by-tenant-compliance-frameworks": {
      "get": {
        "description": "List lightweight controls grouped by tenant compliance requirements for the selected tenant compliance frameworks.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlListTenantComplianceFrameworksBatch",
        "parameters": [
          {
            "description": "The id of the tenant to get controls for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The tenant compliance framework IDs to fetch controls for.",
            "explode": true,
            "in": "query",
            "name": "tenantFrameworkIds",
            "required": true,
            "schema": {
              "items": {
                "format": "uuid",
                "maxLength": 36,
                "minLength": 36,
                "type": "string"
              },
              "maxItems": 50,
              "minItems": 1,
              "type": "array",
              "uniqueItems": true
            },
            "style": "form"
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceRequirementControlSummaryList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List lightweight controls for multiple tenant compliance frameworks.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenants/{tenant}/controls/by-tenant-compliance-requirements": {
      "post": {
        "description": "List controls grouped by tenant compliance requirement IDs.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlListTenantComplianceRequirementsBatch",
        "parameters": [
          {
            "description": "The id of the tenant to get controls for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GetControlsByTenantComplianceRequirementsRequest"
              }
            }
          },
          "description": "The tenant compliance requirement IDs to fetch controls for.",
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceRequirementControlList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List controls for multiple tenant compliance requirements.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenants/{tenant}/controls/program": {
      "get": {
        "description": "List slim controls for the tenant program UI.\n\n**Required scope:** `READ_CONTROLS`",
        "operationId": "ControlListProgram",
        "parameters": [
          {
            "description": "The id of the tenant to get controls for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ProgramControlList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List slim controls for a tenant.",
        "tags": [
          "Control"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_CONTROLS"
      }
    },
    "/api/v1/tenants/{tenant}/dashboard": {
      "get": {
        "description": "Gets the dashboard for the current tenant\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetDashboard",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantDashboard"
                }
              }
            },
            "description": "Successfully got the dashboard for the current tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          }
        },
        "summary": "Get tenant dashboard",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/dashboard/compliance": {
      "get": {
        "description": "Lean stats payload for the redesigned compliance dashboard: framework\ncontrol rollups and per-control statuses, device/people/monitor counts,\nand audits. Unlike the full dashboard endpoint, it skips the per-control\nchecks projection and findings, which the redesigned dashboard never\nreads.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetDashboardCompliance",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DashboardStats"
                }
              }
            },
            "description": "Successfully got the compliance dashboard stats"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant not found"
          }
        },
        "summary": "Get compliance dashboard stats",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/dashboard/security-issues": {
      "get": {
        "description": "Cross-tool security issue summary for the tenant dashboard: per-tool\nopen-issue counts bucketed by severity, plus a feed of issues detected\nin the last 30 days. Only tools the tenant has enabled are included.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetDashboardSecurityIssues",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DashboardSecurityIssues"
                }
              }
            },
            "description": "Successfully got the security issue summary"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get tenant dashboard security issues",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/dashboard/security-issues/list": {
      "get": {
        "description": "Open issues for one security tool and severity bucket, newest first,\ncapped server-side. Backs the dashboard's open-issues drill-down; the\nbuckets match the counts reported by the security-issues summary.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantListDashboardSecurityIssues",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The security tool to list open issues for",
            "in": "query",
            "name": "source",
            "required": true,
            "schema": {
              "$ref": "#/components/schemas/DashboardSecuritySource"
            }
          },
          {
            "description": "The severity bucket to list open issues for",
            "in": "query",
            "name": "severity",
            "required": true,
            "schema": {
              "$ref": "#/components/schemas/DashboardSecuritySeverity"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DashboardSecurityIssueList"
                }
              }
            },
            "description": "Successfully listed the open issues in the bucket"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List tenant dashboard security issues in a bucket",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/dast/applications": {
      "get": {
        "description": "List the tenant's DAST applications with their open issue counts grouped by severity.\n\n\n**Required scope:** `READ_DAST`",
        "operationId": "DastApplicationList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastApplicationListResult"
                }
              }
            },
            "description": "List of DAST applications"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List DAST applications",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      }
    },
    "/api/v1/tenants/{tenant}/dast/applications/{dast-application}": {
      "get": {
        "description": "**Required scope:** `READ_DAST`",
        "operationId": "DastApplicationGet",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastApplication"
                }
              }
            },
            "description": "The DAST application"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Application not found"
          }
        },
        "summary": "Get a DAST application",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      },
      "parameters": [
        {
          "description": "The tenant id",
          "in": "path",
          "name": "tenant",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        {
          "description": "The DAST application id",
          "in": "path",
          "name": "dast-application",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        }
      ]
    },
    "/api/v1/tenants/{tenant}/dast/findings/{dast-finding}": {
      "get": {
        "description": "Get a single DAST finding with all details\n\n\n**Required scope:** `READ_DAST`",
        "operationId": "DastFindingGet",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastFinding"
                }
              }
            },
            "description": "The DAST finding"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Finding not found"
          }
        },
        "summary": "Get a DAST finding",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      },
      "parameters": [
        {
          "description": "The tenant id",
          "in": "path",
          "name": "tenant",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        {
          "description": "The DAST finding id",
          "in": "path",
          "name": "dast-finding",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        }
      ]
    },
    "/api/v1/tenants/{tenant}/dast/issues": {
      "get": {
        "description": "List all DAST issues for a tenant with their findings nested under each issue.\n\n\n**Required scope:** `READ_DAST`",
        "operationId": "DastIssueList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastIssueListResult"
                }
              }
            },
            "description": "List of DAST issues with findings nested"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List DAST issues with nested findings",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      }
    },
    "/api/v1/tenants/{tenant}/dast/issues/{dast-issue}": {
      "get": {
        "description": "Get a single DAST issue with its findings nested. Same response shape as\none element of the issue list endpoint.\n\n\n**Required scope:** `READ_DAST`",
        "operationId": "DastIssueGet",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastIssue"
                }
              }
            },
            "description": "The DAST issue"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Issue not found"
          }
        },
        "summary": "Get a DAST issue with nested findings",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      },
      "parameters": [
        {
          "description": "The tenant id",
          "in": "path",
          "name": "tenant",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        },
        {
          "description": "The DAST issue id",
          "in": "path",
          "name": "dast-issue",
          "required": true,
          "schema": {
            "format": "uuid",
            "maxLength": 36,
            "minLength": 36,
            "type": "string"
          }
        }
      ]
    },
    "/api/v1/tenants/{tenant}/dast/scans": {
      "get": {
        "description": "List the tenant's DAST scans.\n\n\n**Required scope:** `READ_DAST`",
        "operationId": "DastScanList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Restrict scans to a single application.",
            "in": "query",
            "name": "applicationId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Filter by scan status.",
            "in": "query",
            "name": "status",
            "schema": {
              "$ref": "#/components/schemas/DastScanStatus"
            }
          },
          {
            "description": "Only return scans created on or after this timestamp.",
            "in": "query",
            "name": "fromDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "Only return scans created on or before this timestamp.",
            "in": "query",
            "name": "toDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DastScanListResult"
                }
              }
            },
            "description": "List of DAST scans"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List DAST scans",
        "tags": [
          "dast"
        ],
        "x-feature-flags": [
          "dynamic-application-security-testing"
        ],
        "x-service-key-scope": "READ_DAST"
      }
    },
    "/api/v1/tenants/{tenant}/data-inventory-tags": {
      "get": {
        "description": "List available data inventory tags (system + tenant-scoped)\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantDataInventoryTagList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorDataInventoryTagList"
                }
              }
            },
            "description": "A list of data inventory tags"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List data inventory tags: system tags (PII, PHI, PCI, Customer Data) plus workspace tags; call before creating items",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "READ_VENDORS"
      },
      "post": {
        "description": "Create a tenant-scoped data inventory tag\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantDataInventoryTagCreate",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateVendorDataInventoryTag"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorDataInventoryTag"
                }
              }
            },
            "description": "The created tag"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create a workspace data inventory tag; prefer system tags, only system PII/PHI drive processesPii; names unique per workspace, max 100 chars",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}/dependency-scan": {
      "post": {
        "description": "Trigger a dependency scan for the given git repositories, or for all repositories with scanning enabled.\n\n**Required scope:** `WRITE_DEPENDENCY_SCANNING`",
        "operationId": "TenantUpdateDependencyTriggerScan",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TriggerDependencyScanBody"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successfully triggered a dependency scan"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Trigger a dependency scan",
        "tags": [
          "dependency_scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "WRITE_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/dependency-scan-info": {
      "post": {
        "description": "Gets each repository's last dependency scan run, next scheduled run, and whether a scan is currently running.\n\n**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "TenantGetDependencyScanInfo",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GetDependencyScanInfoBody"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DependencyScanInfoList"
                }
              }
            },
            "description": "Successfully fetched dependency scan info for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get dependency scan info for a tenant",
        "tags": [
          "dependency_scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/digest-defaults": {
      "get": {
        "description": "Returns digest defaults for every admin-visible role in a single response. Admin-only. Roles with no stored row carry the hardcoded fallback (biweekly, all sections, disabled) with hasOverride=false.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetDigestDefaults",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantDigestDefaults"
                }
              }
            },
            "description": "Successfully retrieved tenant digest defaults"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant not found"
          }
        },
        "summary": "Get tenant digest defaults across all roles",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/evidence": {
      "get": {
        "description": "List the evidence under a tenant.\n\n**Required scope:** `READ_EVIDENCE`",
        "operationId": "EvidenceList",
        "parameters": [
          {
            "description": "The id of the tenant to list evidence for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/Evidence"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List the evidence under a tenant.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_EVIDENCE"
      },
      "post": {
        "description": "Create a new evidence for a tenant and optionally a control. The file is\nsent inline as multipart/form-data.\n\nFor MCP / programmatic clients uploading IMAGE or FILE evidence, prefer\nthe two-step `evidence:create-upload-url` + `evidence:create-from-upload`\nflow instead — it streams the file directly to S3 via a presigned URL,\navoiding the base64 inflation and context-window pressure of inlining\nthe file in this request.\n\n\n**Required scope:** `WRITE_EVIDENCE`",
        "operationId": "EvidenceCreate",
        "parameters": [
          {
            "description": "The id of the tenant to create an evidence for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "multipart/form-data": {
              "schema": {
                "$ref": "#/components/schemas/CreateEvidenceRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Evidence"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create a new evidence for a tenant and optionally a control.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_EVIDENCE"
      }
    },
    "/api/v1/tenants/{tenant}/evidence/from-upload": {
      "post": {
        "description": "Create an evidence row backed by a file already uploaded to S3 via a\npresigned URL from `evidence:create-upload-url`. The server validates\nthat the file exists, lives under the tenant's S3 prefix, and matches\nthe supported MIME types and size limits.\n\n\n**Required scope:** `WRITE_EVIDENCE`",
        "operationId": "EvidenceCreateFromUpload",
        "parameters": [
          {
            "description": "The id of the tenant to create the evidence under",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateEvidenceFromUploadRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Evidence"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Uploaded file not found"
          }
        },
        "summary": "Create an evidence from a previously uploaded file.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_EVIDENCE"
      }
    },
    "/api/v1/tenants/{tenant}/evidence/pr-evidence": {
      "post": {
        "description": "Asynchronously collect code review evidence (merged GitHub pull\nrequests and/or GitLab merge requests) for a date range and attach\nthe result as CSV evidence rows per provider, automatically linked to\nthe relevant code-review controls. The server enqueues one Hatchet\ntask per provider that has at least one configured connection for the\ntenant and returns 202 immediately; clients should poll the evidence\nlist to observe new rows.\n\n\n**Required scope:** `WRITE_EVIDENCE`",
        "operationId": "EvidenceGetPrEvidence",
        "parameters": [
          {
            "description": "The id of the tenant to collect code review evidence for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GetPrEvidenceRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "202": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/GetPrEvidenceResponse"
                }
              }
            },
            "description": "Collection tasks enqueued"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Collect code review evidence for merged PRs/MRs.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_EVIDENCE"
      }
    },
    "/api/v1/tenants/{tenant}/evidence/upload-url": {
      "post": {
        "description": "Mint a presigned S3 PUT URL for uploading an evidence file out-of-band.\n\nUse this when you have a file (image, PDF, etc.) and want to attach it as\nevidence without sending the bytes through the API server. The flow is:\n\n1. Call this endpoint with the file's MIME type and size in bytes.\n2. PUT the file bytes directly to the returned `uploadUrl`, including the\n   headers in `requiredHeaders` (Content-Type and Content-Length).\n3. Call `evidence:create-from-upload` with the returned `s3Key` to attach\n   the upload to a new evidence row.\n\nThis is the recommended path for any client that doesn't want to base64-\nencode and stream large files through this API. The MCP `evidence:create`\ntool also accepts files via this flow.\n\n\n**Required scope:** `WRITE_EVIDENCE`",
        "operationId": "EvidenceCreateUploadUrl",
        "parameters": [
          {
            "description": "The id of the tenant to upload an evidence file for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/EvidenceCreateUploadUrlRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/EvidenceUploadUrl"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request (unsupported MIME type or oversized file)"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create a presigned upload URL for an evidence file.",
        "tags": [
          "Evidence"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_EVIDENCE"
      }
    },
    "/api/v1/tenants/{tenant}/feature-flags": {
      "get": {
        "description": "Lists all feature flags for a tenant\n\n**Required scope:** `READ_FEATURE_FLAGS`",
        "operationId": "TenantFeatureFlagsList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/FeatureFlagList"
                }
              }
            },
            "description": "Successfully listed the feature flags for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          }
        },
        "summary": "Get tenant feature flags",
        "x-service-key-scope": "READ_FEATURE_FLAGS"
      }
    },
    "/api/v1/tenants/{tenant}/fieldwork/deliveries": {
      "post": {
        "description": "Send one message for a Fieldwork workflow's delivery step, by email through the platform's email notification sender or to a Slack channel through the tenant's Slack connection. Only the tenant's Fieldwork stack calls this. A repeat with a delivery id that was already sent returns the recorded result without sending again.\n\n**Required scope:** `WRITE_FIELDWORK_DELIVERIES`",
        "operationId": "FieldworkDeliveryCreate",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateFieldworkDeliveryBody"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/FieldworkDelivery"
                }
              }
            },
            "description": "The delivery's outcome, including per-recipient results"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The delivery id is still being sent, or the tenant has notifications turned off"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Email sending isn't configured on the platform"
          }
        },
        "summary": "Send a fieldwork delivery",
        "tags": [
          "fieldwork"
        ],
        "x-feature-flags": [
          "fieldwork-workflows"
        ],
        "x-service-key-scope": "WRITE_FIELDWORK_DELIVERIES"
      }
    },
    "/api/v1/tenants/{tenant}/fieldwork/deliveries/slack-channel": {
      "get": {
        "description": "Report whether a delivery can post to a Slack channel: the channel still exists in a Slack workspace the tenant has connected, the connection is working, and whether the Oneleet app is in the channel. Only the tenant's Fieldwork stack calls this.\n\n**Required scope:** `WRITE_FIELDWORK_DELIVERIES`",
        "operationId": "FieldworkDeliveryGetSlackChannel",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The Slack channel id",
            "in": "query",
            "name": "channelId",
            "required": true,
            "schema": {
              "maxLength": 64,
              "minLength": 1,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/FieldworkDeliverySlackChannel"
                }
              }
            },
            "description": "The channel"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The channel isn't in a connected Slack workspace, or its connection was removed or is failing"
          }
        },
        "summary": "Get a Slack channel a fieldwork delivery posts to",
        "tags": [
          "fieldwork"
        ],
        "x-feature-flags": [
          "fieldwork-workflows"
        ],
        "x-service-key-scope": "WRITE_FIELDWORK_DELIVERIES"
      }
    },
    "/api/v1/tenants/{tenant}/git-repository-package-finding-bump-patches": {
      "post": {
        "description": "Kicks off dependency bump patch creation for the given findings.\n\n**Required scope:** `WRITE_GIT_REPOSITORY_CONTENTS`",
        "operationId": "GitRepositoryPackageFindingCreateBumpPatch",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "properties": {
                  "gitRepositoryPackageFindingIds": {
                    "items": {
                      "format": "uuid",
                      "type": "string"
                    },
                    "minItems": 1,
                    "type": "array"
                  }
                },
                "required": [
                  "gitRepositoryPackageFindingIds"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "202": {
            "description": "Successfully kicked off dependency bumping for the findings"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Generate dependency bump patches for a set of findings",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning",
          "autofixes"
        ],
        "x-service-key-scope": "WRITE_GIT_REPOSITORY_CONTENTS"
      }
    },
    "/api/v1/tenants/{tenant}/git-repository-package-findings/{git-repository-package-finding}": {
      "patch": {
        "description": "Update a single git repository package finding.\n\n**Required scope:** `WRITE_DEPENDENCY_SCANNING`",
        "operationId": "GitRepositoryPackageFindingUpdate",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The finding id",
            "in": "path",
            "name": "git-repository-package-finding",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateGitRepositoryPackageFindingBody"
              }
            }
          },
          "required": true
        },
        "responses": {
          "204": {
            "description": "Successfully updated git repository package finding"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Update a git repository package finding",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "WRITE_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/github-security-advisories/batch": {
      "post": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageVulnerabilityListGithubSecurityAdvisories",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GitHubSecurityAdvisoryBatchRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/GitHubSecurityAdvisoryBatchResponse"
                }
              }
            },
            "description": "Successfully fetched GitHub Security Advisory data"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Batch-fetch GitHub Security Advisory descriptions",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/groups": {
      "get": {
        "description": "List the groups under a tenant.\n\n**Required scope:** `READ_TENANTMEMBERS`",
        "operationId": "GroupList",
        "parameters": [
          {
            "description": "The id of the tenant to list groups for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/Group"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List the groups under a tenant.",
        "tags": [
          "Groups"
        ],
        "x-service-key-scope": "READ_TENANTMEMBERS"
      }
    },
    "/api/v1/tenants/{tenant}/integration-types": {
      "get": {
        "description": "List integration types for a tenant\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationListTenantTypes",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntegrationTypeList"
                }
              }
            },
            "description": "A list of integration types"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List integration types",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      }
    },
    "/api/v1/tenants/{tenant}/integrations": {
      "get": {
        "description": "List integrations for a tenant\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Include Oneleet managed integrations",
            "in": "query",
            "name": "includeOneleetManaged",
            "schema": {
              "type": "boolean"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntegrationList"
                }
              }
            },
            "description": "A list of integrations"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List integrations",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      },
      "post": {
        "description": "Create a new integration for a tenant\n\n**Required scope:** `WRITE_INTEGRATIONS`",
        "operationId": "IntegrationCreate",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateIntegrationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Integration"
                }
              }
            },
            "description": "Integration successfully created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Create new integration",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "WRITE_INTEGRATIONS"
      }
    },
    "/api/v1/tenants/{tenant}/integrations/assets/export": {
      "get": {
        "description": "Download every asset discovered by the tenant's integrations as CSV, with the owning integration and its owner.\n\n**Required scope:** `READ_INTEGRATIONS`",
        "operationId": "IntegrationListAssetsExport",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "text/csv": {}
            },
            "description": "CSV export"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Export integration assets CSV",
        "tags": [
          "Integration"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_INTEGRATIONS"
      }
    },
    "/api/v1/tenants/{tenant}/invites": {
      "get": {
        "description": "Lists all invites for a tenant\n\n**Required scope:** `READ_TENANTMEMBERS`",
        "operationId": "TenantInviteList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantInviteList"
                }
              }
            },
            "description": "Successfully listed the invites for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get tenant invites",
        "tags": [
          "Tenant"
        ],
        "x-service-key-scope": "READ_TENANTMEMBERS"
      }
    },
    "/api/v1/tenants/{tenant}/journey": {
      "get": {
        "description": "Get the compliance journey for a tenant, for a single compliance program.\n\nWhich program is rendered is chosen by the optional query parameters,\ntried in order; the first that resolves a journey template wins:\n  - auditId: render the journey for this specific audit, keyed on its\n    audit type. This is the path for audit-backed programs such as SOC 2\n    and ISO 27001, where an audit signals the tenant is actively pursuing\n    the program.\n  - frameworkId: render the journey for the tenant's\n    TenantComplianceFramework with this id, keyed on its framework type.\n    This is the fallback for programs without an audit, such as HIPAA and\n    GDPR; these render the PREPARATION stage only.\nWith neither parameter, the journey defaults to the tenant's most recent\naudit that has a journey template.\n\nThe response is a discriminated union keyed on currentStage; exactly one\nstage-specific progress payload is populated per response. Returns 404 if\nno journey resolves for the given selection.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetJourney",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Render the journey for this specific audit, resolved by its audit\ntype. Takes precedence over frameworkId. The audit must belong to the\ntenant, else the journey 404s.\n",
            "in": "query",
            "name": "auditId",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Render the journey for the tenant's TenantComplianceFramework with\nthis id, resolved by its framework type. Used for programs without an\naudit; renders the PREPARATION stage only. Ignored when auditId is\nprovided and resolves.\n",
            "in": "query",
            "name": "frameworkId",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/JourneyResponse"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get tenant journey",
        "tags": [
          "Journey"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/journey/programs": {
      "get": {
        "description": "List the compliance programs the tenant has a journey for — the options\nfor the journey switcher. Each entry carries the id to pass back to the\njourney endpoint to view it: an auditId when kind is AUDIT, a frameworkId\n(TenantComplianceFramework id) when kind is FRAMEWORK. Audit-backed\nprograms come first, most recent first, so the first entry is the\njourney's default selection.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetJourneyPrograms",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/JourneyProgram"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "List tenant journey programs",
        "tags": [
          "Journey"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/journey/summaries": {
      "get": {
        "description": "List condensed summaries of every journey program the tenant has — the\ndashboard's amalgamated journey view. One entry per program, in the same\norder as the programs endpoint (audit-backed first, most recent first),\neach carrying its stage position plus a small stage-appropriate teaser\npayload (preparation step teasers, observation attention counts, open\nevidence-request counts, or the completed report's download info).\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetJourneySummaries",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/JourneySummary"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "List tenant journey summaries",
        "tags": [
          "Journey"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/members": {
      "get": {
        "description": "List a tenant's members\n\n**Required scope:** `READ_TENANTMEMBERS`",
        "operationId": "TenantMemberList",
        "parameters": [
          {
            "description": "The id of the tenant to list members for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantMemberList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List the members of a tenant",
        "tags": [
          "TenantMember"
        ],
        "x-service-key-scope": "READ_TENANTMEMBERS"
      }
    },
    "/api/v1/tenants/{tenant}/monitors": {
      "get": {
        "description": "List monitors for a tenant\n\n**Required scope:** `READ_MONITORS`",
        "operationId": "MonitorList",
        "parameters": [
          {
            "description": "The tenant ID",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The asset type ID to filter monitors on",
            "in": "query",
            "name": "assetTypeId",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "A boolean indicating if we only want monitors which are enabled or disabled. Omit for both.",
            "in": "query",
            "name": "isEnabled",
            "schema": {
              "type": "boolean"
            }
          },
          {
            "description": "A date after which only monitors with a reviewRemindAt value greater than and not null will be returned",
            "in": "query",
            "name": "reviewRemindAfter",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "description": "A date before which only monitors with a reviewRemindAt value less than and not null will be returned",
            "in": "query",
            "name": "reviewRemindBefore",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MonitorList"
                }
              }
            },
            "description": "Successfully fetched the list of monitors for a tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List monitors for a tenant",
        "x-service-key-scope": "READ_MONITORS"
      }
    },
    "/api/v1/tenants/{tenant}/ng-attack-surface/findings": {
      "get": {
        "description": "List all ASM findings with filtering and pagination\n\n**Required scope:** `READ_ATTACK_SURFACE`",
        "operationId": "NgAttackSurfaceFindingList",
        "parameters": [
          {
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "type": "integer"
            }
          },
          {
            "description": "Filter by specific issue type",
            "in": "query",
            "name": "issueId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "status",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "severity",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "ownerId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "serviceId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "assetId",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Filter findings by specific scan",
            "in": "query",
            "name": "scanId",
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "search",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "fromDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "toDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "sortBy",
            "schema": {
              "default": "lastSeenAt",
              "enum": [
                "severity",
                "detectedAt",
                "lastSeenAt"
              ],
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "sortOrder",
            "schema": {
              "default": "desc",
              "enum": [
                "asc",
                "desc"
              ],
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/NgAttackSurfaceFindingListResult"
                }
              }
            },
            "description": "List of ASM findings"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          }
        },
        "summary": "List ASM findings",
        "tags": [
          "Tenant",
          "ng-attack-surface"
        ],
        "x-feature-flags": [
          "attack-surface"
        ],
        "x-service-key-scope": "READ_ATTACK_SURFACE"
      }
    },
    "/api/v1/tenants/{tenant}/ng-attack-surface/findings/{finding-id}": {
      "get": {
        "description": "Get detailed information about a specific ASM finding\n\n**Required scope:** `READ_ATTACK_SURFACE`",
        "operationId": "NgAttackSurfaceFindingGet",
        "parameters": [
          {
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "path",
            "name": "finding-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/NgAttackSurfaceFindingDetail"
                }
              }
            },
            "description": "ASM finding details"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get ASM finding details",
        "tags": [
          "Tenant",
          "ng-attack-surface"
        ],
        "x-feature-flags": [
          "attack-surface"
        ],
        "x-service-key-scope": "READ_ATTACK_SURFACE"
      }
    },
    "/api/v1/tenants/{tenant}/ng-attack-surface/issues": {
      "get": {
        "description": "List all ASM issues with filtering, pagination, and grouping\n\n**Required scope:** `READ_ATTACK_SURFACE`",
        "operationId": "NgAttackSurfaceIssueList",
        "parameters": [
          {
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "status",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "severity",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "domain",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "hostname",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "templateId",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "search",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "fromDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "toDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "sortBy",
            "schema": {
              "default": "severity",
              "enum": [
                "severity",
                "detectedAt",
                "lastSeenAt"
              ],
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "sortOrder",
            "schema": {
              "default": "desc",
              "enum": [
                "asc",
                "desc"
              ],
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "groupBy",
            "schema": {
              "default": "template",
              "enum": [
                "template",
                "none"
              ],
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/NgAttackSurfaceIssueListResult"
                }
              }
            },
            "description": "List of ASM issues"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List ASM issues",
        "tags": [
          "Tenant",
          "ng-attack-surface"
        ],
        "x-feature-flags": [
          "attack-surface"
        ],
        "x-service-key-scope": "READ_ATTACK_SURFACE"
      }
    },
    "/api/v1/tenants/{tenant}/ng-attack-surface/scans": {
      "get": {
        "description": "List all ASM scans with optional grouping by month\n\n**Required scope:** `READ_ATTACK_SURFACE`",
        "operationId": "NgAttackSurfaceScanList",
        "parameters": [
          {
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "page",
            "schema": {
              "default": 1,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "limit",
            "schema": {
              "default": 50,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "type",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "status",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "fromDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "toDate",
            "schema": {
              "format": "date-time",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "groupBy",
            "schema": {
              "default": "none",
              "enum": [
                "month",
                "none"
              ],
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/NgAttackSurfaceScanListResult"
                }
              }
            },
            "description": "List of scans"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List ASM scans",
        "tags": [
          "Tenant",
          "ng-attack-surface"
        ],
        "x-feature-flags": [
          "attack-surface"
        ],
        "x-service-key-scope": "READ_ATTACK_SURFACE"
      }
    },
    "/api/v1/tenants/{tenant}/ng-attack-surface/scans/{scan-id}": {
      "get": {
        "description": "Get detailed information about a specific scan\n\n**Required scope:** `READ_ATTACK_SURFACE`",
        "operationId": "NgAttackSurfaceScanGet",
        "parameters": [
          {
            "description": "The tenant ID",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "in": "path",
            "name": "scan-id",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/NgAttackSurfaceScanDetail"
                }
              }
            },
            "description": "Scan details"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get scan details",
        "tags": [
          "Tenant",
          "ng-attack-surface"
        ],
        "x-feature-flags": [
          "attack-surface"
        ],
        "x-service-key-scope": "READ_ATTACK_SURFACE"
      }
    },
    "/api/v1/tenants/{tenant}/notification-defaults": {
      "get": {
        "description": "Returns notification defaults for every admin-visible role in a single response. Admin-only. All catalog notifications are included; entries with respectsPreference=false signal that the dispatcher does not honor the stored default today.\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetNotificationDefaults",
        "parameters": [
          {
            "description": "The id of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantNotificationDefaults"
                }
              }
            },
            "description": "Successfully retrieved tenant notification defaults"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant not found"
          }
        },
        "summary": "Get tenant notification defaults across all roles",
        "tags": [
          "Tenant"
        ],
        "x-feature-flags": [
          "notifications"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/pentest-findings": {
      "get": {
        "description": "List the pentest findings for a tenant.\n\n**Required scope:** `READ_PENTESTFINDINGS`",
        "operationId": "PentestFindingList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/FindingList"
                }
              }
            },
            "description": "Successfully fetched the pentest findings for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List pentest findings",
        "tags": [
          "Finding"
        ],
        "x-service-key-scope": "READ_PENTESTFINDINGS"
      }
    },
    "/api/v1/tenants/{tenant}/pentest-findings/{pentest-finding}": {
      "get": {
        "description": "Get a pentest finding by id.\n\n**Required scope:** `READ_PENTESTFINDINGS`",
        "operationId": "PentestFindingGet",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The pentest finding id",
            "in": "path",
            "name": "pentest-finding",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Finding"
                }
              }
            },
            "description": "Successfully fetched the pentest finding"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get a pentest finding",
        "tags": [
          "Finding"
        ],
        "x-service-key-scope": "READ_PENTESTFINDINGS"
      }
    },
    "/api/v1/tenants/{tenant}/policies": {
      "get": {
        "description": "Gets a list of policies.\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyList",
        "parameters": [
          {
            "description": "The ID of the tenant to get policies for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicyList"
                }
              }
            },
            "description": "Success"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policies",
        "tags": [
          "Policy"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/tenants/{tenant}/policy-templates": {
      "get": {
        "description": "Gets a list of policy templates.\n\n**Required scope:** `READ_POLICIES`",
        "operationId": "PolicyTemplateList",
        "parameters": [
          {
            "description": "The ID of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Optional boolean flag to filter templates by the tenant's compliance frameworks",
            "in": "query",
            "name": "filterByTenant",
            "schema": {
              "type": "boolean"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/PolicyTemplateList"
                }
              }
            },
            "description": "Success"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get policy templates",
        "tags": [
          "Policy Template"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_POLICIES"
      }
    },
    "/api/v1/tenants/{tenant}/readiness": {
      "get": {
        "description": "Get the tenant's audit-readiness rollup: the recurring activities an\naudit examines that still need attention, plus the counts behind the\non-track state.\n\nRows are one per catalog definition, not one per check — a per-hire\nactivity is a single row carrying its subjects, because a large tenant\nwould otherwise return dozens of identical lines. Framework variants of\none activity are already collapsed by the engine, keyed to whichever\nvariant has the tightest deadline.\n\nEverything here is read from what the daily readiness sweep persisted;\nnothing is recomputed per request, so this response cannot disagree with\nwhat the tenant's escalation emails and weekly digest already said.\n\nA tenant without the `readiness-checks` feature flag gets an empty\nsummary — zero counts, no groups — rather than a 403 or 404.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetReadiness",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Narrow the rollup to activities whose control is verified under this\nTenantComplianceFramework — the same id the journey endpoint returns\nas `tenantComplianceFrameworkId`.\n\nThe compliance journey is per-program, so without this a tenant on\nboth SOC 2 and ISO 27001 would see the same items on either journey,\ncarrying due dates from the other program's audit window. Omit it for\na whole-tenant rollup.\n\nA control serving several frameworks appears under each of them; that\nis the same work, dated to each program's own window.\n",
            "in": "query",
            "name": "frameworkId",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReadinessSummary"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get tenant audit readiness",
        "tags": [
          "Readiness"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/readiness/settings": {
      "get": {
        "description": "List the tenant's timing for every audit-readiness activity it holds a\ncontrol for: each activity's defaults, the tenant's own cadence or grace\nperiod where set, and the values that apply. `summary` and `description`\nare rendered with the values that apply. Rows are ordered by\n`definitionId`.\n\nActivities the tenant holds no control for are left out, since the\ntenant has no checks under them.\n\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TenantGetReadinessSettings",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/ReadinessSetting"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "List tenant readiness settings",
        "tags": [
          "Readiness"
        ],
        "x-feature-flags": [
          "readiness-checks"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/risk-assessments": {
      "get": {
        "description": "List all risk assessments associated with a tenant\n\n**Required scope:** `READ_RISKS`",
        "operationId": "RiskAssessmentList",
        "parameters": [
          {
            "description": "The ID of the tenant.",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "description": "Whether to fetch completed or in progress risk assessments. True indicates only completed, false indicates on in progress, and both are returned by default.",
            "in": "query",
            "name": "completed",
            "schema": {
              "type": "boolean"
            }
          },
          {
            "description": "The maximum number of records to fetch. Defaults to all.",
            "in": "query",
            "name": "limit",
            "schema": {
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/RiskAssessment"
                  },
                  "type": "array"
                }
              }
            },
            "description": "List of risk assessments for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "List risk assessments",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "READ_RISKS"
      },
      "post": {
        "description": "Create a new risk assessment\n\n**Required scope:** `WRITE_RISKS`",
        "operationId": "RiskAssessmentCreate",
        "parameters": [
          {
            "description": "The ID of the tenant.",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateRiskAssessmentRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RiskAssessment"
                }
              }
            },
            "description": "The risk assessment was created"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The request was invalid"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The tenant does not exist"
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "An internal error occurred"
          }
        },
        "summary": "Create a risk assessment",
        "x-feature-flags": [
          "risk-management"
        ],
        "x-service-key-scope": "WRITE_RISKS"
      }
    },
    "/api/v1/tenants/{tenant}/software-package-types": {
      "get": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageListPackageTypes",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "description": "Software package URL (purl) type",
                    "type": "string"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched software package URL (purl) types for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List all software package URL (purl) types for a tenant",
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/software-package-vulnerabilities": {
      "post": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageVulnerabilityList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "properties": {
                  "gitRepositoryIds": {
                    "description": "Filter by Git repository IDs",
                    "items": {
                      "format": "uuid",
                      "maxLength": 36,
                      "minLength": 36,
                      "type": "string"
                    },
                    "type": "array"
                  },
                  "name": {
                    "description": "Filter by package name",
                    "type": "string"
                  },
                  "orderBy": {
                    "description": "Sort order for the results",
                    "enum": [
                      "highest-risk",
                      "lowest-risk",
                      "highest-severity",
                      "lowest-severity",
                      "newest",
                      "oldest",
                      "most-findings",
                      "fewest-findings"
                    ],
                    "type": "string"
                  },
                  "ownerIds": {
                    "description": "Filter by tenant member owner IDs. A vulnerability is returned\nif any of its findings has an owner in the set of owner IDs.\n",
                    "items": {
                      "format": "uuid",
                      "maxLength": 36,
                      "minLength": 36,
                      "type": "string"
                    },
                    "type": "array"
                  },
                  "packageUrlTypes": {
                    "description": "Filter by package URL (purl) types",
                    "items": {
                      "type": "string"
                    },
                    "type": "array"
                  }
                },
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/SoftwarePackageVulnerability"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched software package vulnerabilities for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Search software package vulnerabilities for a tenant",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/software-package-vulnerabilities/{software-package-vulnerability}": {
      "get": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageVulnerabilityGet",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The software package vulnerability id",
            "in": "path",
            "name": "software-package-vulnerability",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SoftwarePackageVulnerability"
                }
              }
            },
            "description": "Successfully fetched software package vulnerability for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get a software package vulnerability for a tenant",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/software-packages": {
      "post": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "properties": {
                  "cursor": {
                    "description": "Opaque pagination cursor that was returned as nextCursor in the previous response (if any).",
                    "type": "string"
                  },
                  "gitRepositoryIds": {
                    "description": "Filter by Git repository IDs",
                    "items": {
                      "format": "uuid",
                      "maxLength": 36,
                      "minLength": 36,
                      "type": "string"
                    },
                    "type": "array"
                  },
                  "limit": {
                    "description": "Number of packages per page. Defaults to 100.",
                    "maximum": 100,
                    "minimum": 1,
                    "type": "integer"
                  },
                  "name": {
                    "description": "Filter by package name",
                    "type": "string"
                  },
                  "orderBy": {
                    "description": "Sort order for the results",
                    "enum": [
                      "newest",
                      "oldest",
                      "name-asc",
                      "name-desc",
                      "most-repositories",
                      "most-distinct-versions"
                    ],
                    "type": "string"
                  },
                  "packageUrlTypes": {
                    "description": "Filter by package URL (purl) types",
                    "items": {
                      "type": "string"
                    },
                    "type": "array"
                  }
                },
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SoftwarePackageListResult"
                }
              }
            },
            "description": "Successfully fetched software packages for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Search software packages for a tenant",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/software-packages/{software-package}": {
      "get": {
        "description": "**Required scope:** `READ_DEPENDENCY_SCANNING`",
        "operationId": "SoftwarePackageGet",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The software package id",
            "in": "path",
            "name": "software-package",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SoftwarePackage"
                }
              }
            },
            "description": "Successfully fetched software package for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get a software package for a tenant",
        "tags": [
          "dependency-scanning"
        ],
        "x-feature-flags": [
          "dependency-scanning"
        ],
        "x-service-key-scope": "READ_DEPENDENCY_SCANNING"
      }
    },
    "/api/v1/tenants/{tenant}/tenant-compliance-frameworks": {
      "get": {
        "description": "List all of a tenant's tenant compliance frameworks\n\n**Required scope:** `READ_TENANTCOMPLIANCEFRAMEWORKS`",
        "operationId": "TenantComplianceFrameworkList",
        "parameters": [
          {
            "description": "The id of the tenant to get tenant compliance frameworks for",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantComplianceFrameworkList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get tenant compliance frameworks for a tenant.",
        "tags": [
          "TenantComplianceFramework"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANTCOMPLIANCEFRAMEWORKS"
      }
    },
    "/api/v1/tenants/{tenant}/tenant-devices": {
      "get": {
        "description": "Read device details including agentInfo.agentVersion and agentInfo.lastPing. Service-key and OAuth reads return up to 25 devices by default (limit 1–100). Follow nextCursor until absent. Paginated results are ordered by device ID and are a live listing, not a snapshot. Reported versions and contact times do not establish auto-update health. Archived devices are included.\n\n**Required scope:** `READ_DEVICES`",
        "operationId": "TenantDeviceList",
        "parameters": [
          {
            "description": "The ID of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "limit",
            "schema": {
              "maximum": 100,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "description": "Device ID returned as nextCursor from the previous page.",
            "in": "query",
            "name": "cursor",
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantDeviceList"
                }
              }
            },
            "description": "Successfully listed devices for the tenant"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "tags": [
          "Device Management"
        ],
        "x-feature-flags": [
          "oneleet-agent"
        ],
        "x-service-key-scope": "READ_DEVICES"
      }
    },
    "/api/v1/tenants/{tenant}/tenant-devices/export": {
      "get": {
        "description": "Get a bulk export of every device, including archived ones, with the same details, agent info, and compliance status as the device list, as a gzip-compressed JSON Lines file with one TenantDevice per line. The file is prepared in the background; the call waits up to `wait` seconds for it and then answers with its status. While status is PENDING or RUNNING, call again until it is COMPLETED, then download from downloadUrl within one hour and read the file locally instead of loading it into model context. A completed export is reused for one hour; a FAILED export is retried by the next call.\n\n**Required scope:** `READ_DEVICES`",
        "operationId": "TenantDeviceListExport",
        "parameters": [
          {
            "description": "The ID of the tenant",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "Seconds to wait for an export still building before answering with its status. Defaults to 15.",
            "in": "query",
            "name": "wait",
            "schema": {
              "maximum": 25,
              "minimum": 0,
              "type": "integer"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Export"
                }
              }
            },
            "description": "The export, with downloadUrl once it is COMPLETED"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Export storage is unavailable"
          }
        },
        "tags": [
          "Device Management"
        ],
        "x-feature-flags": [
          "oneleet-agent"
        ],
        "x-service-key-scope": "READ_DEVICES"
      }
    },
    "/api/v1/tenants/{tenant}/trust-document-requests": {
      "get": {
        "description": "List all document requests submitted for a tenant.\n\n**Required scope:** `READ_TRUST_CENTER`",
        "operationId": "TenantGetTrustDocumentRequests",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/TrustDocumentResponse"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched the document request list"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List the document requests for a tenant.",
        "tags": [
          "Tenant",
          "Trust"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TRUST_CENTER"
      }
    },
    "/api/v1/tenants/{tenant}/trust-documents": {
      "get": {
        "description": "Get the trust page documents for the current tenant\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TrustDocumentList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/TrustDocument"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched the trust page documents"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get tenant trust page documents",
        "tags": [
          "Tenant"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/trust-faqs": {
      "get": {
        "description": "Get the trust page FAQs for the current tenant\n\n**Required scope:** `READ_TENANT`",
        "operationId": "TrustFaqList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/TrustFaq"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched the trust page FAQs"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get tenant trust page FAQs",
        "tags": [
          "Tenant",
          "Trust"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TENANT"
      }
    },
    "/api/v1/tenants/{tenant}/trust-security-issues": {
      "get": {
        "description": "List all security issues reported for a tenant.\n\n**Required scope:** `READ_TRUST_CENTER`",
        "operationId": "TenantGetTrustSecurityIssues",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "items": {
                    "$ref": "#/components/schemas/TrustSecurityIssueResponse"
                  },
                  "type": "array"
                }
              }
            },
            "description": "Successfully fetched the document request list"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List the security issues reported for a tenant.",
        "tags": [
          "Tenant"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TRUST_CENTER"
      }
    },
    "/api/v1/tenants/{tenant}/trust/config": {
      "get": {
        "description": "Get the trust page configs for the current tenant, such as publish or un-publish status\n\n**Required scope:** `READ_TRUST_CENTER`",
        "operationId": "TenantGetTrustConfigs",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TrustPageConfigsResponse"
                }
              }
            },
            "description": "Successfully updated the trust page configurations"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "Get tenant trust page configs",
        "tags": [
          "Tenant"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_TRUST_CENTER"
      }
    },
    "/api/v1/tenants/{tenant}/vendor-accounts": {
      "get": {
        "description": "Get vendor accounts for a tenant\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "VendorAccountList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorAccountList"
                }
              }
            },
            "description": "Success"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get vendor accounts by tenant",
        "tags": [
          "VendorAccount"
        ],
        "x-feature-flags": [
          "integrations"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}/vendor-discoveries": {
      "get": {
        "description": "Lists discoveries which haven't been added as tenant vendors\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantVendorDiscoveryList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendorDiscoveryList"
                }
              }
            },
            "description": "A list of vendors"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List tenant vendor discoveries",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}/vendor-requests": {
      "get": {
        "description": "List every vendor request for the tenant, for the reviewer queue\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "VendorRequestList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorRequestList"
                }
              }
            },
            "description": "The tenant's vendor requests"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          }
        },
        "summary": "List vendor requests",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "vendor-requests"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}/vendors": {
      "get": {
        "description": "List tenant vendors\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantVendorList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "When true, soft-deleted vendors are included alongside active ones; they carry a deletedAt timestamp and can be restored.",
            "in": "query",
            "name": "includeDeleted",
            "schema": {
              "type": "boolean"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TenantVendorList"
                }
              }
            },
            "description": "A list of vendors"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List tenant vendors",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/tenants/{tenant}/vendors/{tenant-vendor}/data-inventory": {
      "get": {
        "description": "List data inventory items for a tenant vendor\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "TenantVendorDataInventoryList",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorDataInventoryItemList"
                }
              }
            },
            "description": "A list of data inventory items"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant vendor not found"
          }
        },
        "summary": "List a vendor's data inventory items (what data it stores or processes) with sensitivity level and tags; for inventory-mode vendors these rows drive services, processesPii, and completion",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "READ_VENDORS"
      },
      "post": {
        "description": "Create a data inventory item for a tenant vendor. The vendor must not be deleted, and its assessment must not answer stores_data = no or still carry legacy data answers (data_description, pii, customer_or_company_data). When the assessment answers stores_data = yes, creating an item switches the vendor to data inventory mode and updates its review date the same way an assessment save does.\n\n**Required scope:** `WRITE_VENDORS`",
        "operationId": "TenantVendorDataInventoryCreate",
        "parameters": [
          {
            "description": "The tenant id",
            "in": "path",
            "name": "tenant",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          },
          {
            "description": "The tenant vendor id",
            "in": "path",
            "name": "tenant-vendor",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateVendorDataInventoryItem"
              }
            }
          }
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorDataInventoryItem"
                }
              }
            },
            "description": "The created data inventory item"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Tenant vendor not found or deleted"
          }
        },
        "summary": "Add one data inventory item to a vendor; answer stores_data = yes first, list data inventory tags for ids; system PII/PHI tags mark the vendor as processing personal data; max 200 items",
        "tags": [
          "Vendor"
        ],
        "x-service-key-scope": "WRITE_VENDORS"
      }
    },
    "/api/v1/trust-document-requests/{trust-document-request}/approve": {
      "post": {
        "description": "Approve a pending trust page document request. The requester is emailed a download link for the document, so the document must have a file attached. Only pending requests can be approved.\n\n**Required scope:** `WRITE_TRUST_CENTER`",
        "operationId": "TrustDocumentRequestUpdateApprove",
        "parameters": [
          {
            "description": "The trust document request id",
            "in": "path",
            "name": "trust-document-request",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TrustDocumentResponse"
                }
              }
            },
            "description": "The approved document request"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The document request is no longer pending"
          }
        },
        "summary": "Approve a trust page document request",
        "tags": [
          "Tenant",
          "Trust"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_TRUST_CENTER"
      }
    },
    "/api/v1/trust-document-requests/{trust-document-request}/deny": {
      "post": {
        "description": "Deny a pending trust page document request. The requester is emailed that access was denied. Only pending requests can be denied.\n\n**Required scope:** `WRITE_TRUST_CENTER`",
        "operationId": "TrustDocumentRequestUpdateDeny",
        "parameters": [
          {
            "description": "The trust document request id",
            "in": "path",
            "name": "trust-document-request",
            "required": true,
            "schema": {
              "format": "uuid",
              "maxLength": 36,
              "minLength": 36,
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TrustDocumentResponse"
                }
              }
            },
            "description": "The denied document request"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          },
          "404": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Not found"
          },
          "409": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "The document request is no longer pending"
          }
        },
        "summary": "Deny a trust page document request",
        "tags": [
          "Tenant",
          "Trust"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "WRITE_TRUST_CENTER"
      }
    },
    "/api/v1/vendors": {
      "get": {
        "description": "List vendors\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "VendorList",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/VendorList"
                }
              }
            },
            "description": "A list of vendors"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "List vendors",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    },
    "/api/v1/vendors/{vendor}": {
      "get": {
        "description": "Get vendor\n\n**Required scope:** `READ_VENDORS`",
        "operationId": "VendorGet",
        "parameters": [
          {
            "description": "The vendor id",
            "in": "path",
            "name": "vendor",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Vendor"
                }
              }
            },
            "description": "A vendor"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "A malformed or bad request"
          },
          "403": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/APIError"
                }
              }
            },
            "description": "Forbidden"
          }
        },
        "summary": "Get vendor",
        "tags": [
          "Vendor"
        ],
        "x-feature-flags": [
          "tenant-compliance-frameworks"
        ],
        "x-service-key-scope": "READ_VENDORS"
      }
    }
  },
  "security": [
    {
      "bearerAuth": []
    }
  ]
}