openapi: 3.2.0 info: title: Case Manager V2 API version: 1.0.0 servers: - url: /airmdrapi tags: - name: Case Manager V2 paths: /v2/case: post: tags: - Case Manager V2 operationId: createCaseAPIV2 summary: create a new v2 case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateCaseRequestV2' security: - SessionCookie: [] responses: '200': description: case created successfully content: application/json: schema: $ref: '#/components/schemas/CreateCaseResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}: get: tags: - Case Manager V2 operationId: getCaseAPIV2 summary: get details of a v2 case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id of the case to be fetched required: true schema: type: string - name: requested_view in: query description: Requested view of the case required: true schema: $ref: '#/components/schemas/CaseView' - name: include_hidden_findings in: query description: Whether to include hidden findings in the response required: false schema: type: boolean - name: subscribe_to_updates in: query description: If true, the user will receive WebSocket events when this case is updated required: false schema: type: boolean security: - SessionCookie: [] responses: '200': description: case fetched successfully content: application/json: schema: $ref: '#/components/schemas/GetCaseResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Case Manager V2 operationId: updateCaseAPIV2 summary: update details of a v2 case parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The uuid of the case to be updated required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateCaseRequestV2' security: - SessionCookie: [] responses: '200': description: case updated successfully content: application/json: schema: $ref: '#/components/schemas/UpdateCaseResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: archiveCaseAPI summary: archive a case parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string security: - SessionCookie: [] responses: '200': description: case archived successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/hard_delete: delete: tags: - Case Manager V2 operationId: deleteCaseAPI summary: delete a case parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string security: - SessionCookie: [] responses: '200': description: case deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/ignore_case_metric: patch: tags: - Case Manager V2 operationId: ignoreCaseMetricAPI summary: ignore/unignore the case from metrics parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string security: - SessionCookie: [] responses: '200': description: operation performed successfully content: application/json: schema: $ref: '#/components/schemas/GetCaseResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/finding: post: tags: - Case Manager V2 operationId: addCaseFindingAPI summary: add a new finding in case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to upsert finding required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AddCaseFindingRequest' security: - SessionCookie: [] responses: '200': description: finding created successfully content: application/json: schema: $ref: '#/components/schemas/AddCaseFindingResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/finding/{finding_uuid}: patch: tags: - Case Manager V2 operationId: updateCaseFindingAPI summary: update a finding in the case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to upsert finding required: true schema: type: string - name: finding_uuid in: path description: The id or uuid of the finding to be deleted required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateCaseFindingRequest' security: - SessionCookie: [] responses: '200': description: finding updated successfully content: application/json: schema: $ref: '#/components/schemas/UpdateCaseFindingResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: deleteCaseFindingAPI summary: delete a finding in a case parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to delete finding from required: true schema: type: string - name: finding_uuid in: path description: The id or uuid of the finding to be deleted required: true schema: type: string security: - SessionCookie: [] responses: '200': description: finding deleted successfully content: application/json: schema: $ref: '#/components/schemas/DeleteCaseFindingResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/finding/{finding_uuid}/email: post: tags: - Case Manager V2 operationId: emailCaseFindingDetailsAPIV2 summary: email details of a v2 case finding parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The uuid of the case required: true schema: type: string - name: finding_uuid in: path description: The uuid of the finding required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EmailCaseFindingDetailsRequest' security: - SessionCookie: [] responses: '200': description: email sent successfully content: application/json: schema: $ref: '#/components/schemas/EmailCaseFindingDetailsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/finding/{finding_uuid}/evidence/{evidence_uuid}: get: tags: - Case Manager V2 operationId: getEvidenceAPI summary: get evidence data for a finding based on uuid parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string - name: finding_uuid in: path description: The id or uuid of the finding required: true schema: type: string - name: evidence_uuid in: path description: The id or uuid of the evidence to be deleted required: true schema: type: string - name: version in: query description: Version for evidence. If not provided, latest evidence will be returned schema: type: integer security: - SessionCookie: [] responses: '200': description: evidence fetched successfully content: application/json: schema: $ref: '#/components/schemas/GetEvidenceResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/attachment: post: tags: - Case Manager V2 operationId: uploadCaseAttachmentAPI summary: upload an image attachment for a case description: 'Uploads a single image, stored in the case attachments S3 bucket and rendered in the images strip under the alert details section of the case. The bytes are validated server side: the declared content type is ignored in favour of magic byte sniffing, the file must decode as a real image, and SVG is never accepted because serving it same origin would be stored XSS in an analyst session.' parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is performed through a darryl action schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string security: - SessionCookie: [] requestBody: required: true content: multipart/form-data: schema: type: object required: - file properties: file: type: string format: binary description: The image to upload. Maximum 5 MiB. Allowed types are PNG, JPEG and GIF. section: type: string description: Which section of the case the image belongs to. Defaults to alert_details. enum: - alert_details - comment caption: type: string description: Optional analyst supplied caption. responses: '201': description: attachment uploaded successfully content: application/json: schema: $ref: '#/components/schemas/UploadCaseAttachmentResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/attachments: get: tags: - Case Manager V2 operationId: listCaseAttachmentsAPI summary: list the image attachments for a case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string - name: section in: query description: Restrict the result to a single section. All sections are returned when omitted. schema: type: string enum: - alert_details - comment - name: comment_id in: query description: 'Restrict the result to images attached to a single comment. Implies section=comment. ' schema: type: string security: - SessionCookie: [] responses: '200': description: attachments fetched successfully content: application/json: schema: $ref: '#/components/schemas/ListCaseAttachmentsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/attachment/{attachment_uuid}: delete: tags: - Case Manager V2 operationId: deleteCaseAttachmentAPI summary: delete a case image attachment parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is performed through a darryl action schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string - name: attachment_uuid in: path description: The uuid of the attachment required: true schema: type: string security: - SessionCookie: [] responses: '200': description: attachment deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/attachment/{attachment_uuid}/content: get: tags: - Case Manager V2 operationId: getCaseAttachmentContentAPI summary: stream the bytes of a case image attachment description: Streams the image from S3 through the service so that organization access is re-checked on every request. This is the URL used as the src of the rendered img element; it is permanent and revocable, unlike a presigned S3 URL. The response Content-Type is the type sniffed at upload time and is served with X-Content-Type-Options nosniff and a restrictive Content-Security-Policy. parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: case_uuid in: path description: The id or uuid of the case required: true schema: type: string - name: attachment_uuid in: path description: The uuid of the attachment required: true schema: type: string security: - SessionCookie: [] responses: '200': description: attachment content content: application/octet-stream: schema: type: string format: binary default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/email: post: tags: - Case Manager V2 operationId: emailCaseDetailsAPIV2 summary: email details of a v2 case parameters: - name: User-ID in: header description: The User ID of the requestor. schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The uuid of the case required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EmailCaseDetailsRequest' security: - SessionCookie: [] responses: '200': description: email sent successfully content: application/json: schema: $ref: '#/components/schemas/EmailCaseDetailsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/list: post: tags: - Case Manager V2 operationId: getCasesForOrgAPIV2 summary: get case list for an organization based on filter and sort parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: page in: query description: Page number for paginated results. required: true schema: type: integer - name: size in: query description: Number of results per page. required: true schema: type: integer requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CaseListRequestV2' security: - SessionCookie: [] responses: '200': description: List of cases retrieved successfully content: application/json: schema: $ref: '#/components/schemas/CaseListResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_identifier}/chat_session/{chat_session_id}/link: post: tags: - Case Manager V2 operationId: linkChatSessionToCaseAPIV2 summary: Link given chat session to case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_identifier in: path description: Unique identifier (id or uuid) of the case to which chat session will be linked schema: type: string - name: chat_session_id in: path description: Unique identifier uuid of the chat session to link to the case schema: type: string security: - SessionCookie: [] responses: '200': description: chat session linked successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_identifier}/chat_session/{chat_session_id}/unlink: post: tags: - Case Manager V2 operationId: unlinkChatSessionToCaseAPIV2 summary: Unlink given session from case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_identifier in: path description: Unique identifier (id or uuid) of the case from which session will be unlinked schema: type: string - name: chat_session_id in: path description: Unique identifier uuid of the session to unlink from case schema: type: string security: - SessionCookie: [] responses: '200': description: session unlinked successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/chat_session/{chat_session_id}: get: tags: - Case Manager V2 operationId: getLinkedCasesForSessionAPIV2 summary: Get linked cases for given session uuid parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: chat_session_id in: path description: Unique identifier uuid of the session to which cases are linked schema: type: string required: true security: - SessionCookie: [] responses: '200': description: case list fetched successfully content: application/json: schema: $ref: '#/components/schemas/CaseListResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_identifier}/cases/link: post: tags: - Case Manager V2 operationId: linkCasesAPIV2 summary: Link given cases in request to the case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_identifier in: path description: Unique identifier (id or uuid) of the case to which others cases will be linked schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CaseLinkRequest' security: - SessionCookie: [] responses: '200': description: case linked successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{primary_case_identifier}/secondary/case/{secondary_case_identifier}/unlink: post: tags: - Case Manager V2 operationId: unlinkCaseAPIV2 summary: Unlink cases from one another parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: primary_case_identifier in: path description: Unique identifier (id or uuid) of the case from which second case will be unlinked schema: type: string - name: secondary_case_identifier in: path description: Unique identifier uuid of the second case to unlink from primary case schema: type: string security: - SessionCookie: [] responses: '200': description: cases unlinked successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_identifier}/alert/{alert_uuid}/unlink: post: tags: - Case Manager V2 operationId: unlinkAlertToCaseAPIV2 summary: Unlink given alert from case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_identifier in: path description: Unique identifier (id or uuid) of the case from which alert will be unlinked schema: type: string - name: alert_uuid in: path description: Unique identifier of the alert to unlink from case schema: type: string security: - SessionCookie: [] responses: '200': description: alert unlinked successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/comment: post: tags: - Case Manager V2 operationId: addCaseCommentAPI summary: add a new comment to the case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to upsert comment required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpsertCaseCommentRequest' security: - SessionCookie: [] responses: '200': description: comment created successfully content: application/json: schema: $ref: '#/components/schemas/UpsertCaseCommentResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/comment/{comment_id}: patch: tags: - Case Manager V2 operationId: updateCaseCommentAPI summary: update a comment in the case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The uuid of the case to update comment required: true schema: type: string - name: comment_id in: path description: The uuid of the comment to be updated required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpsertCaseCommentRequest' security: - SessionCookie: [] responses: '200': description: comment updated successfully content: application/json: schema: $ref: '#/components/schemas/UpsertCaseCommentResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: deleteCaseCommentAPI summary: delete a comment in the case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The uuid of the case to delete the comment from required: true schema: type: string - name: comment_id in: path description: The uuid of the comment to be deleted required: true schema: type: string security: - SessionCookie: [] responses: '200': description: comment deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/comments: get: tags: - Case Manager V2 operationId: getCaseCommentsListAPI summary: get paginated list of case comments parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to get comments required: true schema: type: string - name: page in: query description: Page number for paginated results. required: true schema: type: integer - name: size in: query description: Number of results per page. required: true schema: type: integer security: - SessionCookie: [] responses: '200': description: comments list fetched successfully content: application/json: schema: $ref: '#/components/schemas/CaseCommentsListResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/history: get: tags: - Case Manager V2 operationId: getCaseHistoryAPI summary: get paginated list of case history parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to get history required: true schema: type: string - name: page in: query description: Page number for paginated results. required: true schema: type: integer - name: size in: query description: Number of results per page. required: true schema: type: integer - name: sort in: query description: Sort type for history. Possible values are 1 (Latest First), 5(Oldest First) schema: $ref: '#/components/schemas/CaseHistorySort' security: - SessionCookie: [] responses: '200': description: history fetched successfully content: application/json: schema: $ref: '#/components/schemas/CaseHistoryResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/history/{change_log_id}/case: get: tags: - Case Manager V2 operationId: getCaseAtHistoryEntryAPI summary: get the case reconstructed as it was at a specific history entry, read-only parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to reconstruct required: true schema: type: string - name: change_log_id in: path description: The history entry to reconstruct the case as of (inclusive) required: true schema: type: string security: - SessionCookie: [] responses: '200': description: case reconstructed successfully content: application/json: schema: $ref: '#/components/schemas/GetCaseResponseV2' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/versions: get: tags: - Case Manager V2 operationId: listCaseNamedVersionsAPI summary: list named versions for a case parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: case_uuid in: path required: true schema: type: string - name: page in: query required: true schema: type: integer - name: size in: query required: true schema: type: integer security: - SessionCookie: [] responses: '200': description: named versions fetched successfully content: application/json: schema: $ref: '#/components/schemas/ListCaseNamedVersionsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/history/{change_log_id}/version: post: tags: - Case Manager V2 operationId: createCaseNamedVersionAPI summary: name this history entry as a version parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: case_uuid in: path required: true schema: type: string - name: change_log_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CaseNamedVersionNameRequest' security: - SessionCookie: [] responses: '201': description: named version created content: application/json: schema: $ref: '#/components/schemas/CaseNamedVersionResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Case Manager V2 operationId: renameCaseNamedVersionAPI summary: rename the named version pinned to this history entry parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: case_uuid in: path required: true schema: type: string - name: change_log_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CaseNamedVersionNameRequest' security: - SessionCookie: [] responses: '200': description: named version renamed content: application/json: schema: $ref: '#/components/schemas/CaseNamedVersionResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: deleteCaseNamedVersionAPI summary: delete the named version pinned to this history entry parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: case_uuid in: path required: true schema: type: string - name: change_log_id in: path required: true schema: type: string security: - SessionCookie: [] responses: '200': description: named version deleted content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/watchers: get: tags: - Case Manager V2 operationId: getCaseWatchersAPI summary: get list of case watchers parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to get watchers required: true schema: type: string security: - SessionCookie: [] responses: '200': description: watchers fetched successfully content: application/json: schema: $ref: '#/components/schemas/CaseWatchersResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' post: tags: - Case Manager V2 operationId: addCaseWatchersAPI summary: add list of users to case watchers parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to get watchers required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpsertCaseWatchersRequest' security: - SessionCookie: [] responses: '200': description: watchers fetched successfully content: application/json: schema: $ref: '#/components/schemas/CaseWatchersResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: removeCaseWatchersAPI summary: remove list of user from case watchers parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: Execution-ID in: header description: ID of the execution if action is perfomed through a darryl action schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization schema: type: string - name: case_uuid in: path description: The id or uuid of the case to get watchers required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpsertCaseWatchersRequest' security: - SessionCookie: [] responses: '200': description: watchers deleted successfully content: application/json: schema: $ref: '#/components/schemas/CaseWatchersResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/clone: post: tags: - Case Manager V2 operationId: cloneCaseAPI summary: Clone a case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CloneCaseRequest' responses: '200': description: case cloned successfully content: application/json: schema: $ref: '#/components/schemas/CloneCaseResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/{case_uuid}/reinvestigate: post: tags: - Case Manager V2 operationId: reinvestigateCaseAPI summary: Reinvestigate a case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: case_uuid in: path description: The uuid of the case to reinvestigate required: true schema: type: string security: - SessionCookie: [] responses: '200': description: case reinvestigated successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/comments/list: post: tags: - Case Manager V2 operationId: listCaseCommentsAPI summary: List case comments parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: page in: query required: false schema: type: integer - name: size in: query required: false schema: type: integer requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ListCaseCommentsRequest' security: - SessionCookie: [] responses: '200': description: case comments listed successfully content: application/json: schema: $ref: '#/components/schemas/ListCaseCommentsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/views: post: tags: - Case Manager V2 operationId: createSavedViewAPI summary: Create a new saved view for case filters parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateSavedViewRequest' security: - SessionCookie: [] responses: '200': description: Saved view created successfully content: application/json: schema: $ref: '#/components/schemas/SavedViewResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' get: tags: - Case Manager V2 operationId: listSavedViewsAPI summary: Get list of saved views for the organization parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: is_preset in: query description: Whether to list preset views only required: false schema: type: boolean security: - SessionCookie: [] responses: '200': description: List of saved views retrieved successfully content: application/json: schema: $ref: '#/components/schemas/ListSavedViewsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/views/{view_id}: patch: tags: - Case Manager V2 operationId: updateSavedViewAPI summary: Update an existing saved view parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: view_id in: path description: ID of the saved view to update required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateSavedViewRequest' security: - SessionCookie: [] responses: '200': description: Saved view updated successfully content: application/json: schema: $ref: '#/components/schemas/SavedViewResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: deleteSavedViewAPI summary: Delete a saved view parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: view_id in: path description: ID of the saved view to delete required: true schema: type: string security: - SessionCookie: [] responses: '200': description: Saved view deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/views/preference: get: tags: - Case Manager V2 operationId: getUserViewPreferenceAPI summary: Get user's current view preference and temporary filters parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string security: - SessionCookie: [] responses: '200': description: User view preference retrieved successfully content: application/json: schema: $ref: '#/components/schemas/UserViewPreferenceResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' put: tags: - Case Manager V2 operationId: updateUserViewPreferenceAPI summary: Update user's selected view preference parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateUserViewPreferenceRequest' security: - SessionCookie: [] responses: '200': description: User view preference updated successfully content: application/json: schema: $ref: '#/components/schemas/UserViewPreferenceResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/views/preference/temp-filter: patch: tags: - Case Manager V2 operationId: updateTemporaryFiltersAPI summary: Update user's temporary filters for current session parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateTemporaryFiltersRequest' security: - SessionCookie: [] responses: '200': description: Temporary filters updated successfully content: application/json: schema: $ref: '#/components/schemas/UserViewPreferenceResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Case Manager V2 operationId: deleteTemporaryFiltersAPI summary: Delete user's temporary filters for current session parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string security: - SessionCookie: [] responses: '200': description: Saved view deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/views/preference/selected-view: delete: tags: - Case Manager V2 operationId: clearSelectedViewPreferenceAPI summary: Clear user's selected view preference parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string security: - SessionCookie: [] responses: '200': description: Selected view preference cleared successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/custom/fields: post: tags: - Case Manager V2 operationId: createCustomCaseFieldsAPI summary: create a new custom field that can be used in cases parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateCustomCaseFieldRequest' security: - SessionCookie: [] responses: '200': description: custom case field created successfully content: application/json: schema: $ref: '#/components/schemas/UpsertCustomCaseFieldResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/custom/fields/list: post: tags: - Case Manager V2 operationId: getCustomCaseFieldsAPI summary: get custom case fields that the organization has access to parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: organization_id in: query description: Organization ID to filter custom case fields by. required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetCustomCaseFieldsRequest' security: - SessionCookie: [] responses: '200': description: custom case fields retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetCustomCaseFieldsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/custom/fields/{field_id}: delete: tags: - Case Manager V2 operationId: deleteCustomCaseFieldAPI summary: delete a custom field if its not used in any case parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: field_id in: path description: The uuid of the custom field required: true schema: type: string security: - SessionCookie: [] responses: '200': description: custom case fields deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Case Manager V2 operationId: updateCustomCaseFieldsAPI summary: update a case custom field (title) parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: field_id in: path description: The uuid of the custom field required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateCustomCaseFieldRequest' security: - SessionCookie: [] responses: '200': description: custom case field updated successfully content: application/json: schema: $ref: '#/components/schemas/UpsertCustomCaseFieldResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/custom/fields/values: get: tags: - Case Manager V2 operationId: getCustomCaseFieldValuesAPI summary: get custom case field values that are present in the cases available to the… parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: page in: query description: The page number to retrieve required: true schema: type: integer - name: size in: query description: The number of items to retrieve per page required: true schema: type: integer - name: search in: query description: The search query to filter the custom case fields by required: false schema: type: string security: - SessionCookie: [] responses: '200': description: custom case fields and their values retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetCustomCaseFieldValuesResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/configuration: get: tags: - Case Manager V2 operationId: getCaseConfigurationAPI summary: get case configuration for the organizations parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetCaseConfigurationRequest' security: - SessionCookie: [] responses: '200': description: case configuration retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetCaseConfigurationResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Case Manager V2 operationId: updateCaseConfigurationAPI summary: Update case configuration fields (hidden_dashboard_widgets only) parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateCaseConfigurationRequest' security: - SessionCookie: [] responses: '200': description: case configuration updated successfully content: application/json: schema: $ref: '#/components/schemas/UpdateCaseConfigurationResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' post: tags: - Case Manager V2 operationId: createCaseConfigurationAPI summary: create a new case configuration for the organization parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OrganizationCaseConfiguration' security: - SessionCookie: [] responses: '200': description: case configuration created successfully content: application/json: schema: $ref: '#/components/schemas/OrganizationCaseConfigurationResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/configuration/copy: post: tags: - Case Manager V2 operationId: copyCaseConfigurationAPI summary: copy case configuration for the organizations parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: from_organization_id in: query description: The organization id to copy the case configuration from required: true schema: type: string - name: to_organization_id in: query description: The organization id to copy the case configuration to required: true schema: type: string security: - SessionCookie: [] responses: '200': description: case configuration copied successfully content: application/json: schema: $ref: '#/components/schemas/OrganizationCaseConfigurationResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /v2/case/dashboard/chart-config: get: tags: - Case Manager V2 operationId: getDashboardChartConfigAPI summary: Get saved chart config (widget_id -> chart_type) for an OOB dashboard parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: dashboard_source in: query required: true description: OOB dashboard identifier (case_analytics, soc_performance or executive). schema: type: string - name: organization_id in: query required: false description: Target organization. Defaults to the requestor's organization. schema: type: string security: - SessionCookie: [] responses: '200': description: chart config retrieved successfully content: application/json: schema: $ref: '#/components/schemas/DashboardChartConfigResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Case Manager V2 operationId: updateDashboardChartConfigAPI summary: Add or update chart types for widgets on an OOB dashboard parameters: - name: User-ID in: header description: The User ID of the requestor. required: true schema: type: string - name: Organization-ID in: header description: The Organization ID associated with the requestor. required: true schema: type: string - name: X-Request-ID in: header description: The ID associated with the request schema: type: string - name: dashboard_source in: query required: true description: OOB dashboard identifier (case_analytics, soc_performance or executive). schema: type: string - name: organization_id in: query required: true description: Target organization to update chart config for. schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateDashboardChartConfigRequest' security: - SessionCookie: [] responses: '200': description: chart config updated successfully content: application/json: schema: $ref: '#/components/schemas/DashboardChartConfigResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: CaseHistorySort: type: integer enum: - 1 - 5 x-enum-varnames: - LatestFirst - OldestFirst UpdateCaseResponseV2: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseDetailsV2' description: updated case object SavedViewResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/SavedView' UpdateCaseStructuredData: type: object properties: entities: type: array items: $ref: '#/components/schemas/Entity' description: Entities of the structured data. This will replace the existing entities list. geo_info: type: array items: $ref: '#/components/schemas/GeoInfo' description: Geo info of the structured data. This will replace the existing geo info list. events: type: array items: $ref: '#/components/schemas/Event' description: Events of the structured data. This will replace the existing events list. relationships: type: array items: $ref: '#/components/schemas/Relationship' description: Relationships of the structured data. This will replace the existing relationships list. CaseAnalyticsWidget: type: string enum: - top_attacking_ips - persistent_ips - internal_ips - top_attacking_domains - common_iocs - repeat_targeted_users - users_in_malicious_activity - users_high_false_positives - multi_vector_targeted_users - hosts_in_malicious_activity - multi_vector_targeted_hosts - repeat_incident_hosts - high_value_detections - false_positive_alert_types - uninvestigated_alerts - missing_data - cases_over_time - cases_by_severity - cases_by_threat_type - high_severity_by_threat_type - emerging_threats - unresolved_actions - customer_action_cases OrganizationCaseConfigurationResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/OrganizationCaseConfiguration' CaseResponseData: type: object required: - case - alerts properties: case: $ref: '#/components/schemas/CaseDetailsV2' alerts: type: array items: $ref: '#/components/schemas/GetAlertResponse' CreateCaseResponseV2: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseDetailsV2' description: created case object CaseConfidence: type: object required: - score - summary - assumptions - missing_information properties: score: type: integer description: Number indicating the confidence of the investigation and conclusion summary: type: string description: Describe how the confidence number was established assumptions: type: string description: Assumptions made while investigating the case missing_information: type: string description: Information that was missing while investigating the case GetCaseConfigurationRequest: type: object required: - organization_ids properties: organization_ids: type: array items: type: string description: Organization ids to get case configurations for CaseCategory: type: object required: - category_name properties: category_name: type: string sub_categories: type: array items: $ref: '#/components/schemas/CaseSubCategory' ListCaseCommentsResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseComment' total: type: integer description: Total number of comments found. UserDetail: type: object required: - firstname - user_uuid - email properties: firstname: type: string lastname: type: string email: type: string user_uuid: type: string CreateCaseRequestV2: type: object required: - name properties: name: type: string description: Title to be set for the case description: type: string description: Description to be set for the case case_uuid: type: string description: Unique identifier of case organization_identifier: type: string description: Identifier (uuid or org code) of the organization associated with the case type: $ref: '#/components/schemas/CaseType' description: Default value is 5 signifying v2 case type. v1 is deprecated. status: type: integer status_label: type: string severity: type: integer severity_label: type: string disposition: type: integer disposition_label: type: string category: type: string description: category the case belongs to sub_category: type: string description: sub category the case belongs to based on category assignee: type: string description: Unique identifier of the assignee assignee_email: type: string description: Email of the assigned user assignee_usergroup_name: type: string description: Name of the assignee user group assignee_usergroup_organization: type: string description: Organization code of the assignee user group is_customer_request: type: boolean description: If this flag is true then reporter field will be honored, otherwise repporter will be the user who sent the request reporter: type: string description: Uuid of the reporting user reporter_email: type: string description: Email of the reporting user performed_by_darryl: type: boolean is_agentic_case: type: boolean description: Flag indicating whether the case was created by agentic investigation agentic_investigation_id: type: string description: ID of the agentic investigation associated with this case adr_triage: $ref: '#/components/schemas/AdrTriage' description: Indicates if triage was done through automation, analyst or combination. Possible Values are 0(NA), 1(None), 5(Partial), 10(Full) case_detail_fields: $ref: '#/components/schemas/AddCaseDetailFieldsRequest' description: Case summary object linked_sessions: type: array items: type: string description: Linked sessions with the case watchers: type: array items: type: string description: Uuids of users to be added to watchers list watcher_emails: type: array items: type: string description: Emails of the users to be added to watchers list confidence: $ref: '#/components/schemas/CaseConfidence' description: Confidence in the investigation and conclusion of the case template_version: type: string description: Version of the template used to create the case UpdateCaseConfigurationRequest: type: object required: - organization_id properties: organization_id: type: string hidden_dashboard_widgets: $ref: '#/components/schemas/HiddenDashboardWidgets' description: Widget visibility config to update. Replaces existing hidden_dashboard_widgets. CaseActivity: type: object required: - happened_at - activity_summary - activity_details - activity_severity properties: happened_at: type: integer format: int64 description: Timestamp of the activity activity_summary: type: string description: Summary of the activity activity_details: type: string description: Details of the activity activity_severity: $ref: '#/components/schemas/ActionSeverityLevel' description: Severity of the activity FieldType: type: string enum: - case - name - disposition - status - assignee - reporter - is_customer_request - severity - category - sub_category - archived - escalated_to_customer - executive_summary - actions_required - findings - evidences - alert_details - linked_cases - linked_alerts - comment - provider - sla_response_met - escalations - custom_field_values x-enum-varnames: - case - name - disposition - status - assignee - reporter - is_customer_request - severity - category - sub_category - archived - escalated_to_customer - executive_summary - actions_required - findings - evidences - alert_details - linked_cases - linked_alerts - comment - provider - sla_response_met - escalations - custom_field_values UpdateCaseRequestV2: type: object properties: name: type: string description: Title to be set for the case description: type: string description: Description to be set for the case status: type: integer status_label: type: string severity: type: integer severity_label: type: string disposition: type: integer disposition_label: type: string disposition_summary: type: string description: Human-readable summary of the case disposition investigation_tier: type: string description: Investigation tier (L1, L2, L3) the case was investigated at. When provided, weekly investigation credits are deducted for the organization based on the tier's cost, and the tier's model (from investigation_cost_templates) is stored on the case. category: type: string description: category the case belongs to sub_category: type: string description: sub category the case belongs to based on category assignee: type: string description: Uuid of the assigned user assignee_email: type: string description: Email of the assigned user assignee_usergroup_name: type: string description: Name of the assignee user group assignee_usergroup_organization: type: string description: Organization code of the assignee user group archived: type: boolean description: Unarchive case if it's archived. (no change if its true) escalations: $ref: '#/components/schemas/UpsertEscalation' performed_by_darryl: type: boolean is_agentic_case: type: boolean description: Flag indicating whether the case was created by agentic investigation agentic_investigation_id: type: string description: ID of the agentic investigation associated with this case adr_triage: $ref: '#/components/schemas/AdrTriage' description: Indicates if triage was done through automation, analyst or combination. Possible Values are 0(NA), 1(None), 5(Partial), 10(Full) sla_response_met: type: boolean description: Flag to indicate feedback for a case on whether it met the SLA response or not. case_detail_fields: $ref: '#/components/schemas/UpdateCaseDetailFieldsRequest' description: Case details object replace_case_details: type: boolean description: If this field is true, case details provided in case_detail_fields will be replace. Otherwise, it will append to previously existing value. append_mode: description: Specify how to append data to existing one. Use 0 for new line, 1 for space. $ref: '#/components/schemas/AppendMode' marked_for_review: type: boolean description: if true, case will be marked for review confidence: $ref: '#/components/schemas/UpdateConfidenceRequest' description: Confidence in the investigation and conclusion of the case template_version: type: string description: Version of the template used to update the case structured_data: $ref: '#/components/schemas/UpdateCaseStructuredData' description: Structured data of the case CausalityGraphEdge: type: object required: - from - to properties: from: type: string description: Source node id to: type: string description: Target node id label: type: string description: Causal action linking the two nodes, e.g. "spawned", "beaconed to" CloneCaseResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseResponseData' ProviderSummary: type: object required: - name - display_name - logo_url - provider_id properties: name: type: string display_name: type: string logo_url: type: string provider_id: type: string CaseListResponseV2: type: object required: - message - data - total - metadata properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseV2' description: list of minimal case objects total: type: integer description: total number of cases found that match the given filter(s) metadata: $ref: '#/components/schemas/CaseListSummary' description: summary representing counts of all groups of cases list case_matches_filter: type: boolean description: present only when check_case_uuid was provided in the request; true if that case matches the current filter and search generated_query: type: string description: present only when nl_query was provided; the advanced query language string the natural-language query was translated into UploadCaseAttachmentResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseAttachment' UpdateCaseDetailFieldsRequest: type: object properties: executive_summary: type: string actions_required: type: array items: $ref: '#/components/schemas/UpsertCaseAction' description: List of actions required for completion of case alert_details: type: string provider_id: type: string linked_alerts: type: array items: $ref: '#/components/schemas/UpsertLinkedAlertSource' primary_alert_id: type: string description: primary alert id in a case timeline: $ref: '#/components/schemas/CaseTimeline' description: Timestamps and duration between different milestions of case activity_timeline: type: array items: $ref: '#/components/schemas/CaseActivity' description: Timeline of the activities to be added to the existing activity timeline. custom_field_values: type: array items: $ref: '#/components/schemas/UpsertCustomFieldValue' description: Custom fields to be created/updated/deleted investigation_summary: type: string description: Investigation summary to be added in the case conclusion: type: string description: Conclusion of the case conclusion_overview: $ref: '#/components/schemas/ConclusionOverview' description: Overview of the conclusion of the case faqs: type: array items: $ref: '#/components/schemas/UpsertFaqRequest' description: FAQs to be added in the case custom_questions: type: array items: $ref: '#/components/schemas/UpsertCustomQuestionRequest' description: Custom questions to be added in the case explore_deeper_questions: type: array items: $ref: '#/components/schemas/UpsertExploreDeeperQuestionRequest' description: Explore deeper questions to be added in the case alert_metadata: type: object additionalProperties: type: string description: Arbitrary string key-value metadata associated with the alert causality_graph: $ref: '#/components/schemas/CausalityGraph' description: Directed causality chain graph tracing the incident from root cause to outcome fact_ids: type: array items: type: string description: IDs of knowledge-service facts to associate with the case AddCommentSource: type: integer enum: - 0 - 1 - 2 - 5 - 6 x-enum-varnames: - User - EscalationToCustomer - EscalationToAnalyst - DescalationToCustomer - DescalationToAnalyst UpsertLinkedAlertSource: type: object properties: name: type: string path: type: string uuid: type: string deleted: type: boolean type: $ref: '#/components/schemas/LinkedAlertSourceType' description: Possible Values are 0(Internal alert), 1 (external link) EntityRiskLabel: type: string enum: - benign - suspicious - malicious x-enum-varnames: - EntityRiskLabelBenign - EntityRiskLabelSuspicious - EntityRiskLabelMalicious ResourceType: type: integer enum: - 1 x-enum-varnames: - Case UpsertCaseCommentResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseComment' description: Comment added successfully CaseNamedVersion: type: object required: - case_uuid - change_log_id - name - created_by - created_at properties: case_uuid: type: string change_log_id: type: string name: type: string created_by: $ref: '#/components/schemas/UserInformation' created_at: type: integer format: int64 SavedView: type: object required: - view_id - organization_id - name - filter - created_by - created_at - is_default - is_preset properties: view_id: type: string description: Unique identifier for the saved view organization_id: type: string description: Organization ID this view belongs to name: type: string description: Name of the saved view filter: $ref: '#/components/schemas/CaseFilterV2' description: Filter configuration for this view sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Sort configuration for this view created_by: $ref: '#/components/schemas/UserDetails' created_at: type: integer format: int64 modified_by: $ref: '#/components/schemas/UserDetails' modified_at: type: integer format: int64 is_default: type: boolean description: Whether this is the default view for the organization view_mode: $ref: '#/components/schemas/CaseViewMode' description: Specify the view mode - anaylst view or reader view view_settings: $ref: '#/components/schemas/ViewSettings' description: Settings for the view. is_preset: type: boolean description: Whether this is a preset view UpdateCaseFindingRequest: type: object properties: title: type: string description: Finding title summary: type: string description: Detailed description of finding risk: type: integer risk_label: type: string hidden: type: boolean description: If true, the finding will not be shown in the UI evidences: type: array items: $ref: '#/components/schemas/UpsertEvidenceRequest' description: Evidence provided in support of the finding decision_iocs: type: array items: $ref: '#/components/schemas/DecisionIoc' ai_reasoning: type: string description: AI reasoning for adding the finding to the case UpsertCustomCaseFieldResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CustomField' CreateSavedViewRequest: type: object required: - name - filter - is_preset properties: name: type: string description: Name for the new saved view filter: $ref: '#/components/schemas/CaseFilterV2' description: Filter configuration to save sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Sort configuration for this view is_default: type: boolean description: Whether to set this as the default view view_mode: $ref: '#/components/schemas/CaseViewMode' description: Specify the view mode - anaylst view or reader view view_settings: $ref: '#/components/schemas/ViewSettings' description: Settings for the view. is_preset: type: boolean description: Whether this is a preset view CaseExecutionDetails: type: object properties: case_id: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_playbook_id: type: string investigation_playbook_name: type: string execution_id: type: string linked_manually: type: boolean description: Flag to indicate if the case was linked manually or through investigation playbook is_agentic_case: type: boolean description: whether the linked case was created by agentic investigation UserViewPreferenceResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/UserViewPreference' ChangelogActionType: type: integer enum: - 0 - 1 - 2 - 5 - 10 - 11 - 12 x-enum-varnames: - NoChange - Add - Create - Update - Delete - Remove - Archive ExecutionSummary: type: object required: - skill_id - skill_name - execution_link properties: skill_id: type: string skill_name: type: string execution_link: type: string RelationshipType: type: string enum: - uses - connects_to - owns - authenticates_as - resolves_to - downloaded - executed - modified - sent_email_to - lateral_moved_to - belongs_to - other x-enum-varnames: - RelationshipTypeUses - RelationshipTypeConnectsTo - RelationshipTypeOwns - RelationshipTypeAuthenticatesAs - RelationshipTypeResolvesTo - RelationshipTypeDownloaded - RelationshipTypeExecuted - RelationshipTypeModified - RelationshipTypeSentEmailTo - RelationshipTypeLateralMovedTo - RelationshipTypeBelongsTo - RelationshipTypeOther EventOutcome: type: string enum: - success - failure - partial - unknown x-enum-varnames: - EventOutcomeSuccess - EventOutcomeFailure - EventOutcomePartial - EventOutcomeUnknown CreateCustomCaseFieldRequest: type: object required: - title - type - scope properties: title: type: string description: Title of the custom field type: $ref: '#/components/schemas/CustomFieldType' description: Type of the custom field. Possible values are 0(Text), 5(Boolean), 10(DateTime) scope: $ref: '#/components/schemas/CustomFieldScope' description: Scope of the custom field. Possible values are 0(Organizational), 5(Shared) organization_id: type: string description: Organization to create custom field in. If value is not set, field will be created in the organization present in headers. CaseTimeline: type: object properties: alert_raised_at: type: integer format: int64 description: Timestamp of the Alert raised at source alert_acknowledged_at: type: integer format: int64 description: Timestamp of the Alert acknowledged at AirMDR System case_disposition_created_at: type: integer format: int64 description: Timestamp of the Case disposition created escalated_to_customer_at: type: integer format: int64 description: Timestamp when the case was escalated to customer investigation_completed_at: type: integer format: int64 description: Timestamp when case investigation is completed case_contained_at: type: integer format: int64 description: Timestamp when case is moved into contained status case_closed_at: type: integer format: int64 description: Timestamp when case is moved into closed status reinvestigated_at: type: integer format: int64 description: Timestamp when case is created for reinvestigation LinkedAlertSource: type: object required: - uuid - type - name - path properties: type: $ref: '#/components/schemas/LinkedAlertSourceType' description: Possible Values are 0(Internal alert), 1 (external link) name: type: string path: type: string uuid: type: string alert_link: type: string ScoreStatus: type: string enum: - not_generated - in_progress - completed x-enum-varnames: - ScoreStatusNotGenerated - ScoreStatusInProgress - ScoreStatusCompleted EventSeverity: type: string enum: - info - low - medium - high - critical x-enum-varnames: - EventSeverityInfo - EventSeverityLow - EventSeverityMedium - EventSeverityHigh - EventSeverityCritical CaseNamedVersionResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseNamedVersion' EmailCaseFindingDetailsResponse: type: object required: - message - failed_deliveries properties: message: type: string failed_deliveries: type: array items: type: string description: list of emails the case finding details could not be sent to GetCustomCaseFieldValuesResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseCustomFieldValue' description: list of all the custom case fields and their values present in the cases available to the organization total: type: integer description: total number of custom case field values found that match the given search query ConnectionDetails: type: object properties: connection_id: type: string connection_name: type: string UpsertCustomQuestionRequest: type: object required: - question_id properties: question: type: string answer: type: string question_id: type: string guideline: type: string deleted: type: boolean description: To delete an existing question, send this flag as true add_to_template: type: boolean description: To add the question to the template for future use, send this flag as true EntityType: type: string enum: - user - service_account - host - ip - domain - file_hash - cloud_resource - process - threat_actor x-enum-varnames: - EntityTypeUser - EntityTypeServiceAccount - EntityTypeHost - EntityTypeIP - EntityTypeDomain - EntityTypeFileHash - EntityTypeCloudResource - EntityTypeProcess - EntityTypeThreatActor UpsertCaseAction: type: object properties: uuid: type: string description: unique identifier of the action title: type: string description: Information on action required status: type: integer status_label: type: string assignee: type: string assignee_email: type: string created_at: type: integer format: int64 description: Timestamp of creation of the action. modified_at: type: integer format: int64 description: Timestamp of the last modification of the action completed_at: type: integer format: int64 description: Timestamp of the completion of the action deleted: type: boolean description: To delete an existing action, send this flag as true action_severity: $ref: '#/components/schemas/ActionSeverityLevel' session_id: type: string description: Session ID of the action where execution of the action took place required: type: boolean description: Whether this action is required description: type: string description: Description of the action required type: type: string enum: - approval - customer_action - answer_question description: Type of action; null is treated as customer_action blocking_reason: type: string description: Reason this action is blocking the case; only set when type is customer_action blocking_fact_id: type: string description: ID of the fact this action is blocking; only set when type is customer_action playbook_id: type: string description: ID of the playbook associated with this action; only set when type is approval priority: type: string enum: - Containment - Required - Recommended description: Priority of the action; when set on create/update, the required flag is derived from it (Containment/Required -> true, Recommended -> false) evidences: type: array items: type: string description: Free-form evidence text snippets associated with the action status_v2: $ref: '#/components/schemas/ActionStatusV2' description: Lifecycle status of the action, kept in sync with status. If both status and status_v2 are set on write, status_v2 takes priority and status is derived from it. For type approval/answer_question, only completed/will_not_do may be set directly; customer_action allows all values. execution_details: $ref: '#/components/schemas/ActionExecutionDetails' description: Details of the playbook execution triggered externally for this action; only set when type is approval. Set this to record execution_id/started_by when the execution is triggered; the poller updates status_v2/type once the execution reaches a terminal state. CustomFieldValue: type: object required: - uuid - value properties: uuid: type: string description: UUID of the custom field value: description: Value of the custom field CloneCaseRequest: type: object required: - case_id properties: case_id: type: string description: ID of the case to clone target_organization_code: type: string description: Code of the organization to clone the case to dry_run: type: boolean description: Whether to clone the case or just return the generated values regenerate_obfuscated_values: type: boolean description: Flag to regenerate the obfuscated values prompt: type: string description: Prompt to use for the clone max_evidence_size: type: integer description: Maximum size of the evidence to be cloned UpdateTemporaryFiltersRequest: type: object properties: temp_filter: $ref: '#/components/schemas/CaseFilterV2' description: Temporary filter configuration to apply. Only provided fields will be updated. temp_sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Temporary sort configuration for current session. Will replace existing sort configuration if provided. selected_case_id: type: string description: ID of the currently selected case selected_view_mode: $ref: '#/components/schemas/CaseViewMode' description: Specify the user selectedview mode - anaylst view or reader view EntityFilterItem: type: object required: - value properties: type: $ref: '#/components/schemas/EntityType' description: Type of the entity to filter on (e.g. ip, domain) value: type: string description: Value of the field to filter on ConclusionOverview: type: object required: - summary - key_evidence properties: summary: type: string description: Summary of the conclusion key_evidence: type: string description: Key evidences supporting the conclusion UpsertExploreDeeperQuestionRequest: type: object required: - question_id properties: question_id: type: string description: Question ID of the explore deeper question title: type: string description: Title of the explore deeper question description: type: string description: Description of the explore deeper question status: $ref: '#/components/schemas/ExploreDeeperQuestionStatus' description: Status of the explore deeper question exploration_type: $ref: '#/components/schemas/ExplorationType' description: Type of exploration for the explore deeper question required_data: type: string description: Required data for the explore deeper question answer: type: string description: Answer to the explore deeper question key_identifiers: type: array items: type: string description: Key identifiers used to identify the data for the explore deeper question deleted: type: boolean description: To delete an existing explore deeper question, send this flag as true CaseDetailsV2: type: object required: - case_id - case_uuid - organization_id - organization_name - organization_code - name - type - status - status_label - severity - severity_label - priority - disposition - disposition_label - category - sub_category - assignee - reporter - archived - adr_triage - sla_response_met - is_customer_request - case_detail_fields - created_at - modified_at - status_modified_at - case_link - watchers_count properties: case_id: type: string description: Unique number respresenting case of an organization case_uuid: type: string description: Unique identifier of case organization_id: type: string description: Identifier of the organization associated with the case organization_name: type: string description: Name of the organization the case belongs to organization_code: type: string description: Code of the organization the case belongs to name: type: string description: Title of the case description: type: string description: Description of the case type: $ref: '#/components/schemas/CaseType' description: Default value is 5 signifying v2 case type. v1 is deprecated. status: type: integer status_label: type: string disposition: type: integer disposition_label: type: string disposition_summary: type: string description: Human-readable summary of the case disposition severity: type: integer severity_label: type: string priority: description: Possible values are 0 (Need Attention), 1 (Active), 5(Closed) $ref: '#/components/schemas/CasePriorityV2' category: type: string description: category the case belongs to sub_category: type: string description: sub category the case belongs to based on category assignee: $ref: '#/components/schemas/AssigneeDetails' reporter: $ref: '#/components/schemas/UserDetails' archived: type: boolean description: Flag indicating if the case has been archived or not escalations: type: array items: $ref: '#/components/schemas/Escalation' adr_triage: $ref: '#/components/schemas/AdrTriage' description: Indicates if triage was done through automation, analyst or combination. Possible Values are 0(NA), 1(None), 5(Partial), 10(Full) is_agentic_case: type: boolean description: Flag indicating whether the case was created by agentic investigation agentic_investigation_id: type: string description: ID of the agentic investigation associated with this case sla_response_met: type: boolean is_customer_request: type: boolean case_detail_fields: $ref: '#/components/schemas/CaseDetailFields' description: Case details object created_at: type: integer format: int64 description: Timestamp of creation of the case. modified_at: type: integer format: int64 description: Timestamp of the last modification of the case status_modified_at: type: integer format: int64 description: Timestamp of the last status modification of the case linked_sessions: type: array items: $ref: '#/components/schemas/ChatSessionDetail' description: Linked sessions with the case linked_cases: type: array items: $ref: '#/components/schemas/CaseV2' description: Other linked cases with the case case_link: type: string description: link to the case manager execution_link: type: string description: link of the execution if the case was created through a darryl action watchers_count: type: integer description: Number of watchers associated with the case. reviewed: type: boolean description: if true, case has been reviewed marked_for_review: type: boolean description: if true, case is marked for review ignore_metrics: type: boolean description: if true, case is ignored from metrics case_reinvestigated: type: boolean description: if true, case is crreated through reinvestigation confidence: $ref: '#/components/schemas/CaseConfidence' description: Confidence in the investigation and conclusion of the case template_version: type: string description: Version of the template used to create the case investigation_tier: type: string description: Investigation tier (L1, L2, L3) the case was investigated at model: type: string description: Model used to investigate the case (e.g. sonnet, haiku, gemini) structured_data: $ref: '#/components/schemas/CaseStructuredData' description: Structured data of the case agentic_investigation_url: type: string description: Pre-signed S3 URL for the agentic investigation case writeup, present only when the linked alert was investigated by the agent UpsertCustomFieldValue: type: object required: - field_identifier - value properties: field_identifier: type: string description: Identifier of the custom field (can be string or uuid) value: description: Value of the custom field deleted: type: boolean description: Whether the custom field is deleted EnumOption: type: object required: - key - label properties: key: type: number label: type: string style_config: $ref: '#/components/schemas/StyleConfig' UserViewPreference: type: object required: - user_id - organization_id - selected_view_id - selected_preset_id - last_updated properties: user_id: type: string description: UUID of the user organization_id: type: string description: Organization ID this preference belongs to selected_view_id: type: string description: ID of the currently selected saved view selected_preset_id: type: string description: ID of the currently selected preset view selected_case_id: type: string description: ID of the currently selected case selected_view_filter: $ref: '#/components/schemas/CaseFilterV2' description: Filter configuration from the selected saved view selected_view_sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Sort configuration from the selected saved view temp_filter: $ref: '#/components/schemas/CaseFilterV2' description: Temporary filter configuration for current session temp_sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Temporary sort configuration for current session selected_view_mode: $ref: '#/components/schemas/CaseViewMode' description: Specify the user selectedview mode - anaylst view or reader view last_updated: type: integer format: int64 description: Timestamp of last preference update view_settings: $ref: '#/components/schemas/ViewSettings' description: Settings for the view. CausalityGraph: type: object properties: title: type: string description: Title of the graph, e.g. "Causality chain" direction: type: string description: Layout direction — always "TB" (top-to-bottom) for causality chains enum: - TB default: TB nodes: type: array items: $ref: '#/components/schemas/CausalityGraphNode' edges: type: array items: $ref: '#/components/schemas/CausalityGraphEdge' UpdateCustomCaseFieldRequest: type: object properties: title: type: string description: Updated title of the custom field ExploreDeeperQuestionStatus: type: string enum: - Available - Data Needed x-enum-varnames: - AvailableExploreDeeperQuestionStatus - DataNeededExploreDeeperQuestionStatus CaseSection: type: string enum: - Executive Summary - Incident Graph - Attack Timeline - Timeline - Investigation Plan - Conclusion - Alert Details - Actions - Your Questions - Explore Deeper - FAQs - Comments and Reviews x-enum-varnames: - ExecutiveSummaryCaseSection - IncidentGraphCaseSection - AttackTimelineCaseSection - TimelineCaseSection - InvestigationPlanCaseSection - ConclusionCaseSection - AlertDetailsCaseSection - ActionsCaseSection - YourQuestionsCaseSection - ExploreDeeperCaseSection - FAQsCaseSection - CommentsAndReviewsCaseSection StyleConfig: type: object properties: bg_color: type: string font_color: type: string font_size: type: string border: type: string border_radius: type: string size: type: string start_adornments: $ref: '#/components/schemas/Adornments' end_adornments: $ref: '#/components/schemas/Adornments' text_class: type: string show_clock_icon: type: boolean wrapper_class: type: string show_modified_at_time: type: boolean tooltip_title: type: string icon_src: type: string icon_color: type: string CaseWatchers: type: object required: - firstname - lastname - email - user_uuid - organization_uuid - organization_name properties: firstname: type: string lastname: type: string user_uuid: type: string organization_uuid: type: string organization_name: type: string email: type: string UpsertCaseFinding: type: object required: - finding - modified_at properties: finding: $ref: '#/components/schemas/CaseFinding' description: updated case finding object modified_at: type: integer format: int64 Adornments: type: object required: - type - src - size properties: type: type: string src: type: string size: type: string CaseView: type: integer enum: - 0 - 1 x-enum-varnames: - CustomerCaseView - AnalystCaseView EntityFilter: type: object required: - items properties: operator: type: string description: Operator to combine the entity filter items. Can be "and" or "or". Default is "and". enum: - and - or x-enum-varnames: - EntityFilterOperatorAnd - EntityFilterOperatorOr items: type: array items: $ref: '#/components/schemas/EntityFilterItem' description: List of entity filter items to filter on LinkedAlertSourceType: type: integer enum: - 0 - 1 x-enum-varnames: - InternalAlertSourceType - ExternalAlertSourceType UpsertCaseCommentRequest: type: object required: - content properties: content: type: string content_style: type: string rating: type: integer comment_privacy: $ref: '#/components/schemas/CommentPrivacy' comment_type: $ref: '#/components/schemas/CommentType' attachment_uuids: type: array description: 'Uuids of images previously uploaded with section=comment and not yet claimed by a comment. The server attaches them to this comment. On update, this is the complete set: uuids omitted here are detached and deleted, so send the full list rather than a delta. ' items: type: string CaseStructuredData: type: object required: - entities - events - relationships properties: entities: type: array items: $ref: '#/components/schemas/Entity' geo_info: type: array items: $ref: '#/components/schemas/GeoInfo' events: type: array items: $ref: '#/components/schemas/Event' relationships: type: array items: $ref: '#/components/schemas/Relationship' CaseScoreMinimal: type: object required: - score - score_status properties: score: type: number description: Score of the case score_status: $ref: '#/components/schemas/ScoreStatus' description: Status of the score UpdateCaseFindingResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/UpsertCaseFinding' description: updated case finding object with timestamp AlertTypeSeverity: type: integer enum: - 10 - 20 - 30 - 40 x-enum-varnames: - AlertTypeSeverityLow - AlertTypeSeverityMedium - AlertTypeSeverityHigh - AlertTypeSeverityCritical ActionStatusV2: type: string enum: - open - in_progress - blocked - completed - will_not_do description: 'Lifecycle status of an action, kept in sync with status. Mapping from status: 0/New -> open, 1/Pending -> in_progress, 2/Customer Pending -> blocked, 3/Approved -> in_progress, 4/Rejected -> will_not_do, 5/Completed -> completed.' ListCaseAttachmentsResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseAttachment' total: type: integer CaseAttachment: type: object required: - attachment_uuid - case_uuid - section - content_path - content_type - size_bytes - original_filename - created_at properties: attachment_uuid: type: string description: Unique identifier of the attachment case_uuid: type: string description: Uuid of the case the attachment belongs to comment_id: type: string description: 'Set when section is comment, identifying which comment the image belongs to. Absent while an upload is still unclaimed, and absent entirely for other sections. ' section: type: string description: Which section of the case the image is rendered under enum: - alert_details - comment content_path: type: string description: 'Service relative path to stream the image bytes from. Use this directly as the src of an img element. It is relative rather than absolute because organizations can be served from different hosts, and it never expires. ' content_type: type: string description: The image type detected from the file contents at upload time size_bytes: type: integer format: int64 description: Size of the stored image in bytes width: type: integer description: Pixel width, so the UI can reserve layout space before the image loads height: type: integer description: Pixel height, so the UI can reserve layout space before the image loads sha256: type: string description: SHA-256 of the stored bytes original_filename: type: string description: Sanitized filename supplied by the uploader, for display only caption: type: string description: Optional analyst supplied caption uploaded_by: $ref: '#/components/schemas/UserInformation' created_at: type: integer format: int64 description: Upload time as a unix timestamp HiddenDashboardWidgets: type: object properties: case_analytics_widgets: type: array items: $ref: '#/components/schemas/CaseAnalyticsWidget' description: Analytics dashboard widget IDs to hide. soc_performance_widgets: type: array items: $ref: '#/components/schemas/SocPerformanceWidget' description: SOC performance dashboard widget IDs to hide. ViewSettings: type: object required: - single_column_view - sections properties: single_column_view: type: boolean description: Whether to show the view in single column mode. sections: type: array items: $ref: '#/components/schemas/SectionSetting' description: Sections to show in the view. layout: $ref: '#/components/schemas/ViewLayout' description: Layout configuration. Null means no layout; fall back to sections. hide_empty_sections: type: boolean description: 'When true, sections whose data fields are empty or null are hidden in the case viewer. When false, all configured sections render regardless of whether they have content. Defaults to true when absent. ' CaseListSummary: type: object required: - need_attention_count - active_count - closed_count properties: need_attention_count: type: integer description: total number of cases in need attention section active_count: type: integer description: total number of cases in active section closed_count: type: integer description: total number of cases in closed section AlertTypeWithProperties: type: object required: - alert_type - alert_provider - default_severity - categories - mitre_tactics properties: alert_type: type: string alert_provider: type: string default_severity: $ref: '#/components/schemas/AlertTypeSeverity' categories: type: array items: type: string mitre_tactics: type: array items: type: string AddCaseFindingResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/UpsertCaseFinding' description: created case finding object with timestamp UpdateConfidenceRequest: type: object properties: score: type: integer description: Number indicating the confidence of the investigation and conclusion summary: type: string description: Describe how the confidence number was established assumptions: type: string description: Assumptions made while investigating the case missing_information: type: string description: Information that was missing while investigating the case UpsertEvidenceRequest: type: object properties: name: type: string attached_content_link: type: string attached_content_version: type: integer attached_content_type: $ref: '#/components/schemas/EvidenceAttachmentType' description: Possible values are O (Undefined), 1(Json), 5(Pdf) data: type: string deleted: type: boolean link_existing_evidence: type: boolean description: If true, the evidence id passed in attached_content_link will be linked to the existing evidence CaseSort: type: object required: - field - sort_order properties: field: type: string description: indicates which field will be used for sorting sort_order: $ref: '#/components/schemas/SortOrder' description: indicates sort order - asc or desc CaseLinkRequest: type: object required: - case_uuids properties: case_uuids: type: array items: type: string UserInformation: type: object required: - firstname - user_id properties: firstname: type: string lastname: type: string user_id: type: string email: type: string Entity: type: object required: - id - name - type - source - tags - finding_refs - attributes properties: id: type: string description: ID of the entity name: type: string description: Name of the entity type: $ref: '#/components/schemas/EntityType' description: Type of the entity source: $ref: '#/components/schemas/EntitySource' description: Source of the entity tags: type: array items: type: string description: Tags of the entity finding_refs: type: array items: type: string description: Finding references of the entity attributes: description: Attributes of the entity display_name: type: string description: Display name of the entity display_summary: type: string description: Display summary of the entity risk: $ref: '#/components/schemas/EntityRisk' description: Risk of the entity PriorityConfig: type: object required: - need_attention_statuses - active_statuses - closed_statuses properties: need_attention_statuses: description: list of statuses that will be shown in Need attention tab type: array items: type: integer active_statuses: description: list of statuses that will be shown in Active tab type: array items: type: integer closed_statuses: description: list of statuses that will be shown in Closed tab type: array items: type: integer EntityRisk: type: object required: - score - label - reasons properties: score: type: integer label: $ref: '#/components/schemas/EntityRiskLabel' description: Label of the entity risk reasons: type: array items: type: string description: Reasons of the entity risk TimeRange: type: object properties: from_date: type: integer format: int64 to_date: type: integer format: int64 CaseCustomFieldValue: type: object required: - uuid - title - value properties: uuid: type: string description: UUID of the custom field title: type: string description: Title of the custom field value: description: Value of the custom field present in some case UpsertFaqRequest: type: object required: - question_id properties: question: type: string answer: type: string question_id: type: string deleted: type: boolean description: To delete an existing faq, send this flag as true ListSavedViewsResponse: type: object required: - message - data properties: message: type: string data: type: array items: $ref: '#/components/schemas/SavedView' description: List of saved views for the organization ProviderDetails: type: object properties: name: type: string icon: type: string provider_id: type: string ChatSessionDetail: type: object required: - chat_session_id - title - owner_details - created_at - deleted properties: chat_session_id: type: string title: type: string owner_details: $ref: '#/components/schemas/UserDetail' created_at: type: integer format: int64 deleted: type: boolean description: Flag indicating if session has been deleted or not CustomQuestion: type: object required: - question - answer - question_id - created_at - created_by properties: question: type: string answer: type: string guideline: type: string question_id: type: string created_at: type: integer format: int64 description: Timestamp of creation of the question created_by: type: string description: User ID of the user who created the question CaseCommentsListResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseComment' description: comments list fetched successfully total: type: integer description: total number of case comments found Event: type: object required: - event_id - actor - action - target - outcome - finding_refs properties: event_id: type: string description: ID of the event timestamp: type: integer description: Timestamp of the event actor: type: array items: type: string description: Actors of the event action: type: string description: Action of the event target: type: array items: type: string description: Targets of the event outcome: $ref: '#/components/schemas/EventOutcome' description: Outcome of the event summary: type: string description: Summary of the event severity: $ref: '#/components/schemas/EventSeverity' description: Severity of the event mitre_technique_id: type: string description: MITRE technique ID of the event mitre_technique_name: type: string description: MITRE technique name of the event finding_refs: type: array items: type: string description: Finding references of the event CaseDetailFields: type: object properties: executive_summary: type: string actions_required: type: array items: $ref: '#/components/schemas/CaseAction' description: List of actions required for completion of case alert_details: type: string alert_details_style: type: string alert_type: type: string description: Alert type of the primary alert in the case provider: $ref: '#/components/schemas/ProviderSummary' linked_alerts: type: array items: $ref: '#/components/schemas/LinkedAlertSource' primary_alert_id: type: string description: primary alert id in a case timeline: $ref: '#/components/schemas/CaseTimeline' description: Timestamps between different milestions of case activity_timeline: type: array items: $ref: '#/components/schemas/CaseActivity' description: Timeline of activities in the case metrics: $ref: '#/components/schemas/CaseTimelineMetrics' description: Case metrics - duration between different milestions of case findings: type: array items: $ref: '#/components/schemas/CaseFinding' description: List of findings during course of case custom_field_values: type: array items: $ref: '#/components/schemas/CustomFieldValue' description: Custom fields added in the case investigation_summary: type: string description: Investigation summary of the findings of the case conclusion: type: string description: Conclusion of the case conclusion_overview: $ref: '#/components/schemas/ConclusionOverview' description: Overview of the conclusion of the case faqs: type: array items: $ref: '#/components/schemas/Faq' description: FAQs added in the case custom_questions: type: array items: $ref: '#/components/schemas/CustomQuestion' description: Custom questions added in the case explore_deeper_questions: type: array items: $ref: '#/components/schemas/ExploreDeeperQuestion' description: Explore deeper questions added in the case alert_metadata: type: object additionalProperties: type: string description: Arbitrary string key-value metadata associated with the alert causality_graph: $ref: '#/components/schemas/CausalityGraph' description: Directed causality chain graph tracing the incident from root cause to outcome facts: type: array items: $ref: '#/components/schemas/CaseFactSummary' description: Facts associated with the case, resolved from the stored fact ids GetCaseResponseV2: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/CaseDetailsV2' description: fetched case object EntitySource: type: string enum: - alert_seed - darryl_enriched x-enum-varnames: - EntitySourceAlertSeed - EntitySourceDarrylEnriched EscalationType: type: integer enum: - 0 - 1 x-enum-varnames: - Escalated - Descalated LinkedCaseSummary: type: object properties: case_id: type: string description: Human-readable case ID disposition: type: integer description: Disposition of the case disposition_label: type: string description: Human-readable label for the case disposition disposition_summary: type: string description: Human-readable summary of the case disposition created_at: type: integer format: int64 description: Timestamp when the case was created is_agentic_case: type: boolean description: Flag indicating whether the case was created by agentic investigation agentic_investigation_id: type: string description: ID of the agentic investigation associated with this case AlertsIOC: type: object properties: ip_address: type: array items: type: string domain: type: array items: type: string username: type: array items: type: string location: type: array items: type: string hostname: type: array items: type: string url: type: array items: type: string ioc_fields: type: object CaseFilterV2: type: object properties: severity: type: array items: type: integer severity_label: type: array items: type: string status: type: array items: type: integer status_label: type: array items: type: string disposition: type: array items: type: integer disposition_label: type: array items: type: string provider: type: array items: type: string description: Provider names custom_field_values: type: array items: $ref: '#/components/schemas/CustomFieldValue' description: Custom field values assignee: type: string assignee_id: type: array items: type: string watcher: type: string description: Can either be watcher uuid, name or email organization_id: type: array items: type: string categories: type: array items: $ref: '#/components/schemas/CategoryFilter' modified_at_time_range: $ref: '#/components/schemas/TimeRange' created_at_time_range: $ref: '#/components/schemas/TimeRange' queries: type: array description: list of queries to search for in all fields. A case will be listed if it matches any of the queries items: type: string search_fields: type: array description: list of fields to search the queries in. If not provided, it will search in all fields. items: type: string archived: type: boolean description: Flag indicating if archived cases has to be searched or not only_archived: type: boolean description: if true, only archived cases are shown. Takes precedence over the archived flag. only_escalated: type: boolean description: if false, all cases are shown. If true, only escalated cases are shown. only_descalated: type: boolean description: if false, all cases are shown. If true, only de-escalated cases are shown. only_marked_for_review: type: boolean description: if false, all cases are shown. If true, only cases marked for review are shown. priority: type: array description: Priority of the case. Possible values are 0 (Need Attention), 1 (Active), 5(Closed) items: type: integer has_case_score: type: boolean description: if true, case has a score case_score: $ref: '#/components/schemas/NumberRange' description: range of the case score entities: $ref: '#/components/schemas/EntityFilter' description: filter for entities (iocs) in the case case_sensitive: type: boolean description: if true, search is case-sensitive. If false or omitted, search is case-insensitive (default) LayoutSectionItem: type: object required: - kind - id - name - children properties: kind: type: string enum: - section description: Discriminator identifying this item as a section. id: type: string description: Unique identifier for the section. name: type: string description: Display name for the section. children: type: array items: $ref: '#/components/schemas/LayoutWidgetItem' description: Widgets within this section. ViewLayout: type: object properties: main_body: type: array items: oneOf: - $ref: '#/components/schemas/LayoutSectionItem' - $ref: '#/components/schemas/LayoutWidgetItem' discriminator: propertyName: kind description: Items in the main body of the layout. pinned: type: array items: $ref: '#/components/schemas/LayoutWidgetItem' description: Pinned widgets shown outside the main body. GetEvidenceResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/Evidence' description: fetched evidence object ExploreDeeperQuestion: type: object required: - title - description - status - exploration_type - key_identifiers - question_id - created_at properties: question_id: type: string description: Question ID of the explore deeper question title: type: string description: Title of the explore deeper question description: type: string description: Description of the explore deeper question status: $ref: '#/components/schemas/ExploreDeeperQuestionStatus' description: Status of the explore deeper question exploration_type: $ref: '#/components/schemas/ExplorationType' description: Type of exploration for the explore deeper question required_data: type: string description: Required data for the explore deeper question answer: type: string description: Answer to the explore deeper question key_identifiers: type: array items: type: string description: Key identifiers used to identify the data for the explore deeper question created_at: type: integer format: int64 description: Timestamp of creation of the explore deeper question CustomFieldType: type: integer enum: - 0 - 5 - 10 x-enum-varnames: - TextCustomField - BooleanCustomField - DateTimeCustomField Error: type: object required: - message properties: message: type: string description: user friendly error message CaseSubCategory: type: object required: - sub_category_name properties: sub_category_name: type: string SortOrder: type: integer enum: - 0 - 1 x-enum-varnames: - Asc - Desc ActionSeverityLevel: type: string enum: - Critical - High - Medium - Low x-enum-varnames: - CriticalActionSeverity - HighActionSeverity - MediumActionSeverity - LowActionSeverity ListCaseCommentsRequest: type: object properties: accessible_organization_ids: type: array items: type: string description: List of organization IDs for which comments are needed. date_range: $ref: '#/components/schemas/TimeRange' description: Date range for which comments are needed. CommentSource: type: object required: - source properties: source: $ref: '#/components/schemas/AddCommentSource' description: Possible values for comment source are 0(manually by user), 1(Escalation To Customer), 2(Escalation To Analyst), 5(Descalation To Customer), 6(Descalation To Analyst) path: type: string SectionSetting: type: object required: - field_name - visible - order properties: field_name: $ref: '#/components/schemas/CaseSection' description: Name of the section visible: type: boolean description: Whether to show the section in the view. order: type: integer description: Order of the section in the view. CaseTimelineMetrics: type: object required: - alert_acknowledged_metric - investigation_completed_metric - case_contained_metric - case_closed_metric properties: alert_acknowledged_metric: type: integer format: int64 description: Difference between Alert raised at source and Alert acknowledged at AirMDR System in seconds investigation_completed_metric: type: integer format: int64 description: Difference between when case investigation is completed and Alert acknowledged at AirMDR System in seconds case_contained_metric: type: integer format: int64 description: Difference between when case is moved into contained status and Alert acknowledged at AirMDR System in seconds case_closed_metric: type: integer format: int64 description: Difference between when case is moved into closed status and Alert acknowledged at AirMDR System in seconds UpdateUserViewPreferenceRequest: type: object required: - selected_view_id - selected_preset_id properties: selected_view_id: type: string description: ID of the saved view to select selected_preset_id: type: string description: ID of the preset view to select GetCustomCaseFieldsRequest: type: object properties: search_query: type: string description: Search custom fields that matches the query sort: $ref: '#/components/schemas/CaseSort' description: Sort order for the custom fields GetCaseConfigurationResponse: type: object required: - message - data properties: message: type: string data: type: array items: $ref: '#/components/schemas/OrganizationCaseConfiguration' description: list of case configurations EmailCaseDetailsRequest: type: object required: - to_addresses properties: to_addresses: type: array items: type: string description: list of emails to send the case details to subject: type: string description: subject of the email html_content: type: string description: html content for the email body message: type: string description: message to be sent in email body along with html content include_hidden_findings: type: boolean description: if true, hidden findings will be included in the email view_id: type: string description: id of the saved case view whose section layout should drive the emailed case details (v2 only). Resolved against the requestor's organization. When omitted, falls back to the default saved view of the organization the case belongs to. Faq: type: object required: - question - answer - question_id properties: question: type: string answer: type: string question_id: type: string created_at: type: integer format: int64 GeoInfo: type: object required: - entity_ref properties: entity_ref: type: string description: Entity reference of the geo info lat: type: number description: Latitude of the geo info lon: type: number description: Longitude of the geo info country: type: string description: Country of the geo info country_code: type: string description: Country code of the geo info city: type: string description: City of the geo info asn: type: string description: ASN of the geo info org: type: string description: Org of the geo info is_vpn: type: boolean description: Is VPN of the geo info is_tor: type: boolean description: Is Tor of the geo info is_datacenter: type: boolean description: Is datacenter of the geo info AlertInvestigationStatus: type: integer enum: - 0 - 5 - 10 - 12 - 15 - 20 - 25 - 30 - 35 - 40 x-enum-varnames: - AlertInvestigationStatusCreated - AlertInvestigationStatusSubmitted - AlertInvestigationStatusInProgress - AlertInvestigationStatusSuspended - AlertInvestigationStatusCompleted - AlertInvestigationStatusFailed - AlertInvestigationStatusInvestigationLimitReached - AlertInvestigationStatusStopped - AlertInvestigationStatusSkipped - AlertInvestigationStatusDuplicate DeleteCaseFindingResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/UpsertCaseFinding' description: deleted case finding timestamp CaseNamedVersionNameRequest: type: object required: - name properties: name: type: string minLength: 1 maxLength: 120 UpdateCaseConfigurationResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/HiddenDashboardWidgets' CausalityGraphNode: type: object required: - id - label properties: id: type: string description: Short unique key referenced by edges label: type: string description: Display text shown in the node box kind: type: string description: 'Colour hint: alert/threat/malicious → red; finding/uncertain → amber; anything else → neutral' LayoutWidgetItem: type: object required: - kind - field_name - display_name properties: kind: type: string enum: - widget description: Discriminator identifying this item as a widget. field_name: type: string description: Field name of the widget. display_name: type: string minLength: 1 description: 'Per-view display name for this widget. Always present and non-empty — holds the custom alias when the user has renamed the widget in this view, otherwise the widget''s default section title. The case viewer shows this name in place of the default title. Display-only metadata; no backend logic depends on it. ' CaseComment: type: object required: - comment_id - case_uuid - content - created_by - created_at properties: comment_id: type: string case_uuid: type: string content: type: string content_style: type: string created_by: $ref: '#/components/schemas/UserInformation' created_at: type: integer format: int64 modified_at: type: integer format: int64 comment_source: $ref: '#/components/schemas/CommentSource' rating: type: integer comment_privacy: $ref: '#/components/schemas/CommentPrivacy' comment_type: $ref: '#/components/schemas/CommentType' CaseAction: type: object required: - title - status - status_label - assignee properties: uuid: type: string description: unique identifier of the action title: type: string description: Information on action required status: type: integer status_label: type: string assignee: $ref: '#/components/schemas/UserDetails' assignee_v2: $ref: '#/components/schemas/AssigneeDetails' description: AssigneeDetails for the action; populated alongside assignee during migration created_at: type: integer format: int64 description: Timestamp of creation of the action. modified_at: type: integer format: int64 description: Timestamp of the last modification of the action completed_at: type: integer format: int64 description: Timestamp of the completion of the action action_severity: $ref: '#/components/schemas/ActionSeverityLevel' description: Severity of the action session_id: type: string description: Session ID of the action where execution of the action took place required: type: boolean description: Whether this action is required description: type: string description: Description of the action required type: type: string enum: - approval - customer_action - answer_question description: Type of action; null is treated as customer_action blocking_reason: type: string description: Reason this action is blocking the case; only set when type is customer_action blocking_fact_id: type: string description: ID of the fact this action is blocking; only set when type is customer_action playbook_id: type: string description: ID of the playbook associated with this action; only set when type is approval priority: type: string enum: - Containment - Required - Recommended description: Priority of the action; when set on create/update, the required flag is derived from it (Containment/Required -> true, Recommended -> false) evidences: type: array items: type: string description: Free-form evidence text snippets associated with the action status_v2: $ref: '#/components/schemas/ActionStatusV2' description: Lifecycle status of the action, kept in sync with status. If both status and status_v2 are set on write, status_v2 takes priority and status is derived from it. For type approval/answer_question, only completed/will_not_do may be set directly; customer_action allows all values. execution_details: $ref: '#/components/schemas/ActionExecutionDetails' description: Details of the playbook execution triggered externally for this action; only set when type is approval. Polled until the execution reaches a terminal state, at which point status_v2/type are updated accordingly. AppendMode: type: integer enum: - 0 - 1 x-enum-varnames: - NewLine - Space CategoryFilter: type: object required: - category properties: category: type: string subcategory: type: string OrganizationCaseConfiguration: type: object description: case configuration set for the organization required: - organization_id properties: case_categories: type: array items: $ref: '#/components/schemas/CaseCategory' severity_options: type: array items: $ref: '#/components/schemas/EnumOption' disposition_options: type: array items: $ref: '#/components/schemas/EnumOption' status_options: type: array items: $ref: '#/components/schemas/EnumOption' finding_risk_options: type: array items: $ref: '#/components/schemas/EnumOption' action_status_options: type: array items: $ref: '#/components/schemas/EnumOption' disabled_features: type: array description: list of case features disabled for the organization items: $ref: '#/components/schemas/CaseFeature' case_priority_config: $ref: '#/components/schemas/CasePriorityConfig' description: describe how cases will be divided in Need attention, Closed and Active tabs for the organization case_closed_statuses: type: array items: type: integer description: list of statuses that will be shown in Closed tab organization_id: type: string description: Organization id of the organization reply_to_email: type: string description: Email address to set as reply-to header in the emails sent by the organization hidden_dashboard_widgets: $ref: '#/components/schemas/HiddenDashboardWidgets' description: Widget IDs to hide per dashboard. Absent or empty list means all widgets are visible. Admin-only field. Escalation: type: object required: - escalation_type - escalated_to - escalated_by - escalated_at - email_sent_to - uuid properties: escalation_type: $ref: '#/components/schemas/EscalationType' description: Possible Values are 0(Escalated), 1(Descalated) escalated_to: $ref: '#/components/schemas/EscalatedToType' description: Possible Values are 0(Escalated to customer), 1(Escalated to analyst) escalated_by: type: null $ref: '#/components/schemas/UserDetails' escalated_at: type: integer format: int64 comment: type: string email_sent_to: type: array items: type: string uuid: type: string GetCustomCaseFieldsResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CustomField' description: list of custom case fields total: type: integer description: total number of case fields found that match the given search query CaseHistoryResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/ChangeLog' description: history fetched successfully total: type: integer description: total number of changes found for the case UpsertEscalation: type: object properties: escalation_type: $ref: '#/components/schemas/EscalationType' description: Possible Values are 0(Escalated), 1(Descalated) escalated_to: $ref: '#/components/schemas/EscalatedToType' description: Possible Values are 0(Escalated to customer), 1(Escalated to analyst) comment: type: string email_sent_to: type: array items: type: string do_not_send_email: type: boolean description: To prevent escalation email from being sent, send this flag as true uuid: type: string UpdateDashboardChartConfigRequest: type: object additionalProperties: type: string description: Map of widget_id -> chart_type to add or update. Merged into the saved config; entries not listed are left untouched. CaseFinding: type: object required: - title - risk - risk_label - sequence properties: uuid: type: string description: Unique identifier of the finding title: type: string description: Finding title summary: type: string description: Detailed description of finding risk: type: integer risk_label: type: string hidden: type: boolean description: If true, the finding will not be shown in the UI evidences: type: array items: $ref: '#/components/schemas/Evidence' description: Evidence provided in support of the finding sequence: type: integer description: Sequence of the finding execution_id: type: string description: Execution ID of the finding ai_reasoning: type: string description: AI reasoning for adding the finding to the case CaseFeature: type: object required: - name properties: name: type: string CaseViewMode: type: string enum: - analyst - reader x-enum-varnames: - AnalystViewMode - CustomerViewMode EscalatedToType: type: integer enum: - 0 - 1 x-enum-varnames: - EscalatedToCustomer - EscalatedToAnalyst CustomField: type: object required: - title - type - scope - uuid - organization_id - organization_code - created_at - modified_at - created_by properties: title: type: string description: Title of the custom field type: $ref: '#/components/schemas/CustomFieldType' description: Type of the custom field. Possible values are 0(Text), 5(Boolean), 10(DateTime) scope: $ref: '#/components/schemas/CustomFieldScope' description: Scope of the custom field. Possible values are 0(Organizational), 5(Shared) uuid: type: string description: UUID of the custom field organization_id: type: string description: Organization ID of the custom field organization_code: type: string description: Organization code of the custom field created_at: type: integer format: int64 description: Timestamp of creation of the custom field modified_at: type: integer format: int64 description: Timestamp of last modification of the custom field created_by: $ref: '#/components/schemas/UserInformation' AddCaseFindingRequest: type: object required: - title properties: uuid: type: string description: Unique indenfitifer of the finding title: type: string description: Finding title summary: type: string description: Detailed description of finding risk: type: integer risk_label: type: string hidden: type: boolean description: If true, the finding will not be shown in the UI evidences: type: array items: $ref: '#/components/schemas/UpsertEvidenceRequest' description: Evidence provided in support of the finding decision_iocs: type: array items: $ref: '#/components/schemas/DecisionIoc' execution_id: type: string description: Execution ID of the finding ai_reasoning: type: string description: AI reasoning for adding the finding to the case ListCaseNamedVersionsResponse: type: object required: - message - data - total properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseNamedVersion' total: type: integer DashboardChartConfigData: type: object required: - dashboard_source - chart_config properties: dashboard_source: type: string chart_config: type: object additionalProperties: type: string description: Saved widget_id -> chart_type map for this dashboard. CaseFactSummary: type: object required: - id properties: id: type: string name: type: string content: type: string ActionExecutionDetails: type: object properties: execution_id: type: string description: ID of the execution triggered against knowledge-management for this action execution_status: type: string description: Last known execution status, as reported by knowledge-management's GetExecutionLogAPI started_by: type: string description: ID of the user who started the execution started_at: type: integer format: int64 description: Timestamp the execution was started; used to bound how long the execution is polled before it is force-resolved as failed Evidence: type: object required: - name - attached_content_type - attached_content_link - attached_content_version - data properties: name: type: string attached_content_link: type: string attached_content_version: type: integer attached_content_type: $ref: '#/components/schemas/EvidenceAttachmentType' description: Possible values are O (Undefined), 1(Json), 5(Pdf) data: type: string CommentType: type: integer enum: - 0 - 5 x-enum-varnames: - TextOnlyCommentType - RatingCommentType UpdateSavedViewRequest: type: object properties: name: type: string description: Updated name for the view filter: $ref: '#/components/schemas/CaseFilterV2' description: Updated filter configuration sort: type: array items: $ref: '#/components/schemas/CaseSort' description: Sort configuration for this view is_default: type: boolean description: Whether to set this as the default view view_mode: $ref: '#/components/schemas/CaseViewMode' description: Specify the view mode - anaylst view or reader view view_settings: $ref: '#/components/schemas/ViewSettings' description: Updated settings for the view. ChangeLog: type: object required: - change_log_id - resource_type - resource_id - action_summary - field_changes - request_id - performed_by - automation_action - performed_at properties: change_log_id: type: string resource_type: $ref: '#/components/schemas/ResourceType' description: enum specifying the resource type. Values - 1(Case) resource_id: type: string description: UUID for the resource whose change is captured action_summary: type: string description: simple message to summarize the change captured field_changes: type: array items: $ref: '#/components/schemas/FieldChange' request_id: type: string performed_by: $ref: '#/components/schemas/UserInformation' execution_summary: $ref: '#/components/schemas/ExecutionSummary' automation_action: type: boolean description: flag to indicate if action was performed by darryl on behalf of performed_by user performed_at: type: integer format: int64 Relationship: type: object required: - relationship_id - source - target - type - finding_refs - event_refs properties: relationship_id: type: string description: ID of the relationship source: type: string description: Source of the relationship target: type: string description: Target of the relationship type: $ref: '#/components/schemas/RelationshipType' description: Type of the relationship timestamp: type: integer description: Timestamp of the relationship confidence: type: integer description: Confidence of the relationship label: type: string description: Label of the relationship finding_refs: type: array items: type: string description: Finding references of the relationship event_refs: type: array items: type: string description: Event references of the relationship NumberRange: type: object properties: min: type: number max: type: number CaseType: type: integer enum: - 0 - 5 x-enum-varnames: - BasicCaseType - V2CaseType DashboardChartConfigResponse: type: object required: - message - data properties: message: type: string data: $ref: '#/components/schemas/DashboardChartConfigData' UpsertCaseWatchersRequest: type: object required: - user_uuids properties: user_uuids: type: array items: type: string description: User uuids ExplorationType: type: string enum: - user_investigations - attack_analysis - command/code_analysis - service/system_investigations - data_access_mapping - threat_intelligence - authentication_patterns - network_analysis - file_analysis - policy_review x-enum-varnames: - UserInvestigationsExplorationType - AttackAnalysisExplorationType - CommandCodeAnalysisExplorationType - ServiceSystemInvestigationsExplorationType - DataAccessMappingExplorationType - ThreatIntelligenceExplorationType - AuthenticationPatternsExplorationType - NetworkAnalysisExplorationType - FileAnalysisExplorationType - PolicyReviewExplorationType UserDetails: type: object properties: firstname: type: string lastname: type: string user_uuid: type: string performed_by_darryl: type: boolean CustomFieldScope: type: integer enum: - 0 - 5 x-enum-varnames: - OrganizationalScope - SharedScope Success: type: object required: - message properties: message: type: string description: user friendly message CasePriorityConfig: type: object required: - analyst_priority_config - customer_priority_config description: describe how cases will be divided in Need attention, Closed and Active tabs for the organization properties: analyst_priority_config: $ref: '#/components/schemas/PriorityConfig' description: describe how current organization cases will be divided customer_priority_config: $ref: '#/components/schemas/PriorityConfig' description: describe how child organization cases will be divided DecisionIoc: type: object required: - type - key - severity properties: type: type: string key: type: string severity: type: integer extra: type: object SocPerformanceWidget: type: string enum: - mtta - mtti - mttc - mtt_close - critical_incident_adherence - critical_alert_adherence - non_critical_adherence - sla_adherence_trend - response_time_percentiles - total_cases - daily_case_volume - analyst_performance - peak_load_by_hour - adr_triage_breakdown - escalations_by_severity - questions_per_category - rework_daily - questions_answered_by_outcome - quality_score_daily - stalled_cases_count - stalled_cases_by_category - customer_response_time - outlier_cases - cases_with_communication_count - communication_by_severity - adr_triage_trend - time_saved_full_auto_hours - time_saved_partial_auto_hours - total_hours_saved - days_saved - missing_telemetry_by_alert_type - blocked_by_customer_by_category FieldChange: type: object required: - previous_state - current_state - action_type - field_type properties: previous_state: type: object current_state: type: object action_type: $ref: '#/components/schemas/ChangelogActionType' description: enum specifying type of action. Values 0(No change), 1(Add), 2(Create), 5(Update), 10(Delete), 11(Remove), 12(Archive) field_type: $ref: '#/components/schemas/FieldType' description: enum specifying the field that is being changed in the request CasePriorityV2: type: integer enum: - 0 - 5 - 10 x-enum-varnames: - NeedAttentionCasePriorityV2 - ActiveCasePriorityV2 - ClosedCasePriorityV2 GetAlertResponse: type: object required: - alert_id - alert_uuid - alert_content - alert_provider - alert_ioc - organization_uuid - organization_code - created_at - created_by - created_at_source - fetched_playbook_id - fetched_playbook_name - investigation_status - alert_provider_details - alert_link properties: alert_id: type: string alert_uuid: type: string alert_content: type: string alert_provider: type: string alert_type: type: string alert_ioc: $ref: '#/components/schemas/AlertsIOC' organization_uuid: type: string organization_code: type: string created_by: type: string created_at: type: integer format: int64 modified_at: type: integer format: int64 created_at_source: type: integer format: int64 fetched_playbook_id: type: string fetched_playbook_name: type: string fetched_execution_id: type: string investigation_playbook_id: type: string investigation_playbook_name: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_retry_count: type: integer investigation_completed_time: type: integer format: int64 execution_id: type: string linked_case_id: type: string description: ID of the latest case linked to the alert original_alert_id: type: string description: When investigation_status is Duplicate, the alert_id this alert was found to be a duplicate of alert_provider_details: $ref: '#/components/schemas/ProviderDetails' resolved: type: boolean is_investigated_with_agent: type: boolean description: Flag indicating whether the alert was investigated by the agentic investigation service is_alert_reinvestigated: type: boolean description: Flag indicating whether the alert has been manually reinvestigated via the InvestigateAlert API alert_summary: type: string description: Human-readable summary of the alert linked_case_details: type: array items: $ref: '#/components/schemas/CaseExecutionDetails' description: Details of the all the cases that are linked to the alert linked_case_summary: $ref: '#/components/schemas/LinkedCaseSummary' description: Summary of the latest case linked to the alert connection_details: $ref: '#/components/schemas/ConnectionDetails' description: Details of the connection fetched the alert alert_type_details: $ref: '#/components/schemas/AlertTypeWithProperties' description: Details of the alert type alert_link: type: string description: URL for the alert CaseV2: type: object required: - case_id - case_uuid - name - type - status - status_label - severity - severity_label - disposition - disposition_label - priority - category - sub_category - assignee - archived - escalations_count - created_at - modified_at - status_modified_at - case_link - organization_uuid - organization_name properties: case_id: type: string description: Unique number respresenting case of an organization case_uuid: type: string description: Unique identifier of case name: type: string description: Title of the case type: $ref: '#/components/schemas/CaseType' description: Default value is 5 signifying v2 case type. v1 is deprecated. status: type: integer status_label: type: string severity: type: integer severity_label: type: string disposition: type: integer disposition_label: type: string priority: description: Possible values are 0 (Need Attention), 1 (Active), 5(Closed) $ref: '#/components/schemas/CasePriorityV2' category: type: string description: category the case belongs to sub_category: type: string description: sub category the case belongs to based on category assignee: $ref: '#/components/schemas/AssigneeDetails' archived: type: boolean description: Flag indicating if the case has been archived or not escalations_count: type: integer created_at: type: integer format: int64 description: Timestamp of creation of the case. modified_at: type: integer format: int64 description: Timestamp of the last modification of the case status_modified_at: type: integer format: int64 description: Timestamp of the last status modification of the case case_closed_at: type: integer format: int64 description: Timestamp of the closing of the case case_link: type: string description: link to the case manager organization_uuid: type: string description: OrganizationUuid of the organization the case belongs to organization_name: type: string description: Name of the organization the case belongs to reviewed: type: boolean description: if true, case has been reviewed marked_for_review: type: boolean description: if true, case is marked for review ignore_metrics: type: boolean description: if true, case is ignored from metrics timeline: $ref: '#/components/schemas/CaseTimeline' description: Timestamps and duration between different milestions in a case alert_type: type: string description: Alert type of the primary alert in the case case_score: $ref: '#/components/schemas/CaseScoreMinimal' description: Score of the case CaseListRequestV2: type: object required: - requested_view properties: requested_view: $ref: '#/components/schemas/CaseView' description: Indicates which view is requested sort_on_closest_match: type: boolean description: if true, first sort will be on closest match (opensearch default). Otherwise priority sort will be applied. filter: $ref: '#/components/schemas/CaseFilterV2' sort: type: array items: $ref: '#/components/schemas/CaseSort' description: list of sort fields in order check_case_identifier: type: string description: if provided, the response will include case_matches_filter indicating whether this case matches the current filter and search; accepts either case_uuid or case_id nl_query: type: string description: natural-language search query. When set (and filter.queries is empty), it is translated server-side into the advanced query language. Gated by a service flag; falls back to a plain text search if the translator is disabled. CommentPrivacy: type: integer enum: - 0 - 5 x-enum-varnames: - PublicCommentPrivacy - InternalToParentCommentPrivacy AssigneeDetails: type: object required: - assignee_id - assignee_type properties: firstname: type: string lastname: type: string email: type: string assignee_id: type: string user_uuid: type: string assignee_type: type: string performed_by_darryl: type: boolean AdrTriage: type: integer enum: - 0 - 1 - 5 - 10 x-enum-varnames: - NotAvaialbleAdrTriage - NoneAdrTriage - PartialAdrTriage - FullAdrTriage AddCaseDetailFieldsRequest: type: object properties: executive_summary: type: string alert_details: type: string provider_id: type: string linked_alerts: type: array items: $ref: '#/components/schemas/UpsertLinkedAlertSource' primary_alert_id: type: string description: primary alert id in a case timeline: $ref: '#/components/schemas/CaseTimeline' description: Timestamps and duration between different milestions in a case activity_timeline: type: array items: $ref: '#/components/schemas/CaseActivity' description: Timeline of activities in the case custom_field_values: type: array items: $ref: '#/components/schemas/UpsertCustomFieldValue' description: Custom fields to be added in the case investigation_summary: type: string description: Investigation summary to be added in the case conclusion: type: string description: Conclusion of the case conclusion_overview: $ref: '#/components/schemas/ConclusionOverview' faqs: type: array items: $ref: '#/components/schemas/UpsertFaqRequest' description: FAQs to be added in the case custom_questions: type: array items: $ref: '#/components/schemas/UpsertCustomQuestionRequest' description: Custom questions to be added in the case explore_deeper_questions: type: array items: $ref: '#/components/schemas/UpsertExploreDeeperQuestionRequest' description: Explore deeper questions to be added in the case alert_metadata: type: object additionalProperties: type: string description: Arbitrary string key-value metadata associated with the alert causality_graph: $ref: '#/components/schemas/CausalityGraph' description: Directed causality chain graph tracing the incident from root cause to outcome fact_ids: type: array items: type: string description: IDs of knowledge-service facts to associate with the case EmailCaseDetailsResponse: type: object required: - message - failed_deliveries properties: message: type: string failed_deliveries: type: array items: type: string description: list of emails the case details could not be sent to CaseWatchersResponse: type: object required: - message - data properties: message: type: string data: type: array items: $ref: '#/components/schemas/CaseWatchers' description: case watchers list EmailCaseFindingDetailsRequest: type: object required: - to_addresses properties: to_addresses: type: array items: type: string description: list of emails to send the case finding details to html_content: type: string description: html content for the email body message: type: string description: message to be sent in email body along with html content EvidenceAttachmentType: type: integer enum: - 0 - 1 - 5 x-enum-varnames: - UndefinedAttachmentType - JsonAttachmentType - PdfAttachmentType parameters: user-id: name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string x-request-id: name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string organization-id: name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string securitySchemes: SessionCookie: type: apiKey in: cookie name: Session x-tagGroups: - name: Included APIs tags: - Case Manager V2 - Dashboard - Alerts - Webhooks - Query DSL