openapi: 3.2.0 info: title: User Management Service Organization API version: 1.0.0 description: Endpoints to manage organizations servers: - url: /airmdrapi tags: - name: Organization description: Endpoints to manage organizations paths: /organization: post: tags: - Organization operationId: createOrganizationAPI summary: create an organization description: Creates an organization. This operation can only be performed by a superadmin. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateOrganizationRequest' responses: '201': description: organization created successfully content: application/json: schema: $ref: '#/components/schemas/UpdateOrganizationResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' '409': description: conflict content: application/json: schema: $ref: '#/components/schemas/Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' get: tags: - Organization operationId: getOrganizationListAPI summary: get list of organizations description: Get list of organizations accessible to the logged in user. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string security: - SessionCookie: [] responses: '200': description: List of organizations retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetOrganizationListResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/filter: post: tags: - Organization operationId: filterOrganizationAPI summary: filter organizations description: Get list of organizations with respect to given filters and accessible to logged in user. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/FilterOrganizationRequest' responses: '200': description: organizations fetched successfully content: application/json: schema: $ref: '#/components/schemas/FilterOrganizationListResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/{organization_identifier}: get: tags: - Organization operationId: getOrganizationAPI summary: get details of an organization description: Get details of an organization. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: organization_identifier in: path description: The identifier (id or code) of the organization to be fetched required: true schema: type: string security: - SessionCookie: [] responses: '200': description: organization fetched successfully content: application/json: schema: $ref: '#/components/schemas/GetOrganizationResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Organization operationId: updateOrganizationAPI summary: update an organization description: Updates an organization. This operation can only be performed by a superadmin. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: organization_identifier in: path description: The unique identifier (id or code) of the organization required: true schema: type: string security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateOrganizationRequest' responses: '200': description: organization updated successfully content: application/json: schema: $ref: '#/components/schemas/UpdateOrganizationResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Organization operationId: deleteOrganizationAPI summary: delete an organization description: Deletes an organization. This operation can only be performed by a superadmin, and a user cannot delete their own organization. Deleting an organization also deletes all descendant organizations, along with their users and user groups. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: organization_identifier in: path description: The unique identifier (id or code) of the organization required: true schema: type: string security: - SessionCookie: [] responses: '200': description: organization deleted successfully content: application/json: schema: $ref: '#/components/schemas/DeleteOrganizationResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/logo/upload: post: tags: - Organization operationId: uploadOrganizationLogoAPI summary: upload logo of an organization description: Upload logo of an organization. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string security: - SessionCookie: [] requestBody: required: true content: multipart/form-data: schema: type: object properties: logo: type: string format: binary description: Image of the logo of the organization usage_type: $ref: '#/components/schemas/LogoUsageType' description: Logo should be used in Login screen or darryl responses: '200': description: organization created successfully content: application/json: schema: $ref: '#/components/schemas/UploadOrganizationLogoResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/{organization_identifier}/investigation-configuration: get: tags: - Organization operationId: getOrganizationInvestigationConfigurationAPI summary: get investigation configuration for an organization description: Returns the investigation configuration for the given organization. parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_identifier in: path required: true schema: type: string description: The unique identifier (id or code) of the organization - name: include_disabled in: query required: false schema: type: boolean default: false description: if true, provider_configs includes all providers and alert types with their enabled state; if false (default), only enabled entries are returned security: - SessionCookie: [] responses: '200': description: investigation configuration retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetOrganizationInvestigationConfigurationResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/{organization_identifier}/credit-context: get: tags: - Organization operationId: getOrganizationCreditContextAPI summary: get resolved investigation-credit context for an organization description: Resolves where the organization's investigation-credit charges are billed. For an org with credit_source "own" (default) it bills itself; for "parent" it walks up the org hierarchy to the nearest ancestor that owns a credit pool and bills that org, surfacing the pool's weekly allocation and this org's optional sub-cap. Used by case-manager to enforce pooled (MSSP) budgets. parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_identifier in: path required: true schema: type: string description: The unique identifier (id or code) of the organization security: - SessionCookie: [] responses: '200': description: credit context resolved successfully content: application/json: schema: $ref: '#/components/schemas/GetOrganizationCreditContextResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/{organization_identifier}/features: get: tags: - Organization operationId: getOrganizationFeaturesAPI summary: get features for an organization description: Returns the list of features for the given organization, including whether each feature is enabled/disabled and whether the config is applied at this org level or inherited from a parent organization. parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_identifier in: path required: true schema: type: string description: The unique identifier (id or code) of the organization security: - SessionCookie: [] responses: '200': description: features retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetOrganizationFeaturesResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Organization operationId: updateOrganizationFeaturesAPI summary: update features for an organization description: Updates the enabled/disabled flag for the specified features at the org level. Only features included in the request are modified. Changes are always applied at the specified org level (never to parent). parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_identifier in: path required: true schema: type: string description: The unique identifier (id or code) of the organization security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateOrganizationFeaturesRequest' responses: '200': description: features updated successfully content: application/json: schema: $ref: '#/components/schemas/UpdateOrganizationFeaturesResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/403Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/{organization_identifier}/metabase/restore: post: tags: - Organization operationId: restoreMetabaseResourcesAPI summary: deletes and recreates metabase resources description: Deletes and recreates metabase resources. parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_identifier in: path description: The unique identifier (id or code) of the organization required: true schema: type: string security: - SessionCookie: [] responses: '200': description: metabase resources restored successfully content: application/json: schema: $ref: '#/components/schemas/Success' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /organization/metabase/session: get: tags: - Organization operationId: getMetabaseSessionAPI summary: gets metabase session description: Gets metabase session. parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' security: - SessionCookie: [] responses: '200': description: metabase session retrieved successfully content: application/json: schema: $ref: '#/components/schemas/GetMetabaseSessionResponse' '403': description: forbidden content: application/json: schema: $ref: '#/components/schemas/Error' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: ProviderInvestigationConfig: type: object required: - provider - investigation_type properties: provider: type: string description: provider name investigation_type: $ref: '#/components/schemas/ProviderInvestigationType' description: investigation type for this provider; default inherits from the org default: default alert_type_configs: type: - array - 'null' items: $ref: '#/components/schemas/AlertTypeInvestigationConfig' description: per-alert-type overrides; alert types not listed use the provider investigation_type UpdateOrganizationRequest: type: object properties: name: type: string description: name of the organization contact_email: type: - string - 'null' description: contact email of the organization updates_email: type: - string - 'null' description: email for sending updates to organization's customer updates_email_for_escalations_from_parent: type: - array - 'null' items: type: string description: list of email addresses to notify when case is escalated from parent organization updates_email_for_escalations_from_children: type: - array - 'null' items: type: string description: list of email addresses to notify when case is escalated from child organizations logo_url: type: - string - 'null' description: url of the organization's logo enable_metabase: type: - boolean - 'null' description: whether metabase is enabled for the organization sso_configuration: $ref: '#/components/schemas/OrganizationSSOConfiguration' description: sso configuration of the organization darryl_configuration: $ref: '#/components/schemas/OrganizationDarrylConfigurationRequest' description: darryl configuration of the organization rbac_template_id: type: string description: id of the rbac template to be used for the organization metadata: type: - object - 'null' description: additional metadata of the organization additionalProperties: type: string investigation_configuration: $ref: '#/components/schemas/UpdateOrganizationInvestigationConfigurationRequest' description: investigation configuration of the organization Organization: type: object required: - organization_id - name - code - contact_email - can_have_child_organizations - created_at - created_by - modified_at properties: organization_id: type: string description: unique id of the organization name: type: string description: name of the organization code: type: string description: code of the organization contact_email: type: string description: contact email of the organization updates_email: type: string description: email for sending updates to organization's customer parent_organization_id: type: string description: id of the parent organization parent_organization: $ref: '#/components/schemas/OrganizationMinimal' description: parent organization updates_email_for_escalations_from_parent: type: array items: type: string description: list of email addresses to notify when case is escalated from parent organization can_have_child_organizations: type: boolean description: flag indicating whether the new organization can further have child organizations parent_has_access_to_descendants: type: boolean description: whether parent organization has access to descendant organizations of the created organization parent_has_access: type: boolean description: whether parent organization has access to organization's entities. Default is True. If False, parent will also not have access to descendants updates_email_for_escalations_from_children: type: array items: type: string description: list of email addresses to notify when case is escalated from child organizations host_url: type: string description: host url of the organization logo_url: type: string description: url of the organization's logo metadata: type: object description: additional metadata of the organization additionalProperties: type: string features: type: array items: $ref: '#/components/schemas/AirMDRFeature' permissions: type: array items: $ref: '#/components/schemas/Permission' created_at: type: integer format: int64 description: creation time of organization created_by: type: string description: unique id of the user who created the organization modified_at: type: integer format: int64 description: modified time of organization CreditSource: type: string enum: - own - parent description: 'Where an organization''s investigation credits are drawn from. own: use this org''s own weekly_credit_allocation (default, independent budget). parent: draw from the nearest ancestor org that owns a credit pool; this org''s weekly_credit_allocation is then treated as an optional per-child sub-cap within that shared pool. ' ChildVisibility: type: object description: What child orgs are allowed to see required: - org_data properties: org_data: $ref: '#/components/schemas/VisibilitySetting' description: Other organization data visibility for child organizations CaseFeature: type: object required: - name properties: name: type: string OrganizationRBACConfiguration: type: - object - 'null' required: - template_id - parent_visibility - child_visibility - org_visibility properties: template_id: type: string description: Unique identifier for the RBAC template parent_visibility: $ref: '#/components/schemas/ParentVisibility' child_visibility: $ref: '#/components/schemas/ChildVisibility' org_visibility: $ref: '#/components/schemas/OrgVisibility' LogoDetails: type: object required: - logo_url properties: logo_url: type: string ParentVisibility: type: object description: What parents are allowed to see required: - user_mgmt - org_data properties: user_mgmt: $ref: '#/components/schemas/VisibilitySetting' description: User management visibility for parent organizations org_data: $ref: '#/components/schemas/VisibilitySetting' description: Other organization data visibility for parent organizations UploadOrganizationLogoResponse: type: object required: - data - message properties: message: type: string data: $ref: '#/components/schemas/LogoDetails' FilterOrganizationRequest: type: object properties: user_permissions: type: array description: Returns the organizations on which user has access for the given permissions items: type: string include_organization_configuration: type: boolean description: If true, configuration for organizations will be included in the response. Default value is false. root_organization_id: type: string description: Organization ID for which descendants are to be fetched. can_have_child_organizations: type: boolean description: flag indicating whether the organization can further have child organizations include_organizations_with_no_access: type: boolean description: flag indicating whether to include organizations with parent_has_access flag as false. The default value is false for backward compatibility. include_organizations_with_inaccessible_descendants: type: boolean description: flag indicating whether to include organizations with parent_has_access_to_descendants flag as false. The default value is true. feature: type: string description: Feature for which accessible organizations will be fetched. GetOrganizationInvestigationConfigurationResponse: type: object required: - data - message properties: data: $ref: '#/components/schemas/OrganizationInvestigationConfiguration' message: type: string CaseCategory: type: object required: - category_name properties: category_name: type: string sub_categories: type: array items: $ref: '#/components/schemas/CaseSubCategory' GetOrganizationFeaturesResponse: type: object required: - data - message properties: data: type: array items: $ref: '#/components/schemas/OrganizationFeature' message: type: string MetabaseDashboard: type: object required: - id - name properties: id: type: string name: type: string UpdateOrganizationResponse: type: object required: - data - message properties: message: type: string data: $ref: '#/components/schemas/OrganizationWithConfiguration' GetOrganizationListResponse: type: object required: - data - message properties: message: type: string data: type: array items: $ref: '#/components/schemas/Organization' ProviderInvestigationType: type: string enum: - agentic - agentic_preview - playbook - default description: 'Investigation type for a provider or alert type. default: inherit from the parent level (provider inherits org; alert type inherits provider). ' UpdateOrganizationFeaturesRequest: type: object required: - features properties: features: type: array items: $ref: '#/components/schemas/UpdateOrganizationFeatureItem' description: List of features to update. Only mentioned features are changed. UpdateOrganizationFeatureItem: type: object required: - feature_id - enabled properties: feature_id: type: string enabled: type: boolean OrganizationFeature: type: object required: - feature_id - name - enabled - config_level properties: feature_id: type: string description: The id of the feature name: type: string description: The name of the feature description: type: string description: The description of the feature enabled: type: boolean description: Whether the feature is enabled or disabled config_level: type: string enum: - org - inherited description: 'Whether the feature config is set at this org level ("org") or inherited from a parent organization ("inherited") ' inherited_from_organization_id: type: string description: 'If config_level is "inherited", the organization_id of the ancestor that defines this feature''s config ' DeleteOrganizationResponse: type: object required: - message properties: message: type: string UpdateOrganizationInvestigationConfigurationRequest: type: - object - 'null' description: investigation configuration update request properties: use_shared_playbooks: type: - boolean - 'null' description: whether shared playbooks are used for investigation weekly_investigation_limit: type: - integer - 'null' description: maximum number of investigations allowed per week enforce_weekly_investigation_limit: type: - boolean - 'null' description: 'whether the weekly investigation limit is enforced as a hard cutoff. Decouples setting the budget number (weekly_investigation_limit) from the blind count-cutoff: when false, the limit is informational (used for reporting/projection) and investigations are not blocked when it is exceeded. Defaults to false for new orgs.' weekly_credit_allocation: type: - integer - 'null' description: default weekly investigation-credit allocation for the organization credit_source: $ref: '#/components/schemas/CreditSource' description: where the organization's investigation credits are drawn from. "own" (default) uses this org's own weekly_credit_allocation. "parent" draws from the nearest ancestor org that owns a credit pool, in which case weekly_credit_allocation is treated as this org's optional sub-cap within that shared pool. investigation_type: $ref: '#/components/schemas/OrgInvestigationType' description: default investigation type for the organization default: playbook provider_configs: type: - array - 'null' items: $ref: '#/components/schemas/ProviderInvestigationConfig' description: per-provider investigation type overrides blocked_llm_providers: type: - array - 'null' items: type: string description: list of LLM providers blocked from being used in agentic investigation ConfigSource: type: string enum: - parent - new x-enum-varnames: - ConfigSourceParent - ConfigSourceNew AlertTypeInvestigationConfig: type: object required: - alert_type - investigation_type properties: alert_type: type: string description: alert type identifier investigation_type: $ref: '#/components/schemas/ProviderInvestigationType' description: investigation type for this alert type; default inherits from the provider default: default Permission: type: object required: - permission_id - name properties: permission_id: type: string name: type: string description: type: string CreateOrganizationRequest: type: object required: - name - contact_email - parent_organization_id - can_have_child_organizations - rbac_template_id properties: name: type: string description: name of the organization code: type: string description: code of the organization contact_email: type: string description: contact email of the organization updates_email: type: string description: email for sending updates to organization's customer parent_organization_id: type: string description: id of the parent organization organization_id: type: string description: id of the organization (used if we want to create an organization with a specific id) updates_email_for_escalations_from_parent: type: array items: type: string description: list of email addresses to notify when case is escalated from parent organization can_have_child_organizations: type: boolean description: flag indicating whether the new organization can further have child organizations parent_has_access_to_descendants: type: boolean description: whether parent organization has access to descendant organizations of the created organization parent_has_access: type: boolean description: whether parent organization has access to organization's entities. Default is True. If False, parent will also not have access to descendants updates_email_for_escalations_from_children: type: array items: type: string description: list of email addresses to notify when case is escalated from child organizations logo_url: type: string description: url of the organization's logo sso_configuration: $ref: '#/components/schemas/OrganizationSSOConfiguration' darryl_configuration: $ref: '#/components/schemas/OrganizationDarrylConfigurationRequest' description: darryl configuration of the organization rbac_template_id: type: string description: id of the rbac template to be used for the organization metadata: type: object description: additional metadata of the organization additionalProperties: type: string investigation_configuration: $ref: '#/components/schemas/UpdateOrganizationInvestigationConfigurationRequest' description: investigation configuration of the organization Error: type: object required: - message properties: message: type: string description: user friendly error message EnumOption: type: object required: - key - label properties: key: type: number label: type: string style_config: $ref: '#/components/schemas/StyleConfig' GetOrganizationCreditContextResponse: type: object required: - data - message properties: data: $ref: '#/components/schemas/CreditContext' message: type: string CreditContext: type: object description: 'Resolved investigation-credit context for an organization: which org''s balance its charges debit (itself for own; the nearest ancestor pool owner for parent), the pool''s weekly allocation, and this org''s optional sub-cap within the pool. ' required: - organization_id - credit_source - billing_organization_id - billing_organization_code - enforced properties: organization_id: type: string description: the organization this context was resolved for credit_source: $ref: '#/components/schemas/CreditSource' description: the org's effective credit source (own if unset) billing_organization_id: type: string description: id of the org whose credit balance charges debit (self for own; the pool owner for parent) billing_organization_code: type: string description: code of the billing org (used as the credit-balance key in case-manager) pool_weekly_allocation: type: - integer - 'null' description: weekly credit allocation of the billing org (the shared pool size); null/unset means unlimited child_sub_cap: type: - integer - 'null' description: 'this org''s optional weekly sub-cap within the shared pool (only set when credit_source is parent and the child has its own weekly_credit_allocation) ' enforced: type: boolean description: 'false when no ancestor pool was found and no own allocation is set, i.e. charges are unlimited (still recorded for reporting) ' OrgInvestigationType: type: string enum: - agentic - agentic_preview - playbook description: 'Investigation type for the organization. agentic: agentic investigation only, creates case. agentic_preview: both agentic and playbook run; playbook creates case. playbook: playbook investigation only. ' CaseSubCategory: type: object required: - sub_category_name properties: sub_category_name: type: string Success: type: object required: - message properties: message: type: string description: user friendly message StyleConfig: type: object properties: bg_color: type: string font_color: type: string font_size: type: string border: type: string border_radius: type: string size: type: string start_adornments: $ref: '#/components/schemas/Adornments' end_adornments: $ref: '#/components/schemas/Adornments' text_class: type: string show_clock_icon: type: boolean wrapper_class: type: string show_modified_at_time: type: boolean tooltip_title: type: string icon_src: type: string icon_color: type: string CasePriorityConfig: type: object required: - analyst_priority_config - customer_priority_config description: describe how cases will be divided in Need attention, Closed and Active tabs for the organization properties: analyst_priority_config: $ref: '#/components/schemas/PriorityConfig' description: describe how current organization cases will be divided customer_priority_config: $ref: '#/components/schemas/PriorityConfig' description: describe how child organization cases will be divided GetOrganizationResponse: type: object required: - data - message properties: message: type: string data: $ref: '#/components/schemas/OrganizationWithConfiguration' Adornments: type: object required: - type - src - size properties: type: type: string src: type: string size: type: string UpdateOrganizationFeaturesResponse: type: object required: - data - message properties: data: type: array items: $ref: '#/components/schemas/OrganizationFeature' message: type: string GetMetabaseSessionResponse: type: object required: - jwt properties: jwt: type: string OrganizationInvestigationConfiguration: type: - object - 'null' description: investigation configuration for the organization required: - use_shared_playbooks properties: use_shared_playbooks: type: boolean weekly_investigation_limit: type: - integer - 'null' description: maximum number of investigations allowed per week enforce_weekly_investigation_limit: type: - boolean - 'null' description: 'whether the weekly investigation limit is enforced as a hard cutoff. Decouples setting the budget number (weekly_investigation_limit) from the blind count-cutoff: when false, the limit is informational (used for reporting/projection) and investigations are not blocked when it is exceeded. Defaults to false for new orgs.' weekly_credit_allocation: type: - integer - 'null' description: default weekly investigation-credit allocation for the organization credit_source: $ref: '#/components/schemas/CreditSource' description: where the organization's investigation credits are drawn from. "own" (default) uses this org's own weekly_credit_allocation. "parent" draws from the nearest ancestor org that owns a credit pool, in which case weekly_credit_allocation is treated as this org's optional sub-cap within that shared pool. investigation_type: $ref: '#/components/schemas/OrgInvestigationType' description: default investigation type for the organization default: playbook provider_configs: type: - array - 'null' items: $ref: '#/components/schemas/ProviderInvestigationConfig' description: per-provider investigation type overrides blocked_llm_providers: type: - array - 'null' items: type: string description: list of LLM providers blocked from being used in agentic investigation SSOConfigSource: type: string enum: - parent - new x-enum-varnames: - SSOConfigSourceParent - SSOConfigSourceNew OrganizationWithConfiguration: type: object allOf: - $ref: '#/components/schemas/Organization' - properties: configuration: $ref: '#/components/schemas/OrganizationConfiguration' OrganizationMetabaseConfiguration: type: - object - 'null' required: - enabled - dashboards properties: enabled: type: boolean description: whether metabase is enabled for the organization dashboards: type: array items: $ref: '#/components/schemas/MetabaseDashboard' description: list of dashboards enabled OrganizationSSOConfiguration: type: - object - 'null' description: sso configuration set for the organization required: - sso_config_source properties: sso_config_source: $ref: '#/components/schemas/SSOConfigSource' identity_provider_name: type: string description: the name of the identity provider entity_id: type: string description: the entity id or the issuer id certificate: type: string description: public certificate of the identity provider sso_url: type: string description: the sso url of the identity provider logout_url: type: string description: the logout url of the identity provider FilterOrganizationListResponse: type: object required: - data - message properties: message: type: string data: type: array items: $ref: '#/components/schemas/OrganizationWithConfiguration' LogoUsageType: type: string enum: - login - darryl x-enum-varnames: - LogoUsageTypeLogin - LogoUsageTypeDarryl AirMDRFeature: type: object required: - feature_id - name properties: feature_id: type: string description: The id of the feature name: type: string description: The name of the feature description: type: string description: The description of the feature VisibilitySetting: type: string enum: - full_access - no_access - org_context_access - usage_access x-enum-varnames: - VisibilityFullAccess - VisibilityNoAccess - VisibilityOrgContextAccess - VisibilityUsageAccess OrganizationDarrylConfiguration: type: - object - 'null' required: - darryl_config_source properties: logo_url: type: string description: alternate logo url for darryl darryl_config_source: $ref: '#/components/schemas/ConfigSource' name: type: string description: alternate name for darryl color: type: string OrganizationDarrylConfigurationRequest: type: - object - 'null' required: - darryl_config_source properties: darryl_config_source: $ref: '#/components/schemas/ConfigSource' name: type: string description: alternate name for darryl color: type: string OrgVisibility: type: object description: Organization-level visibility settings required: - org_data properties: org_data: $ref: '#/components/schemas/VisibilitySetting' description: Other organization data visibility 403Error: type: object properties: message: type: string const: User does not have permission to perform this action OrganizationConfiguration: type: object properties: case_configuration: $ref: '#/components/schemas/OrganizationCaseConfiguration' sso_configuration: $ref: '#/components/schemas/OrganizationSSOConfiguration' darryl_configuration: $ref: '#/components/schemas/OrganizationDarrylConfiguration' metabase_configuration: $ref: '#/components/schemas/OrganizationMetabaseConfiguration' rbac_configuration: $ref: '#/components/schemas/OrganizationRBACConfiguration' investigation_configuration: $ref: '#/components/schemas/OrganizationInvestigationConfiguration' OrganizationCaseConfiguration: type: object description: case configuration set for the organization properties: case_categories: type: array items: $ref: '#/components/schemas/CaseCategory' severity_options: type: array items: $ref: '#/components/schemas/EnumOption' disposition_options: type: array items: $ref: '#/components/schemas/EnumOption' status_options: type: array items: $ref: '#/components/schemas/EnumOption' finding_risk_options: type: array items: $ref: '#/components/schemas/EnumOption' action_status_options: type: array items: $ref: '#/components/schemas/EnumOption' disabled_features: type: array description: list of case features disabled for the organization items: $ref: '#/components/schemas/CaseFeature' case_priority_config: $ref: '#/components/schemas/CasePriorityConfig' description: describe how cases will be divided in Need attention, Closed and Active tabs for the organization case_closed_statuses: type: array items: type: integer description: list of statuses that will be shown in Closed tab reply_to_email: type: string description: Email address to set as reply-to header in the emails sent by the organization PriorityConfig: type: object required: - need_attention_statuses - active_statuses - closed_statuses properties: need_attention_statuses: description: list of statuses that will be shown in Need attention tab type: array items: type: integer active_statuses: description: list of statuses that will be shown in Active tab type: array items: type: integer closed_statuses: description: list of statuses that will be shown in Closed tab type: array items: type: integer OrganizationMinimal: type: object required: - organization_id - name - code - sso_enabled properties: organization_id: type: string description: unique id of the organization name: type: string description: name of the organization code: type: string description: code of the organization logo_url: type: string description: url of the organization's logo sso_enabled: type: boolean description: flag indicating whether sso is enabled for the organization parameters: organization-id: name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string x-request-id: name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string user-id: name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string securitySchemes: SessionCookie: type: apiKey in: cookie name: Session x-tagGroups: - name: Included APIs tags: - Organization - User - User Group - Token - Permission