openapi: 3.2.0 info: title: Axonflow Policy Simulation API version: 11.1.0 contact: name: AxonFlow Support url: https://getaxonflow.com/support license: name: Business Source License 1.1 url: https://github.com/getaxonflow/axonflow/blob/main/LICENSE description: 'Operations tagged Policy Simulation across 2 of this provider''s published API definitions: axonflow-orchestrator-api.yaml, axonflow-orchestrator-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://orchestrator.getaxonflow.com description: Production (SaaS) - url: http://localhost:8081 description: Local Development tags: - name: Policy Simulation paths: /api/v1/policies/simulate: post: deprecated: true tags: - Policy Simulation summary: Simulate all active policies (Evaluation+) description: 'Runs all active policies against the provided input as a dry run. No audit writes or action application. Requires Evaluation or Enterprise license.' operationId: simulatePolicies security: - BearerAuth: [] - basicAuth: [] requestBody: required: true content: application/json: schema: type: object required: - query properties: query: type: string description: The input text to simulate against all policies request_type: type: string description: Request type (defaults to "simulation") user: $ref: '#/components/schemas/UserContext' client: $ref: '#/components/schemas/ClientContext' context: type: object additionalProperties: true responses: '200': description: Simulation results content: application/json: schema: type: object properties: allowed: type: boolean applied_policies: type: array items: type: string risk_score: type: number required_actions: type: array items: type: string processing_time_ms: type: integer total_policies: type: integer description: 'Number of active policies visible to the calling tenant — its own plus the shared global/default baseline. CHANGED: this previously counted every active policy in the deployment, across all tenants, which disclosed the deployment-wide policy count to every caller. ' dry_run: type: boolean enum: - true simulated_at: type: string format: date-time tier: type: string daily_usage: type: object properties: used: type: integer limit: type: integer '403': description: Feature requires Evaluation or Enterprise license '429': description: Daily simulation limit exceeded servers: - url: https://orchestrator.getaxonflow.com description: Production (SaaS) - url: http://localhost:8081 description: Local Development /api/v1/policies/impact-report: post: deprecated: true tags: - Policy Simulation summary: Generate impact report for a policy (Evaluation+) description: 'Tests a single policy against multiple inputs and returns aggregate statistics. Requires Evaluation or Enterprise license.' operationId: generateImpactReport security: - BearerAuth: [] - basicAuth: [] requestBody: required: true content: application/json: schema: type: object required: - policy_id - inputs properties: policy_id: type: string inputs: type: array items: type: object required: - query properties: query: type: string request_type: type: string user: type: object additionalProperties: true context: type: object additionalProperties: true responses: '200': description: Impact report results content: application/json: schema: type: object properties: policy_id: type: string total_inputs: type: integer matched: type: integer blocked: type: integer match_rate: type: number block_rate: type: number results: type: array items: type: object properties: input_index: type: integer matched: type: boolean blocked: type: boolean actions: type: array items: type: string processing_time_ms: type: integer generated_at: type: string format: date-time tier: type: string '400': description: Bad request (missing fields or input limit exceeded) '403': description: Feature requires Evaluation or Enterprise license servers: - url: https://orchestrator.getaxonflow.com description: Production (SaaS) - url: http://localhost:8081 description: Local Development /api/v1/policies/conflicts: post: deprecated: true tags: - Policy Simulation summary: Detect policy conflicts (Evaluation+) description: 'Analyzes active policies for contradictions, shadows, and redundancies. Optionally filter to conflicts involving a specific policy. Requires Evaluation or Enterprise license.' operationId: detectPolicyConflicts security: - BearerAuth: [] - basicAuth: [] requestBody: required: false content: application/json: schema: type: object properties: policy_id: type: string description: Optional — filter to conflicts involving this policy responses: '200': description: Conflict analysis results content: application/json: schema: type: object properties: conflicts: type: array items: type: object properties: policy_a: type: object properties: id: type: string name: type: string type: type: string policy_b: type: object properties: id: type: string name: type: string type: type: string conflict_type: type: string enum: - contradictory_action - shadow - redundant description: type: string severity: type: string enum: - high - medium - low overlapping_field: type: string total_policies: type: integer conflict_count: type: integer checked_at: type: string format: date-time tier: type: string '403': description: Feature requires Evaluation or Enterprise license '429': description: Daily simulation limit exceeded servers: - url: https://orchestrator.getaxonflow.com description: Production (SaaS) - url: http://localhost:8081 description: Local Development components: schemas: UserContext: type: object properties: id: type: integer email: type: string role: type: string region: type: string description: User's region, read by geo-based routing policies. permissions: type: array items: type: string tenant_id: type: string org_id: type: string description: Organisation for multi-tenant isolation, populated from the X-Org-ID header the agent stamps on the trusted hop. ClientContext: type: object properties: id: type: string name: type: string org_id: type: string tenant_id: type: string securitySchemes: basicAuth: type: http scheme: basic description: OAuth2-style client credentials (clientId:clientSecret) BearerAuth: type: http scheme: bearer bearerFormat: JWT description: Enterprise JWT token (see /scripts/generate-jwt.sh) x-refined-from: - axonflow-orchestrator-api.yaml - axonflow-orchestrator-openapi.yml