generated: '2026-07-15' method: generated source: openapi/health-data-ai-deid-2024-11-15.json, openapi/healthcare-apis-2024-03-31.json description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 53 by_action_class: acting: 26 connected: 27 by_consequence: write: 26 read: 27 human_in_the_loop_required: 0 operations: - path: /deid method: post operationId: DeidentifyText x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - https://deid.azure.com/.default - path: /jobs method: get operationId: ListJobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - https://deid.azure.com/.default - path: /jobs/{name} method: get operationId: GetJob x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - https://deid.azure.com/.default - path: /jobs/{name} method: put operationId: DeidentifyDocuments x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - https://deid.azure.com/.default - path: /jobs/{name} method: delete operationId: DeleteJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - https://deid.azure.com/.default - path: /jobs/{name}:cancel method: post operationId: CancelJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - https://deid.azure.com/.default - path: /jobs/{name}/documents method: get operationId: ListJobDocuments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - https://deid.azure.com/.default - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName} method: get operationId: Services_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName} method: put operationId: Services_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName} method: patch operationId: Services_Update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName} method: delete operationId: Services_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/providers/Microsoft.HealthcareApis/services method: get operationId: Services_List x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services method: get operationId: Services_ListByResourceGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/providers/Microsoft.HealthcareApis/checkNameAvailability method: post operationId: Services_CheckNameAvailability x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateEndpointConnections method: get operationId: PrivateEndpointConnections_ListByService x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateEndpointConnections/{privateEndpointConnectionName} method: get operationId: PrivateEndpointConnections_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateEndpointConnections/{privateEndpointConnectionName} method: put operationId: PrivateEndpointConnections_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateEndpointConnections/{privateEndpointConnectionName} method: delete operationId: PrivateEndpointConnections_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateLinkResources method: get operationId: PrivateLinkResources_ListByService x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/services/{resourceName}/privateLinkResources/{groupName} method: get operationId: PrivateLinkResources_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/providers/Microsoft.HealthcareApis/workspaces method: get operationId: Workspaces_ListBySubscription x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces method: get operationId: Workspaces_ListByResourceGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName} method: get operationId: Workspaces_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName} method: put operationId: Workspaces_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName} method: patch operationId: Workspaces_Update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName} method: delete operationId: Workspaces_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/dicomservices method: get operationId: DicomServices_ListByWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/dicomservices/{dicomServiceName} method: get operationId: DicomServices_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/dicomservices/{dicomServiceName} method: put operationId: DicomServices_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/dicomservices/{dicomServiceName} method: patch operationId: DicomServices_Update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/dicomservices/{dicomServiceName} method: delete operationId: DicomServices_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors method: get operationId: IotConnectors_ListByWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName} method: get operationId: IotConnectors_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName} method: put operationId: IotConnectors_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName} method: patch operationId: IotConnectors_Update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName} method: delete operationId: IotConnectors_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName}/fhirdestinations method: get operationId: FhirDestinations_ListByIotConnector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName}/fhirdestinations/{fhirDestinationName} method: get operationId: IotConnectorFhirDestination_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName}/fhirdestinations/{fhirDestinationName} method: put operationId: IotConnectorFhirDestination_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/iotconnectors/{iotConnectorName}/fhirdestinations/{fhirDestinationName} method: delete operationId: IotConnectorFhirDestination_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/fhirservices method: get operationId: FhirServices_ListByWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/fhirservices/{fhirServiceName} method: get operationId: FhirServices_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/fhirservices/{fhirServiceName} method: put operationId: FhirServices_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/fhirservices/{fhirServiceName} method: patch operationId: FhirServices_Update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/fhirservices/{fhirServiceName} method: delete operationId: FhirServices_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateEndpointConnections method: get operationId: WorkspacePrivateEndpointConnections_ListByWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateEndpointConnections/{privateEndpointConnectionName} method: get operationId: WorkspacePrivateEndpointConnections_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateEndpointConnections/{privateEndpointConnectionName} method: put operationId: WorkspacePrivateEndpointConnections_CreateOrUpdate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateEndpointConnections/{privateEndpointConnectionName} method: delete operationId: WorkspacePrivateEndpointConnections_Delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateLinkResources method: get operationId: WorkspacePrivateLinkResources_ListByWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.HealthcareApis/workspaces/{workspaceName}/privateLinkResources/{groupName} method: get operationId: WorkspacePrivateLinkResources_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /providers/Microsoft.HealthcareApis/operations method: get operationId: Operations_List x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation - path: /subscriptions/{subscriptionId}/providers/Microsoft.HealthcareApis/locations/{locationName}/operationresults/{operationResultId} method: get operationId: OperationResults_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - user_impersonation