generated: '2026-08-01' method: searched source: openapi/kandji-endpoint-management-openapi.json, openapi/kandji-upload-to-s3-openapi.json (generated by 0-working/derive-agentic-access.py) then CURATED against Iru's own published agent guidance at https://docs.iru.com/en/endpoint/integrations/ai-assistants/iru-mcp description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 122 by_action_class: connected: 69 acting: 53 by_consequence: read: 69 write: 43 safety-critical: 10 human_in_the_loop_required: 10 operations: - path: /api/v1/audit/events method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/public_key/ method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/ method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/integrations/apple/ade/{ade_token_id}/renew method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/integrations/apple/ade/{ade_token_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/integrations/apple/ade/{ade_token_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/{ade_token_id} method: delete x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/integrations/apple/ade method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/{ade_token_id}/devices method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/devices method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/devices/{device_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/integrations/apple/ade/devices/{device_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/blueprints method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/blueprints method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/blueprints/{blueprint_id}/ota-enrollment-profile method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/blueprints/templates/ method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/action/enablelostmode method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/disablelostmode method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/playlostmodesound method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/updatelocation method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/clearpasscode method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id} method: delete x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/erase method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/commands method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/action/lock method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/reinstallagent method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/remotedesktop method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/renewmdmprofile method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/restart method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/blankpush method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required x-curation-reason: Blank push is a benign MDM wake-up ping; the generator matched it on the "push" keyword. Downgraded from physical. - path: /api/v1/devices/{device_id}/action/setname method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/shutdown method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/devices/{device_id}/action/updateinventory method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/unlockaccount method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/notes method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/notes method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/notes/{note_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/notes/{note_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/notes/{note_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/details method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/details/lostmode method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/details/lostmode method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/activity method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/apps method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/library-items method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/parameters method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/status method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/secrets/bypasscode method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: required x-sensitivity: credential-material x-curation-reason: Read-only, but returns FileVault recovery key / Activation Lock bypass code / recovery password / unlock PIN. Treat as a high-sensitivity read requiring purpose and audit. escalation: human-in-the-loop: conditional triggers: - high-value - path: /api/v1/devices/{device_id}/secrets/filevaultkey method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: required x-sensitivity: credential-material x-curation-reason: Read-only, but returns FileVault recovery key / Activation Lock bypass code / recovery password / unlock PIN. Treat as a high-sensitivity read requiring purpose and audit. escalation: human-in-the-loop: conditional triggers: - high-value - path: /api/v1/devices/{device_id}/secrets/unlockpin method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: required x-sensitivity: credential-material x-curation-reason: Read-only, but returns FileVault recovery key / Activation Lock bypass code / recovery password / unlock PIN. Treat as a high-sensitivity read requiring purpose and audit. escalation: human-in-the-loop: conditional triggers: - high-value - path: /api/v1/devices/{device_id}/secrets/recoverypassword method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: required x-sensitivity: credential-material x-curation-reason: Read-only, but returns FileVault recovery key / Activation Lock bypass code / recovery password / unlock PIN. Treat as a high-sensitivity read requiring purpose and audit. escalation: human-in-the-loop: conditional triggers: - high-value - path: /api/v1/library/custom-apps method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-apps method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-apps/{library_item_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-apps/{library_item_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-apps/{library_item_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-apps/upload method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/ipa-apps method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/ipa-apps method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/ipa-apps/{library_item_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/ipa-apps/{library_item_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/ipa-apps/{library_item_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/ipa-apps/upload method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/ipa-apps/upload/{pending_upload_id}/status method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-profiles method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-profiles method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-profiles/{library_item_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-profiles/{library_item_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-profiles/{library_item_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-scripts method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-scripts method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-scripts/{library_item_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/custom-scripts/{library_item_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/library/custom-scripts/{library_item_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/self-service/categories method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/library-items/{library_item_id}/activity method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/library/library-items/{library_item_id}/status method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/activation_lock method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/apps method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/application_firewall method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/cellular method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/certificates method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/desktop_and_screensaver method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/device_information method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/filevault method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/gatekeeper_and_xprotect method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/installed_profiles method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/kernel_extensions method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/launch_agents_and_daemons method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/local_users method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/startup_settings method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/system_extensions method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/transparency_database method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/export method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/prism/export/{export_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/prism/count method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/settings/licensing method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/tags method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/tags method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/tags/{tag_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/tags/{tag_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/threat-details method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/behavioral-detections method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/vulnerability-management/detections method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/vulnerability-management/vulnerabilities method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/blueprints/{blueprint_id} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/blueprints/{blueprint_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/blueprints/{blueprint_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/devices/{device_id}/action/deleteuser method: post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required x-curation-reason: Destructive MDM/tenant operation. Iru documents that destructive operations (erase, delete, lock) require explicit human approval before execution. - path: /api/v1/users method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/users/{user_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/users/{user_id} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/blueprints/{blueprint_id}/assign-library-item method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/blueprints/{blueprint_id}/list-library-items method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/vulnerability-management/vulnerabilities/{cve_id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/vulnerability-management/vulnerabilities/{cve_id}/devices method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/vulnerability-management/vulnerabilities/{cve_id}/software method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/devices/{device_id}/action/dailycheckin method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{post_url} method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required x-curation: date: '2026-08-01' basis: 'Iru documents: "For destructive operations (for example erase, delete, lock), your assistant should summarize the impact and require your explicit approval before executing, unless you have added that action to an allowlist for the MCP." The keyword heuristic did not reach those operations, so they were raised by hand; one false positive was lowered.' changes: - DELETE /api/v1/integrations/apple/ade/{ade_token_id} -> safety-critical - POST /api/v1/devices/{device_id}/action/enablelostmode -> safety-critical - POST /api/v1/devices/{device_id}/action/clearpasscode -> safety-critical - DELETE /api/v1/devices/{device_id} -> safety-critical - POST /api/v1/devices/{device_id}/action/erase -> safety-critical - POST /api/v1/devices/{device_id}/action/lock -> safety-critical - POST /api/v1/devices/{device_id}/action/restart -> safety-critical - POST /api/v1/devices/{device_id}/action/blankpush -> write - GET /api/v1/devices/{device_id}/secrets/bypasscode -> read+credential-material - GET /api/v1/devices/{device_id}/secrets/filevaultkey -> read+credential-material - GET /api/v1/devices/{device_id}/secrets/unlockpin -> read+credential-material - GET /api/v1/devices/{device_id}/secrets/recoverypassword -> read+credential-material - POST /api/v1/devices/{device_id}/action/deleteuser -> safety-critical