generated: '2026-07-24' method: generated source: openapi/nextgen-office-bulk-fhir-r4-openapi.yml, openapi/nextgen-office-fhir-r4-openapi.yaml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 54 by_action_class: connected: 50 acting: 4 by_consequence: read: 50 write: 4 human_in_the_loop_required: 0 operations: - path: /bulkfhir/r4/$patient-search method: get operationId: searchPatients x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bulkfhir/r4/Group method: post operationId: createGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /bulkfhir/r4/Group method: get operationId: getAllGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bulkfhir/r4/Group/{id} method: put operationId: updateGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /bulkfhir/r4/Group/{id} method: delete operationId: deleteGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /bulkfhir/r4/Group/{id} method: get operationId: getGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bulkfhir/r4/Group/{id}/$export method: get operationId: groupExport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bulkfhir/r4/$export-poll-status method: get operationId: pollJobStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bulkfhir/r4/$export-poll-status method: delete operationId: deleteJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /fhir/r4/Patient/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Patient method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/DocumentReference/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/DocumentReference method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Encounter/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Encounter method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Procedure/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Procedure method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Condition/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Condition method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Goal/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Goal method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Observation/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Observation method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Immunization/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Immunization method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/AllergyIntolerance/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/AllergyIntolerance method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationRequest/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationRequest method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationDispense/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationDispense method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationAdministration/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/MedicationAdministration method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/DiagnosticReport/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/DiagnosticReport method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Device/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Device method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/CarePlan/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/CarePlan method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/CareTeam/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/CareTeam method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Practitioner/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/PractitionerRole/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/PractitionerRole method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Location/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Organization/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Provenance/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Specimen/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Specimen method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/RelatedPerson/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/RelatedPerson method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Coverage/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /fhir/r4/Coverage method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read - path: /ccda method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - patient/*.read