generated: '2026-07-15' method: generated source: openapi/phorest-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 62 by_action_class: connected: 39 acting: 23 by_consequence: read: 39 write: 20 physical: 3 human_in_the_loop_required: 0 operations: - path: /{businessId}/client method: get operationId: getClients x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/client method: post operationId: createClient x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/client/{clientId} method: get operationId: getClient x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/client/{clientId} method: put operationId: updateClient x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/client/walkin method: get operationId: getWalkInClient x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/category/client method: get operationId: getClientCategories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/category/client/{categoryId} method: get operationId: getClientCategory x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/appointment method: get operationId: getAppointments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/appointment/{appointmentId} method: get operationId: getAppointment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/appointment/{appointmentId} method: put operationId: updateAppointment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/appointment/{appointmentId}/cancel method: post operationId: cancelAppointment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/appointment/{appointmentId}/confirm method: post operationId: confirmAppointment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/appointment/{appointmentId}/checkin method: post operationId: checkInAppointment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/appointments/availability method: post operationId: checkAppointmentAvailability x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/booking method: post operationId: createBooking x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/booking/{bookingId}/cancel method: post operationId: cancelBooking x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/booking/{bookingId}/activate method: post operationId: activateBooking x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/booking/{bookingId}/note method: post operationId: appendNoteToBooking x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/deposit-payment-link method: post operationId: createDepositPaymentLink x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/staff method: get operationId: getStaffList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/staff/{staffId} method: get operationId: getStaff x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/staff-work-time-table method: get operationId: getStaffWorkTimeTables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/staff/{staffId}/break method: get operationId: getBreaks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/staff/{staffId}/break method: post operationId: createBreak x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/staff/{staffId}/break/{breakId} method: get operationId: getStaffBreak x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/staff/{staffId}/break/{breakId} method: put operationId: updateBreak x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/staff/{staffId}/break/{breakId} method: delete operationId: deleteBreak x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/service method: get operationId: getServices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/service/{serviceId} method: get operationId: getService x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/service-category method: get operationId: getServiceCategories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/package method: get operationId: getServicePackages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/service-special-offer method: get operationId: getServiceSpecialOffers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/course method: get operationId: getCourses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/client/{clientId}/course method: get operationId: getClientCourses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/client/{clientId}/course/{courseId} method: get operationId: getClientCourse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/client/{clientId}/course/{courseId} method: put operationId: updateClientCourse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch method: get operationId: getBranches x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/worktimetable method: get operationId: getBranchWorkTimeTable x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/room method: get operationId: getRooms x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/room/{roomId} method: get operationId: getRoom x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/machine method: get operationId: getMachines x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/machine/{machineId} method: get operationId: getMachine x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/taxrate method: get operationId: getTaxRates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/taxrate/{taxRateId} method: get operationId: getTaxRate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/product method: get operationId: getProducts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/inventorytransaction method: get operationId: getInventoryTransactions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/stock/adjustment method: post operationId: performStockAdjustment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/purchase method: post operationId: createPurchase x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/till/{tillId}/balance method: get operationId: getTillBalance x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/salefee method: get operationId: getSaleFeeList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/voucher method: get operationId: getVouchers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/voucher method: post operationId: createVoucher x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/voucher/{voucherId} method: get operationId: getVoucher x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/voucher/{voucherId} method: put operationId: updateVoucherBalance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/loyaltypoints method: post operationId: changeLoyaltyPoints x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/csvexportjob method: post operationId: createCsvExportJob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{businessId}/branch/{branchId}/csvexportjob/{jobId} method: get operationId: getCsvExportJob x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/review method: get operationId: getReviewList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/review/{reviewId} method: get operationId: getReview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/leads method: get operationId: getLeads x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/branch/{branchId}/leads/stats method: get operationId: getLeadsStats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{businessId}/lead method: post operationId: createLead x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required