{ "openapi": "3.1.0", "info": { "title": "Qualio Developer API", "version": "0.1", "description": "Whether you're streamlining document control, automating quality event management, integrating training records, or syncing supplier data across systems, the Qualio API provides secure and scalable solutions. Getting started is easy: generate an API key, authenticate your requests, explore example code, and start building. Follow the steps below to integrate with Qualio quickly and efficiently.\n\n This portal includes everything you need to build with confidence:\n- Secure, token-based authentication\n- Full reference documentation for each endpoint\n- Example code in multiple programming languages\n- \"Try it out\" functionality to test requests live\n- Fair usage rate limits to ensure system stability\n \n\n #### Generate Your API Key \n To access the API, you’ll need an API key:\n\n- Log in to the [Qualio admin panel](https://app.qualio.com/user-management/admin).\n\n- Navigate to Admin Settings > [Developer API tokens](https://app.qualio.com/user-management/admin/dev-api).\n\n- Click Create token and save the key securely.\n\n- Only users with administrative privileges can generate API keys. \n\n\n\nIf you don’t have admin access, please ask your Qualio administrator to create a key for you.\n \n\n #### Authenticate Your Requests\n\nQualio uses API key authentication using the X-Api-Key header. Add your API key in the authentication panel to the right to see examples of how to use it in a language of your choice.\n \n\n #### Make Your First API Call\n\nHere is an easy place to get started: [fetching all your effective documents](#tag/documents/GET/v1/documents/query)\n \n\n #### Respect Rate Limits\n\nTo ensure fair use and maintain performance, API requests are subject to rate limits:\n\n- Each API key has a request threshold of maximum 200 requests per minute\n- If you exceed this limit, you'll receive an HTTP 429 (Too Many Requests) response.\n- We recommend implementing retry logic in your client applications, if this is a concern for you.\n\n \n\n #### Explore and Build\nUse the navigation panel to browse available API endpoints, such as:\n- Documents — Create, query, and manage your controlled documents\n- User Management — Invite users, update roles, or sync user data\n- Audit Trail — Retrieve historical changes for compliance reporting\n- You’ll find example code in Python, JavaScript, C#, Ruby, PHP, Go, and Shell for each endpoint. Click “Try it out” to test requests directly from the browser.\n \n\n #### How is this API versioned? \n We prefix each URL with the major version of the API. Within this major version, we promise to not make any breaking changes, which are:\n - Changes to the datatype of request or response payload attribute. \n - Removal of an attribute or parameter. \n - Changes to a URL. \n\n We do not consider the following to be breaking changes: \n - Additional attributes on return payloads \n - Additional optional attributes on request payloads \n\n \n#### Where can I get an OpenApi spec for this? \n You can [find it here](/download-openapi), but bear in mind that this API is updated regularly, so be sure to fetch it afresh for the latest features\n" }, "servers": [ { "url": "https://api.qualio.com" } ], "security": [ { "api_key": [] } ], "tags": [ { "name": "Audit Trail" }, { "name": "Design Controls" }, { "name": "Documents" }, { "name": "Change Management" }, { "name": "Compliance Intelligence" }, { "name": "Events" }, { "name": "Resource Library" }, { "name": "Shared" }, { "name": "Suppliers" }, { "name": "Tags" }, { "name": "Training" }, { "name": "User Management" } ], "paths": { "/v1/audit-trail/audits": { "get": { "summary": "Query the audit trail", "description": "Returns the company's audit trail: a chronological, immutable log of significant user and system activity across the quality management system (also referred to as the activity log or history). Each entry captures the action performed, the user who performed it (or none, for automated system actions), the date, and a link to the affected object. Tracked activity includes document approvals, reviews and status changes; user and group management (invitations, account changes, group membership); tag changes; quality event, issue and task activity; periodic reviews; and configuration changes such as SSO and billing. Results are scoped to the company associated with the API key and can be filtered by user and by date range.", "operationId": "queryAuditTrail", "tags": [ "Audit Trail" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" }, "required": true, "description": "The maximum number of results to return. This is typically used with offset to paginate results." }, { "in": "query", "name": "user_id", "schema": { "$ref": "#/components/schemas/userIdParam" }, "description": "A unique identifier for a user in Qualio" }, { "in": "query", "name": "start_date", "schema": { "$ref": "#/components/schemas/startDateParam" }, "description": "Filter results from this date onwards (ISO 8601 format)" }, { "in": "query", "name": "end_date", "schema": { "$ref": "#/components/schemas/endDateParam" }, "description": "Filter results up to this date (ISO 8601 format)" } ], "responses": { "200": { "description": "Successful audit trail retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/auditTrailResp" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Returns the company's audit trail: a chronological, immutable log of significant user and system activity across the quality management system (also referred to as the activity log or history). Each entry captures the action performed, the user who performed it (or none, for automated system actions), the date, and a link to the affected object. Tracked activity includes document approvals, reviews and status changes; user and group management (invitations, account changes, group membership); tag changes; quality event, issue and task activity; periodic reviews; and configuration changes such as SSO and billing. Results are scoped to the company associated with the API key and can be filtered by user and by date range.", "operationId": "queryAuditTrailOptions", "tags": [ "Audit Trail" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" }, "required": true, "description": "The maximum number of results to return. This is typically used with offset to paginate results." }, { "in": "query", "name": "user_id", "schema": { "$ref": "#/components/schemas/userIdParam" }, "description": "A unique identifier for a user in Qualio" }, { "in": "query", "name": "start_date", "schema": { "$ref": "#/components/schemas/startDateParam" }, "description": "Filter results from this date onwards (ISO 8601 format)" }, { "in": "query", "name": "end_date", "schema": { "$ref": "#/components/schemas/endDateParam" }, "description": "Filter results up to this date (ISO 8601 format)" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/change-management/change-controls": { "get": { "summary": "List change controls", "description": "Lists change controls for your Qualio instance. A change control (CC) is a formal, auditable record that documents and routes a change for review and approval â typically a change to one or more controlled documents, which appear as the change control's linked items. Each entry includes its id (e.g. CC-123), title, owner, status (`open` or `closed`), timestamps, and content sections. Supports filtering by status, ordering, and pagination.", "operationId": "listChangeControls", "tags": [ "Change Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/statusParam" }, "description": "The status of a domain object" }, { "in": "query", "name": "orderBy", "schema": { "$ref": "#/components/schemas/orderByParam" }, "description": "The field to order the results by" } ], "responses": { "200": { "description": "Successful change control entries retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/changeControlResp" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists change controls for your Qualio instance. A change control (CC) is a formal, auditable record that documents and routes a change for review and approval â typically a change to one or more controlled documents, which appear as the change control's linked items. Each entry includes its id (e.g. CC-123), title, owner, status (`open` or `closed`), timestamps, and content sections. Supports filtering by status, ordering, and pagination.", "operationId": "listChangeControlsOptions", "tags": [ "Change Management" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/statusParam" }, "description": "The status of a domain object" }, { "in": "query", "name": "orderBy", "schema": { "$ref": "#/components/schemas/orderByParam" }, "description": "The field to order the results by" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a change control", "description": "Creates a change control for a draft document. A change control is the formal workflow record that documents and routes the proposed change for review and approval. Provide the document and the content `sections`; the section positions must match those defined by the change control template and start at position 1.", "operationId": "createChangeControl", "tags": [ "Change Management" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createCC" } } } }, "responses": { "200": { "description": "Successful change control entries retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createdCC" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/change-management/change-requests": { "get": { "summary": "List change requests", "description": "Lists change requests for your Qualio instance. A change request (CR) is a formal record used to propose, track, and approve changes to controlled documents. Each entry includes its code (e.g. DCR-1), title, owner, status, timestamps, and linked change items. Supports filtering by status, text search, ordering, and pagination.", "operationId": "listChangeRequests", "tags": [ "Change Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/statusParam" }, "description": "The status of a domain object" }, { "in": "query", "name": "orderBy", "schema": { "$ref": "#/components/schemas/orderByParam" }, "description": "The field to order the results by" } ], "responses": { "200": { "description": "Successful change request list retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/changeRequestResp" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists change requests for your Qualio instance. A change request (CR) is a formal record used to propose, track, and approve changes to controlled documents. Each entry includes its code (e.g. DCR-1), title, owner, status, timestamps, and linked change items. Supports filtering by status, text search, ordering, and pagination.", "operationId": "listChangeRequestsOptions", "tags": [ "Change Management" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/statusParam" }, "description": "The status of a domain object" }, { "in": "query", "name": "orderBy", "schema": { "$ref": "#/components/schemas/orderByParam" }, "description": "The field to order the results by" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/compliance/frameworks": { "get": { "summary": "List frameworks", "description": "Lists the compliance frameworks in your Qualio instance. A framework is a compliance standard (for example ISO 13485, ISO 9001, or GDPR) that groups the requirements your organisation has committed to meet. Each framework has a status: disabled (not currently in use), implementing (controls are being set up), or monitoring (actively tracking compliance against the standard). Results are ordered by framework id. Use the offset and limit parameters to page through large sets; the total field in the response reports the full count of matching frameworks before pagination is applied. Filter by status to return only frameworks in a particular state; omit the parameter to return frameworks in any state.", "operationId": "listComplianceFrameworks", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "status", "schema": { "description": "Filter results to only frameworks with this status. Accepted values: disabled, implementing, monitoring. Omit to return frameworks in any state.", "example": "monitoring", "type": "string", "enum": [ "disabled", "implementing", "monitoring" ] }, "description": "Filter results to only frameworks with this status. Accepted values: disabled, implementing, monitoring. Omit to return frameworks in any state." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Successful retrieval of compliance frameworks.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the framework.", "example": 1 }, "name": { "type": "string", "description": "The display name of the compliance framework.", "example": "ISO 13485" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the framework.", "example": "Medical devices: Quality management systems" }, "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The current status of the framework. disabled: not currently in use. implementing: controls are being set up. monitoring: actively tracking compliance.", "example": "monitoring" } }, "required": [ "id", "name", "description", "status" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A paginated list of compliance frameworks.", "example": { "total": 2, "items": [ { "id": 1, "name": "ISO 13485", "description": "Medical devices: Quality management systems", "status": "monitoring" }, { "id": 2, "name": "ISO 9001", "description": null, "status": "implementing" } ] }, "ref": "complianceFrameworkListResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the compliance frameworks in your Qualio instance. A framework is a compliance standard (for example ISO 13485, ISO 9001, or GDPR) that groups the requirements your organisation has committed to meet. Each framework has a status: disabled (not currently in use), implementing (controls are being set up), or monitoring (actively tracking compliance against the standard). Results are ordered by framework id. Use the offset and limit parameters to page through large sets; the total field in the response reports the full count of matching frameworks before pagination is applied. Filter by status to return only frameworks in a particular state; omit the parameter to return frameworks in any state.", "operationId": "listComplianceFrameworksOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "status", "schema": { "description": "Filter results to only frameworks with this status. Accepted values: disabled, implementing, monitoring. Omit to return frameworks in any state.", "example": "monitoring", "type": "string", "enum": [ "disabled", "implementing", "monitoring" ] }, "description": "Filter results to only frameworks with this status. Accepted values: disabled, implementing, monitoring. Omit to return frameworks in any state." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a framework", "description": "Creates a new compliance framework in your Qualio instance. Provide a name and an optional description. The framework is created with a disabled status and must be activated in the Qualio application before requirements can be tracked against it. The id returned in the response can be used to retrieve or update the framework via the other Compliance Intelligence endpoints.", "operationId": "createComplianceFramework", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "name": { "type": "string", "minLength": 1, "description": "The display name of the new compliance framework.", "example": "ISO 13485" }, "description": { "description": "An optional human-readable description of the framework.", "example": "Medical devices: Quality management systems", "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "name" ], "description": "The framework to create.", "example": { "name": "ISO 13485", "description": "Medical devices: Quality management systems" }, "ref": "createComplianceFrameworkRequest" } } } }, "responses": { "201": { "description": "Framework created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the framework.", "example": 1 }, "name": { "type": "string", "description": "The display name of the compliance framework.", "example": "ISO 13485" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the framework.", "example": "Medical devices: Quality management systems" }, "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The current status of the framework. disabled: not currently in use. implementing: controls are being set up. monitoring: actively tracking compliance.", "example": "monitoring" }, "stats": { "anyOf": [ { "type": "object", "properties": { "total_requirements": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Total number of requirements in the framework.", "example": 42 }, "passed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements with a met assessment.", "example": 30 }, "failed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements flagged as attention required.", "example": 5 }, "not_assessed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements that have not yet been fully assessed. Includes requirements in not_started and in_progress states.", "example": 7 } }, "required": [ "total_requirements", "passed", "failed", "not_assessed" ], "additionalProperties": false }, { "type": "null" } ] } }, "required": [ "id", "name", "description", "status" ], "additionalProperties": false, "description": "The newly created framework.", "example": { "id": 10, "name": "ISO 13485", "description": "Medical devices: Quality management systems", "status": "disabled", "stats": null }, "ref": "createdComplianceFramework" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/frameworks/{frameworkId}": { "put": { "summary": "Update a framework", "description": "Updates a compliance framework identified by its numeric id. This is a partial update: include only the fields you want to change. Omitting a field leaves its current value unchanged. Pass null for description to clear it. To change the framework lifecycle status, use PATCH /v1/compliance/frameworks/{frameworkId}/status.", "operationId": "updateComplianceFramework", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "name": { "description": "New display name for the framework. Omit to leave unchanged.", "example": "ISO 13485 (2016)", "type": "string", "minLength": 1 }, "description": { "description": "New description for the framework. Omit to leave unchanged. Pass null to clear an existing description.", "example": "Medical devices: Quality management systems", "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "description": "Fields to update on the framework.", "example": { "name": "ISO 13485 (2016)", "description": "Medical devices: Quality management systems" }, "ref": "updateComplianceFrameworkRequest" } } } }, "responses": { "200": { "description": "Framework updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the framework.", "example": 1 }, "name": { "type": "string", "description": "The display name of the compliance framework.", "example": "ISO 13485" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the framework.", "example": "Medical devices: Quality management systems" }, "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The current status of the framework. disabled: not currently in use. implementing: controls are being set up. monitoring: actively tracking compliance.", "example": "monitoring" }, "stats": { "description": "Assessment statistics for the framework. Populated when the framework status is implementing or monitoring. null or absent when the framework is disabled.", "example": null, "anyOf": [ { "type": "object", "properties": { "total_requirements": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Total number of requirements in the framework.", "example": 42 }, "passed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements with a met assessment.", "example": 30 }, "failed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements flagged as attention required.", "example": 5 }, "not_assessed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements that have not yet been fully assessed. Includes requirements in not_started and in_progress states.", "example": 7 } }, "required": [ "total_requirements", "passed", "failed", "not_assessed" ], "additionalProperties": false }, { "type": "null" } ] } }, "required": [ "id", "name", "description", "status" ], "additionalProperties": false, "description": "The updated framework.", "example": { "id": 1, "name": "ISO 13485 (2016)", "description": "Medical devices: Quality management systems", "status": "monitoring", "stats": null }, "ref": "updatedComplianceFramework" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Framework not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Updates a compliance framework identified by its numeric id. This is a partial update: include only the fields you want to change. Omitting a field leaves its current value unchanged. Pass null for description to clear it. To change the framework lifecycle status, use PATCH /v1/compliance/frameworks/{frameworkId}/status.", "operationId": "updateComplianceFrameworkOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "get": { "summary": "Get a framework", "description": "Returns the details of a single compliance framework identified by its numeric id. The stats field is populated when the framework status is implementing or monitoring, and is null when the framework is disabled. Stats break down the framework requirements by assessment outcome: passed counts requirements with a met assessment, failed counts requirements flagged as attention required, and not_assessed counts requirements that are not_started or in_progress. The sum of passed, failed, and not_assessed equals total_requirements.", "operationId": "getComplianceFramework", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "responses": { "200": { "description": "Successful retrieval of the compliance framework.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the framework.", "example": 1 }, "name": { "type": "string", "description": "The display name of the compliance framework.", "example": "ISO 13485" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the framework.", "example": "Medical devices: Quality management systems" }, "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The current status of the framework. disabled: not currently in use. implementing: controls are being set up. monitoring: actively tracking compliance.", "example": "monitoring" }, "stats": { "description": "Assessment statistics for the framework. Populated when the framework status is implementing or monitoring. null or absent when the framework is disabled.", "example": null, "anyOf": [ { "type": "object", "properties": { "total_requirements": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Total number of requirements in the framework.", "example": 42 }, "passed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements with a met assessment.", "example": 30 }, "failed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements flagged as attention required.", "example": 5 }, "not_assessed": { "type": "integer", "minimum": 0, "maximum": 9007199254740991, "description": "Number of requirements that have not yet been fully assessed. Includes requirements in not_started and in_progress states.", "example": 7 } }, "required": [ "total_requirements", "passed", "failed", "not_assessed" ], "additionalProperties": false }, { "type": "null" } ] } }, "required": [ "id", "name", "description", "status" ], "additionalProperties": false, "description": "The requested compliance framework.", "example": { "id": 1, "name": "ISO 13485", "description": "Medical devices: Quality management systems", "status": "monitoring", "stats": { "total_requirements": 42, "passed": 30, "failed": 5, "not_assessed": 7 } }, "ref": "complianceFrameworkDetail" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Framework not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "delete": { "summary": "Delete a framework", "description": "Permanently deletes a custom compliance framework identified by its numeric id. Only frameworks created by your organisation can be deleted. Qualio-managed frameworks (built-in standards such as ISO 13485 or GDPR) cannot be deleted and will return a 403 if you attempt to do so. Deletion removes the framework and its associated requirements from your instance. This action cannot be undone. A successful deletion returns no content.", "operationId": "deleteComplianceFramework", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "responses": { "204": { "description": "Framework deleted successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "anyOf": [ { "type": "object", "properties": {}, "additionalProperties": false }, { "type": "null" } ] } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Framework not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/frameworks/{frameworkId}/status": { "patch": { "summary": "Update a framework status", "description": "Updates the lifecycle status of a compliance framework for your Qualio instance. The status controls whether the framework is actively tracked: disabled (not currently in use), implementing (controls are being set up), or monitoring (activated for active compliance tracking).", "operationId": "updateComplianceFrameworkStatus", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The new lifecycle status for the framework. disabled: deactivates the framework. implementing: marks the framework as being set up. monitoring: activates the framework for active compliance tracking.", "example": "monitoring" } }, "required": [ "status" ], "description": "The new status to apply to the framework.", "example": { "status": "monitoring" }, "ref": "updateComplianceFrameworkStatusRequest" } } } }, "responses": { "200": { "description": "Framework status updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework whose status was updated.", "example": 1 }, "status": { "type": "string", "enum": [ "disabled", "implementing", "monitoring" ], "description": "The current lifecycle status of the framework.", "example": "monitoring" } }, "required": [ "framework_id", "status" ], "additionalProperties": false, "description": "The updated framework status.", "example": { "framework_id": 1, "status": "monitoring" }, "ref": "complianceFrameworkStatus" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Framework not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Updates the lifecycle status of a compliance framework for your Qualio instance. The status controls whether the framework is actively tracked: disabled (not currently in use), implementing (controls are being set up), or monitoring (activated for active compliance tracking).", "operationId": "updateComplianceFrameworkStatusOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "frameworkId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance framework.", "example": 1 }, "required": true, "description": "The numeric id of the compliance framework." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/compliance/requirements": { "get": { "summary": "List requirements", "description": "Lists the compliance requirements in your Qualio instance. A requirement is an individual clause or control obligation from a compliance framework that your organisation has committed to meet. Each requirement belongs to exactly one framework and carries a requirement_number (for example a clause reference such as 7.1), a short name, and optional full normative text. Use the framework_id parameter to return requirements for a specific framework only. Omit it to return requirements across all frameworks visible to your instance. Results are ordered by requirement id. Use offset and limit to page through large sets; the total field in the response reports the full count before pagination is applied.", "operationId": "listComplianceRequirements", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to requirements belonging to this framework id. Omit to return requirements across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to requirements belonging to this framework id. Omit to return requirements across all frameworks." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Successful retrieval of compliance requirements.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the requirement.", "example": 101 }, "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework this requirement belongs to.", "example": 1 }, "requirement_number": { "type": "string", "description": "The alphanumeric identifier for the requirement within its framework. For example, a clause number such as 7.1 or a section reference such as A.5.1.", "example": "7.1" }, "name": { "type": "string", "description": "The short title of the requirement.", "example": "Planning of product realisation" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional description of the requirement.", "example": null } }, "required": [ "id", "framework_id", "requirement_number", "name", "description" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A paginated list of compliance requirements.", "example": { "total": 2, "items": [ { "id": 101, "framework_id": 1, "requirement_number": "7.1", "name": "Planning of product realisation", "description": null }, { "id": 102, "framework_id": 1, "requirement_number": "7.2", "name": "Customer-related processes", "description": null } ] }, "ref": "complianceRequirementListResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the compliance requirements in your Qualio instance. A requirement is an individual clause or control obligation from a compliance framework that your organisation has committed to meet. Each requirement belongs to exactly one framework and carries a requirement_number (for example a clause reference such as 7.1), a short name, and optional full normative text. Use the framework_id parameter to return requirements for a specific framework only. Omit it to return requirements across all frameworks visible to your instance. Results are ordered by requirement id. Use offset and limit to page through large sets; the total field in the response reports the full count before pagination is applied.", "operationId": "listComplianceRequirementsOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to requirements belonging to this framework id. Omit to return requirements across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to requirements belonging to this framework id. Omit to return requirements across all frameworks." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a requirement", "description": "Creates a new compliance requirement and associates it with an existing framework. Provide the framework_id of the framework the requirement belongs to, a unique requirement_number within that framework (for example a clause reference such as 7.1), and a short name. The description and requirement_text fields are optional: omit them or pass null when not available. The id returned in the response can be used to retrieve the requirement via the List requirements endpoint.", "operationId": "createComplianceRequirement", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework this requirement belongs to.", "example": 1 }, "requirement_number": { "type": "string", "minLength": 1, "description": "The alphanumeric identifier for the requirement within its framework. For example, a clause number such as 7.1 or a section reference such as A.5.1.", "example": "7.1" }, "name": { "type": "string", "minLength": 1, "description": "The short title of the requirement.", "example": "Planning of product realisation" }, "description": { "description": "An optional description of the requirement.", "example": null, "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "framework_id", "requirement_number", "name" ], "description": "The requirement to create.", "example": { "framework_id": 1, "requirement_number": "7.1", "name": "Planning of product realisation", "description": null }, "ref": "createComplianceRequirementRequest" } } } }, "responses": { "201": { "description": "Requirement created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the requirement.", "example": 101 }, "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework this requirement belongs to.", "example": 1 }, "requirement_number": { "type": "string", "description": "The alphanumeric identifier for the requirement within its framework. For example, a clause number such as 7.1 or a section reference such as A.5.1.", "example": "7.1" }, "name": { "type": "string", "description": "The short title of the requirement.", "example": "Planning of product realisation" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional description of the requirement.", "example": null } }, "required": [ "id", "framework_id", "requirement_number", "name", "description" ], "additionalProperties": false, "description": "The newly created requirement.", "example": { "id": 101, "framework_id": 1, "requirement_number": "7.1", "name": "Planning of product realisation", "description": null }, "ref": "createdComplianceRequirement" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Framework not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/requirements/{requirementId}": { "put": { "summary": "Update a requirement", "description": "Updates a compliance requirement identified by its numeric id. This is a partial update: include only the fields you want to change. Omitting a field leaves its current value unchanged. Pass null for description to clear it.", "operationId": "updateComplianceRequirement", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "requirementId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance requirement.", "example": 101 }, "required": true, "description": "The numeric id of the compliance requirement." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "name": { "description": "New short title for the requirement. Omit to leave unchanged.", "example": "Updated planning of product realisation", "type": "string", "minLength": 1 }, "requirement_number": { "description": "New alphanumeric identifier for the requirement. Omit to leave unchanged.", "example": "7.1.1", "type": "string", "minLength": 1 }, "description": { "description": "New description for the requirement. Omit to leave unchanged. Pass null to clear an existing description.", "example": null, "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "description": "Fields to update on the requirement.", "example": { "name": "Planning of product realisation (revised)", "requirement_number": "7.1.1", "description": null }, "ref": "updateComplianceRequirementRequest" } } } }, "responses": { "200": { "description": "Requirement updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the requirement.", "example": 101 }, "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework this requirement belongs to.", "example": 1 }, "requirement_number": { "type": "string", "description": "The alphanumeric identifier for the requirement within its framework. For example, a clause number such as 7.1 or a section reference such as A.5.1.", "example": "7.1" }, "name": { "type": "string", "description": "The short title of the requirement.", "example": "Planning of product realisation" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional description of the requirement.", "example": null } }, "required": [ "id", "framework_id", "requirement_number", "name", "description" ], "additionalProperties": false, "description": "The updated requirement.", "example": { "id": 101, "framework_id": 1, "requirement_number": "7.1.1", "name": "Planning of product realisation (revised)", "description": null }, "ref": "updatedComplianceRequirement" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Requirement not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Updates a compliance requirement identified by its numeric id. This is a partial update: include only the fields you want to change. Omitting a field leaves its current value unchanged. Pass null for description to clear it.", "operationId": "updateComplianceRequirementOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "requirementId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance requirement.", "example": 101 }, "required": true, "description": "The numeric id of the compliance requirement." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "delete": { "summary": "Delete a requirement", "description": "Permanently deletes a custom compliance requirement identified by its numeric id. Only requirements created by your organisation can be deleted. Qualio-managed requirements (built-in clauses from standards such as ISO 13485 or GDPR) cannot be deleted and will return a 403 if you attempt to do so. Deletion removes the requirement and cleans up any open compliance gaps that were exclusively linked to it. This action cannot be undone. A successful deletion returns no content.", "operationId": "deleteComplianceRequirement", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "requirementId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance requirement.", "example": 101 }, "required": true, "description": "The numeric id of the compliance requirement." } ], "responses": { "204": { "description": "Requirement deleted successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "anyOf": [ { "type": "object", "properties": {}, "additionalProperties": false }, { "type": "null" } ] } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Requirement not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/requirements/{requirementId}/status": { "patch": { "summary": "Update a requirement status", "description": "Updates the assessment status of a compliance requirement for your Qualio instance. The status reflects the current compliance posture for the requirement: not_started (assessment has not begun), in_progress (assessment is underway), met (the requirement is satisfied), attention_required (the requirement needs attention), or not_applicable (the requirement does not apply â a justification is required). A justification must be provided when setting the status to not_applicable.", "operationId": "updateComplianceRequirementStatus", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "requirementId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance requirement.", "example": 101 }, "required": true, "description": "The numeric id of the compliance requirement." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "status": { "type": "string", "enum": [ "not_started", "in_progress", "met", "attention_required", "not_applicable" ], "description": "The new assessment status for the requirement. not_started: assessment has not begun. in_progress: assessment is underway. met: the requirement is satisfied. attention_required: the requirement needs attention. not_applicable: the requirement does not apply â justification is required.", "example": "met" }, "justification": { "description": "Required when status is not_applicable. Explains why the requirement does not apply to this instance.", "example": "Exempt under clause 1.2", "type": "string" } }, "required": [ "status" ], "description": "The new status to apply to the requirement.", "example": { "status": "met" }, "ref": "updateComplianceRequirementStatusRequest" } } } }, "responses": { "200": { "description": "Requirement status updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "requirement_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the requirement whose status was updated.", "example": 101 }, "status": { "type": "string", "enum": [ "not_started", "in_progress", "met", "attention_required", "not_applicable" ], "description": "The current assessment status of the requirement.", "example": "met" }, "justification": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The justification provided when status is not_applicable. null for all other statuses.", "example": null } }, "required": [ "requirement_id", "status", "justification" ], "additionalProperties": false, "description": "The updated requirement status.", "example": { "requirement_id": 101, "status": "met", "justification": null }, "ref": "complianceRequirementStatus" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Requirement not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Updates the assessment status of a compliance requirement for your Qualio instance. The status reflects the current compliance posture for the requirement: not_started (assessment has not begun), in_progress (assessment is underway), met (the requirement is satisfied), attention_required (the requirement needs attention), or not_applicable (the requirement does not apply â a justification is required). A justification must be provided when setting the status to not_applicable.", "operationId": "updateComplianceRequirementStatusOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "requirementId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance requirement.", "example": 101 }, "required": true, "description": "The numeric id of the compliance requirement." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/compliance/controls": { "get": { "summary": "List controls", "description": "Lists the compliance controls in your Qualio instance. A control is a measure your organisation implements to satisfy one or more compliance requirements. Controls are either Qualio-managed (built-in, with a QMC- code prefix) or created by your organisation (with a C- code prefix). Each control carries an implementation status: ready (implemented and effective), not_ready (in progress), not_applicable (does not apply to your instance), or not_started (work has not begun). Use the framework_id parameter to return only controls linked to requirements of a specific framework, and the status parameter to return only controls in a particular state. Omit either parameter to apply no filter on that dimension. Results are ordered by control id. Use offset and limit to page through large sets; the total field in the response reports the full count of matching controls before pagination is applied.", "operationId": "listComplianceControls", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to controls linked to requirements of this framework id. Omit to return controls across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to controls linked to requirements of this framework id. Omit to return controls across all frameworks." }, { "in": "query", "name": "status", "schema": { "description": "Filter results to only controls with this status. Accepted values: ready, not_ready, not_applicable, not_started. Omit to return controls in any state.", "example": "ready", "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, "description": "Filter results to only controls with this status. Accepted values: ready, not_ready, not_applicable, not_started. Omit to return controls in any state." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Successful retrieval of compliance controls.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the control.", "example": 1 }, "code": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The human-readable control code. Qualio-managed controls are prefixed with QMC (for example QMC-1); controls created by your organisation are prefixed with C (for example C-15). null when the control has no assigned code.", "example": "QMC-1" }, "name": { "type": "string", "description": "The display name of the control.", "example": "Access Control Policy" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the control.", "example": "Restricts system access to authorised users." }, "category": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional category used to group related controls.", "example": "Information Security" }, "status": { "anyOf": [ { "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, { "type": "null" } ], "description": "The current implementation status of the control. ready: the control is implemented and effective. not_ready: the control is in progress. not_applicable: the control does not apply to this instance. not_started: work on the control has not begun. null when no status has been determined.", "example": "ready" } }, "required": [ "id", "code", "name", "description", "category", "status" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A paginated list of compliance controls.", "example": { "total": 2, "items": [ { "id": 1, "code": "QMC-1", "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security", "status": "ready" }, { "id": 2, "code": "C-15", "name": "Data Backup", "description": null, "category": null, "status": "not_started" } ] }, "ref": "complianceControlListResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the compliance controls in your Qualio instance. A control is a measure your organisation implements to satisfy one or more compliance requirements. Controls are either Qualio-managed (built-in, with a QMC- code prefix) or created by your organisation (with a C- code prefix). Each control carries an implementation status: ready (implemented and effective), not_ready (in progress), not_applicable (does not apply to your instance), or not_started (work has not begun). Use the framework_id parameter to return only controls linked to requirements of a specific framework, and the status parameter to return only controls in a particular state. Omit either parameter to apply no filter on that dimension. Results are ordered by control id. Use offset and limit to page through large sets; the total field in the response reports the full count of matching controls before pagination is applied.", "operationId": "listComplianceControlsOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to controls linked to requirements of this framework id. Omit to return controls across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to controls linked to requirements of this framework id. Omit to return controls across all frameworks." }, { "in": "query", "name": "status", "schema": { "description": "Filter results to only controls with this status. Accepted values: ready, not_ready, not_applicable, not_started. Omit to return controls in any state.", "example": "ready", "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, "description": "Filter results to only controls with this status. Accepted values: ready, not_ready, not_applicable, not_started. Omit to return controls in any state." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a control", "description": "Creates a new compliance control in your Qualio instance. A control is a measure your organisation implements to satisfy one or more compliance requirements. Provide a name and, optionally, a description and category. The control is created with a generated C- code and starts in the not_started status; use the other Compliance Intelligence endpoints to link it to requirements and track its implementation.", "operationId": "createComplianceControl", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "name": { "type": "string", "minLength": 1, "description": "The display name of the new control.", "example": "Access Control Policy" }, "description": { "description": "An optional human-readable description of the control.", "example": "Restricts system access to authorised users.", "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "category": { "description": "An optional category used to group related controls.", "example": "Information Security", "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "name" ], "description": "The control to create.", "example": { "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security" }, "ref": "createComplianceControlRequest" } } } }, "responses": { "201": { "description": "Control created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the control.", "example": 1 }, "code": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The human-readable control code. Qualio-managed controls are prefixed with QMC (for example QMC-1); controls created by your organisation are prefixed with C (for example C-15). null when the control has no assigned code.", "example": "QMC-1" }, "name": { "type": "string", "description": "The display name of the control.", "example": "Access Control Policy" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the control.", "example": "Restricts system access to authorised users." }, "category": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional category used to group related controls.", "example": "Information Security" }, "status": { "anyOf": [ { "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, { "type": "null" } ], "description": "The current implementation status of the control. ready: the control is implemented and effective. not_ready: the control is in progress. not_applicable: the control does not apply to this instance. not_started: work on the control has not begun. null when no status has been determined.", "example": "ready" } }, "required": [ "id", "code", "name", "description", "category", "status" ], "additionalProperties": false, "description": "The newly created control.", "example": { "id": 15, "code": "C-15", "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security", "status": "not_started" }, "ref": "createdComplianceControl" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/controls/{controlId}": { "get": { "summary": "Get a control", "description": "Retrieves a single compliance control in your Qualio instance, including the evidence and definitions linked to it. A control is a measure your organisation implements to satisfy one or more compliance requirements. The definitions array holds evidence documenting how the control is designed; the evidence array holds evidence demonstrating that the control is operating. Each control carries an implementation status: ready (implemented and effective), not_ready (in progress), not_applicable (does not apply to your instance), or not_started (work has not begun).", "operationId": "getComplianceControl", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "controlId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance control.", "example": 1 }, "required": true, "description": "The numeric id of the compliance control." } ], "responses": { "200": { "description": "Successful retrieval of the compliance control.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the control.", "example": 1 }, "code": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The human-readable control code. Qualio-managed controls are prefixed with QMC (for example QMC-1); controls created by your organisation are prefixed with C (for example C-15). null when the control has no assigned code.", "example": "QMC-1" }, "name": { "type": "string", "description": "The display name of the control.", "example": "Access Control Policy" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the control.", "example": "Restricts system access to authorised users." }, "category": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional category used to group related controls.", "example": "Information Security" }, "status": { "anyOf": [ { "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, { "type": "null" } ], "description": "The current implementation status of the control. ready: the control is implemented and effective. not_ready: the control is in progress. not_applicable: the control does not apply to this instance. not_started: work on the control has not begun. null when no status has been determined.", "example": "ready" }, "guidelines": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "Optional guidance describing how to implement and satisfy the control.", "example": "Apply the principle of least privilege when granting access." }, "evidence": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the evidence item.", "example": 100 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this evidence belongs to.", "example": 1 }, "evidence_type": { "type": "string", "enum": [ "definition", "execution", "execution_only" ], "description": "The kind of evidence. definition: documents how the control is designed. execution and execution_only: demonstrate that the control is operating.", "example": "execution" }, "source": { "type": "string", "enum": [ "qualio", "external", "text_input" ], "description": "Where the evidence originates. qualio: a linked Qualio document. external: an externally uploaded file. text_input: free text entered directly.", "example": "qualio" }, "link": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A link to the underlying evidence, when applicable. null for free-text evidence.", "example": "https://app.qualio.com/documents/1" }, "title": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The title of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "content": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The free-text content of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "created_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ], "description": "The time the evidence was created, as an ISO 8601 timestamp. null when unknown.", "example": "2026-01-01T12:00:00Z" } }, "required": [ "id", "control_id", "evidence_type", "source", "link", "title", "content", "created_at" ], "additionalProperties": false }, "description": "Execution evidence demonstrating that the control is operating." }, "definitions": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the evidence item.", "example": 100 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this evidence belongs to.", "example": 1 }, "evidence_type": { "type": "string", "enum": [ "definition", "execution", "execution_only" ], "description": "The kind of evidence. definition: documents how the control is designed. execution and execution_only: demonstrate that the control is operating.", "example": "execution" }, "source": { "type": "string", "enum": [ "qualio", "external", "text_input" ], "description": "Where the evidence originates. qualio: a linked Qualio document. external: an externally uploaded file. text_input: free text entered directly.", "example": "qualio" }, "link": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A link to the underlying evidence, when applicable. null for free-text evidence.", "example": "https://app.qualio.com/documents/1" }, "title": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The title of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "content": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The free-text content of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "created_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ], "description": "The time the evidence was created, as an ISO 8601 timestamp. null when unknown.", "example": "2026-01-01T12:00:00Z" } }, "required": [ "id", "control_id", "evidence_type", "source", "link", "title", "content", "created_at" ], "additionalProperties": false }, "description": "Definition evidence documenting how the control is designed." } }, "required": [ "id", "code", "name", "description", "category", "status", "guidelines", "evidence", "definitions" ], "additionalProperties": false, "description": "The compliance control, including its evidence and definitions.", "example": { "id": 1, "code": "QMC-1", "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security", "status": "ready", "guidelines": "Apply the principle of least privilege when granting access.", "evidence": [ { "id": 200, "control_id": 1, "evidence_type": "execution", "source": "qualio", "link": "https://app.qualio.com/documents/1", "title": null, "content": null, "created_at": "2026-01-01T12:00:00Z" } ], "definitions": [ { "id": 100, "control_id": 1, "evidence_type": "definition", "source": "text_input", "link": null, "title": "Access Control Policy", "content": "Documents the organisation's access control policy.", "created_at": "2026-01-01T12:00:00Z" } ] }, "ref": "complianceControlDetail" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Control not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single compliance control in your Qualio instance, including the evidence and definitions linked to it. A control is a measure your organisation implements to satisfy one or more compliance requirements. The definitions array holds evidence documenting how the control is designed; the evidence array holds evidence demonstrating that the control is operating. Each control carries an implementation status: ready (implemented and effective), not_ready (in progress), not_applicable (does not apply to your instance), or not_started (work has not begun).", "operationId": "getComplianceControlOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "controlId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance control.", "example": 1 }, "required": true, "description": "The numeric id of the compliance control." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "put": { "summary": "Update a control", "description": "Updates a compliance control in your Qualio instance. This is a partial update: include only the fields you want to change, and omit the rest. Pass null for description or category to clear them. Use the status field to update the control's implementation status (a justification is required when setting it to not_applicable). Use requirement_ids to replace the set of requirements the control is mapped to; pass an empty array to clear the mappings, or omit it to leave them as they are.", "operationId": "updateComplianceControl", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "controlId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance control.", "example": 1 }, "required": true, "description": "The numeric id of the compliance control." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "name": { "description": "New display name for the control. Omit to leave unchanged.", "example": "Access Control Policy", "type": "string", "minLength": 1 }, "description": { "description": "New description for the control. Omit to leave unchanged. Pass null to clear an existing description.", "example": "Restricts system access to authorised users.", "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "category": { "description": "New category for the control. Omit to leave unchanged. Pass null to clear an existing category.", "example": "Information Security", "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "status": { "description": "New implementation status for the control. Omit to leave unchanged. A justification is required when setting the status to not_applicable.", "example": "ready", "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, "justification": { "description": "Required when status is not_applicable. Explains why the control does not apply to this instance.", "example": "Not applicable to this product line.", "type": "string" }, "requirement_ids": { "description": "Replaces the control's mapped requirements with this set of requirement ids. Omit to leave the existing mappings unchanged; pass an empty array to clear them.", "example": [ 101, 102 ], "type": "array", "items": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 } } }, "description": "Fields to update on the control.", "example": { "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security", "status": "ready", "requirement_ids": [ 101, 102 ] }, "ref": "updateComplianceControlRequest" } } } }, "responses": { "200": { "description": "Control updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the control.", "example": 1 }, "code": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The human-readable control code. Qualio-managed controls are prefixed with QMC (for example QMC-1); controls created by your organisation are prefixed with C (for example C-15). null when the control has no assigned code.", "example": "QMC-1" }, "name": { "type": "string", "description": "The display name of the control.", "example": "Access Control Policy" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional human-readable description of the control.", "example": "Restricts system access to authorised users." }, "category": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "An optional category used to group related controls.", "example": "Information Security" }, "status": { "anyOf": [ { "type": "string", "enum": [ "ready", "not_ready", "not_applicable", "not_started" ] }, { "type": "null" } ], "description": "The current implementation status of the control. ready: the control is implemented and effective. not_ready: the control is in progress. not_applicable: the control does not apply to this instance. not_started: work on the control has not begun. null when no status has been determined.", "example": "ready" } }, "required": [ "id", "code", "name", "description", "category", "status" ], "additionalProperties": false, "description": "The updated control.", "example": { "id": 15, "code": "C-15", "name": "Access Control Policy", "description": "Restricts system access to authorised users.", "category": "Information Security", "status": "ready" }, "ref": "updatedComplianceControl" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Control not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/evidence": { "get": { "summary": "List evidence", "description": "Lists the compliance evidence in your Qualio instance. Evidence is the documentation and records that demonstrate a control is defined and operating â for example linked Qualio documents, externally uploaded files, or free-text notes. Use the control_id parameter to return only the evidence linked to a specific control; omit it to return evidence across all controls. Results are ordered by evidence id. Use offset and limit to page through large sets; the total field in the response reports the full count of matching evidence before pagination is applied.", "operationId": "listComplianceEvidence", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "control_id", "schema": { "description": "Filter results to evidence linked to this control id. Omit to return evidence across all controls.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to evidence linked to this control id. Omit to return evidence across all controls." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Successful retrieval of compliance evidence.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the evidence item.", "example": 100 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this evidence belongs to.", "example": 1 }, "evidence_type": { "type": "string", "enum": [ "definition", "execution", "execution_only" ], "description": "The kind of evidence. definition: documents how the control is designed. execution and execution_only: demonstrate that the control is operating.", "example": "execution" }, "source": { "type": "string", "enum": [ "qualio", "external", "text_input" ], "description": "Where the evidence originates. qualio: a linked Qualio document. external: an externally uploaded file. text_input: free text entered directly.", "example": "qualio" }, "link": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A link to the underlying evidence, when applicable. null for free-text evidence.", "example": "https://app.qualio.com/documents/1" }, "title": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The title of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "content": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "The free-text content of the evidence, when applicable. Populated for free-text evidence; null otherwise.", "example": null }, "created_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ], "description": "The time the evidence was created, as an ISO 8601 timestamp. null when unknown.", "example": "2026-01-01T12:00:00Z" } }, "required": [ "id", "control_id", "evidence_type", "source", "link", "title", "content", "created_at" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A paginated list of compliance evidence.", "example": { "total": 2, "items": [ { "id": 200, "control_id": 1, "evidence_type": "execution", "source": "qualio", "link": "https://app.qualio.com/documents/1", "title": null, "content": null, "created_at": "2026-01-01T12:00:00Z" }, { "id": 100, "control_id": 1, "evidence_type": "definition", "source": "text_input", "link": null, "title": "Access Control Policy", "content": "Documents the organisation's access control policy.", "created_at": "2026-01-01T12:00:00Z" } ] }, "ref": "complianceEvidenceListResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the compliance evidence in your Qualio instance. Evidence is the documentation and records that demonstrate a control is defined and operating â for example linked Qualio documents, externally uploaded files, or free-text notes. Use the control_id parameter to return only the evidence linked to a specific control; omit it to return evidence across all controls. Results are ordered by evidence id. Use offset and limit to page through large sets; the total field in the response reports the full count of matching evidence before pagination is applied.", "operationId": "listComplianceEvidenceOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "control_id", "schema": { "description": "Filter results to evidence linked to this control id. Omit to return evidence across all controls.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to evidence linked to this control id. Omit to return evidence across all controls." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/compliance/gaps": { "get": { "summary": "List gaps", "description": "Lists the compliance gaps in your Qualio instance. A gap is a shortfall identified against a control â for example a control that is missing objective evidence or whose evidence does not satisfy its requirements. Use the framework_id parameter to return only gaps on controls linked to a specific framework, the status parameter to return only gaps in a particular state (open, resolved, dismissed), and the severity parameter to return only gaps of a given severity (high, medium, low). Omit a parameter to apply no filter on that dimension. Use offset and limit to page through large sets; the total field in the response reports the full count of matching gaps before pagination is applied.", "operationId": "listComplianceGaps", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to gaps on controls linked to this framework id. Omit to return gaps across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to gaps on controls linked to this framework id. Omit to return gaps across all frameworks." }, { "in": "query", "name": "status", "schema": { "description": "Filter results to only gaps with this status. Accepted values: open, resolved, dismissed. Omit to return gaps in any state.", "example": "open", "type": "string", "enum": [ "open", "resolved", "dismissed" ] }, "description": "Filter results to only gaps with this status. Accepted values: open, resolved, dismissed. Omit to return gaps in any state." }, { "in": "query", "name": "severity", "schema": { "description": "Filter results to only gaps with this severity. Accepted values: high, medium, low. Omit to return gaps of any severity.", "example": "high", "type": "string", "enum": [ "high", "medium", "low" ] }, "description": "Filter results to only gaps with this severity. Accepted values: high, medium, low. Omit to return gaps of any severity." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Successful retrieval of compliance gaps.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the gap.", "example": 500 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this gap was raised against.", "example": 1 }, "summary": { "type": "string", "description": "A short summary of the gap.", "example": "Missing objective evidence" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A fuller description of the gap. null when none is available.", "example": "The control has no objective evidence demonstrating it is operating." }, "recommendation": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A recommended action to resolve the gap. null when none is available.", "example": "Attach objective evidence to the control." }, "severity": { "type": "string", "enum": [ "high", "medium", "low" ], "description": "The severity of the gap. high: significant compliance risk. medium: moderate risk. low: minor risk.", "example": "high" }, "status": { "type": "string", "enum": [ "open", "resolved", "dismissed" ], "description": "The current status of the gap. open: the gap is outstanding. resolved: the gap has been addressed. dismissed: the gap was reviewed and set aside.", "example": "open" }, "created_at": { "type": "string", "format": "date-time", "description": "The time the gap was created, as an ISO 8601 timestamp.", "example": "2026-01-01T12:00:00Z" }, "updated_at": { "type": "string", "format": "date-time", "description": "The time the gap was last updated, as an ISO 8601 timestamp.", "example": "2026-01-02T12:00:00Z" } }, "required": [ "id", "control_id", "summary", "description", "recommendation", "severity", "status", "created_at", "updated_at" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A paginated list of compliance gaps.", "example": { "total": 1, "items": [ { "id": 500, "control_id": 1, "summary": "Missing objective evidence", "description": "The control has no objective evidence demonstrating it is operating.", "recommendation": "Attach objective evidence to the control.", "severity": "high", "status": "open", "created_at": "2026-01-01T12:00:00Z", "updated_at": "2026-01-02T12:00:00Z" } ] }, "ref": "complianceGapListResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the compliance gaps in your Qualio instance. A gap is a shortfall identified against a control â for example a control that is missing objective evidence or whose evidence does not satisfy its requirements. Use the framework_id parameter to return only gaps on controls linked to a specific framework, the status parameter to return only gaps in a particular state (open, resolved, dismissed), and the severity parameter to return only gaps of a given severity (high, medium, low). Omit a parameter to apply no filter on that dimension. Use offset and limit to page through large sets; the total field in the response reports the full count of matching gaps before pagination is applied.", "operationId": "listComplianceGapsOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "framework_id", "schema": { "description": "Filter results to gaps on controls linked to this framework id. Omit to return gaps across all frameworks.", "example": 1, "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, "description": "Filter results to gaps on controls linked to this framework id. Omit to return gaps across all frameworks." }, { "in": "query", "name": "status", "schema": { "description": "Filter results to only gaps with this status. Accepted values: open, resolved, dismissed. Omit to return gaps in any state.", "example": "open", "type": "string", "enum": [ "open", "resolved", "dismissed" ] }, "description": "Filter results to only gaps with this status. Accepted values: open, resolved, dismissed. Omit to return gaps in any state." }, { "in": "query", "name": "severity", "schema": { "description": "Filter results to only gaps with this severity. Accepted values: high, medium, low. Omit to return gaps of any severity.", "example": "high", "type": "string", "enum": [ "high", "medium", "low" ] }, "description": "Filter results to only gaps with this severity. Accepted values: high, medium, low. Omit to return gaps of any severity." }, { "in": "query", "name": "offset", "schema": { "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0.", "example": 0, "type": "integer", "minimum": 0, "maximum": 9007199254740991 }, "description": "Number of items to skip before collecting results. Use with limit to page through results. Defaults to 0." }, { "in": "query", "name": "limit", "schema": { "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25.", "example": 25, "type": "integer", "minimum": 1, "maximum": 100 }, "description": "Maximum number of items to return in a single response. Minimum 1, maximum 100. Defaults to 25." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a gap", "description": "Creates a new compliance gap in your Qualio instance. A gap records a shortfall against a control â for example missing objective evidence or evidence that does not satisfy the control's requirements. Provide the control, a summary, description, recommendation, severity, and gap type. Optionally link the gap to one or more requirements by including the requirements array. The gap is created in the open status.", "operationId": "createComplianceGap", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this gap is raised against.", "example": 1 }, "summary": { "type": "string", "minLength": 1, "description": "A short summary of the gap.", "example": "Missing objective evidence" }, "description": { "type": "string", "minLength": 1, "description": "A fuller description of the gap.", "example": "The control has no objective evidence demonstrating it is operating." }, "recommendation": { "type": "string", "minLength": 1, "description": "A recommended action to resolve the gap.", "example": "Attach objective evidence to the control." }, "severity": { "type": "string", "enum": [ "high", "medium", "low" ], "description": "The severity of the gap. high: significant compliance risk. medium: moderate risk. low: minor risk.", "example": "high" }, "type": { "type": "string", "enum": [ "Missing process definition", "Process definition gaps", "No evidence provided", "Insufficient evidence", "Evidence not aligned with process", "Evidence not current", "Process not followed" ], "description": "The type of gap being raised.", "example": "No evidence provided" }, "requirements": { "description": "Requirements to link to this gap. Omit or pass an empty array to create an unlinked gap.", "example": [ { "requirement_id": 101, "framework_id": 1 } ], "type": "array", "items": { "type": "object", "properties": { "requirement_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the requirement to link to this gap.", "example": 101 }, "framework_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the framework the requirement belongs to.", "example": 1 } }, "required": [ "requirement_id", "framework_id" ] } } }, "required": [ "control_id", "summary", "description", "recommendation", "severity", "type" ], "description": "The gap to create.", "example": { "control_id": 1, "summary": "Missing objective evidence", "description": "The control has no objective evidence demonstrating it is operating.", "recommendation": "Attach objective evidence to the control.", "severity": "high", "type": "No evidence provided", "requirements": [ { "requirement_id": 101, "framework_id": 1 } ] }, "ref": "createComplianceGapRequest" } } } }, "responses": { "201": { "description": "Gap created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the gap.", "example": 500 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this gap was raised against.", "example": 1 }, "summary": { "type": "string", "description": "A short summary of the gap.", "example": "Missing objective evidence" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A fuller description of the gap. null when none is available.", "example": "The control has no objective evidence demonstrating it is operating." }, "recommendation": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A recommended action to resolve the gap. null when none is available.", "example": "Attach objective evidence to the control." }, "severity": { "type": "string", "enum": [ "high", "medium", "low" ], "description": "The severity of the gap. high: significant compliance risk. medium: moderate risk. low: minor risk.", "example": "high" }, "status": { "type": "string", "enum": [ "open", "resolved", "dismissed" ], "description": "The current status of the gap. open: the gap is outstanding. resolved: the gap has been addressed. dismissed: the gap was reviewed and set aside.", "example": "open" }, "created_at": { "type": "string", "format": "date-time", "description": "The time the gap was created, as an ISO 8601 timestamp.", "example": "2026-01-01T12:00:00Z" }, "updated_at": { "type": "string", "format": "date-time", "description": "The time the gap was last updated, as an ISO 8601 timestamp.", "example": "2026-01-02T12:00:00Z" } }, "required": [ "id", "control_id", "summary", "description", "recommendation", "severity", "status", "created_at", "updated_at" ], "additionalProperties": false, "description": "The newly created gap.", "example": { "id": 501, "control_id": 1, "summary": "Missing objective evidence", "description": "The control has no objective evidence demonstrating it is operating.", "recommendation": "Attach objective evidence to the control.", "severity": "high", "status": "open", "created_at": "2026-01-01T12:00:00Z", "updated_at": "2026-01-01T12:00:00Z" }, "ref": "createdComplianceGap" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/compliance/gaps/{gapId}": { "get": { "summary": "Get a gap", "description": "Retrieves a single compliance gap in your Qualio instance. A gap is a shortfall identified against a control â for example a control that is missing objective evidence or whose evidence does not satisfy its requirements. The status field reports whether the gap is open, resolved or dismissed, and severity reports its level (high, medium, low).", "operationId": "getComplianceGap", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "gapId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance gap.", "example": 500 }, "required": true, "description": "The numeric id of the compliance gap." } ], "responses": { "200": { "description": "Successful retrieval of the compliance gap.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the gap.", "example": 500 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this gap was raised against.", "example": 1 }, "summary": { "type": "string", "description": "A short summary of the gap.", "example": "Missing objective evidence" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A fuller description of the gap. null when none is available.", "example": "The control has no objective evidence demonstrating it is operating." }, "recommendation": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A recommended action to resolve the gap. null when none is available.", "example": "Attach objective evidence to the control." }, "severity": { "type": "string", "enum": [ "high", "medium", "low" ], "description": "The severity of the gap. high: significant compliance risk. medium: moderate risk. low: minor risk.", "example": "high" }, "status": { "type": "string", "enum": [ "open", "resolved", "dismissed" ], "description": "The current status of the gap. open: the gap is outstanding. resolved: the gap has been addressed. dismissed: the gap was reviewed and set aside.", "example": "open" }, "created_at": { "type": "string", "format": "date-time", "description": "The time the gap was created, as an ISO 8601 timestamp.", "example": "2026-01-01T12:00:00Z" }, "updated_at": { "type": "string", "format": "date-time", "description": "The time the gap was last updated, as an ISO 8601 timestamp.", "example": "2026-01-02T12:00:00Z" } }, "required": [ "id", "control_id", "summary", "description", "recommendation", "severity", "status", "created_at", "updated_at" ], "additionalProperties": false, "description": "The compliance gap.", "example": { "id": 500, "control_id": 1, "summary": "Missing objective evidence", "description": "The control has no objective evidence demonstrating it is operating.", "recommendation": "Attach objective evidence to the control.", "severity": "high", "status": "open", "created_at": "2026-01-01T12:00:00Z", "updated_at": "2026-01-02T12:00:00Z" }, "ref": "complianceGap" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Gap not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single compliance gap in your Qualio instance. A gap is a shortfall identified against a control â for example a control that is missing objective evidence or whose evidence does not satisfy its requirements. The status field reports whether the gap is open, resolved or dismissed, and severity reports its level (high, medium, low).", "operationId": "getComplianceGapOptions", "tags": [ "Compliance Intelligence" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "gapId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance gap.", "example": 500 }, "required": true, "description": "The numeric id of the compliance gap." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "put": { "summary": "Update a gap", "description": "Updates the status of a compliance gap in your Qualio instance. Accepted status values are open, resolved, and dismissed. A reason is required and will be recorded in the gap's audit trail.", "operationId": "updateComplianceGap", "tags": [ "Compliance Intelligence" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "gapId", "schema": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The numeric id of the compliance gap.", "example": 500 }, "required": true, "description": "The numeric id of the compliance gap." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "status": { "type": "string", "enum": [ "open", "resolved", "dismissed" ], "description": "New status for the gap. Accepted values: open, resolved, dismissed.", "example": "resolved" }, "reason": { "type": "string", "minLength": 1, "description": "Explains why the status is being changed.", "example": "Objective evidence has been attached and verified." } }, "required": [ "status", "reason" ], "description": "Fields to update on the gap.", "example": { "status": "resolved", "reason": "Objective evidence has been attached and verified." }, "ref": "updateComplianceGapRequest" } } } }, "responses": { "200": { "description": "Gap updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The unique numeric identifier of the gap.", "example": 500 }, "control_id": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "The id of the control this gap was raised against.", "example": 1 }, "summary": { "type": "string", "description": "A short summary of the gap.", "example": "Missing objective evidence" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A fuller description of the gap. null when none is available.", "example": "The control has no objective evidence demonstrating it is operating." }, "recommendation": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "description": "A recommended action to resolve the gap. null when none is available.", "example": "Attach objective evidence to the control." }, "severity": { "type": "string", "enum": [ "high", "medium", "low" ], "description": "The severity of the gap. high: significant compliance risk. medium: moderate risk. low: minor risk.", "example": "high" }, "status": { "type": "string", "enum": [ "open", "resolved", "dismissed" ], "description": "The current status of the gap. open: the gap is outstanding. resolved: the gap has been addressed. dismissed: the gap was reviewed and set aside.", "example": "open" }, "created_at": { "type": "string", "format": "date-time", "description": "The time the gap was created, as an ISO 8601 timestamp.", "example": "2026-01-01T12:00:00Z" }, "updated_at": { "type": "string", "format": "date-time", "description": "The time the gap was last updated, as an ISO 8601 timestamp.", "example": "2026-01-02T12:00:00Z" } }, "required": [ "id", "control_id", "summary", "description", "recommendation", "severity", "status", "created_at", "updated_at" ], "additionalProperties": false, "description": "The updated gap.", "example": { "id": 500, "control_id": 1, "summary": "Missing objective evidence", "description": "The control has no objective evidence demonstrating it is operating.", "recommendation": "Attach objective evidence to the control.", "severity": "medium", "status": "resolved", "created_at": "2026-01-01T12:00:00Z", "updated_at": "2026-01-03T12:00:00Z" }, "ref": "updatedComplianceGap" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Gap not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/design-controls/products": { "get": { "summary": "List products", "description": "Lists the design control products in your Qualio instance. Design Controls (also called Product Development) is Qualio's module for medical-device design control and traceability: each product groups the requirements, test cases, and risks that demonstrate it is properly designed, verified, and risk-managed (per FDA / ISO 14971). A product is identified by a UUID; use that id with the requirements, test-case, risk, and test-result endpoints. Returns each product's id, name, and tag ids.", "operationId": "listDesignControlProducts", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful design controls products retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "name": { "type": "string" }, "tag_ids": { "type": "array", "items": { "type": "number" } } }, "required": [ "id", "name", "tag_ids" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A list of design control products", "example": { "items": [ { "id": "123e4567-e89b-12d3-a456-426614174000", "name": "Cardio pump", "tag_ids": [ 12, 21, 31 ] } ], "total": 1 } } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the design control products in your Qualio instance. Design Controls (also called Product Development) is Qualio's module for medical-device design control and traceability: each product groups the requirements, test cases, and risks that demonstrate it is properly designed, verified, and risk-managed (per FDA / ISO 14971). A product is identified by a UUID; use that id with the requirements, test-case, risk, and test-result endpoints. Returns each product's id, name, and tag ids.", "operationId": "listDesignControlProductsOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/design-controls/products/{productId}/test-cases": { "get": { "summary": "List test cases", "description": "Lists the test cases for a design control product, identified by its UUID. A test case documents a verification procedure that proves one or more requirements are satisfied. Each item includes its id, auto-generated code (e.g. TC-1), title, type, change-control status, source, the traceability issues flagged by design-control policy (e.g. a failing or outdated test result), and its latest recorded test result.", "operationId": "listProductTestCases", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Successful design controls test cases retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "code": { "type": "string", "minLength": 1, "maxLength": 255 }, "created_at": { "type": "string", "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" }, "type": { "type": "string", "enum": [ "testCase1", "testCase2", "testCase3" ] }, "changeControlStatus": { "type": "string", "enum": [ "unstaged", "staged", "approved", "not_approved" ] }, "source": { "type": "string", "minLength": 1 }, "source_url": { "type": "string", "format": "uri" }, "issues": { "type": "object", "propertyNames": { "type": "string", "enum": [ "REQUIRES_PARENT", "UNMITIGATED", "REQUIRES_CHILD", "UNTESTED_REQUIREMENT", "FAILING_TEST", "OUTDATED_TESTRESULT" ] }, "additionalProperties": { "type": "boolean" }, "required": [ "REQUIRES_PARENT", "UNMITIGATED", "REQUIRES_CHILD", "UNTESTED_REQUIREMENT", "FAILING_TEST", "OUTDATED_TESTRESULT" ] }, "testResult": { "type": "object", "properties": { "result": { "type": "string", "enum": [ "passed", "failed", "blocked" ] }, "date": { "type": "string", "format": "date-time" }, "comment": { "type": "string", "maxLength": 255 }, "tester": { "type": "string", "minLength": 1, "maxLength": 255 }, "url": { "type": "string" }, "source": { "type": "string" } }, "required": [ "result", "date", "tester" ], "additionalProperties": false }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters.", "type": "string", "maxLength": 150000 } }, "required": [ "id", "title", "code", "created_at", "updated_at", "type", "changeControlStatus", "source", "issues" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A list of design control test cases", "example": { "items": [ { "id": "123e4567-e89b-12d3-a456-426614174000", "title": "Test case 1", "code": "TC-1", "created_at": "2021-01-01T00:00:00.000Z", "updated_at": "2021-01-01T00:00:00.000Z", "type": "testCase1", "changeControlStatus": "unstaged", "source": "Source 1", "testResult": { "result": "passed", "date": "2021-01-01T00:00:00.000Z", "comment": "Test case 1 passed", "tester": "Tester 1", "source": "developer-api" }, "issues": { "REQUIRES_PARENT": false, "UNMITIGATED": false, "REQUIRES_CHILD": false, "UNTESTED_REQUIREMENT": false, "FAILING_TEST": false, "OUTDATED_TESTRESULT": false } } ], "total": 1 }, "ref": "testCase" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the test cases for a design control product, identified by its UUID. A test case documents a verification procedure that proves one or more requirements are satisfied. Each item includes its id, auto-generated code (e.g. TC-1), title, type, change-control status, source, the traceability issues flagged by design-control policy (e.g. a failing or outdated test result), and its latest recorded test result.", "operationId": "listProductTestCasesOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a test case", "description": "Create a test case in a design control product. A test case documents a verification procedure used to confirm that one or more product requirements are satisfied. The type field identifies which test case template slot to use: testCase1, testCase2, and testCase3 map to the first, second, and third configured templates respectively. A code is generated automatically when none is supplied. Use the links or requirements fields to add traceability connections to existing quality items by providing their codes or UUIDs. Type-matching is enforced: testCase1 can only link to req1 requirements, testCase2 to req2, and testCase3 to req3. Mismatched types return 400. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created. Providing an id that already exists in the product returns 409 Conflict.", "operationId": "createProductTestCase", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The title of the item, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters.", "type": "string", "maxLength": 150000 }, "links": { "description": "An array of quality item codes or UUIDs to establish as trace links. You may supply codes (such as REQ-1 or TC-5) or UUIDs. If a supplied value is not found in the product, it is stored as an unresolved link and resolved automatically when the target item is created later. Type-matching rules apply: see the notes on test_cases for requirements and on the type field for test cases.", "type": "array", "items": { "type": "string" } }, "requirements": { "description": "An array of requirement codes or UUIDs to link for traceability coverage. Entries are combined with links and test_cases and processed together. The same type-matching rules apply.", "type": "array", "items": { "type": "string" } }, "type": { "type": "string", "enum": [ "testCase1", "testCase2", "testCase3" ], "description": "The test case template slot to use for this item. Qualio products support up to three test case templates; testCase1, testCase2, and testCase3 correspond to the first, second, and third configured templates. Check your product configuration in Qualio to determine which value to supply. The type also governs which requirements this test case can be linked to: testCase1 can only be linked to req1 requirements, testCase2 to req2, and testCase3 to req3. Attempting to link a test case to a requirement of a different template number returns 400." } }, "required": [ "title", "type" ], "description": "A request body to create a new test case in a design control product. Supply a title and a type to identify the test case template slot to use. An optional id may be provided to assign a specific identifier; when omitted the server generates one automatically. A short code is always auto-generated by the server from the product type configuration counter. Use links and requirements to establish traceability connections to existing quality items by supplying their codes or UUIDs. Supplying an id that already belongs to an existing test case in this product returns 409 Conflict.", "example": { "title": "Verify pump pressure under maximum load", "type": "testCase1", "description": "Apply maximum rated load to the pump for 30 minutes and confirm that pressure remains within the specified safety range throughout the test.", "links": [ "REQ-1", "REQ-5" ] }, "ref": "createTestCase" } } } }, "responses": { "201": { "description": "Test case created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "enum": [ "testCase1", "testCase2", "testCase3" ], "description": "The quality item category. Can be testCase1, testCase2, or testCase3" } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type" ], "additionalProperties": false, "description": "The test case that was created.", "example": { "id": "9d8c7b6a-5e4f-4321-8c0b-7a6d5e4f3c2b", "title": "Verify pump pressure under maximum load", "code": "TC-42", "type": "testCase1", "source": "jira", "source_url": "https://your-company.atlassian.net/browse/TC-42", "created_at": "2025-05-21T10:00:00.000Z", "updated_at": "2025-05-21T10:00:00.000Z", "issues": {} }, "ref": "createdTestCase" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "409": { "description": "A test case with the provided id already exists in this product.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/testCaseConflictResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/design-controls/products/{productId}/requirements": { "get": { "summary": "List requirements", "description": "Lists the requirements for a design control product, identified by its UUID. A requirement describes a condition or capability the product must satisfy, organised into levels (req1âreq4). Each item includes its id, auto-generated code (e.g. REQ-1), title, type, change-control status, source, and the traceability issues flagged by design-control policy (e.g. a requirement with no test case, or a child requirement missing its parent).", "operationId": "listProductRequirements", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Successful design controls requirements retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "code": { "type": "string", "minLength": 1, "maxLength": 255 }, "created_at": { "type": "string", "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" }, "type": { "type": "string", "enum": [ "req1", "req2", "req3", "req4" ] }, "changeControlStatus": { "type": "string", "enum": [ "unstaged", "staged", "approved", "not_approved" ] }, "source": { "type": "string", "minLength": 1 }, "source_url": { "type": "string", "format": "uri" }, "issues": { "type": "object", "propertyNames": { "type": "string", "enum": [ "REQUIRES_PARENT", "UNMITIGATED", "REQUIRES_CHILD", "UNTESTED_REQUIREMENT", "FAILING_TEST", "OUTDATED_TESTRESULT" ] }, "additionalProperties": { "type": "boolean" }, "required": [ "REQUIRES_PARENT", "UNMITIGATED", "REQUIRES_CHILD", "UNTESTED_REQUIREMENT", "FAILING_TEST", "OUTDATED_TESTRESULT" ] }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters.", "type": "string", "maxLength": 150000 } }, "required": [ "id", "title", "code", "created_at", "updated_at", "type", "changeControlStatus", "source", "issues" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A list of design control requirements", "example": { "items": [ { "id": "123e4567-e89b-12d3-a456-426614174000", "title": "Requirement 1", "code": "RC-1", "created_at": "2021-01-01T00:00:00.000Z", "updated_at": "2021-01-01T00:00:00.000Z", "type": "req1", "changeControlStatus": "approved", "source": "jira", "source_url": "https://test.atlassian.com/jira/RC-1", "issues": { "REQUIRES_PARENT": false, "UNMITIGATED": false, "REQUIRES_CHILD": false, "UNTESTED_REQUIREMENT": false, "FAILING_TEST": false, "OUTDATED_TESTRESULT": false } } ], "total": 1 }, "ref": "designControlQualityItem" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the requirements for a design control product, identified by its UUID. A requirement describes a condition or capability the product must satisfy, organised into levels (req1âreq4). Each item includes its id, auto-generated code (e.g. REQ-1), title, type, change-control status, source, and the traceability issues flagged by design-control policy (e.g. a requirement with no test case, or a child requirement missing its parent).", "operationId": "listProductRequirementsOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a requirement", "description": "Create a requirement in a design control product. A requirement describes a condition or capability the product must satisfy. The type field identifies which requirement template slot to use: req1, req2, req3, and req4 map to the first, second, third, and fourth configured templates respectively. A code is generated automatically when none is supplied. Use the links, requirements, or test_cases fields to add traceability connections to existing quality items by providing their codes or UUIDs. Type-matching is enforced: req1 can only link to testCase1 items, req2 to testCase2, and req3 to testCase3. req4 requirements cannot link to any test case type. Mismatched types return 400. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created. Providing an id that already exists in the product returns 409 Conflict.", "operationId": "createProductRequirement", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The title of the item, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters.", "type": "string", "maxLength": 150000 }, "links": { "description": "An array of quality item codes or UUIDs to establish as trace links. You may supply codes (such as REQ-1 or TC-5) or UUIDs. If a supplied value is not found in the product, it is stored as an unresolved link and resolved automatically when the target item is created later. Type-matching rules apply: see the notes on test_cases for requirements and on the type field for test cases.", "type": "array", "items": { "type": "string" } }, "requirements": { "description": "An array of requirement codes or UUIDs to link for traceability coverage. Entries are combined with links and test_cases and processed together. The same type-matching rules apply.", "type": "array", "items": { "type": "string" } }, "type": { "type": "string", "enum": [ "req1", "req2", "req3", "req4" ], "description": "The requirement template slot to use for this item. Qualio products support up to four requirement templates; req1, req2, req3, and req4 correspond to the first, second, third, and fourth configured templates. Check your product configuration in Qualio to determine which value to supply. The type also governs which test cases this requirement can be linked to: req1 can only be linked to testCase1 items, req2 to testCase2, and req3 to testCase3. req4 requirements cannot be directly linked to any test case type. Attempting to link incompatible types returns 400." }, "test_cases": { "description": "An array of test case codes or UUIDs to link to this requirement, establishing coverage traceability. The test case template number must match the requirement template number: a req1 requirement can only link to testCase1 items, req2 to testCase2, and req3 to testCase3. Supplying a test case whose type does not match returns 400. If a supplied code or UUID is not found in the product, it is stored as an unresolved link and resolved automatically when the target item is created. Entries are combined with links and requirements and processed together.", "type": "array", "items": { "type": "string" } } }, "required": [ "title", "type" ], "description": "A request body to create a new requirement in a design control product. Supply a title and a type to identify the requirement template slot to use. An optional id may be provided to assign a specific identifier; when omitted the server generates one automatically. A short code is always auto-generated by the server from the product type configuration counter. Use links, requirements, and test_cases to establish traceability connections to existing quality items by supplying their codes or UUIDs. Supplying an id that already belongs to an existing requirement in this product returns 409 Conflict.", "example": { "title": "Pump pressure must remain within safe operating range", "type": "req1", "description": "The pump shall maintain output pressure between 0.5 bar and 4.0 bar under all rated operating conditions.", "test_cases": [ "TC-1", "TC-3" ] }, "ref": "createRequirement" } } } }, "responses": { "201": { "description": "Requirement created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "enum": [ "req1", "req2", "req3", "req4" ], "description": "The quality item category. Can be req1, req2, req3 or req4." } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type" ], "additionalProperties": false, "description": "The requirement that was created.", "example": { "id": "3f8b2c14-7d6e-4a9f-bc21-5e0d9a1f23b4", "title": "Pump pressure must remain within safe operating range", "code": "REQ-42", "type": "req1", "source": "jira", "source_url": "https://your-company.atlassian.net/browse/REQ-42", "created_at": "2025-05-21T10:00:00.000Z", "updated_at": "2025-05-21T10:00:00.000Z", "issues": {} }, "ref": "createdRequirement" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "409": { "description": "A requirement with the provided id already exists in this product.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/requirementConflictResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/design-controls/products/{productId}/test-results": { "post": { "summary": "Record a test result", "description": "Records a test result against a test case in a design control product. A test result captures the outcome of executing a test case â `passed`, `failed`, or `blocked` â along with the execution date, who ran it, optional notes, a link to external evidence, and attachments. The latest result is reflected on the test case and feeds the product's verification/traceability status. Identify the target test case by its id or code in the request body.", "operationId": "createProductTestResult", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "result": { "type": "string", "enum": [ "passed", "failed", "blocked" ] }, "date": { "type": "string", "format": "date-time" }, "comment": { "type": "string", "maxLength": 255 }, "tester": { "type": "string", "minLength": 1, "maxLength": 255 }, "test_case_id": { "type": "string", "format": "uuid" } }, "required": [ "result", "tester", "test_case_id" ], "description": "A test result to add to a test case", "example": { "test_case_id": "123e4567-e89b-12d3-a456-426614174000", "result": "passed", "date": "2021-01-01T00:00:00.000Z", "comment": "Test case 1 passed", "tester": "Tester 1" }, "ref": "createTestResult" } } } }, "responses": { "200": { "description": "Successful design controls test result creation", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "result": { "type": "string", "enum": [ "passed", "failed", "blocked" ] }, "date": { "type": "string", "format": "date-time" }, "comment": { "type": "string", "maxLength": 255 }, "tester": { "type": "string", "minLength": 1, "maxLength": 255 }, "url": { "type": "string" }, "source": { "type": "string" } }, "required": [ "result", "date", "tester" ], "additionalProperties": false, "description": "A test result", "example": { "result": "passed", "date": "2021-01-01T00:00:00.000Z", "comment": "Test case 1 passed", "tester": "Tester 1", "source": "developer-api" }, "ref": "testResult" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Records a test result against a test case in a design control product. A test result captures the outcome of executing a test case â `passed`, `failed`, or `blocked` â along with the execution date, who ran it, optional notes, a link to external evidence, and attachments. The latest result is reflected on the test case and feeds the product's verification/traceability status. Identify the target test case by its id or code in the request body.", "operationId": "createProductTestResultOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/design-controls/products/{productId}/test-cases/{testCaseId}": { "put": { "summary": "Update a test case", "description": "Update an existing test case in a design control product. The request body replaces the mutable fields of the test case: title, type, and description. The type field must match the existing type of the test case; changing the type across categories is not supported and returns 400. The links and requirements fields define the complete set of desired trace links and replace all existing trace links on the test case. Omit both links and requirements to leave existing trace links unchanged. The id, code, and source of the test case are immutable and cannot be changed by this endpoint.", "operationId": "updateProductTestCase", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "testCaseId", "schema": { "$ref": "#/components/schemas/testCaseId" }, "required": true, "description": "The unique identifier of the test case to update. This is the id returned when the test case was created." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The updated title of the item, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters. Omit this field to leave the existing description unchanged.", "type": "string", "maxLength": 150000 }, "links": { "description": "The complete desired set of trace link codes or UUIDs for this item. Both requirement codes and test case codes are accepted, for example REQ-1 or TC-5. This field replaces all existing trace links. Type-matching rules apply: requirement and test case template numbers must match.", "type": "array", "items": { "type": "string" } }, "requirements": { "description": "An array of requirement codes or UUIDs to link for traceability coverage. Entries are combined with links and replace all existing trace links together. The same type-matching rules apply.", "type": "array", "items": { "type": "string" } }, "type": { "type": "string", "enum": [ "testCase1", "testCase2", "testCase3" ], "description": "The test case template slot for this item. Must match the existing type of the test case; changing the type across categories is not supported and returns 400. Use testCase1, testCase2, or testCase3 to match the first, second, or third configured template in the product. Type-matching is also enforced on links: testCase1 can only link to req1 requirements, testCase2 to req2, and testCase3 to req3." } }, "required": [ "title", "type" ], "description": "A request body to update an existing test case in a design control product. The type field must match the existing type of the test case; attempting to change the type across categories returns 400. The links and requirements fields replace all existing trace links on the test case when provided. Omitting both leaves existing trace links unchanged.", "example": { "title": "Verify pump pressure under maximum and minimum load", "type": "testCase1", "description": "Apply maximum rated load to the pump for 30 minutes, then minimum load for 15 minutes, and confirm that pressure remains within the specified safety range throughout.", "links": [ "REQ-1", "REQ-5", "REQ-9" ] }, "ref": "updateTestCase" } } } }, "responses": { "200": { "description": "Test case updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "enum": [ "testCase1", "testCase2", "testCase3" ], "description": "The quality item category. Can be testCase1, testCase2, or testCase3" } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type" ], "additionalProperties": false, "description": "The test case after the update was applied.", "example": { "id": "9d8c7b6a-5e4f-4321-8c0b-7a6d5e4f3c2b", "title": "Verify pump pressure under maximum load", "code": "TC-42", "type": "testCase1", "source": "jira", "source_url": "https://your-company.atlassian.net/browse/TC-42", "created_at": "2025-05-21T10:00:00.000Z", "updated_at": "2025-05-21T10:00:00.000Z", "issues": {} }, "ref": "updatedTestCase" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product or test case not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Update an existing test case in a design control product. The request body replaces the mutable fields of the test case: title, type, and description. The type field must match the existing type of the test case; changing the type across categories is not supported and returns 400. The links and requirements fields define the complete set of desired trace links and replace all existing trace links on the test case. Omit both links and requirements to leave existing trace links unchanged. The id, code, and source of the test case are immutable and cannot be changed by this endpoint.", "operationId": "updateProductTestCaseOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "testCaseId", "schema": { "$ref": "#/components/schemas/testCaseId" }, "required": true, "description": "The unique identifier of the test case to update. This is the id returned when the test case was created." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/design-controls/products/{productId}/requirements/{requirementId}": { "put": { "summary": "Update a requirement", "description": "Update an existing requirement in a design control product. The request body replaces the mutable fields of the requirement: title, type, and description. The type field must match the existing type of the requirement; changing the type across categories is not supported and returns 400. The links, requirements, and test_cases fields define the complete desired set of trace links and replace all existing trace links on the requirement. Omit all three to leave existing trace links unchanged. Type-matching is enforced: req1 can only link to testCase1 items, req2 to testCase2, and req3 to testCase3. req4 requirements cannot link to any test case type. Mismatched types return 400. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created. The id, code, and source of the requirement are immutable and cannot be changed by this endpoint.", "operationId": "updateProductRequirement", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "requirementId", "schema": { "$ref": "#/components/schemas/requirementId" }, "required": true, "description": "The unique identifier of the requirement to update. This is the id returned when the requirement was created." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The updated title of the item, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the item. Accepts plain text up to 150,000 characters. Omit this field to leave the existing description unchanged.", "type": "string", "maxLength": 150000 }, "links": { "description": "The complete desired set of trace link codes or UUIDs for this item. Both requirement codes and test case codes are accepted, for example REQ-1 or TC-5. This field replaces all existing trace links. Type-matching rules apply: requirement and test case template numbers must match.", "type": "array", "items": { "type": "string" } }, "requirements": { "description": "An array of requirement codes or UUIDs to link for traceability coverage. Entries are combined with links and replace all existing trace links together. The same type-matching rules apply.", "type": "array", "items": { "type": "string" } }, "type": { "type": "string", "enum": [ "req1", "req2", "req3", "req4" ], "description": "The requirement template slot for this item. Must match the existing type of the requirement; changing the type across categories is not supported and returns 400. Use req1, req2, req3, or req4 to match the first, second, third, or fourth configured template in the product. Type-matching is also enforced on links: req1 can only link to testCase1 items, req2 to testCase2, and req3 to testCase3. req4 requirements cannot link to any test case type." }, "test_cases": { "description": "An array of test case codes or UUIDs to link to this requirement, establishing coverage traceability. The test case template number must match the requirement template number: req1 links to testCase1, req2 to testCase2, and req3 to testCase3. Supplying a mismatched type returns 400. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created. Entries are combined with links and requirements and replace all existing trace links together.", "type": "array", "items": { "type": "string" } } }, "required": [ "title", "type" ], "description": "A request body to update an existing requirement in a design control product. The type field must match the existing type of the requirement; changing the type across categories is not supported and returns 400. The links, requirements, and test_cases fields define the complete desired set of trace links and replace all existing trace links when provided. Omitting all three leaves existing trace links unchanged. The id, code, and source of the requirement are immutable and cannot be changed by this endpoint.", "example": { "title": "Pump pressure must remain within safe and extended operating range", "type": "req1", "description": "The pump shall maintain output pressure between 0.5 bar and 5.0 bar under all rated operating conditions, including transient startup and shutdown phases.", "test_cases": [ "TC-1", "TC-3", "TC-7" ] }, "ref": "updateRequirement" } } } }, "responses": { "200": { "description": "Requirement updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "enum": [ "req1", "req2", "req3", "req4" ], "description": "The quality item category. Can be req1, req2, req3 or req4." } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type" ], "additionalProperties": false, "description": "The requirement after the update was applied.", "example": { "id": "3f8b2c14-7d6e-4a9f-bc21-5e0d9a1f23b4", "title": "Pump pressure must remain within safe operating range", "code": "REQ-42", "type": "req1", "source": "jira", "source_url": "https://your-company.atlassian.net/browse/REQ-42", "created_at": "2025-05-21T10:00:00.000Z", "updated_at": "2025-05-21T10:00:00.000Z", "issues": {} }, "ref": "updatedRequirement" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product or requirement not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Update an existing requirement in a design control product. The request body replaces the mutable fields of the requirement: title, type, and description. The type field must match the existing type of the requirement; changing the type across categories is not supported and returns 400. The links, requirements, and test_cases fields define the complete desired set of trace links and replace all existing trace links on the requirement. Omit all three to leave existing trace links unchanged. Type-matching is enforced: req1 can only link to testCase1 items, req2 to testCase2, and req3 to testCase3. req4 requirements cannot link to any test case type. Mismatched types return 400. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created. The id, code, and source of the requirement are immutable and cannot be changed by this endpoint.", "operationId": "updateProductRequirementOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "requirementId", "schema": { "$ref": "#/components/schemas/requirementId" }, "required": true, "description": "The unique identifier of the requirement to update. This is the id returned when the requirement was created." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/design-controls/products/{productId}/risks": { "post": { "summary": "Create a risk", "description": "Create a risk in a design control product. Set subType to iso for ISO 14971 qualitative risk analysis or fmea for Failure Mode and Effects Analysis. An optional id may be provided for idempotency; when omitted the server generates one automatically. A short code is always auto-generated by the server. ISO risks accept hazard, foreseeableUseMisuse, hazardSituation, and harm fields, with string-based preMitigation and postMitigation assessments. FMEA risks accept failureMode, failureModeEffects, failureCauses, and evaluationMethod fields, with numeric preMitigation and postMitigation scores (1 to 10). postMitigation requires riskControl to be provided. Use sources for upstream items this risk stems from and mitigations for downstream items that mitigate this risk. Providing an id that already exists in the product returns 409 Conflict.", "operationId": "createProductRisk", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The title of the risk, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the risk. Accepts plain text.", "type": "string" }, "riskControl": { "type": "object", "properties": { "mitigation": { "type": "string", "minLength": 1, "description": "A description of the control measure applied to reduce or eliminate the risk." } }, "required": [ "mitigation" ], "description": "The risk control measure. Required before a post-mitigation assessment can be recorded." }, "sources": { "description": "An array of quality item codes or UUIDs that are the upstream sources of this risk, for example requirement codes. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created.", "type": "array", "items": { "type": "string" } }, "mitigations": { "description": "An array of quality item codes or UUIDs for items that mitigate this risk downstream, for example requirement or test case codes. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created.", "type": "array", "items": { "type": "string" } }, "subType": { "type": "string", "enum": [ "iso", "fmea" ], "description": "The risk assessment methodology. Use iso for ISO 14971 qualitative risk analysis with probability and severity string scales. Use fmea for Failure Mode and Effects Analysis with numeric severity, occurrence, and detectability scores (1 to 10). The subType determines which assessment fields apply: iso uses hazard, foreseeableUseMisuse, hazardSituation, and harm; fmea uses failureMode, failureModeEffects, failureCauses, and evaluationMethod." }, "hazard": { "description": "The hazard associated with this risk. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "foreseeableUseMisuse": { "description": "The reasonably foreseeable use or misuse scenario. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "hazardSituation": { "description": "The hazardous situation resulting from the hazard. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "harm": { "description": "The harm that could result from the hazardous situation. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureMode": { "description": "A description of the way in which a component or process could fail. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureModeEffects": { "description": "The effects of the failure mode on the system or end user. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureCauses": { "description": "The root causes that lead to the failure mode. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "evaluationMethod": { "description": "Current controls or evaluation methods in place to detect the failure mode. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "preMitigation": { "description": "Pre-mitigation assessment. For iso risks: an object with probability (string), severity (string), and optionally riskLevel (string). For fmea risks: an object with severity, occurrence, and detectability as positive integers (1 to 10).", "anyOf": [ { "type": "object", "properties": { "probability": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the probability of occurrence, taken from the probability scale configured in the product." }, "severity": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the severity of harm, taken from the severity scale configured in the product." }, "riskLevel": { "description": "The overall risk level derived from probability and severity. When omitted the server calculates it from the configured risk matrix.", "type": "string" } }, "required": [ "probability", "severity" ] }, { "type": "object", "properties": { "severity": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Severity score from 1 to 10 representing the impact of the failure mode." }, "occurrence": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Occurrence score from 1 to 10 representing the likelihood that the failure mode will occur." }, "detectability": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Detectability score from 1 to 10 representing the likelihood that the failure mode will be detected before reaching the end user. Lower values mean higher detectability." } }, "required": [ "severity", "occurrence", "detectability" ] } ] }, "postMitigation": { "description": "Post-mitigation assessment after the risk control is applied. Shape is identical to preMitigation for the given subType. Requires riskControl to be set.", "anyOf": [ { "type": "object", "properties": { "probability": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the probability of occurrence, taken from the probability scale configured in the product." }, "severity": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the severity of harm, taken from the severity scale configured in the product." }, "riskLevel": { "description": "The overall risk level derived from probability and severity. When omitted the server calculates it from the configured risk matrix.", "type": "string" } }, "required": [ "probability", "severity" ] }, { "type": "object", "properties": { "severity": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Severity score from 1 to 10 representing the impact of the failure mode." }, "occurrence": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Occurrence score from 1 to 10 representing the likelihood that the failure mode will occur." }, "detectability": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Detectability score from 1 to 10 representing the likelihood that the failure mode will be detected before reaching the end user. Lower values mean higher detectability." } }, "required": [ "severity", "occurrence", "detectability" ] } ] } }, "required": [ "title", "subType" ], "description": "A request body to create a new risk in a design control product. The subType field selects the risk assessment methodology: iso for ISO 14971 qualitative risk analysis, fmea for Failure Mode and Effects Analysis. An optional id may be provided to assign a specific identifier; when omitted the server generates one automatically. A short code is always auto-generated by the server. ISO risks support hazard, foreseeableUseMisuse, hazardSituation, harm, and string-based preMitigation and postMitigation assessments. FMEA risks support failureMode, failureModeEffects, failureCauses, evaluationMethod, and numeric preMitigation and postMitigation assessments (scores 1 to 10). postMitigation requires riskControl to be provided. Use sources to link items this risk stems from (upstream) and mitigations to link items that mitigate this risk (downstream). Supplying an id that already exists in this product returns 409 Conflict.", "example": { "title": "Risk of pump over-pressurisation causing patient harm", "subType": "iso", "description": "If the pump delivers pressure above the rated maximum, the patient may be harmed.", "hazard": "Mechanical failure of pressure regulation valve", "hazardSituation": "Pump delivers pressure above rated maximum during infusion", "harm": "Patient trauma due to over-pressurisation", "preMitigation": { "probability": "Occasional", "severity": "Critical", "riskLevel": "High" }, "riskControl": { "mitigation": "Add a secondary pressure relief valve rated at 110% of maximum operating pressure" }, "postMitigation": { "probability": "Remote", "severity": "Critical", "riskLevel": "Medium" }, "sources": [ "REQ-1" ], "mitigations": [ "REQ-5", "TC-1" ] }, "ref": "createRisk" } } } }, "responses": { "201": { "description": "Risk created successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "const": "risk", "description": "The quality item category. Always risk for items created by this endpoint." }, "subType": { "type": "string", "enum": [ "iso", "fmea" ], "description": "The risk assessment methodology used for this risk: iso or fmea." }, "riskControl": { "type": "object", "properties": { "mitigation": { "type": "string", "minLength": 1, "description": "A description of the control measure applied to reduce or eliminate the risk." } }, "required": [ "mitigation" ], "additionalProperties": false, "description": "The risk control measure. Required before a post-mitigation assessment can be recorded." }, "hazard": { "description": "The hazard. Present when subType is iso.", "type": "string" }, "foreseeableUseMisuse": { "description": "The foreseeable use or misuse scenario. Present when subType is iso.", "type": "string" }, "hazardSituation": { "description": "The hazardous situation. Present when subType is iso.", "type": "string" }, "harm": { "description": "The harm that could result. Present when subType is iso.", "type": "string" }, "failureMode": { "description": "The failure mode description. Present when subType is fmea.", "type": "string" }, "failureModeEffects": { "description": "The effects of the failure mode. Present when subType is fmea.", "type": "string" }, "failureCauses": { "description": "The root causes of the failure mode. Present when subType is fmea.", "type": "string" }, "evaluationMethod": { "description": "Current controls or evaluation methods. Present when subType is fmea.", "type": "string" }, "preMitigation": { "description": "Pre-mitigation assessment. For iso risks contains probability, severity, and optionally riskLevel strings. For fmea risks contains numeric severity, occurrence, and detectability scores.", "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "anyOf": [ { "type": "string" }, { "type": "number" } ] } }, "postMitigation": { "description": "Post-mitigation assessment after the risk control is applied. Shape is the same as preMitigation for the given subType.", "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "anyOf": [ { "type": "string" }, { "type": "number" } ] } } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type", "subType" ], "additionalProperties": false, "description": "The risk that was created.", "example": { "id": "a1c3e5f7-2b4d-4068-9a8c-1d2e3f405162", "title": "Risk of pump over-pressurisation causing patient harm", "code": "RISK-1", "type": "risk", "subType": "iso", "source": "developer-api", "created_at": "2026-05-22T09:00:00.000Z", "updated_at": "2026-05-22T09:00:00.000Z", "issues": {}, "hazard": "Mechanical failure of pressure regulation valve", "hazardSituation": "Pump delivers pressure above rated maximum during infusion", "harm": "Patient trauma due to over-pressurisation", "riskControl": { "mitigation": "Add a secondary pressure relief valve rated at 110% of maximum operating pressure" }, "preMitigation": { "probability": "Occasional", "severity": "Critical", "riskLevel": "High" }, "postMitigation": { "probability": "Remote", "severity": "Critical", "riskLevel": "Medium" } }, "ref": "createdRisk" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "409": { "description": "A risk with the provided id already exists in this product.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/riskConflictResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Create a risk in a design control product. Set subType to iso for ISO 14971 qualitative risk analysis or fmea for Failure Mode and Effects Analysis. An optional id may be provided for idempotency; when omitted the server generates one automatically. A short code is always auto-generated by the server. ISO risks accept hazard, foreseeableUseMisuse, hazardSituation, and harm fields, with string-based preMitigation and postMitigation assessments. FMEA risks accept failureMode, failureModeEffects, failureCauses, and evaluationMethod fields, with numeric preMitigation and postMitigation scores (1 to 10). postMitigation requires riskControl to be provided. Use sources for upstream items this risk stems from and mitigations for downstream items that mitigate this risk. Providing an id that already exists in the product returns 409 Conflict.", "operationId": "createProductRiskOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/design-controls/products/{productId}/risks/{riskId}": { "put": { "summary": "Update a risk", "description": "Update an existing risk in a design control product. The subType field must match the existing subType of the risk; changing the subType is not supported and returns 400. The request body replaces the mutable fields of the risk: title, subType, description, and all sub-type-specific assessment and narrative fields. The sources and mitigations fields define the complete desired set of trace links and replace all existing trace links when provided. Omitting both leaves existing trace links unchanged. The id and code of the risk are immutable and cannot be changed by this endpoint.", "operationId": "updateProductRisk", "tags": [ "Design Controls" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "riskId", "schema": { "$ref": "#/components/schemas/riskId" }, "required": true, "description": "The unique identifier of the risk to update. This is the id returned when the risk was created." } ], "requestBody": { "content": { "application/json": { "schema": { "type": "object", "properties": { "title": { "type": "string", "minLength": 1, "maxLength": 255, "description": "The title of the risk, displayed in the Qualio UI. Must be between 1 and 255 characters." }, "description": { "description": "An optional description of the risk. Accepts plain text.", "type": "string" }, "riskControl": { "type": "object", "properties": { "mitigation": { "type": "string", "minLength": 1, "description": "A description of the control measure applied to reduce or eliminate the risk." } }, "required": [ "mitigation" ], "description": "The risk control measure. Required before a post-mitigation assessment can be recorded." }, "sources": { "description": "An array of quality item codes or UUIDs that are the upstream sources of this risk, for example requirement codes. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created.", "type": "array", "items": { "type": "string" } }, "mitigations": { "description": "An array of quality item codes or UUIDs for items that mitigate this risk downstream, for example requirement or test case codes. Codes or UUIDs not found in the product are stored as unresolved links and resolved automatically when the target item is created.", "type": "array", "items": { "type": "string" } }, "subType": { "type": "string", "enum": [ "iso", "fmea" ], "description": "The risk assessment methodology. Must match the existing subType of the risk; changing the subType is not supported and returns 400. iso uses probability and severity string scales; fmea uses numeric severity, occurrence, and detectability scores (1 to 10)." }, "hazard": { "description": "The hazard associated with this risk. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "foreseeableUseMisuse": { "description": "The reasonably foreseeable use or misuse scenario. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "hazardSituation": { "description": "The hazardous situation resulting from the hazard. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "harm": { "description": "The harm that could result from the hazardous situation. Only applicable when subType is iso. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureMode": { "description": "A description of the way in which a component or process could fail. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureModeEffects": { "description": "The effects of the failure mode on the system or end user. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "failureCauses": { "description": "The root causes that lead to the failure mode. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "evaluationMethod": { "description": "Current controls or evaluation methods in place to detect the failure mode. Only applicable when subType is fmea. Max 1000 characters.", "type": "string", "maxLength": 1000 }, "preMitigation": { "description": "Pre-mitigation assessment. For iso risks: an object with probability (string), severity (string), and optionally riskLevel (string). For fmea risks: an object with severity, occurrence, and detectability as positive integers (1 to 10).", "anyOf": [ { "type": "object", "properties": { "probability": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the probability of occurrence, taken from the probability scale configured in the product." }, "severity": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the severity of harm, taken from the severity scale configured in the product." }, "riskLevel": { "description": "The overall risk level derived from probability and severity. When omitted the server calculates it from the configured risk matrix.", "type": "string" } }, "required": [ "probability", "severity" ] }, { "type": "object", "properties": { "severity": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Severity score from 1 to 10 representing the impact of the failure mode." }, "occurrence": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Occurrence score from 1 to 10 representing the likelihood that the failure mode will occur." }, "detectability": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Detectability score from 1 to 10 representing the likelihood that the failure mode will be detected before reaching the end user. Lower values mean higher detectability." } }, "required": [ "severity", "occurrence", "detectability" ] } ] }, "postMitigation": { "description": "Post-mitigation assessment after the risk control is applied. Shape is identical to preMitigation for the given subType. Requires riskControl to be set.", "anyOf": [ { "type": "object", "properties": { "probability": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the probability of occurrence, taken from the probability scale configured in the product." }, "severity": { "type": "string", "minLength": 1, "description": "A qualitative or quantitative label for the severity of harm, taken from the severity scale configured in the product." }, "riskLevel": { "description": "The overall risk level derived from probability and severity. When omitted the server calculates it from the configured risk matrix.", "type": "string" } }, "required": [ "probability", "severity" ] }, { "type": "object", "properties": { "severity": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Severity score from 1 to 10 representing the impact of the failure mode." }, "occurrence": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Occurrence score from 1 to 10 representing the likelihood that the failure mode will occur." }, "detectability": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "Detectability score from 1 to 10 representing the likelihood that the failure mode will be detected before reaching the end user. Lower values mean higher detectability." } }, "required": [ "severity", "occurrence", "detectability" ] } ] } }, "required": [ "title", "subType" ], "description": "A request body to update an existing risk in a design control product. The subType field must match the existing subType of the risk; changing the subType is not supported and returns 400. The sources and mitigations fields define the complete desired set of trace links and replace all existing trace links when provided. Omitting both leaves existing trace links unchanged. The id and code of the risk are immutable and cannot be changed by this endpoint.", "example": { "title": "Risk of pump over-pressurisation causing patient harm (revised)", "subType": "iso", "hazard": "Mechanical failure of pressure regulation valve", "hazardSituation": "Pump delivers pressure above rated maximum during infusion", "harm": "Patient trauma due to over-pressurisation", "preMitigation": { "probability": "Occasional", "severity": "Critical", "riskLevel": "High" }, "riskControl": { "mitigation": "Add a secondary pressure relief valve and software interlock" }, "postMitigation": { "probability": "Remote", "severity": "Critical", "riskLevel": "Low" }, "mitigations": [ "REQ-5", "REQ-12", "TC-1" ] }, "ref": "updateRisk" } } } }, "responses": { "200": { "description": "Risk updated successfully.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid", "description": "The unique identifier of the created item." }, "title": { "type": "string", "description": "The title of the item." }, "code": { "description": "The short identifier visible in the Qualio UI.", "type": "string" }, "description": { "description": "The content of the object", "type": "string" }, "source": { "type": "string", "description": "The system associated with this item. Set at creation time from the source field in the request, defaulting to developer-api. This value is immutable after creation." }, "source_url": { "description": "The URL linking back to the corresponding entry in the source system. Reflects the url field from the request.", "type": "string", "format": "uri" }, "created_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was created." }, "updated_at": { "type": "string", "format": "date-time", "description": "An ISO 8601 timestamp recording when the item was last modified." }, "issues": { "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "type": "boolean" }, "description": "A map of policy violation flags. Keys are policy statement identifiers such as REQUIRES_CHILD, UNTESTED_REQUIREMENT, or FAILING_TEST. Newly created items have no active violations and this object is empty." }, "type": { "type": "string", "const": "risk", "description": "The quality item category. Always risk for items created by this endpoint." }, "subType": { "type": "string", "enum": [ "iso", "fmea" ], "description": "The risk assessment methodology used for this risk: iso or fmea." }, "riskControl": { "type": "object", "properties": { "mitigation": { "type": "string", "minLength": 1, "description": "A description of the control measure applied to reduce or eliminate the risk." } }, "required": [ "mitigation" ], "additionalProperties": false, "description": "The risk control measure. Required before a post-mitigation assessment can be recorded." }, "hazard": { "description": "The hazard. Present when subType is iso.", "type": "string" }, "foreseeableUseMisuse": { "description": "The foreseeable use or misuse scenario. Present when subType is iso.", "type": "string" }, "hazardSituation": { "description": "The hazardous situation. Present when subType is iso.", "type": "string" }, "harm": { "description": "The harm that could result. Present when subType is iso.", "type": "string" }, "failureMode": { "description": "The failure mode description. Present when subType is fmea.", "type": "string" }, "failureModeEffects": { "description": "The effects of the failure mode. Present when subType is fmea.", "type": "string" }, "failureCauses": { "description": "The root causes of the failure mode. Present when subType is fmea.", "type": "string" }, "evaluationMethod": { "description": "Current controls or evaluation methods. Present when subType is fmea.", "type": "string" }, "preMitigation": { "description": "Pre-mitigation assessment. For iso risks contains probability, severity, and optionally riskLevel strings. For fmea risks contains numeric severity, occurrence, and detectability scores.", "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "anyOf": [ { "type": "string" }, { "type": "number" } ] } }, "postMitigation": { "description": "Post-mitigation assessment after the risk control is applied. Shape is the same as preMitigation for the given subType.", "type": "object", "propertyNames": { "type": "string" }, "additionalProperties": { "anyOf": [ { "type": "string" }, { "type": "number" } ] } } }, "required": [ "id", "title", "source", "created_at", "updated_at", "issues", "type", "subType" ], "additionalProperties": false, "description": "The risk after the update was applied.", "example": { "id": "a1c3e5f7-2b4d-4068-9a8c-1d2e3f405162", "title": "Risk of pump over-pressurisation causing patient harm", "code": "RISK-1", "type": "risk", "subType": "iso", "source": "developer-api", "created_at": "2026-05-22T09:00:00.000Z", "updated_at": "2026-05-22T09:00:00.000Z", "issues": {}, "hazard": "Mechanical failure of pressure regulation valve", "hazardSituation": "Pump delivers pressure above rated maximum during infusion", "harm": "Patient trauma due to over-pressurisation", "riskControl": { "mitigation": "Add a secondary pressure relief valve rated at 110% of maximum operating pressure" }, "preMitigation": { "probability": "Occasional", "severity": "Critical", "riskLevel": "High" }, "postMitigation": { "probability": "Remote", "severity": "Critical", "riskLevel": "Medium" } }, "ref": "updatedRisk" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Product or risk not found.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Update an existing risk in a design control product. The subType field must match the existing subType of the risk; changing the subType is not supported and returns 400. The request body replaces the mutable fields of the risk: title, subType, description, and all sub-type-specific assessment and narrative fields. The sources and mitigations fields define the complete desired set of trace links and replace all existing trace links when provided. Omitting both leaves existing trace links unchanged. The id and code of the risk are immutable and cannot be changed by this endpoint.", "operationId": "updateProductRiskOptions", "tags": [ "Design Controls" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "productId", "schema": { "$ref": "#/components/schemas/dcProductId" }, "required": true, "description": "A design control product id" }, { "in": "path", "name": "riskId", "schema": { "$ref": "#/components/schemas/riskId" }, "required": true, "description": "The unique identifier of the risk to update. This is the id returned when the risk was created." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/document/{documentId}": { "get": { "summary": "Retrieve a document", "description": "Retrieves a single document version by its numeric id, with full details including title, status, version, owner, reviewers/approvers, and tags. In Qualio, each version of a document has its own numeric id, while the document code (e.g. SOP-1) is shared across all versions â this endpoint returns the specific version identified by `documentId`. Use the versions endpoints to list the other versions of the same document.", "operationId": "getDocument", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Successful document retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentDetailed" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single document version by its numeric id, with full details including title, status, version, owner, reviewers/approvers, and tags. In Qualio, each version of a document has its own numeric id, while the document code (e.g. SOP-1) is shared across all versions â this endpoint returns the specific version identified by `documentId`. Use the versions endpoints to list the other versions of the same document.", "operationId": "getDocumentOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "patch": { "summary": "Update document people and tags", "description": "Updates the approvers, reviewers, and/or tags of a document that is in **draft** status (for approvers and reviewers) or any status (for tags).\n\nThis is a **partial update**: only the fields included in the request body are modified. Omitted fields are left unchanged. Each supplied list fully replaces the current set for that role â to add a single reviewer, include all existing reviewer IDs plus the new one.\n\n**Quality approvers vs other approvers**: Qualio distinguishes between quality approvers (users belonging to the Quality group) and other approvers. Supply them in separate lists; they are merged and stored together as the document's approver group.\n\n**Errors:**\n- `400` with slug `document_not_in_draft`: approvers or reviewers were supplied but the document is not in draft status.\n- `404`: the document does not exist or is not accessible to the API key's user.", "operationId": "updateDocument", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/updateDocumentPayload" } } } }, "responses": { "200": { "description": "The document with its updated approvers, reviewers, and tags", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentDetailed" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/documents/document/{documentId}/content": { "get": { "summary": "Retrieve document content", "description": "Retrieves the section content of a specific document version, identified by its numeric id. Content is returned per section (each with a title and HTML body). Use `GET /v1/documents/document/{documentId}` for the document's metadata, or the templates endpoints for the section structure of a document type.", "operationId": "getDocumentContent", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Successful document content retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentContentResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves the section content of a specific document version, identified by its numeric id. Content is returned per section (each with a title and HTML body). Use `GET /v1/documents/document/{documentId}` for the document's metadata, or the templates endpoints for the section structure of a document type.", "operationId": "getDocumentContentOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "patch": { "summary": "Update document content", "description": "Updates the HTML section content of a document that is in **draft** status.\n\nThis is a **partial update**: only the sections listed in the request body are modified. Sections not included retain their existing content unchanged. To replace all content, include every section position defined by the document template.\n\n**Sections are identified by their `position` number** (1-indexed, matching the order defined by the document template). Use `GET /v1/documents/templates/{templateId}/content` to discover the positions and titles available for a given template.\n\n**Content format**: Section content is stored and returned as HTML. Plain text is also accepted. Unsafe HTML is stripped on ingestion, and only a permitted set of tags and attributes is stored.\n\n**Collaboration sessions**: Any in-progress collaborative editing session on this document is automatically cleared when this endpoint is called, ensuring the content provided here is what gets persisted. Do not call this endpoint while end-users are actively editing the same document in the Qualio UI, as it will discard their unsaved changes.\n\n**Errors:**\n- `400` with slug `document_not_in_draft`: the document exists but is not in draft status. Only draft documents can have their content updated via this endpoint.\n- `404`: the document does not exist, belongs to a different organisation, or is not accessible to the API key's user.", "operationId": "updateDocumentContent", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/updateDocumentContentPayload" } } } }, "responses": { "200": { "description": "The full updated content of the document, including all sections (both modified and unmodified)", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentContentResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/documents/document/{documentId}/status": { "put": { "summary": "Change document status", "description": "Advances or reverts the lifecycle status of a document.\n\n**The document must be accessible to the API key's user.** The transition must be valid for the document's current status. Invalid transitions are rejected with a 400 and the document is left unchanged.\n\n**Valid status transitions:**\n\n| From | To | Notes |\n|------|----|-------|\n| `draft` | `for_review` | Document must have at least one reviewer assigned |\n| `draft` | `for_approval` | Document must have at least one approver (including a quality approver) |\n| `for_review` | `for_approval` | Document must have at least one approver |\n| `for_review` | `draft` | Reverts to draft |\n| `for_approval` | `draft` | Reverts to draft |\n| `approval_declined` | `draft` | Reverts to draft after a decline |\n| `deleted` | `draft` | Restores a deleted document to draft |\n\nTransitions that require electronic signature authentication (such as `for_approval` to `approved`, `approved` to `effective`, and `for_approval` to `approval_declined`) are not supported via this endpoint and will return a 400 with slug `esign_required`.\n\n**Side effects, same as the Qualio UI:**\n- Notifications are sent to reviewers or approvers on `for_review` and `for_approval` transitions\n- The audit trail records the status change, the acting user, and any comment provided\n- Reverting to `draft` clears any in-progress approvals and notifies affected users\n\n**Errors:**\n- `400`: the transition is not valid (e.g. no reviewers assigned, document is not in a state that permits the requested transition, or the transition requires e-signature). The error message describes the specific reason.\n- `404`: the document does not exist or is not accessible to the API key's user.", "operationId": "changeDocumentStatus", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/changeDocumentStatusPayload" } } } }, "responses": { "200": { "description": "The document with its updated status and metadata. Use the returned `status` field to confirm the transition completed.", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentStatusChangeResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Advances or reverts the lifecycle status of a document.\n\n**The document must be accessible to the API key's user.** The transition must be valid for the document's current status. Invalid transitions are rejected with a 400 and the document is left unchanged.\n\n**Valid status transitions:**\n\n| From | To | Notes |\n|------|----|-------|\n| `draft` | `for_review` | Document must have at least one reviewer assigned |\n| `draft` | `for_approval` | Document must have at least one approver (including a quality approver) |\n| `for_review` | `for_approval` | Document must have at least one approver |\n| `for_review` | `draft` | Reverts to draft |\n| `for_approval` | `draft` | Reverts to draft |\n| `approval_declined` | `draft` | Reverts to draft after a decline |\n| `deleted` | `draft` | Restores a deleted document to draft |\n\nTransitions that require electronic signature authentication (such as `for_approval` to `approved`, `approved` to `effective`, and `for_approval` to `approval_declined`) are not supported via this endpoint and will return a 400 with slug `esign_required`.\n\n**Side effects, same as the Qualio UI:**\n- Notifications are sent to reviewers or approvers on `for_review` and `for_approval` transitions\n- The audit trail records the status change, the acting user, and any comment provided\n- Reverting to `draft` clears any in-progress approvals and notifies affected users\n\n**Errors:**\n- `400`: the transition is not valid (e.g. no reviewers assigned, document is not in a state that permits the requested transition, or the transition requires e-signature). The error message describes the specific reason.\n- `404`: the document does not exist or is not accessible to the API key's user.", "operationId": "changeDocumentStatusOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/document/{documentId}/versions": { "get": { "summary": "List document versions by ID", "description": "Lists every version of a document, identified by the numeric id of any one of its versions, sorted newest version first. All versions of a document share the same code (e.g. SOP-1) but each has its own id and version number (e.g. 1.0, 2.0). Returns a summary of each version, letting you trace a document's revision history.", "operationId": "listDocumentVersions", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Successful document versions retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentVersionsResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists every version of a document, identified by the numeric id of any one of its versions, sorted newest version first. All versions of a document share the same code (e.g. SOP-1) but each has its own id and version number (e.g. 1.0, 2.0). Returns a summary of each version, letting you trace a document's revision history.", "operationId": "listDocumentVersionsOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/document/{documentId}/comments": { "get": { "summary": "List comments on a document", "description": "Lists the comment and suggestion threads on a document version, identified by its numeric id. Each thread includes its status (Open, Resolved, Removed, Accepted, or Rejected), the commented-on content (if available), and any replies. Returns an empty list if the document has no comments.", "operationId": "listDocumentComments", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Successful document comments retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentCommentsResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the comment and suggestion threads on a document version, identified by its numeric id. Each thread includes its status (Open, Resolved, Removed, Accepted, or Rejected), the commented-on content (if available), and any replies. Returns an empty list if the document has no comments.", "operationId": "listDocumentCommentsOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/documentId" }, "required": true, "description": "A unique identifier for a document version" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/document/code/{code}/versions": { "get": { "summary": "List document versions by code", "description": "Lists every version of a document, identified by its document code (e.g. SOP-1, POL-42), sorted newest version first. The code is shared across all versions of a document; each version has its own id and version number. Returns a summary of each version. Use this when you know the human-readable code rather than a numeric version id.", "operationId": "listDocumentVersionsByCode", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "code", "schema": { "$ref": "#/components/schemas/documentCode" }, "required": true, "description": "A unique code identifier for a document (e.g. SOP-1, POL-42)" } ], "responses": { "200": { "description": "Successful document versions retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentVersionsResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists every version of a document, identified by its document code (e.g. SOP-1, POL-42), sorted newest version first. The code is shared across all versions of a document; each version has its own id and version number. Returns a summary of each version. Use this when you know the human-readable code rather than a numeric version id.", "operationId": "listDocumentVersionsByCodeOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "code", "schema": { "$ref": "#/components/schemas/documentCode" }, "required": true, "description": "A unique code identifier for a document (e.g. SOP-1, POL-42)" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/query": { "get": { "summary": "Query documents", "description": "Queries documents across your Qualio instance, returning a light summary of each (code, title, status, version, owner, etc.). Filter by document status (`draft`, `for_review`, `for_approval`, `approved`, `effective`, `superseded`, `retired`, and others) and paginate with offset/limit. Use this to find documents â for example all effective SOPs, or documents currently awaiting approval â then fetch full details or content with the per-document endpoints.", "operationId": "queryDocuments", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/documentStatus" }, "required": true, "description": "The different states of a document in Qualio" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } } ], "responses": { "200": { "description": "Successful document query response, with a light summary of each document", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentSummaryResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Queries documents across your Qualio instance, returning a light summary of each (code, title, status, version, owner, etc.). Filter by document status (`draft`, `for_review`, `for_approval`, `approved`, `effective`, `superseded`, `retired`, and others) and paginate with offset/limit. Use this to find documents â for example all effective SOPs, or documents currently awaiting approval â then fetch full details or content with the per-document endpoints.", "operationId": "queryDocumentsOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/documentStatus" }, "required": true, "description": "The different states of a document in Qualio" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/templates": { "get": { "summary": "List document templates", "description": "Lists all active document templates for your instance. A document template defines a document type â its section structure and the code prefix used to generate document codes (e.g. an 'SOP' template produces SOP-1, SOP-2â¦). Each template includes its `template_matrix_id`, which is required when creating a new document.", "operationId": "listDocumentTemplates", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful templates query response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentTemplatesQueryResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists all active document templates for your instance. A document template defines a document type â its section structure and the code prefix used to generate document codes (e.g. an 'SOP' template produces SOP-1, SOP-2â¦). Each template includes its `template_matrix_id`, which is required when creating a new document.", "operationId": "listDocumentTemplatesOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/templates/{templateId}": { "get": { "summary": "Retrieve a document template", "description": "Retrieves a single document template by id. A document template defines a document type, its section structure, and the code prefix used for documents created from it.", "operationId": "getDocumentTemplate", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Successful template response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentTemplateResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Template not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single document template by id. A document template defines a document type, its section structure, and the code prefix used for documents created from it.", "operationId": "getDocumentTemplateOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/templates/{templateId}/content": { "get": { "summary": "Retrieve template content", "description": "Retrieves the section structure and default content of a document template, including each section's title and position. Use these positions when supplying section content to create or update a document from this template.", "operationId": "getDocumentTemplateContent", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Successful template content response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/documentTemplateContentResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Template not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves the section structure and default content of a document template, including each section's title and position. Use these positions when supplying section content to create or update a document from this template.", "operationId": "getDocumentTemplateContentOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/attachments/{id}": { "get": { "summary": "Retrieve an attachment", "description": "Retrieves metadata for a single attachment by its numeric id. Pass `download=true` as a query parameter to trigger a file download instead of returning JSON metadata. When downloading, also send `Accept: application/octet-stream` so the file is returned as raw binary; without it, the file body is returned as a base64-encoded string instead. Downloads are limited to files up to 10MB. Only send `Accept: application/octet-stream` together with `download=true` â sending it without `download=true` will cause this endpoint to fail.", "operationId": "getAttachment", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "id", "schema": { "$ref": "#/components/schemas/attachmentId" }, "required": true, "description": "A unique identifier for an attachment" }, { "in": "query", "name": "download", "schema": { "description": "Set to true to download the file instead of returning JSON metadata", "example": false, "type": "boolean" }, "description": "Set to true to download the file instead of returning JSON metadata" } ], "responses": { "200": { "description": "Successful attachment retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/attachment" } }, "application/octet-stream": { "schema": { "type": "string", "format": "binary" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Attachment not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves metadata for a single attachment by its numeric id. Pass `download=true` as a query parameter to trigger a file download instead of returning JSON metadata. When downloading, also send `Accept: application/octet-stream` so the file is returned as raw binary; without it, the file body is returned as a base64-encoded string instead. Downloads are limited to files up to 10MB. Only send `Accept: application/octet-stream` together with `download=true` â sending it without `download=true` will cause this endpoint to fail.", "operationId": "getAttachmentOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "id", "schema": { "$ref": "#/components/schemas/attachmentId" }, "required": true, "description": "A unique identifier for an attachment" }, { "in": "query", "name": "download", "schema": { "description": "Set to true to download the file instead of returning JSON metadata", "example": false, "type": "boolean" }, "description": "Set to true to download the file instead of returning JSON metadata" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/documents/document": { "post": { "summary": "Create a draft document", "description": "Creates a new draft document. The template (via its `template_matrix_id`) determines the document type and its section structure. The document is created in `draft` status; use the change-status endpoint to advance it through review and approval.", "operationId": "createDocument", "tags": [ "Documents" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createDocumentPayload" } } } }, "responses": { "200": { "description": "Successful document creation response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createDocumentResponse" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Creates a new draft document. The template (via its `template_matrix_id`) determines the document type and its section structure. The document is created in `draft` status; use the change-status endpoint to advance it through review and approval.", "operationId": "createDocumentOptions", "tags": [ "Documents" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/events/events/{code}": { "get": { "summary": "Retrieve an event", "description": "Retrieves a single quality event in full detail by its code (e.g. CAPA-1, NCR-12), as shown in Qualio. A quality event is a structured record of a quality-related incident or action â such as a CAPA (corrective/preventive action), non-conformance/non-compliance, complaint, deviation, or audit finding; the code's prefix indicates its type. The detailed view includes the event's status, owner, dates, risk, tags, escalation links, and the contents of each workflow step.", "operationId": "getEvent", "tags": [ "Events" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "code", "schema": { "$ref": "#/components/schemas/eventCode" }, "required": true, "description": "A unique identifier for an Event, that includes a prefix that corresponds to its type" } ], "responses": { "200": { "description": "Successful event retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/eventDetailed" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Event not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single quality event in full detail by its code (e.g. CAPA-1, NCR-12), as shown in Qualio. A quality event is a structured record of a quality-related incident or action â such as a CAPA (corrective/preventive action), non-conformance/non-compliance, complaint, deviation, or audit finding; the code's prefix indicates its type. The detailed view includes the event's status, owner, dates, risk, tags, escalation links, and the contents of each workflow step.", "operationId": "getEventOptions", "tags": [ "Events" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "code", "schema": { "$ref": "#/components/schemas/eventCode" }, "required": true, "description": "A unique identifier for an Event, that includes a prefix that corresponds to its type" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/events/events": { "get": { "summary": "Query events", "description": "Queries quality events across your Qualio instance, returning a summary of each. Quality events are structured records of quality-related incidents and actions â CAPAs, non-conformances, complaints, deviations, audit findings, and other custom types. Filter by status (`open`, `closed`, `imported`, `rejected`, `cancelled`), by owner (owner_user_id), and by event type (event_template_matrix_id, from the templates endpoint), and paginate with offset/limit. Use this to find events â for example all open CAPAs or events owned by a given user.", "operationId": "queryEvents", "tags": [ "Events" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/eventStatus" }, "required": true, "description": "The status of a given event" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "owner_user_id", "schema": { "$ref": "#/components/schemas/userIdParam" }, "description": "A unique identifier for a user in Qualio" }, { "in": "query", "name": "event_template_matrix_id", "schema": { "$ref": "#/components/schemas/eventTemplateMatrixIdParam" }, "description": "A unique identifier for an event template in Qualio, use this to filter the results by event type" } ], "responses": { "200": { "description": "Successful event query response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/eventQueryResponse" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Queries quality events across your Qualio instance, returning a summary of each. Quality events are structured records of quality-related incidents and actions â CAPAs, non-conformances, complaints, deviations, audit findings, and other custom types. Filter by status (`open`, `closed`, `imported`, `rejected`, `cancelled`), by owner (owner_user_id), and by event type (event_template_matrix_id, from the templates endpoint), and paginate with offset/limit. Use this to find events â for example all open CAPAs or events owned by a given user.", "operationId": "queryEventsOptions", "tags": [ "Events" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/eventStatus" }, "required": true, "description": "The status of a given event" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "owner_user_id", "schema": { "$ref": "#/components/schemas/userIdParam" }, "description": "A unique identifier for a user in Qualio" }, { "in": "query", "name": "event_template_matrix_id", "schema": { "$ref": "#/components/schemas/eventTemplateMatrixIdParam" }, "description": "A unique identifier for an event template in Qualio, use this to filter the results by event type" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create an event", "description": "A request to create an event based on an event template. The event_template_matrix_id should correspond to the type of event you wish to create, which can be found on the response from querying templates. If you wish to populate values within the steps, use template_step_matrix_id from the desired step in the template, Then use field_matrix_id from the template to select what field to populate (form steps), or section_id from the template to select what section to populate (content steps).You do not have to set all of the fields or sections for your request to be valid, these can be completed later in the UI.If populating a field of type change_request, product, root_cause, registry, design_controls, training_plan, document_template, event_template, or task, you can use the code (ID visible in the UI) to populate the field.For the users field, you can use the email address of the user to populate the field. For suppliers, you can use the supplier name. You will see examples of these in the sample code.The event will be created with the owner set to the default owner for the event template, if available, and will list the API key user otherwise.", "operationId": "createEvent", "tags": [ "Events" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createEventPayload" } } } }, "responses": { "200": { "description": "Successfully created an event", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/event" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/events/templates": { "get": { "summary": "List event templates", "description": "Lists all effective event templates in your Qualio instance. An event template defines a type of quality event (e.g. CAPA, NCR, complaint) â its code prefix and the workflow steps that events of that type follow. Each template includes its `event_template_matrix_id`, which is used to filter events by type and to create a new event of that type.", "operationId": "listEventTemplates", "tags": [ "Events" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful event template query response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/eventTemplateResp" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists all effective event templates in your Qualio instance. An event template defines a type of quality event (e.g. CAPA, NCR, complaint) â its code prefix and the workflow steps that events of that type follow. Each template includes its `event_template_matrix_id`, which is used to filter events by type and to create a new event of that type.", "operationId": "listEventTemplatesOptions", "tags": [ "Events" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/events/templates/{eventTemplateMatrixId}": { "get": { "summary": "Retrieve an event template", "description": "Retrieves a single event template in full detail by its `event_template_matrix_id`, including its ordered workflow steps. Steps may be form steps (with fields to complete), content steps (with sections), or task steps. Use the step, field, and section identifiers returned here to populate values when creating an event of this type.", "operationId": "getEventTemplate", "tags": [ "Events" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "eventTemplateMatrixId", "schema": { "type": "string", "format": "uuid" }, "required": true } ], "responses": { "200": { "description": "Successful event template response", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/eventTemplateDetailedResp" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Event template not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single event template in full detail by its `event_template_matrix_id`, including its ordered workflow steps. Steps may be form steps (with fields to complete), content steps (with sections), or task steps. Use the step, field, and section identifiers returned here to populate values when creating an event of this type.", "operationId": "getEventTemplateOptions", "tags": [ "Events" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "eventTemplateMatrixId", "schema": { "type": "string", "format": "uuid" }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/resource-library/templates/list": { "get": { "summary": "List resource templates", "description": "Lists the resource templates configured for your instance â these are shown as \"Resources\" in the Qualio application. The Resource Library holds structured registries (logs) such as equipment, suppliers, parts, root causes, or training records, and each template defines the type and field structure of one such registry. Use this to discover the available resource types and their identifiers before creating items against them. Supports filtering by status (effective, draft, archived, superseded), a free-text search query, ordering by name, and pagination.", "operationId": "listResourceTemplates", "tags": [ "Resource Library" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "order_by", "schema": { "$ref": "#/components/schemas/orderBy" }, "description": "A property to order the results by" }, { "in": "query", "name": "search_query", "schema": { "$ref": "#/components/schemas/query" }, "description": "A search query to filter the results by" }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/status" }, "required": true, "description": "A status to filter the results by" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } } ], "responses": { "200": { "description": "Successful resource library template/resource query retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/resourceLibraryTemplateQueryResp" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the resource templates configured for your instance â these are shown as \"Resources\" in the Qualio application. The Resource Library holds structured registries (logs) such as equipment, suppliers, parts, root causes, or training records, and each template defines the type and field structure of one such registry. Use this to discover the available resource types and their identifiers before creating items against them. Supports filtering by status (effective, draft, archived, superseded), a free-text search query, ordering by name, and pagination.", "operationId": "listResourceTemplatesOptions", "tags": [ "Resource Library" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "order_by", "schema": { "$ref": "#/components/schemas/orderBy" }, "description": "A property to order the results by" }, { "in": "query", "name": "search_query", "schema": { "$ref": "#/components/schemas/query" }, "description": "A search query to filter the results by" }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/status" }, "required": true, "description": "A status to filter the results by" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/resource-library/templates/{templateId}": { "get": { "summary": "Retrieve a resource template", "description": "Retrieves a single resource template (a \"Resource\" in the Qualio application) by its id, including its definition and field structure. A template describes the type of a Resource Library registry â for example equipment, suppliers, or root causes â that items are created against.", "operationId": "getResourceTemplate", "tags": [ "Resource Library" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Successful resource library template query retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/resourceLibrarySingleTemplateResp" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Resource library template not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single resource template (a \"Resource\" in the Qualio application) by its id, including its definition and field structure. A template describes the type of a Resource Library registry â for example equipment, suppliers, or root causes â that items are created against.", "operationId": "getResourceTemplateOptions", "tags": [ "Resource Library" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "templateId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/resource-library/items": { "post": { "summary": "Create a resource item", "description": "Creates a new item (a record) in the Resource Library under the given resource template. The template determines which type of registry the item belongs to and its field structure. `display_id` is the human-readable identifier shown as 'ID' in the Qualio UI and must be unique.", "operationId": "createResourceItem", "tags": [ "Resource Library" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createResourceLibraryItem" } } } }, "responses": { "200": { "description": "Successful resource library template query retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createResourceLibraryItemSuccessResp" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Creates a new item (a record) in the Resource Library under the given resource template. The template determines which type of registry the item belongs to and its field structure. `display_id` is the human-readable identifier shown as 'ID' in the Qualio UI and must be unique.", "operationId": "createResourceItemOptions", "tags": [ "Resource Library" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/resource-library/items/{itemId}": { "get": { "summary": "Retrieve a resource item", "description": "Retrieves a single resource library item by its numeric id, including its fields, status, version, and any associated structured form data.", "operationId": "getResourceItem", "tags": [ "Resource Library" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "itemId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Successfully retrieved the resource library item", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/resourceLibraryItemResp" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Resource library item not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single resource library item by its numeric id, including its fields, status, version, and any associated structured form data.", "operationId": "getResourceItemOptions", "tags": [ "Resource Library" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "itemId", "schema": { "type": "number" }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/suppliers/suppliers": { "get": { "summary": "List suppliers", "description": "Lists suppliers in your Qualio instance filtered by status. Supplier Quality Management (SQM) maintains your approved vendor list and supplier qualification records â the external vendors and contractors your company assesses, approves, and monitors. Filter by status: `APPROVED`, `REVIEW_PENDING`, `REJECTED`, `DRAFT`, or `ARCHIVED`. Returns each supplier's id, name, status, assigned risk level, intended use, and contact details.", "operationId": "listSuppliers", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "status", "schema": { "type": "string", "enum": [ "REVIEW_PENDING", "APPROVED", "REJECTED", "DRAFT", "ARCHIVED" ] }, "required": true } ], "responses": { "200": { "description": "Successful retrieval of suppliers for a given status", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/supplierResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists suppliers in your Qualio instance filtered by status. Supplier Quality Management (SQM) maintains your approved vendor list and supplier qualification records â the external vendors and contractors your company assesses, approves, and monitors. Filter by status: `APPROVED`, `REVIEW_PENDING`, `REJECTED`, `DRAFT`, or `ARCHIVED`. Returns each supplier's id, name, status, assigned risk level, intended use, and contact details.", "operationId": "listSuppliersOptions", "tags": [ "Suppliers" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "status", "schema": { "type": "string", "enum": [ "REVIEW_PENDING", "APPROVED", "REJECTED", "DRAFT", "ARCHIVED" ] }, "required": true } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "post": { "summary": "Create a supplier", "description": "Creates a new supplier (vendor) record in Supplier Quality Management. Provide the name and, optionally, the intended use, sponsor, risk level (risk_id, from the risk-levels endpoint), and contact details. The supplier is created in a draft state and progresses through review and approval before becoming an approved vendor.", "operationId": "createSupplier", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createSupplier" } } } }, "responses": { "200": { "description": "Successful creation of supplier", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/supplier" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/suppliers/suppliers/{supplierId}": { "get": { "summary": "Retrieve a supplier", "description": "Retrieves a single supplier by its id, including name, status, assigned risk level, intended use, sponsor, approval date, and contact information.", "operationId": "getSupplier", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "supplierId", "schema": { "$ref": "#/components/schemas/supplierId" }, "required": true, "description": "A unique identifier for a supplier" } ], "responses": { "200": { "description": "Successful retrieval of supplier", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/supplier" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Supplier not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single supplier by its id, including name, status, assigned risk level, intended use, sponsor, approval date, and contact information.", "operationId": "getSupplierOptions", "tags": [ "Suppliers" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "supplierId", "schema": { "$ref": "#/components/schemas/supplierId" }, "required": true, "description": "A unique identifier for a supplier" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "put": { "summary": "Update a supplier", "description": "Updates an existing supplier, identified by its id. Replaces the supplier's editable details â name, intended use, sponsor, risk level (risk_id), and contact information.", "operationId": "updateSupplier", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "supplierId", "schema": { "$ref": "#/components/schemas/supplierId" }, "required": true, "description": "A unique identifier for a supplier" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/createSupplier" } } } }, "responses": { "200": { "description": "Successful update of a supplier", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/supplier" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Supplier not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/suppliers/risks": { "get": { "summary": "List risk levels", "description": "Lists the supplier risk levels configured for your company. Risk levels (e.g. High, Medium, Low) are company-defined ratings assigned to suppliers to reflect the risk they pose; each carries an id, title, description, and a periodic-review interval that drives how often the supplier should be re-audited. Use a risk level's id as the `risk_id` when creating or updating a supplier.", "operationId": "listSupplierRisks", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful retrieval of risks", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/risksResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the supplier risk levels configured for your company. Risk levels (e.g. High, Medium, Low) are company-defined ratings assigned to suppliers to reflect the risk they pose; each carries an id, title, description, and a periodic-review interval that drives how often the supplier should be re-audited. Use a risk level's id as the `risk_id` when creating or updating a supplier.", "operationId": "listSupplierRisksOptions", "tags": [ "Suppliers" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/suppliers/suppliers/{supplierId}/audits": { "get": { "summary": "List supplier audits", "description": "Lists the audits recorded against a supplier, identified by the supplier's id. Supplier audits capture your assessments of a vendor: each returns its id, name, type, status, planned/actual dates, owner, notes, and any attached documents. Deleted (archived) audits are not returned.", "operationId": "listSupplierAudits", "tags": [ "Suppliers" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "supplierId", "schema": { "$ref": "#/components/schemas/supplierId" }, "required": true, "description": "A unique identifier for a supplier" } ], "responses": { "200": { "description": "Successful retrieval of the supplier's audits", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/supplierAuditsResponse" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the audits recorded against a supplier, identified by the supplier's id. Supplier audits capture your assessments of a vendor: each returns its id, name, type, status, planned/actual dates, owner, notes, and any attached documents. Deleted (archived) audits are not returned.", "operationId": "listSupplierAuditsOptions", "tags": [ "Suppliers" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "supplierId", "schema": { "$ref": "#/components/schemas/supplierId" }, "required": true, "description": "A unique identifier for a supplier" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/tags/tags": { "get": { "summary": "List tags", "description": "Lists all tags defined for your Qualio instance. Tags are company-wide labels used to categorise and filter entities such as documents and quality events, and can also gate access to private documents. Each tag has an id and a name; the returned ids are the same tag ids that appear on documents and events, so use this endpoint to resolve a tag name to its id (or vice versa).", "operationId": "listTags", "tags": [ "Tags" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful retrieval of all tags", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/tagsResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists all tags defined for your Qualio instance. Tags are company-wide labels used to categorise and filter entities such as documents and quality events, and can also gate access to private documents. Each tag has an id and a name; the returned ids are the same tag ids that appear on documents and events, so use this endpoint to resolve a tag name to its id (or vice versa).", "operationId": "listTagsOptions", "tags": [ "Tags" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/training/user-training/query": { "get": { "summary": "Query training assignments", "description": "Queries user training assignments (also called training records, or the training matrix) across your Qualio instance. When a document that requires training becomes effective, Qualio assigns the relevant users the requirement to read and acknowledge it; this endpoint reports the state of those assignments. Each result links a user to a document and reports a computed status of `complete`, `due`, or `overdue`, along with the assigned, due, and completion dates. Use this to check training completion or find outstanding/overdue training. Filter by document_ids (training on specific documents) and/or group_ids (training for users in specific groups).", "operationId": "queryUserTraining", "tags": [ "Training" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "query", "name": "document_ids", "schema": { "$ref": "#/components/schemas/documentIds" }, "description": "A unique identifier for a document version, for which you want to query for user training sessions" }, { "in": "query", "name": "group_ids", "schema": { "$ref": "#/components/schemas/groupIds" }, "description": "A unique identifier for a user group, for whom you want to retrieve training sessions" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/trainingStatus" }, "description": "Filter by training status. 'overdue' returns assignments past their due date that are not yet complete. 'due' returns incomplete assignments that are not yet overdue. 'complete' returns completed assignments. Omit to return all assignments." }, { "in": "query", "name": "include_removed", "schema": { "$ref": "#/components/schemas/includeRemoved" }, "description": "When true, includes training assignments that were completed and subsequently unassigned. Defaults to false." }, { "in": "query", "name": "include_inactive_users", "schema": { "$ref": "#/components/schemas/includeInactiveUsers" }, "description": "When true, includes training records for users who are no longer active in the company. Defaults to false." } ], "responses": { "200": { "description": "Successful training query retrieval", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/trainingQueryResp" } } } }, "400": { "description": "The request has malformed query parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400ParametersResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Queries user training assignments (also called training records, or the training matrix) across your Qualio instance. When a document that requires training becomes effective, Qualio assigns the relevant users the requirement to read and acknowledge it; this endpoint reports the state of those assignments. Each result links a user to a document and reports a computed status of `complete`, `due`, or `overdue`, along with the assigned, due, and completion dates. Use this to check training completion or find outstanding/overdue training. Filter by document_ids (training on specific documents) and/or group_ids (training for users in specific groups).", "operationId": "queryUserTrainingOptions", "tags": [ "Training" ], "x-scalar-ignore": true, "parameters": [ { "in": "query", "name": "document_ids", "schema": { "$ref": "#/components/schemas/documentIds" }, "description": "A unique identifier for a document version, for which you want to query for user training sessions" }, { "in": "query", "name": "group_ids", "schema": { "$ref": "#/components/schemas/groupIds" }, "description": "A unique identifier for a user group, for whom you want to retrieve training sessions" }, { "in": "query", "name": "offset", "schema": { "$ref": "#/components/schemas/offsetParam" }, "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population" }, { "in": "query", "name": "limit", "schema": { "$ref": "#/components/schemas/limitParam" } }, { "in": "query", "name": "status", "schema": { "$ref": "#/components/schemas/trainingStatus" }, "description": "Filter by training status. 'overdue' returns assignments past their due date that are not yet complete. 'due' returns incomplete assignments that are not yet overdue. 'complete' returns completed assignments. Omit to return all assignments." }, { "in": "query", "name": "include_removed", "schema": { "$ref": "#/components/schemas/includeRemoved" }, "description": "When true, includes training assignments that were completed and subsequently unassigned. Defaults to false." }, { "in": "query", "name": "include_inactive_users", "schema": { "$ref": "#/components/schemas/includeInactiveUsers" }, "description": "When true, includes training records for users who are no longer active in the company. Defaults to false." } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/training/document/{documentId}/remind": { "put": { "summary": "Send training reminders", "description": "Send training reminders for a document to one or more users. Recipients can be specified by numeric user ID or email address. If no recipients are provided, reminders are sent to all users with incomplete training on the document.", "operationId": "sendTrainingReminders", "tags": [ "Training" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/trainingDocumentId" }, "required": true, "description": "A unique identifier for a document" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/trainingReminderRequest" } } } }, "responses": { "200": { "description": "Reminders sent", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/trainingReminderResponse" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Document not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Send training reminders for a document to one or more users. Recipients can be specified by numeric user ID or email address. If no recipients are provided, reminders are sent to all users with incomplete training on the document.", "operationId": "sendTrainingRemindersOptions", "tags": [ "Training" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "documentId", "schema": { "$ref": "#/components/schemas/trainingDocumentId" }, "required": true, "description": "A unique identifier for a document" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/user-management/invite": { "post": { "summary": "Invite a user", "description": "Invites a user to your Qualio instance. This will generate an email for them to accept the invite, whereupon they will be asked to set their name and password, etc", "operationId": "inviteUser", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/invite" } } } }, "responses": { "200": { "description": "Successful user invitation", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/user" } } } }, "400": { "description": "The request has malformed body", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Invites a user to your Qualio instance. This will generate an email for them to accept the invite, whereupon they will be asked to set their name and password, etc", "operationId": "inviteUserOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/user-management/users": { "get": { "summary": "List users", "description": "Retrieves all users in your Qualio instance, including each user's id, email, full name, role (`quality`, `normal`, or `basic`), admin flag, and invite status (`pending`, `accepted`, `declined`, `canceled`). Use this to look up a user's id from their email, or to audit who has access.", "operationId": "listUsers", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful retrieval of list of users", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/userList" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves all users in your Qualio instance, including each user's id, email, full name, role (`quality`, `normal`, or `basic`), admin flag, and invite status (`pending`, `accepted`, `declined`, `canceled`). Use this to look up a user's id from their email, or to audit who has access.", "operationId": "listUsersOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/user-management/user/{userId}": { "get": { "summary": "Retrieve a user", "description": "Retrieves a single user by id, including email, full name, role (`quality`, `normal`, or `basic`), admin flag, and invite status.", "operationId": "getUser", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "responses": { "200": { "description": "Successful user fetch", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/user" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "User not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves a single user by id, including email, full name, role (`quality`, `normal`, or `basic`), admin flag, and invite status.", "operationId": "getUserOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "delete": { "summary": "Remove a user", "description": "Removes a specific user from your Qualio instance. For this to complete successfully, the user must have no assignments remaining. The endpoint /v1/user-management/user/{userId}/assignments can be used to reassign all assignments to a new user. This requires admin permissions", "operationId": "deleteUser", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "responses": { "200": { "description": "Successful user removal", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/deleteUserResp" } } } }, "400": { "description": "User has assignments remaining that must be reassigned before removal", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "anyOf": [ { "$ref": "#/components/schemas/userHasAssignmentsError" }, { "$ref": "#/components/schemas/genericBadRequestResponse" } ], "example": { "message": "User has assignments remaining that must be reassigned before removal", "slug": "user_has_assignments", "assignments": { "document_owner": [ 101, 102, 103 ], "document_reviewer": [ 201, 202 ], "document_approver": [ 301 ], "event_owner": [ 401, 402 ], "task_owner": [ 501 ] } } } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "User not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/user-management/user/{userId}/assignments": { "put": { "summary": "Reassign user's assignments", "description": "Reassigns all entities associated with a user to a new owner. Works for a variety of entities including documents, events, tasks, etc. Requires admin permissions", "operationId": "reassignUserAssignments", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "requestBody": { "content": { "application/json": { "schema": { "$ref": "#/components/schemas/reassignmentRequest" } } } }, "responses": { "200": { "description": "Successful reassignment", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/reassignmentResponse" } } } }, "400": { "description": "The request has malformed body or parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequestResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "User not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Reassigns all entities associated with a user to a new owner. Works for a variety of entities including documents, events, tasks, etc. Requires admin permissions", "operationId": "reassignUserAssignmentsOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "get": { "summary": "List user's assignments", "description": "Retrieves all entity assignments for a specific user. Returns document, event, task, and other entity IDs where the user is assigned as owner, reviewer, or approver. Requires admin permissions", "operationId": "listUserAssignments", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" } ], "responses": { "200": { "description": "Successful retrieval of user assignments", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/userAssignmentMapping" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "User not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/user-management/groups": { "get": { "summary": "List groups", "description": "Lists the user groups defined in your Qualio instance, returning each group's id and name. Groups are named collections of users used to organise people (e.g. by team or function) and to assign or filter responsibilities such as document training in bulk. Use a group's id with the add/remove-user-to-group endpoints, or with the training query's group filter.", "operationId": "listGroups", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful retrieval of groups", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/groupList" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Lists the user groups defined in your Qualio instance, returning each group's id and name. Groups are named collections of users used to organise people (e.g. by team or function) and to assign or filter responsibilities such as document training in bulk. Use a group's id with the add/remove-user-to-group endpoints, or with the training query's group filter.", "operationId": "listGroupsOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } }, "/v1/user-management/groups/{groupId}/user/{userId}": { "put": { "summary": "Add user to group", "description": "Adds a user to a group within your Qualio instance. Requires admin permissions", "operationId": "addUserToGroup", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" }, { "in": "path", "name": "groupId", "schema": { "$ref": "#/components/schemas/groupId" }, "required": true, "description": "A unique identifier for a group in Qualio" } ], "responses": { "200": { "description": "User successfully added to group", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/userGroupResp" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Group not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Adds a user to a group within your Qualio instance. Requires admin permissions", "operationId": "addUserToGroupOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" }, { "in": "path", "name": "groupId", "schema": { "$ref": "#/components/schemas/groupId" }, "required": true, "description": "A unique identifier for a group in Qualio" } ], "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } }, "delete": { "summary": "Remove user from group", "description": "Removes a user from a group within your Qualio instance. Requires admin permissions", "operationId": "removeUserFromGroup", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "parameters": [ { "in": "path", "name": "userId", "schema": { "$ref": "#/components/schemas/userId" }, "required": true, "description": "A unique identifier for a user in Qualio" }, { "in": "path", "name": "groupId", "schema": { "$ref": "#/components/schemas/groupId" }, "required": true, "description": "A unique identifier for a group in Qualio" } ], "responses": { "200": { "description": "User successfully removed from group", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/userGroupRemoveResp" } } } }, "400": { "description": "The request has malformed path parameters", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericBadRequest400PathResponse" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "404": { "description": "Group not found", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/generic404" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } } }, "/v1/user-management/user/me": { "get": { "summary": "Retrieve the current user's id and name", "description": "Retrieves the currently logged in user's id and name.", "operationId": "getCurrentUser", "tags": [ "User Management" ], "security": [ { "api_key": [] } ], "responses": { "200": { "description": "Successful user fetch", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/me" } } } }, "403": { "description": "This API key is not allowed to perform this action, or the API key is incorrect", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/genericForbiddenResponse" } } } }, "429": { "description": "This API key has exceeded the fair usage policy in Qualio, and has it its requests restricted. This request has not been processed", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/throttledResponse" } } } } } }, "options": { "description": "Retrieves the currently logged in user's id and name.", "operationId": "getCurrentUserOptions", "tags": [ "User Management" ], "x-scalar-ignore": true, "responses": { "200": { "description": "Options 200", "headers": { "Access-Control-Allow-Origin": { "schema": { "type": "string" } }, "Access-Control-Allow-Headers": { "schema": { "type": "string" } }, "Access-Control-Allow-Methods": { "schema": { "type": "string" } }, "Content-Type": { "schema": { "type": "string" } }, "Content-Disposition": { "schema": { "type": "string" } } } } } } } }, "components": { "schemas": { "offsetParam": { "description": "A start point for the batch to be returned. For example, a value of 5 will start at the 6th element in the overall population", "example": 0, "type": "number" }, "limitParam": { "type": "number", "description": "The maximum number of results to return. This is typically used with offset to paginate results.", "example": 30 }, "userIdParam": { "description": "A unique identifier for a user in Qualio", "example": 12345, "type": "number" }, "startDateParam": { "description": "Filter results from this date onwards (ISO 8601 format)", "example": "2025-01-01T00:00:00Z", "type": "string" }, "endDateParam": { "description": "Filter results up to this date (ISO 8601 format)", "example": "2025-12-31T23:59:59Z", "type": "string" }, "statusParam": { "description": "The status of a domain object", "example": "Closed", "type": "string" }, "orderByParam": { "description": "The field to order the results by", "example": "created_date", "type": "string" }, "createCC": { "type": "object", "properties": { "document_id": { "type": "number" }, "sections": { "type": "array", "items": { "type": "object", "properties": { "content": { "type": "string" }, "position": { "type": "number" } }, "required": [ "content", "position" ] } } }, "required": [ "document_id", "sections" ], "description": "The request to create a change control, the sections must match those in the change control template, and position starts at 1", "example": { "document_id": 1, "sections": [ { "content": "This change is to our privacy policy to bring it in line with GDPR", "position": 1 }, { "content": "There is no impact to our other documented processes, and employees will be trained on this document before it becomes effective", "position": 2 } ] } }, "dcProductId": { "type": "string", "format": "uuid", "description": "A design control product id", "example": "123e4567-e89b-12d3-a456-426614174000" }, "testCaseId": { "type": "string", "format": "uuid", "description": "The unique identifier of the test case to update. This is the id returned when the test case was created.", "example": "123e4567-e89b-12d3-a456-426614174001" }, "requirementId": { "type": "string", "format": "uuid", "description": "The unique identifier of the requirement to update. This is the id returned when the requirement was created.", "example": "223e4567-e89b-12d3-a456-426614174002" }, "riskId": { "type": "string", "format": "uuid", "description": "The unique identifier of the risk to update. This is the id returned when the risk was created.", "example": "333e4567-e89b-12d3-a456-426614174003" }, "documentId": { "type": "number", "description": "A unique identifier for a document version", "example": 12345 }, "updateDocumentPayload": { "type": "object", "properties": { "quality_approver_user_ids": { "description": "The complete list of quality approver user IDs for this document. Replaces the current quality approvers. Omit to leave unchanged. Only permitted on draft documents.", "example": [ 1, 2 ], "type": "array", "items": { "type": "number" } }, "other_approver_user_ids": { "description": "The complete list of non-quality approver user IDs for this document. Replaces the current other approvers. Omit to leave unchanged. Only permitted on draft documents.", "example": [ 3, 4 ], "type": "array", "items": { "type": "number" } }, "reviewer_user_ids": { "description": "The complete list of reviewer user IDs for this document. Replaces the current reviewers. Omit to leave unchanged. Only permitted on draft documents.", "example": [ 5, 6 ], "type": "array", "items": { "type": "number" } }, "editor_user_ids": { "description": "The complete list of editor user IDs for this document. Replaces the current editors. Omit to leave unchanged. Only permitted on draft documents.", "example": [ 7, 8 ], "type": "array", "items": { "type": "number" } }, "tag_ids": { "description": "The complete list of tag IDs to apply to this document. Replaces the current tags. Omit to leave unchanged.", "example": [ 10, 11 ], "type": "array", "items": { "type": "number" } } }, "description": "A partial update to the people and tags on a draft document. Supply only the fields you want to change â omitted fields are left unchanged. Each supplied list fully replaces the current set for that role.", "example": { "quality_approver_user_ids": [ 1, 2 ], "other_approver_user_ids": [ 3, 4 ], "reviewer_user_ids": [ 5, 6 ], "editor_user_ids": [ 7, 8 ], "tag_ids": [ 10, 11 ] } }, "updateDocumentContentPayload": { "type": "object", "properties": { "sections": { "type": "array", "items": { "type": "object", "properties": { "position": { "type": "number", "description": "The 1-indexed position of the section within the document, as defined by the document template. Sections not included in the request are left unchanged.", "example": 1 }, "content": { "type": "string", "description": "The new HTML content for the section. Must be valid HTML. Plain text is also accepted and will be stored as-is.", "example": "
Updated section content.
" } }, "required": [ "position", "content" ] }, "description": "A list of sections to update, identified by position. Only the sections included here are modified; all other sections retain their existing content. To update all sections, include every section position defined by the document template." } }, "required": [ "sections" ], "description": "A partial update to the HTML section content of a draft document. Only sections included in the request are modified; all other sections retain their existing content.", "example": { "sections": [ { "position": 1, "content": "At Acme Medical Software, we recognize that the security of our software systems is critical to ensuring the safety, privacy, and trust of patients and regulatory stakeholders.
" } ] } }, "changeDocumentStatusPayload": { "type": "object", "properties": { "status": { "type": "string", "enum": [ "draft", "for_review", "for_approval", "deleted" ], "description": "The target lifecycle status for the document. Only transitions that do not require electronic signature are supported. Invalid or esign-required transitions are rejected with a 400. Common sequences: draft to for_review, draft to for_approval, for_review to for_approval. Reverting to draft is supported from for_review, for_approval, and approval_declined.", "example": "for_review" }, "comment": { "description": "An optional comment to record alongside the status change, visible in the document's audit trail.", "example": "Reviewed by legal, ready for approval.", "type": "string" } }, "required": [ "status" ], "description": "A request to advance or revert the lifecycle status of a draft document.", "example": { "status": "for_review", "comment": "Reviewed by legal â ready for sign-off." } }, "documentCode": { "type": "string", "description": "A unique code identifier for a document (e.g. SOP-1, POL-42)", "example": "SOP-1" }, "documentStatus": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ], "description": "The different states of a document in Qualio", "example": "effective" }, "attachmentId": { "type": "number", "description": "A unique identifier for an attachment", "example": 1 }, "createDocumentPayload": { "type": "object", "properties": { "template_matrix_id": { "type": "string" }, "title": { "type": "string" }, "effective_on_approval": { "type": "boolean" }, "training_required": { "type": "boolean" }, "approver_user_ids": { "type": "array", "items": { "type": "number" } }, "reviewer_user_ids": { "type": "array", "items": { "type": "number" } }, "editor_user_ids": { "type": "array", "items": { "type": "number" } }, "sections": { "type": "array", "items": { "type": "object", "properties": { "content": { "type": "string" }, "position": { "type": "number" } }, "required": [ "content", "position" ] } } }, "required": [ "template_matrix_id", "title", "effective_on_approval", "training_required", "sections" ], "description": "A request to create a new draft document. The template matrix id determines the type of the document created. Section positions start at 1, and the number of sections must not exceed what is defined in the corresponding template", "example": { "title": "Security Policy", "sections": [ { "content": "This is the content in the first section of the document", "position": 1 } ], "template_matrix_id": "sdfsdf-sdfsdf-sdcvvv-vcvc", "effective_on_approval": false, "training_required": false, "approver_user_ids": [ 1, 2 ], "editor_user_ids": [ 3, 4 ] } }, "eventCode": { "type": "string", "description": "A unique identifier for an Event, that includes a prefix that corresponds to its type", "example": "CAPA-1" }, "eventStatus": { "type": "string", "enum": [ "closed", "open", "imported", "rejected", "cancelled" ], "description": "The status of a given event", "example": "open" }, "eventTemplateMatrixIdParam": { "description": "A unique identifier for an event template in Qualio, use this to filter the results by event type", "example": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "type": "string", "format": "uuid" }, "createEventPayload": { "type": "object", "properties": { "event_template_matrix_id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "description": { "type": "string", "maxLength": 512 }, "steps": { "type": "array", "items": { "anyOf": [ { "$ref": "#/components/schemas/createEventFormStep" }, { "$ref": "#/components/schemas/createEventContentStep" }, { "$ref": "#/components/schemas/createEventTaskStep" } ] } } }, "required": [ "event_template_matrix_id", "title" ], "description": "A request to create an event based on an event template. The event_template_matrix_id should correspond to the type of event you wish to create, which can be found on the response from querying templates. If you wish to populate values within the steps, use template_step_matrix_id from the desired step in the template, Then use field_matrix_id from the template to select what field to populate (form steps), or section_id from the template to select what section to populate (content steps).You do not have to set all of the fields or sections for your request to be valid, these can be completed later in the UI.If populating a field of type change_request, product, root_cause, registry, design_controls, training_plan, document_template, event_template, or task, you can use the code (ID visible in the UI) to populate the field.For the users field, you can use the email address of the user to populate the field. For suppliers, you can use the supplier name. You will see examples of these in the sample code.The event will be created with the owner set to the default owner for the event template, if available, and will list the API key user otherwise.", "example": { "title": "Non Compliance: procedure was not followed", "description": "An incidence of a non compliance with a work instuction, procedure or policy", "event_template_matrix_id": "c3e000df-4e7e-4916-b5dc-b236a83b3fe5", "steps": [ { "template_step_matrix_id": "a1b2c3d4-e5f6-4789-a012-b3c4d5e6f789", "sections": [ { "template_section_id": 1, "content": "This Non-Compliance Report (NCR) documents a deviation from standard operating procedures." } ] }, { "template_step_matrix_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "fields": [ { "field_matrix_id": "c3d4e5f6-a7b8-4901-c234-d5e6f7a8b901", "values": [ "Procedure was not followed during assembly" ] }, { "field_matrix_id": "d4e5f6a7-b8c9-4012-d345-e6f7a8b9c012", "values": [ "Minor" ] }, { "field_matrix_id": "e5f6a7b8-c9d0-4123-e456-f7a8b9c0d123", "values": [ "2025-01-01" ] }, { "field_matrix_id": "f6a7b8c9-d0e1-4234-f567-a8b9c0d1e234", "values": [ "Manufacturing" ] }, { "field_matrix_id": "a7b8c9d0-e1f2-4345-a678-b9c0d1e2f345", "values": [ "true" ] }, { "field_matrix_id": "b8c9d0e1-f2a3-4456-b789-c0d1e2f3a456", "values": [ "Product A", "Product B", "Product C", "Product D" ] }, { "field_matrix_id": "c9d0e1f2-a3b4-4567-c890-d1e2f3a4b567", "values": [ "123456" ] }, { "field_matrix_id": "d0e1f2a3-b4c5-4678-d901-e2f3a4b5c678", "values": [ "1000.75" ] }, { "field_matrix_id": "fdd7d0fa-d9b0-11f0-a30a-be7f281741c5", "values": [ "INC-123", "INC-999" ] }, { "field_matrix_id": "db423422-d9b0-11f0-a30a-be7f281741c5", "values": [ "manager1@qualio.com", "manager2@qualio.com" ] } ] }, { "template_step_matrix_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "tasks": [ { "title": "Investigate root cause", "description": "Determine the underlying cause of the non-compliance.", "owner_user_id": 2, "time_limit_days": 10 } ] } ] } }, "createEventFormStep": { "type": "object", "properties": { "template_step_matrix_id": { "type": "string", "format": "uuid" }, "fields": { "type": "array", "items": { "type": "object", "properties": { "field_matrix_id": { "type": "string", "format": "uuid" }, "values": { "type": "array", "items": { "type": "string" } } }, "required": [ "field_matrix_id", "values" ] } } }, "required": [ "template_step_matrix_id", "fields" ], "description": "A object containing form fields to populate" }, "createEventContentStep": { "type": "object", "properties": { "template_step_matrix_id": { "type": "string", "format": "uuid" }, "sections": { "type": "array", "items": { "type": "object", "properties": { "template_section_id": { "type": "number" }, "content": { "type": "string" } }, "required": [ "template_section_id", "content" ] } } }, "required": [ "template_step_matrix_id", "sections" ], "description": "A object containing content sections to populate" }, "createEventTaskStep": { "type": "object", "properties": { "template_step_matrix_id": { "type": "string", "format": "uuid" }, "tasks": { "type": "array", "items": { "type": "object", "properties": { "title": { "type": "string" }, "description": { "type": "string" }, "owner_user_id": { "type": "number" }, "time_limit_days": { "type": "number", "minimum": 1, "maximum": 999999999 } }, "required": [ "title", "description", "owner_user_id", "time_limit_days" ] } } }, "required": [ "template_step_matrix_id", "tasks" ], "description": "A object containing tasks to create on the step" }, "orderBy": { "description": "A property to order the results by", "example": "name", "type": "string", "enum": [ "name" ] }, "query": { "description": "A search query to filter the results by", "example": "test", "type": "string" }, "status": { "type": "string", "enum": [ "effective", "archived", "superseded", "draft" ], "description": "A status to filter the results by", "example": "effective" }, "createResourceLibraryItem": { "type": "object", "properties": { "template_matrix_id": { "type": "string" }, "name": { "type": "string" }, "description": { "type": "string" }, "display_id": { "type": "string" } }, "required": [ "template_matrix_id", "name", "display_id" ], "description": "A resource library item. display_id is what will show as 'ID' in the UI and must be unique.", "example": { "template_matrix_id": "aaaa-bbbb-cccc-dddd", "name": "My Resource Library Item", "description": "Test description", "display_id": "RES-10" } }, "createSupplier": { "type": "object", "properties": { "name": { "type": "string" }, "contact_information": { "type": "object", "properties": { "name": { "type": "string" }, "email": { "type": "string" }, "phone": { "type": "string" }, "address": { "type": "string" }, "website": { "type": "string" }, "notes": { "type": "string" } } }, "intended_use": { "type": "string" }, "sponsor_user_id": { "type": "number" }, "risk_id": { "type": "string", "format": "uuid" } }, "required": [ "name" ], "description": "A request to create a new supplier, or update an existing one", "example": { "name": "Acme", "intended_use": "Chemical reagents only", "contact_information": { "name": "Mr Acme", "email": "info@acme.com", "address": "1 Acme st, Acme, NY", "notes": "Call in emergency only", "phone": "555-1234-345" }, "sponsor_user_id": 999, "risk_id": "458bf34c-8ee1-475f-8c4c-ae735518991a" } }, "supplierId": { "type": "string", "description": "A unique identifier for a supplier", "example": "qwerty-qwerty-qwerty-qwerty" }, "documentIds": { "description": "A unique identifier for a document version, for which you want to query for user training sessions", "example": [ 1, 2, 3 ], "type": "array", "items": { "type": "number" } }, "groupIds": { "description": "A unique identifier for a user group, for whom you want to retrieve training sessions", "example": [ 1, 2, 3 ], "type": "array", "items": { "type": "number" } }, "trainingStatus": { "description": "Filter by training status. 'overdue' returns assignments past their due date that are not yet complete. 'due' returns incomplete assignments that are not yet overdue. 'complete' returns completed assignments. Omit to return all assignments.", "example": "overdue", "type": "string", "enum": [ "due", "overdue", "complete" ] }, "includeRemoved": { "description": "When true, includes training assignments that were completed and subsequently unassigned. Defaults to false.", "example": false, "type": "boolean" }, "includeInactiveUsers": { "description": "When true, includes training records for users who are no longer active in the company. Defaults to false.", "example": false, "type": "boolean" }, "trainingDocumentId": { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991, "description": "A unique identifier for a document", "example": 12345 }, "trainingReminderRequest": { "type": "object", "properties": { "to": { "type": "array", "items": { "anyOf": [ { "type": "integer", "exclusiveMinimum": 0, "maximum": 9007199254740991 }, { "type": "string" } ] } } }, "description": "Training reminder request body", "example": { "to": [ 1224, "user@example.com" ] } }, "invite": { "type": "object", "properties": { "email": { "type": "string" }, "role": { "type": "string", "enum": [ "quality", "normal", "basic" ] }, "can_access_billing": { "type": "boolean" }, "is_admin": { "type": "boolean" } }, "required": [ "email", "role" ], "description": "An invite for a user to join your Qualio instance", "example": { "email": "testuser1@example.com", "role": "quality", "is_admin": false, "can_access_billing": false } }, "userId": { "type": "number", "description": "A unique identifier for a user in Qualio", "example": 12345 }, "reassignmentRequest": { "type": "object", "properties": { "destination_user_id": { "type": "number" }, "reassignments": { "type": "object", "properties": { "document_owner": { "type": "array", "items": { "type": "number" } }, "document_reviewer": { "type": "array", "items": { "type": "number" } }, "document_approver": { "type": "array", "items": { "type": "number" } }, "event_owner": { "type": "array", "items": { "type": "number" } }, "event_template_owner": { "type": "array", "items": { "type": "number" } }, "event_template_default_owner": { "type": "array", "items": { "type": "number" } }, "change_request_owner": { "type": "array", "items": { "type": "number" } }, "task_owner": { "type": "array", "items": { "type": "number" } }, "doc_template_owner": { "type": "array", "items": { "type": "number" } } } } }, "required": [ "destination_user_id", "reassignments" ], "description": "A request to reassign all entities from one user to another", "example": { "destination_user_id": 67890, "reassignments": { "document_owner": [ 101, 102 ], "event_owner": [ 103 ] } } }, "groupId": { "type": "number", "description": "A unique identifier for a group in Qualio", "example": 1 }, "auditTrailResp": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "date": { "type": "string" }, "target": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "audit_id": { "type": "string" }, "action": { "type": "string" }, "user_id": { "anyOf": [ { "type": "number" }, { "type": "null" } ] } }, "required": [ "date", "target", "audit_id", "action", "user_id" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A series of audit trail entries", "example": { "items": [ { "date": "2025-05-01T14:48:43.472Z", "target": "POL-1 Security Policy v1.0", "audit_id": "document-aaaa04f1-01a9-43a8-ab9f-ac5c7dd1ec5c", "action": "Approved", "user_id": 99 } ], "total": 1 } }, "genericBadRequest400ParametersResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "description": { "type": "string" }, "location": { "type": "string" }, "name": { "type": "string" } }, "required": [ "description" ], "additionalProperties": false } }, "status": { "type": "string", "const": "error" } }, "required": [ "errors", "status" ], "additionalProperties": false, "example": { "status": "error", "errors": [ { "location": "query", "name": "document_id", "description": "document_id is not an integer" } ] } }, "genericForbiddenResponse": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "example": { "message": "User is not authorized to access this resource with an explicit deny" } }, "throttledResponse": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "example": { "message": "You have exceeded what is allowed in the fair use policy for this API" } }, "changeControlResp": { "type": "object", "properties": { "total": { "type": "number" }, "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string" }, "title": { "type": "string" }, "status": { "type": "string" }, "owner": { "type": "string" }, "created_time": { "type": "string", "format": "date-time" }, "closed_time": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "change_items": { "type": "array", "items": { "type": "object", "properties": { "title": { "type": "string" }, "code": { "type": "string" }, "version": { "type": "string" }, "type": { "type": "string", "enum": [ "document", "supplier", "event" ] } }, "required": [ "title", "code", "version", "type" ], "additionalProperties": false } } }, "required": [ "id", "title", "status", "owner", "created_time", "closed_time", "change_items" ], "additionalProperties": false } } }, "required": [ "total", "items" ], "additionalProperties": false, "description": "A series of change control entries", "example": { "total": 1, "items": [ { "id": "CC-1-123", "title": "Test Change Control", "status": "open", "created_time": "2024-07-30T18:00:00.000Z", "closed_time": "2024-07-29T18:00:00.000Z", "owner": "Kai Havertz", "change_items": [ { "title": "Test Policy", "code": "POL-1", "version": "1.0", "type": "document" } ] } ] } }, "createdCC": { "type": "object", "properties": { "id": { "type": "string" }, "title": { "type": "string" }, "status": { "type": "string" }, "owner": { "type": "string" }, "created_time": { "type": "string", "format": "date-time" }, "closed_time": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "change_items": { "type": "array", "items": { "type": "object", "properties": { "title": { "type": "string" }, "code": { "type": "string" }, "version": { "type": "string" }, "type": { "type": "string", "enum": [ "document", "supplier", "event" ] } }, "required": [ "title", "code", "version", "type" ], "additionalProperties": false } } }, "required": [ "id", "title", "status", "owner", "created_time", "closed_time", "change_items" ], "additionalProperties": false, "description": "A successfully created change control", "example": { "id": "CC-1-123", "title": "Test Change Control", "status": "open", "created_time": "2024-07-30T18:00:00.000Z", "closed_time": "2024-07-29T18:00:00.000Z", "owner": "Kai Havertz", "change_items": [ { "title": "Test Policy", "code": "POL-1", "version": "1.0", "type": "document" } ] } }, "genericBadRequestResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "description": { "type": "string" }, "location": { "type": "string" }, "name": { "type": "string" } }, "required": [ "description" ], "additionalProperties": false } }, "status": { "type": "string", "const": "error" } }, "required": [ "errors", "status" ], "additionalProperties": false, "example": { "status": "error", "errors": [ { "location": "body", "name": "email", "description": "Email missing from payload" } ] } }, "changeRequestResp": { "type": "object", "properties": { "total": { "type": "number" }, "items": { "type": "array", "items": { "type": "object", "properties": { "code": { "type": "string" }, "title": { "type": "string" }, "status": { "type": "string" }, "owner": { "type": "string" }, "created_time": { "type": "string", "format": "date-time" }, "closed_time": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "change_items": { "type": "array", "items": { "type": "object", "properties": { "title": { "type": "string" }, "code": { "type": "string" }, "version": { "type": "string" }, "type": { "type": "string", "enum": [ "document", "supplier", "event" ] } }, "required": [ "title", "code", "version", "type" ], "additionalProperties": false } } }, "required": [ "code", "title", "status", "owner", "created_time", "closed_time", "change_items" ], "additionalProperties": false } } }, "required": [ "total", "items" ], "additionalProperties": false, "description": "A paginated list of change requests", "example": { "total": 1, "items": [ { "code": "DCR-1", "title": "Update Privacy Policy", "status": "in_progress", "owner": "John Smith", "created_time": "2024-07-30T18:00:00.000Z", "closed_time": null, "change_items": [ { "title": "Privacy Policy", "code": "POL-1", "version": "2.0", "type": "document" } ] } ] } }, "genericBadRequest400PathResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "description": { "type": "string" }, "location": { "type": "string" }, "name": { "type": "string" } }, "required": [ "description" ], "additionalProperties": false } }, "status": { "type": "string", "const": "error" } }, "required": [ "errors", "status" ], "additionalProperties": false, "example": { "status": "error", "errors": [ { "location": "path", "name": "user_id", "description": "user_id is not an integer" } ] } }, "generic404": { "anyOf": [ { "type": "object", "properties": {}, "additionalProperties": false }, { "type": "null" } ], "description": "A generic response when a resource can't be found", "example": {} }, "testCaseConflictResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "field": { "type": "string" }, "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false }, "description": "One or more error objects describing the conflict. The field property identifies which request field caused the conflict." } }, "required": [ "errors" ], "additionalProperties": false, "example": { "errors": [ { "field": "id", "message": "A test case with this id already exists" } ] } }, "requirementConflictResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "field": { "type": "string" }, "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false }, "description": "One or more error objects describing the conflict. The field property identifies which request field caused the conflict." } }, "required": [ "errors" ], "additionalProperties": false, "example": { "errors": [ { "field": "id", "message": "A requirement with this id already exists" } ] } }, "riskConflictResponse": { "type": "object", "properties": { "errors": { "type": "array", "items": { "type": "object", "properties": { "field": { "type": "string" }, "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false }, "description": "One or more error objects describing the conflict. The field property identifies which request field caused the conflict." } }, "required": [ "errors" ], "additionalProperties": false, "example": { "errors": [ { "field": "id", "message": "A risk with this id already exists" } ] } }, "documentDetailed": { "type": "object", "properties": { "document_id": { "type": "number" }, "status": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, "code": { "type": "string" }, "type": { "type": "string" }, "document_format": { "type": "string", "enum": [ "qualio_document", "file_document" ], "description": "The format of the document. `qualio_document` is a native Qualio document with section-based content; `file_document` is a document whose main content is an uploaded file", "example": "qualio_document" }, "title": { "type": "string" }, "version": { "type": "string" }, "document_matrix_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "created_at": { "type": "string", "format": "date-time" }, "effective_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "type": "string", "format": "date-time" }, "url": { "type": "string" }, "next_periodic_review_due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "effective_upon_approval": { "type": "boolean" }, "owner_user_id": { "type": "number" }, "tag_ids": { "type": "array", "items": { "type": "number" } }, "reviewers": { "type": "array", "items": { "type": "object", "properties": { "type": { "type": "string" }, "user_id": { "type": "number" }, "is_done": { "type": "boolean" }, "done_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "type", "user_id", "is_done", "done_at" ], "additionalProperties": false } }, "approvers": { "type": "array", "items": { "type": "object", "properties": { "type": { "type": "string" }, "user_id": { "type": "number" }, "is_done": { "type": "boolean" }, "done_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "type", "user_id", "is_done", "done_at" ], "additionalProperties": false } }, "editors": { "type": "array", "items": { "type": "object", "properties": { "type": { "type": "string" }, "user_id": { "type": "number" }, "is_done": { "type": "boolean" }, "done_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "type", "user_id", "is_done", "done_at" ], "additionalProperties": false } } }, "required": [ "document_id", "status", "code", "type", "document_format", "title", "version", "document_matrix_id", "created_at", "effective_at", "modified_at", "url", "next_periodic_review_due_at", "effective_upon_approval", "owner_user_id", "tag_ids", "reviewers", "approvers", "editors" ], "additionalProperties": false, "description": "A Qualio document version, with additional details", "example": { "document_id": 1, "status": "effective", "code": "POL-1", "type": "Policy", "document_format": "qualio_document", "title": "Security policy", "version": "1.0", "document_matrix_id": "40a6a13f-f227-4274-807f-694a4d90f175", "created_at": "2025-05-01T14:48:43.472Z", "effective_at": "2025-05-07T14:48:43.472Z", "modified_at": "2025-05-07T14:48:43.472Z", "url": "https://app.qualio.com/library/documents/1", "next_periodic_review_due_at": "2025-07-07T14:48:43.472Z", "effective_upon_approval": false, "owner_user_id": 9981, "tag_ids": [ 12, 13, 14 ], "reviewers": [ { "type": "review", "user_id": 1, "is_done": true, "done_at": "2025-07-07T14:48:43.472Z" } ], "approvers": [ { "type": "approve", "user_id": 1, "is_done": false, "done_at": null } ], "editors": [ { "type": "edit", "user_id": 1, "is_done": false, "done_at": null } ] } }, "documentContentResponse": { "type": "object", "properties": { "sections": { "type": "array", "items": { "type": "object", "properties": { "content": { "type": "string", "description": "The section content as HTML." }, "position": { "type": "number" }, "title": { "type": "string" }, "attachments": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "filename": { "type": "string" } }, "required": [ "id", "filename" ], "additionalProperties": false }, "description": "Attachments referenced within this section's content. Use `GET /v1/documents/attachments/{id}` to retrieve an attachment's full metadata or download it." } }, "required": [ "content", "position", "title", "attachments" ], "additionalProperties": false } } }, "required": [ "sections" ], "additionalProperties": false, "description": "The content of a particular Qualio document version", "example": { "sections": [ { "title": "Introduction", "position": 1, "content": "At Acme Medical Software, we recognize that the security of our software systems is critical to ensuring the safety, privacy, and trust of patients, healthcare providers, and regulatory stakeholders.
", "attachments": [] }, { "title": "Purpose", "position": 2, "content": "The purpose of this Security Policy is to:
This policy applies to all employees, contractors, and systems handling company or customer data.
Access to systems shall be granted on a least-privilege basis and reviewed quarterly.
", "attachments": [ { "id": 1, "filename": "Policy.docx" } ] } ] } }, "documentStatusChangeResponse": { "type": "object", "properties": { "document_id": { "type": "number" }, "status": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, "code": { "type": "string" }, "type": { "type": "string" }, "document_format": { "type": "string", "enum": [ "qualio_document", "file_document" ], "description": "The format of the document. `qualio_document` is a native Qualio document with section-based content; `file_document` is a document whose main content is an uploaded file", "example": "qualio_document" }, "title": { "type": "string" }, "version": { "type": "string" }, "document_matrix_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "created_at": { "type": "string", "format": "date-time" }, "effective_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "type": "string", "format": "date-time" }, "url": { "type": "string" }, "next_periodic_review_due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "effective_upon_approval": { "type": "boolean" } }, "required": [ "document_id", "status", "code", "type", "document_format", "title", "version", "document_matrix_id", "created_at", "effective_at", "modified_at", "url", "next_periodic_review_due_at", "effective_upon_approval" ], "additionalProperties": false, "description": "The document with its updated status and key metadata, confirming the transition completed", "example": { "document_id": 1, "status": "effective", "code": "POL-1", "type": "Policy", "document_format": "qualio_document", "title": "Security policy", "version": "1.0", "document_matrix_id": "40a6a13f-f227-4274-807f-694a4d90f175", "created_at": "2025-05-01T14:48:43.472Z", "effective_at": "2025-05-07T14:48:43.472Z", "modified_at": "2025-05-07T14:48:43.472Z", "url": "https://app.qualio.com/library/documents/1", "next_periodic_review_due_at": "2025-07-07T14:48:43.472Z", "effective_upon_approval": false } }, "documentVersionsResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "document_id": { "type": "number" }, "status": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, "code": { "type": "string" }, "type": { "type": "string" }, "document_format": { "type": "string", "enum": [ "qualio_document", "file_document" ], "description": "The format of the document. `qualio_document` is a native Qualio document with section-based content; `file_document` is a document whose main content is an uploaded file", "example": "qualio_document" }, "title": { "type": "string" }, "version": { "type": "string" }, "document_matrix_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "created_at": { "type": "string", "format": "date-time" }, "effective_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "type": "string", "format": "date-time" }, "url": { "type": "string" }, "next_periodic_review_due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "effective_upon_approval": { "type": "boolean" } }, "required": [ "document_id", "status", "code", "type", "document_format", "title", "version", "document_matrix_id", "created_at", "effective_at", "modified_at", "url", "next_periodic_review_due_at", "effective_upon_approval" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "All versions of a Qualio document, with a summary of each version", "example": { "items": [ { "document_id": 1, "status": "effective", "code": "POL-1", "type": "Policy", "document_format": "qualio_document", "title": "Security policy", "version": "1.0", "document_matrix_id": "40a6a13f-f227-4274-807f-694a4d90f175", "created_at": "2025-05-01T14:48:43.472Z", "effective_at": "2025-05-07T14:48:43.472Z", "modified_at": "2025-05-07T14:48:43.472Z", "url": "https://app.qualio.com/library/documents/1", "next_periodic_review_due_at": "2025-07-07T14:48:43.472Z", "effective_upon_approval": false } ], "total": 1 } }, "documentCommentsResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string" }, "type": { "type": "string", "enum": [ "comment", "suggestion" ] }, "status": { "type": "string", "enum": [ "Open", "Resolved", "Removed", "Accepted", "Rejected" ] }, "content": { "type": "string" }, "created_at": { "type": "string", "format": "date-time" }, "author_full_name": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "content_commented_on": { "anyOf": [ { "type": "array", "items": { "type": "object", "properties": { "name": { "type": "string" }, "data": { "type": "string" } }, "required": [ "name", "data" ], "additionalProperties": false } }, { "type": "null" } ] }, "last_updated_time": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "replies": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string" }, "content": { "type": "string" }, "created_at": { "type": "string", "format": "date-time" }, "author_full_name": { "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "id", "content", "created_at" ], "additionalProperties": false } } }, "required": [ "id", "type", "status", "content", "created_at", "replies" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "The comment threads on a Qualio document version", "example": { "items": [ { "id": "c1a2b3c4-0001-4000-8000-000000000001", "type": "comment", "status": "Open", "content": "Please clarify the retention period referenced in section 2.", "created_at": "2025-06-01T09:15:00.000Z", "author_full_name": "Jane Doe", "content_commented_on": [ { "name": "Section 2", "data": "retention period of 7 years" } ], "last_updated_time": "2025-06-01T09:15:00.000Z", "replies": [ { "id": "c1a2b3c4-0002-4000-8000-000000000002", "content": "Updated to 10 years per legal guidance.", "created_at": "2025-06-01T10:00:00.000Z", "author_full_name": "John Smith" } ] } ], "total": 1 } }, "documentSummaryResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "document_id": { "type": "number" }, "status": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, "code": { "type": "string" }, "type": { "type": "string" }, "document_format": { "type": "string", "enum": [ "qualio_document", "file_document" ], "description": "The format of the document. `qualio_document` is a native Qualio document with section-based content; `file_document` is a document whose main content is an uploaded file", "example": "qualio_document" }, "title": { "type": "string" }, "version": { "type": "string" }, "document_matrix_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "created_at": { "type": "string", "format": "date-time" }, "effective_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "type": "string", "format": "date-time" }, "url": { "type": "string" }, "next_periodic_review_due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "effective_upon_approval": { "type": "boolean" } }, "required": [ "document_id", "status", "code", "type", "document_format", "title", "version", "document_matrix_id", "created_at", "effective_at", "modified_at", "url", "next_periodic_review_due_at", "effective_upon_approval" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A summary of the main attributes of a Qualio document version", "example": { "items": [ { "document_id": 1, "status": "effective", "code": "POL-1", "type": "Policy", "document_format": "qualio_document", "title": "Security policy", "version": "1.0", "document_matrix_id": "40a6a13f-f227-4274-807f-694a4d90f175", "created_at": "2025-05-01T14:48:43.472Z", "effective_at": "2025-05-07T14:48:43.472Z", "modified_at": "2025-05-07T14:48:43.472Z", "url": "https://app.qualio.com/library/documents/1", "next_periodic_review_due_at": "2025-07-07T14:48:43.472Z", "effective_upon_approval": false } ], "total": 1 } }, "documentTemplatesQueryResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "name": { "type": "string" }, "prefix": { "type": "string" }, "template_matrix_id": { "type": "string" }, "status": { "type": "string" } }, "required": [ "id", "name", "prefix", "template_matrix_id", "status" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A list of document templates", "example": { "items": [ { "id": 1, "name": "Policy", "prefix": "POL", "template_matrix_id": "sdfsdf-sdfsdf-sdcvvv-vcvc", "status": "effective" } ], "total": 1 } }, "documentTemplateResponse": { "type": "object", "properties": { "id": { "type": "number" }, "name": { "type": "string" }, "prefix": { "type": "string" }, "template_matrix_id": { "type": "string" }, "status": { "type": "string" } }, "required": [ "id", "name", "prefix", "template_matrix_id", "status" ], "additionalProperties": false, "description": "A document template", "example": { "id": 1, "name": "Policy", "prefix": "POL", "template_matrix_id": "sdfsdf-sdfsdf-sdcvvv-vcvc", "status": "effective" } }, "documentTemplateContentResponse": { "type": "object", "properties": { "sections": { "type": "array", "items": { "type": "object", "properties": { "content": { "type": "string", "description": "The section content as HTML." }, "position": { "type": "number" }, "title": { "type": "string" } }, "required": [ "content", "position", "title" ], "additionalProperties": false } } }, "required": [ "sections" ], "additionalProperties": false, "description": "The content of a document template", "example": { "sections": [ { "title": "Introduction", "position": 1, "content": "At Acme Medical Software, we recognize that the security of our software systems is critical to ensuring the safety, privacy, and trust of patients, healthcare providers, and regulatory stakeholders.
" }, { "title": "Purpose", "position": 2, "content": "The purpose of this Security Policy is to:
This policy applies to all employees, contractors, and systems handling company or customer data.
Access to systems shall be granted on a least-privilege basis and reviewed quarterly.
" } ] } }, "attachment": { "type": "object", "properties": { "id": { "type": "number" }, "filename": { "type": "string" }, "date_added": { "type": "number" }, "file_size": { "anyOf": [ { "type": "number" }, { "type": "null" } ] } }, "required": [ "id", "filename", "date_added", "file_size" ], "additionalProperties": false, "description": "Metadata for a Qualio attachment", "example": { "id": 1, "filename": "attachment.docx", "date_added": 1782415612, "file_size": 100000 } }, "createDocumentResponse": { "type": "object", "properties": { "document_id": { "type": "number" }, "status": { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, "code": { "type": "string" }, "type": { "type": "string" }, "document_format": { "type": "string", "enum": [ "qualio_document", "file_document" ], "description": "The format of the document. `qualio_document` is a native Qualio document with section-based content; `file_document` is a document whose main content is an uploaded file", "example": "qualio_document" }, "title": { "type": "string" }, "version": { "type": "string" }, "document_matrix_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "created_at": { "type": "string", "format": "date-time" }, "effective_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "type": "string", "format": "date-time" }, "url": { "type": "string" }, "next_periodic_review_due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "effective_upon_approval": { "type": "boolean" } }, "required": [ "document_id", "status", "code", "type", "document_format", "title", "version", "document_matrix_id", "created_at", "effective_at", "modified_at", "url", "next_periodic_review_due_at", "effective_upon_approval" ], "additionalProperties": false, "description": "The newly created draft document, including its generated identifiers (document_id, code) and url", "example": { "document_id": 1, "status": "effective", "code": "POL-1", "type": "Policy", "document_format": "qualio_document", "title": "Security policy", "version": "1.0", "document_matrix_id": "40a6a13f-f227-4274-807f-694a4d90f175", "created_at": "2025-05-01T14:48:43.472Z", "effective_at": "2025-05-07T14:48:43.472Z", "modified_at": "2025-05-07T14:48:43.472Z", "url": "https://app.qualio.com/library/documents/1", "next_periodic_review_due_at": "2025-07-07T14:48:43.472Z", "effective_upon_approval": false } }, "eventDetailed": { "type": "object", "properties": { "code": { "type": "string" }, "title": { "type": "string" }, "description": { "type": "string" }, "status": { "type": "string", "enum": [ "closed", "open", "imported", "rejected", "cancelled" ] }, "url": { "type": "string" }, "owner_user_id": { "type": "number" }, "created_at": { "type": "string", "format": "date-time" }, "due_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "closed_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "risk": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "escalated_from": { "type": "array", "items": { "type": "string" } }, "escalated_to": { "type": "array", "items": { "type": "string" } }, "tag_ids": { "type": "array", "items": { "type": "number" } }, "steps": { "type": "array", "items": { "anyOf": [ { "$ref": "#/components/schemas/eventStepForm" }, { "$ref": "#/components/schemas/eventStepContent" }, { "$ref": "#/components/schemas/eventStepTasks" } ] } } }, "required": [ "code", "title", "description", "status", "url", "owner_user_id", "created_at", "due_at", "modified_at", "closed_at", "risk", "escalated_from", "escalated_to", "tag_ids", "steps" ], "additionalProperties": false, "description": "A more detailed view of a single event in Qualio, e.g. a corrective action, a complaint, a non-compliance, etc", "example": { "code": "NCR-12", "title": "Non Compliance: procedure was not followed", "description": "An incidence of a non compliance with a work instuction, procedure or policy", "status": "open", "url": "https://app.qualio.com/quality-events/events/123456", "owner_user_id": 1, "created_at": "2020-01-01T00:00:00Z", "due_at": "2020-01-02T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "closed_at": null, "risk": "1+ Acceptable", "escalated_from": [ "COM-1" ], "escalated_to": [ "NCR-21" ], "tag_ids": [ 21, 92 ], "steps": [ { "label": "Introduction", "type": "content", "order": 0, "sections": [ { "label": "Overview", "order": 0, "section_id": 1, "content": "This Non-Compliance Report (NCR) template is used to document and track non-conformances in your quality management system. Please complete all required fields and follow the workflow steps." } ], "content_status": "effective", "owner_user_id": 1, "created_at": "2020-01-01T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "approvers": [ { "user_id": 5, "action_done": true }, { "user_id": 6, "action_done": false } ], "reviewers": [ { "user_id": 4, "action_done": true } ] }, { "label": "Non Compliance Details", "type": "form", "order": 1, "fields": [ { "label": "Description", "type": "text", "order": 0, "mandatory": true, "multi": false, "values": [ "Procedure was not followed" ] }, { "label": "Severity", "type": "dropdown", "order": 1, "mandatory": true, "multi": false, "values": [ "Minor" ] }, { "label": "Related Incidents", "type": "event", "order": 2, "mandatory": false, "multi": true, "values": [ { "link": "https://app.qualio.com/quality-events/events/123456", "name": "Non Compliance: procedure was not followed", "label": "Non Compliance", "status": "open", "code": "NCR-12" } ] } ], "form_status": "approved", "owner_user_id": 1, "created_at": "2020-01-01T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "approvers": [ { "user_id": 7, "action_done": true } ], "reviewers": [ { "user_id": 8, "action_done": true }, { "user_id": 9, "action_done": false } ] }, { "label": "Corrective Actions", "type": "tasks", "order": 2, "tasks": [ { "title": "Investigate root cause", "owner_user_id": 2, "status": "open", "description": "Determine the underlying cause of the non-compliance.", "code": "#T-1", "due_at": "2020-01-05T00:00:00Z", "updated_at": "2020-01-01T00:00:00Z", "closed_at": null }, { "title": "Implement corrective action", "owner_user_id": 3, "status": "open", "description": "Apply the agreed corrective action and monitor effectiveness.", "code": "#T-2", "due_at": "2020-01-10T00:00:00Z", "updated_at": "2020-01-01T00:00:00Z", "closed_at": null } ] } ] } }, "eventStepForm": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "const": "form" }, "order": { "type": "number" }, "fields": { "type": "array", "items": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "enum": [ "text", "rich_text", "date", "dropdown", "boolean", "numeric", "attachment", "document", "event", "supplier", "user", "radio", "checkbox", "section", "change_request", "product", "root_cause", "registry", "design_controls", "training_plan", "document_template", "event_template", "task" ] }, "order": { "type": "number" }, "helptext": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "mandatory": { "type": "boolean" }, "default_content": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "multi": { "type": "boolean" }, "values": { "type": "array", "items": { "anyOf": [ { "type": "string" }, { "type": "object", "properties": { "link": { "type": "string" }, "name": { "type": "string" }, "label": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "status": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "code": { "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "link", "name" ], "additionalProperties": false } ] } } }, "required": [ "label", "type", "mandatory", "multi", "values" ], "additionalProperties": false } }, "form_status": { "anyOf": [ { "type": "string", "enum": [ "draft", "for_review", "for_approval", "approved", "approval_declined", "superseded", "cancelled" ] }, { "type": "null" } ] }, "owner_user_id": { "anyOf": [ { "type": "number" }, { "type": "null" } ] }, "created_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "approvers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "action_done": { "type": "boolean" } }, "required": [ "user_id", "action_done" ], "additionalProperties": false } }, "reviewers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "action_done": { "type": "boolean" } }, "required": [ "user_id", "action_done" ], "additionalProperties": false } } }, "required": [ "label", "type", "order", "fields", "form_status", "owner_user_id", "created_at", "modified_at", "approvers", "reviewers" ], "additionalProperties": false, "description": "A form step in an event" }, "eventStepContent": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "const": "content" }, "order": { "type": "number" }, "sections": { "type": "array", "items": { "type": "object", "properties": { "label": { "type": "string" }, "order": { "type": "number" }, "section_id": { "type": "number" }, "content": { "type": "string" } }, "required": [ "label", "section_id", "content" ], "additionalProperties": false } }, "content_status": { "anyOf": [ { "type": "string", "enum": [ "approval_declined", "approved", "deleted", "draft", "effective", "for_approval", "for_review", "for_retirement", "retired", "superseded" ] }, { "type": "null" } ] }, "owner_user_id": { "anyOf": [ { "type": "number" }, { "type": "null" } ] }, "created_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "modified_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "approvers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "action_done": { "type": "boolean" } }, "required": [ "user_id", "action_done" ], "additionalProperties": false } }, "reviewers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "action_done": { "type": "boolean" } }, "required": [ "user_id", "action_done" ], "additionalProperties": false } } }, "required": [ "label", "type", "order", "sections", "content_status", "owner_user_id", "created_at", "modified_at", "approvers", "reviewers" ], "additionalProperties": false, "description": "A content step in an event" }, "eventStepTasks": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "const": "tasks" }, "order": { "type": "number" }, "tasks": { "type": "array", "items": { "type": "object", "properties": { "title": { "type": "string" }, "owner_user_id": { "type": "number" }, "status": { "type": "string", "enum": [ "open", "closed_fail", "closed_success" ] }, "description": { "type": "string" }, "code": { "type": "string" }, "due_at": { "type": "string", "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" }, "closed_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "title", "owner_user_id", "status", "description", "code", "due_at", "updated_at", "closed_at" ], "additionalProperties": false } } }, "required": [ "label", "type", "order", "tasks" ], "additionalProperties": false, "description": "A tasks step in an event" }, "eventQueryResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "code": { "type": "string" }, "title": { "type": "string" }, "description": { "type": "string" }, "status": { "type": "string", "enum": [ "closed", "open", "imported", "rejected", "cancelled" ] }, "url": { "type": "string" }, "owner_user_id": { "type": "number" }, "created_at": { "type": "string", "format": "date-time" }, "due_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "closed_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "code", "title", "description", "status", "url", "owner_user_id", "created_at", "due_at", "modified_at", "closed_at" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "An series of Events, based on the results of your query", "example": { "items": [ { "code": "NCR-12", "title": "Non Compliance: procedure was not followed", "description": "An incidence of a non compliance with a work instuction, procedure or policy", "status": "open", "url": "https://app.qualio.com/quality-events/events/123456", "owner_user_id": 1, "created_at": "2020-01-01T00:00:00Z", "due_at": "2020-01-02T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "closed_at": null } ], "total": 1 } }, "event": { "type": "object", "properties": { "code": { "type": "string" }, "title": { "type": "string" }, "description": { "type": "string" }, "status": { "type": "string", "enum": [ "closed", "open", "imported", "rejected", "cancelled" ] }, "url": { "type": "string" }, "owner_user_id": { "type": "number" }, "created_at": { "type": "string", "format": "date-time" }, "due_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "closed_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] } }, "required": [ "code", "title", "description", "status", "url", "owner_user_id", "created_at", "due_at", "modified_at", "closed_at" ], "additionalProperties": false, "description": "An event in Qualio, e.g. a corrective action, a complaint, a non-compliance, etc", "example": { "code": "NCR-12", "title": "Non Compliance: procedure was not followed", "description": "An incidence of a non compliance with a work instuction, procedure or policy", "status": "open", "url": "https://app.qualio.com/quality-events/events/123456", "owner_user_id": 1, "created_at": "2020-01-01T00:00:00Z", "due_at": "2020-01-02T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "closed_at": null } }, "eventTemplateResp": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "prefix": { "type": "string" }, "title": { "type": "string" }, "status": { "type": "string", "enum": [ "draft", "for_approval", "approval_declined", "effective", "superseded", "archived" ] }, "event_template_matrix_id": { "type": "string", "format": "uuid" }, "url": { "type": "string" } }, "required": [ "prefix", "title", "status", "event_template_matrix_id", "url" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A list of event templates for your Qualio instance", "example": { "items": [ { "title": "Non Compliance", "status": "effective", "url": "https://app.qualio.com/quality-events/templates/123456", "prefix": "NCR", "event_template_matrix_id": "c3e000df-4e7e-4916-b5dc-b236a83b3fe5" } ], "total": 1 } }, "eventTemplateDetailedResp": { "type": "object", "properties": { "prefix": { "type": "string" }, "title": { "type": "string" }, "status": { "type": "string", "enum": [ "draft", "for_approval", "approval_declined", "effective", "superseded", "archived" ] }, "event_template_matrix_id": { "type": "string", "format": "uuid" }, "url": { "type": "string" }, "steps": { "type": "array", "items": { "anyOf": [ { "$ref": "#/components/schemas/eventTemplateFormStep" }, { "$ref": "#/components/schemas/eventTemplateContentStep" }, { "$ref": "#/components/schemas/eventTemplateTaskStep" } ] } } }, "required": [ "prefix", "title", "status", "event_template_matrix_id", "url", "steps" ], "additionalProperties": false, "description": "A detailed version of an event template, including steps", "example": { "title": "Non Compliance", "status": "effective", "url": "https://app.qualio.com/quality-events/templates/123456", "prefix": "NCR", "event_template_matrix_id": "c3e000df-4e7e-4916-b5dc-b236a83b3fe5", "steps": [ { "label": "Introduction", "type": "content", "order": 0, "template_step_matrix_id": "a1b2c3d4-e5f6-4789-a012-b3c4d5e6f789", "sections": [ { "label": "Overview", "order": 0, "template_section_id": 1, "content": "This Non-Compliance Report (NCR) template is used to document and track non-conformances in your quality management system. Please complete all required fields and follow the workflow steps." }, { "label": "Instructions", "order": 1, "template_section_id": 2, "content": "1. Fill out the form with all relevant details\n2. Attach any supporting documentation\n3. Complete the assigned tasks\n4. Review and submit for approval" } ] }, { "label": "Non Compliance Details", "type": "form", "order": 1, "template_step_matrix_id": "b2c3d4e5-f6a7-4890-b123-c4d5e6f7a890", "fields": [ { "label": "Description", "type": "rich_text", "order": 0, "field_matrix_id": "c3d4e5f6-a7b8-4901-c234-d5e6f7a8b901", "helptext": "Provide a detailed description of the non-compliance", "mandatory": true, "default_content": null, "multi": false }, { "label": "Severity", "type": "dropdown", "order": 1, "field_matrix_id": "d4e5f6a7-b8c9-4012-d345-e6f7a8b9c012", "helptext": "Select the severity level of this non-compliance", "mandatory": true, "default_content": null, "multi": false, "options": [ "Critical", "Major", "Minor", "Observation" ] }, { "label": "Discovered Date", "type": "date", "order": 2, "field_matrix_id": "e5f6a7b8-c9d0-4123-e456-f7a8b9c0d123", "helptext": "When was this non-compliance discovered?", "mandatory": true, "default_content": null, "multi": false }, { "label": "Department", "type": "radio", "order": 3, "field_matrix_id": "f6a7b8c9-d0e1-4234-f567-a8b9c0d1e234", "helptext": "Select the department where the non-compliance occurred", "mandatory": false, "default_content": null, "multi": false, "options": [ "Manufacturing", "Quality Assurance", "Research & Development", "Operations", "Other" ] }, { "label": "Requires Immediate Action", "type": "boolean", "order": 4, "field_matrix_id": "a7b8c9d0-e1f2-4345-a678-b9c0d1e2f345", "helptext": "Check if this requires immediate corrective action", "mandatory": false, "default_content": null, "multi": false }, { "label": "Affected Products", "type": "checkbox", "order": 5, "field_matrix_id": "b8c9d0e1-f2a3-4456-b789-c0d1e2f3a456", "helptext": "Select all products affected by this non-compliance", "mandatory": false, "default_content": null, "multi": true, "options": [ "Product A", "Product B", "Product C", "Product D" ] }, { "label": "Reference Number", "type": "text", "order": 6, "field_matrix_id": "c9d0e1f2-a3b4-4567-c890-d1e2f3a4b567", "helptext": "Internal reference number if applicable", "mandatory": false, "default_content": null, "multi": false }, { "label": "Estimated Cost Impact", "type": "numeric", "order": 7, "field_matrix_id": "d0e1f2a3-b4c5-4678-d901-e2f3a4b5c678", "helptext": "Estimated financial impact in USD", "mandatory": false, "default_content": null, "multi": false }, { "label": "Related Incidents", "type": "event", "order": 8, "field_matrix_id": "fdd7d0fa-d9b0-11f0-a30a-be7f281741c5", "helptext": "Select the related incidents", "mandatory": false, "default_content": null, "multi": true }, { "label": "Responsible Managers", "type": "user", "order": 9, "field_matrix_id": "db423422-d9b0-11f0-a30a-be7f281741c5", "helptext": "Select the responsible managers", "mandatory": false, "default_content": null, "multi": true } ] }, { "label": "Corrective Actions", "type": "tasks", "template_step_matrix_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "order": 2 } ] } }, "eventTemplateFormStep": { "type": "object", "properties": { "label": { "type": "string" }, "order": { "type": "number" }, "template_step_matrix_id": { "type": "string", "format": "uuid" }, "type": { "type": "string", "const": "form" }, "fields": { "type": "array", "items": { "anyOf": [ { "$ref": "#/components/schemas/eventTemplateFormFieldMultiOption" }, { "$ref": "#/components/schemas/eventTemplateFormField" } ] } } }, "required": [ "label", "template_step_matrix_id", "type", "fields" ], "additionalProperties": false, "description": "A form step in an event template" }, "eventTemplateFormFieldMultiOption": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "enum": [ "text", "rich_text", "date", "dropdown", "boolean", "numeric", "attachment", "document", "event", "supplier", "user", "radio", "checkbox", "section", "change_request", "product", "root_cause", "registry", "design_controls", "training_plan", "document_template", "event_template", "task" ] }, "order": { "type": "number" }, "field_matrix_id": { "type": "string", "format": "uuid" }, "helptext": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "mandatory": { "type": "boolean" }, "default_content": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "multi": { "type": "boolean" }, "options": { "type": "array", "items": { "type": "string" } } }, "required": [ "label", "type", "field_matrix_id", "mandatory", "multi", "options" ], "additionalProperties": false, "description": "A multi-option form field in an event template" }, "eventTemplateFormField": { "type": "object", "properties": { "label": { "type": "string" }, "type": { "type": "string", "enum": [ "text", "rich_text", "date", "dropdown", "boolean", "numeric", "attachment", "document", "event", "supplier", "user", "radio", "checkbox", "section", "change_request", "product", "root_cause", "registry", "design_controls", "training_plan", "document_template", "event_template", "task" ] }, "order": { "type": "number" }, "field_matrix_id": { "type": "string", "format": "uuid" }, "helptext": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "mandatory": { "type": "boolean" }, "default_content": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "multi": { "type": "boolean" } }, "required": [ "label", "type", "field_matrix_id", "mandatory", "multi" ], "additionalProperties": false, "description": "A form field in an event template" }, "eventTemplateContentStep": { "type": "object", "properties": { "label": { "type": "string" }, "order": { "type": "number" }, "template_step_matrix_id": { "type": "string", "format": "uuid" }, "type": { "type": "string", "const": "content" }, "sections": { "type": "array", "items": { "type": "object", "properties": { "label": { "type": "string" }, "order": { "type": "number" }, "template_section_id": { "type": "number" }, "content": { "type": "string" } }, "required": [ "label", "template_section_id", "content" ], "additionalProperties": false } } }, "required": [ "label", "template_step_matrix_id", "type", "sections" ], "additionalProperties": false, "description": "A content step in an event template" }, "eventTemplateTaskStep": { "type": "object", "properties": { "label": { "type": "string" }, "order": { "type": "number" }, "template_step_matrix_id": { "type": "string", "format": "uuid" }, "type": { "type": "string", "const": "tasks" } }, "required": [ "label", "template_step_matrix_id", "type" ], "additionalProperties": false, "description": "A tasks step in an event template" }, "resourceLibraryTemplateQueryResp": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "name": { "type": "string" }, "qualio_managed": { "type": "boolean" }, "status": { "type": "string", "enum": [ "effective", "archived", "superseded", "draft" ] }, "template_matrix_id": { "type": "string" }, "major_version": { "type": "number" }, "minor_version": { "type": "number" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "id", "name", "qualio_managed", "status", "template_matrix_id" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "Resource library templates for your instance", "example": { "items": [ { "id": 10, "name": "Test", "qualio_managed": false, "status": "effective", "template_matrix_id": "aaaa-bbbb-cccc-dddd", "major_version": 1, "minor_version": 0, "description": "Test description" }, { "id": 11, "name": "Test 2", "qualio_managed": false, "status": "draft", "template_matrix_id": "eeee-ffff-gggg-hhhh", "major_version": 2, "minor_version": 1, "description": null } ], "total": 2 } }, "resourceLibrarySingleTemplateResp": { "type": "object", "properties": { "id": { "type": "number" }, "name": { "type": "string" }, "qualio_managed": { "type": "boolean" }, "status": { "type": "string", "enum": [ "effective", "archived", "superseded", "draft" ] }, "template_matrix_id": { "type": "string" }, "major_version": { "type": "number" }, "minor_version": { "type": "number" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "domain_form_template": { "anyOf": [ { "type": "object", "properties": { "id": { "type": "number" }, "fields": { "anyOf": [ { "type": "array", "items": { "anyOf": [ { "type": "object", "properties": { "id": { "type": "number" }, "mandatory": { "type": "boolean" }, "order": { "type": "number" }, "label": { "type": "string" }, "helptext": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "type": { "type": "string" }, "multi": { "type": "boolean" }, "default_content": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "form_option_list": { "anyOf": [ { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "value": { "type": "string" } }, "required": [ "id", "value" ], "additionalProperties": false } }, { "type": "null" } ] } }, "required": [ "id", "mandatory", "order", "label", "type", "multi" ], "additionalProperties": false }, { "type": "null" } ] } }, { "type": "null" } ] } }, "required": [ "id" ], "additionalProperties": false }, { "type": "null" } ] } }, "required": [ "id", "name", "qualio_managed", "status", "template_matrix_id" ], "additionalProperties": false, "description": "A single resource library template", "example": { "id": 10, "name": "Test", "qualio_managed": false, "status": "effective", "template_matrix_id": "aaaa-bbbb-cccc-dddd", "major_version": 1, "minor_version": 0, "description": "Test description", "domain_form_template": { "id": 10, "fields": [ { "id": 10, "mandatory": false, "order": 0, "label": "Test", "helptext": "Test helptext", "type": "text", "multi": false, "default_content": "Test default content", "form_option_list": [ { "id": 10, "value": "Test value" } ] } ] } } }, "createResourceLibraryItemSuccessResp": { "type": "object", "properties": { "item_id": { "type": "number" } }, "required": [ "item_id" ], "additionalProperties": false, "description": "A successful resource library item creation", "example": { "item_id": 21 } }, "resourceLibraryItemResp": { "type": "object", "properties": { "id": { "type": "number" }, "name": { "type": "string" }, "display_id": { "type": "string" }, "description": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "status": { "type": "string", "enum": [ "effective", "archived", "superseded", "draft" ] }, "registry_item_matrix_id": { "type": "string" }, "registry_category_id": { "type": "string" }, "version": { "anyOf": [ { "type": "number" }, { "type": "null" } ] }, "minor_version": { "anyOf": [ { "type": "number" }, { "type": "null" } ] }, "created_time": { "type": "number" }, "last_modified_time": { "type": "number" }, "effective_date": { "anyOf": [ { "type": "number" }, { "type": "null" } ] }, "qri": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "source": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "domain_form_item": { "anyOf": [ { "type": "object", "properties": { "id": { "type": "number" }, "fields": { "anyOf": [ { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "mandatory": { "type": "boolean" }, "order": { "type": "number" }, "label": { "type": "string" }, "helptext": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "type": { "type": "string" }, "multi": { "type": "boolean" }, "default_content": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "form_option_list": { "anyOf": [ { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "number" }, "value": { "type": "string" } }, "required": [ "id", "value" ], "additionalProperties": false } }, { "type": "null" } ] } }, "required": [ "id", "mandatory", "order", "label", "type", "multi" ], "additionalProperties": false } }, { "type": "null" } ] } }, "required": [ "id" ], "additionalProperties": false }, { "type": "null" } ] } }, "required": [ "id", "name", "display_id", "status", "registry_item_matrix_id", "registry_category_id", "created_time", "last_modified_time" ], "additionalProperties": false, "description": "A single resource library item", "example": { "id": 532630, "name": "Primary Centrifuge", "display_id": "EQ-001", "description": "Main lab centrifuge", "status": "effective", "registry_item_matrix_id": "aaaa-bbbb-cccc-dddd", "registry_category_id": "eeee-ffff-gggg-hhhh", "version": 1, "minor_version": 0, "created_time": 1700000000000, "last_modified_time": 1700000000000, "effective_date": 1700000000000, "qri": null, "source": "DEV_API", "domain_form_item": null } }, "supplierResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "name": { "type": "string" }, "contact_information": { "type": "object", "properties": { "name": { "type": "string" }, "email": { "type": "string" }, "phone": { "type": "string" }, "address": { "type": "string" }, "website": { "type": "string" }, "notes": { "type": "string" } }, "additionalProperties": false }, "intended_use": { "type": "string" }, "sponsor_user_id": { "type": "number" }, "supplier_id": { "type": "string" }, "archived": { "type": "boolean" }, "status": { "type": "string", "enum": [ "REVIEW_PENDING", "APPROVED", "REJECTED", "DRAFT", "ARCHIVED" ] }, "created_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "approved_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "risk_type": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "description": { "type": "string" }, "periodic_review": { "type": "number" } }, "additionalProperties": false }, "approvers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "full_name": { "type": "string" }, "email": { "type": "string" } }, "required": [ "user_id", "full_name", "email" ], "additionalProperties": false } } }, "required": [ "name", "supplier_id", "archived", "status", "created_at", "modified_at", "approved_at", "due_at", "approvers" ], "additionalProperties": false } } }, "required": [ "items" ], "additionalProperties": false, "description": "An Array of suppliers", "example": { "items": [ { "name": "Acme", "contact_information": { "name": "Mr Acme", "email": "info@acme.com", "address": "1 Acme st, Acme, NY", "notes": "Call in emergency only", "phone": "555-1234-345" }, "intended_use": "Chemical reagents only", "sponsor_user_id": 999, "archived": false, "status": "APPROVED", "created_at": "2020-01-01T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "approved_at": "2020-03-01T00:00:00Z", "due_at": "2021-01-01T00:00:00Z", "supplier_id": "asdf-asdasd-asdas-adss", "risk_type": { "id": "458bf34c-8ee1-475f-8c4c-ae735518991a", "title": "Risk 1", "description": "Risk 1 description", "periodic_review": 1 }, "approvers": [ { "user_id": 999, "full_name": "Mr Acme", "email": "info@acme.com" } ] } ] } }, "supplier": { "type": "object", "properties": { "name": { "type": "string" }, "contact_information": { "type": "object", "properties": { "name": { "type": "string" }, "email": { "type": "string" }, "phone": { "type": "string" }, "address": { "type": "string" }, "website": { "type": "string" }, "notes": { "type": "string" } }, "additionalProperties": false }, "intended_use": { "type": "string" }, "sponsor_user_id": { "type": "number" }, "supplier_id": { "type": "string" }, "archived": { "type": "boolean" }, "status": { "type": "string", "enum": [ "REVIEW_PENDING", "APPROVED", "REJECTED", "DRAFT", "ARCHIVED" ] }, "created_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "approved_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "due_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "risk_type": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "description": { "type": "string" }, "periodic_review": { "type": "number" } }, "additionalProperties": false }, "approvers": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "full_name": { "type": "string" }, "email": { "type": "string" } }, "required": [ "user_id", "full_name", "email" ], "additionalProperties": false } } }, "required": [ "name", "supplier_id", "archived", "status", "created_at", "modified_at", "approved_at", "due_at", "approvers" ], "additionalProperties": false, "description": "A supplier", "example": { "name": "Acme", "contact_information": { "name": "Mr Acme", "email": "info@acme.com", "address": "1 Acme st, Acme, NY", "notes": "Call in emergency only", "phone": "555-1234-345" }, "intended_use": "Chemical reagents only", "sponsor_user_id": 999, "archived": false, "status": "APPROVED", "created_at": "2020-01-01T00:00:00Z", "modified_at": "2020-01-01T00:00:00Z", "approved_at": "2020-03-01T00:00:00Z", "due_at": "2021-01-01T00:00:00Z", "supplier_id": "asdf-asdasd-asdas-adss", "risk_type": { "id": "458bf34c-8ee1-475f-8c4c-ae735518991a", "title": "Risk 1", "description": "Risk 1 description", "periodic_review": 1 }, "approvers": [ { "user_id": 999, "full_name": "Mr Acme", "email": "info@acme.com" } ] } }, "risksResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "type": { "anyOf": [ { "type": "string", "const": "Risk" }, { "type": "string", "const": "Type" }, { "type": "string", "const": "Document" }, { "type": "string", "const": "Audit" } ] }, "options": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "description": { "type": "string" }, "periodic_review": { "type": "number" } }, "additionalProperties": false } } }, "required": [ "type", "options" ], "additionalProperties": false } } }, "required": [ "items" ], "additionalProperties": false, "description": "An array of risks configured for your company", "example": { "items": [ { "type": "Risk", "options": [ { "id": "458bf34c-8ee1-475f-8c4c-ae735518991a", "title": "Risk 1", "description": "Risk 1 description", "periodic_review": 1 } ] } ] } }, "supplierAuditsResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "audit_id": { "type": "string" }, "supplier_id": { "type": "string" }, "name": { "type": "string" }, "status": { "type": "string", "enum": [ "PLANNED", "ONGOING", "DONE" ] }, "audit_type": { "type": "object", "properties": { "id": { "type": "string", "format": "uuid" }, "title": { "type": "string" }, "description": { "type": "string" }, "periodic_review": { "type": "number" } }, "additionalProperties": false }, "notes": { "type": "string" }, "start_date": { "type": "string" }, "end_date": { "type": "string" }, "created_by": { "type": "string" }, "created_at": { "type": "string", "format": "date-time" }, "modified_at": { "type": "string", "format": "date-time" }, "documents": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string" }, "title": { "type": "string" }, "description": { "type": "string" }, "file": { "type": "object", "properties": { "file_name": { "type": "string" }, "description": { "type": "string" }, "id": { "type": "string" }, "type": { "type": "string", "enum": [ "FILE", "QUALIO_DOC" ] } }, "required": [ "id", "type" ], "additionalProperties": false } }, "required": [ "file" ], "additionalProperties": false } } }, "required": [ "audit_id", "supplier_id", "name", "status" ], "additionalProperties": false } } }, "required": [ "items" ], "additionalProperties": false, "description": "An array of a supplier's audits", "example": { "items": [ { "audit_id": "1b9d6bcd-bbfd-4b2d-9b5d-ab8dfbbd4bed", "supplier_id": "asdf-asdasd-asdas-adss", "name": "2024 On-site Audit", "status": "DONE", "audit_type": { "id": "c9c2302f-bf0d-4e50-81f6-ccc78f0c5a58", "title": "On-site", "description": "On-site supplier audit", "periodic_review": 12 }, "notes": "No major findings.", "start_date": "2024-05-01T09:00:00Z", "end_date": "2024-05-02T17:00:00Z", "created_by": "Jane Auditor", "created_at": "2024-05-01T09:00:00Z", "modified_at": "2024-05-02T17:00:00Z", "documents": [ { "id": "458bf34c-8ee1-475f-8c4c-ae735518991a", "title": "Audit report", "description": "Signed audit report", "file": { "file_name": "audit-report.pdf", "description": "Signed audit report", "id": "a3f5c2d1-0e4b-4c8a-9f2d-6b7e8c9a0d1e", "type": "FILE" } } ] } ] } }, "tagsResponse": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "tag_id": { "type": "number" }, "name": { "type": "string" } }, "required": [ "tag_id", "name" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "All the tags for your qualio instance. Tag ids can be found on events or documents", "example": { "items": [ { "tag_id": 99, "name": "Engineering" } ], "total": 1 } }, "trainingQueryResp": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "email": { "type": "string" }, "full_name": { "type": "string" }, "document_id": { "type": "number" }, "completed": { "type": "boolean" }, "assigned_at": { "type": "string", "format": "date-time" }, "due_at": { "type": "string", "format": "date-time" }, "completed_at": { "anyOf": [ { "type": "string", "format": "date-time" }, { "type": "null" } ] }, "status": { "type": "string", "enum": [ "due", "overdue", "completed" ] }, "is_retraining": { "type": "boolean" }, "is_overdue": { "type": "boolean" }, "training_removed": { "type": "boolean" } }, "required": [ "user_id", "email", "full_name", "document_id", "completed", "assigned_at", "due_at", "completed_at", "status", "is_retraining", "is_overdue", "training_removed" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "A series of training assignments for your instance, based on the query", "example": { "items": [ { "user_id": 1, "email": "test@user.com", "full_name": "Test User", "document_id": 12345, "completed": false, "assigned_at": "2020-01-01T00:00:00Z", "due_at": "2020-06-01T00:00:00Z", "status": "completed", "is_retraining": false, "is_overdue": false, "completed_at": null, "training_removed": false } ], "total": 1 } }, "trainingReminderResponse": { "type": "object", "properties": { "success": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "email": { "type": "string" } }, "required": [ "user_id", "email" ], "additionalProperties": false } }, "failure": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "email": { "type": "string" } }, "required": [ "user_id", "email" ], "additionalProperties": false } } }, "required": [ "success", "failure" ], "additionalProperties": false, "description": "Training reminder response", "example": { "success": [ { "user_id": 1224, "email": "user@example.com" } ], "failure": [] } }, "user": { "type": "object", "properties": { "user_id": { "type": "number" }, "email": { "type": "string" }, "full_name": { "type": "string" }, "invite_status": { "type": "string", "enum": [ "pending", "accepted", "declined", "canceled" ] }, "role": { "type": "string", "enum": [ "quality", "normal", "basic" ] }, "is_admin": { "type": "boolean" } }, "required": [ "user_id", "email", "full_name", "invite_status", "role", "is_admin" ], "additionalProperties": false, "description": "A Qualio user", "example": { "user_id": 1, "email": "testuser1@example.com", "full_name": "John Doe", "invite_status": "pending", "role": "quality", "is_admin": false } }, "userList": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "user_id": { "type": "number" }, "email": { "type": "string" }, "full_name": { "type": "string" }, "invite_status": { "type": "string", "enum": [ "pending", "accepted", "declined", "canceled" ] }, "role": { "type": "string", "enum": [ "quality", "normal", "basic" ] }, "is_admin": { "type": "boolean" } }, "required": [ "user_id", "email", "full_name", "invite_status", "role", "is_admin" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "An array of Qualio users", "example": { "items": [ { "user_id": 1, "email": "testuser1@example.com", "full_name": "John Doe", "invite_status": "pending", "role": "quality", "is_admin": false } ], "total": 1 } }, "deleteUserResp": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "description": "A message indicating the user has been removed", "example": { "message": "User removed successfully" } }, "userHasAssignmentsError": { "type": "object", "properties": { "message": { "type": "string" }, "slug": { "type": "string", "const": "user_has_assignments" }, "assignments": { "type": "object", "properties": { "document_owner": { "type": "array", "items": { "type": "number" } }, "document_reviewer": { "type": "array", "items": { "type": "number" } }, "document_approver": { "type": "array", "items": { "type": "number" } }, "event_owner": { "type": "array", "items": { "type": "number" } }, "event_template_owner": { "type": "array", "items": { "type": "number" } }, "event_template_default_owner": { "type": "array", "items": { "type": "number" } }, "change_request_owner": { "type": "array", "items": { "type": "number" } }, "task_owner": { "type": "array", "items": { "type": "number" } }, "doc_template_owner": { "type": "array", "items": { "type": "number" } } }, "additionalProperties": false } }, "required": [ "message", "slug", "assignments" ], "additionalProperties": false, "description": "A message indicating the user has assignments remaining that must be reassigned before removal", "example": { "message": "User has assignments remaining that must be reassigned before removal", "slug": "user_has_assignments", "assignments": { "document_owner": [ 101, 102, 103 ], "document_reviewer": [ 201, 202 ], "document_approver": [ 301 ], "event_owner": [ 401, 402 ], "task_owner": [ 501 ] } } }, "reassignmentResponse": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "description": "A response confirming the reassignment was successful", "example": { "message": "User reassignments updated" } }, "userAssignmentMapping": { "type": "object", "properties": { "document_owner": { "type": "array", "items": { "type": "number" } }, "document_reviewer": { "type": "array", "items": { "type": "number" } }, "document_approver": { "type": "array", "items": { "type": "number" } }, "event_owner": { "type": "array", "items": { "type": "number" } }, "event_template_owner": { "type": "array", "items": { "type": "number" } }, "event_template_default_owner": { "type": "array", "items": { "type": "number" } }, "change_request_owner": { "type": "array", "items": { "type": "number" } }, "task_owner": { "type": "array", "items": { "type": "number" } }, "doc_template_owner": { "type": "array", "items": { "type": "number" } } }, "additionalProperties": false, "description": "A response containing all entity assignments for a specific user", "example": { "document_owner": [ 101, 102, 103 ], "document_reviewer": [ 201, 202 ], "document_approver": [ 301 ], "event_owner": [ 401, 402 ], "task_owner": [ 501 ] } }, "groupList": { "type": "object", "properties": { "items": { "type": "array", "items": { "type": "object", "properties": { "group_id": { "type": "number" }, "name": { "type": "string" } }, "required": [ "group_id", "name" ], "additionalProperties": false } }, "total": { "type": "number" } }, "required": [ "items", "total" ], "additionalProperties": false, "description": "An array of groups within your Qualio instance", "example": { "items": [ { "group_id": 1, "name": "Quality Team" }, { "group_id": 2, "name": "Engineering Team" } ], "total": 1 } }, "userGroupResp": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "description": "A message confirming the user group addition was successful", "example": { "message": "User added to group" } }, "userGroupRemoveResp": { "type": "object", "properties": { "message": { "type": "string" } }, "required": [ "message" ], "additionalProperties": false, "description": "A message confirming the user group removal was successful", "example": { "message": "User removed from group" } }, "me": { "type": "object", "properties": { "user_id": { "type": "number" }, "full_name": { "type": "string" } }, "required": [ "user_id", "full_name" ], "additionalProperties": false, "description": "Retrieve the current user's id and name", "example": { "user_id": 1, "full_name": "John Doe" } } }, "securitySchemes": { "api_key": { "type": "apiKey", "name": "X-Api-Key", "in": "header" } } } }