generated: '2026-10-04' method: generated source: openapi/sciencelogic-agent-api-openapi.yml, openapi/sciencelogic-agent-debug-api-openapi.yml, openapi/sciencelogic-agent-remote-api-openapi.yml, openapi/sciencelogic-backup-api-openapi.yml, openapi/sciencelogic-command-api-openapi.yml, openapi/sciencelogic-command-output-api-openapi.yml, openapi/sciencelogic-command-schedule-api-openapi.yml, openapi/sciencelogic-command-variables-api-openapi.yml, openapi/sciencelogic-credential-api-openapi.yml, openapi/sciencelogic-credential-bulk-api-openapi.yml, openapi/sciencelogic-credential-provider-cyberark-api-openapi.yml, openapi/sciencelogic-device-api-openapi.yml, openapi/sciencelogic-device-backup-api-openapi.yml, openapi/sciencelogic-device-bulkcreate-api-openapi.yml, openapi/sciencelogic-device-bulkedit-api-openapi.yml, openapi/sciencelogic-dictionary-api-openapi.yml, openapi/sciencelogic-discovery-api-openapi.yml, openapi/sciencelogic-discovery-device-api-openapi.yml, openapi/sciencelogic-domain-api-openapi.yml, openapi/sciencelogic-download-api-openapi.yml, openapi/sciencelogic-export-api-openapi.yml, openapi/sciencelogic-export-policy-api-openapi.yml, openapi/sciencelogic-file-server-api-openapi.yml, openapi/sciencelogic-firmware-api-openapi.yml, openapi/sciencelogic-job-api-openapi.yml, openapi/sciencelogic-label-api-openapi.yml, openapi/sciencelogic-log-api-openapi.yml, openapi/sciencelogic-login-api-openapi.yml, openapi/sciencelogic-network-api-openapi.yml, openapi/sciencelogic-permission-api-openapi.yml, openapi/sciencelogic-permissions-validaterequest-api-openapi.yml, openapi/sciencelogic-plugin-api-openapi.yml, openapi/sciencelogic-plugin-default-values-api-openapi.yml, openapi/sciencelogic-plugin-redact-rule-api-openapi.yml, openapi/sciencelogic-policy-api-openapi.yml, openapi/sciencelogic-policy-rule-api-openapi.yml, openapi/sciencelogic-policy-variable-api-openapi.yml, openapi/sciencelogic-recovery-api-openapi.yml, openapi/sciencelogic-report-api-openapi.yml, openapi/sciencelogic-report-schedule-api-openapi.yml, openapi/sciencelogic-role-api-openapi.yml, openapi/sciencelogic-saml-api-openapi.yml, openapi/sciencelogic-schedule-api-openapi.yml, openapi/sciencelogic-settings-advanced-api-openapi.yml, openapi/sciencelogic-settings-alerts-api-openapi.yml, openapi/sciencelogic-settings-appliance-actions-api-openapi.yml, openapi/sciencelogic-settings-appliance-api-openapi.yml, openapi/sciencelogic-settings-appliance-debug-api-openapi.yml, openapi/sciencelogic-settings-appliance-logo-api-openapi.yml, openapi/sciencelogic-settings-appliance-support-api-openapi.yml, openapi/sciencelogic-settings-appliance-updates-api-openapi.yml, openapi/sciencelogic-settings-archive-api-openapi.yml, openapi/sciencelogic-settings-assetfield-api-openapi.yml, openapi/sciencelogic-settings-assetfield-notifications-api-openapi.yml, openapi/sciencelogic-settings-authentication-api-openapi.yml, openapi/sciencelogic-settings-device-api-openapi.yml, openapi/sciencelogic-settings-discovery-api-openapi.yml, openapi/sciencelogic-settings-ha-api-openapi.yml, openapi/sciencelogic-settings-logs-api-openapi.yml, openapi/sciencelogic-settings-network-api-openapi.yml, openapi/sciencelogic-settings-passwords-api-openapi.yml, openapi/sciencelogic-settings-publickey-api-openapi.yml, openapi/sciencelogic-settings-security-api-openapi.yml, openapi/sciencelogic-settings-security-csr-api-openapi.yml, openapi/sciencelogic-settings-security-ssh-api-openapi.yml, openapi/sciencelogic-settings-security-tls-api-openapi.yml, openapi/sciencelogic-settings-snmp-api-openapi.yml, openapi/sciencelogic-status-api-openapi.yml, openapi/sciencelogic-status-ping-api-openapi.yml, openapi/sciencelogic-syslog-api-openapi.yml, openapi/sciencelogic-table-view-api-openapi.yml, openapi/sciencelogic-template-api-openapi.yml, openapi/sciencelogic-token-api-openapi.yml, openapi/sciencelogic-transcript-api-openapi.yml, openapi/sciencelogic-user-api-openapi.yml, openapi/sciencelogic-user-ldap-api-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 321 by_action_class: connected: 129 acting: 192 by_consequence: read: 129 write: 182 safety-critical: 10 human_in_the_loop_required: 10 operations: - path: /agents method: get operationId: list_agents x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /agents method: post operationId: create_agent x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{id} method: get operationId: get_agent x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /agents/{id} method: put operationId: update_agent x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{id} method: delete operationId: delete_agent x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{id}/info method: get operationId: get_agent_info x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /agents/{id}/debug method: post operationId: start_agent_debug x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{id}/debug method: put operationId: stop_agent_debug x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /agents/{id}/debug method: get operationId: get_agent_debug_state x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /agents/{id}/debug/log method: get operationId: get_agent_debug_log x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /agents/{id}/remote method: post operationId: start_agent_remote x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{id}/remote method: put operationId: stop_agent_remote x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /backups method: get operationId: list_backups x-agentic-access: action-class: connected consequence: read subject: optional scope: - ListBackups token: max-ttl: 3600 audit: none - path: /commands method: get operationId: list_commands x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands method: post operationId: create_command x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/perform method: post operationId: perform_adhoc_command x-agentic-access: action-class: acting consequence: write subject: required scope: - CommandDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/{id} method: get operationId: get_command x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/{id} method: put operationId: update_command x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/{id} method: delete operationId: delete_command x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/{id}/perform method: post operationId: perform_command x-agentic-access: action-class: acting consequence: write subject: required scope: - CommandDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs method: get operationId: list_outputs x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/{id} method: get operationId: get_output x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/{id} method: delete operationId: delete_output x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs/{id}/content method: get operationId: get_output_content x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/{id}/download method: post operationId: download_output x-agentic-access: action-class: acting consequence: write subject: required scope: - CommandDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs/{id}/export method: get operationId: export_output x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/diff method: post operationId: diff_output x-agentic-access: action-class: acting consequence: write subject: required scope: - CommandDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs/settings method: get operationId: get_command_output_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSysAdmin token: max-ttl: 3600 audit: none - path: /commands/outputs/settings method: put operationId: update_command_output_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysAdmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs/groups/{id} method: delete operationId: delete_output_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/outputs/grouped method: get operationId: list_grouped_outputs x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/grouped/{id} method: get operationId: get_grouped_output x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/outputs/grouped/{outputGroupId}/export method: get operationId: export_grouped_output x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/schedules method: get operationId: list_command_schedules x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/{id}/schedules method: get operationId: list_command_schedules_by_command_id x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/{id}/schedules method: post operationId: create_command_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/{id}/schedules/{schedule_id} method: get operationId: get_command_schedule x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceCommand token: max-ttl: 3600 audit: none - path: /commands/{id}/schedules/{schedule_id} method: put operationId: update_command_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/{id}/schedules/{schedule_id} method: delete operationId: delete_command_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDeviceCommand audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /commands/variables/csv method: post operationId: parse_command_variables_from_csv x-agentic-access: action-class: acting consequence: write subject: required scope: - CommandDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials method: get operationId: list_credentials x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewCredentials token: max-ttl: 3600 audit: none - path: /credentials method: post operationId: create_credential x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/{id} method: get operationId: get_credential x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyCredentials token: max-ttl: 3600 audit: none - path: /credentials/{id} method: put operationId: update_credential x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/{id} method: delete operationId: delete_credential x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/bulk method: post operationId: bulk_create_credentials x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredential audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/bulk method: put operationId: bulk_update_credentials x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredential audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/providers/cyberark method: get operationId: list_cyberark_providers x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewCredentials token: max-ttl: 3600 audit: none - path: /credentials/providers/cyberark method: post operationId: create_cyberark_provider x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/providers/cyberark/{id} method: get operationId: get_cyberark_provider x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewCredentials token: max-ttl: 3600 audit: none - path: /credentials/providers/cyberark/{id} method: put operationId: update_cyberark_provider x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /credentials/providers/cyberark/{id} method: delete operationId: delete_cyberark_provider x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyCredentials audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices method: get operationId: list_devices x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /devices method: post operationId: create_device x-agentic-access: action-class: acting consequence: write subject: required scope: - AddDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices method: patch operationId: patch_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id} method: get operationId: get_device x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /devices/{id} method: put operationId: update_device x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id} method: delete operationId: delete_device x-agentic-access: action-class: acting consequence: write subject: required scope: - DeleteDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/monitors method: get operationId: monitor_device x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceauth token: max-ttl: 3600 audit: none - path: /devices/{id}/knownhosts method: delete operationId: clear_known_hosts x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevices audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/compliance method: get operationId: device_compliance x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyDevicePolicy token: max-ttl: 3600 audit: none - path: /devices/{id}/plugincommand/{command} method: get operationId: device_plugin_command x-agentic-access: action-class: connected consequence: read subject: optional scope: - CommandDevice token: max-ttl: 3600 audit: none - path: /devices/search method: post operationId: global_search x-agentic-access: action-class: acting consequence: write subject: required scope: - ViewBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/import method: post operationId: import_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/export method: post operationId: export_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - ExportDevices audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/test method: post operationId: test_device x-agentic-access: action-class: acting consequence: write subject: required scope: - AddDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/count method: get operationId: get_device_counters x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDeviceauth token: max-ttl: 3600 audit: none - path: /devices/{id}/assetfields/{assetfield_id}/upload method: post operationId: upload_assetfield_file x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/scores method: put operationId: update_policy_devices_scores x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/backups/diff method: post operationId: diff_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - ViewBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups method: get operationId: list_device_backups x-agentic-access: action-class: connected consequence: read subject: optional scope: - ListBackups token: max-ttl: 3600 audit: none - path: /devices/{id}/backups method: post operationId: create_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - BackupDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/import method: post operationId: import_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/export method: post operationId: export_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - ExportBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/{backup_id} method: get operationId: get_backup x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewBackup token: max-ttl: 3600 audit: none - path: /devices/{id}/backups/{backup_id} method: put operationId: update_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/{backup_id} method: delete operationId: delete_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/{backup_id}/config method: post operationId: config_details x-agentic-access: action-class: acting consequence: write subject: required scope: - ViewBackup audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/{id}/backups/{backup_id}/restore method: post operationId: restore_backup x-agentic-access: action-class: acting consequence: write subject: required scope: - RestoreDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/bulk/create method: post operationId: bulk_create_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - AddDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/bulk method: post operationId: retrieve_bulk_device x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /devices/bulk method: patch operationId: save_bulk_device x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /devices/bulk/schedule method: post operationId: schedule_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /dictionaries/{type} method: get operationId: list_dictionary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /discovery method: post operationId: run_discovery x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDiscovery audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /discovery/import method: post operationId: import_discovery x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDiscovery audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /discovery/rescan method: post operationId: rescan_discovery x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDiscovery audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /discovery/devices method: get operationId: list_discovered_devices x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyDiscovery token: max-ttl: 3600 audit: none - path: /discovery/devices method: patch operationId: update_discovered_devices x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDiscovery audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains method: get operationId: list_domains x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDomain - ViewSysadmin token: max-ttl: 3600 audit: none - path: /domains method: post operationId: create_domain x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDomain - ViewSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains/{id} method: get operationId: get_domain x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDomain - ViewSysadmin token: max-ttl: 3600 audit: none - path: /domains/{id} method: put operationId: update_domain x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDomain - ViewSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains/{id} method: delete operationId: delete_domain x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDomain - ViewSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domains/{id}/relationships method: get operationId: export_domain_relationships x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDomain token: max-ttl: 3600 audit: none - path: /domains/public method: get operationId: list_domains_public x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDomain token: max-ttl: 3600 audit: none - path: /domains/public/{id} method: get operationId: get_domain_public x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDomain token: max-ttl: 3600 audit: none - path: /downloads/{id} method: get operationId: download x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /export method: post operationId: create_export x-agentic-access: action-class: acting consequence: write subject: required scope: - ExportDevices audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /export/policies method: get operationId: list_export_policies x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /export/policies method: post operationId: create_export_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /export/policies/{id} method: get operationId: get_export_policy x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /export/policies/{id} method: put operationId: update_export_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /export/policies/{id} method: delete operationId: delete_export_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /fileservers method: get operationId: list_fileservers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /fileservers method: post operationId: create_fileserver x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /fileservers/{id} method: get operationId: get_fileserver x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /fileservers/{id} method: put operationId: update_fileserver x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /fileservers/{id} method: delete operationId: delete_fileserver x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /fileservers/test method: post operationId: test_fileserver x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firmware method: get operationId: list_firmwares x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewFirmware token: max-ttl: 3600 audit: none - path: /firmware method: post operationId: upload_firmware x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyFirmware audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firmware/{id} method: get operationId: get_firmware x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewFirmware token: max-ttl: 3600 audit: none - path: /firmware/{id} method: put operationId: update_firmware x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyFirmware audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firmware/{id} method: delete operationId: delete_firmware x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyFirmware audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firmware/{id}/push method: post operationId: push_firmware x-agentic-access: action-class: acting consequence: write subject: required scope: - PushFirmware audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firmware/export method: post operationId: export_firmware x-agentic-access: action-class: acting consequence: write subject: required scope: - PushFirmware audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /jobs method: get operationId: list_jobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /jobs method: delete operationId: cancel_all_jobs x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /jobs/{id} method: get operationId: get_job x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /jobs/{id} method: delete operationId: cancel_job x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /jobs/historic method: get operationId: list_historic_jobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /jobs/historic/{id} method: delete operationId: delete_historic_job x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /labels method: get operationId: list_labels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /labels method: post operationId: create_label x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyLabels audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /labels/{id} method: get operationId: get_label x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /labels/{id} method: put operationId: update_label x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyLabels audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /labels/{id} method: delete operationId: delete_label x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyLabels audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs method: get operationId: list_logs x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /logs/{id} method: get operationId: get_log x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /logs/export method: get operationId: export_logs x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /login method: get operationId: check_login x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /login method: post operationId: authenticate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login method: delete operationId: logout x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login method: put operationId: update_login x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login/saml method: get operationId: saml_redirect x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /login/activation method: post operationId: complete_activation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login/recovery method: put operationId: set_recovery_details x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/fingerprint method: post operationId: fingerprint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/ping method: post operationId: ping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/resolve method: post operationId: resolve x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/testproxy method: post operationId: test_proxy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /permissions method: get operationId: list_permissions x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewRoles token: max-ttl: 3600 audit: none - path: /permissions/validate-request method: post operationId: validate_request x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins method: get operationId: list_plugins x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name} method: get operationId: get_plugin x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name}/defaults method: get operationId: get_plugin_default_values x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name}/defaults method: put operationId: update_plugin_default_values x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules method: get operationId: get_plugin_redact_rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name}/redactrules method: post operationId: create_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules/{id} method: put operationId: update_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules/{id} method: delete operationId: delete_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/defaults method: get operationId: get_plugin_default_values x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name}/defaults method: put operationId: update_plugin_default_values x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules method: get operationId: get_plugin_redact_rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /plugins/{name}/redactrules method: post operationId: create_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules/{id} method: put operationId: update_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /plugins/{name}/redactrules/{id} method: delete operationId: delete_plugin_redact_rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies method: get operationId: list_policies x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies method: post operationId: create_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id} method: get operationId: get_policy x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/{id} method: put operationId: update_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id} method: delete operationId: delete_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/test method: post operationId: test_policy x-agentic-access: action-class: acting consequence: write subject: required scope: - ApplyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/scores method: put operationId: update_policy_devices_scores x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevice audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/import method: post operationId: import_device_policies x-agentic-access: action-class: acting consequence: write subject: required scope: - ViewDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/export method: get operationId: export_device_policies x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/settings method: get operationId: get_policy_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSysadmin token: max-ttl: 3600 audit: none - path: /policies/settings method: put operationId: update_policy_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/rules/test method: post operationId: test_rule x-agentic-access: action-class: acting consequence: write subject: required scope: - ApplyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/rules method: get operationId: list_rules x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/{id}/rules method: post operationId: create_rule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/rules/{rule_id} method: get operationId: get_rule x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/{id}/rules/{rule_id} method: put operationId: update_rule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/{id}/rules/{rule_id} method: delete operationId: delete_rule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/variables method: get operationId: list_variables x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/variables method: post operationId: create_variable x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/variables/{id} method: get operationId: get_variable x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /policies/variables/{id} method: put operationId: update_variable x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/variables/{id} method: delete operationId: delete_variable x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/variables/import method: post operationId: import_policy_variables x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDevicePolicy audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/variables/export method: get operationId: export_policy_variables x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevicePolicy token: max-ttl: 3600 audit: none - path: /recovery/password-reset method: post operationId: recovery_password_reset x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /recovery/question method: get operationId: get_recovery_question x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /reports method: get operationId: list_reports x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewReports token: max-ttl: 3600 audit: none - path: /reports method: post operationId: create_report x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/assettypes method: get operationId: get_report_assettypes x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewReports token: max-ttl: 3600 audit: none - path: /reports/adhoc method: post operationId: generate_adhoc_report x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/{id} method: get operationId: get_report x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewReports token: max-ttl: 3600 audit: none - path: /reports/{id} method: put operationId: update_report x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/{id} method: delete operationId: delete_report x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/schedules method: get operationId: list_report_schedules x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewReports token: max-ttl: 3600 audit: none - path: /reports/schedules method: post operationId: create_report_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/schedules/{id} method: get operationId: get_report_schedule x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewReports token: max-ttl: 3600 audit: none - path: /reports/schedules/{id} method: put operationId: update_report_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/schedules/{id} method: delete operationId: delete_report_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyReports audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles method: get operationId: list_roles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles method: post operationId: create_role x-agentic-access: action-class: acting consequence: write subject: required scope: - EditRoles audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id} method: get operationId: get_role x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewRoles token: max-ttl: 3600 audit: none - path: /roles/{id} method: put operationId: update_role x-agentic-access: action-class: acting consequence: write subject: required scope: - EditRoles audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id} method: delete operationId: delete_role x-agentic-access: action-class: acting consequence: write subject: required scope: - EditRoles audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /saml/groups method: get operationId: list_saml_groups x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewUsers token: max-ttl: 3600 audit: none - path: /saml/groups method: post operationId: create_saml_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /saml/groups/{id} method: put operationId: update_saml_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /saml/groups/{id} method: delete operationId: delete_saml_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /schedules method: get operationId: list_all_schedules x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewAllSchedules token: max-ttl: 3600 audit: none - path: /schedules/nextdue method: post operationId: next_due x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /schedules/status method: get operationId: check_schedule_status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /schedules/pause method: post operationId: pause_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllSchedules audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /schedules/resume method: post operationId: resume_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllSchedules audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /schedules/postpone method: post operationId: postpone_schedule x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllSchedules audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/advanced method: get operationId: get_advanced_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSysAdmin token: max-ttl: 3600 audit: none - path: /settings/advanced method: put operationId: update_advanced_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysAdmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/alerts method: get operationId: get_alert_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/alerts method: put operationId: update_alert_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/alerts/test method: get operationId: test_alert_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/appliance/restart method: post operationId: restart_restorepoint x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/reboot method: post operationId: reboot_appliance x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/appliance/shutdown method: post operationId: shutdown_appliance x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/appliance method: get operationId: get_appliance_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/appliance method: put operationId: update_appliance_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/cache method: delete operationId: clear_cache x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/install method: post operationId: install_appliance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/install/status method: get operationId: check_install_status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/appliance/debug method: post operationId: start_debug x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/debug method: put operationId: stop_debug x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/appliance/debug method: get operationId: get_debug x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /settings/appliance/debug/log method: get operationId: download_debug_log x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /settings/appliance/debug/log method: delete operationId: delete_debug_log x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/debug/details method: get operationId: download_debug_details x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /settings/appliance/trace method: get operationId: stack_trace x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /settings/appliance/logo method: post operationId: upload_logo x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/logo method: delete operationId: reset_logo x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/appliance/support method: post operationId: start_remote_support x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/support method: delete operationId: stop_remote_support x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/appliance/support method: get operationId: get_remote_support x-agentic-access: action-class: connected consequence: read subject: optional scope: - UpdateSysadmin token: max-ttl: 3600 audit: none - path: /settings/appliance/update method: get operationId: check_update x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/appliance/update method: put operationId: run_update x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/update method: delete operationId: force_check_update x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/appliance/update method: post operationId: upload_update x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/archive method: get operationId: get_archive_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ArchivePlatform token: max-ttl: 3600 audit: none - path: /settings/archive method: put operationId: update_archive_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - ArchivePlatform audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/archive/backup method: post operationId: backup_restorepoint x-agentic-access: action-class: acting consequence: write subject: required scope: - ArchivePlatform audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/archive/restore method: get operationId: list_restorepoint_backups x-agentic-access: action-class: connected consequence: read subject: optional scope: - ArchivePlatform token: max-ttl: 3600 audit: none - path: /settings/archive/restore method: post operationId: restore_restorepoint x-agentic-access: action-class: acting consequence: write subject: required scope: - ArchivePlatform audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/assetfields method: get operationId: list_assetfields x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewAssets token: max-ttl: 3600 audit: none - path: /settings/assetfields method: post operationId: create_assetfield x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAssets audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/assetfields/{id} method: get operationId: get_assetfield x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewAssets token: max-ttl: 3600 audit: none - path: /settings/assetfields/{id} method: put operationId: update_assetfield x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAssets audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/assetfields/{id} method: delete operationId: delete_assetfield x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAssets audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/assetfields/notifications method: get operationId: get_asset_notification_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewAssets token: max-ttl: 3600 audit: none - path: /settings/assetfields/notifications method: put operationId: update_asset_notification_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAssets audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/assetfields/notifications method: delete operationId: disable_asset_notifications x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - ModifyAssets audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/authentication method: get operationId: get_authentication_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewRadius token: max-ttl: 3600 audit: none - path: /settings/authentication method: put operationId: update_authentication_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyRadius audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/authentication/testldap method: post operationId: test_ldap x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/device method: get operationId: get_device_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/device method: put operationId: update_device_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/discovery method: get operationId: get_discovery_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyDiscovery token: max-ttl: 3600 audit: none - path: /settings/discovery method: put operationId: update_discovery_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyDiscovery audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/ha method: get operationId: get_ha_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/ha method: put operationId: update_ha_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/ha/status method: get operationId: get_high_availability_status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/ha/active method: get operationId: get_high_availability_active x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/logs method: get operationId: get_log_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/logs method: put operationId: update_log_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/network method: get operationId: get_network_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/network method: put operationId: update_network_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/network/routes method: get operationId: get_routes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/network/routes method: post operationId: add_route x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/network/routes method: delete operationId: delete_route x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/passwords method: get operationId: get_password_settings x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewPassrules token: max-ttl: 3600 audit: none - path: /settings/passwords method: put operationId: update_password_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyPassrules audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/publickeys method: get operationId: list_publickeys x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewDevices token: max-ttl: 3600 audit: none - path: /settings/security method: get operationId: get_security_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/security method: put operationId: update_security_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/reset-ssh-keys method: post operationId: reset_ssh_keys x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /settings/security/csr method: get operationId: get_tls_csr x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSysAdmin token: max-ttl: 3600 audit: none - path: /settings/security/csr method: post operationId: post_tls_csr x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/ssh/knownhosts method: delete operationId: clear_appliance_ssh_known_hosts x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/tls method: get operationId: get_tls_certificate x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSysAdmin token: max-ttl: 3600 audit: none - path: /settings/security/tls method: post operationId: post_tls_certificate x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/tls method: put operationId: put_tls_certificate x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/tls/certificate method: put operationId: put_tls_standalone_certificate x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/security/tls/newkey method: post operationId: post_tls_new_key x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /settings/snmp method: get operationId: get_snmp_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /settings/snmp method: put operationId: update_snmp_settings x-agentic-access: action-class: acting consequence: write subject: required scope: - UpdateSysadmin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /status method: get operationId: system_status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /status/ping method: get operationId: system_status_ping x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /syslogs method: get operationId: list_syslogs x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewSyslogs token: max-ttl: 3600 audit: none - path: /tableviews method: get operationId: list_table_views x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tableviews method: post operationId: create_table_view x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tableviews/{id} method: get operationId: get_table_view x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tableviews/{id} method: put operationId: update_table_view x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tableviews/{id} method: delete operationId: delete_table_view x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /templates method: get operationId: list_templates x-agentic-access: action-class: connected consequence: read subject: optional scope: - ListTemplates token: max-ttl: 3600 audit: none - path: /templates method: post operationId: create_template x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyTemplate audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /templates/{id} method: get operationId: get_template x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewTemplate token: max-ttl: 3600 audit: none - path: /templates/{id} method: put operationId: update_template x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyTemplate audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /templates/{id} method: delete operationId: delete_template x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyTemplate audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /templates/{id}/download method: post operationId: download_template x-agentic-access: action-class: acting consequence: write subject: required scope: - ViewTemplate audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /templates/{id}/push method: post operationId: push_template x-agentic-access: action-class: acting consequence: write subject: required scope: - PushTemplate audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tokens method: get operationId: list_tokens x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyAllTokens - ModifyOwnTokens token: max-ttl: 3600 audit: none - path: /tokens method: post operationId: create_token x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllTokens - ModifyOwnTokens audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tokens/{id} method: get operationId: get_token x-agentic-access: action-class: connected consequence: read subject: optional scope: - ModifyAllTokens - ModifyOwnTokens token: max-ttl: 3600 audit: none - path: /tokens/{id} method: put operationId: update_token x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllTokens - ModifyOwnTokens audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tokens/{id} method: delete operationId: delete_token x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyAllTokens - ModifyOwnTokens audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /transcripts method: get operationId: list_transcripts x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /transcripts/{id} method: get operationId: get_transcript x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewLogs token: max-ttl: 3600 audit: none - path: /users method: get operationId: list_users x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewUsers token: max-ttl: 3600 audit: none - path: /users method: post operationId: create_user x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/broadcast method: post operationId: user_broadcast x-agentic-access: action-class: acting consequence: write subject: required scope: - PermModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id} method: get operationId: get_user x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewUserauth token: max-ttl: 3600 audit: none - path: /users/{id} method: put operationId: update_user x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id} method: delete operationId: delete_user x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/action method: post operationId: log_action x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/activationlink method: get operationId: email_activation_link x-agentic-access: action-class: connected consequence: read subject: optional scope: - PermModifyUser token: max-ttl: 3600 audit: none - path: /users/ldap/groups method: get operationId: list_ldap_groups x-agentic-access: action-class: connected consequence: read subject: optional scope: - ViewUsers token: max-ttl: 3600 audit: none - path: /users/ldap/groups method: post operationId: create_ldap_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/ldap/groups/{id} method: put operationId: update_ldap_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/ldap/groups/{id} method: delete operationId: delete_ldap_group x-agentic-access: action-class: acting consequence: write subject: required scope: - ModifyUser audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required