API · 17 operationer
policy-engine
Genererad ur services/policy-engine/openapi.json, kontraktsversion 0.1.0. Auth-modell och anropare står i atlasen.
GET /healthz
Healthz
Lever processen?
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | { [nyckel]: string } application/json |
GET /readyz
Readyz
Kan podden ta trafik? Nej om OPA inte svarar.
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | { [nyckel]: string } application/json |
GET /v1/admin/decisions
List Decisions
| Parameter | I | Typ | Krävs |
|---|---|---|---|
q | query | string | null | nej |
action | query | string | null | nej |
since | query | string (date-time) | null | nej |
until | query | string (date-time) | null | nej |
user_id_hashExakt matchning. Personens identitet. Trots namnet är värdet inte alltid en hash. Det bär en av två identitetsrymder beroende på anroparen: `auth.users.id`-UUID:t orört (D-31) från bff, llm-gateway och agent-runtime, eller aktörsvärdet `sha256(canonical_json("platform:" + sub))` (D-113) från mcp-gateway. `policy_decisions.user_id_hash` innehåller alltså båda, och den som filtrerar på en person måste fråga på båda värdena (P43). | query | string | null | nej |
limit | query | integer | nej |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | DecisionAuditPage application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/admin/decisions/traces
Decision Traces
| Parameter | I | Typ | Krävs |
|---|---|---|---|
user_id_hashExakt matchning. Personens identitet. Trots namnet är värdet inte alltid en hash. Det bär en av två identitetsrymder beroende på anroparen: `auth.users.id`-UUID:t orört (D-31) från bff, llm-gateway och agent-runtime, eller aktörsvärdet `sha256(canonical_json("platform:" + sub))` (D-113) från mcp-gateway. `policy_decisions.user_id_hash` innehåller alltså båda, och den som filtrerar på en person måste fråga på båda värdena (P43). | query | string | ja |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | DecisionTracesResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/admin/decisions/verify
Verify Decisions
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | ChainVerification application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/admin/protection-defaults
Get Protection Defaults
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | { [nyckel]: { [nyckel]: string } } application/json |
422 | Validation Error | HTTPValidationError application/json |
PUT /v1/admin/protection-defaults
Put Protection Defaults
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
Kropp: ProtectionDefaultsPayload application/json
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | { [nyckel]: { [nyckel]: string } } application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/admin/retention
Get Retention
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | { [nyckel]: object[] } application/json |
422 | Validation Error | HTTPValidationError application/json |
PUT /v1/admin/retention/{data_category}
Put Retention
| Parameter | I | Typ | Krävs |
|---|---|---|---|
data_category | path | "chat_conversation" | "chat_upload" | "public_session" | "public_forensics" | "rag_document" | "knowledge_superseded" | ja |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
Kropp: RetentionPolicyPayload application/json
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | object application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/admin/tenants/{tenant_id}/export
Export Tenant
| Parameter | I | Typ | Krävs |
|---|---|---|---|
tenant_id | path | string (uuid) | ja |
authorization | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | TenantExport application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/assistants
List Assistants
| Parameter | I | Typ | Krävs |
|---|---|---|---|
limit | query | integer | nej |
offset | query | integer | nej |
knowledge_scope_contains | query | string (uuid) | null | nej |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | AssistantListResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
POST /v1/assistants
Create Assistant
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
Kropp: CreateAssistantRequest application/json
| Svar | Beskrivning | Kropp |
|---|---|---|
201 | Successful Response | AssistantResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/assistants/{assistant_id}
Get Assistant
| Parameter | I | Typ | Krävs |
|---|---|---|---|
assistant_id | path | string (uuid) | ja |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | AssistantResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
PATCH /v1/assistants/{assistant_id}
Patch Assistant
| Parameter | I | Typ | Krävs |
|---|---|---|---|
assistant_id | path | string (uuid) | ja |
If-Match | header | string | null | nej |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
Kropp: PatchAssistantRequest application/json
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | AssistantResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
POST /v1/assistants/{assistant_id}/retire
Retire Assistant
| Parameter | I | Typ | Krävs |
|---|---|---|---|
assistant_id | path | string (uuid) | ja |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | AssistantResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
POST /v1/decide
Decide
| Parameter | I | Typ | Krävs |
|---|---|---|---|
authorization | header | string | null | nej |
Kropp: DecideRequest application/json
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | DecideResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
GET /v1/decisions
List Decisions
| Parameter | I | Typ | Krävs |
|---|---|---|---|
trace_id | query | string | ja |
authorization | header | string | null | nej |
X-Tenant-Id | header | string | null | nej |
| Svar | Beskrivning | Kropp |
|---|---|---|
200 | Successful Response | DecisionsResponse application/json |
422 | Validation Error | HTTPValidationError application/json |
Scheman
AssistantListResponse
| Fält | Typ | Krävs |
|---|---|---|
items | AssistantResponse[] | ja |
limit | integer | ja |
offset | integer | ja |
total | integer | ja |
AssistantResponse
| Fält | Typ | Krävs |
|---|---|---|
action_level | string | ja |
ai_act_classification | string | ja |
allowed_groups | string[] | ja |
allowed_models | string[] | ja |
allowed_roles | string[] | ja |
allowed_tool_scopes | string[] | ja |
archetype | string | null | ja |
content_trail_enabled | boolean | ja |
created_at | string (date-time) | ja |
default_model | string | ja |
delegated_editors | string[] | ja |
description | string | null | ja |
exposure | string | ja |
fallback_chain | string[] | ja |
geo_constraint | string | null | ja |
icon | string | null | ja |
id | string (uuid) | ja |
information_class | string | ja |
intended_use | string | ja |
knowledge_scope | string[] | ja |
name | string | ja |
owner | string | null | ja |
retention_policy | string | ja |
runtime | RuntimeModel | ja |
shared_with_org | boolean | ja |
status | string | ja |
superseded_by | string (uuid) | null | ja |
system_prompt | string | null | ja |
tenant_id | string (uuid) | ja |
updated_at | string (date-time) | ja |
version | integer | ja |
ChainVerification
| Fält | Typ | Krävs |
|---|---|---|
chain | string | ja |
events | integer | ja |
status | "valid" | "invalid" | "incomplete" | ja |
verified_at | string | ja |
CoverageGap
En store exporten INTE täcker, med ett ärligt skäl. `store` måste vara IDENTISK med namnet i `covered` när en store demoteras (t.ex. `page_truncated_over_500`), så en konsument kan korrelera flytten. Se regel (c) i docs/tenant-export-coverage.md.
| Fält | Typ | Krävs |
|---|---|---|
reason | string | ja |
store | string | ja |
CreateAssistantRequest
| Fält | Typ | Krävs |
|---|---|---|
action_level | "informs" | "supports" | "acts_with_approval" | nej |
ai_act_classification | string | ja |
allowed_groups | string[] | nej |
allowed_models | string[] | ja |
allowed_roles | string[] | nej |
allowed_tool_scopes | "read_only" | "read_write" | "destructive"[] | nej |
archetype | string | null | nej |
content_trail_enabled | boolean | nej |
default_model | string | ja |
delegated_editors | string[] | nej |
description | string | null | nej |
exposure | "public_chat" | "internal_chat" | "api" | "pipeline" | ja |
fallback_chain | string[] | nej |
geo_constraint | string | null | nej |
icon | string | null | nej |
information_class | string | ja |
intended_use | string | ja |
knowledge_scope | string[] | nej |
name | string | ja |
owner | string | null | nej |
retention_policy | string | nej |
runtime | RuntimeModel | nej |
shared_with_org | boolean | nej |
system_prompt | string | null | nej |
DecideRequest
| Fält | Typ | Krävs |
|---|---|---|
action | string | null | nej |
assistant_ctx | object | null | nej |
assistant_id | string (uuid) | null | nej |
file | FileCtx | null | nej |
grant | GrantCtx | null | nej |
knowledge_ctx | KnowledgeCtx | null | nej |
model_residency | string | null | nej |
output_check | OutputCheckSignals | null | nej |
pii | PiiSignals | null | nej |
purpose | "eval" | null | nej |
requested_model | string | ja |
tenant_id | string (uuid) | ja |
tool_name | string | null | nej |
tool_scope | string | null | nej |
trace_id | string | ja |
user_groups | string[] | nej |
user_id_hashPersonens identitet. Trots namnet är värdet inte alltid en hash. Det bär en av två identitetsrymder beroende på anroparen: `auth.users.id`-UUID:t orört (D-31) från bff, llm-gateway och agent-runtime, eller aktörsvärdet `sha256(canonical_json("platform:" + sub))` (D-113) från mcp-gateway. `policy_decisions.user_id_hash` innehåller alltså båda, och den som filtrerar på en person måste fråga på båda värdena (P43). | string | null | nej |
user_role | string | null | nej |
DecideResponse
| Fält | Typ | Krävs |
|---|---|---|
content_trail_enabled | boolean | nej |
decision | string | ja |
decision_id | string (uuid) | ja |
evaluation_ms | integer | ja |
human_oversight_required | boolean | nej |
information_class | string | null | nej |
jit_approval_required | boolean | nej |
output_check_failures | OutputCheckFailure[] | null | nej |
output_check_required | boolean | null | nej |
pii_verdict | string | null | nej |
policies_version | string | ja |
protection | { [nyckel]: string } | null | nej |
retention_policy | string | null | nej |
substitute_model | string | null | nej |
substitute_reason | string | null | nej |
DecisionAuditItem
| Fält | Typ | Krävs |
|---|---|---|
action | string | ja |
actor | string | ja |
chain | string | ja |
created_at | string | ja |
hash | string | ja |
information_class | string | null | ja |
prev_hash | string | ja |
seq | integer | ja |
target | string | ja |
trace_id | string | ja |
DecisionAuditPage
| Fält | Typ | Krävs |
|---|---|---|
items | DecisionAuditItem[] | ja |
next_cursor | string | null | nej |
total | integer | ja |
DecisionItem
| Fält | Typ | Krävs |
|---|---|---|
assistant_id | string (uuid) | null | ja |
created_at | string (date-time) | ja |
decision | string | ja |
evaluation_ms | integer | null | ja |
human_oversight_required | boolean | ja |
id | string (uuid) | ja |
jit_approval_required | boolean | ja |
policies_version | string | ja |
substitute_model | string | null | ja |
substitute_reason | string | null | ja |
tenant_id | string (uuid) | ja |
trace_id | string | ja |
DecisionsResponse
| Fält | Typ | Krävs |
|---|---|---|
items | DecisionItem[] | ja |
trace_id | string | ja |
DecisionTracesResponse
| Fält | Typ | Krävs |
|---|---|---|
total | integer | ja |
trace_ids | string[] | ja |
user_id_hash | string | ja |
FileCtx
Filens metadata före extraktionen (spec B4): format och storlek, aldrig byte, filnamn eller hash. `format` är strängen BFF läst ur innehållet. Vilka format som är öppna avgör rego, så ett okänt format blir en deny-rad i policy_decisions i stället för en 422 som ingen beslutsrad ser.
| Fält | Typ | Krävs |
|---|---|---|
format | string | ja |
size_bytes | integer | ja |
GrantCtx
Grant-scopad decide-kontext (fas MCP-chokepunkt, D-70): flyttar verktygsbehörigheten från mcp-gatewayens lokala deny (PR #51, utanför WORM) till OPA. None på fältet = REST-vägen, som inte har något grant-begrepp — skiljs medvetet från `granted=False` (grant fanns men saknades).
| Fält | Typ | Krävs |
|---|---|---|
granted | boolean | ja |
scope_cap | string | null | nej |
HTTPValidationError
| Fält | Typ | Krävs |
|---|---|---|
detail | ValidationError[] | nej |
KnowledgeCtx
Kunskaps-scopad decide-kontext (fas R1, D-39): collections har ingen assistant — informationsklassen kommer från kunskapskortet. None = oklassat (fail-closed: rego behandlar det som rod).
| Fält | Typ | Krävs |
|---|---|---|
collection_id | string (uuid) | ja |
information_class | string | null | nej |
OutputCheckFailure
| Fält | Typ | Krävs |
|---|---|---|
message | string | ja |
rule | string | ja |
OutputCheckSignals
Utflödessignaler (fas P2, D-35): metadata om ett genererat svar, aldrig innehållet. pii_entities = entitetstyp -> antal ur utflödesscannen.
| Fält | Typ | Krävs |
|---|---|---|
answer_kind | "tool_calls" | null | nej |
decision_pattern_hit | boolean | null | nej |
has_citations | boolean | null | nej |
knowledge_bound | boolean | null | nej |
pii_entities | { [nyckel]: integer } | nej |
retrieval_score | number | null | nej |
source | string | null | nej |
PatchAssistantRequest
| Fält | Typ | Krävs |
|---|---|---|
action_level | "informs" | "supports" | "acts_with_approval" | null | nej |
ai_act_classification | string | null | nej |
allowed_groups | string[] | null | nej |
allowed_models | string[] | null | nej |
allowed_roles | string[] | null | nej |
allowed_tool_scopes | "read_only" | "read_write" | "destructive"[] | null | nej |
archetype | string | null | nej |
content_trail_enabled | boolean | null | nej |
default_model | string | null | nej |
delegated_editors | string[] | null | nej |
description | string | null | nej |
exposure | "public_chat" | "internal_chat" | "api" | "pipeline" | null | nej |
fallback_chain | string[] | null | nej |
geo_constraint | string | null | nej |
icon | string | null | nej |
information_class | string | null | nej |
intended_use | string | null | nej |
knowledge_scope | string[] | null | nej |
name | string | null | nej |
owner | string | null | nej |
retention_policy | string | null | nej |
runtime | RuntimeModel | null | nej |
shared_with_org | boolean | null | nej |
system_prompt | string | null | nej |
PiiSignals
Entitetstyp -> antal. Aldrig innehall/fynd - GDPR first (D-35).
| Fält | Typ | Krävs |
|---|---|---|
entities | { [nyckel]: integer } | nej |
ProtectionDefaultsPayload
| Fält | Typ | Krävs |
|---|---|---|
api | ProtectionProfilePayload | ja |
internal_chat | ProtectionProfilePayload | ja |
pipeline | ProtectionProfilePayload | ja |
public_chat | ProtectionProfilePayload | ja |
ProtectionProfileModel
runtime.protection — per-tjänst-övrid (D-36). Nivåerna valideras mot app.services.protection.LEVELS (importerad, K3: dubblera inte). extra=forbid ⇒ exakt familjerna inflow/outflow/resistance.
| Fält | Typ | Krävs |
|---|---|---|
inflow | string | ja |
outflow | string | ja |
resistance | string | ja |
ProtectionProfilePayload
| Fält | Typ | Krävs |
|---|---|---|
inflow | "off" | "low" | "medium" | "high" | ja |
outflow | "off" | "low" | "medium" | "high" | ja |
resistance | "off" | "low" | "medium" | "high" | ja |
RetentionPolicyPayload
| Fält | Typ | Krävs |
|---|---|---|
archive_hold | boolean | ja |
retention_days | integer | null | ja |
RuntimeModel
API-projektionen av default_parameters (temperature/max_tokens) + protection-kolumnen (K1/K3). Lagras aldrig som eget fält — packas upp i repo-lagret.
| Fält | Typ | Krävs |
|---|---|---|
max_tokens | integer | ja |
min_retrieval_score | number | null | nej |
protection | ProtectionProfileModel | null | nej |
temperature | number | ja |
TenantExport
En producents svar. `extra="forbid"` medvetet: bevarar de tre befintliga typade deklarationernas beteende, OCH gör att en producent som lägger ett fält utan att koordinatorn lär sig om det failar högt i stället för tyst.
| Fält | Typ | Krävs |
|---|---|---|
coverage | TenantExportCoverage | ja |
data | object | ja |
generated_at | string (date-time) | ja |
service | string | ja |
tenant_id | string (uuid) | ja |
TenantExportCoverage
| Fält | Typ | Krävs |
|---|---|---|
covered | string[] | ja |
not_covered | CoverageGap[] | ja |
ValidationError
| Fält | Typ | Krävs |
|---|---|---|
ctx | object | nej |
input | any | nej |
loc | string | integer[] | ja |
msg | string | ja |
type | string | ja |