Skip to content

Beta module namespace

governance

Beta routes may change with notice and are NOT covered by the 24-month stable window of the core contract.

Every module route is enumerated with method, path, auth and required permission; request/response schemas are not published for the beta surface.

90 operations

MethodPathRequired permissionAuthenticationSummary
get/v1/m/governance/agent-risk-profilesgovernance:agent-risk:readBearer tokenLists profiles, optionally filtered by tier.
post/v1/m/governance/agent-risk-profiles/classifygovernance:agent-risk:writeBearer tokenComputes (or recomputes) the suggested risk tier for an agent from observed signals.
get/v1/m/governance/agent-risk-profiles/{id}governance:agent-risk:readBearer tokenReturns one profile.
post/v1/m/governance/agent-risk-profiles/{id}/reviewgovernance:agent-risk:adminBearer tokenMarks a classification as human-reviewed.
put/v1/m/governance/agent-risk-profiles/{id}/tiergovernance:agent-risk:adminBearer tokenSets the operator's authoritative tier for an agent.
post/v1/m/governance/agentcore-export/applygovernance:agentcore-export:adminBearer tokengovernance module route (requires governance:agentcore-export:admin)
post/v1/m/governance/agentcore-export/plangovernance:agentcore-export:adminBearer tokengovernance module route (requires governance:agentcore-export:admin)
post/v1/m/governance/agentsgovernance:nhi:adminBearer tokenCreates a lifecycle row with kind=agent and mandatory sponsor.
post/v1/m/governance/agents/{agentID}/identitygovernance:identity:adminBearer tokenBinds an agent to its NHI identity (Agent.IdentityID).
delete/v1/m/governance/agents/{agentID}/identitygovernance:identity:adminBearer tokenClears an agent's identity binding.
get/v1/m/governance/approvalsgovernance:approval:readBearer tokenLists requests, optionally filtered by status/action.
post/v1/m/governance/approvalsgovernance:approval:writeBearer tokenOpens an approval request.
post/v1/m/governance/approvals/sweepgovernance:approval:adminBearer tokenMaterializes expiry and escalation for the tenant's pending approvals.
get/v1/m/governance/approvals/{id}governance:approval:readBearer tokenReturns one request with its effective status.
post/v1/m/governance/approvals/{id}/cancelgovernance:approval:writeBearer tokenCancels a pending request.
post/v1/m/governance/approvals/{id}/consumegovernance:approval:writeBearer tokengovernance module route (requires governance:approval:write)
get/v1/m/governance/approvals/{id}/decisionsgovernance:approval:readBearer tokenReturns the immutable decision trail for a request — the action→human traceability view.
post/v1/m/governance/approvals/{id}/decisionsgovernance:approval:adminBearer tokenRecords one human decision.
get/v1/m/governance/bindingsgovernance:idposture:readBearer tokenLists agent↔identity bindings, flagging identities shared across agents.
get/v1/m/governance/breakglassgovernance:breakglass:readBearer tokenLists grants, optionally filtered by stored status; a grant past its expiry reads as "expired" in its DTO regardless.
post/v1/m/governance/breakglassgovernance:breakglass:adminBearer tokenOpens an emergency window.
post/v1/m/governance/breakglass/consumegovernance:breakglass:writeBearer tokengovernance module route (requires governance:breakglass:write)
get/v1/m/governance/breakglass/{id}governance:breakglass:readBearer tokenReturns one grant with its effective status.
post/v1/m/governance/breakglass/{id}/reviewgovernance:breakglass:adminBearer tokenRecords the FORCED post-review of a terminal grant.
post/v1/m/governance/breakglass/{id}/revokegovernance:breakglass:adminBearer tokenCloses an active grant early.
get/v1/m/governance/breakglass/{id}/usesgovernance:breakglass:readBearer tokenReturns the immutable use trail for a grant — what actually proceeded under the emergency window (the post-review's evidence).
get/v1/m/governance/emerging-identity-standardsgovernance:identity:readBearer tokenSurfaces the design-toward registry read-only, with an explicit disclaimer that it is tracked, not implemented (IDN-12).
get/v1/m/governance/groupsgovernance:identity:readBearer tokenLists the reconciled collections (groups/roles/policies).
get/v1/m/governance/groups/{ref}/membersgovernance:identity:readBearer tokenLists a group's members.
get/v1/m/governance/guardian/actionsgovernance:guardian:readBearer tokenLists the containment trail, optionally by status.
get/v1/m/governance/guardian/rulesgovernance:guardian:readBearer tokengovernance module route (requires governance:guardian:read)
post/v1/m/governance/guardian/rulesgovernance:guardian:adminBearer tokenAuthors a containment rule.
put/v1/m/governance/guardian/rules/{id}governance:guardian:adminBearer tokenUpdates a rule's mutable fields (enable/disable, matching, action, mode, note).
delete/v1/m/governance/guardian/rules/{id}governance:guardian:adminBearer tokenDeletes a rule only after terminalizing every queued action that could otherwise execute from its denormalized action row.
get/v1/m/governance/identitiesgovernance:identity:readBearer tokenLists the reconciled identity roster.
get/v1/m/governance/killswitchgovernance:killswitch:readBearer tokenLists stop rows, optionally filtered by stored status — the persisted, visible stop state (who, when, scope, reason).
post/v1/m/governance/killswitchgovernance:killswitch:adminBearer tokengovernance module route (requires governance:killswitch:admin)
get/v1/m/governance/killswitch/stategovernance:killswitch:readBearer tokenReturns the live stop posture for the tenant.
get/v1/m/governance/killswitch/{id}governance:killswitch:readBearer tokenReturns one stop row.
get/v1/m/governance/killswitch/{id}/evidencegovernance:killswitch:adminBearer tokenBuilds and returns the incident evidence pack.
post/v1/m/governance/killswitch/{id}/reenablegovernance:killswitch:adminBearer tokenLifts a stop — NEVER unilaterally.
post/v1/m/governance/killswitch/{id}/reviewgovernance:killswitch:adminBearer tokenRecords the FORCED post-review of a re-enabled stop: a real human DIFFERENT from the engager, the re-enable requester and the re-enabler (separation of duties — nobody signs off their own incident), once, note mandatory.
get/v1/m/governance/nhigovernance:nhi:readBearer tokenLists the NHI lifecycle rows, optionally filtered by enforcement state or offboard state.
get/v1/m/governance/nhi/posturegovernance:nhi:readBearer tokenAggregates the lifecycle posture.
post/v1/m/governance/nhi/sweepgovernance:nhi:adminBearer tokenMaterializes staleness/escalation, orphan and unsponsored state for the tenant's NHI lifecycle rows, and ensures a row exists for every roster NHI.
get/v1/m/governance/nhi/{ref}governance:nhi:readBearer tokenReturns one NHI lifecycle row by identity_ref.
get/v1/m/governance/nhi/{ref}/eventsgovernance:nhi:readBearer tokenLists the append-only lifecycle event trail for one NHI.
post/v1/m/governance/nhi/{ref}/offboardgovernance:nhi:adminBearer tokenRuns the reversible soft-delete step of a governed offboarding: it blocks the NHI in-product (enforcement=blocked, the cascade that denies every bound agent at the PEP), opens an audited recovery window, and best-effort disables the credential at the source.
post/v1/m/governance/nhi/{ref}/offboard/finalizegovernance:nhi:adminBearer tokengovernance module route (requires governance:nhi:admin)
put/v1/m/governance/nhi/{ref}/ownershipgovernance:nhi:writeBearer tokenAssigns owner/sponsor.
put/v1/m/governance/nhi/{ref}/policygovernance:nhi:writeBearer tokenAuthors the per-NHI rotation policy.
post/v1/m/governance/nhi/{ref}/restoregovernance:nhi:adminBearer tokenReverses a soft-delete within the recovery window: best-effort re-enable at the source, clear the in-product block.
post/v1/m/governance/nhi/{ref}/rotategovernance:nhi:adminBearer tokenOrchestrates a governed rotation: it opens the CRITICAL approval (two-person floor via the engine), and only on an approved/break-glass decision invokes the wired actuator, returning the minted credential ONCE.
get/v1/m/governance/pdp/activegovernance:policy:readBearer tokenReports what the STORE currently selects for an engine, and — for cedar — discloses the other surfaces that are unioned into the enforced policy.
post/v1/m/governance/pdp/dry-rungovernance:policy:readBearer tokengovernance module route (requires governance:policy:read)
post/v1/m/governance/pdp/explaingovernance:policy:readBearer tokenEvaluates an example request against a CANDIDATE source and returns the three-valued decision chain: a matched permit GRANTS within scope, a matched forbid RESTRICTS, neither abstains (the RBAC decision stands).
post/v1/m/governance/pdp/publishgovernance:policy:adminBearer tokenPersists a versioned Cedar/OPA policy and, for Cedar, ACTIVATES it on the live hot path (recomposes the per-tenant overlay).
post/v1/m/governance/pdp/rollbackgovernance:policy:adminBearer tokenRe-activates an existing immutable revision by appending an activation record.
get/v1/m/governance/pdp/testsgovernance:policy:readBearer tokengovernance module route (requires governance:policy:read)
post/v1/m/governance/pdp/validategovernance:policy:readBearer tokenCompiles a source WITHOUT loading it into the live evaluator.
get/v1/m/governance/pdp/versionsgovernance:policy:readBearer tokenLists the cedar + opa authored revisions (the shared revision store, kinds cedar/opa).
get/v1/m/governance/pdp/versions/{revision}governance:policy:readBearer tokengovernance module route (requires governance:policy:read)
get/v1/m/governance/policiesgovernance:policy:readBearer tokenLists governance policies, optionally filtered by kind/enabled.
post/v1/m/governance/policiesgovernance:policy:adminBearer tokenAuthors a governance policy.
get/v1/m/governance/policies/{id}governance:policy:readBearer tokenReturns one governance policy.
put/v1/m/governance/policies/{id}governance:policy:adminBearer tokenUpdates a governance policy in place (kind is immutable).
delete/v1/m/governance/policies/{id}governance:policy:adminBearer tokenDeletes a governance policy.
get/v1/m/governance/rbac/cataloggovernance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
get/v1/m/governance/rbac/delegation-authoritygovernance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
get/v1/m/governance/rbac/grantsgovernance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
post/v1/m/governance/rbac/grantsgovernance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
get/v1/m/governance/rbac/grants/{id}governance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
delete/v1/m/governance/rbac/grants/{id}governance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
get/v1/m/governance/rbac/permission-groupsgovernance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
post/v1/m/governance/rbac/permission-groupsgovernance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
get/v1/m/governance/rbac/permission-groups/{name}governance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
put/v1/m/governance/rbac/permission-groups/{name}governance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
delete/v1/m/governance/rbac/permission-groups/{name}governance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
get/v1/m/governance/rbac/rolesgovernance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
post/v1/m/governance/rbac/rolesgovernance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
get/v1/m/governance/rbac/roles/{name}governance:rbac:readBearer tokengovernance module route (requires governance:rbac:read)
put/v1/m/governance/rbac/roles/{name}governance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
delete/v1/m/governance/rbac/roles/{name}governance:rbac:adminBearer tokengovernance module route (requires governance:rbac:admin)
post/v1/m/governance/roster/syncgovernance:identity:adminBearer tokenTriggers a roster reconciliation for the resolved tenant from the identity providers the composition root wired (UseRosterProviders).
get/v1/m/governance/routine-policiesgovernance:routine:readBearer tokenLists routine policies, optionally filtered by scope_kind or enabled.
post/v1/m/governance/routine-policiesgovernance:routine:adminBearer tokenCreates a routine policy.
get/v1/m/governance/routine-policies/posturegovernance:routine:readBearer tokenReturns the routine governance posture: EVERY policy in the tenant (enabled or not, with the two counters splitting them), plus the COMPOSED decision for one resolution scope.
get/v1/m/governance/routine-policies/{id}governance:routine:readBearer tokenReturns one routine policy by ID.
put/v1/m/governance/routine-policies/{id}governance:routine:adminBearer tokenUpdates a routine policy's mutable fields.
delete/v1/m/governance/routine-policies/{id}governance:routine:adminBearer tokenDeletes a routine policy.