{"items":[{"type":"link","label":"Scytale API","link":"/openapi","routeSlug":"/openapi","content":{"contentType":"overview","meta":{"name":"Scytale API"},"children":[{"nodeType":"container","panels":[{"title":"Download OpenAPI description","titleTranslationKey":"download.description.title","children":[{"kind":"download","label":"openapi.json","url":"/_bundle/openapi.json?download"},{"kind":"download","label":"openapi.yaml","url":"/_bundle/openapi.yaml?download"}]},{"title":"Overview","titleTranslationKey":"info.title","children":[]},{"title":"Languages","titleTranslationKey":"languages.title","children":[{"kind":"languages","options":[{"key":"curl","title":"curl","lang":"curl"},{"key":"javascript","title":"JavaScript","lang":"JavaScript"},{"key":"node","title":"Node.js","lang":"Node.js"},{"key":"python","title":"Python","lang":"Python"},{"key":"java","title":"Java","lang":"Java"},{"key":"csharp","title":"C#","lang":"C#"},{"key":"php","title":"PHP","lang":"PHP"},{"key":"go","title":"Go","lang":"Go"},{"key":"ruby","title":"Ruby","lang":"Ruby"},{"key":"r","title":"R","lang":"R"},{"key":"payload","title":"Payload","lang":"Payload"}]}]},{"title":"Servers","titleTranslationKey":"servers.title","children":[{"kind":"servers","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"mode":"default"}]}],"children":[{"nodeType":"overview-section-wrapper","children":[{"nodeType":"header","level":1,"label":"Scytale API (0.1.0)","showPageActions":true},{"nodeType":"overview-section-wrapper","children":[{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Read-only access to your Scytale compliance data."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Authenticate by exchanging your client credentials at "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for an"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"access token, then send it as "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Authorization: Bearer <token>"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}],"sectionId":"/openapi"}],"sectionId":"/openapi"}]}]}},{"type":"group","label":"Controls","link":"/openapi/controls","routeSlug":"/openapi/controls","items":[{"label":"List controls","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/controls/get_controls","routeSlug":"/openapi/controls/get_controls","metadata":{"seo":{"title":"List controls","description":"Return controls matching the filters, one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_controls","name":"List controls","isWebhook":false,"pointer":"/paths/~1v1~1controls/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List controls","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return controls matching the filters, one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row is a full control: code, name, description, owner, framework criteria,"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"framework (id and name), applicability, audit and the monitors feeding it. Filters"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"combine with AND."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every control that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"applicable","in":"query","schemaId":"schema_42","description":"True for only applicable controls, false for only inapplicable. Omit for both - note the dashboard counts applicable controls only, so pass true to match its totals."},{"name":"auditId","in":"query","schemaId":"schema_43","description":"Only controls under this audit (its id)."},{"name":"ownerId","in":"query","schemaId":"schema_44","description":"Only controls owned by this user, by exact user id (not a name)."},{"name":"sort","in":"query","schemaId":"schema_45","description":"Order of the results. Only 'rank' (the product's display order)."},{"name":"descending","in":"query","schemaId":"schema_46","description":"Sort descending instead of ascending."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1controls/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/controls","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"applicable","in":"query","required":false,"schemaId":"schema_42"},{"name":"auditId","in":"query","required":false,"schemaId":"schema_43"},{"name":"ownerId","in":"query","required":false,"schemaId":"schema_44"},{"name":"sort","in":"query","required":false,"schemaId":"schema_45"},{"name":"descending","in":"query","required":false,"schemaId":"schema_46"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/controls","href":"controls/get_controls","openApiOperationId":"get_controls","summary":"List controls"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Control_"}},"schemaId":"components/schemas/Page_Control_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1controls/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Control_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Control_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/controls/get_controls"}],"panels":[]}]},"httpPath":"/v1/controls"},{"label":"Get control by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/controls/get_control","routeSlug":"/openapi/controls/get_control","metadata":{"seo":{"title":"Get control by ID","description":"Return one control by id - the same shape as a list row."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_control","name":"Get control by ID","isWebhook":false,"pointer":"/paths/~1v1~1controls~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get control by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one control by id - the same shape as a list row."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific control after "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_controls"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", or when you already"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"hold an id."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_49","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The control's id, as returned by get_controls."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1controls~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/controls/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_49"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/controls/{id}","href":"controls/get_control","openApiOperationId":"get_control","summary":"Get control by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Control"}},"schemaId":"components/schemas/Control"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such control for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1controls~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Control","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Control"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/controls/get_control"}],"panels":[]}]},"httpPath":"/v1/controls/{id}"}],"content":{"contentType":"group","meta":{"name":"controls"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Controls","showPageActions":true},{"nodeType":"markdoc","content":"Controls are the core compliance unit in Scytale: each represents a security\nrequirement mapped to one or more framework criteria (e.g., SOC 2 CC6.1,\nISO 27001 A.9.4). Use this endpoint to retrieve your control set with owner,\napplicability, framework mapping, and linked monitors. Filter by audit,\napplicability, or owner to build control-status reports and ownership views.\n\nRelated resources: Audits, Monitors."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/controls","summary":"List controls","prefix":{"name":"get","color":"get"},"badges":[],"link":"/controls/get_controls","deprecated":false},{"title":"/v1/controls/{id}","summary":"Get control by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/controls/get_control","deprecated":false}]}]}]}]}},{"type":"group","label":"Audits","link":"/openapi/audits","routeSlug":"/openapi/audits","items":[{"label":"List audits","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/audits/get_audits","routeSlug":"/openapi/audits/get_audits","metadata":{"seo":{"title":"List audits","description":"Return the company's audits, one page at a time, newest audit period first."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_audits","name":"List audits","isWebhook":false,"pointer":"/paths/~1v1~1audits/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List audits","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return the company's audits, one page at a time, newest audit period first."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row is an audit engagement: the framework being audited (id and name), its"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"lifecycle status ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"active"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"not_active"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"completed"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), the audit period and"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"timestamps. Every audit is listed, whatever its status - narrow with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" to"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"answer \"what is our current audit\". Filters combine with AND."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every audit that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"status","in":"query","schemaId":"schema_50","description":"Only audits in this lifecycle status. Omit for all statuses."},{"name":"frameworkId","in":"query","schemaId":"schema_51","description":"Only audits of this framework (its id)."},{"name":"sort","in":"query","schemaId":"schema_52","description":"Field to order the results by. Audits with no value for it come last when descending."},{"name":"descending","in":"query","schemaId":"schema_53","description":"Newest first (the default); false for oldest first."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1audits/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/audits","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"status","in":"query","required":false,"schemaId":"schema_50"},{"name":"frameworkId","in":"query","required":false,"schemaId":"schema_51"},{"name":"sort","in":"query","required":false,"schemaId":"schema_52"},{"name":"descending","in":"query","required":false,"schemaId":"schema_53"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/audits","href":"audits/get_audits","openApiOperationId":"get_audits","summary":"List audits"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Audit_"}},"schemaId":"components/schemas/Page_Audit_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1audits/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Audit_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Audit_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/audits/get_audits"}],"panels":[]}]},"httpPath":"/v1/audits"},{"label":"Get audit by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/audits/get_audit","routeSlug":"/openapi/audits/get_audit","metadata":{"seo":{"title":"Get audit by ID","description":"Return one audit by id: a list row plus product, the product the audit isscoped to when the framework is certified per product (null otherwise)."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_audit","name":"Get audit by ID","isWebhook":false,"pointer":"/paths/~1v1~1audits~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get audit by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one audit by id: a list row plus "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"product"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", the product the audit is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"scoped to when the framework is certified per product (null otherwise)."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific audit after "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_audits"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", or to resolve the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"auditId"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" on a control."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_54","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The audit's id, as returned by get_audits."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1audits~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/audits/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_54"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/audits/{id}","href":"audits/get_audit","openApiOperationId":"get_audit","summary":"Get audit by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/AuditDetail"}},"schemaId":"components/schemas/AuditDetail"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such audit for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1audits~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/AuditDetail","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/AuditDetail"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/audits/get_audit"}],"panels":[]}]},"httpPath":"/v1/audits/{id}"}],"content":{"contentType":"group","meta":{"name":"audits"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Audits","showPageActions":true},{"nodeType":"markdoc","content":"An audit represents your company's engagement toward a specific framework\ncertification (e.g., a SOC 2 or ISO 27001 audit), including its status and\nperiod. Use this endpoint to retrieve your audits and track readiness across\nframeworks. Filter by status or framework.\n\nRelated resources: Controls."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/audits","summary":"List audits","prefix":{"name":"get","color":"get"},"badges":[],"link":"/audits/get_audits","deprecated":false},{"title":"/v1/audits/{id}","summary":"Get audit by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/audits/get_audit","deprecated":false}]}]}]}]}},{"type":"group","label":"Policies","link":"/openapi/policies","routeSlug":"/openapi/policies","items":[{"label":"List policies","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/policies/get_policies","routeSlug":"/openapi/policies/get_policies","metadata":{"seo":{"title":"List policies","description":"Return policies matching the filters, one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_policies","name":"List policies","isWebhook":false,"pointer":"/paths/~1v1~1policies/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List policies","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return policies matching the filters, one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row carries the policy's identity, its owner and approver, both statuses, and"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"when its sign-off was given and lapses. "},"children":[]},{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Metadata only - the policy document itself"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"is never returned."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Filters combine with AND."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" answers \"is this signed off and still valid\"; "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"workflowStatus"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" answers \"where"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"is it in its review cycle\". They can disagree: a policy whose sign-off expired is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"approval-required"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"signedOffAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" still set."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every policy that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"ownerId","in":"query","schemaId":"schema_55","description":"Only policies owned by this user, by exact user id (not a name)."},{"name":"approverId","in":"query","schemaId":"schema_56","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only policies this user must approve, by exact user id. Combine with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"workflowStatus=pending-approval"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for what is actually waiting on them."},"children":[]}]}]}]},{"name":"isExternalPolicy","in":"query","schemaId":"schema_57","description":"True for only externally managed policies, false for only internal. Omit for both."},{"name":"state","in":"query","schemaId":"schema_58","description":"Only policies in this compliance state."},{"name":"workflowStatus","in":"query","schemaId":"schema_59","description":"Only policies at this point in the review cycle."},{"name":"sort","in":"query","schemaId":"schema_60","description":"Order of the results."},{"name":"descending","in":"query","schemaId":"schema_46","description":"Sort descending instead of ascending."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1policies/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/policies","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"ownerId","in":"query","required":false,"schemaId":"schema_55"},{"name":"approverId","in":"query","required":false,"schemaId":"schema_56"},{"name":"isExternalPolicy","in":"query","required":false,"schemaId":"schema_57"},{"name":"state","in":"query","required":false,"schemaId":"schema_58"},{"name":"workflowStatus","in":"query","required":false,"schemaId":"schema_59"},{"name":"sort","in":"query","required":false,"schemaId":"schema_60"},{"name":"descending","in":"query","required":false,"schemaId":"schema_46"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/policies","href":"policies/get_policies","openApiOperationId":"get_policies","summary":"List policies"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Policy_"}},"schemaId":"components/schemas/Page_Policy_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1policies/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Policy_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Policy_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/policies/get_policies"}],"panels":[]}]},"httpPath":"/v1/policies"},{"label":"Get policy by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/policies/get_policy","routeSlug":"/openapi/policies/get_policy","metadata":{"seo":{"title":"Get policy by ID","description":"Return one policy by id - a list row plus this cycle's reviewers."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_policy","name":"Get policy by ID","isWebhook":false,"pointer":"/paths/~1v1~1policies~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get policy by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one policy by id - a list row plus this cycle's reviewers."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up after "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_policies"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", or when you already hold an id, to see who"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"was asked to review and which of them have finished."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_61","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The policy's id, as returned by get_policies."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1policies~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/policies/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_61"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/policies/{id}","href":"policies/get_policy","openApiOperationId":"get_policy","summary":"Get policy by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/PolicyDetail"}},"schemaId":"components/schemas/PolicyDetail"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such policy for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1policies~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/PolicyDetail","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/PolicyDetail"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/policies/get_policy"}],"panels":[]}]},"httpPath":"/v1/policies/{id}"}],"content":{"contentType":"group","meta":{"name":"policies"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Policies","showPageActions":true},{"nodeType":"markdoc","content":"Policies are the security and compliance policies managed in Scytale, each with\nan owner, version, and sign-off status. Use this endpoint to retrieve your\npolicies and track coverage and outstanding approvals. Filter by owner, state,\nor workflow status.\n\nRelated resources: Controls."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/policies","summary":"List policies","prefix":{"name":"get","color":"get"},"badges":[],"link":"/policies/get_policies","deprecated":false},{"title":"/v1/policies/{id}","summary":"Get policy by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/policies/get_policy","deprecated":false}]}]}]}]}},{"type":"group","label":"Monitors","link":"/openapi/monitors","routeSlug":"/openapi/monitors","items":[{"label":"List monitors","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/monitors/get_monitors","routeSlug":"/openapi/monitors/get_monitors","metadata":{"seo":{"title":"List monitors","description":"Return monitors - the automated and manual checks feeding controls - one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_monitors","name":"List monitors","isWebhook":false,"pointer":"/paths/~1v1~1monitors/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List monitors","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return monitors - the automated and manual checks feeding controls - one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row carries the monitor's identity, its "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", the integrations feeding it,"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"when it last ran, its owner, and how many controls it feeds ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"controlCount"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"). The"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"controls themselves are on "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_monitor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":": \"which controls are affected by our failing"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"checks\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state=non-compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" here, then "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_monitor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" on each of those few rows -"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"not a walk of this list. Filters combine with AND."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is the verdict of the latest automated evidence and has three values, not"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"two: "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"non-compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" when a check failed since the monitor was last reviewed,"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" when checks ran and none is failing, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pending"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" when no automated evidence"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"has been collected - a manual monitor, or an integration that has not run. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pending"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"is a third answer, not a failure: do not count it as either. \"Which checks are"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"failing\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state=non-compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"which checks have never produced a verdict\" is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state=pending"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"when did our AWS checks last run\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lastRunAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" on the rows whose"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"integrationNames"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" start with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"aws-"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every monitor that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"state","in":"query","schemaId":"schema_62","description":"Only monitors in this state. Three values, not two: non-compliant (a check failed since the last review), compliant (checks ran and none is failing), pending (no automated evidence has been collected, so there is no verdict either way - a manual monitor, or an integration that has not run)."},{"name":"ownerId","in":"query","schemaId":"schema_63","description":"Only monitors owned by this user, by exact user id (not a name)."},{"name":"frequency","in":"query","schemaId":"schema_64","description":"Only monitors meant to run at this frequency."},{"name":"inactive","in":"query","schemaId":"schema_65","description":"True for only switched-off monitors, false for only active ones. Omit for both."},{"name":"sort","in":"query","schemaId":"schema_66","description":"Order of the results."},{"name":"descending","in":"query","schemaId":"schema_46","description":"Sort descending instead of ascending."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1monitors/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/monitors","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"state","in":"query","required":false,"schemaId":"schema_62"},{"name":"ownerId","in":"query","required":false,"schemaId":"schema_63"},{"name":"frequency","in":"query","required":false,"schemaId":"schema_64"},{"name":"inactive","in":"query","required":false,"schemaId":"schema_65"},{"name":"sort","in":"query","required":false,"schemaId":"schema_66"},{"name":"descending","in":"query","required":false,"schemaId":"schema_46"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/monitors","href":"monitors/get_monitors","openApiOperationId":"get_monitors","summary":"List monitors"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Monitor_"}},"schemaId":"components/schemas/Page_Monitor_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1monitors/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Monitor_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Monitor_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/monitors/get_monitors"}],"panels":[]}]},"httpPath":"/v1/monitors"},{"label":"Get monitor by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/monitors/get_monitor","routeSlug":"/openapi/monitors/get_monitor","metadata":{"seo":{"title":"Get monitor by ID","description":"Return one monitor by id - a list row plus controls, the controls it feeds."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_monitor","name":"Get monitor by ID","isWebhook":false,"pointer":"/paths/~1v1~1monitors~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get monitor by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one monitor by id - a list row plus "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"controls"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", the controls it feeds."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific monitor after "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_monitors"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", or from a control's"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"monitorIds"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", to see what the check is, which of the three states it is in, when it"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"last ran and which controls a failure affects."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_67","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The monitor's id, as returned by get_monitors."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1monitors~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/monitors/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_67"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/monitors/{id}","href":"monitors/get_monitor","openApiOperationId":"get_monitor","summary":"Get monitor by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MonitorDetail"}},"schemaId":"components/schemas/MonitorDetail"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such monitor for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1monitors~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/MonitorDetail","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MonitorDetail"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/monitors/get_monitor"}],"panels":[]}]},"httpPath":"/v1/monitors/{id}"}],"content":{"contentType":"group","meta":{"name":"monitors"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Monitors","showPageActions":true},{"nodeType":"markdoc","content":"Monitors are the automated and manual checks that continuously verify a\ncontrol's requirements are being met, each linked to one or more controls and\noften fed by integrations. Use this endpoint to retrieve monitor state\n(compliant / non-compliant / pending), frequency, last run, and connected\nintegrations. Filter by state, owner, frequency, or active/inactive.\n\nRelated resources: Controls."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/monitors","summary":"List monitors","prefix":{"name":"get","color":"get"},"badges":[],"link":"/monitors/get_monitors","deprecated":false},{"title":"/v1/monitors/{id}","summary":"Get monitor by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/monitors/get_monitor","deprecated":false}]}]}]}]}},{"type":"group","label":"Vendors","link":"/openapi/vendors","routeSlug":"/openapi/vendors","items":[{"label":"List vendors","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/vendors/get_vendors","routeSlug":"/openapi/vendors/get_vendors","metadata":{"seo":{"title":"List vendors","description":"Return vendors - the third parties the company tracks for third-party risk - one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_vendors","name":"List vendors","isWebhook":false,"pointer":"/paths/~1v1~1vendors/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List vendors","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return vendors - the third parties the company tracks for third-party risk - one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row is the whole vendor: identity ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"website"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"category"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"),"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"how much the business depends on it ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"criticality"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), where the relationship stands"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lifeCycle"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), its risk ratings ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"businessRisk"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and the confidentiality, integrity and"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"availability risks), what data it handles ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"dataClassification"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"sensitiveDataTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"),"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the due diligence on file ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"certifications"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"dpaOnFile"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"signedContract"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":","},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"penetrationTestConducted"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), and the review cycle ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"reviewFrequency"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lastReviewDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":","},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"nextReviewDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"ownerId"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"). A vendor added from Scytale's catalog shows the catalog's"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"values wherever the company recorded none, so a row is never missing its name."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_vendor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" returns the same shape; there is nothing more on the detail."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filters combine with AND. \"Which vendors do we currently use\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lifeCycle=active"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":";"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"\"our high-risk vendors\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"businessRisk=high"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"which vendors have never been"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"reviewed\" is the rows with a null "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lastReviewDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"which reviews are overdue\" is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"sort=nextReviewDate&descending=false"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", reading rows whose "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"nextReviewDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is in the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"past; \"which vendors are missing a DPA\" is the rows whose "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"dpaOnFile"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is false or null."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every vendor that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"criticality","in":"query","schemaId":"schema_68","description":"Only vendors of this criticality. A vendor with none recorded counts as critical."},{"name":"lifeCycle","in":"query","schemaId":"schema_69","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only vendors at this lifecycle stage. 'Vendors we use today' is lifeCycle=active."},"children":[]}]}]}]},{"name":"businessRisk","in":"query","schemaId":"schema_70","description":"Only vendors rated at this overall business risk."},{"name":"category","in":"query","schemaId":"schema_71","description":"Only vendors in this category - the catalog's category for a catalog vendor the company did not recategorise."},{"name":"sort","in":"query","schemaId":"schema_72","description":"Order of the results. Vendors with no value for the field come last when descending; name sorts case-insensitively."},{"name":"descending","in":"query","schemaId":"schema_53","description":"Newest first (the default); false for oldest first."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1vendors/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/vendors","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"criticality","in":"query","required":false,"schemaId":"schema_68"},{"name":"lifeCycle","in":"query","required":false,"schemaId":"schema_69"},{"name":"businessRisk","in":"query","required":false,"schemaId":"schema_70"},{"name":"category","in":"query","required":false,"schemaId":"schema_71"},{"name":"sort","in":"query","required":false,"schemaId":"schema_72"},{"name":"descending","in":"query","required":false,"schemaId":"schema_53"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/vendors","href":"vendors/get_vendors","openApiOperationId":"get_vendors","summary":"List vendors"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Vendor_"}},"schemaId":"components/schemas/Page_Vendor_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1vendors/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Vendor_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Vendor_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/vendors/get_vendors"}],"panels":[]}]},"httpPath":"/v1/vendors"},{"label":"Get vendor by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/vendors/get_vendor","routeSlug":"/openapi/vendors/get_vendor","metadata":{"seo":{"title":"Get vendor by ID","description":"Return one vendor by id - the same shape as a get_vendors row."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_vendor","name":"Get vendor by ID","isWebhook":false,"pointer":"/paths/~1v1~1vendors~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get vendor by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one vendor by id - the same shape as a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_vendors"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" row."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific vendor when you already hold its id; to find vendors"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"by name, criticality, lifecycle, risk or category, use "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_vendors"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_73","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The vendor's id, as returned by get_vendors."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1vendors~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/vendors/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_73"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/vendors/{id}","href":"vendors/get_vendor","openApiOperationId":"get_vendor","summary":"Get vendor by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Vendor"}},"schemaId":"components/schemas/Vendor"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such vendor for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1vendors~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Vendor","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Vendor"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/vendors/get_vendor"}],"panels":[]}]},"httpPath":"/v1/vendors/{id}"}],"content":{"contentType":"group","meta":{"name":"vendors"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Vendors","showPageActions":true},{"nodeType":"markdoc","content":"Vendors are the third parties you share information with, each assessed for\nthe risk that relationship carries. Use this endpoint to retrieve your vendor\nregister with criticality, lifecycle stage, data classification, business and\nsecurity risk ratings, certifications held, and review dates. Filter by\ncriticality, lifecycle, business risk, or category to surface the vendors\nthat need attention or to drive a review cycle."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/vendors","summary":"List vendors","prefix":{"name":"get","color":"get"},"badges":[],"link":"/vendors/get_vendors","deprecated":false},{"title":"/v1/vendors/{id}","summary":"Get vendor by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/vendors/get_vendor","deprecated":false}]}]}]}]}},{"type":"group","label":"People","link":"/openapi/people","routeSlug":"/openapi/people","items":[{"label":"List people","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/people/get_people","routeSlug":"/openapi/people/get_people","metadata":{"seo":{"title":"List people","description":"Return people - the employees the company tracks for compliance coverage - one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_people","name":"List people","isWebhook":false,"pointer":"/paths/~1v1~1people/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List people","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return people - the employees the company tracks for compliance coverage - one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row is the whole person: "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"firstName"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lastName"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"email"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"jobTitle"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":","},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"employmentStatus"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (active or inactive), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"source"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (csv or the integration that synced"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the record), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"hiringDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and the record's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" /"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"updatedAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Where the company edited a synced value in Scytale, the edit is what is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"served. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_person"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" returns the same shape; there is nothing more on the detail."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filters combine with AND. \"Who works here today\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"employmentStatus=active"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"who"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"has left, and when\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"employmentStatus=inactive"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", reading "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; \"who"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"are our newest joiners\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"sort=hiringDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (newest first by default); \"who came from"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"our HR system\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"source=<its internal name>"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Training, onboarding and policy-acknowledgement status are not on this resource:"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"they are computed from the person's group memberships and are not part of the People"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"schema."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every person that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated. People the company excluded from compliance scope are not"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"returned."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"employmentStatus","in":"query","schemaId":"schema_74","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only people with this employment status. active is the current workforce; inactive is everyone who has left (there is no 'terminated' status - read "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]}]}]}]},{"name":"source","in":"query","schemaId":"schema_75","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only people whose record came from this source: "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"csv"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for a CSV import, otherwise an integration's internal name as it appears on the rows (bamboohr, hibob, personio, deel, okta, microsoft-graph, google-workspace-hr, ...). A source none of this company's people came from is refused with a 400 rather than answered with an empty page."},"children":[]}]}]}]},{"name":"sort","in":"query","schemaId":"schema_76","description":"Order of the results. People with no value for the field come last when descending; lastName and email sort case-insensitively."},{"name":"descending","in":"query","schemaId":"schema_53","description":"Newest first (the default); false for oldest first."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1people/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/people","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"employmentStatus","in":"query","required":false,"schemaId":"schema_74"},{"name":"source","in":"query","required":false,"schemaId":"schema_75"},{"name":"sort","in":"query","required":false,"schemaId":"schema_76"},{"name":"descending","in":"query","required":false,"schemaId":"schema_53"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/people","href":"people/get_people","openApiOperationId":"get_people","summary":"List people"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Person_"}},"schemaId":"components/schemas/Page_Person_"},{"code":"400","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A filter value is not valid - including a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"source"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" none of this company's people came from. The error code is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"bad_request"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}],"mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1people/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Person_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Person_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/people/get_people"}],"panels":[]}]},"httpPath":"/v1/people"},{"label":"Get person by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/people/get_person","routeSlug":"/openapi/people/get_person","metadata":{"seo":{"title":"Get person by ID","description":"Return one person by id - the same shape as a get_people row."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_person","name":"Get person by ID","isWebhook":false,"pointer":"/paths/~1v1~1people~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get person by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one person by id - the same shape as a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_people"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" row."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific person when you already hold their id; to find"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"people by employment status or source, use "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_people"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_77","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The person's id, as returned by get_people."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1people~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/people/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_77"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/people/{id}","href":"people/get_person","openApiOperationId":"get_person","summary":"Get person by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Person"}},"schemaId":"components/schemas/Person"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such person for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1people~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Person","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Person"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/people/get_person"}],"panels":[]}]},"httpPath":"/v1/people/{id}"}],"content":{"contentType":"group","meta":{"name":"people"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"People","showPageActions":true},{"nodeType":"markdoc","content":"People are the team members in scope for your compliance program, the\npopulation your controls and policies apply to. Use this endpoint to\nretrieve your roster with name, work email, job title, employment status,\nand how each person was added, whether manually or through a connected HR\nintegration. Filter by employment status or source to scope a report to\ncurrent employees, or to the people a particular system brought in.\n\nRelated resources: Policies, Controls."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/people","summary":"List people","prefix":{"name":"get","color":"get"},"badges":[],"link":"/people/get_people","deprecated":false},{"title":"/v1/people/{id}","summary":"Get person by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/people/get_person","deprecated":false}]}]}]}]}},{"type":"group","label":"Risks","link":"/openapi/risks","routeSlug":"/openapi/risks","items":[{"label":"List risks","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/risks/get_risks","routeSlug":"/openapi/risks/get_risks","metadata":{"seo":{"title":"List risks","description":"Return the company's risk register - each risk with its scores, treatment and owner -one page at a time."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_risks","name":"List risks","isWebhook":false,"pointer":"/paths/~1v1~1risks/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List risks","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return the company's risk register - each risk with its scores, treatment and owner -"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"one page at a time."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Each row carries the risk's title and description, the kind of asset it threatens and"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"that asset's classification, its inherent "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"likelihood"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"impact"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (before treatment)"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"and its "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"residualLikelihood"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"residualImpact"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (after), the chosen treatment"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatment"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":": mitigate, transfer, avoid, accept), how far along it is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentStatus"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":": incomplete, complete), the treatment plan ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentPlan"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":": its"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"tasks, each with whether it is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"completed"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and the rationale written for a transfer,"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"avoid or accept decision under "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"rationales.<treatment>"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), free-text notes"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"mitigationInfo"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") and the owner's user id."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The detail ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_risk"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") is the same shape; nothing is held back from the list."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filters combine with AND."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Scores are integers on the company's own scale, 1..N where N is its risk matrix size"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"(3 to 10, 5 by default); a risk score is likelihood x impact. \"Show our highest-severity"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"open risks\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentStatus=incomplete"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" sorted by likelihood x impact on the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"client. \"Which risks have we accepted vs. are actively treating\" is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatment=accept"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"against "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatment=mitigate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". \"Which risks are still unmitigated\" is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentStatus=incomplete"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". \"Which treatment tasks are still open\" is the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentPlan.tasks"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"completed"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" false."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.total"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is every risk that matched, across all pages. A null"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" means there are no more results - it does not mean the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"results were truncated."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"treatmentStatus","in":"query","schemaId":"schema_78","description":"Only risks whose treatment is in this state: incomplete (still being treated, or not started) or complete. 'Which risks are still unmitigated' is incomplete."},{"name":"treatment","in":"query","schemaId":"schema_79","description":"Only risks treated this way: mitigate (reduced with controls), transfer (passed to a third party), avoid (the activity stopped) or accept (lived with). A risk with no treatment decided yet matches none of them."},{"name":"ownerId","in":"query","schemaId":"schema_80","description":"Only risks owned by this user, by exact user id (not a name)."},{"name":"sort","in":"query","schemaId":"schema_81","description":"Order of the results."},{"name":"descending","in":"query","schemaId":"schema_82","description":"Sort descending instead of ascending."},{"name":"cursor","in":"query","schemaId":"schema_47","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"name":"limit","in":"query","schemaId":"schema_48","description":"Results per page (1-100)."}],"pointer":"/paths/~1v1~1risks/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/risks","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[],"query":[{"name":"treatmentStatus","in":"query","required":false,"schemaId":"schema_78"},{"name":"treatment","in":"query","required":false,"schemaId":"schema_79"},{"name":"ownerId","in":"query","required":false,"schemaId":"schema_80"},{"name":"sort","in":"query","required":false,"schemaId":"schema_81"},{"name":"descending","in":"query","required":false,"schemaId":"schema_82"},{"name":"cursor","in":"query","required":false,"schemaId":"schema_47"},{"name":"limit","in":"query","required":false,"schemaId":"schema_48"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","503"],"pointer":"/v1/risks","href":"risks/get_risks","openApiOperationId":"get_risks","summary":"List risks"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Risk_"}},"schemaId":"components/schemas/Page_Risk_"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1risks/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Page_Risk_","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Page_Risk_"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/risks/get_risks"}],"panels":[]}]},"httpPath":"/v1/risks"},{"label":"Get risk by ID","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/risks/get_risk","routeSlug":"/openapi/risks/get_risk","metadata":{"seo":{"title":"Get risk by ID","description":"Return one risk by id - the same shape as a get_risks row."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"get_risk","name":"Get risk by ID","isWebhook":false,"pointer":"/paths/~1v1~1risks~1{id}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get risk by ID","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Return one risk by id - the same shape as a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_risks"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" row."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use it to follow up on a specific risk when you already hold its id; to find risks by"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"treatment, status or owner, use "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_risks"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"BearerAuth","scopes":[],"type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"id","in":"path","schemaId":"schema_83","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The risk's id, as returned by get_risks."},"children":[]}]}]}],"required":true}],"pointer":"/paths/~1v1~1risks~1{id}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/risks/{id}","servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"parameters":{"path":[{"name":"id","in":"path","required":true,"schemaId":"schema_83"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT"}],"scopes":[]}],"responseCodes":["200","400","401","404","503"],"pointer":"/v1/risks/{id}","href":"risks/get_risk","openApiOperationId":"get_risk","summary":"Get risk by ID"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi","description":"Mock server","isMockServer":true},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful Response","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Risk"}},"schemaId":"components/schemas/Risk"},{"code":"400","description":"Invalid or unknown parameter, page size or cursor.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"401","description":"Missing or invalid credentials.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"404","description":"No such risk for this company.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"},{"code":"503","description":"Data is temporarily unavailable.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}},"schemaId":"components/schemas/ErrorResponse"}],"pointer":"/paths/~1v1~1risks~1{id}/get/responses"}],"panels":[{"children":[{"kind":"response","responseCodes":[{"code":"200","schemaId":"components/schemas/Risk","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Risk"}}},{"code":"400","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"401","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"404","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}},{"code":"503","schemaId":"components/schemas/ErrorResponse","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/ErrorResponse"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/risks/get_risk"}],"panels":[]}]},"httpPath":"/v1/risks/{id}"}],"content":{"contentType":"group","meta":{"name":"risks"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Risks","showPageActions":true},{"nodeType":"markdoc","content":"Risks are the entries in your risk register, each scored for likelihood and\nimpact and tracked through to mitigation. Use this endpoint to retrieve your\nregister with the affected asset and its classification, inherent and\nresidual scores, owner, and mitigation plan and status. Filter by mitigation\nstatus, mitigation plan, or owner to report on open exposure or on the risks\na particular team is carrying.\n\nRelated resources: Controls, Vendors."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/v1/risks","summary":"List risks","prefix":{"name":"get","color":"get"},"badges":[],"link":"/risks/get_risks","deprecated":false},{"title":"/v1/risks/{id}","summary":"Get risk by ID","prefix":{"name":"get","color":"get"},"badges":[],"link":"/risks/get_risk","deprecated":false}]}]}]}]}}],"store":{"schemaStore":{"components/schemas/ApprovalManagement":{"id":"components/schemas/ApprovalManagement","kind":"json-schema","title":"ApprovalManagement","data":{"type":"string","enum":["scytale","external"],"title":"ApprovalManagement","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Who owns approval of an external policy: Scytale, or the external system it came from."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only meaningful on an external policy; null on an internal one. When the external system"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"owns approval, Scytale does not track a next sign-off date, so "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"signOffExpiresAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is null."},"children":[]}]}]}]}},"components/schemas/Audit":{"id":"components/schemas/Audit","kind":"json-schema","title":"Audit","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"framework":{"anyOf":[{"$ref":"#/components/schemas/FrameworkRef"},{"type":"null"}],"description":"The framework being audited."},"status":{"$ref":"#/components/schemas/AuditStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Lifecycle status: active, not_active or completed."},"children":[]}]}]}]},"startDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Start of the audit period; null when not set."},"endDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"End of the audit period; null when not set."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the audit was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the audit."}},"type":"object","required":["id","status"],"title":"Audit","description":"One audit as a list row: the framework being audited, where it stands and its period."}},"components/schemas/AuditDetail":{"id":"components/schemas/AuditDetail","kind":"json-schema","title":"AuditDetail","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"framework":{"anyOf":[{"$ref":"#/components/schemas/FrameworkRef"},{"type":"null"}],"description":"The framework being audited."},"status":{"$ref":"#/components/schemas/AuditStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Lifecycle status: active, not_active or completed."},"children":[]}]}]}]},"startDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Start of the audit period; null when not set."},"endDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"End of the audit period; null when not set."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the audit was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the audit."},"product":{"anyOf":[{"$ref":"#/components/schemas/ProductRef"},{"type":"null"}],"description":"The product audited; null when not per-product."}},"type":"object","required":["id","status"],"title":"AuditDetail","description":"One audit in full: a list row plus the product it is scoped to, when the framework is\ncertified per product."}},"components/schemas/AuditStatus":{"id":"components/schemas/AuditStatus","kind":"json-schema","title":"AuditStatus","data":{"type":"string","enum":["active","not_active","completed"],"title":"AuditStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Where an audit is in its lifecycle. Stored by the product; served as snake_case."},"children":[]}]}]}]}},"components/schemas/Control":{"id":"components/schemas/Control","kind":"json-schema","title":"Control","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"code":{"type":"string","description":"Scytale's control reference, e.g. CC.01.08 - the company's override when set."},"name":{"type":"string","description":"Human-readable control name."},"description":{"type":"string","description":"What the control requires."},"applicable":{"type":"boolean","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"False when scoped out of this company's programme. Lists and counts here include inapplicable controls unless filtered by "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"applicable"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; the product's dashboard counts applicable controls only, so totals differ by the inapplicable ones."},"children":[]}]}]}]},"owner":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who owns the control; null when unassigned."},"criteria":{"items":{"$ref":"#/components/schemas/Criterion"},"type":"array","description":"Framework criteria the control maps to."},"auditId":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"The audit this control sits under."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the control was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the control."},"monitorIds":{"items":{"type":"string"},"type":"array","description":"Monitors feeding this control."},"framework":{"anyOf":[{"$ref":"#/components/schemas/FrameworkRef"},{"type":"null"}],"description":"The framework it derives from."}},"type":"object","required":["id","code","name","description","applicable"],"title":"Control","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"One control: the twelve public fields, identical on the list and the detail route."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two more are read on every control and never served - "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"exclude=True"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" keeps them out of"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the JSON and out of the OpenAPI schema: "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"rank"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", the product's display order, used for"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"sorting and the keyset cursor; and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", derived from the linked monitorings"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"data/control_state.py"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"), which drives "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"find_open_audit_items"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and its summary but is"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"not part of the public contract"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/ControlRef":{"id":"components/schemas/ControlRef","kind":"json-schema","title":"ControlRef","data":{"properties":{"id":{"type":"string","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Control id, as "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_control"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" takes it."},"children":[]}]}]}]},"code":{"type":"string","description":"Scytale's control reference, e.g. CC.01.08 - the company's override when set."},"name":{"type":"string","description":"Human-readable control name."}},"type":"object","required":["id","code","name"],"title":"ControlRef","description":"A control this monitor feeds, named so a failing check can be traced to what it\naffects without a second call."}},"components/schemas/Criterion":{"id":"components/schemas/Criterion","kind":"json-schema","title":"Criterion","data":{"properties":{"code":{"type":"string","description":"The framework's own reference for the criterion."},"description":{"type":"string","description":"What the criterion requires."}},"type":"object","required":["code","description"],"title":"Criterion","description":"A framework criterion the control maps to, e.g. SOC 2 CC3.3 or ISO 27001 A.9.4."}},"components/schemas/EmploymentStatus":{"id":"components/schemas/EmploymentStatus","kind":"json-schema","title":"EmploymentStatus","data":{"type":"string","enum":["active","inactive"],"title":"EmploymentStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Whether the person currently works for the company. The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"EmployeeStatusTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":":"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"two values, no \"terminated\" - someone who left is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"inactive"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/ErrorDetail":{"id":"components/schemas/ErrorDetail","kind":"json-schema","title":"ErrorDetail","data":{"properties":{"code":{"type":"string"},"message":{"type":"string"}},"type":"object","required":["code","message"],"title":"ErrorDetail"}},"components/schemas/ErrorResponse":{"id":"components/schemas/ErrorResponse","kind":"json-schema","title":"ErrorResponse","data":{"properties":{"error":{"$ref":"#/components/schemas/ErrorDetail"}},"type":"object","required":["error"],"title":"ErrorResponse","description":"The body of every non-2xx answer. Also the schema the OpenAPI document names."}},"components/schemas/FrameworkRef":{"id":"components/schemas/FrameworkRef","kind":"json-schema","title":"FrameworkRef","data":{"properties":{"id":{"type":"string","description":"Framework id."},"name":{"type":"string","description":"Framework display name, e.g. 'SOC 2 Type II'."}},"type":"object","required":["id","name"],"title":"FrameworkRef","description":"A compliance framework, e.g. SOC 2 or ISO 27001."}},"components/schemas/Monitor":{"id":"components/schemas/Monitor","kind":"json-schema","title":"Monitor","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"code":{"type":"string","description":"Scytale's monitor reference, e.g. SRC.04 or MON.12 for a custom monitor."},"name":{"type":"string","description":"Human-readable monitor name."},"description":{"type":"string","description":"What the monitor checks; empty when the product has none."},"state":{"$ref":"#/components/schemas/MonitorState","description":"Verdict of the latest automated evidence: non-compliant (a check failed since the last review), compliant (checks ran and none is failing) or pending (no automated evidence collected - manual monitors, or an integration that has not run)."},"frequency":{"$ref":"#/components/schemas/MonitorFrequency","description":"How often the check is meant to run."},"owner":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who owns the monitor; null when unassigned."},"inactive":{"type":"boolean","description":"True when the monitor is switched off - by a user, or automatically because no active control needs it. An inactive monitor still lists, so a caller can see it."},"isMandatory":{"type":"boolean","description":"True when the product requires this monitor for its frameworks."},"isCustom":{"type":"boolean","description":"True when the company created this monitor itself rather than from a template."},"dueDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When manual evidence is next due, if a due date is active; null otherwise."},"integrationNames":{"items":{"type":"string"},"type":"array","description":"Integrations that feed this monitor, by identifier (e.g. aws-iam, github). Empty for a manual monitor."},"problemDescription":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"What a failing result means, in the product's words; null when it has none."},"howToFixUrl":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Where the product points for remediation guidance."},"lastRunAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When automated evidence for this monitor was last collected or updated; null if it never has been."},"controlCount":{"type":"integer","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"How many controls in this company this monitor feeds. 0 when unlinked. The controls themselves are on "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_monitor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the monitor was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the monitor."}},"type":"object","required":["id","code","name","description","state","frequency","inactive","isMandatory","isCustom","controlCount"],"title":"Monitor","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"One monitor: what it checks, how it is fed, whether it is passing, and what it affects."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The per-evidence verdicts the state is derived from ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"evidencesCompliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", one entry per"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"collected evidence item) are read on every monitor and never served: they are large,"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"internal, and summarised by "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"lastRunAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/MonitorDetail":{"id":"components/schemas/MonitorDetail","kind":"json-schema","title":"MonitorDetail","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"code":{"type":"string","description":"Scytale's monitor reference, e.g. SRC.04 or MON.12 for a custom monitor."},"name":{"type":"string","description":"Human-readable monitor name."},"description":{"type":"string","description":"What the monitor checks; empty when the product has none."},"state":{"$ref":"#/components/schemas/MonitorState","description":"Verdict of the latest automated evidence: non-compliant (a check failed since the last review), compliant (checks ran and none is failing) or pending (no automated evidence collected - manual monitors, or an integration that has not run)."},"frequency":{"$ref":"#/components/schemas/MonitorFrequency","description":"How often the check is meant to run."},"owner":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who owns the monitor; null when unassigned."},"inactive":{"type":"boolean","description":"True when the monitor is switched off - by a user, or automatically because no active control needs it. An inactive monitor still lists, so a caller can see it."},"isMandatory":{"type":"boolean","description":"True when the product requires this monitor for its frameworks."},"isCustom":{"type":"boolean","description":"True when the company created this monitor itself rather than from a template."},"dueDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When manual evidence is next due, if a due date is active; null otherwise."},"integrationNames":{"items":{"type":"string"},"type":"array","description":"Integrations that feed this monitor, by identifier (e.g. aws-iam, github). Empty for a manual monitor."},"problemDescription":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"What a failing result means, in the product's words; null when it has none."},"howToFixUrl":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Where the product points for remediation guidance."},"lastRunAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When automated evidence for this monitor was last collected or updated; null if it never has been."},"controlCount":{"type":"integer","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"How many controls in this company this monitor feeds. 0 when unlinked. The controls themselves are on "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"get_monitor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the monitor was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the monitor."},"controls":{"items":{"$ref":"#/components/schemas/ControlRef"},"type":"array","description":"The controls this monitor feeds, in this company, ordered by code. Empty when unlinked. Fetch this for the rows you are asking about rather than paging the list for it - a monitor commonly feeds the same requirement across several frameworks."}},"type":"object","required":["id","code","name","description","state","frequency","inactive","isMandatory","isCustom","controlCount"],"title":"MonitorDetail","description":"One monitor in full: a list row plus the controls it feeds."}},"components/schemas/MonitorFrequency":{"id":"components/schemas/MonitorFrequency","kind":"json-schema","title":"MonitorFrequency","data":{"type":"string","enum":["manual","daily","weekly","monthly","quarterly","semi-annual","annual"],"title":"MonitorFrequency","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"How often the check is meant to run. The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"MonitoringFrequencies"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"; an"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"automated monitor is "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"daily"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", a manual one defaults to "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"annual"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/MonitorState":{"id":"components/schemas/MonitorState","kind":"json-schema","title":"MonitorState","data":{"type":"string","enum":["compliant","non-compliant","pending"],"title":"MonitorState","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The verdict of the monitor's latest automated evidence."},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"*"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"non-compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - at least one automated check failed, and the failure is newer than"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the monitor's last review (\"marked as reviewed\" in the product). This is the Control"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Center's "},"children":[]},{"$$mdtype":"Node","type":"em","inline":true,"attributes":{"marker":"*"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"attention"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" rule for automated monitors, ported as is."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"compliant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - automated evidence has been collected and none of it is failing, or every"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"failure has since been reviewed."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pending"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - no automated evidence has been collected yet, so there is no verdict: a"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"manual monitor, or an integration that has not run."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Three values on purpose. The tickets say \"pass/fail\", but collapsing "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pending"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" into either"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"side would report a manual monitor as failing, or a never-run integration as passing."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"tests/test_rest_contract.py"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" pins the enum to exactly these three."},"children":[]}]}]}]}},"components/schemas/Owner":{"id":"components/schemas/Owner","kind":"json-schema","title":"Owner","data":{"properties":{"id":{"type":"string","description":"User id."},"name":{"type":"string","description":"Display name; the email when the user has no name on record."},"email":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Email address, when known."}},"type":"object","required":["id","name"],"title":"Owner","description":"The user who owns a control."}},"components/schemas/PageInfo":{"id":"components/schemas/PageInfo","kind":"json-schema","title":"PageInfo","data":{"properties":{"hasMore":{"type":"boolean","description":"True when another page follows. False means you have seen everything."},"nextCursor":{"anyOf":[{"type":"string"},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Pass as "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"cursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" to fetch the next page. Null means there are no more results - it does not mean the results were truncated."},"children":[]}]}]}]},"limit":{"type":"integer","description":"The page size actually applied, after clamping to the allowed range."},"total":{"anyOf":[{"type":"integer"},{"type":"null"}],"description":"Total across all pages when known. Null means not counted, which is not the same as zero."}},"type":"object","required":["hasMore","limit"],"title":"PageInfo","description":"Where a page sits in its collection."}},"components/schemas/Page_Audit_":{"id":"components/schemas/Page_Audit_","kind":"json-schema","title":"Page[Audit]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Audit"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Audit]"}},"components/schemas/Page_Control_":{"id":"components/schemas/Page_Control_","kind":"json-schema","title":"Page[Control]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Control"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Control]"}},"components/schemas/Page_Monitor_":{"id":"components/schemas/Page_Monitor_","kind":"json-schema","title":"Page[Monitor]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Monitor"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Monitor]"}},"components/schemas/Page_Person_":{"id":"components/schemas/Page_Person_","kind":"json-schema","title":"Page[Person]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Person"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Person]"}},"components/schemas/Page_Policy_":{"id":"components/schemas/Page_Policy_","kind":"json-schema","title":"Page[Policy]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Policy"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Policy]"}},"components/schemas/Page_Risk_":{"id":"components/schemas/Page_Risk_","kind":"json-schema","title":"Page[Risk]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Risk"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Risk]"}},"components/schemas/Page_Vendor_":{"id":"components/schemas/Page_Vendor_","kind":"json-schema","title":"Page[Vendor]","data":{"properties":{"data":{"items":{"$ref":"#/components/schemas/Vendor"},"type":"array","description":"This page of results."},"pagination":{"$ref":"#/components/schemas/PageInfo","description":"How to fetch the next page, and how much there is."}},"type":"object","required":["data","pagination"],"title":"Page[Vendor]"}},"components/schemas/Person":{"id":"components/schemas/Person","kind":"json-schema","title":"Person","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"firstName":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Given name; null when not recorded."},"lastName":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Family name; null when not recorded."},"email":{"type":"string","description":"Work email address, lower-cased. Unique within the company for a given source."},"jobTitle":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Job title as recorded; null when not recorded."},"employmentStatus":{"$ref":"#/components/schemas/EmploymentStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"active or inactive. Filterable. There is no 'terminated' status: someone who has left is inactive, and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" says when."},"children":[]}]}]}]},"source":{"type":"string","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Where the record came from. Filterable. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"csv"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for a CSV import (the manual path), otherwise the internal name of the HR or identity integration that synced it - for example bamboohr, hibob, personio, deel, okta, microsoft-graph, google-workspace-hr."},"children":[]}]}]}]},"hiringDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the person joined; null when the source did not provide one."},"terminationDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the person left; null while they are employed or when the source did not provide one."},"createdAt":{"type":"string","format":"date-time","description":"When the record was created in Scytale."},"updatedAt":{"type":"string","format":"date-time","description":"Last change to the record in Scytale, including integration syncs."}},"type":"object","required":["id","email","employmentStatus","source","createdAt","updatedAt"],"title":"Person","description":"One person: who they are, whether they still work here, where the record came from, and\nwhen they joined and left.\n\nEvery value is the effective one: a manual edit made in Scytale wins over the value the\nintegration last synced, on every read, so the list row and the detail never disagree with\nwhat the product shows."}},"components/schemas/Policy":{"id":"components/schemas/Policy","kind":"json-schema","title":"Policy","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"code":{"type":"string","description":"Scytale's policy reference, e.g. POL.01."},"title":{"type":"string","description":"The policy's title."},"state":{"$ref":"#/components/schemas/PolicyState","description":"Compliance status: signed-off, approval-required (never signed, edited since signing, or the sign-off expired) or review-required."},"workflowStatus":{"$ref":"#/components/schemas/PolicyWorkflowStatus","description":"Where the policy sits in its review and approval cycle."},"version":{"anyOf":[{"$ref":"#/components/schemas/PolicyVersion"},{"type":"null"}],"description":"Latest version number; null when the policy has no version yet."},"owner":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who owns the policy; null when unassigned."},"approver":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who must approve this cycle; null when no approver is assigned."},"signedOffAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the policy was last signed off; null if it never has been."},"signedOffBy":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who signed it off; null if it never has been."},"signOffExpiresAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the current sign-off lapses, one year after it was given. Null when the policy is unsigned, or when an external system owns its approval."},"confidentiality":{"$ref":"#/components/schemas/PolicyConfidentiality"},"isExternalPolicy":{"type":"boolean","description":"True when the policy is managed outside Scytale."},"approvalManagement":{"anyOf":[{"$ref":"#/components/schemas/ApprovalManagement"},{"type":"null"}],"description":"Who owns approval of an external policy; null on an internal one."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the policy was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the policy."}},"type":"object","required":["id","code","title","state","workflowStatus","confidentiality","isExternalPolicy"],"title":"Policy","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"One policy as a list row: its identity, who owns it, and where it stands."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Metadata only - the policy document itself is never served ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"html"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is excluded, and the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"signed PDF is not reachable through this API)."},"children":[]}]}]}]}},"components/schemas/PolicyConfidentiality":{"id":"components/schemas/PolicyConfidentiality","kind":"json-schema","title":"PolicyConfidentiality","data":{"type":"string","enum":["restricted","confidential","internal-use","public"],"title":"PolicyConfidentiality","description":"How widely the policy may be shared."}},"components/schemas/PolicyDetail":{"id":"components/schemas/PolicyDetail","kind":"json-schema","title":"PolicyDetail","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"code":{"type":"string","description":"Scytale's policy reference, e.g. POL.01."},"title":{"type":"string","description":"The policy's title."},"state":{"$ref":"#/components/schemas/PolicyState","description":"Compliance status: signed-off, approval-required (never signed, edited since signing, or the sign-off expired) or review-required."},"workflowStatus":{"$ref":"#/components/schemas/PolicyWorkflowStatus","description":"Where the policy sits in its review and approval cycle."},"version":{"anyOf":[{"$ref":"#/components/schemas/PolicyVersion"},{"type":"null"}],"description":"Latest version number; null when the policy has no version yet."},"owner":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who owns the policy; null when unassigned."},"approver":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who must approve this cycle; null when no approver is assigned."},"signedOffAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the policy was last signed off; null if it never has been."},"signedOffBy":{"anyOf":[{"$ref":"#/components/schemas/Owner"},{"type":"null"}],"description":"Who signed it off; null if it never has been."},"signOffExpiresAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the current sign-off lapses, one year after it was given. Null when the policy is unsigned, or when an external system owns its approval."},"confidentiality":{"$ref":"#/components/schemas/PolicyConfidentiality"},"isExternalPolicy":{"type":"boolean","description":"True when the policy is managed outside Scytale."},"approvalManagement":{"anyOf":[{"$ref":"#/components/schemas/ApprovalManagement"},{"type":"null"}],"description":"Who owns approval of an external policy; null on an internal one."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the policy was created."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the policy."},"reviewers":{"items":{"$ref":"#/components/schemas/Reviewer"},"type":"array","description":"Reviewers for this cycle and whether each has completed; empty when none are assigned."}},"type":"object","required":["id","code","title","state","workflowStatus","confidentiality","isExternalPolicy"],"title":"PolicyDetail","description":"One policy in full: a list row plus this cycle's reviewers."}},"components/schemas/PolicyState":{"id":"components/schemas/PolicyState","kind":"json-schema","title":"PolicyState","data":{"type":"string","enum":["signed-off","approval-required","review-required"],"title":"PolicyState","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Whether the policy is signed off, and whether that sign-off still stands."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"PolicyState"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". A sign-off is valid for one year; an expired one returns"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the policy to "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"approval-required"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" rather than leaving it "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"signed-off"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/PolicyVersion":{"id":"components/schemas/PolicyVersion","kind":"json-schema","title":"PolicyVersion","data":{"properties":{"major":{"type":"integer","description":"Major version; 0 until the policy is first signed off."},"minor":{"type":"integer","description":"Minor version, incremented on each edit."}},"type":"object","required":["major","minor"],"title":"PolicyVersion","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The policy's latest version number."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A policy starts at 0.1 and reaches 1.0 on its first sign-off, so anything past 0.1 has"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"been edited since - which is what drives "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"state"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"workflowStatus"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for a policy that"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"has never been signed."},"children":[]}]}]}]}},"components/schemas/PolicyWorkflowStatus":{"id":"components/schemas/PolicyWorkflowStatus","kind":"json-schema","title":"PolicyWorkflowStatus","data":{"type":"string","enum":["pending","in-progress","in-review","pending-approval","signed-off"],"title":"PolicyWorkflowStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Where the policy sits in its review and approval cycle."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"PolicyWorkflowStatus"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pending-approval"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is reachable only when an"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"approver is assigned; without one, completed reviews leave sign-off open to anyone and"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the policy stays "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"in-review"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/ProductRef":{"id":"components/schemas/ProductRef","kind":"json-schema","title":"ProductRef","data":{"properties":{"id":{"type":"string","description":"Product id."},"name":{"type":"string","description":"Product display name."}},"type":"object","required":["id","name"],"title":"ProductRef","description":"A product of the company, when a framework is certified per product."}},"components/schemas/Reviewer":{"id":"components/schemas/Reviewer","kind":"json-schema","title":"Reviewer","data":{"properties":{"user":{"$ref":"#/components/schemas/Owner","description":"The reviewer."},"completedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When they completed their review; null while still outstanding."}},"type":"object","required":["user"],"title":"Reviewer","description":"Someone asked to review the policy this cycle, and whether they have."}},"components/schemas/Risk":{"id":"components/schemas/Risk","kind":"json-schema","title":"Risk","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"displayName":{"type":"string","description":"The risk's title as it appears in the register."},"description":{"type":"string","description":"What the risk is; may be empty."},"asset":{"anyOf":[{"$ref":"#/components/schemas/RiskAsset"},{"type":"null"}],"description":"The kind of asset at risk: information-data-assets, ict-asset-infrastructure, people, operational-ict-processes, third-party-ict-service-providers or financial-digital-assets; older risks may carry a legacy value (data, devices, financial, information, policy, process, repository, vendor). Null when not recorded."},"assetClassification":{"anyOf":[{"$ref":"#/components/schemas/RiskClassification"},{"type":"null"}],"description":"Sensitivity of the asset at risk: internal, confidential, restricted or public. Null when not recorded."},"likelihood":{"type":"integer","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Inherent likelihood, before treatment, on the company's scale (1..N, N = matrix size, 3-10, default 5)."},"children":[]}]}]}]},"impact":{"type":"integer","description":"Inherent impact, before treatment, on the same scale."},"residualLikelihood":{"anyOf":[{"type":"integer"},{"type":"null"}],"description":"Likelihood after treatment, on the same scale; null when not assessed."},"residualImpact":{"anyOf":[{"type":"integer"},{"type":"null"}],"description":"Impact after treatment, on the same scale; null when not assessed."},"treatment":{"anyOf":[{"$ref":"#/components/schemas/RiskTreatment"},{"type":"null"}],"description":"The chosen treatment: mitigate, transfer, avoid or accept. Filterable. Null when the company has not decided yet."},"treatmentStatus":{"$ref":"#/components/schemas/RiskTreatmentStatus","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"incomplete or complete. Filterable. For a mitigated risk the product derives it from the linked controls; it may also be set by hand. 'Which risks are still unmitigated' is treatmentStatus=incomplete."},"children":[]}]}]}]},"treatmentPlan":{"$ref":"#/components/schemas/TreatmentPlan","description":"The treatment plan: its tasks with their completion state, and the rationale written for a transfer, avoid or accept decision."},"mitigationInfo":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Free-text mitigation notes the company wrote on the risk (the plan as text, from before plans had tasks); null when none."},"ownerId":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Id of the user in this company who owns the risk; the first owner when several are assigned. Filterable. Null when unassigned."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the risk was added to the register."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the risk."}},"type":"object","required":["id","displayName","description","likelihood","impact","treatmentStatus"],"title":"Risk","description":"One risk from the register: what it is, what it threatens, how it scores before and\nafter treatment, how it is treated and how far that has got, and who owns it.\n\nEvery value is the stored one. Risks have no override mechanism: a risk created from a\ntemplate copies the template's values once and the document is the single source of\ntruth from then on."}},"components/schemas/RiskAsset":{"id":"components/schemas/RiskAsset","kind":"json-schema","title":"RiskAsset","data":{"type":"string","enum":["information-data-assets","ict-asset-infrastructure","people","operational-ict-processes","third-party-ict-service-providers","financial-digital-assets","data","devices","financial","information","policy","process","repository","vendor"],"title":"RiskAsset","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The kind of asset the risk threatens. The product's current six values, plus the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"legacy set older risks still carry ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"people"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is in both). Stored values outside the"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"union are served as null."},"children":[]}]}]}]}},"components/schemas/RiskClassification":{"id":"components/schemas/RiskClassification","kind":"json-schema","title":"RiskClassification","data":{"type":"string","enum":["internal","confidential","restricted","public"],"title":"RiskClassification","description":"The sensitivity class of the asset at risk."}},"components/schemas/RiskTreatment":{"id":"components/schemas/RiskTreatment","kind":"json-schema","title":"RiskTreatment","data":{"type":"string","enum":["mitigate","transfer","avoid","accept"],"title":"RiskTreatment","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"How the company chose to treat the risk. The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"RiskTreatmentTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":": reduce it"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"with controls (mitigate), pass it to a third party (transfer), stop the activity that"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"carries it (avoid), or live with it (accept)."},"children":[]}]}]}]}},"components/schemas/RiskTreatmentStatus":{"id":"components/schemas/RiskTreatmentStatus","kind":"json-schema","title":"RiskTreatmentStatus","data":{"type":"string","enum":["incomplete","complete"],"title":"RiskTreatmentStatus","description":"How far along the treatment is. Two values, not a scale: for a mitigated risk the\nproduct derives it from the linked controls (complete when every control in an active\naudit is compliant), and a user may also set it directly."}},"components/schemas/TreatmentPlan":{"id":"components/schemas/TreatmentPlan","kind":"json-schema","title":"TreatmentPlan","data":{"properties":{"tasks":{"items":{"$ref":"#/components/schemas/TreatmentTask"},"type":"array","description":"The plan's tasks, in plan order. Empty when there are none."},"rationales":{"$ref":"#/components/schemas/TreatmentRationales","description":"The justification written for each non-mitigate strategy."}},"type":"object","title":"TreatmentPlan","description":"How the chosen treatment is carried out: the tasks (for mitigate) and the rationales\n(for transfer, avoid and accept). Always present; a risk with no plan has no tasks and\nno rationales."}},"components/schemas/TreatmentRationales":{"id":"components/schemas/TreatmentRationales","kind":"json-schema","title":"TreatmentRationales","data":{"properties":{"accept":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Why the risk is accepted; null when none."},"avoid":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"How and why the risk is avoided; null when none."},"transfer":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"To whom and how the risk is transferred; null when none."}},"type":"object","title":"TreatmentRationales","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The written justification for each non-mitigate strategy, keyed by the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatment"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"value it justifies - so "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"treatmentPlan.rationales[treatment]"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is the current one. A"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"mitigated risk documents tasks instead of a rationale. A rationale written for a strategy"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"the risk no longer uses is kept, as the product keeps it."},"children":[]}]}]}]}},"components/schemas/TreatmentTask":{"id":"components/schemas/TreatmentTask","kind":"json-schema","title":"TreatmentTask","data":{"properties":{"id":{"type":"string","description":"Stable identifier of the task within its risk."},"title":{"type":"string","description":"The task's title; may be empty."},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"What the task involves; null when none. Often the substance of the task, with a placeholder title such as 'Mitigation plan'."},"completed":{"type":"boolean","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Whether the task is done. 'Which tasks are still open' is completed=false."},"children":[]}]}]}]},"completedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the task was marked done; null when open."},"completedBy":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Id of the user who marked the task done; null when open or not recorded."},"source":{"anyOf":[{"$ref":"#/components/schemas/TreatmentTaskSource"},{"type":"null"}],"description":"auto (copied from the risk template when the risk was created) or manual (added by a user). Null for a stored value outside those two."}},"type":"object","required":["id","title","completed"],"title":"TreatmentTask","description":"One step of the treatment plan, with whether it is done."}},"components/schemas/TreatmentTaskSource":{"id":"components/schemas/TreatmentTaskSource","kind":"json-schema","title":"TreatmentTaskSource","data":{"type":"string","enum":["auto","manual"],"title":"TreatmentTaskSource","description":"Where a treatment task came from: copied from the risk template when the risk was\ncreated (auto), or added by a user (manual)."}},"components/schemas/Vendor":{"id":"components/schemas/Vendor","kind":"json-schema","title":"Vendor","data":{"properties":{"id":{"type":"string","description":"Stable identifier."},"name":{"type":"string","description":"Vendor name as the company knows it; for a catalog vendor, the catalog name unless renamed."},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"What the vendor provides; null when neither the company nor the catalog has one."},"website":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"The vendor's website; null when unknown."},"category":{"anyOf":[{"$ref":"#/components/schemas/VendorCategory"},{"type":"null"}],"description":"What kind of service the vendor provides. Filterable. For a catalog vendor this is the catalog's category unless the company set its own; null when neither has one."},"criticality":{"$ref":"#/components/schemas/VendorCriticality","description":"critical (the default) or non-critical: whether the business depends on this vendor."},"lifeCycle":{"anyOf":[{"$ref":"#/components/schemas/VendorLifeCycle"},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"planned, poc, active or terminated. 'Which vendors do we currently use' is lifeCycle=active. Null when the stored value is not one of these."},"children":[]}]}]}]},"businessRisk":{"anyOf":[{"$ref":"#/components/schemas/VendorRiskLevel"},{"type":"null"}],"description":"The company's overall risk rating of this vendor: high, medium or low. Null when the stored value is not one of these."},"confidentialityRisk":{"anyOf":[{"$ref":"#/components/schemas/VendorRiskLevel"},{"type":"null"}],"description":"Risk to the confidentiality of the data the vendor handles; null when not assessed."},"integrityRisk":{"anyOf":[{"$ref":"#/components/schemas/VendorRiskLevel"},{"type":"null"}],"description":"Risk to the integrity of the data the vendor handles; null when not assessed."},"availabilityRisk":{"anyOf":[{"$ref":"#/components/schemas/VendorRiskLevel"},{"type":"null"}],"description":"Risk to the availability of the vendor's service; null when not assessed."},"dataClassification":{"anyOf":[{"$ref":"#/components/schemas/VendorDataClassification"},{"type":"null"}],"description":"Most sensitive class of data the vendor handles; null when not recorded."},"sensitiveDataTypes":{"items":{"type":"string"},"type":"array","description":"Kinds of sensitive data the vendor handles. Documented values: personal-identifiable, protected-health, customer-data, business-data, financial-data, employee-data, marketing-data, payment, other - other values may appear. Empty when none recorded."},"certifications":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"description":"Security certifications on record, by framework identifier (e.g. soc2, iso27001). Null when never collected; empty when collected and none were found."},"dpaOnFile":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"Whether a data processing agreement is on file; null when unknown."},"signedContract":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"Whether a signed contract is on file; null when unknown."},"penetrationTestConducted":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"Whether the vendor has had a penetration test; null when unknown."},"termsOfUseLink":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Link to the vendor's terms of use; null when unknown."},"primaryContactName":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Name of the company's primary contact at the vendor; null when unknown."},"ownerId":{"anyOf":[{"type":"string"},{"type":"null"}],"description":"Id of the user in this company who owns the vendor relationship; null when unassigned."},"reviewFrequency":{"anyOf":[{"$ref":"#/components/schemas/VendorReviewFrequency"},{"type":"null"}],"description":"How often the vendor is reviewed: quarterly, semi-annual, annual, or not-set when the company explicitly chose none. Null when no frequency has been recorded."},"lastReviewDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the vendor was last reviewed; null if it never has been."},"nextReviewDate":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the next review is due; null when no review is scheduled."},"source":{"$ref":"#/components/schemas/VendorSource","description":"common: added from Scytale's vendor catalog; custom: created by the company."},"createdAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"When the vendor was added."},"updatedAt":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"description":"Last change to the vendor."}},"type":"object","required":["id","name","criticality","source"],"title":"Vendor","description":"One vendor: identity, how critical and how risky, what data it handles, what due\ndiligence is on file, and where its review cycle stands.\n\nEvery value is the effective one - what the company recorded, or for a catalog vendor\nthe catalog's value where the company recorded nothing - so the list row and the detail\nnever disagree."}},"components/schemas/VendorCategory":{"id":"components/schemas/VendorCategory","kind":"json-schema","title":"VendorCategory","data":{"type":"string","enum":["security","identity-and-access-management","legal-and-compliance","finance-and-payments","hr-and-people","developer-tools","monitoring-and-observability","it-operations","design","analytics-and-data","ai-and-machine-learning","communication-and-telecom","customer-support","crm-and-sales","marketing-and-advertising","project-and-product-management","collaboration-and-productivity","ecommerce-and-marketplace","cloud-and-infrastructure","business-operations"],"title":"VendorCategory","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"What kind of service the vendor provides. The product's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"VendorCategories"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}]}},"components/schemas/VendorCriticality":{"id":"components/schemas/VendorCriticality","kind":"json-schema","title":"VendorCriticality","data":{"type":"string","enum":["critical","non-critical"],"title":"VendorCriticality","description":"How much the business depends on the vendor. Two values, not a scale: the product asks\n\"could we operate without them\", not \"how much would it hurt\"."}},"components/schemas/VendorDataClassification":{"id":"components/schemas/VendorDataClassification","kind":"json-schema","title":"VendorDataClassification","data":{"type":"string","enum":["public","internal-use","confidential","restricted"],"title":"VendorDataClassification","description":"The most sensitive class of the company's data the vendor handles."}},"components/schemas/VendorLifeCycle":{"id":"components/schemas/VendorLifeCycle","kind":"json-schema","title":"VendorLifeCycle","data":{"type":"string","enum":["planned","poc","active","terminated"],"title":"VendorLifeCycle","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Where the relationship stands. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"active"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is \"we use them today\"; "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"planned"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"poc"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"precede it, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminated"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" follows it."},"children":[]}]}]}]}},"components/schemas/VendorReviewFrequency":{"id":"components/schemas/VendorReviewFrequency","kind":"json-schema","title":"VendorReviewFrequency","data":{"type":"string","enum":["quarterly","semi-annual","annual","not-set"],"title":"VendorReviewFrequency","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"How often the company re-reviews the vendor. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"not-set"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is a stored choice, distinct"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"from a vendor that has no frequency recorded at all (served as null)."},"children":[]}]}]}]}},"components/schemas/VendorRiskLevel":{"id":"components/schemas/VendorRiskLevel","kind":"json-schema","title":"VendorRiskLevel","data":{"type":"string","enum":["high","medium","low"],"title":"VendorRiskLevel","description":"A three-step risk rating, used for the overall business risk and for each of the\nconfidentiality, integrity and availability risks."}},"components/schemas/VendorSource":{"id":"components/schemas/VendorSource","kind":"json-schema","title":"VendorSource","data":{"type":"string","enum":["common","custom"],"title":"VendorSource","description":"Where the vendor record came from: Scytale's shared vendor catalog, or created by the\ncompany from scratch."}},"schema_42":{"kind":"json-schema","data":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"True for only applicable controls, false for only inapplicable. Omit for both - note the dashboard counts applicable controls only, so pass true to match its totals.","title":"Applicable"},"id":"schema_42"},"schema_43":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only controls under this audit (its id).","title":"Auditid"},"id":"schema_43"},"schema_44":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only controls owned by this user, by exact user id (not a name).","title":"Ownerid"},"id":"schema_44"},"schema_45":{"kind":"json-schema","data":{"const":"rank","type":"string","description":"Order of the results. Only 'rank' (the product's display order).","default":"rank","title":"Sort"},"id":"schema_45"},"schema_46":{"kind":"json-schema","data":{"type":"boolean","description":"Sort descending instead of ascending.","default":false,"title":"Descending"},"id":"schema_46"},"schema_47":{"kind":"json-schema","data":{"anyOf":[{"type":"string","minLength":1},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Cursor from a previous page's "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"pagination.nextCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}],"title":"Cursor"},"id":"schema_47"},"schema_48":{"kind":"json-schema","data":{"type":"integer","maximum":100,"minimum":1,"description":"Results per page (1-100).","default":50,"title":"Limit"},"id":"schema_48"},"schema_49":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The control's id, as returned by get_controls."},"children":[]}]}]}],"title":"Id"},"id":"schema_49"},"schema_50":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/AuditStatus"},{"type":"null"}],"description":"Only audits in this lifecycle status. Omit for all statuses.","title":"Status"},"id":"schema_50"},"schema_51":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only audits of this framework (its id).","title":"Frameworkid"},"id":"schema_51"},"schema_52":{"kind":"json-schema","data":{"enum":["startDate","endDate","createdAt","updatedAt"],"type":"string","description":"Field to order the results by. Audits with no value for it come last when descending.","default":"startDate","title":"Sort"},"id":"schema_52"},"schema_53":{"kind":"json-schema","data":{"type":"boolean","description":"Newest first (the default); false for oldest first.","default":true,"title":"Descending"},"id":"schema_53"},"schema_54":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The audit's id, as returned by get_audits."},"children":[]}]}]}],"title":"Id"},"id":"schema_54"},"schema_55":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only policies owned by this user, by exact user id (not a name).","title":"Ownerid"},"id":"schema_55"},"schema_56":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only policies this user must approve, by exact user id. Combine with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"workflowStatus=pending-approval"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for what is actually waiting on them."},"children":[]}]}]}],"title":"Approverid"},"id":"schema_56"},"schema_57":{"kind":"json-schema","data":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"True for only externally managed policies, false for only internal. Omit for both.","title":"Isexternalpolicy"},"id":"schema_57"},"schema_58":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/PolicyState"},{"type":"null"}],"description":"Only policies in this compliance state.","title":"State"},"id":"schema_58"},"schema_59":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/PolicyWorkflowStatus"},{"type":"null"}],"description":"Only policies at this point in the review cycle.","title":"Workflowstatus"},"id":"schema_59"},"schema_60":{"kind":"json-schema","data":{"enum":["code","title","updatedAt"],"type":"string","description":"Order of the results.","default":"code","title":"Sort"},"id":"schema_60"},"schema_61":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The policy's id, as returned by get_policies."},"children":[]}]}]}],"title":"Id"},"id":"schema_61"},"schema_62":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/MonitorState"},{"type":"null"}],"description":"Only monitors in this state. Three values, not two: non-compliant (a check failed since the last review), compliant (checks ran and none is failing), pending (no automated evidence has been collected, so there is no verdict either way - a manual monitor, or an integration that has not run).","title":"State"},"id":"schema_62"},"schema_63":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only monitors owned by this user, by exact user id (not a name).","title":"Ownerid"},"id":"schema_63"},"schema_64":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/MonitorFrequency"},{"type":"null"}],"description":"Only monitors meant to run at this frequency.","title":"Frequency"},"id":"schema_64"},"schema_65":{"kind":"json-schema","data":{"anyOf":[{"type":"boolean"},{"type":"null"}],"description":"True for only switched-off monitors, false for only active ones. Omit for both.","title":"Inactive"},"id":"schema_65"},"schema_66":{"kind":"json-schema","data":{"enum":["code","name","updatedAt","lastRunAt"],"type":"string","description":"Order of the results.","default":"code","title":"Sort"},"id":"schema_66"},"schema_67":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The monitor's id, as returned by get_monitors."},"children":[]}]}]}],"title":"Id"},"id":"schema_67"},"schema_68":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/VendorCriticality"},{"type":"null"}],"description":"Only vendors of this criticality. A vendor with none recorded counts as critical.","title":"Criticality"},"id":"schema_68"},"schema_69":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/VendorLifeCycle"},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only vendors at this lifecycle stage. 'Vendors we use today' is lifeCycle=active."},"children":[]}]}]}],"title":"Lifecycle"},"id":"schema_69"},"schema_70":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/VendorRiskLevel"},{"type":"null"}],"description":"Only vendors rated at this overall business risk.","title":"Businessrisk"},"id":"schema_70"},"schema_71":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/VendorCategory"},{"type":"null"}],"description":"Only vendors in this category - the catalog's category for a catalog vendor the company did not recategorise.","title":"Category"},"id":"schema_71"},"schema_72":{"kind":"json-schema","data":{"enum":["name","createdAt","updatedAt","lastReviewDate","nextReviewDate"],"type":"string","description":"Order of the results. Vendors with no value for the field come last when descending; name sorts case-insensitively.","default":"createdAt","title":"Sort"},"id":"schema_72"},"schema_73":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The vendor's id, as returned by get_vendors."},"children":[]}]}]}],"title":"Id"},"id":"schema_73"},"schema_74":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/EmploymentStatus"},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only people with this employment status. active is the current workforce; inactive is everyone who has left (there is no 'terminated' status - read "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"terminationDate"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]}]}]}],"title":"Employmentstatus"},"id":"schema_74"},"schema_75":{"kind":"json-schema","data":{"anyOf":[{"type":"string","minLength":1,"maxLength":64},{"type":"null"}],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Only people whose record came from this source: "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"csv"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for a CSV import, otherwise an integration's internal name as it appears on the rows (bamboohr, hibob, personio, deel, okta, microsoft-graph, google-workspace-hr, ...). A source none of this company's people came from is refused with a 400 rather than answered with an empty page."},"children":[]}]}]}],"title":"Source"},"id":"schema_75"},"schema_76":{"kind":"json-schema","data":{"enum":["createdAt","updatedAt","hiringDate","terminationDate","lastName","email"],"type":"string","description":"Order of the results. People with no value for the field come last when descending; lastName and email sort case-insensitively.","default":"createdAt","title":"Sort"},"id":"schema_76"},"schema_77":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The person's id, as returned by get_people."},"children":[]}]}]}],"title":"Id"},"id":"schema_77"},"schema_78":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/RiskTreatmentStatus"},{"type":"null"}],"description":"Only risks whose treatment is in this state: incomplete (still being treated, or not started) or complete. 'Which risks are still unmitigated' is incomplete.","title":"Treatmentstatus"},"id":"schema_78"},"schema_79":{"kind":"json-schema","data":{"anyOf":[{"$ref":"#/components/schemas/RiskTreatment"},{"type":"null"}],"description":"Only risks treated this way: mitigate (reduced with controls), transfer (passed to a third party), avoid (the activity stopped) or accept (lived with). A risk with no treatment decided yet matches none of them.","title":"Treatment"},"id":"schema_79"},"schema_80":{"kind":"json-schema","data":{"anyOf":[{"type":"string","pattern":"^[0-9a-fA-F]{24}$"},{"type":"null"}],"description":"Only risks owned by this user, by exact user id (not a name).","title":"Ownerid"},"id":"schema_80"},"schema_81":{"kind":"json-schema","data":{"enum":["createdAt","updatedAt","displayName"],"type":"string","description":"Order of the results.","default":"createdAt","title":"Sort"},"id":"schema_81"},"schema_82":{"kind":"json-schema","data":{"type":"boolean","description":"Sort descending instead of ascending.","default":true,"title":"Descending"},"id":"schema_82"},"schema_83":{"kind":"json-schema","data":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The risk's id, as returned by get_risks."},"children":[]}]}]}],"title":"Id"},"id":"schema_83"}},"exampleStore":{},"securitySchemeStore":{"BearerAuth":{"id":"BearerAuth","type":"http","scheme":"bearer","bearerFormat":"JWT","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Access token from "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"POST /oauth/token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Scopes are enforced per route."},"children":[]}]}]}]}},"servers":[{"url":"/_mock/openapi","isMockServer":true,"description":"Mock server"},{"url":"https://api.scytale.ai","description":"US - for companies whose Scytale data is hosted in the United States."},{"url":"https://api.eu.scytale.ai","description":"EU - for companies whose Scytale data is hosted in the European Union."}],"specType":"openapi"},"options":{"mockServer":{"url":"/_mock/openapi","position":"first","description":"Mock server"},"disableRouter":true,"downloadUrls":[{"url":"/_bundle/openapi.json?download"},{"url":"/_bundle/openapi.yaml?download"}],"excludeFromSearch":false,"replayFeatures":{"graphql":false},"specType":"openapi","markdocOptions":{"tags":{},"nodes":{},"components":{}},"metadata":{"title":"Scytale API","description":"Read-only access to your Scytale compliance data.\n\nAuthenticate by exchanging your client credentials at `POST /oauth/token` for an\naccess token, then send it as `Authorization: Bearer <token>`.\n"}},"baseSlug":"/openapi","routesMapping":{}}