Compliance
Compliance reports how each repository meets the portfolio's rules. Read the rules, the compliance matrix, deficiencies and fix history, and request fixes.
Get account provisioning
Lists the in-progress and most recent add-account and re-login runs for agent accounts, with each run's node, step, status and error. Requires permission to view system settings; returns an empty list unless the caller may also view agent accounts, and shows only accounts granted to the caller on nodes they can see.
Get command log
Lists commands sent to nodes, newest first, one page at a time, with a `total` of matching rows. Filters by node, status, text search and time range; shows commands for nodes the caller can see and those bound to no node. Requires permission to view system settings.
Get compliance matrix
Returns the compliance grid: every subject (project, agent account or organization) the caller can see against every rule, with one verdict cell per pair. `subject`, `offset` and `limit` narrow the cells without trimming the axes; diffs are fetched separately. Requires permission to view compliance.
Get compliance matrix cell diff
Returns the diff text for one evidence cell, named by subject, rule and asset; a missing cell and a subject hidden from the caller both return 404. Requires permission to view compliance.
List deficiencies
Lists every non-compliant verdict the caller can see with its remediation route and the latest fix job covering it. Filters by subject and state, sorts by subject or state, and reports whether the last audit sweep completed. Requires permission to view compliance.
Fix deficiencies
Files one fix task per project for the given deficiencies; each starts at once and opens a pull request. `dry_run` previews without filing, `force` replaces a stuck fix, and naming a project the caller cannot see returns 404 for the whole batch. Requires permission to edit compliance; returns the submitted, rejected and blocked groups.
Get repository compliance detail
Returns one subject's standing against one rule: state, cause, diff, remediation route, the current fix job and past fixes. A pair with no current verdict, or a subject hidden from the caller, returns 200 with empty state and `applicable` false. Requires permission to view compliance.
List fix history
Lists finished fix batches, newest first, including failed and blocked ones, with their state, pull request link and the rules they covered. Filters by subject and `rule_id`; shows only projects the caller can see. Requires permission to view compliance.
Get compliance rollup
Returns one row per subject the caller can see, counting its rules in each compliance state, not applicable included. Projects never audited appear with `audited` false. Requires permission to view compliance.
List rule groups
Lists compliance rules, each with every visible subject's verdict and how many of the rule's assets are current and applicable for it. Requires permission to view compliance.
List rules
Lists every rule asset, the file a rule keeps in step, with its rule, tier, target path, sync mode and propagation counts across the subjects the caller can see. Requires permission to view compliance.
Get portfolio resources
Returns agent accounts with their quota, busy and idle sessions, runners and worktrees, plus overall session and runner totals, for nodes the caller can see. Filters by node; accounts the caller may not view are hidden and counted. Requires permission to view system settings.