diff --git a/.gitignore b/.gitignore index 2fdbcb5..5d6c185 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,6 @@ node_modules/ dist/ +src/generated/ .cache/ .DS_Store vanta diff --git a/api-spec.json b/api-spec.json index 27ebc6a..ffb85fd 100644 --- a/api-spec.json +++ b/api-spec.json @@ -1377,7 +1377,7 @@ "accountManagerEmail": { "type": "string", "description": "Email of the external account manager for this vendor.", - "maxLength": 2000 + "maxLength": 100 }, "securityOwnerUserId": { "type": "string", @@ -1533,7 +1533,7 @@ "accountManagerEmail": { "type": "string", "description": "Email of the external account manager for this vendor.", - "maxLength": 2000 + "maxLength": 100 }, "securityOwnerUserId": { "type": "string", @@ -1611,7 +1611,8 @@ }, "status": { "$ref": "#/components/schemas/VendorStatus", - "description": "The current status of the vendor." + "description": "This field is ignored. Use `POST /vendors/{vendorId}/set-status` to change vendor status.", + "deprecated": true }, "category": { "type": "string", @@ -1786,8 +1787,8 @@ "type": "object", "additionalProperties": false }, - "SecurityReviewDecision": { - "description": "The current decision made for the security review:\n- APPROVED: The security review has been approved.\n- NOT_APPROVED: The security review has been marked not approved.\n- CONDITIONALLY_APPROVED: The security review has been conditionally approved.", + "AssessmentDecision": { + "description": "The current decision made for an assessment:\n- APPROVED: The assessment has been approved.\n- NOT_APPROVED: The assessment has been marked not approved.\n- CONDITIONALLY_APPROVED: The assessment has been conditionally approved.", "enum": [ "APPROVED", "NOT_APPROVED", @@ -1795,6 +1796,67 @@ ], "type": "string" }, + "AssessmentType": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the assessment type." + }, + "name": { + "type": "string", + "description": "Display name of the assessment type." + }, + "description": { + "type": "string", + "nullable": true, + "description": "Description of the assessment type, if set." + } + }, + "required": [ + "id", + "name", + "description" + ], + "type": "object", + "additionalProperties": false + }, + "AssessmentOwnerType": { + "enum": [ + "USER", + "TEAM" + ], + "type": "string" + }, + "AssessmentOwner": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the owner." + }, + "type": { + "$ref": "#/components/schemas/AssessmentOwnerType", + "description": "The type of actor that owns this assessment." + }, + "displayName": { + "type": "string", + "nullable": true, + "description": "Display name of the owner, if available." + }, + "email": { + "type": "string", + "nullable": true, + "description": "Email of the owner. Populated for USER owners, null for TEAM owners." + } + }, + "required": [ + "id", + "type", + "displayName", + "email" + ], + "type": "object", + "additionalProperties": false + }, "SecurityReview": { "properties": { "id": { @@ -1852,7 +1914,7 @@ "description": "The timestamp of when the security review decision was last set." }, "status": { - "$ref": "#/components/schemas/SecurityReviewDecision", + "$ref": "#/components/schemas/AssessmentDecision", "description": "The status of the current decision." } }, @@ -1863,6 +1925,19 @@ "type": "object", "nullable": true, "description": "An object containing information about the decision of the review." + }, + "assessmentType": { + "$ref": "#/components/schemas/AssessmentType", + "description": "The assessment type for this security review." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/AssessmentOwner" + } + ], + "nullable": true, + "description": "The owner of this security review, if assigned." } }, "required": [ @@ -1875,7 +1950,9 @@ "dueDate", "overrideDueDate", "completionDate", - "decision" + "decision", + "assessmentType", + "owner" ], "type": "object", "additionalProperties": false @@ -1907,6 +1984,147 @@ "type": "object", "additionalProperties": false }, + "AssessmentStatus": { + "description": "The lifecycle status of an assessment:\n- NOT_STARTED: The assessment has not yet been started.\n- IN_PROGRESS: The assessment is underway.\n- COMPLETED: The assessment has been completed.", + "enum": [ + "NOT_STARTED", + "IN_PROGRESS", + "COMPLETED" + ], + "type": "string" + }, + "VendorAssessment": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the assessment." + }, + "vendorId": { + "type": "string", + "description": "Unique identifier for the vendor." + }, + "status": { + "$ref": "#/components/schemas/AssessmentStatus", + "description": "The lifecycle status of the assessment." + }, + "completedByUserId": { + "type": "string", + "nullable": true, + "description": "The Vanta user ID of the person who completed this assessment." + }, + "startDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The timestamp of when the assessment was started." + }, + "dueDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The timestamp of when the assessment is due." + }, + "overrideDueDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "A manual override timestamp of when the assessment is due." + }, + "completionDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The timestamp of when the assessment was marked as completed." + }, + "createdDate": { + "type": "string", + "format": "date-time", + "description": "The timestamp of when the assessment was created." + }, + "decision": { + "properties": { + "comments": { + "type": "string", + "nullable": true, + "description": "Comments about the assessment decision." + }, + "lastUpdatedAt": { + "type": "string", + "format": "date-time", + "description": "The timestamp of when the assessment decision was last set." + }, + "status": { + "$ref": "#/components/schemas/AssessmentDecision", + "description": "The status of the current decision." + } + }, + "required": [ + "comments", + "lastUpdatedAt", + "status" + ], + "type": "object", + "nullable": true, + "description": "An object containing information about the decision of the assessment." + }, + "assessmentType": { + "$ref": "#/components/schemas/AssessmentType", + "description": "The assessment type for this assessment." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/AssessmentOwner" + } + ], + "nullable": true, + "description": "The owner of this assessment, if assigned." + } + }, + "required": [ + "id", + "vendorId", + "status", + "completedByUserId", + "startDate", + "dueDate", + "overrideDueDate", + "completionDate", + "createdDate", + "decision", + "assessmentType", + "owner" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_VendorAssessment_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/VendorAssessment" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, "FindingRiskStatus": { "description": "The status of the finding:\n- ACCEPT: The finding and its risk has been accepted and no follow up is required.\n- REMEDIATE: The finding needs to be remediated in some way.\n- NONE: The finding is not related to an observed risk that needs to be accepted or remediated.", "enum": [ @@ -2080,6 +2298,24 @@ "type": "object", "additionalProperties": false }, + "VendorRiskSection": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the risk section." + }, + "name": { + "type": "string", + "description": "Display name of the risk section." + } + }, + "required": [ + "id", + "name" + ], + "type": "object", + "additionalProperties": false + }, "VendorRiskAttribute": { "properties": { "id": { @@ -2108,6 +2344,10 @@ "riskLevel": { "$ref": "#/components/schemas/VendorRiskLevel", "description": "Risk level of this attribute." + }, + "riskSection": { + "$ref": "#/components/schemas/VendorRiskSection", + "description": "Risk section this attribute belongs to." } }, "required": [ @@ -2116,7 +2356,8 @@ "description", "vendorCategories", "enabled", - "riskLevel" + "riskLevel", + "riskSection" ], "type": "object", "additionalProperties": false @@ -2148,6 +2389,70 @@ "type": "object", "additionalProperties": false }, + "VendorAssessmentTypeLifecycleStatus": { + "description": "The lifecycle status of a vendor assessment type:\n- ACTIVE: The assessment type is available for use.\n- ARCHIVED: The assessment type has been archived and is kept for historical reference.", + "enum": [ + "ACTIVE", + "ARCHIVED" + ], + "type": "string" + }, + "VendorAssessmentType": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the assessment type." + }, + "name": { + "type": "string", + "description": "Display name of the assessment type." + }, + "description": { + "type": "string", + "nullable": true, + "description": "Description of the assessment type, if set." + }, + "status": { + "$ref": "#/components/schemas/VendorAssessmentTypeLifecycleStatus", + "description": "The lifecycle status of the assessment type." + } + }, + "required": [ + "id", + "name", + "description", + "status" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_VendorAssessmentType_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/VendorAssessmentType" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, "User": { "properties": { "id": { @@ -2209,6 +2514,16 @@ ], "type": "string" }, + "TrustCenterControlVisibilityMode": { + "type": "string", + "enum": [ + "SHOW_OK_ONLY", + "SHOW_OK_AND_UNMAPPED", + "SHOW_ALL_WITHOUT_STATUS", + "SHOW_ALL_WITH_STATUS" + ], + "description": "Which controls a Trust Center displays, and whether their pass/fail status is\nshown. Set as the Trust Center's global default, or per category to override\nthat default." + }, "TrustCenter": { "properties": { "id": { @@ -2304,6 +2619,10 @@ "nullable": true, "description": "Custom heading displayed on the Trust Center." }, + "controlVisibilityMode": { + "$ref": "#/components/schemas/TrustCenterControlVisibilityMode", + "description": "The default status-visibility mode applied to all controls that don't\nhave a category-level override. Always `SHOW_ALL_WITHOUT_STATUS` for\ndomains without the Vanta Compliance Platform, which have no control\nstatus to render." + }, "creationDate": { "type": "string", "format": "date-time", @@ -2327,6 +2646,7 @@ "customTheme", "contactEmail", "customHeading", + "controlVisibilityMode", "creationDate", "updatedDate" ], @@ -2427,6 +2747,10 @@ "type": "string", "nullable": true, "description": "Custom heading displayed on the Trust Center. If null is passed in, unsets\nthe current custom heading." + }, + "controlVisibilityMode": { + "$ref": "#/components/schemas/TrustCenterControlVisibilityMode", + "description": "The default status-visibility mode applied to all controls that don't\nhave a category-level override. Omit to leave unchanged. Only settable for\ndomains with the Vanta Compliance Platform; other domains have no control\nstatus to render." } }, "type": "object", @@ -2671,10 +2995,6 @@ "properties": { "docuSign": { "properties": { - "webhookId": { - "type": "string", - "description": "Unique ID used to identify and validate incoming webhook requests." - }, "envelopeId": { "type": "string", "description": "ID of the created envelope in DocuSign." @@ -2689,7 +3009,6 @@ } }, "required": [ - "webhookId", "envelopeId", "accountId", "accountBaseUrl" @@ -2929,9 +3248,23 @@ "type": "object", "additionalProperties": false }, - "TrustCenterVideo": { + "InviteReminderResponse": { + "description": "Response returned after a viewer invite reminder is sent.", "properties": { - "url": { + "isSuccessful": { + "type": "boolean", + "description": "Whether the invite reminder email was successfully sent." + } + }, + "required": [ + "isSuccessful" + ], + "type": "object", + "additionalProperties": false + }, + "TrustCenterVideo": { + "properties": { + "url": { "type": "string", "description": "Canonical URL for the video." }, @@ -3826,13 +4159,13 @@ "UploadFaviconResponse": { "description": "Response returned after a favicon upload.", "properties": { - "success": { + "isSuccessful": { "type": "boolean", "description": "Whether the favicon was successfully uploaded." } }, "required": [ - "success" + "isSuccessful" ], "type": "object", "additionalProperties": false @@ -4048,6 +4381,14 @@ "type": "object", "additionalProperties": false }, + "TrustCenterControlVisibility": { + "type": "string", + "enum": [ + "PUBLIC", + "SHAREABLE" + ], + "description": "Visibility of a control category's controls on the Trust Center.\n`SHAREABLE` categories are only visible to accounts with a matching access\ngrant." + }, "TrustCenterControlCategory": { "properties": { "id": { @@ -4057,11 +4398,26 @@ "name": { "type": "string", "description": "Name of the category." + }, + "visibility": { + "$ref": "#/components/schemas/TrustCenterControlVisibility", + "description": "Visibility of the category's controls on the Trust Center. `SHAREABLE`\ncategories are only visible to accounts with a matching access grant." + }, + "statusVisibilityOverride": { + "allOf": [ + { + "$ref": "#/components/schemas/TrustCenterControlVisibilityMode" + } + ], + "nullable": true, + "description": "Per-category status-visibility override. `null` means the category\nfollows the Trust Center's global default." } }, "required": [ "id", - "name" + "name", + "visibility", + "statusVisibilityOverride" ], "type": "object", "additionalProperties": false @@ -4081,7 +4437,7 @@ "type": "object", "additionalProperties": false }, - "AddOrEditTrustCenterControlCategoryInput": { + "AddTrustCenterControlCategoryInput": { "properties": { "name": { "type": "string", @@ -4094,6 +4450,29 @@ "type": "object", "additionalProperties": false }, + "EditTrustCenterControlCategoryInput": { + "properties": { + "name": { + "type": "string", + "description": "New name for the category. Omit to leave the name unchanged." + }, + "visibility": { + "$ref": "#/components/schemas/TrustCenterControlVisibility", + "description": "Visibility of the category's controls on the Trust Center. Omit to\nleave unchanged." + }, + "statusVisibilityOverride": { + "allOf": [ + { + "$ref": "#/components/schemas/TrustCenterControlVisibilityMode" + } + ], + "nullable": true, + "description": "Per-category status-visibility override. Omit to leave unchanged; pass\n`null` to clear the override and fall back to the Trust Center's global\ndefault." + } + }, + "type": "object", + "additionalProperties": false + }, "BulkEditControlsInCategoryInput": { "description": "Request body for bulk editing controls in a category.", "properties": { @@ -4306,17 +4685,22 @@ "type": "object", "additionalProperties": false }, - "ArrayResponse_TrustCenterComplianceFramework_": { + "TrustCenterComplianceFrameworkListResponse": { "properties": { "results": { "items": { "$ref": "#/components/schemas/TrustCenterComplianceFramework" }, "type": "array" + }, + "isSectionVisible": { + "type": "boolean", + "description": "Whether the compliance section is visible on the external Trust Center." } }, "required": [ - "results" + "results", + "isSectionVisible" ], "type": "object", "additionalProperties": false @@ -4332,8 +4716,10 @@ "enum": [ "aiact", "aiuc1", + "aiuc1_26q3", "aue8", "awsFTR", + "bsic5", "ccpa", "cisv8", "cjis", @@ -4361,6 +4747,7 @@ "nis2d", "nist53", "nist171", + "nist171r3", "nistAiRmf", "nistCSF", "nistcsf2", @@ -4374,6 +4761,7 @@ "soxITGC", "t23nycrr500", "tisax", + "tisax2027", "iso22301", "trust", "ukCyberEssentials", @@ -4407,8 +4795,10 @@ "enum": [ "aiact", "aiuc1", + "aiuc1_26q3", "aue8", "awsFTR", + "bsic5", "ccpa", "cisv8", "cjis", @@ -4436,6 +4826,7 @@ "nis2d", "nist53", "nist171", + "nist171r3", "nistAiRmf", "nistCSF", "nistcsf2", @@ -4449,6 +4840,7 @@ "soxITGC", "t23nycrr500", "tisax", + "tisax2027", "iso22301", "trust", "ukCyberEssentials", @@ -4471,13 +4863,13 @@ }, "BadgeUploadResponse": { "properties": { - "success": { + "isSuccessful": { "type": "boolean", "description": "Whether the upload succeeded." } }, "required": [ - "success" + "isSuccessful" ], "type": "object", "additionalProperties": false @@ -4831,6 +5223,10 @@ "reason": { "type": "string", "description": "Reason for denying the access request." + }, + "sendEmail": { + "type": "boolean", + "description": "Whether to email the requester to notify them that their request was\ndenied. The email includes the reason when one is provided. Defaults to\nfalse." } }, "type": "object", @@ -5195,213 +5591,485 @@ "type": "object", "additionalProperties": false }, - "CIA": { - "type": "string", - "enum": [ - "Confidentiality", - "Integrity", - "Availability" - ] + "RequirementNotApplied": { + "description": "A requirement the set does not apply to the personnel it covers.", + "properties": { + "required": { + "type": "boolean", + "enum": [ + false + ], + "nullable": false + } + }, + "required": [ + "required" + ], + "type": "object", + "additionalProperties": false }, - "Treatment": { - "type": "string", - "enum": [ - "Mitigate", - "Transfer", - "Avoid", - "Accept" + "AllPoliciesRequired": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false + }, + "acceptAll": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false + } + }, + "required": [ + "required", + "acceptAll" + ], + "type": "object", + "additionalProperties": false + }, + "SelectedPoliciesRequired": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false + }, + "acceptAll": { + "type": "boolean", + "enum": [ + false + ], + "nullable": false + }, + "policyIds": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "required": [ + "required", + "acceptAll", + "policyIds" + ], + "type": "object", + "additionalProperties": false + }, + "PolicyAcceptanceRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" + }, + { + "$ref": "#/components/schemas/AllPoliciesRequired" + }, + { + "$ref": "#/components/schemas/SelectedPoliciesRequired" + } ] }, - "CustomAttribute": { + "BackgroundCheckRequired": { "properties": { - "label": { - "type": "string" + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false }, - "value": { - "anyOf": [ - { - "type": "string" - }, - { - "items": { - "type": "string" - }, - "type": "array" - } - ] + "cutoffDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "Personnel hired after this date require a check. Null requires a check for everyone in scope." } }, "required": [ - "label", - "value" + "required", + "cutoffDate" ], "type": "object", "additionalProperties": false }, - "ReviewStatus": { - "type": "string", - "enum": [ - "APPROVED", - "DRAFT", - "NOT_REVIEWED", - "AWAITING_SUBMISSION", - "PENDING_APPROVAL", - "REQUESTED_CHANGES" + "BackgroundCheckRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" + }, + { + "$ref": "#/components/schemas/BackgroundCheckRequired" + } ] }, - "RiskScenarioType": { + "SecurityTrainingCategory": { "type": "string", "enum": [ - "Risk Scenario", - "Enterprise Risk" + "aiRisk", + "c5", + "ccpa", + "gdpr", + "general", + "hipaa", + "insiderThreat", + "pci", + "secureCode", + "socialEngineering" ] }, - "RiskScenario": { + "SecurityTrainingRequired": { "properties": { - "riskId": { - "type": "string", - "description": "The unique ID of the risk specified by the user. Used to reference and update existing risks." - }, - "description": { - "type": "string", - "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability.\n\nNaming note: in the UI, `description` is labelled \"Title\" and\n`detailedDescription` is labelled \"Description\". The field names\nare preserved for backwards compatibility with the public REST API\nand existing data." - }, - "detailedDescription": { - "type": "string", - "nullable": true, - "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters.\n\nNaming note: in the UI, `description` is labelled \"Title\" and\n`detailedDescription` is labelled \"Description\". The field names\nare preserved for backwards compatibility with the public REST API\nand existing data." - }, - "isSensitive": { + "required": { "type": "boolean", - "nullable": true, - "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", - "deprecated": true - }, - "likelihood": { - "type": "integer", - "format": "int32", - "nullable": true, - "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." - }, - "impact": { - "type": "integer", - "format": "int32", - "nullable": true, - "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." - }, - "residualLikelihood": { - "type": "integer", - "format": "int32", - "nullable": true, - "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." - }, - "residualImpact": { - "type": "integer", - "format": "int32", - "nullable": true, - "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." + "enum": [ + true + ], + "nullable": false }, - "categories": { + "requiredCategories": { "items": { - "type": "string" + "$ref": "#/components/schemas/SecurityTrainingCategory" }, - "type": "array", - "description": "The list of categories this risk scenario belongs to." + "type": "array" }, - "ciaCategories": { + "requirementIds": { "items": { - "$ref": "#/components/schemas/CIA" + "type": "string" }, - "type": "array", - "description": "A list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" + "type": "array" + } + }, + "required": [ + "required", + "requiredCategories", + "requirementIds" + ], + "type": "object", + "additionalProperties": false + }, + "SecurityTrainingRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" }, - "treatment": { + { + "$ref": "#/components/schemas/SecurityTrainingRequired" + } + ] + }, + "PasswordManager": { + "type": "string", + "enum": [ + "BITWARDEN", + "DASHLANE", + "ENPASS", + "KEEPER", + "LASTPASS", + "NORDPASS", + "ONEPASSWORD", + "PROTON", + "ROBOFORM", + "SAFEINCLOUD", + "TRENDMICRO" + ] + }, + "DeviceMonitoringInstallPrompt": { + "type": "string", + "enum": [ + "INSTALL_VANTA_AGENT", + "NONE" + ] + }, + "DeviceMonitoringRequired": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false + }, + "preferredPasswordManagerId": { "allOf": [ { - "$ref": "#/components/schemas/Treatment" + "$ref": "#/components/schemas/PasswordManager" } ], - "nullable": true, - "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" - }, - "owner": { - "type": "string", - "nullable": true, - "description": "The email of the person responsible for tracking and mitigating this risk scenario." - }, - "note": { - "type": "string", - "nullable": true, - "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." + "nullable": true }, - "riskRegister": { + "installPrompt": { + "$ref": "#/components/schemas/DeviceMonitoringInstallPrompt" + } + }, + "required": [ + "required", + "preferredPasswordManagerId", + "installPrompt" + ], + "type": "object", + "additionalProperties": false + }, + "DeviceMonitoringRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" + }, + { + "$ref": "#/components/schemas/DeviceMonitoringRequired" + } + ] + }, + "TaskRequirementSetCustomTask": { + "properties": { + "checklistTaskId": { + "type": "string" + }, + "effectiveDate": { "type": "string", + "format": "date-time", "nullable": true, - "description": "Name of the risk register associated with this scenario." + "description": "Applies to personnel whose employment start date is after this. Null applies to everyone." + } + }, + "required": [ + "checklistTaskId", + "effectiveDate" + ], + "type": "object", + "additionalProperties": false + }, + "CustomTasksRequired": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false }, - "customFields": { + "tasks": { "items": { - "$ref": "#/components/schemas/CustomAttribute" + "$ref": "#/components/schemas/TaskRequirementSetCustomTask" }, - "type": "array", - "description": "The list of custom fields.\nYou can reference existing custom fields in the Risk Management settings and/or create new ones.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" + "type": "array" + } + }, + "required": [ + "required", + "tasks" + ], + "type": "object", + "additionalProperties": false + }, + "CustomTasksRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" }, - "isArchived": { - "type": "boolean", - "description": "Whether this scenario is archived." + { + "$ref": "#/components/schemas/CustomTasksRequired" + } + ] + }, + "OnboardingRequirements": { + "properties": { + "policyAcceptance": { + "$ref": "#/components/schemas/PolicyAcceptanceRequirement" }, - "reviewStatus": { - "$ref": "#/components/schemas/ReviewStatus", - "description": "The current review status of this risk scenario" + "backgroundCheck": { + "$ref": "#/components/schemas/BackgroundCheckRequirement" }, - "requiredApprovers": { + "securityTraining": { + "$ref": "#/components/schemas/SecurityTrainingRequirement" + }, + "deviceMonitoring": { + "$ref": "#/components/schemas/DeviceMonitoringRequirement" + }, + "custom": { + "$ref": "#/components/schemas/CustomTasksRequirement" + } + }, + "required": [ + "policyAcceptance", + "backgroundCheck", + "securityTraining", + "deviceMonitoring", + "custom" + ], + "type": "object", + "additionalProperties": false + }, + "DeactivateAllAccounts": { + "properties": { + "deactivateAll": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false + } + }, + "required": [ + "deactivateAll" + ], + "type": "object", + "additionalProperties": false + }, + "DeactivateSelectedAccounts": { + "properties": { + "deactivateAll": { + "type": "boolean", + "enum": [ + false + ], + "nullable": false + }, + "accountIds": { "items": { "type": "string" }, - "type": "array", - "description": "The list of required approvers for this risk scenario." + "type": "array" + } + }, + "required": [ + "deactivateAll", + "accountIds" + ], + "type": "object", + "additionalProperties": false + }, + "AccountSelection": { + "anyOf": [ + { + "$ref": "#/components/schemas/DeactivateAllAccounts" }, - "type": { - "$ref": "#/components/schemas/RiskScenarioType", - "description": "The type of risk scenario.\n- \"Risk Scenario\": Standard risk scenario\n- \"Enterprise Risk\": Enterprise-level risk" + { + "$ref": "#/components/schemas/DeactivateSelectedAccounts" + } + ] + }, + "AccountDeactivationRequired": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false }, - "identificationDate": { + "accounts": { + "$ref": "#/components/schemas/AccountSelection" + } + }, + "required": [ + "required", + "accounts" + ], + "type": "object", + "additionalProperties": false + }, + "AccountDeactivationRequirement": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" + }, + { + "$ref": "#/components/schemas/AccountDeactivationRequired" + } + ] + }, + "OffboardingRequirements": { + "properties": { + "accountDeactivation": { + "$ref": "#/components/schemas/AccountDeactivationRequirement" + }, + "custom": { + "$ref": "#/components/schemas/CustomTasksRequirement" + } + }, + "required": [ + "accountDeactivation", + "custom" + ], + "type": "object", + "additionalProperties": false + }, + "TaskRequirements": { + "properties": { + "onboarding": { + "$ref": "#/components/schemas/OnboardingRequirements" + }, + "offboarding": { + "$ref": "#/components/schemas/OffboardingRequirements" + } + }, + "required": [ + "onboarding", + "offboarding" + ], + "type": "object", + "additionalProperties": false + }, + "TaskRequirementSet": { + "properties": { + "id": { + "type": "string", + "description": "The task requirement set's unique ID." + }, + "name": { + "type": "string", + "description": "The task requirement set's display name." + }, + "description": { + "type": "string", + "nullable": true, + "description": "The task requirement set's description." + }, + "isReusable": { + "type": "boolean", + "description": "Whether groups other than the one that owns this set may also apply it." + }, + "createdAt": { "type": "string", "format": "date-time", - "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Set by the customer when a risk is created; defaults to the scenario's creation time when not explicitly provided." + "description": "The date the set was created." + }, + "updatedAt": { + "type": "string", + "format": "date-time", + "description": "The date the set was last updated." + }, + "taskRequirements": { + "$ref": "#/components/schemas/TaskRequirements", + "description": "The onboarding and offboarding requirements the set applies to its personnel." } }, "required": [ - "riskId", + "id", + "name", "description", - "isSensitive", - "likelihood", - "impact", - "residualLikelihood", - "residualImpact", - "categories", - "ciaCategories", - "treatment", - "owner", - "note", - "riskRegister", - "customFields", - "isArchived", - "reviewStatus", - "requiredApprovers", - "type", - "identificationDate" + "isReusable", + "createdAt", + "updatedAt", + "taskRequirements" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_RiskScenario_": { + "PaginatedResponse_TaskRequirementSet_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/RiskScenario" + "$ref": "#/components/schemas/TaskRequirementSet" }, "type": "array" }, @@ -5422,2687 +6090,2656 @@ "type": "object", "additionalProperties": false }, - "UNCATEGORIZED": { - "type": "string", - "enum": [ - "Uncategorized" - ], - "nullable": false - }, - "NO_TREATMENT_TYPE": { - "type": "string", - "enum": [ - "No treatment type" - ], - "nullable": false - }, - "ScoreGroup": { - "type": "string", - "enum": [ - "Very low", - "Low", - "Med", - "High", - "Critical" - ] - }, - "CreateRiskScenarioInput": { + "VantaSecurityTrainingInput": { + "description": "A training supplied by Vanta.", "properties": { - "description": { + "type": { "type": "string", - "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability." + "enum": [ + "VANTA" + ], + "nullable": false }, - "detailedDescription": { + "category": { + "$ref": "#/components/schemas/SecurityTrainingCategory" + }, + "instructions": { "type": "string", - "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters." + "nullable": true, + "description": "Completion instructions shown to personnel. Null uses Vanta's own." }, - "riskId": { + "url": { + "type": "number", + "enum": [ + null + ], + "nullable": true + } + }, + "required": [ + "type", + "category", + "instructions", + "url" + ], + "type": "object", + "additionalProperties": false + }, + "CustomSecurityTrainingInput": { + "description": "A training the organization hosts itself.", + "properties": { + "type": { "type": "string", - "description": "The unique ID of the risk. Used to reference and update existing risks.\nWe will auto-generate one if one isn't specified." + "enum": [ + "CUSTOM" + ], + "nullable": false }, - "isSensitive": { - "type": "boolean", - "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", - "deprecated": true + "category": { + "$ref": "#/components/schemas/SecurityTrainingCategory" }, - "likelihood": { - "type": "integer", - "format": "int32", - "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings." + "instructions": { + "type": "string", + "nullable": true, + "description": "Completion instructions shown to personnel." }, - "impact": { - "type": "integer", - "format": "int32", - "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings." - }, - "residualLikelihood": { - "type": "integer", - "format": "int32", - "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." - }, - "residualImpact": { - "type": "integer", - "format": "int32", - "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." - }, - "categories": { - "items": { - "type": "string" - }, - "type": "array", - "description": "The list of categories this risk scenario belongs to.\nEach element in the list will become a new custom category if it doesn't match an existing one.\nYou can reference the current category options in the Risk Management settings and/or enter new values." - }, - "ciaCategories": { - "items": { - "$ref": "#/components/schemas/CIA" - }, - "type": "array", - "description": "Enter a list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" - }, - "treatment": { - "$ref": "#/components/schemas/Treatment", - "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" - }, - "owner": { - "type": "string", - "description": "The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user." - }, - "note": { - "type": "string", - "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." - }, - "riskRegister": { - "type": "string", - "description": "Name of the risk register to associate with this scenario.\n\nThis field must be set if the organization has multiple registers." - }, - "customFields": { - "items": { - "$ref": "#/components/schemas/CustomAttribute" - }, - "type": "array", - "description": "The list of custom attributes.\nYou can reference existing custom attributes in the Risk Management settings and/or create new ones.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" - }, - "type": { - "$ref": "#/components/schemas/RiskScenarioType", - "description": "The type of risk scenario to create.\n- \"Risk Scenario\": Standard risk scenario (default)\n- \"Enterprise Risk\": Enterprise-level risk (requires Enterprise Risk Management SKU)\n\nEnterprise risks cannot be associated with a risk register.\nDefaults to \"Risk Scenario\" if not specified." - }, - "identificationDate": { + "url": { "type": "string", - "format": "date-time", - "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Defaults to the scenario's creation time if omitted." + "nullable": true, + "description": "Where personnel complete the training." } }, "required": [ - "description" + "type", + "category", + "instructions", + "url" ], "type": "object", "additionalProperties": false }, - "UpdateRiskScenarioInput": { + "IntegrationSecurityTrainingInput": { + "description": "A training completed in a connected integration", "properties": { - "description": { - "type": "string", - "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability." - }, - "detailedDescription": { + "type": { "type": "string", - "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters." - }, - "isSensitive": { - "type": "boolean", - "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", - "deprecated": true - }, - "likelihood": { - "type": "integer", - "format": "int32", - "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings." - }, - "impact": { - "type": "integer", - "format": "int32", - "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings." - }, - "residualLikelihood": { - "type": "integer", - "format": "int32", - "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." - }, - "residualImpact": { - "type": "integer", - "format": "int32", - "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." - }, - "categories": { - "items": { - "type": "string" - }, - "type": "array", - "description": "The list of categories this risk scenario belongs to.\nEach element in the list will become a new custom category if it doesn't match an existing one.\nYou can reference the current category options in the Risk Management settings and/or enter new values." + "enum": [ + "INTEGRATION" + ], + "nullable": false }, - "ciaCategories": { - "items": { - "$ref": "#/components/schemas/CIA" - }, - "type": "array", - "description": "Enter a list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" + "category": { + "$ref": "#/components/schemas/SecurityTrainingCategory" }, - "treatment": { - "$ref": "#/components/schemas/Treatment", - "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" + "instructions": { + "type": "number", + "enum": [ + null + ], + "nullable": true }, - "owner": { - "type": "string", - "nullable": true, - "description": "The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user." + "url": { + "type": "number", + "enum": [ + null + ], + "nullable": true + } + }, + "required": [ + "type", + "category", + "instructions", + "url" + ], + "type": "object", + "additionalProperties": false + }, + "SecurityTrainingInput": { + "anyOf": [ + { + "$ref": "#/components/schemas/VantaSecurityTrainingInput" }, - "note": { - "type": "string", - "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." + { + "$ref": "#/components/schemas/CustomSecurityTrainingInput" }, - "riskRegister": { - "type": "string", - "description": "Name of the risk register to associate with this scenario." + { + "$ref": "#/components/schemas/IntegrationSecurityTrainingInput" + } + ] + }, + "SecurityTrainingRequiredInput": { + "properties": { + "required": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false }, - "customFields": { + "trainings": { "items": { - "$ref": "#/components/schemas/CustomAttribute" + "$ref": "#/components/schemas/SecurityTrainingInput" }, "type": "array", - "description": "The list of custom fields.\nYou can reference custom fields in the Risk Management settings and/or create new one.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" - }, - "type": { - "$ref": "#/components/schemas/RiskScenarioType", - "description": "Changing the risk scenario type (`\"Risk Scenario\"` vs. `\"Enterprise Risk\"`)\nis not supported via update. Requests that include this field will be\nrejected. To change a risk's type, create a new scenario with the desired\ntype and archive the old one." - }, - "identificationDate": { - "type": "string", - "format": "date-time", - "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Omitting the field leaves the existing value unchanged." + "description": "Replaces the set's trainings wholesale. At most one per category." } }, + "required": [ + "required", + "trainings" + ], "type": "object", "additionalProperties": false }, - "SubmitRiskForApprovalInput": { - "properties": { - "comment": { - "type": "string", - "description": "Optional comment to include with the approval request." + "SecurityTrainingRequirementInput": { + "anyOf": [ + { + "$ref": "#/components/schemas/RequirementNotApplied" + }, + { + "$ref": "#/components/schemas/SecurityTrainingRequiredInput" } - }, - "type": "object", - "additionalProperties": false - }, - "RiskScenarioControlType": { - "type": "string", - "enum": [ - "EXISTING", - "TREATMENT_PLAN" - ] + ], + "description": "Security training is written as the trainings to require and read back as the\ncategories and requirement records the server resolved them into." }, - "RiskScenarioControl": { - "description": "A control's association with a risk scenario.\n\nThe relationship identity is `(riskScenarioId, controlId)`; `controlType`\nis mutable state on that relationship. A given control can have at most one\nassociation per risk scenario.", + "OnboardingRequirementsInput": { "properties": { - "controlId": { - "type": "string", - "description": "The control's shorthand identifier (e.g. `\"A.12.2.1\"`) when it has one,\nfalling back to the canonical Vanta control id (Mongo object id) otherwise." + "policyAcceptance": { + "$ref": "#/components/schemas/PolicyAcceptanceRequirement" }, - "controlType": { - "$ref": "#/components/schemas/RiskScenarioControlType", - "description": "`TREATMENT_PLAN` for controls that are part of the risk's treatment plan\n(planned mitigations); `EXISTING` for controls linked to the risk without a\ntreatment-plan designation." + "backgroundCheck": { + "$ref": "#/components/schemas/BackgroundCheckRequirement" + }, + "securityTraining": { + "$ref": "#/components/schemas/SecurityTrainingRequirementInput" + }, + "deviceMonitoring": { + "$ref": "#/components/schemas/DeviceMonitoringRequirement" + }, + "custom": { + "$ref": "#/components/schemas/CustomTasksRequirement" } }, - "required": [ - "controlId", - "controlType" - ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_RiskScenarioControl_": { + "OffboardingRequirementsInput": { "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/RiskScenarioControl" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "accountDeactivation": { + "$ref": "#/components/schemas/AccountDeactivationRequirement" + }, + "custom": { + "$ref": "#/components/schemas/CustomTasksRequirement" } }, - "required": [ - "results" - ], "type": "object", "additionalProperties": false }, - "CreateRiskScenarioControlInput": { + "CreateTaskRequirementSetInput": { "properties": { - "controlId": { + "name": { "type": "string", - "description": "Control to associate with the risk scenario. Accepts Vanta control\nshorthands (e.g. `\"A.12.2.1\"`), custom-control shorthand names, or\nobject IDs." + "description": "Display name for the set." }, - "controlType": { - "$ref": "#/components/schemas/RiskScenarioControlType", - "description": "`TREATMENT_PLAN` for a control that is part of the risk's treatment plan.\nOmit (or pass `\"EXISTING\"`) to associate the control without a\ntreatment-plan designation — the default \"existing control\" relationship." + "description": { + "type": "string", + "nullable": true, + "description": "Description of the set. Omit for none." + }, + "isReusable": { + "type": "boolean", + "description": "Whether groups other than the one that owns this set may also apply it." + }, + "onboarding": { + "$ref": "#/components/schemas/OnboardingRequirementsInput", + "description": "Onboarding requirements to apply. Omitted requirements default to not required." + }, + "offboarding": { + "$ref": "#/components/schemas/OffboardingRequirementsInput", + "description": "Offboarding requirements to apply. Omitted requirements default to not required." } }, "required": [ - "controlId" + "name", + "isReusable" ], "type": "object", "additionalProperties": false }, - "UpdateRiskScenarioControlInput": { + "TaskRequirementsInput": { "properties": { - "controlType": { - "$ref": "#/components/schemas/RiskScenarioControlType", - "description": "The new relationship state. `TREATMENT_PLAN` moves the control into the\nrisk's treatment plan; `EXISTING` removes it from the treatment plan while\nkeeping it linked as an existing control (use DELETE to unlink entirely)." + "onboarding": { + "$ref": "#/components/schemas/OnboardingRequirementsInput", + "description": "Onboarding requirements to replace. Omit a requirement to leave it unchanged." + }, + "offboarding": { + "$ref": "#/components/schemas/OffboardingRequirementsInput", + "description": "Offboarding requirements to replace. Omit a requirement to leave it unchanged." } }, - "required": [ - "controlType" - ], "type": "object", "additionalProperties": false }, - "PolicyStatus": { + "CIA": { + "type": "string", "enum": [ - "OK", - "NEEDS_REMEDIATION" - ], - "type": "string" + "Confidentiality", + "Integrity", + "Availability" + ] }, - "PolicyVersionStatus": { + "Treatment": { + "type": "string", "enum": [ - "NOT_STARTED", - "DRAFT", - "PENDING_APPROVAL", - "APPROVED", - "RENEW_SOON", - "EXPIRED" - ], - "type": "string" + "Mitigate", + "Transfer", + "Avoid", + "Accept" + ] }, - "PolicyLatestVersion": { + "CustomAttribute": { "properties": { - "status": { - "$ref": "#/components/schemas/PolicyVersionStatus", - "description": "The status of the policy's latest version." + "label": { + "type": "string" + }, + "value": { + "anyOf": [ + { + "type": "string" + }, + { + "items": { + "type": "string" + }, + "type": "array" + } + ] } }, "required": [ - "status" + "label", + "value" ], "type": "object", "additionalProperties": false }, - "PolicyLocale": { + "ReviewStatus": { + "type": "string", "enum": [ - "CS", - "CY", - "DA", - "DE", - "EN", - "ES", - "FI", - "FR", - "HU", - "IS", - "IT", - "JA", - "KO", - "NL", - "NO", - "NOT_SPECIFIED", - "PL", - "PT", - "ET", - "RO", - "AR", - "SK", - "SV", - "TR", - "ZH" + "APPROVED", + "DRAFT", + "NOT_REVIEWED", + "AWAITING_SUBMISSION", + "PENDING_APPROVAL", + "REQUESTED_CHANGES" + ] + }, + "RiskScenarioType": { + "type": "string", + "enum": [ + "Risk Scenario", + "Enterprise Risk" + ] + }, + "ScoreBreakdownEntryKind": { + "type": "string", + "enum": [ + "SCORE", + "DIMENSION", + "FACTOR" ], - "type": "string" + "description": "`SCORE` is the root, `DIMENSION` is a direct child, and `FACTOR` is any deeper node." }, - "PolicyDocument": { + "ScoreBreakdownEntryStatus": { + "type": "string", + "enum": [ + "SCORED", + "MISSING", + "NOT_APPLICABLE" + ], + "description": "`SCORED` has an entered value; `MISSING` is unscored; `NOT_APPLICABLE`\nis excluded from its parent's calculation." + }, + "ScoreBreakdownEntry": { + "description": "One node in the inherent risk scoring tree. Entries are ordered parents before\nchildren, with `parentId` linking each child to its parent.", "properties": { - "language": { + "id": { + "type": "string", + "description": "Config node ID, unique within this breakdown. IDs can change when the scoring\nconfig is restructured; re-read the breakdown instead of storing them long-term." + }, + "kind": { + "$ref": "#/components/schemas/ScoreBreakdownEntryKind", + "description": "Whether this entry is the overall score, a dimension, or a factor." + }, + "name": { + "type": "string", + "description": "Display name of this node, from the scoring config." + }, + "score": { + "type": "number", + "format": "double", + "nullable": true, + "description": "Entered or calculated value, which may be fractional. `null` when unscored,\nnot applicable, or no aggregate value is available; see `status` for leaf nodes." + }, + "status": { "allOf": [ { - "$ref": "#/components/schemas/PolicyLocale" + "$ref": "#/components/schemas/ScoreBreakdownEntryStatus" } ], "nullable": true, - "description": "The language of the policy document." + "description": "Scoring status for a directly scored node. `null` for aggregates; read their\nchildren's statuses instead." }, - "slugId": { + "scoreLabel": { "type": "string", - "description": "The slug ID of the policy document." + "nullable": true, + "description": "Matching option label for a directly scored node, or the register's range-band\nlabel for the overall score. `null` when no label applies, including non-root\naggregates and overall scores on registers using matrix-based severity." }, - "url": { + "parentId": { "type": "string", - "description": "The URL of the policy document." + "nullable": true, + "description": "Parent entry's ID, or `null` for the overall score." } }, "required": [ - "language", - "slugId", - "url" + "id", + "kind", + "name", + "score", + "status", + "scoreLabel", + "parentId" ], "type": "object", "additionalProperties": false }, - "PolicyLatestApprovedVersion": { + "RiskScenario": { "properties": { - "versionId": { + "riskId": { "type": "string", - "description": "The ID of the latest approved version of the policy." + "description": "The unique ID of the risk specified by the user. Used to reference and update existing risks." }, - "documents": { - "items": { - "$ref": "#/components/schemas/PolicyDocument" - }, - "type": "array", - "description": "Available document versions for this policy, organized by language." - } - }, - "required": [ - "versionId", - "documents" - ], - "type": "object", - "additionalProperties": false - }, - "Policy": { - "properties": { - "id": { + "description": { "type": "string", - "description": "The policy's unique ID." + "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability.\n\nNaming note: in the UI, `description` is labelled \"Title\" and\n`detailedDescription` is labelled \"Description\". The field names\nare preserved for backwards compatibility with the public REST API\nand existing data." }, - "name": { + "detailedDescription": { "type": "string", - "description": "The policy's name." + "nullable": true, + "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters.\n\nNaming note: in the UI, `description` is labelled \"Title\" and\n`detailedDescription` is labelled \"Description\". The field names\nare preserved for backwards compatibility with the public REST API\nand existing data." }, - "description": { - "type": "string", - "description": "The policy's description." + "isSensitive": { + "type": "boolean", + "nullable": true, + "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", + "deprecated": true }, - "status": { - "$ref": "#/components/schemas/PolicyStatus", - "description": "The policy's current status." + "likelihood": { + "type": "integer", + "format": "int32", + "nullable": true, + "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." }, - "approvedAtDate": { - "type": "string", - "format": "date-time", + "impact": { + "type": "integer", + "format": "int32", "nullable": true, - "description": "The policy's most recent date of approval, if applicable." + "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." }, - "latestVersion": { - "$ref": "#/components/schemas/PolicyLatestVersion", - "description": "The latest version of the policy." + "residualLikelihood": { + "type": "integer", + "format": "int32", + "nullable": true, + "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." }, - "latestApprovedVersion": { + "residualImpact": { + "type": "integer", + "format": "int32", + "nullable": true, + "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings.\nA value of `null` indicates that no score has been assigned." + }, + "categories": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The list of categories this risk scenario belongs to." + }, + "ciaCategories": { + "items": { + "$ref": "#/components/schemas/CIA" + }, + "type": "array", + "description": "A list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" + }, + "treatment": { "allOf": [ { - "$ref": "#/components/schemas/PolicyLatestApprovedVersion" + "$ref": "#/components/schemas/Treatment" } ], "nullable": true, - "description": "The latest approved version of the policy, if available." - } - }, - "required": [ - "id", - "name", - "description", - "status", - "approvedAtDate", - "latestVersion", - "latestApprovedVersion" - ], - "type": "object", - "additionalProperties": false - }, - "PaginatedResponse_Policy_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Policy" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" - } - }, - "required": [ - "results" - ], - "type": "object", - "additionalProperties": false - }, - "EmploymentStatus": { - "description": "The employment status of a person:\n- UPCOMING: The person is not yet employed and will start employment in the future.\n- CURRENT: The person is currently employed.\n- ON_LEAVE: The person is on leave.\n- INACTIVE: The person's employment is inactive.\n- FORMER: The person was previously employed.", - "enum": [ - "UPCOMING", - "CURRENT", - "ON_LEAVE", - "INACTIVE", - "FORMER" - ], - "type": "string" - }, - "LeaveStatus": { - "description": "User can be active or upcoming leave period", - "enum": [ - "ACTIVE", - "UPCOMING" - ], - "type": "string" - }, - "LeaveInfo": { - "properties": { - "startDate": { + "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" + }, + "owner": { "type": "string", - "format": "date-time", - "description": "The start of the person's leave." + "nullable": true, + "description": "The email of the person responsible for tracking and mitigating this risk scenario." }, - "endDate": { + "note": { "type": "string", - "format": "date-time", "nullable": true, - "description": "The end of the person's leave. Null endDate implies indefinite leave." + "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." }, - "status": { - "$ref": "#/components/schemas/LeaveStatus", - "description": "ACTIVE if the leave is currently ongoing. UPCOMING if the startDate is in the future." + "riskRegister": { + "type": "string", + "nullable": true, + "description": "Name of the risk register associated with this scenario." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomAttribute" + }, + "type": "array", + "description": "The list of custom fields.\nYou can reference existing custom fields in the Risk Management settings and/or create new ones.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" + }, + "isArchived": { + "type": "boolean", + "description": "Whether this scenario is archived." + }, + "reviewStatus": { + "$ref": "#/components/schemas/ReviewStatus", + "description": "The current review status of this risk scenario" + }, + "requiredApprovers": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The list of required approvers for this risk scenario." + }, + "type": { + "$ref": "#/components/schemas/RiskScenarioType", + "description": "The type of risk scenario.\n- \"Risk Scenario\": Standard risk scenario\n- \"Enterprise Risk\": Enterprise-level risk" + }, + "identificationDate": { + "type": "string", + "format": "date-time", + "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Set by the customer when a risk is created; defaults to the scenario's creation time when not explicitly provided." + }, + "scoreBreakdown": { + "items": { + "$ref": "#/components/schemas/ScoreBreakdownEntry" + }, + "type": "array", + "nullable": true, + "description": "Overall inherent score, dimensions, and nested factors, ordered parents before\nchildren and linked by `parentId`. `null` when Flexible Risk Scoring is off or\nthe scenario has no score or matching config. Closed beta." } }, "required": [ - "startDate", - "endDate", - "status" + "riskId", + "description", + "isSensitive", + "likelihood", + "impact", + "residualLikelihood", + "residualImpact", + "categories", + "ciaCategories", + "treatment", + "owner", + "note", + "riskRegister", + "customFields", + "isArchived", + "reviewStatus", + "requiredApprovers", + "type", + "identificationDate", + "scoreBreakdown" ], "type": "object", "additionalProperties": false }, - "PersonInfoSourceType.VANTA": { - "enum": [ - "VANTA" - ], - "type": "string" - }, - "VantaBasedPersonInfoSource": { - "description": "The person's information comes from what is set in Vanta.", + "PaginatedResponse_RiskScenario_": { "properties": { - "type": { - "$ref": "#/components/schemas/PersonInfoSourceType.VANTA" + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/RiskScenario" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, "required": [ - "type" + "results" ], "type": "object", "additionalProperties": false }, - "PersonInfoSourceType.SCIM": { + "UNCATEGORIZED": { + "type": "string", "enum": [ - "SCIM" + "Uncategorized" ], - "type": "string" + "nullable": false }, - "ScimBasedPersonInfoSource": { - "description": "The person's information comes from SCIM.", - "properties": { - "type": { - "$ref": "#/components/schemas/PersonInfoSourceType.SCIM" - } - }, - "required": [ - "type" + "NO_TREATMENT_TYPE": { + "type": "string", + "enum": [ + "No treatment type" ], - "type": "object", - "additionalProperties": false + "nullable": false }, - "PersonInfoSourceType.INTEGRATION": { + "ScoreGroup": { + "type": "string", "enum": [ - "INTEGRATION" - ], - "type": "string" + "Very low", + "Low", + "Med", + "High", + "Critical" + ] }, - "IntegrationBasedPersonInfoSource": { - "description": "The person's information comes from an integration.", + "CreateRiskScenarioInput": { "properties": { - "integrationId": { - "type": "string" + "description": { + "type": "string", + "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability." }, - "resourceId": { + "detailedDescription": { "type": "string", - "nullable": true + "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters." + }, + "riskId": { + "type": "string", + "description": "The unique ID of the risk. Used to reference and update existing risks.\nWe will auto-generate one if one isn't specified." + }, + "isSensitive": { + "type": "boolean", + "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", + "deprecated": true + }, + "likelihood": { + "type": "integer", + "format": "int32", + "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings." + }, + "impact": { + "type": "integer", + "format": "int32", + "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings." + }, + "residualLikelihood": { + "type": "integer", + "format": "int32", + "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." + }, + "residualImpact": { + "type": "integer", + "format": "int32", + "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." + }, + "categories": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The list of categories this risk scenario belongs to.\nEach element in the list will become a new custom category if it doesn't match an existing one.\nYou can reference the current category options in the Risk Management settings and/or enter new values." + }, + "ciaCategories": { + "items": { + "$ref": "#/components/schemas/CIA" + }, + "type": "array", + "description": "Enter a list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" + }, + "treatment": { + "$ref": "#/components/schemas/Treatment", + "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" + }, + "owner": { + "type": "string", + "description": "The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user." + }, + "note": { + "type": "string", + "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." + }, + "riskRegister": { + "type": "string", + "description": "Name of the risk register to associate with this scenario.\n\nThis field must be set if the organization has multiple registers." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomAttribute" + }, + "type": "array", + "description": "The list of custom attributes.\nYou can reference existing custom attributes in the Risk Management settings and/or create new ones.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" }, "type": { - "$ref": "#/components/schemas/PersonInfoSourceType.INTEGRATION" + "$ref": "#/components/schemas/RiskScenarioType", + "description": "The type of risk scenario to create.\n- \"Risk Scenario\": Standard risk scenario (default)\n- \"Enterprise Risk\": Enterprise-level risk (requires Enterprise Risk Management SKU)\n\nEnterprise risks cannot be associated with a risk register.\nDefaults to \"Risk Scenario\" if not specified." + }, + "identificationDate": { + "type": "string", + "format": "date-time", + "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Defaults to the scenario's creation time if omitted." } }, "required": [ - "integrationId", - "resourceId", - "type" + "description" ], "type": "object", "additionalProperties": false }, - "PersonInfoSource": { - "anyOf": [ - { - "$ref": "#/components/schemas/VantaBasedPersonInfoSource" + "UpdateRiskScenarioInput": { + "properties": { + "description": { + "type": "string", + "description": "This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities.\nDocument actual issues or likely scenarios based on your specific environment or a potential vulnerability." }, - { - "$ref": "#/components/schemas/ScimBasedPersonInfoSource" + "detailedDescription": { + "type": "string", + "description": "Optional long-form description providing extended context for the risk scenario.\nMaximum 10000 characters." }, - { - "$ref": "#/components/schemas/IntegrationBasedPersonInfoSource" + "isSensitive": { + "type": "boolean", + "description": "If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions.", + "deprecated": true + }, + "likelihood": { + "type": "integer", + "format": "int32", + "description": "Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings." + }, + "impact": { + "type": "integer", + "format": "int32", + "description": "Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score.\nDefaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings." + }, + "residualLikelihood": { + "type": "integer", + "format": "int32", + "description": "Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." + }, + "residualImpact": { + "type": "integer", + "format": "int32", + "description": "Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations.\nExpressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings." + }, + "categories": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The list of categories this risk scenario belongs to.\nEach element in the list will become a new custom category if it doesn't match an existing one.\nYou can reference the current category options in the Risk Management settings and/or enter new values." + }, + "ciaCategories": { + "items": { + "$ref": "#/components/schemas/CIA" + }, + "type": "array", + "description": "Enter a list of the following for the type of risk documented:\n- Confidentiality: Risk to data stores, customer/sensitive information, etc.\n- Integrity: Risk to accuracy or integrity of system settings and/or data\n- Availability: Risk to normal service operations and critical system functionality" + }, + "treatment": { + "$ref": "#/components/schemas/Treatment", + "description": "Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are:\n- Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score.\n- Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance.\n- Avoid: Stop doing the activity which is causing the risk to your organization and its assets.\n- Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset" + }, + "owner": { + "type": "string", + "nullable": true, + "description": "The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user." + }, + "note": { + "type": "string", + "description": "Additional context about the risk scenario and why it has specific impact and likelihood scores." + }, + "riskRegister": { + "type": "string", + "description": "Name of the risk register to associate with this scenario." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomAttribute" + }, + "type": "array", + "description": "The list of custom fields.\nYou can reference custom fields in the Risk Management settings and/or create new one.\nThe format is:\n- {label: \"field-name\", value: \"string-representation\"} for text, date, number and currency fields\n- {label: \"field-name\", value: [\"option1\", \"option2\"]} for picklist fields" + }, + "type": { + "$ref": "#/components/schemas/RiskScenarioType", + "description": "Changing the risk scenario type (`\"Risk Scenario\"` vs. `\"Enterprise Risk\"`)\nis not supported via update. Requests that include this field will be\nrejected. To change a risk's type, create a new scenario with the desired\ntype and archive the old one." + }, + "identificationDate": { + "type": "string", + "format": "date-time", + "description": "The date this risk was identified. Matches the \"Identified Date\" field in the Vanta UI. Omitting the field leaves the existing value unchanged." } - ], - "description": "The source of the person's information." + }, + "type": "object", + "additionalProperties": false }, - "TasksSummaryStatus": { - "description": "The overall status of a person's outstanding tasks:\n- NONE: There are no tasks.\n- DUE_SOON: At least one task is due soon.\n- OVERDUE: At least one task is overdue. Has a higher priority than DUE_SOON.\n- COMPLETE: All tasks are complete.\n- PAUSED: All tasks are paused.\n- OFFBOARDING_DUE_SOON: At least one offboarding task is due soon.\n- OFFBOARDING_OVERDUE: At least one offboarding task is overdue. Has a higher priority than OFFBOARDING_DUE_SOON.\n- OFFBOARDING_COMPLETE: All offboarding tasks are complete.", + "SubmitRiskForApprovalInput": { + "properties": { + "comment": { + "type": "string", + "description": "Optional comment to include with the approval request." + } + }, + "type": "object", + "additionalProperties": false + }, + "RiskScenarioControlType": { + "type": "string", "enum": [ - "COMPLETE", - "DUE_SOON", - "NONE", - "OFFBOARDING_COMPLETE", - "OFFBOARDING_DUE_SOON", - "OFFBOARDING_OVERDUE", - "OVERDUE", - "PAUSED" + "EXISTING", + "TREATMENT_PLAN" + ] + }, + "RiskScenarioControl": { + "description": "A control's association with a risk scenario.\n\nThe relationship identity is `(riskScenarioId, controlId)`; `controlType`\nis mutable state on that relationship. A given control can have at most one\nassociation per risk scenario.", + "properties": { + "controlId": { + "type": "string", + "description": "The control's shorthand identifier (e.g. `\"A.12.2.1\"`) when it has one,\nfalling back to the canonical Vanta control id (Mongo object id) otherwise." + }, + "controlType": { + "$ref": "#/components/schemas/RiskScenarioControlType", + "description": "`TREATMENT_PLAN` for controls that are part of the risk's treatment plan\n(planned mitigations); `EXISTING` for controls linked to the risk without a\ntreatment-plan designation." + } + }, + "required": [ + "controlId", + "controlType" ], - "type": "string" + "type": "object", + "additionalProperties": false }, - "TaskType.COMPLETE_TRAININGS": { - "enum": [ - "COMPLETE_TRAININGS" + "PaginatedResponse_RiskScenarioControl_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/RiskScenarioControl" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" ], - "type": "string" + "type": "object", + "additionalProperties": false }, - "Training": { - "description": "A person's security training.", + "CreateRiskScenarioControlInput": { "properties": { - "name": { - "type": "string" + "controlId": { + "type": "string", + "description": "Control to associate with the risk scenario. Accepts Vanta control\nshorthands (e.g. `\"A.12.2.1\"`), custom-control shorthand names, or\nobject IDs." + }, + "controlType": { + "$ref": "#/components/schemas/RiskScenarioControlType", + "description": "`TREATMENT_PLAN` for a control that is part of the risk's treatment plan.\nOmit (or pass `\"EXISTING\"`) to associate the control without a\ntreatment-plan designation — the default \"existing control\" relationship." } }, "required": [ - "name" + "controlId" ], "type": "object", "additionalProperties": false }, - "TaskType": { - "description": "The type a task summary falls into.\nCOMPLETE_TRAININGS: The task summary containing security trainings.\nACCEPT_POLICIES: The task summary containing policy acceptance.\nCOMPLETE_CUSTOM_TASKS: The task summary containing custom tasks.\nINSTALL_DEVICE_MONITORING: The task summary containing device monitoring installation.\nCOMPLETE_BACKGROUND_CHECKS: The task summary containing background checks.", - "enum": [ - "COMPLETE_TRAININGS", - "ACCEPT_POLICIES", - "COMPLETE_CUSTOM_TASKS", - "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "INSTALL_DEVICE_MONITORING", - "COMPLETE_BACKGROUND_CHECKS" + "UpdateRiskScenarioControlInput": { + "properties": { + "controlType": { + "$ref": "#/components/schemas/RiskScenarioControlType", + "description": "The new relationship state. `TREATMENT_PLAN` moves the control into the\nrisk's treatment plan; `EXISTING` removes it from the treatment plan while\nkeeping it linked as an existing control (use DELETE to unlink entirely)." + } + }, + "required": [ + "controlType" ], - "type": "string" + "type": "object", + "additionalProperties": false }, - "TaskStatus": { - "description": "The status of a task.\n- COMPLETE: The task has been completed.\n- DUE_SOON: The task is due soon.\n- OVERDUE: The task is overdue.\n- NONE: The task is not assigned.", + "RestRiskRegisterType": { + "type": "string", "enum": [ - "COMPLETE", - "DUE_SOON", - "OVERDUE", - "NONE" - ], - "type": "string" + "SCOPED", + "ENTERPRISE" + ] }, - "CompleteTrainingsTaskSummary": { - "description": "Task summary for completing all trainings.", + "RiskRegister": { + "description": "A risk register — a grouping of risk scenarios.\n\nRisk scenarios reference their register by **name** (the `riskRegister`\nfield on `CreateRiskScenarioInput` and `RiskScenario`). Domains with\nmultiple registers must specify a register name on create.", "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.COMPLETE_TRAININGS" + "id": { + "type": "string", + "description": "The unique ID of the risk register." }, - "status": { - "$ref": "#/components/schemas/TaskStatus" + "name": { + "type": "string", + "description": "The name of the risk register. This is the value used in the\n`riskRegister` field on risk-scenario create and update requests." }, - "dueDate": { + "description": { "type": "string", - "format": "date-time", "nullable": true, - "description": "The due date of the task." + "description": "Optional description of this register." }, - "completionDate": { + "registerType": { + "$ref": "#/components/schemas/RestRiskRegisterType", + "description": "Whether this is a scoped user-managed register or the system-managed\nenterprise register." + }, + "creationDate": { "type": "string", "format": "date-time", - "nullable": true, - "description": "The date the task was completed." - }, - "disabled": { + "description": "When this risk register was created." + } + }, + "required": [ + "id", + "name", + "description", + "registerType", + "creationDate" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_RiskRegister_": { + "properties": { + "results": { "properties": { - "date": { - "type": "string", - "format": "date-time" + "data": { + "items": { + "$ref": "#/components/schemas/RiskRegister" + }, + "type": "array" }, - "reason": { - "type": "string", - "nullable": true + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" } }, "required": [ - "date", - "reason" + "data", + "pageInfo" ], - "type": "object", - "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." - }, - "incompleteTrainings": { - "items": { - "$ref": "#/components/schemas/Training" - }, - "type": "array", - "description": "Incomplete security trainings that are relevant given a person's requirements." - }, - "completedTrainings": { - "items": { - "$ref": "#/components/schemas/Training" - }, - "type": "array", - "description": "Security trainings that have been completed and are relevant given a person's current requirements." + "type": "object" } }, "required": [ - "taskType", - "status", - "dueDate", - "completionDate", - "disabled", - "incompleteTrainings", - "completedTrainings" + "results" ], "type": "object", "additionalProperties": false }, - "TaskType.ACCEPT_POLICIES": { - "enum": [ - "ACCEPT_POLICIES" - ], - "type": "string" - }, - "AcceptPoliciesTaskSummary": { - "description": "Policy acceptance details for a person.", + "ProgramScope": { "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.ACCEPT_POLICIES" - }, - "status": { - "$ref": "#/components/schemas/TaskStatus" - }, - "dueDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the task." + "id": { + "type": "string" }, - "completionDate": { + "businessUnitId": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the task was completed." + "nullable": true }, - "disabled": { + "frameworkId": { + "type": "string" + } + }, + "required": [ + "id", + "businessUnitId", + "frameworkId" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_ProgramScope_": { + "properties": { + "results": { "properties": { - "date": { - "type": "string", - "format": "date-time" + "data": { + "items": { + "$ref": "#/components/schemas/ProgramScope" + }, + "type": "array" }, - "reason": { - "type": "string", - "nullable": true + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" } }, "required": [ - "date", - "reason" + "data", + "pageInfo" ], - "type": "object", - "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." - }, - "unacceptedPolicies": { - "items": { - "properties": { - "name": { - "type": "string" - } - }, - "required": [ - "name" - ], - "type": "object" - }, - "type": "array", - "description": "Unaccepted policies that are relevant to the person." - }, - "acceptedPolicies": { - "items": { - "properties": { - "name": { - "type": "string" - } - }, - "required": [ - "name" - ], - "type": "object" - }, - "type": "array", - "description": "Accepted policies that are relevant to the person." + "type": "object" } }, "required": [ - "taskType", - "status", - "dueDate", - "completionDate", - "disabled", - "unacceptedPolicies", - "acceptedPolicies" + "results" ], "type": "object", "additionalProperties": false }, - "TaskType.COMPLETE_CUSTOM_TASKS": { + "PolicyStatus": { "enum": [ - "COMPLETE_CUSTOM_TASKS" + "OK", + "NEEDS_REMEDIATION" ], "type": "string" }, - "CustomTask": { - "description": "A custom task.", + "PolicyVersionStatus": { + "enum": [ + "NOT_STARTED", + "DRAFT", + "PENDING_APPROVAL", + "APPROVED", + "RENEW_SOON", + "EXPIRED" + ], + "type": "string" + }, + "PolicyLatestVersion": { "properties": { - "name": { - "type": "string" + "status": { + "$ref": "#/components/schemas/PolicyVersionStatus", + "description": "The status of the policy's latest version." } }, "required": [ - "name" + "status" ], "type": "object", "additionalProperties": false }, - "CompleteCustomTasksTaskSummary": { - "description": "Task summary for completing all custom tasks.", + "PolicyLocale": { + "enum": [ + "CS", + "CY", + "DA", + "DE", + "EN", + "ES", + "FI", + "FR", + "HU", + "IS", + "IT", + "JA", + "KO", + "NL", + "NO", + "NOT_SPECIFIED", + "PL", + "PT", + "ET", + "RO", + "AR", + "SK", + "SV", + "TR", + "ZH" + ], + "type": "string" + }, + "PolicyDocument": { "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.COMPLETE_CUSTOM_TASKS" - }, - "status": { - "$ref": "#/components/schemas/TaskStatus" - }, - "dueDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the task." - }, - "completionDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the task was completed." - }, - "disabled": { - "properties": { - "date": { - "type": "string", - "format": "date-time" - }, - "reason": { - "type": "string", - "nullable": true + "language": { + "allOf": [ + { + "$ref": "#/components/schemas/PolicyLocale" } - }, - "required": [ - "date", - "reason" ], - "type": "object", "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." + "description": "The language of the policy document." }, - "incompleteCustomTasks": { - "items": { - "$ref": "#/components/schemas/CustomTask" - }, - "type": "array", - "description": "Incomplete custom tasks that are relevant given a person's requirements." + "slugId": { + "type": "string", + "description": "The slug ID of the policy document." }, - "completedCustomTasks": { - "items": { - "$ref": "#/components/schemas/CustomTask" - }, - "type": "array", - "description": "Custom tasks that have been completed and are relevant given a person's current requirements." + "url": { + "type": "string", + "description": "The URL of the policy document." } }, "required": [ - "taskType", - "status", - "dueDate", - "completionDate", - "disabled", - "incompleteCustomTasks", - "completedCustomTasks" + "language", + "slugId", + "url" ], "type": "object", "additionalProperties": false }, - "TaskType.COMPLETE_CUSTOM_OFFBOARDING_TASKS": { - "enum": [ - "COMPLETE_CUSTOM_OFFBOARDING_TASKS" - ], - "type": "string" - }, - "CompleteOffboardingCustomTasksTaskSummary": { - "description": "Task summary for completing all offboarding custom tasks.", + "PolicyLatestApprovedVersion": { "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.COMPLETE_CUSTOM_OFFBOARDING_TASKS" - }, - "status": { - "$ref": "#/components/schemas/TaskStatus" - }, - "dueDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the task." - }, - "completionDate": { + "versionId": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the task was completed." - }, - "disabled": { - "properties": { - "date": { - "type": "string", - "format": "date-time" - }, - "reason": { - "type": "string", - "nullable": true - } - }, - "required": [ - "date", - "reason" - ], - "type": "object", - "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." - }, - "incompleteCustomOffboardingTasks": { - "items": { - "$ref": "#/components/schemas/CustomTask" - }, - "type": "array", - "description": "Incomplete custom tasks that are relevant given a person's requirements." + "description": "The ID of the latest approved version of the policy." }, - "completedCustomOffboardingTasks": { + "documents": { "items": { - "$ref": "#/components/schemas/CustomTask" + "$ref": "#/components/schemas/PolicyDocument" }, "type": "array", - "description": "Custom tasks that have been completed and are relevant given a person's current requirements." + "description": "Available document versions for this policy, organized by language." } }, "required": [ - "taskType", - "status", - "dueDate", - "completionDate", - "disabled", - "incompleteCustomOffboardingTasks", - "completedCustomOffboardingTasks" + "versionId", + "documents" ], "type": "object", "additionalProperties": false }, - "TaskType.INSTALL_DEVICE_MONITORING": { - "enum": [ - "INSTALL_DEVICE_MONITORING" - ], - "type": "string" - }, - "InstallDeviceMonitoringTaskSummary": { - "description": "Task summary for installing device monitoring.", + "Policy": { "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.INSTALL_DEVICE_MONITORING" + "id": { + "type": "string", + "description": "The policy's unique ID." }, - "status": { - "$ref": "#/components/schemas/TaskStatus" + "name": { + "type": "string", + "description": "The policy's name." }, - "dueDate": { + "description": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the task." + "description": "The policy's description." }, - "completionDate": { + "status": { + "$ref": "#/components/schemas/PolicyStatus", + "description": "The policy's current status." + }, + "approvedAtDate": { "type": "string", "format": "date-time", "nullable": true, - "description": "The date the task was completed." + "description": "The policy's most recent date of approval, if applicable." }, - "disabled": { - "properties": { - "date": { - "type": "string", - "format": "date-time" - }, - "reason": { - "type": "string", - "nullable": true + "latestVersion": { + "$ref": "#/components/schemas/PolicyLatestVersion", + "description": "The latest version of the policy." + }, + "latestApprovedVersion": { + "allOf": [ + { + "$ref": "#/components/schemas/PolicyLatestApprovedVersion" } - }, - "required": [ - "date", - "reason" ], - "type": "object", "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." + "description": "The latest approved version of the policy, if available." } }, "required": [ - "taskType", + "id", + "name", + "description", "status", - "dueDate", - "completionDate", - "disabled" + "approvedAtDate", + "latestVersion", + "latestApprovedVersion" ], "type": "object", "additionalProperties": false }, - "TaskType.COMPLETE_BACKGROUND_CHECKS": { - "enum": [ - "COMPLETE_BACKGROUND_CHECKS" - ], - "type": "string" - }, - "CompleteBackgroundChecksTaskSummary": { - "description": "Task summary for completing background checks.", + "PaginatedResponse_Policy_": { "properties": { - "taskType": { - "$ref": "#/components/schemas/TaskType.COMPLETE_BACKGROUND_CHECKS" - }, - "status": { - "$ref": "#/components/schemas/TaskStatus" - }, - "dueDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the task." - }, - "completionDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the task was completed." - }, - "disabled": { + "results": { "properties": { - "date": { - "type": "string", - "format": "date-time" + "data": { + "items": { + "$ref": "#/components/schemas/Policy" + }, + "type": "array" }, - "reason": { - "type": "string", - "nullable": true + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" } }, "required": [ - "date", - "reason" + "data", + "pageInfo" ], - "type": "object", - "nullable": true, - "description": "If the task is disabled, the reason and date when it was disabled." + "type": "object" } }, "required": [ - "taskType", - "status", - "dueDate", - "completionDate", - "disabled" + "results" ], "type": "object", "additionalProperties": false }, - "TaskSummaryDetails": { - "description": "All detailed information about a person's tasks, split across task categories.", + "NotificationFrequency.DAILY": { + "enum": [ + "DAILY" + ], + "type": "string" + }, + "NotificationFrequency.WEEKLY": { + "enum": [ + "WEEKLY" + ], + "type": "string" + }, + "NotificationChannelType": { + "enum": [ + "EMAIL", + "SLACK" + ], + "type": "string" + }, + "EnabledPersonnelNotificationSettings": { "properties": { - "completeTrainings": { - "$ref": "#/components/schemas/CompleteTrainingsTaskSummary" - }, - "acceptPolicies": { - "$ref": "#/components/schemas/AcceptPoliciesTaskSummary" - }, - "completeCustomTasks": { - "$ref": "#/components/schemas/CompleteCustomTasksTaskSummary" + "enabled": { + "type": "boolean", + "enum": [ + true + ], + "nullable": false }, - "completeOffboardingCustomTasks": { - "$ref": "#/components/schemas/CompleteOffboardingCustomTasksTaskSummary" + "employeeDigestFrequency": { + "anyOf": [ + { + "$ref": "#/components/schemas/NotificationFrequency.DAILY" + }, + { + "$ref": "#/components/schemas/NotificationFrequency.WEEKLY" + } + ] }, - "installDeviceMonitoring": { - "$ref": "#/components/schemas/InstallDeviceMonitoringTaskSummary" + "enabledChannels": { + "items": { + "$ref": "#/components/schemas/NotificationChannelType" + }, + "type": "array" }, - "completeBackgroundChecks": { - "$ref": "#/components/schemas/CompleteBackgroundChecksTaskSummary" + "nextReminderAt": { + "type": "string", + "format": "date-time" } }, "required": [ - "completeTrainings", - "acceptPolicies", - "completeCustomTasks", - "completeOffboardingCustomTasks", - "installDeviceMonitoring", - "completeBackgroundChecks" + "enabled", + "employeeDigestFrequency", + "enabledChannels", + "nextReminderAt" ], "type": "object", "additionalProperties": false }, - "Person": { + "DisabledPersonnelNotificationSettings": { "properties": { - "id": { - "type": "string" + "enabled": { + "type": "boolean", + "enum": [ + false + ], + "nullable": false + } + }, + "required": [ + "enabled" + ], + "type": "object", + "additionalProperties": false + }, + "PersonnelNotificationSettings": { + "anyOf": [ + { + "$ref": "#/components/schemas/EnabledPersonnelNotificationSettings" }, - "userId": { - "type": "string", - "nullable": true, - "description": "The ID of the Vanta user account associated with this person, if one exists." - }, - "emailAddress": { - "type": "string" - }, - "employment": { - "properties": { - "status": { - "$ref": "#/components/schemas/EmploymentStatus", - "description": "The person's employment status." - }, - "startDate": { - "type": "string", - "format": "date-time", - "description": "The date the person's employment started." - }, - "jobTitle": { - "type": "string", - "nullable": true, - "description": "The person's job title." - }, - "endDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "If present, the date the person's employment ended." - } - }, - "required": [ - "status", - "startDate", - "jobTitle", - "endDate" - ], - "type": "object" - }, - "leaveInfo": { - "allOf": [ - { - "$ref": "#/components/schemas/LeaveInfo" - } - ], - "nullable": true, - "description": "If present, the user's active/upcoming leave. Empty if the user has no active/upcoming leave." + { + "$ref": "#/components/schemas/DisabledPersonnelNotificationSettings" + } + ] + }, + "NotificationFrequency": { + "enum": [ + "DAILY", + "NEVER", + "WEEKLY" + ], + "type": "string" + }, + "UpdatePersonnelNotificationSettingsInput": { + "properties": { + "frequency": { + "$ref": "#/components/schemas/NotificationFrequency", + "description": "Omit to preserve the current frequency. NEVER disables reminders." }, - "groupIds": { + "channels": { "items": { - "type": "string" + "$ref": "#/components/schemas/NotificationChannelType" }, "type": "array", - "description": "The id of each group the user belongs to. This includes both manually created groups in Vanta and groups imported from an identity provider." - }, - "name": { - "properties": { - "first": { - "type": "string", - "nullable": true, - "description": "The person's first (given) name." - }, - "last": { - "type": "string", - "nullable": true, - "description": "The person's last (family) name." - }, - "display": { - "type": "string", - "description": "The person's display name, used in Vanta." - } - }, - "required": [ - "first", - "last", - "display" - ], - "type": "object" - }, - "sources": { - "properties": { - "employment": { - "properties": { - "endDate": { - "$ref": "#/components/schemas/PersonInfoSource", - "description": "The source of the person's employment end date." - }, - "startDate": { - "$ref": "#/components/schemas/PersonInfoSource", - "description": "The source of the person's employment start date." - } - }, - "required": [ - "endDate", - "startDate" - ], - "type": "object" - }, - "emailAddress": { - "$ref": "#/components/schemas/PersonInfoSource", - "description": "The source of the person's email address." - } - }, - "required": [ - "employment", - "emailAddress" - ], - "type": "object", - "description": "The sources of the person's information." - }, - "tasksSummary": { - "properties": { - "details": { - "$ref": "#/components/schemas/TaskSummaryDetails" - }, - "status": { - "$ref": "#/components/schemas/TasksSummaryStatus", - "description": "The status of the person's tasks summary." - }, - "dueDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The due date of the person's earliest-due task." - }, - "completionDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date when person's tasks were completed." - } - }, - "required": [ - "details", - "status", - "dueDate", - "completionDate" - ], - "type": "object", - "description": "The person's tasks summary, which aggregates their current status across\nall of their relevant tasks." + "description": "Replaces the complete channel set. Omit to preserve it; an empty array disables reminders." } }, - "required": [ - "id", - "userId", - "emailAddress", - "employment", - "leaveInfo", - "groupIds", - "name", - "sources", - "tasksSummary" - ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Person_": { + "EmploymentStatus": { + "description": "The employment status of a person:\n- UPCOMING: The person is not yet employed and will start employment in the future.\n- CURRENT: The person is currently employed.\n- ON_LEAVE: The person is on leave.\n- INACTIVE: The person's employment is inactive.\n- FORMER: The person was previously employed.", + "enum": [ + "UPCOMING", + "CURRENT", + "ON_LEAVE", + "INACTIVE", + "FORMER" + ], + "type": "string" + }, + "LeaveStatus": { + "description": "User can be active or upcoming leave period", + "enum": [ + "ACTIVE", + "UPCOMING" + ], + "type": "string" + }, + "LeaveInfo": { "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Person" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "startDate": { + "type": "string", + "format": "date-time", + "description": "The start of the person's leave." + }, + "endDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The end of the person's leave. Null endDate implies indefinite leave." + }, + "status": { + "$ref": "#/components/schemas/LeaveStatus", + "description": "ACTIVE if the leave is currently ongoing. UPCOMING if the startDate is in the future." } }, "required": [ - "results" + "startDate", + "endDate", + "status" ], "type": "object", "additionalProperties": false }, - "ComputerStatusOutcome": { - "description": "The possible outcomes of a status check. The outcome can be one of the following:\nFAIL: The check is failing.\nIN_PROGRESS: The check needs further data from the given computer in order to evaluate. The field(s) needed from a computer to calculate the ComputerStatusOutcome were null.\nNA: The check is not applicable for the given computer.\nPASS: The check is passing.", + "PersonInfoSourceType.VANTA": { "enum": [ - "FAIL", - "IN_PROGRESS", - "NA", - "PASS" + "VANTA" ], "type": "string" }, - "ComputerStatus": { - "description": "The a status check for a computer. Representation for screenlock, diskEncryption, passwordManager, and antivirusInstallation.", + "VantaBasedPersonInfoSource": { + "description": "The person's information comes from what is set in Vanta.", "properties": { - "outcome": { - "$ref": "#/components/schemas/ComputerStatusOutcome", - "description": "The outcome of the status check." + "type": { + "$ref": "#/components/schemas/PersonInfoSourceType.VANTA" } }, "required": [ - "outcome" + "type" ], "type": "object", "additionalProperties": false }, - "OperatingSystemType": { - "description": "The possible types of the operating system. One of `mac_OS`, `linux`, or `windows`.", + "PersonInfoSourceType.SCIM": { "enum": [ - "macOS", - "linux", - "windows" + "SCIM" ], "type": "string" }, - "OperatingSystem": { - "description": "The computer's operating system type and version.", + "ScimBasedPersonInfoSource": { + "description": "The person's information comes from SCIM.", "properties": { "type": { - "$ref": "#/components/schemas/OperatingSystemType", - "description": "The type of the operating system." - }, - "version": { - "type": "string", - "nullable": true, - "description": "The version of the operating system." + "$ref": "#/components/schemas/PersonInfoSourceType.SCIM" } }, "required": [ - "type", - "version" + "type" ], "type": "object", "additionalProperties": false }, - "MonitoredComputer": { - "properties": { - "id": { - "type": "string", - "description": "Unique identifier for the monitored computer." - }, + "PersonInfoSourceType.INTEGRATION": { + "enum": [ + "INTEGRATION" + ], + "type": "string" + }, + "IntegrationBasedPersonInfoSource": { + "description": "The person's information comes from an integration.", + "properties": { "integrationId": { - "type": "string", - "description": "Hard-coded enums for Vanta-built integrations or application IDs for 3rd-party-built integrations." - }, - "lastCheckDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "Date of the computer's most recent report." - }, - "screenlock": { - "$ref": "#/components/schemas/ComputerStatus", - "description": "Whether or not the computer has screenlock enabled." - }, - "diskEncryption": { - "$ref": "#/components/schemas/ComputerStatus", - "description": "Whether or not the computer's hard drive is encrypted." - }, - "passwordManager": { - "$ref": "#/components/schemas/ComputerStatus", - "description": "Whether or not the computer has a password manager installed." - }, - "antivirusInstallation": { - "$ref": "#/components/schemas/ComputerStatus", - "description": "Whether or not the computer has antivirus software installed." - }, - "operatingSystem": { - "allOf": [ - { - "$ref": "#/components/schemas/OperatingSystem" - } - ], - "nullable": true, - "description": "The computer's operating system name and version." - }, - "owner": { - "allOf": [ - { - "$ref": "#/components/schemas/Owner" - } - ], - "nullable": true, - "description": "The name, unique identifier, and email address of the computer's owner." + "type": "string" }, - "serialNumber": { + "resourceId": { "type": "string", - "nullable": true, - "description": "The serial number of the computer. This value may be null if it is not reported by the device." + "nullable": true }, - "udid": { - "type": "string", - "nullable": true, - "description": "The universal device id of the computer." + "type": { + "$ref": "#/components/schemas/PersonInfoSourceType.INTEGRATION" } }, "required": [ - "id", "integrationId", - "lastCheckDate", - "screenlock", - "diskEncryption", - "passwordManager", - "antivirusInstallation", - "operatingSystem", - "owner", - "serialNumber", - "udid" + "resourceId", + "type" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_MonitoredComputer_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/MonitoredComputer" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "PersonInfoSource": { + "anyOf": [ + { + "$ref": "#/components/schemas/VantaBasedPersonInfoSource" + }, + { + "$ref": "#/components/schemas/ScimBasedPersonInfoSource" + }, + { + "$ref": "#/components/schemas/IntegrationBasedPersonInfoSource" } - }, - "required": [ - "results" ], - "type": "object", - "additionalProperties": false + "description": "The source of the person's information." }, - "ComputerStatusFilter": { - "description": "Enum representing computer compliance statuses that can be utilized as a filter. The meanings are as follows:\nAV_NOT_INSTALLED: The computer does not have antivirus software installed.\nHD_NOT_ENCRYPTED: The computer's harddrive is not encrypted.\nLAST_CHECK_OVER_14_DAYS: No data has been received from computer for over 14 days.\nPWM_NOT_INSTALLED: The computer does not have a password manager installed.\nSCREENLOCK_NOT_CONFIGURED: The computer does not have screenlock configured appropriately.", + "TasksSummaryStatus": { + "description": "The overall status of a person's outstanding tasks:\n- NONE: There are no tasks.\n- DUE_SOON: At least one task is due soon.\n- OVERDUE: At least one task is overdue. Has a higher priority than DUE_SOON.\n- COMPLETE: All tasks are complete.\n- PAUSED: All tasks are paused.\n- OFFBOARDING_DUE_SOON: At least one offboarding task is due soon.\n- OFFBOARDING_OVERDUE: At least one offboarding task is overdue. Has a higher priority than OFFBOARDING_DUE_SOON.\n- OFFBOARDING_COMPLETE: All offboarding tasks are complete.", "enum": [ - "PWM_NOT_INSTALLED", - "HD_NOT_ENCRYPTED", - "AV_NOT_INSTALLED", - "SCREENLOCK_NOT_CONFIGURED", - "LAST_CHECK_OVER_14_DAYS" + "COMPLETE", + "DUE_SOON", + "NONE", + "OFFBOARDING_COMPLETE", + "OFFBOARDING_DUE_SOON", + "OFFBOARDING_OVERDUE", + "OVERDUE", + "PAUSED" ], "type": "string" }, - "KnowledgeBaseResourceActorAssignment": { + "TaskType.COMPLETE_TRAININGS": { + "enum": [ + "COMPLETE_TRAININGS" + ], + "type": "string" + }, + "Training": { + "description": "A person's security training.", "properties": { - "type": { - "type": "string", - "enum": [ - "User", - "Team" - ] - }, - "id": { + "name": { "type": "string" - }, - "displayName": { - "type": "string", - "nullable": true } }, "required": [ - "type", - "id", - "displayName" + "name" ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseExpirationStatus": { - "type": "string", + "TaskType": { + "description": "The type a task summary falls into.\nCOMPLETE_TRAININGS: The task summary containing security trainings.\nACCEPT_POLICIES: The task summary containing policy acceptance.\nCOMPLETE_CUSTOM_TASKS: The task summary containing custom tasks.\nINSTALL_DEVICE_MONITORING: The task summary containing device monitoring installation.\nCOMPLETE_BACKGROUND_CHECKS: The task summary containing background checks.", "enum": [ - "CURRENT", - "EXPIRED" + "COMPLETE_TRAININGS", + "ACCEPT_POLICIES", + "COMPLETE_CUSTOM_TASKS", + "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "INSTALL_DEVICE_MONITORING", + "COMPLETE_BACKGROUND_CHECKS" ], - "description": "Customer-facing expiration status used by knowledge-base API responses\n(answer library entries and resources). Derived from the persisted\n`expiresAt` field at read time." + "type": "string" }, - "TagInput": { - "properties": { - "categoryId": { - "type": "string" - }, - "tagId": { - "type": "string" - } - }, - "required": [ - "categoryId", - "tagId" + "TaskStatus": { + "description": "The status of a task.\n- COMPLETE: The task has been completed.\n- DUE_SOON: The task is due soon.\n- OVERDUE: The task is overdue.\n- NONE: The task is not assigned.", + "enum": [ + "COMPLETE", + "DUE_SOON", + "OVERDUE", + "NONE" ], - "type": "object", - "additionalProperties": false + "type": "string" }, - "KnowledgeBaseWebpageResourceOutput": { + "CompleteTrainingsTaskSummary": { + "description": "Task summary for completing all trainings.", "properties": { - "id": { - "type": "string" - }, - "type": { - "type": "string", - "enum": [ - "URL" - ], - "nullable": false + "taskType": { + "$ref": "#/components/schemas/TaskType.COMPLETE_TRAININGS" }, - "title": { - "type": "string" + "status": { + "$ref": "#/components/schemas/TaskStatus" }, - "description": { + "dueDate": { "type": "string", - "nullable": true - }, - "url": { - "type": "string" + "format": "date-time", + "nullable": true, + "description": "The due date of the task." }, - "customerVisibility": { + "completionDate": { "type": "string", - "enum": [ - "PRIVATE", - "SHAREABLE", - "REQUEST_ACCESS", - "PUBLIC", - null - ], - "nullable": true - }, - "includeSubPages": { - "type": "boolean", - "nullable": true - }, - "isUsedInQuestionnaires": { - "type": "boolean", - "nullable": true + "format": "date-time", + "nullable": true, + "description": "The date the task was completed." }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignment" + "disabled": { + "properties": { + "date": { + "type": "string", + "format": "date-time" + }, + "reason": { + "type": "string", + "nullable": true } + }, + "required": [ + "date", + "reason" ], - "nullable": true - }, - "expirationStatus": { - "$ref": "#/components/schemas/KnowledgeBaseExpirationStatus" - }, - "expirationDate": { - "type": "string", - "nullable": true - }, - "lastUpdated": { - "type": "string" - }, - "lastVerified": { - "type": "string", - "nullable": true + "type": "object", + "nullable": true, + "description": "If the task is disabled, the reason and date when it was disabled." }, - "tags": { + "incompleteTrainings": { "items": { - "$ref": "#/components/schemas/TagInput" + "$ref": "#/components/schemas/Training" }, - "type": "array" + "type": "array", + "description": "Incomplete security trainings that are relevant given a person's requirements." }, - "categoryId": { - "type": "string", - "nullable": true, - "description": "Trust Center category id the resource is currently filed under, or\n`null` if uncategorized (or not on the Trust Center, which is the case\nfor `PRIVATE` / `SHAREABLE` resources)." + "completedTrainings": { + "items": { + "$ref": "#/components/schemas/Training" + }, + "type": "array", + "description": "Security trainings that have been completed and are relevant given a person's current requirements." } }, "required": [ - "id", - "type", - "title", - "description", - "url", - "customerVisibility", - "includeSubPages", - "isUsedInQuestionnaires", - "ownerAssignment", - "expirationStatus", - "expirationDate", - "lastUpdated", - "lastVerified", - "tags", - "categoryId" + "taskType", + "status", + "dueDate", + "completionDate", + "disabled", + "incompleteTrainings", + "completedTrainings" ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseResourceActorAssignmentInput": { + "TaskType.ACCEPT_POLICIES": { + "enum": [ + "ACCEPT_POLICIES" + ], + "type": "string" + }, + "AcceptPoliciesTaskSummary": { + "description": "Policy acceptance details for a person.", "properties": { - "type": { + "taskType": { + "$ref": "#/components/schemas/TaskType.ACCEPT_POLICIES" + }, + "status": { + "$ref": "#/components/schemas/TaskStatus" + }, + "dueDate": { "type": "string", - "enum": [ - "User" - ], - "nullable": false, - "description": "The type of actor. Currently only \"User\" is supported." + "format": "date-time", + "nullable": true, + "description": "The due date of the task." }, - "id": { + "completionDate": { "type": "string", - "description": "The unique identifier of the user." + "format": "date-time", + "nullable": true, + "description": "The date the task was completed." + }, + "disabled": { + "properties": { + "date": { + "type": "string", + "format": "date-time" + }, + "reason": { + "type": "string", + "nullable": true + } + }, + "required": [ + "date", + "reason" + ], + "type": "object", + "nullable": true, + "description": "If the task is disabled, the reason and date when it was disabled." + }, + "unacceptedPolicies": { + "items": { + "properties": { + "name": { + "type": "string" + } + }, + "required": [ + "name" + ], + "type": "object" + }, + "type": "array", + "description": "Unaccepted policies that are relevant to the person." + }, + "acceptedPolicies": { + "items": { + "properties": { + "name": { + "type": "string" + } + }, + "required": [ + "name" + ], + "type": "object" + }, + "type": "array", + "description": "Accepted policies that are relevant to the person." } }, "required": [ - "type", - "id" + "taskType", + "status", + "dueDate", + "completionDate", + "disabled", + "unacceptedPolicies", + "acceptedPolicies" ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseCustomerVisibility": { - "type": "string", + "TaskType.COMPLETE_CUSTOM_TASKS": { "enum": [ - "PRIVATE", - "SHAREABLE", - "REQUEST_ACCESS", - "PUBLIC" + "COMPLETE_CUSTOM_TASKS" ], - "description": "Customer-facing visibility of a knowledge-base resource on the\nTrust Center. Use {@link CUSTOMER_VISIBILITY_TO_DB} to translate to\n{@link TrustCenterResourceVisibility} when persisting." + "type": "string" }, - "CreateWebpageResourceInput": { + "CustomTask": { + "description": "A custom task.", "properties": { - "title": { - "type": "string", - "description": "The title of the webpage resource.", - "minLength": 1 - }, - "url": { - "type": "string", - "description": "The URL of the webpage.", - "format": "uri" - }, - "description": { - "type": "string", - "description": "A description for the webpage resource." - }, - "ownerAssignment": { - "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput", - "description": "The actor to assign as owner. Currently only type \"User\" is supported." - }, - "customerVisibility": { - "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", - "description": "Customer visibility on the Trust Center." - }, - "includeSubPages": { - "type": "boolean", - "description": "Whether to scan sub-pages one level deep alongside the primary URL." - }, - "isUsedInQuestionnaires": { - "type": "boolean", - "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." - }, - "expirationDate": { - "type": "string", - "description": "Expiration date in ISO 8601 format." - }, - "tags": { - "items": { - "$ref": "#/components/schemas/TagInput" - }, - "type": "array", - "description": "Tags to associate with the resource." - }, - "categoryId": { - "type": "string", - "nullable": true, - "description": "Trust Center category id to associate this resource with. Pass `null`\nto keep the resource uncategorized. Only valid when `customerVisibility`\nis REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return\nan InvalidInputError." + "name": { + "type": "string" } }, "required": [ - "title", - "url" + "name" ], "type": "object", "additionalProperties": false }, - "UpdateWebpageResourceInput": { + "CompleteCustomTasksTaskSummary": { + "description": "Task summary for completing all custom tasks.", "properties": { - "title": { + "taskType": { + "$ref": "#/components/schemas/TaskType.COMPLETE_CUSTOM_TASKS" + }, + "status": { + "$ref": "#/components/schemas/TaskStatus" + }, + "dueDate": { "type": "string", - "description": "The title of the webpage resource.", - "minLength": 1 + "format": "date-time", + "nullable": true, + "description": "The due date of the task." }, - "description": { + "completionDate": { "type": "string", + "format": "date-time", "nullable": true, - "description": "A description for the webpage resource. Pass `null` to clear." + "description": "The date the task was completed." }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput" + "disabled": { + "properties": { + "date": { + "type": "string", + "format": "date-time" + }, + "reason": { + "type": "string", + "nullable": true } + }, + "required": [ + "date", + "reason" ], + "type": "object", "nullable": true, - "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." - }, - "customerVisibility": { - "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", - "description": "Customer visibility on the Trust Center." + "description": "If the task is disabled, the reason and date when it was disabled." }, - "includeSubPages": { - "type": "boolean", - "description": "Whether to scan sub-pages one level deep alongside the primary URL." - }, - "isUsedInQuestionnaires": { - "type": "boolean", - "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." - }, - "expirationDate": { - "type": "string", - "nullable": true, - "description": "Expiration date in ISO 8601 format. Pass `null` to clear." - }, - "tags": { + "incompleteCustomTasks": { "items": { - "$ref": "#/components/schemas/TagInput" + "$ref": "#/components/schemas/CustomTask" }, "type": "array", - "description": "Tags to associate with the resource. A non-empty array replaces the\nexisting tag set; pass `[]` to clear all tags." + "description": "Incomplete custom tasks that are relevant given a person's requirements." }, - "categoryId": { - "type": "string", - "nullable": true, - "description": "Trust Center category id to associate this resource with. Pass `null`\nto move the resource to uncategorized. Only valid when the resource's\neffective visibility (after applying any patched `customerVisibility`)\nis REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return\nan InvalidInputError." + "completedCustomTasks": { + "items": { + "$ref": "#/components/schemas/CustomTask" + }, + "type": "array", + "description": "Custom tasks that have been completed and are relevant given a person's current requirements." } }, + "required": [ + "taskType", + "status", + "dueDate", + "completionDate", + "disabled", + "incompleteCustomTasks", + "completedCustomTasks" + ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseDocumentResourceOutput": { + "TaskType.COMPLETE_CUSTOM_OFFBOARDING_TASKS": { + "enum": [ + "COMPLETE_CUSTOM_OFFBOARDING_TASKS" + ], + "type": "string" + }, + "CompleteOffboardingCustomTasksTaskSummary": { + "description": "Task summary for completing all offboarding custom tasks.", "properties": { - "id": { - "type": "string" - }, - "type": { - "type": "string", - "enum": [ - "FILE" - ], - "nullable": false - }, - "title": { - "type": "string" - }, - "description": { - "type": "string", - "nullable": true + "taskType": { + "$ref": "#/components/schemas/TaskType.COMPLETE_CUSTOM_OFFBOARDING_TASKS" }, - "fileUrl": { - "type": "string", - "description": "Presigned S3 URL for the underlying document. Expires after 1 hour due\nto AWS IAM Role limitations on presigned URL lifetimes. Re-fetch the\nresource to obtain a fresh URL once this one expires." + "status": { + "$ref": "#/components/schemas/TaskStatus" }, - "customerVisibility": { + "dueDate": { "type": "string", - "enum": [ - "PRIVATE", - "SHAREABLE", - "REQUEST_ACCESS", - "PUBLIC", - null - ], - "nullable": true + "format": "date-time", + "nullable": true, + "description": "The due date of the task." }, - "downloadPermission": { + "completionDate": { "type": "string", - "enum": [ - "VIEW_ONLY", - "VIEW_AND_DOWNLOAD", - null - ], - "nullable": true - }, - "isUsedInQuestionnaires": { - "type": "boolean", - "nullable": true + "format": "date-time", + "nullable": true, + "description": "The date the task was completed." }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignment" + "disabled": { + "properties": { + "date": { + "type": "string", + "format": "date-time" + }, + "reason": { + "type": "string", + "nullable": true } + }, + "required": [ + "date", + "reason" ], - "nullable": true - }, - "expirationStatus": { - "$ref": "#/components/schemas/KnowledgeBaseExpirationStatus" - }, - "expirationDate": { - "type": "string", - "nullable": true - }, - "lastUpdated": { - "type": "string" - }, - "lastVerified": { - "type": "string", - "nullable": true + "type": "object", + "nullable": true, + "description": "If the task is disabled, the reason and date when it was disabled." }, - "tags": { + "incompleteCustomOffboardingTasks": { "items": { - "$ref": "#/components/schemas/TagInput" + "$ref": "#/components/schemas/CustomTask" }, - "type": "array" + "type": "array", + "description": "Incomplete custom tasks that are relevant given a person's requirements." }, - "categoryId": { - "type": "string", - "nullable": true, - "description": "Trust Center category id the resource is currently filed under, or\n`null` if uncategorized (or not on the Trust Center, which is the case\nfor `PRIVATE` / `SHAREABLE` resources)." + "completedCustomOffboardingTasks": { + "items": { + "$ref": "#/components/schemas/CustomTask" + }, + "type": "array", + "description": "Custom tasks that have been completed and are relevant given a person's current requirements." } }, "required": [ - "id", - "type", - "title", - "description", - "fileUrl", - "customerVisibility", - "downloadPermission", - "isUsedInQuestionnaires", - "ownerAssignment", - "expirationStatus", - "expirationDate", - "lastUpdated", - "lastVerified", - "tags", - "categoryId" + "taskType", + "status", + "dueDate", + "completionDate", + "disabled", + "incompleteCustomOffboardingTasks", + "completedCustomOffboardingTasks" ], "type": "object", "additionalProperties": false }, - "TrustKnowledgeBaseResourceOutput": { - "anyOf": [ - { - "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" - }, - { - "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" - } + "TaskType.INSTALL_DEVICE_MONITORING": { + "enum": [ + "INSTALL_DEVICE_MONITORING" ], - "description": "Discriminated union over `type` of all resource kinds in the Trust\nKnowledge Base (currently FILE and URL)." + "type": "string" }, - "PaginatedResponse_TrustKnowledgeBaseResourceOutput_": { + "InstallDeviceMonitoringTaskSummary": { + "description": "Task summary for installing device monitoring.", "properties": { - "results": { + "taskType": { + "$ref": "#/components/schemas/TaskType.INSTALL_DEVICE_MONITORING" + }, + "status": { + "$ref": "#/components/schemas/TaskStatus" + }, + "dueDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The due date of the task." + }, + "completionDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date the task was completed." + }, + "disabled": { "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" - }, - "type": "array" + "date": { + "type": "string", + "format": "date-time" }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" + "reason": { + "type": "string", + "nullable": true } }, "required": [ - "data", - "pageInfo" + "date", + "reason" ], - "type": "object" + "type": "object", + "nullable": true, + "description": "If the task is disabled, the reason and date when it was disabled." } }, "required": [ - "results" + "taskType", + "status", + "dueDate", + "completionDate", + "disabled" ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseResourceTypeFilter": { - "type": "string", + "TaskType.COMPLETE_BACKGROUND_CHECKS": { "enum": [ - "FILE", - "URL" - ] + "COMPLETE_BACKGROUND_CHECKS" + ], + "type": "string" }, - "VerifyKnowledgeBaseResourceInput": { + "CompleteBackgroundChecksTaskSummary": { + "description": "Task summary for completing background checks.", "properties": { - "expirationDate": { + "taskType": { + "$ref": "#/components/schemas/TaskType.COMPLETE_BACKGROUND_CHECKS" + }, + "status": { + "$ref": "#/components/schemas/TaskStatus" + }, + "dueDate": { "type": "string", - "description": "The expiration date in ISO 8601 format. If omitted, falls back to the\nconfigured review cadence.", - "example": "2025-12-31T00:00:00.000Z" - } - }, - "type": "object", - "additionalProperties": false - }, - "KnowledgeBaseResourceDownloadPermission": { - "type": "string", - "enum": [ - "VIEW_ONLY", - "VIEW_AND_DOWNLOAD" - ], - "description": "Customer-facing download permission for a knowledge-base resource on\nthe Trust Center. Use {@link DOWNLOAD_PERMISSION_TO_DB} to translate\nto {@link TrustKnowledgeBaseResourceDownloadSetting} when persisting." - }, - "UpdateDocumentResourceInput": { - "properties": { - "title": { - "type": "string", - "description": "The title of the document resource.", - "minLength": 1 - }, - "description": { - "type": "string", - "nullable": true, - "description": "A description for the document resource. Pass `null` to clear." - }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput" - } - ], + "format": "date-time", "nullable": true, - "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." - }, - "customerVisibility": { - "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", - "description": "Customer visibility on the Trust Center." - }, - "downloadPermission": { - "$ref": "#/components/schemas/KnowledgeBaseResourceDownloadPermission", - "description": "Trust Center download permission." - }, - "isUsedInQuestionnaires": { - "type": "boolean", - "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." + "description": "The due date of the task." }, - "expirationDate": { + "completionDate": { "type": "string", + "format": "date-time", "nullable": true, - "description": "Expiration date in ISO 8601 format. Pass `null` to clear." + "description": "The date the task was completed." }, - "tags": { - "items": { - "$ref": "#/components/schemas/TagInput" + "disabled": { + "properties": { + "date": { + "type": "string", + "format": "date-time" + }, + "reason": { + "type": "string", + "nullable": true + } }, - "type": "array", - "description": "Tags to associate with the resource. A non-empty array replaces the\nexisting tag set; pass `[]` to clear all tags." - }, - "categoryId": { - "type": "string", + "required": [ + "date", + "reason" + ], + "type": "object", "nullable": true, - "description": "Trust Center category id to associate this resource with. Pass `null`\nto move the resource to uncategorized. Only valid when the resource's\neffective visibility (after applying any patched `customerVisibility`)\nis REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return\nan InvalidInputError." + "description": "If the task is disabled, the reason and date when it was disabled." } }, + "required": [ + "taskType", + "status", + "dueDate", + "completionDate", + "disabled" + ], "type": "object", "additionalProperties": false }, - "AnswerLibraryActorAssignment": { + "TaskSummaryDetails": { + "description": "All detailed information about a person's tasks, split across task categories.", "properties": { - "type": { - "type": "string", - "enum": [ - "User", - "Team" - ] + "completeTrainings": { + "$ref": "#/components/schemas/CompleteTrainingsTaskSummary" }, - "id": { - "type": "string" + "acceptPolicies": { + "$ref": "#/components/schemas/AcceptPoliciesTaskSummary" }, - "displayName": { - "type": "string", - "nullable": true + "completeCustomTasks": { + "$ref": "#/components/schemas/CompleteCustomTasksTaskSummary" + }, + "completeOffboardingCustomTasks": { + "$ref": "#/components/schemas/CompleteOffboardingCustomTasksTaskSummary" + }, + "installDeviceMonitoring": { + "$ref": "#/components/schemas/InstallDeviceMonitoringTaskSummary" + }, + "completeBackgroundChecks": { + "$ref": "#/components/schemas/CompleteBackgroundChecksTaskSummary" } }, "required": [ - "type", - "id", - "displayName" + "completeTrainings", + "acceptPolicies", + "completeCustomTasks", + "completeOffboardingCustomTasks", + "installDeviceMonitoring", + "completeBackgroundChecks" ], "type": "object", "additionalProperties": false }, - "KnowledgeBaseAnswerLibraryEntryOutput": { + "Person": { "properties": { "id": { "type": "string" }, - "question": { - "type": "string" + "userId": { + "type": "string", + "nullable": true, + "description": "The ID of the Vanta user account associated with this person, if one exists." }, - "answer": { + "emailAddress": { "type": "string" }, - "expirationStatus": { - "type": "string", - "enum": [ - "CURRENT", - "EXPIRED" - ] + "employment": { + "properties": { + "status": { + "$ref": "#/components/schemas/EmploymentStatus", + "description": "The person's employment status." + }, + "startDate": { + "type": "string", + "format": "date-time", + "description": "The date the person's employment started." + }, + "jobTitle": { + "type": "string", + "nullable": true, + "description": "The person's job title." + }, + "endDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "If present, the date the person's employment ended." + } + }, + "required": [ + "status", + "startDate", + "jobTitle", + "endDate" + ], + "type": "object" }, - "ownerAssignment": { + "leaveInfo": { "allOf": [ { - "$ref": "#/components/schemas/AnswerLibraryActorAssignment" + "$ref": "#/components/schemas/LeaveInfo" } ], - "nullable": true - }, - "expirationDate": { - "type": "string", - "nullable": true - }, - "lastUpdated": { - "type": "string" - }, - "lastVerified": { - "type": "string", - "nullable": true + "nullable": true, + "description": "If present, the user's active/upcoming leave. Empty if the user has no active/upcoming leave." }, - "tags": { + "groupIds": { "items": { - "$ref": "#/components/schemas/TagInput" + "type": "string" }, - "type": "array" - } - }, - "required": [ - "id", - "question", - "answer", - "expirationStatus", - "ownerAssignment", - "expirationDate", - "lastUpdated", - "lastVerified", - "tags" - ], - "type": "object", - "additionalProperties": false - }, - "PaginatedResponse_KnowledgeBaseAnswerLibraryEntryOutput_": { - "properties": { - "results": { + "type": "array", + "description": "The id of each group the user belongs to. This includes both manually created groups in Vanta and groups imported from an identity provider." + }, + "name": { "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" - }, - "type": "array" + "first": { + "type": "string", + "nullable": true, + "description": "The person's first (given) name." }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" + "last": { + "type": "string", + "nullable": true, + "description": "The person's last (family) name." + }, + "display": { + "type": "string", + "description": "The person's display name, used in Vanta." } }, "required": [ - "data", - "pageInfo" + "first", + "last", + "display" ], "type": "object" - } - }, - "required": [ - "results" - ], - "type": "object", - "additionalProperties": false - }, - "AnswerLibraryActorAssignmentInput": { - "properties": { - "type": { - "type": "string", - "enum": [ - "User" - ], - "nullable": false, - "description": "The type of actor. Currently only \"User\" is supported.", - "example": "User" }, - "id": { - "type": "string", - "description": "The unique identifier of the user or team.", - "example": "507f1f77bcf86cd799439041" - } - }, - "required": [ - "type", - "id" - ], - "type": "object", - "additionalProperties": false - }, - "CreateAnswerLibraryEntryInput": { - "properties": { - "question": { - "type": "string", - "description": "The question text.", - "example": "Do you encrypt customer data at rest?" - }, - "answer": { - "type": "string", - "description": "The answer text.", - "example": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS." - }, - "ownerAssignment": { - "$ref": "#/components/schemas/AnswerLibraryActorAssignmentInput", - "description": "The actor to assign as owner. Currently only type \"User\" is supported." - }, - "expirationDate": { - "type": "string", - "description": "The expiration date in ISO 8601 format.", - "example": "2025-12-31T00:00:00.000Z" + "sources": { + "properties": { + "employment": { + "properties": { + "endDate": { + "$ref": "#/components/schemas/PersonInfoSource", + "description": "The source of the person's employment end date." + }, + "startDate": { + "$ref": "#/components/schemas/PersonInfoSource", + "description": "The source of the person's employment start date." + } + }, + "required": [ + "endDate", + "startDate" + ], + "type": "object" + }, + "emailAddress": { + "$ref": "#/components/schemas/PersonInfoSource", + "description": "The source of the person's email address." + } + }, + "required": [ + "employment", + "emailAddress" + ], + "type": "object", + "description": "The sources of the person's information." }, - "tags": { - "items": { - "$ref": "#/components/schemas/TagInput" + "tasksSummary": { + "properties": { + "details": { + "$ref": "#/components/schemas/TaskSummaryDetails" + }, + "status": { + "$ref": "#/components/schemas/TasksSummaryStatus", + "description": "The status of the person's tasks summary." + }, + "dueDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The due date of the person's earliest-due task." + }, + "completionDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date when person's tasks were completed." + } }, - "type": "array", - "description": "Tags to associate with the entry. Discover valid `categoryId` and `tagId`\nvalues via `GET /v1/customer-trust/tag-categories` (to list categories)\nand `GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags\nwithin a category)." + "required": [ + "details", + "status", + "dueDate", + "completionDate" + ], + "type": "object", + "description": "The person's tasks summary, which aggregates their current status across\nall of their relevant tasks." } }, "required": [ - "question", - "answer" + "id", + "userId", + "emailAddress", + "employment", + "leaveInfo", + "groupIds", + "name", + "sources", + "tasksSummary" ], "type": "object", "additionalProperties": false }, - "UpdateAnswerLibraryEntryInput": { + "PaginatedResponse_Person_": { "properties": { - "question": { - "type": "string", - "description": "The question text.", - "example": "Do you encrypt customer data at rest?" - }, - "answer": { - "type": "string", - "description": "The answer text.", - "example": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS." - }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/AnswerLibraryActorAssignmentInput" + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/Person" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" } - ], - "nullable": true, - "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." - }, - "expirationDate": { - "type": "string", - "nullable": true, - "description": "The expiration date in ISO 8601 format. Pass `null` to clear.", - "example": "2025-12-31T00:00:00.000Z" - }, - "tags": { - "items": { - "$ref": "#/components/schemas/TagInput" }, - "type": "array", - "description": "Tags to associate with the entry. Replaces the existing tag set. Pass\n`[]` to clear all tags. Discover valid `categoryId` and `tagId` values\nvia `GET /v1/customer-trust/tag-categories` (to list categories) and\n`GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags\nwithin a category)." - } - }, - "type": "object", - "additionalProperties": false - }, - "VerifyAnswerLibraryEntryInput": { - "properties": { - "expirationDate": { - "type": "string", - "description": "The expiration date in ISO 8601 format. If omitted, falls back to the\nconfigured review cadence.", - "example": "2025-12-31T00:00:00.000Z" + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, + "required": [ + "results" + ], "type": "object", "additionalProperties": false }, - "Extract_IssueTemplate.STANDARD_ISSUE_": { - "type": "string", + "ComputerStatusOutcome": { + "description": "The possible outcomes of a status check. The outcome can be one of the following:\nFAIL: The check is failing.\nIN_PROGRESS: The check needs further data from the given computer in order to evaluate. The field(s) needed from a computer to calculate the ComputerStatusOutcome were null.\nNA: The check is not applicable for the given computer.\nPASS: The check is passing.", "enum": [ - "STANDARD_ISSUE" + "FAIL", + "IN_PROGRESS", + "NA", + "PASS" ], - "nullable": false, - "description": "Extract from T those types that are assignable to U" - }, - "StandardIssueType": { - "type": "string", - "enum": [ - "AREA_OF_CONCERN", - "MAJOR_NONCONFORMITY", - "MINOR_NONCONFORMITY", - "OPP_FOR_IMPROVEMENT", - "EXCEPTION", - "PROCESS_FOR_IMPROVEMENT" - ] - }, - "ActorType": { - "type": "string", - "enum": [ - "USER", - "WORKFLOW_GENERATED" - ] + "type": "string" }, - "Actor": { + "ComputerStatus": { + "description": "The a status check for a computer. Representation for screenlock, diskEncryption, passwordManager, and antivirusInstallation.", "properties": { - "actorType": { - "$ref": "#/components/schemas/ActorType" - }, - "actorId": { - "type": "string" + "outcome": { + "$ref": "#/components/schemas/ComputerStatusOutcome", + "description": "The outcome of the status check." } }, "required": [ - "actorType", - "actorId" + "outcome" ], "type": "object", "additionalProperties": false }, - "OwnerType": { - "type": "string", + "OperatingSystemType": { + "description": "The possible types of the operating system. One of `mac_OS`, `linux`, or `windows`.", "enum": [ - "USER", - "TEAM" - ] + "macOS", + "linux", + "windows" + ], + "type": "string" }, - "IssueOwner": { + "OperatingSystem": { + "description": "The computer's operating system type and version.", "properties": { - "ownerType": { - "$ref": "#/components/schemas/OwnerType" + "type": { + "$ref": "#/components/schemas/OperatingSystemType", + "description": "The type of the operating system." }, - "ownerId": { - "type": "string" + "version": { + "type": "string", + "nullable": true, + "description": "The version of the operating system." } }, "required": [ - "ownerType", - "ownerId" + "type", + "version" ], "type": "object", "additionalProperties": false }, - "IssueSeverity": { - "type": "string", - "enum": [ - "CRITICAL", - "HIGH", - "MEDIUM", - "LOW", - "NO_SEVERITY" - ] - }, - "IssueStatus": { - "type": "string", - "enum": [ - "NOT_STARTED", - "IN_PROGRESS", - "CLOSED" - ] - }, - "SourceType": { - "type": "string", - "enum": [ - "AUDIT", - "AUDIT_EXTERNAL", - "INCIDENT", - "EXTERNAL_PARTY", - "SELF_ASSESSMENT", - "OTHER" - ] - }, - "Source": { + "MonitoredComputer": { "properties": { - "sourceType": { - "$ref": "#/components/schemas/SourceType" + "id": { + "type": "string", + "description": "Unique identifier for the monitored computer." }, - "sourceId": { - "type": "string" + "integrationId": { + "type": "string", + "description": "Hard-coded enums for Vanta-built integrations or application IDs for 3rd-party-built integrations." + }, + "lastCheckDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "Date of the computer's most recent report." + }, + "screenlock": { + "$ref": "#/components/schemas/ComputerStatus", + "description": "Whether or not the computer has screenlock enabled." + }, + "diskEncryption": { + "$ref": "#/components/schemas/ComputerStatus", + "description": "Whether or not the computer's hard drive is encrypted." + }, + "passwordManager": { + "$ref": "#/components/schemas/ComputerStatus", + "description": "Whether or not the computer has a password manager installed." + }, + "antivirusInstallation": { + "$ref": "#/components/schemas/ComputerStatus", + "description": "Whether or not the computer has antivirus software installed." + }, + "operatingSystem": { + "allOf": [ + { + "$ref": "#/components/schemas/OperatingSystem" + } + ], + "nullable": true, + "description": "The computer's operating system name and version." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/Owner" + } + ], + "nullable": true, + "description": "The name, unique identifier, and email address of the computer's owner." + }, + "serialNumber": { + "type": "string", + "nullable": true, + "description": "The serial number of the computer. This value may be null if it is not reported by the device." + }, + "udid": { + "type": "string", + "nullable": true, + "description": "The universal device id of the computer." } }, "required": [ - "sourceType" + "id", + "integrationId", + "lastCheckDate", + "screenlock", + "diskEncryption", + "passwordManager", + "antivirusInstallation", + "operatingSystem", + "owner", + "serialNumber", + "udid" ], "type": "object", "additionalProperties": false }, - "ClosedReason": { - "type": "string", + "PaginatedResponse_MonitoredComputer_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/MonitoredComputer" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "ComputerStatusFilter": { + "description": "Enum representing computer compliance statuses that can be utilized as a filter. The meanings are as follows:\nAV_NOT_INSTALLED: The computer does not have antivirus software installed.\nHD_NOT_ENCRYPTED: The computer's harddrive is not encrypted.\nLAST_CHECK_OVER_14_DAYS: No data has been received from computer for over 14 days.\nPWM_NOT_INSTALLED: The computer does not have a password manager installed.\nSCREENLOCK_NOT_CONFIGURED: The computer does not have screenlock configured appropriately.", "enum": [ - "RESOLVED", - "DUPLICATE", - "ACCEPTED", - "OTHER" - ] + "PWM_NOT_INSTALLED", + "HD_NOT_ENCRYPTED", + "AV_NOT_INSTALLED", + "SCREENLOCK_NOT_CONFIGURED", + "LAST_CHECK_OVER_14_DAYS" + ], + "type": "string" }, - "ClosedMetadata": { + "KnowledgeBaseResourceActorAssignment": { "properties": { - "reason": { - "$ref": "#/components/schemas/ClosedReason" + "type": { + "type": "string", + "enum": [ + "User", + "Team" + ] }, - "comment": { + "id": { "type": "string" }, - "closedAt": { + "displayName": { "type": "string", - "format": "date-time" + "nullable": true } }, "required": [ - "reason", - "comment", - "closedAt" + "type", + "id", + "displayName" ], "type": "object", "additionalProperties": false }, - "IssueCustomField": { + "KnowledgeBaseExpirationStatus": { + "type": "string", + "enum": [ + "CURRENT", + "EXPIRED" + ], + "description": "Customer-facing expiration status used by knowledge-base API responses\n(answer library entries and resources). Derived from the persisted\n`expiresAt` field at read time." + }, + "TagInput": { "properties": { - "label": { + "categoryId": { "type": "string" }, - "value": { - "anyOf": [ - { - "type": "string" - }, - { - "items": { - "type": "string" - }, - "type": "array" - } - ] + "tagId": { + "type": "string" } }, "required": [ - "label", - "value" + "categoryId", + "tagId" ], "type": "object", "additionalProperties": false }, - "StandardIssue": { + "KnowledgeBaseWebpageResourceOutput": { "properties": { "id": { "type": "string" }, - "readableIssueId": { - "type": "string" - }, - "createdAt": { - "type": "string", - "format": "date-time" - }, - "createdBy": { - "$ref": "#/components/schemas/Actor" - }, - "lastModifiedBy": { - "$ref": "#/components/schemas/Actor" - }, - "lastModifiedAt": { + "type": { "type": "string", - "format": "date-time" + "enum": [ + "URL" + ], + "nullable": false }, "title": { "type": "string" }, "description": { - "type": "string" - }, - "owners": { - "items": { - "$ref": "#/components/schemas/IssueOwner" - }, - "type": "array" - }, - "severity": { - "$ref": "#/components/schemas/IssueSeverity" + "type": "string", + "nullable": true }, - "status": { - "$ref": "#/components/schemas/IssueStatus" + "url": { + "type": "string" }, - "rootCause": { + "customerVisibility": { "type": "string", + "enum": [ + "PUBLIC", + "SHAREABLE", + "PRIVATE", + "REQUEST_ACCESS", + null + ], "nullable": true }, - "correctiveAction": { - "type": "string", + "includeSubPages": { + "type": "boolean", "nullable": true }, - "dueDate": { - "type": "string", - "format": "date-time", + "isUsedInQuestionnaires": { + "type": "boolean", "nullable": true }, - "source": { + "ownerAssignment": { "allOf": [ { - "$ref": "#/components/schemas/Source" + "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignment" } ], "nullable": true }, - "controlDomain": { + "expirationStatus": { + "$ref": "#/components/schemas/KnowledgeBaseExpirationStatus" + }, + "expirationDate": { "type": "string", "nullable": true }, - "closedMetadata": { - "allOf": [ - { - "$ref": "#/components/schemas/ClosedMetadata" - } - ], - "nullable": true + "lastUpdated": { + "type": "string" }, - "detectedAt": { + "lastVerified": { "type": "string", - "format": "date-time", "nullable": true }, - "mappedControlIds": { - "items": { - "type": "string" - }, - "type": "array" - }, - "mappedRiskScenarioIds": { - "items": { - "type": "string" - }, - "type": "array" - }, - "mappedPolicyIds": { - "items": { - "type": "string" - }, - "type": "array" - }, - "customFields": { + "tags": { "items": { - "$ref": "#/components/schemas/IssueCustomField" + "$ref": "#/components/schemas/TagInput" }, "type": "array" }, - "template": { - "$ref": "#/components/schemas/Extract_IssueTemplate.STANDARD_ISSUE_" - }, - "type": { - "allOf": [ - { - "$ref": "#/components/schemas/StandardIssueType" - } - ], - "nullable": true + "categoryId": { + "type": "string", + "nullable": true, + "description": "Trust Center category id the resource is currently filed under, or\n`null` if uncategorized (or not on the Trust Center, which is the case\nfor `PRIVATE` / `SHAREABLE` resources)." } }, "required": [ "id", - "readableIssueId", - "createdAt", - "createdBy", - "lastModifiedBy", - "lastModifiedAt", + "type", "title", "description", - "owners", - "severity", - "status", - "rootCause", - "correctiveAction", - "dueDate", - "source", - "controlDomain", - "closedMetadata", - "detectedAt", - "mappedControlIds", - "mappedRiskScenarioIds", - "mappedPolicyIds", - "customFields", - "template", - "type" + "url", + "customerVisibility", + "includeSubPages", + "isUsedInQuestionnaires", + "ownerAssignment", + "expirationStatus", + "expirationDate", + "lastUpdated", + "lastVerified", + "tags", + "categoryId" ], "type": "object", "additionalProperties": false }, - "Extract_IssueTemplate.STANDARD_POAM_": { + "KnowledgeBaseResourceActorAssignmentInput": { + "properties": { + "type": { + "type": "string", + "enum": [ + "User" + ], + "nullable": false, + "description": "The type of actor. Currently only \"User\" is supported." + }, + "id": { + "type": "string", + "description": "The unique identifier of the user." + } + }, + "required": [ + "type", + "id" + ], + "type": "object", + "additionalProperties": false + }, + "KnowledgeBaseCustomerVisibility": { "type": "string", "enum": [ - "STANDARD_POAM" + "PRIVATE", + "SHAREABLE", + "REQUEST_ACCESS", + "PUBLIC" ], - "nullable": false, - "description": "Extract from T those types that are assignable to U" + "description": "Customer-facing visibility of a knowledge-base resource on the\nTrust Center. Use {@link CUSTOMER_VISIBILITY_TO_DB} to translate to\n{@link TrustCenterResourceVisibility} when persisting." }, - "StandardPOAM": { + "CreateWebpageResourceInput": { "properties": { - "id": { - "type": "string" + "title": { + "type": "string", + "description": "The title of the webpage resource.", + "minLength": 1 }, - "readableIssueId": { - "type": "string" + "url": { + "type": "string", + "description": "The URL of the webpage.", + "format": "uri" }, - "createdAt": { + "description": { "type": "string", - "format": "date-time" + "description": "A description for the webpage resource." }, - "createdBy": { - "$ref": "#/components/schemas/Actor" + "ownerAssignment": { + "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput", + "description": "The actor to assign as owner. Currently only type \"User\" is supported." }, - "lastModifiedBy": { - "$ref": "#/components/schemas/Actor" + "customerVisibility": { + "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", + "description": "Customer visibility on the Trust Center. Webpage resources accept only\nPRIVATE or PUBLIC; REQUEST_ACCESS and SHAREABLE return an\nInvalidInputError." }, - "lastModifiedAt": { - "type": "string", - "format": "date-time" + "includeSubPages": { + "type": "boolean", + "description": "Whether to scan sub-pages one level deep alongside the primary URL." }, - "title": { - "type": "string" + "isUsedInQuestionnaires": { + "type": "boolean", + "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." }, - "description": { - "type": "string" + "expirationDate": { + "type": "string", + "description": "Expiration date in ISO 8601 format." }, - "owners": { + "tags": { "items": { - "$ref": "#/components/schemas/IssueOwner" + "$ref": "#/components/schemas/TagInput" }, - "type": "array" - }, - "severity": { - "$ref": "#/components/schemas/IssueSeverity" - }, - "status": { - "$ref": "#/components/schemas/IssueStatus" - }, - "rootCause": { - "type": "string", - "nullable": true + "type": "array", + "description": "Tags to associate with the resource." }, - "correctiveAction": { + "categoryId": { "type": "string", - "nullable": true - }, - "dueDate": { + "nullable": true, + "description": "Trust Center category id to associate this resource with. Pass `null`\nto keep the resource uncategorized. Only valid when `customerVisibility`\nis PUBLIC; other combinations and unknown ids return an\nInvalidInputError." + } + }, + "required": [ + "title", + "url" + ], + "type": "object", + "additionalProperties": false + }, + "UpdateWebpageResourceInput": { + "properties": { + "title": { "type": "string", - "format": "date-time", - "nullable": true - }, - "source": { - "allOf": [ - { - "$ref": "#/components/schemas/Source" - } - ], - "nullable": true + "description": "The title of the webpage resource.", + "minLength": 1 }, - "controlDomain": { + "description": { "type": "string", - "nullable": true + "nullable": true, + "description": "A description for the webpage resource. Pass `null` to clear." }, - "closedMetadata": { + "ownerAssignment": { "allOf": [ { - "$ref": "#/components/schemas/ClosedMetadata" + "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput" } ], - "nullable": true + "nullable": true, + "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." }, - "detectedAt": { - "type": "string", - "format": "date-time", - "nullable": true + "customerVisibility": { + "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", + "description": "Customer visibility on the Trust Center. Webpage resources accept only\nPRIVATE or PUBLIC; REQUEST_ACCESS and SHAREABLE return an\nInvalidInputError." }, - "mappedControlIds": { - "items": { - "type": "string" - }, - "type": "array" + "includeSubPages": { + "type": "boolean", + "description": "Whether to scan sub-pages one level deep alongside the primary URL." }, - "mappedRiskScenarioIds": { - "items": { - "type": "string" - }, - "type": "array" + "isUsedInQuestionnaires": { + "type": "boolean", + "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." }, - "mappedPolicyIds": { - "items": { - "type": "string" - }, - "type": "array" + "expirationDate": { + "type": "string", + "nullable": true, + "description": "Expiration date in ISO 8601 format. Pass `null` to clear." }, - "customFields": { + "tags": { "items": { - "$ref": "#/components/schemas/IssueCustomField" + "$ref": "#/components/schemas/TagInput" }, - "type": "array" - }, - "template": { - "$ref": "#/components/schemas/Extract_IssueTemplate.STANDARD_POAM_" - }, - "requiredResources": { - "type": "string", - "nullable": true + "type": "array", + "description": "Tags to associate with the resource. A non-empty array replaces the\nexisting tag set; pass `[]` to clear all tags." }, - "systemsDescription": { + "categoryId": { "type": "string", - "nullable": true + "nullable": true, + "description": "Trust Center category id to associate this resource with. Pass `null`\nto move the resource to uncategorized. Only valid when the resource's\neffective visibility (after applying any patched `customerVisibility`)\nis PUBLIC; other combinations and unknown ids return an\nInvalidInputError." } }, - "required": [ - "id", - "readableIssueId", - "createdAt", - "createdBy", - "lastModifiedBy", - "lastModifiedAt", - "title", - "description", - "owners", - "severity", - "status", - "rootCause", - "correctiveAction", - "dueDate", - "source", - "controlDomain", - "closedMetadata", - "detectedAt", - "mappedControlIds", - "mappedRiskScenarioIds", - "mappedPolicyIds", - "customFields", - "template", - "requiredResources", - "systemsDescription" + "type": "object", + "additionalProperties": false + }, + "KnowledgeBaseDocumentResourceOutput": { + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string", + "enum": [ + "FILE" + ], + "nullable": false + }, + "title": { + "type": "string" + }, + "description": { + "type": "string", + "nullable": true + }, + "fileUrl": { + "type": "string", + "description": "Presigned S3 URL for the underlying document. Expires after 1 hour due\nto AWS IAM Role limitations on presigned URL lifetimes. Re-fetch the\nresource to obtain a fresh URL once this one expires." + }, + "customerVisibility": { + "type": "string", + "enum": [ + "PUBLIC", + "SHAREABLE", + "PRIVATE", + "REQUEST_ACCESS", + null + ], + "nullable": true + }, + "downloadPermission": { + "type": "string", + "enum": [ + "VIEW_ONLY", + "VIEW_AND_DOWNLOAD", + null + ], + "nullable": true + }, + "isUsedInQuestionnaires": { + "type": "boolean", + "nullable": true + }, + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignment" + } + ], + "nullable": true + }, + "expirationStatus": { + "$ref": "#/components/schemas/KnowledgeBaseExpirationStatus" + }, + "expirationDate": { + "type": "string", + "nullable": true + }, + "lastUpdated": { + "type": "string" + }, + "lastVerified": { + "type": "string", + "nullable": true + }, + "tags": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array" + }, + "categoryId": { + "type": "string", + "nullable": true, + "description": "Trust Center category id the resource is currently filed under, or\n`null` if uncategorized (or not on the Trust Center, which is the case\nfor `PRIVATE` / `SHAREABLE` resources)." + } + }, + "required": [ + "id", + "type", + "title", + "description", + "fileUrl", + "customerVisibility", + "downloadPermission", + "isUsedInQuestionnaires", + "ownerAssignment", + "expirationStatus", + "expirationDate", + "lastUpdated", + "lastVerified", + "tags", + "categoryId" ], "type": "object", "additionalProperties": false }, - "Issue": { + "TrustKnowledgeBaseResourceOutput": { "anyOf": [ { - "$ref": "#/components/schemas/StandardIssue" + "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" }, { - "$ref": "#/components/schemas/StandardPOAM" + "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" } - ] + ], + "description": "Discriminated union over `type` of all resource kinds in the Trust\nKnowledge Base (currently FILE and URL)." }, - "PaginatedResponse_Issue_": { + "PaginatedResponse_TrustKnowledgeBaseResourceOutput_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/Issue" + "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" }, "type": "array" }, @@ -8123,101 +8760,180 @@ "type": "object", "additionalProperties": false }, - "IssueTemplate": { + "KnowledgeBaseResourceTypeFilter": { "type": "string", "enum": [ - "STANDARD_ISSUE", - "STANDARD_POAM" + "FILE", + "URL" ] }, - "IssueSortField": { - "type": "string", - "enum": [ - "DUE_DATE", - "CREATED_AT", - "DETECTED_AT", - "LAST_MODIFIED_AT", - "STATUS", - "SEVERITY" - ] + "VerifyKnowledgeBaseResourceInput": { + "properties": { + "expirationDate": { + "type": "string", + "description": "The expiration date in ISO 8601 format. If omitted, falls back to the\nconfigured review cadence.", + "example": "2025-12-31T00:00:00.000Z" + } + }, + "type": "object", + "additionalProperties": false }, - "OrderDirection": { + "KnowledgeBaseResourceDownloadPermission": { "type": "string", "enum": [ - "asc", - "desc" + "VIEW_ONLY", + "VIEW_AND_DOWNLOAD" ], - "description": "Sort direction shared across the external REST API surface.\n\n`\"asc\"` for ascending, `\"desc\"` for descending. Endpoints expose this as the\n`orderDirection` / `sortDirection` query parameter and map it onto whatever\ninternal direction representation the underlying service expects." + "description": "Customer-facing download permission for a knowledge-base resource on\nthe Trust Center. Use {@link DOWNLOAD_PERMISSION_TO_DB} to translate\nto {@link TrustKnowledgeBaseResourceDownloadSetting} when persisting." }, - "Connection": { + "UpdateDocumentResourceInput": { "properties": { - "connectionId": { + "title": { "type": "string", - "description": "The unique identifier for the Connection." + "description": "The title of the document resource.", + "minLength": 1 }, - "isDisabled": { + "description": { + "type": "string", + "nullable": true, + "description": "A description for the document resource. Pass `null` to clear." + }, + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/KnowledgeBaseResourceActorAssignmentInput" + } + ], + "nullable": true, + "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." + }, + "customerVisibility": { + "$ref": "#/components/schemas/KnowledgeBaseCustomerVisibility", + "description": "Customer visibility on the Trust Center." + }, + "downloadPermission": { + "$ref": "#/components/schemas/KnowledgeBaseResourceDownloadPermission", + "description": "Trust Center download permission." + }, + "isUsedInQuestionnaires": { "type": "boolean", - "description": "Whether the Connection has been disabled by Vanta." + "description": "Whether the resource should be used for question-answering in\nQuestionnaire Automation." }, - "connectionErrorMessage": { + "expirationDate": { "type": "string", "nullable": true, - "description": "An error message that may accompany disabled Connections." + "description": "Expiration date in ISO 8601 format. Pass `null` to clear." + }, + "tags": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array", + "description": "Tags to associate with the resource. A non-empty array replaces the\nexisting tag set; pass `[]` to clear all tags." + }, + "categoryId": { + "type": "string", + "nullable": true, + "description": "Trust Center category id to associate this resource with. Pass `null`\nto move the resource to uncategorized. Only valid when the resource's\neffective visibility (after applying any patched `customerVisibility`)\nis REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return\nan InvalidInputError." } }, - "required": [ - "connectionId", - "isDisabled", - "connectionErrorMessage" - ], "type": "object", "additionalProperties": false }, - "Integration": { + "AnswerLibraryActorAssignment": { "properties": { - "integrationId": { + "type": { "type": "string", - "description": "A unique identifier for the Integration." + "enum": [ + "User", + "Team" + ] + }, + "id": { + "type": "string" }, "displayName": { "type": "string", - "description": "The Integration's display name." - }, - "resourceKinds": { - "items": { - "type": "string" - }, - "type": "array", - "description": "A list of string identifiers for the resource types ingested by the Integration." - }, - "connections": { - "items": { - "$ref": "#/components/schemas/Connection" - }, - "type": "array", - "description": "A list of installed Connections." + "nullable": true } }, "required": [ - "integrationId", - "displayName", - "resourceKinds", - "connections" + "type", + "id", + "displayName" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Integration_": { + "KnowledgeBaseAnswerLibraryEntryOutput": { "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Integration" - }, - "type": "array" - }, - "pageInfo": { + "id": { + "type": "string" + }, + "question": { + "type": "string" + }, + "answer": { + "type": "string" + }, + "expirationStatus": { + "type": "string", + "enum": [ + "CURRENT", + "EXPIRED" + ] + }, + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/AnswerLibraryActorAssignment" + } + ], + "nullable": true + }, + "expirationDate": { + "type": "string", + "nullable": true + }, + "lastUpdated": { + "type": "string" + }, + "lastVerified": { + "type": "string", + "nullable": true + }, + "tags": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array" + } + }, + "required": [ + "id", + "question", + "answer", + "expirationStatus", + "ownerAssignment", + "expirationDate", + "lastUpdated", + "lastVerified", + "tags" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_KnowledgeBaseAnswerLibraryEntryOutput_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + }, + "type": "array" + }, + "pageInfo": { "$ref": "#/components/schemas/PageInfo" } }, @@ -8234,548 +8950,879 @@ "type": "object", "additionalProperties": false }, - "ResourceKindSummary": { + "AnswerLibraryActorAssignmentInput": { "properties": { - "integrationId": { + "type": { "type": "string", - "description": "The unique identifier for the Integration that ingests this resource." + "enum": [ + "User" + ], + "nullable": false, + "description": "The type of actor. Currently only \"User\" is supported.", + "example": "User" }, - "resourceKind": { + "id": { "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." - }, - "isScopable": { - "type": "boolean", - "description": "Whether resources of this type may be scoped out of an audit." - }, - "canUpdateDescription": { - "type": "boolean", - "description": "Whether resources of this type may be assigned a description." - }, - "canUpdateOwner": { - "type": "boolean", - "description": "Whether resources of this type may be assigned an owner." + "description": "The unique identifier of the user or team.", + "example": "507f1f77bcf86cd799439041" } }, "required": [ - "integrationId", - "resourceKind", - "isScopable", - "canUpdateDescription", - "canUpdateOwner" + "type", + "id" ], "type": "object", "additionalProperties": false }, - "ResourceKindDetails": { + "CreateAnswerLibraryEntryInput": { "properties": { - "integrationId": { + "question": { "type": "string", - "description": "The unique identifier for the Integration that ingests this resource." + "description": "The question text.", + "example": "Do you encrypt customer data at rest?" }, - "resourceKind": { + "answer": { "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." - }, - "isScopable": { - "type": "boolean", - "description": "Whether resources of this type may be scoped out of an audit." - }, - "canUpdateDescription": { - "type": "boolean", - "description": "Whether resources of this type may be assigned a description." - }, - "canUpdateOwner": { - "type": "boolean", - "description": "Whether resources of this type may be assigned an owner." - }, - "numResources": { - "type": "integer", - "format": "int32", - "description": "The count of resources of the given type.", - "minimum": 0 + "description": "The answer text.", + "example": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS." }, - "numInScope": { - "type": "integer", - "format": "int32", - "description": "The count of resources of the given type that are in scope for audits.", - "minimum": 0 + "ownerAssignment": { + "$ref": "#/components/schemas/AnswerLibraryActorAssignmentInput", + "description": "The actor to assign as owner. Currently only type \"User\" is supported." }, - "numOwned": { - "type": "integer", - "format": "int32", - "description": "The count of resources of the given type that have been assigned an owner in Vanta.", - "minimum": 0 + "expirationDate": { + "type": "string", + "description": "The expiration date in ISO 8601 format.", + "example": "2025-12-31T00:00:00.000Z" }, - "numWithDescription": { - "type": "integer", - "format": "int32", - "description": "The count of resources of the given type that have been given a description in Vanta.", - "minimum": 0 + "tags": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array", + "description": "Tags to associate with the entry. Discover valid `categoryId` and `tagId`\nvalues via `GET /v1/customer-trust/tag-categories` (to list categories)\nand `GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags\nwithin a category)." } }, "required": [ - "integrationId", - "resourceKind", - "isScopable", - "canUpdateDescription", - "canUpdateOwner", - "numResources", - "numInScope", - "numOwned", - "numWithDescription" + "question", + "answer" ], "type": "object", "additionalProperties": false }, - "UpdateResourceRequest": { + "UpdateAnswerLibraryEntryInput": { "properties": { - "id": { + "question": { "type": "string", - "description": "ID of the resource to update." + "description": "The question text.", + "example": "Do you encrypt customer data at rest?" }, - "ownerId": { + "answer": { "type": "string", - "description": "Owner ID to update for the resource." + "description": "The answer text.", + "example": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS." }, - "description": { + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/AnswerLibraryActorAssignmentInput" + } + ], + "nullable": true, + "description": "The actor to assign as owner. Pass `null` to clear. Currently only type\n\"User\" is supported." + }, + "expirationDate": { "type": "string", - "description": "Description to update for the resource." + "nullable": true, + "description": "The expiration date in ISO 8601 format. Pass `null` to clear.", + "example": "2025-12-31T00:00:00.000Z" }, - "inScope": { - "type": "boolean", - "description": "Determines whether resources should be marked in scope or not." + "tags": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array", + "description": "Tags to associate with the entry. Replaces the existing tag set. Pass\n`[]` to clear all tags. Discover valid `categoryId` and `tagId` values\nvia `GET /v1/customer-trust/tag-categories` (to list categories) and\n`GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags\nwithin a category)." } }, - "required": [ - "id" - ], "type": "object", "additionalProperties": false }, - "ResourceResponseType": { + "VerifyAnswerLibraryEntryInput": { + "properties": { + "expirationDate": { + "type": "string", + "description": "The expiration date in ISO 8601 format. If omitted, falls back to the\nconfigured review cadence.", + "example": "2025-12-31T00:00:00.000Z" + } + }, + "type": "object", + "additionalProperties": false + }, + "Extract_IssueTemplate.STANDARD_ISSUE_": { + "type": "string", "enum": [ - "Account", - "AutoScalingGroup", - "ClusterDeployment", - "ComputeInstance", - "ContainerCluster", - "ContainerRepository", - "Database", - "Device", - "GitRepository", - "KubernetesCluster", - "LoadBalancer", - "PaaS", - "Resource", - "Queue", - "ServerlessFunction", - "StorageBucket" + "STANDARD_ISSUE" ], - "type": "string" + "nullable": false, + "description": "Extract from T those types that are assignable to U" }, - "Resource": { - "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" - }, - "resourceKind": { - "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." - }, - "resourceId": { - "type": "string", - "description": "The unique identifier for the Resource." - }, - "connectionId": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." + "StandardIssueType": { + "type": "string", + "enum": [ + "AREA_OF_CONCERN", + "MAJOR_NONCONFORMITY", + "MINOR_NONCONFORMITY", + "OPP_FOR_IMPROVEMENT", + "EXCEPTION", + "PROCESS_FOR_IMPROVEMENT" + ] + }, + "ActorType": { + "type": "string", + "enum": [ + "USER", + "APPLICATION", + "WORKFLOW_GENERATED" + ] + }, + "Actor": { + "properties": { + "actorType": { + "$ref": "#/components/schemas/ActorType" }, - "displayName": { - "type": "string", - "description": "The Resource's display name." + "actorId": { + "type": "string" + } + }, + "required": [ + "actorType", + "actorId" + ], + "type": "object", + "additionalProperties": false + }, + "OwnerType": { + "type": "string", + "enum": [ + "USER", + "TEAM" + ] + }, + "IssueOwner": { + "properties": { + "ownerType": { + "$ref": "#/components/schemas/OwnerType" }, - "owner": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the owner of the resource in Vanta." + "ownerId": { + "type": "string" + } + }, + "required": [ + "ownerType", + "ownerId" + ], + "type": "object", + "additionalProperties": false + }, + "IssueSeverity": { + "type": "string", + "enum": [ + "CRITICAL", + "HIGH", + "MEDIUM", + "LOW", + "NO_SEVERITY" + ] + }, + "IssueStatus": { + "type": "string", + "enum": [ + "NOT_STARTED", + "IN_PROGRESS", + "CLOSED" + ] + }, + "SourceType": { + "type": "string", + "enum": [ + "AUDIT", + "AUDIT_EXTERNAL", + "INCIDENT", + "EXTERNAL_PARTY", + "SELF_ASSESSMENT", + "OTHER" + ] + }, + "Source": { + "properties": { + "sourceType": { + "$ref": "#/components/schemas/SourceType" }, - "inScope": { - "type": "boolean", - "description": "Whether the resource is in scope for audits." + "sourceId": { + "type": "string" + } + }, + "required": [ + "sourceType" + ], + "type": "object", + "additionalProperties": false + }, + "ClosedReason": { + "type": "string", + "enum": [ + "RESOLVED", + "DUPLICATE", + "ACCEPTED", + "OTHER" + ] + }, + "ClosedMetadata": { + "properties": { + "reason": { + "$ref": "#/components/schemas/ClosedReason" }, - "description": { - "type": "string", - "nullable": true, - "description": "The description of the resource in Vanta." + "comment": { + "type": "string" }, - "creationDate": { + "closedAt": { "type": "string", - "format": "date-time", - "description": "When Vanta first ingested the Resource." + "format": "date-time" + } + }, + "required": [ + "reason", + "comment", + "closedAt" + ], + "type": "object", + "additionalProperties": false + }, + "IssueCustomField": { + "properties": { + "label": { + "type": "string" }, - "deletedDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + "value": { + "anyOf": [ + { + "type": "string" + }, + { + "items": { + "type": "string" + }, + "type": "array" + } + ] } }, "required": [ - "responseType", - "resourceKind", - "resourceId", - "connectionId", - "displayName", - "owner", - "inScope", - "description", - "creationDate" + "label", + "value" ], "type": "object", "additionalProperties": false }, - "CloudInfrastructure": { + "StandardIssue": { "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" + "id": { + "type": "string" }, - "resourceKind": { - "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." + "readableIssueId": { + "type": "string" }, - "resourceId": { + "createdDate": { "type": "string", - "description": "The unique identifier for the Resource." + "format": "date-time" }, - "connectionId": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." + "createdBy": { + "$ref": "#/components/schemas/Actor" }, - "displayName": { - "type": "string", - "description": "The Resource's display name." + "lastModifiedBy": { + "$ref": "#/components/schemas/Actor" }, - "owner": { + "lastModifiedDate": { "type": "string", - "nullable": true, - "description": "The unique identifier for the owner of the resource in Vanta." + "format": "date-time" }, - "inScope": { - "type": "boolean", - "description": "Whether the resource is in scope for audits." + "title": { + "type": "string" }, "description": { + "type": "string" + }, + "owners": { + "items": { + "$ref": "#/components/schemas/IssueOwner" + }, + "type": "array" + }, + "severity": { + "$ref": "#/components/schemas/IssueSeverity" + }, + "status": { + "$ref": "#/components/schemas/IssueStatus" + }, + "rootCause": { "type": "string", - "nullable": true, - "description": "The description of the resource in Vanta." + "nullable": true }, - "creationDate": { + "correctiveAction": { "type": "string", - "format": "date-time", - "description": "When Vanta first ingested the Resource." + "nullable": true }, - "deletedDate": { + "dueDate": { "type": "string", "format": "date-time", - "nullable": true, - "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + "nullable": true }, - "account": { - "type": "string", - "description": "Name of the account associated with the Resource" + "source": { + "allOf": [ + { + "$ref": "#/components/schemas/Source" + } + ], + "nullable": true }, - "region": { + "controlDomain": { "type": "string", - "description": "Region in which the Resource is located" - } + "nullable": true + }, + "closedMetadata": { + "allOf": [ + { + "$ref": "#/components/schemas/ClosedMetadata" + } + ], + "nullable": true + }, + "detectedDate": { + "type": "string", + "format": "date-time" + }, + "mappedControlIds": { + "items": { + "type": "string" + }, + "type": "array" + }, + "mappedRiskScenarioIds": { + "items": { + "type": "string" + }, + "type": "array" + }, + "mappedPolicyIds": { + "items": { + "type": "string" + }, + "type": "array" + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/IssueCustomField" + }, + "type": "array" + }, + "template": { + "$ref": "#/components/schemas/Extract_IssueTemplate.STANDARD_ISSUE_" + }, + "type": { + "allOf": [ + { + "$ref": "#/components/schemas/StandardIssueType" + } + ], + "nullable": true + } }, "required": [ - "responseType", - "resourceKind", - "resourceId", - "connectionId", - "displayName", - "owner", - "inScope", + "id", + "readableIssueId", + "createdDate", + "createdBy", + "lastModifiedBy", + "lastModifiedDate", + "title", "description", - "creationDate", - "account", - "region" + "owners", + "severity", + "status", + "rootCause", + "correctiveAction", + "dueDate", + "source", + "controlDomain", + "closedMetadata", + "detectedDate", + "mappedControlIds", + "mappedRiskScenarioIds", + "mappedPolicyIds", + "customFields", + "template", + "type" ], "type": "object", "additionalProperties": false }, - "ComputeInstance": { - "description": "A CloudInfrastructure resource backed by a machine image — e.g. a virtual\nmachine or a Kubernetes node. Carries the machine image identifier and\nhuman-readable image name when available.", + "Extract_IssueTemplate.STANDARD_POAM_": { + "type": "string", + "enum": [ + "STANDARD_POAM" + ], + "nullable": false, + "description": "Extract from T those types that are assignable to U" + }, + "StandardPOAM": { "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" + "id": { + "type": "string" }, - "resourceKind": { - "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." + "readableIssueId": { + "type": "string" }, - "resourceId": { + "createdDate": { "type": "string", - "description": "The unique identifier for the Resource." + "format": "date-time" }, - "connectionId": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." + "createdBy": { + "$ref": "#/components/schemas/Actor" }, - "displayName": { - "type": "string", - "description": "The Resource's display name." + "lastModifiedBy": { + "$ref": "#/components/schemas/Actor" }, - "owner": { + "lastModifiedDate": { "type": "string", - "nullable": true, - "description": "The unique identifier for the owner of the resource in Vanta." + "format": "date-time" }, - "inScope": { - "type": "boolean", - "description": "Whether the resource is in scope for audits." + "title": { + "type": "string" }, "description": { - "type": "string", - "nullable": true, - "description": "The description of the resource in Vanta." + "type": "string" }, - "creationDate": { - "type": "string", - "format": "date-time", - "description": "When Vanta first ingested the Resource." + "owners": { + "items": { + "$ref": "#/components/schemas/IssueOwner" + }, + "type": "array" }, - "deletedDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + "severity": { + "$ref": "#/components/schemas/IssueSeverity" }, - "account": { - "type": "string", - "description": "Name of the account associated with the Resource" + "status": { + "$ref": "#/components/schemas/IssueStatus" }, - "region": { + "rootCause": { "type": "string", - "description": "Region in which the Resource is located" + "nullable": true }, - "machineImageId": { + "correctiveAction": { "type": "string", - "nullable": true, - "description": "The machine image identifier the resource was launched from (e.g. an AWS\nAMI ID, a GCP image self-link, or an Azure publisher/offer/sku/version\ncomposite). Null when the image could not be resolved." + "nullable": true }, - "machineImageName": { + "dueDate": { "type": "string", - "nullable": true, - "description": "A human-readable name describing the machine image's OS and version (e.g.\nan AMI name or GCP image name). Null when no descriptive name is available." - } - }, - "required": [ - "responseType", - "resourceKind", - "resourceId", - "connectionId", - "displayName", - "owner", - "inScope", - "description", - "creationDate", - "account", - "region" - ], - "type": "object", - "additionalProperties": false - }, - "ContainerRepository": { - "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" + "format": "date-time", + "nullable": true }, - "resourceKind": { - "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." + "source": { + "allOf": [ + { + "$ref": "#/components/schemas/Source" + } + ], + "nullable": true }, - "resourceId": { + "controlDomain": { "type": "string", - "description": "The unique identifier for the Resource." + "nullable": true }, - "connectionId": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." + "closedMetadata": { + "allOf": [ + { + "$ref": "#/components/schemas/ClosedMetadata" + } + ], + "nullable": true }, - "displayName": { + "detectedDate": { "type": "string", - "description": "The Resource's display name." + "format": "date-time" }, - "owner": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the owner of the resource in Vanta." + "mappedControlIds": { + "items": { + "type": "string" + }, + "type": "array" }, - "inScope": { - "type": "boolean", - "description": "Whether the resource is in scope for audits." + "mappedRiskScenarioIds": { + "items": { + "type": "string" + }, + "type": "array" }, - "description": { - "type": "string", - "nullable": true, - "description": "The description of the resource in Vanta." + "mappedPolicyIds": { + "items": { + "type": "string" + }, + "type": "array" }, - "creationDate": { - "type": "string", - "format": "date-time", - "description": "When Vanta first ingested the Resource." + "customFields": { + "items": { + "$ref": "#/components/schemas/IssueCustomField" + }, + "type": "array" }, - "deletedDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + "template": { + "$ref": "#/components/schemas/Extract_IssueTemplate.STANDARD_POAM_" }, - "account": { + "requiredResources": { "type": "string", - "description": "Name of the account associated with the Resource" + "nullable": true }, - "region": { + "systemsDescription": { "type": "string", - "description": "Region in which the Resource is located" - }, - "isAutoscanEnabled": { - "type": "boolean", - "nullable": true, - "description": "Whether autoscans have been enabled" + "nullable": true } }, "required": [ - "responseType", - "resourceKind", - "resourceId", - "connectionId", - "displayName", - "owner", - "inScope", + "id", + "readableIssueId", + "createdDate", + "createdBy", + "lastModifiedBy", + "lastModifiedDate", + "title", "description", - "creationDate", - "account", - "region", - "isAutoscanEnabled" + "owners", + "severity", + "status", + "rootCause", + "correctiveAction", + "dueDate", + "source", + "controlDomain", + "closedMetadata", + "detectedDate", + "mappedControlIds", + "mappedRiskScenarioIds", + "mappedPolicyIds", + "customFields", + "template", + "requiredResources", + "systemsDescription" ], "type": "object", "additionalProperties": false }, - "Database": { - "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" - }, - "resourceKind": { - "type": "string", - "description": "The identifier for the resource type, unique within the scope of an Integration." - }, - "resourceId": { - "type": "string", - "description": "The unique identifier for the Resource." + "Issue": { + "anyOf": [ + { + "$ref": "#/components/schemas/StandardIssue" }, + { + "$ref": "#/components/schemas/StandardPOAM" + } + ] + }, + "PaginatedResponse_Issue_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/Issue" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "IssueTemplate": { + "type": "string", + "enum": [ + "STANDARD_ISSUE", + "STANDARD_POAM" + ] + }, + "IssueSortField": { + "type": "string", + "enum": [ + "dueDate", + "createdDate", + "detectedDate", + "lastModifiedDate", + "status", + "severity" + ] + }, + "OrderDirection": { + "type": "string", + "enum": [ + "asc", + "desc" + ], + "description": "`\"asc\"` for ascending, `\"desc\"` for descending." + }, + "Connection": { + "properties": { "connectionId": { "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." - }, - "displayName": { - "type": "string", - "description": "The Resource's display name." - }, - "owner": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the owner of the resource in Vanta." + "description": "The unique identifier for the Connection." }, - "inScope": { + "isDisabled": { "type": "boolean", - "description": "Whether the resource is in scope for audits." + "description": "Whether the Connection has been disabled by Vanta." }, - "description": { + "connectionErrorMessage": { "type": "string", "nullable": true, - "description": "The description of the resource in Vanta." - }, - "creationDate": { - "type": "string", - "format": "date-time", - "description": "When Vanta first ingested the Resource." - }, - "deletedDate": { + "description": "An error message that may accompany disabled Connections." + } + }, + "required": [ + "connectionId", + "isDisabled", + "connectionErrorMessage" + ], + "type": "object", + "additionalProperties": false + }, + "Integration": { + "properties": { + "integrationId": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + "description": "A unique identifier for the Integration." }, - "account": { + "displayName": { "type": "string", - "description": "Name of the account associated with the Database" - }, - "areBackupsEnabled": { - "type": "boolean", - "nullable": true, - "description": "Whether backups are enabled for the Database" - }, - "isEncrypted": { - "type": "boolean", - "description": "Whether the Database is encrypted" + "description": "The Integration's display name." }, - "containsEphi": { - "type": "boolean", - "nullable": true, - "description": "Whether the Database contains Ephi" + "resourceKinds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "A list of string identifiers for the resource types ingested by the Integration." }, - "containsUserData": { - "type": "boolean", - "nullable": true, - "description": "Whether the Database contains user data" + "connections": { + "items": { + "$ref": "#/components/schemas/Connection" + }, + "type": "array", + "description": "A list of installed Connections." } }, "required": [ - "responseType", - "resourceKind", - "resourceId", - "connectionId", + "integrationId", "displayName", - "owner", - "inScope", - "description", - "creationDate", - "account", - "areBackupsEnabled", - "isEncrypted", - "containsEphi", - "containsUserData" + "resourceKinds", + "connections" ], "type": "object", "additionalProperties": false }, - "Device": { + "PaginatedResponse_Integration_": { "properties": { - "responseType": { - "$ref": "#/components/schemas/ResourceResponseType" + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/Integration" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "ResourceKindSummary": { + "properties": { + "integrationId": { + "type": "string", + "description": "The unique identifier for the Integration that ingests this resource." }, "resourceKind": { "type": "string", "description": "The identifier for the resource type, unique within the scope of an Integration." }, - "resourceId": { - "type": "string", - "description": "The unique identifier for the Resource." + "isScopable": { + "type": "boolean", + "description": "Whether resources of this type may be scoped out of an audit." }, - "connectionId": { - "type": "string", - "nullable": true, - "description": "The unique identifier for the Connection used to ingest the Resource if it exists." + "canUpdateDescription": { + "type": "boolean", + "description": "Whether resources of this type may be assigned a description." + }, + "canUpdateOwner": { + "type": "boolean", + "description": "Whether resources of this type may be assigned an owner." + } + }, + "required": [ + "integrationId", + "resourceKind", + "isScopable", + "canUpdateDescription", + "canUpdateOwner" + ], + "type": "object", + "additionalProperties": false + }, + "ResourceKindDetails": { + "properties": { + "integrationId": { + "type": "string", + "description": "The unique identifier for the Integration that ingests this resource." + }, + "resourceKind": { + "type": "string", + "description": "The identifier for the resource type, unique within the scope of an Integration." + }, + "isScopable": { + "type": "boolean", + "description": "Whether resources of this type may be scoped out of an audit." + }, + "canUpdateDescription": { + "type": "boolean", + "description": "Whether resources of this type may be assigned a description." + }, + "canUpdateOwner": { + "type": "boolean", + "description": "Whether resources of this type may be assigned an owner." + }, + "numResources": { + "type": "integer", + "format": "int32", + "description": "The count of resources of the given type.", + "minimum": 0 + }, + "numInScope": { + "type": "integer", + "format": "int32", + "description": "The count of resources of the given type that are in scope for audits.", + "minimum": 0 + }, + "numOwned": { + "type": "integer", + "format": "int32", + "description": "The count of resources of the given type that have been assigned an owner in Vanta.", + "minimum": 0 + }, + "numWithDescription": { + "type": "integer", + "format": "int32", + "description": "The count of resources of the given type that have been given a description in Vanta.", + "minimum": 0 + } + }, + "required": [ + "integrationId", + "resourceKind", + "isScopable", + "canUpdateDescription", + "canUpdateOwner", + "numResources", + "numInScope", + "numOwned", + "numWithDescription" + ], + "type": "object", + "additionalProperties": false + }, + "UpdateResourceRequest": { + "properties": { + "id": { + "type": "string", + "description": "ID of the resource to update." + }, + "ownerId": { + "type": "string", + "description": "Owner ID to update for the resource." + }, + "description": { + "type": "string", + "description": "Description to update for the resource." + }, + "inScope": { + "type": "boolean", + "description": "Determines whether resources should be marked in scope or not." + } + }, + "required": [ + "id" + ], + "type": "object", + "additionalProperties": false + }, + "ResourceResponseType": { + "enum": [ + "Account", + "AutoScalingGroup", + "ClusterDeployment", + "ComputeInstance", + "ContainerCluster", + "ContainerRepository", + "Database", + "Device", + "GitRepository", + "KubernetesCluster", + "LoadBalancer", + "PaaS", + "Resource", + "Queue", + "ServerlessFunction", + "StorageBucket" + ], + "type": "string" + }, + "Resource": { + "properties": { + "responseType": { + "$ref": "#/components/schemas/ResourceResponseType" + }, + "resourceKind": { + "type": "string", + "description": "The identifier for the resource type, unique within the scope of an Integration." + }, + "resourceId": { + "type": "string", + "description": "The unique identifier for the Resource." + }, + "connectionId": { + "type": "string", + "nullable": true, + "description": "The unique identifier for the Connection used to ingest the Resource if it exists." }, "displayName": { "type": "string", @@ -8805,25 +9852,6 @@ "format": "date-time", "nullable": true, "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." - }, - "operatingSystemName": { - "type": "string", - "description": "Name of the operating system" - }, - "isEncrypted": { - "type": "boolean", - "nullable": true, - "description": "Whether the Device is encrypted" - }, - "containsEphi": { - "type": "boolean", - "nullable": true, - "description": "Whether the Device contains Ephi" - }, - "containsUserData": { - "type": "boolean", - "nullable": true, - "description": "Whether the Device contains user data" } }, "required": [ @@ -8835,16 +9863,12 @@ "owner", "inScope", "description", - "creationDate", - "operatingSystemName", - "isEncrypted", - "containsEphi", - "containsUserData" + "creationDate" ], "type": "object", "additionalProperties": false }, - "PaaS": { + "CloudInfrastructure": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -8891,15 +9915,13 @@ "nullable": true, "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "containsEphi": { - "type": "boolean", - "nullable": true, - "description": "Whether the PaaS contains Ephi" + "account": { + "type": "string", + "description": "Name of the account associated with the Resource" }, - "containsUserData": { - "type": "boolean", - "nullable": true, - "description": "Whether the PaaS contains user data" + "region": { + "type": "string", + "description": "Region in which the Resource is located" } }, "required": [ @@ -8912,13 +9934,13 @@ "inScope", "description", "creationDate", - "containsEphi", - "containsUserData" + "account", + "region" ], "type": "object", "additionalProperties": false }, - "Queue": { + "ContainerRepository": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -8973,15 +9995,10 @@ "type": "string", "description": "Region in which the Resource is located" }, - "containsEphi": { - "type": "boolean", - "nullable": true, - "description": "Whether the Queue contains Ephi" - }, - "containsUserData": { + "isAutoscanEnabled": { "type": "boolean", "nullable": true, - "description": "Whether the Queue contains user data" + "description": "Whether autoscans have been enabled" } }, "required": [ @@ -8996,13 +10013,12 @@ "creationDate", "account", "region", - "containsEphi", - "containsUserData" + "isAutoscanEnabled" ], "type": "object", "additionalProperties": false }, - "StorageBucket": { + "Database": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -9051,30 +10067,26 @@ }, "account": { "type": "string", - "description": "Name of the account associated with the Resource" + "description": "Name of the account associated with the Database" }, - "region": { - "type": "string", - "description": "Region in which the Resource is located" + "areBackupsEnabled": { + "type": "boolean", + "nullable": true, + "description": "Whether backups are enabled for the Database" }, "isEncrypted": { "type": "boolean", - "description": "Whether the StorageBucket is encrypted" + "description": "Whether the Database is encrypted" }, "containsEphi": { "type": "boolean", "nullable": true, - "description": "Whether the StorageBucket contains Ephi" + "description": "Whether the Database contains Ephi" }, "containsUserData": { "type": "boolean", "nullable": true, - "description": "Whether the StorageBucket contains user data" - }, - "isVersioned": { - "type": "boolean", - "nullable": true, - "description": "Whether the StorageBucket is versioned" + "description": "Whether the Database contains user data" } }, "required": [ @@ -9088,16 +10100,15 @@ "description", "creationDate", "account", - "region", + "areBackupsEnabled", "isEncrypted", "containsEphi", - "containsUserData", - "isVersioned" + "containsUserData" ], "type": "object", "additionalProperties": false }, - "Account": { + "Device": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -9144,32 +10155,24 @@ "nullable": true, "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "accountName": { + "operatingSystemName": { "type": "string", - "description": "Name associated with the Account" - }, - "roles": { - "items": { - "type": "string" - }, - "type": "array", - "description": "Any role(s) assigned to the Account" + "description": "Name of the operating system" }, - "groups": { - "items": { - "type": "string" - }, - "type": "array", - "description": "Any groups to which the Account belongs" + "isEncrypted": { + "type": "boolean", + "nullable": true, + "description": "Whether the Device is encrypted" }, - "isDeactivated": { + "containsEphi": { "type": "boolean", - "description": "Whether the account has been deactivated/disabled/deleted." + "nullable": true, + "description": "Whether the Device contains Ephi" }, - "isMfaEnabled": { + "containsUserData": { "type": "boolean", "nullable": true, - "description": "Whether MFA has been enabled for the account." + "description": "Whether the Device contains user data" } }, "required": [ @@ -9182,34 +10185,15 @@ "inScope", "description", "creationDate", - "accountName", - "roles", - "groups", - "isDeactivated", - "isMfaEnabled" - ], - "type": "object", - "additionalProperties": false - }, - "AccessKeyInfo": { - "properties": { - "accessKeyId": { - "type": "string", - "description": "The access key ID" - }, - "status": { - "type": "string", - "description": "The status of the access key" - } - }, - "required": [ - "accessKeyId", - "status" + "operatingSystemName", + "isEncrypted", + "containsEphi", + "containsUserData" ], "type": "object", "additionalProperties": false }, - "AwsAccount": { + "PaaS": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -9256,47 +10240,15 @@ "nullable": true, "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "accountName": { - "type": "string", - "description": "Name associated with the Account" - }, - "roles": { - "items": { - "type": "string" - }, - "type": "array", - "description": "Any role(s) assigned to the Account" - }, - "groups": { - "items": { - "type": "string" - }, - "type": "array", - "description": "Any groups to which the Account belongs" - }, - "isDeactivated": { + "containsEphi": { "type": "boolean", - "description": "Whether the account has been deactivated/disabled/deleted." + "nullable": true, + "description": "Whether the PaaS contains Ephi" }, - "isMfaEnabled": { + "containsUserData": { "type": "boolean", "nullable": true, - "description": "Whether MFA has been enabled for the account." - }, - "awsUserAccountId": { - "type": "string", - "description": "The AWS user account ID associated with the account" - }, - "awsAccountNumber": { - "type": "string", - "description": "AWS account number (12 digit number) that uniquely identifies your AWS account" - }, - "accessKeys": { - "items": { - "$ref": "#/components/schemas/AccessKeyInfo" - }, - "type": "array", - "description": "The list of access keys associated with the AWS account" + "description": "Whether the PaaS contains user data" } }, "required": [ @@ -9309,19 +10261,13 @@ "inScope", "description", "creationDate", - "accountName", - "roles", - "groups", - "isDeactivated", - "isMfaEnabled", - "awsUserAccountId", - "awsAccountNumber", - "accessKeys" + "containsEphi", + "containsUserData" ], "type": "object", "additionalProperties": false }, - "OrganizationSubunit": { + "Queue": { "properties": { "responseType": { "$ref": "#/components/schemas/ResourceResponseType" @@ -9368,10 +10314,23 @@ "nullable": true, "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "accountId": { + "account": { + "type": "string", + "description": "Name of the account associated with the Resource" + }, + "region": { "type": "string", + "description": "Region in which the Resource is located" + }, + "containsEphi": { + "type": "boolean", "nullable": true, - "description": "Account ID corresponding to the subunit. Could be null if the subunit is not an account, e.g. a subscription" + "description": "Whether the Queue contains Ephi" + }, + "containsUserData": { + "type": "boolean", + "nullable": true, + "description": "Whether the Queue contains user data" } }, "required": [ @@ -9384,476 +10343,445 @@ "inScope", "description", "creationDate", - "accountId" + "account", + "region", + "containsEphi", + "containsUserData" ], "type": "object", "additionalProperties": false }, - "AnyResource": { - "anyOf": [ - { - "$ref": "#/components/schemas/Resource" + "StorageBucket": { + "properties": { + "responseType": { + "$ref": "#/components/schemas/ResourceResponseType" }, - { - "$ref": "#/components/schemas/CloudInfrastructure" + "resourceKind": { + "type": "string", + "description": "The identifier for the resource type, unique within the scope of an Integration." }, - { - "$ref": "#/components/schemas/ComputeInstance" + "resourceId": { + "type": "string", + "description": "The unique identifier for the Resource." }, - { - "$ref": "#/components/schemas/ContainerRepository" + "connectionId": { + "type": "string", + "nullable": true, + "description": "The unique identifier for the Connection used to ingest the Resource if it exists." }, - { - "$ref": "#/components/schemas/Database" + "displayName": { + "type": "string", + "description": "The Resource's display name." }, - { - "$ref": "#/components/schemas/Device" + "owner": { + "type": "string", + "nullable": true, + "description": "The unique identifier for the owner of the resource in Vanta." }, - { - "$ref": "#/components/schemas/PaaS" + "inScope": { + "type": "boolean", + "description": "Whether the resource is in scope for audits." }, - { - "$ref": "#/components/schemas/Queue" + "description": { + "type": "string", + "nullable": true, + "description": "The description of the resource in Vanta." }, - { - "$ref": "#/components/schemas/StorageBucket" + "creationDate": { + "type": "string", + "format": "date-time", + "description": "When Vanta first ingested the Resource." }, - { - "$ref": "#/components/schemas/Account" + "deletedDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - { - "$ref": "#/components/schemas/AwsAccount" + "account": { + "type": "string", + "description": "Name of the account associated with the Resource" }, - { - "$ref": "#/components/schemas/OrganizationSubunit" - } - ] - }, - "PaginatedResponse_AnyResource_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/AnyResource" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "region": { + "type": "string", + "description": "Region in which the Resource is located" + }, + "isEncrypted": { + "type": "boolean", + "description": "Whether the StorageBucket is encrypted" + }, + "containsEphi": { + "type": "boolean", + "nullable": true, + "description": "Whether the StorageBucket contains Ephi" + }, + "containsUserData": { + "type": "boolean", + "nullable": true, + "description": "Whether the StorageBucket contains user data" + }, + "isVersioned": { + "type": "boolean", + "nullable": true, + "description": "Whether the StorageBucket is versioned" } }, "required": [ - "results" + "responseType", + "resourceKind", + "resourceId", + "connectionId", + "displayName", + "owner", + "inScope", + "description", + "creationDate", + "account", + "region", + "isEncrypted", + "containsEphi", + "containsUserData", + "isVersioned" ], "type": "object", "additionalProperties": false }, - "Group": { + "Account": { "properties": { - "id": { + "responseType": { + "$ref": "#/components/schemas/ResourceResponseType" + }, + "resourceKind": { "type": "string", - "description": "The group's unique ID." + "description": "The identifier for the resource type, unique within the scope of an Integration." }, - "name": { + "resourceId": { "type": "string", - "description": "The group's name." + "description": "The unique identifier for the Resource." }, - "creationDate": { + "connectionId": { "type": "string", - "format": "date-time", "nullable": true, - "description": "The group's creation date." - } - }, - "required": [ - "id", - "name", - "creationDate" - ], - "type": "object", - "additionalProperties": false - }, - "PaginatedResponse_Group_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Group" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" - } - }, - "required": [ - "results" - ], - "type": "object", - "additionalProperties": false - }, - "Framework": { - "properties": { - "id": { - "type": "string", - "description": "The framework's unique ID." + "description": "The unique identifier for the Connection used to ingest the Resource if it exists." }, "displayName": { "type": "string", - "description": "The framework's display name." + "description": "The Resource's display name." }, - "shorthandName": { + "owner": { "type": "string", - "description": "The short version of the framework's display name." + "nullable": true, + "description": "The unique identifier for the owner of the resource in Vanta." + }, + "inScope": { + "type": "boolean", + "description": "Whether the resource is in scope for audits." }, "description": { "type": "string", - "description": "The framework's description." + "nullable": true, + "description": "The description of the resource in Vanta." }, - "numControlsCompleted": { - "type": "number", - "format": "double", - "description": "The number of completed controls in the framework." + "creationDate": { + "type": "string", + "format": "date-time", + "description": "When Vanta first ingested the Resource." }, - "numControlsTotal": { - "type": "number", - "format": "double", - "description": "The total number of controls in the framework." + "deletedDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "numDocumentsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing documents in the framework." + "accountName": { + "type": "string", + "description": "Name associated with the Account" }, - "numDocumentsTotal": { - "type": "number", - "format": "double", - "description": "The total number of documents in the framework." + "roles": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Any role(s) assigned to the Account" }, - "numTestsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing tests in the framework." + "groups": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Any groups to which the Account belongs" }, - "numTestsTotal": { - "type": "number", - "format": "double", - "description": "The total number of tests in the framework." + "isDeactivated": { + "type": "boolean", + "description": "Whether the account has been deactivated/disabled/deleted." + }, + "isMfaEnabled": { + "type": "boolean", + "nullable": true, + "description": "Whether MFA has been enabled for the account." } }, "required": [ - "id", + "responseType", + "resourceKind", + "resourceId", + "connectionId", "displayName", - "shorthandName", + "owner", + "inScope", "description", - "numControlsCompleted", - "numControlsTotal", - "numDocumentsPassing", - "numDocumentsTotal", - "numTestsPassing", - "numTestsTotal" + "creationDate", + "accountName", + "roles", + "groups", + "isDeactivated", + "isMfaEnabled" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Framework_": { + "AccessKeyInfo": { "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Framework" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "accessKeyId": { + "type": "string", + "description": "The access key ID" + }, + "status": { + "type": "string", + "description": "The status of the access key" } }, "required": [ - "results" + "accessKeyId", + "status" ], "type": "object", "additionalProperties": false }, - "FrameworkRequirementCategory": { + "AwsAccount": { "properties": { - "id": { - "type": "string", - "description": "The framework's requiremet category unique ID." + "responseType": { + "$ref": "#/components/schemas/ResourceResponseType" }, - "name": { + "resourceKind": { "type": "string", - "description": "The framework's requiremet category name." + "description": "The identifier for the resource type, unique within the scope of an Integration." }, - "shorthand": { + "resourceId": { "type": "string", - "nullable": true, - "description": "The framework's short name." + "description": "The unique identifier for the Resource." }, - "requirements": { - "items": { - "properties": { - "controls": { - "items": { - "properties": { - "description": { - "type": "string", - "description": "The control's description." - }, - "name": { - "type": "string", - "description": "The control's name." - }, - "externalId": { - "type": "string", - "nullable": true, - "description": "The control's external ID." - }, - "id": { - "type": "string", - "description": "The control's unique ID." - } - }, - "required": [ - "description", - "name", - "externalId", - "id" - ], - "type": "object" - }, - "type": "array", - "description": "The requirement's list of controls" - }, - "description": { - "type": "string", - "nullable": true, - "description": "The requirement's description" - }, - "shorthand": { - "type": "string", - "nullable": true, - "description": "The requirement's short name." - }, - "name": { - "type": "string", - "description": "The requirement's name." - }, - "id": { - "type": "string", - "description": "The requirement's unique ID." - } - }, - "required": [ - "controls", - "description", - "shorthand", - "name", - "id" - ], - "type": "object" - }, - "type": "array" - } - }, - "required": [ - "id", - "name", - "shorthand", - "requirements" - ], - "type": "object", - "additionalProperties": false - }, - "FrameworkDetail": { - "properties": { - "id": { + "connectionId": { "type": "string", - "description": "The framework's unique ID." + "nullable": true, + "description": "The unique identifier for the Connection used to ingest the Resource if it exists." }, "displayName": { "type": "string", - "description": "The framework's display name." + "description": "The Resource's display name." }, - "shorthandName": { + "owner": { "type": "string", - "description": "The short version of the framework's display name." + "nullable": true, + "description": "The unique identifier for the owner of the resource in Vanta." + }, + "inScope": { + "type": "boolean", + "description": "Whether the resource is in scope for audits." }, "description": { "type": "string", - "description": "The framework's description." + "nullable": true, + "description": "The description of the resource in Vanta." }, - "numControlsCompleted": { - "type": "number", - "format": "double", - "description": "The number of completed controls in the framework." + "creationDate": { + "type": "string", + "format": "date-time", + "description": "When Vanta first ingested the Resource." }, - "numControlsTotal": { - "type": "number", - "format": "double", - "description": "The total number of controls in the framework." + "deletedDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." }, - "numDocumentsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing documents in the framework." + "accountName": { + "type": "string", + "description": "Name associated with the Account" }, - "numDocumentsTotal": { - "type": "number", - "format": "double", - "description": "The total number of documents in the framework." + "roles": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Any role(s) assigned to the Account" }, - "numTestsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing tests in the framework." + "groups": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Any groups to which the Account belongs" }, - "numTestsTotal": { - "type": "number", - "format": "double", - "description": "The total number of tests in the framework." + "isDeactivated": { + "type": "boolean", + "description": "Whether the account has been deactivated/disabled/deleted." }, - "requirementCategories": { + "isMfaEnabled": { + "type": "boolean", + "nullable": true, + "description": "Whether MFA has been enabled for the account." + }, + "awsUserAccountId": { + "type": "string", + "description": "The AWS user account ID associated with the account" + }, + "awsAccountNumber": { + "type": "string", + "description": "AWS account number (12 digit number) that uniquely identifies your AWS account" + }, + "accessKeys": { "items": { - "$ref": "#/components/schemas/FrameworkRequirementCategory" + "$ref": "#/components/schemas/AccessKeyInfo" }, "type": "array", - "description": "The famework's list of requirement categories." + "description": "The list of access keys associated with the AWS account" } }, "required": [ - "id", + "responseType", + "resourceKind", + "resourceId", + "connectionId", "displayName", - "shorthandName", + "owner", + "inScope", "description", - "numControlsCompleted", - "numControlsTotal", - "numDocumentsPassing", - "numDocumentsTotal", - "numTestsPassing", - "numTestsTotal", - "requirementCategories" + "creationDate", + "accountName", + "roles", + "groups", + "isDeactivated", + "isMfaEnabled", + "awsUserAccountId", + "awsAccountNumber", + "accessKeys" ], "type": "object", "additionalProperties": false }, - "ControlSource": { - "enum": [ - "Vanta", - "Custom" - ], - "type": "string" - }, - "Control": { + "OrganizationSubunit": { "properties": { - "id": { - "type": "string", - "description": "The control's unique ID." + "responseType": { + "$ref": "#/components/schemas/ResourceResponseType" }, - "externalId": { + "resourceKind": { "type": "string", - "nullable": true, - "description": "The control's external ID." + "description": "The identifier for the resource type, unique within the scope of an Integration." }, - "name": { + "resourceId": { "type": "string", - "description": "The control's name." + "description": "The unique identifier for the Resource." }, - "description": { + "connectionId": { "type": "string", - "description": "The control's description." - }, - "source": { - "$ref": "#/components/schemas/ControlSource", - "description": "The control's source, either \"VANTA\" or \"CUSTOM\"." + "nullable": true, + "description": "The unique identifier for the Connection used to ingest the Resource if it exists." }, - "domains": { - "items": { - "type": "string" - }, - "type": "array", - "description": "The security domains that the control belongs to." + "displayName": { + "type": "string", + "description": "The Resource's display name." }, "owner": { - "allOf": [ - { - "$ref": "#/components/schemas/Owner" - } - ], + "type": "string", "nullable": true, - "description": "The control's owner." + "description": "The unique identifier for the owner of the resource in Vanta." }, - "role": { + "inScope": { + "type": "boolean", + "description": "Whether the resource is in scope for audits." + }, + "description": { "type": "string", "nullable": true, - "description": "The control's GDPR role, if the control is a GDPR control." - }, - "customFields": { - "items": { - "$ref": "#/components/schemas/CustomField" - }, - "type": "array", - "description": "The control's custom field values, if control custom fields is included in your Vanta instance." + "description": "The description of the resource in Vanta." }, "creationDate": { "type": "string", "format": "date-time", - "nullable": true, - "description": "When the control was created. Returns null for Vanta library controls." + "description": "When Vanta first ingested the Resource." }, - "modificationDate": { + "deletedDate": { "type": "string", "format": "date-time", "nullable": true, - "description": "When the control was last modified. Returns null for Vanta library controls." + "description": "When the resource was deleted/removed from the integration, if applicable.\nThis field is only present when the resource has been deleted." + }, + "accountId": { + "type": "string", + "nullable": true, + "description": "Account ID corresponding to the subunit. Could be null if the subunit is not an account, e.g. a subscription" } }, "required": [ - "id", - "externalId", - "name", - "description", - "source", - "domains", + "responseType", + "resourceKind", + "resourceId", + "connectionId", + "displayName", "owner", - "customFields", + "inScope", + "description", "creationDate", - "modificationDate" + "accountId" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Control_": { + "AnyResource": { + "anyOf": [ + { + "$ref": "#/components/schemas/Resource" + }, + { + "$ref": "#/components/schemas/CloudInfrastructure" + }, + { + "$ref": "#/components/schemas/ContainerRepository" + }, + { + "$ref": "#/components/schemas/Database" + }, + { + "$ref": "#/components/schemas/Device" + }, + { + "$ref": "#/components/schemas/PaaS" + }, + { + "$ref": "#/components/schemas/Queue" + }, + { + "$ref": "#/components/schemas/StorageBucket" + }, + { + "$ref": "#/components/schemas/Account" + }, + { + "$ref": "#/components/schemas/AwsAccount" + }, + { + "$ref": "#/components/schemas/OrganizationSubunit" + } + ] + }, + "PaginatedResponse_AnyResource_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/Control" + "$ref": "#/components/schemas/AnyResource" }, "type": "array" }, @@ -9874,90 +10802,75 @@ "type": "object", "additionalProperties": false }, - "PaginationArgs": { - "properties": { - "pageSize": { - "$ref": "#/components/schemas/PageSize" - }, - "pageCursor": { - "$ref": "#/components/schemas/PageCursor" - } - }, - "type": "object", - "additionalProperties": false - }, - "EventLog": { + "Group": { "properties": { "id": { "type": "string", - "description": "The event log's unique ID." + "description": "The group's unique ID." }, - "actor": { - "properties": { - "type": { - "type": "string", - "description": "The actor's type." - }, - "id": { - "type": "string", - "description": "The actor's unique ID." - } - }, - "required": [ - "type", - "id" - ], - "type": "object", - "description": "The event's initiator." + "name": { + "type": "string", + "description": "The group's name." }, - "date": { + "creationDate": { "type": "string", "format": "date-time", - "description": "The event's creation date." + "nullable": true, + "description": "The group's creation date." }, - "action": { + "description": { "type": "string", - "description": "The event's action." + "nullable": true, + "description": "The group's description." }, - "targets": { - "items": { - "properties": { - "type": { - "type": "string", - "description": "The target's type." - }, - "id": { - "type": "string", - "description": "The target's unique ID." - } + "source": { + "type": "string", + "description": "The source that created the group. Manually created groups are set to \"Vanta\"; groups imported from an external source use that source's display name." + }, + "personnelCount": { + "type": "number", + "format": "double", + "description": "The number of personnel in the group." + }, + "pointOfContact": { + "properties": { + "email": { + "type": "string", + "description": "The point of contact's email address." }, - "required": [ - "type", - "id" - ], - "type": "object" + "displayName": { + "type": "string", + "description": "The point of contact's display name." + } }, - "type": "array", - "description": "The list of targets of the event." + "required": [ + "email", + "displayName" + ], + "type": "object", + "nullable": true, + "description": "The group's point of contact." } }, "required": [ "id", - "actor", - "date", - "action", - "targets" + "name", + "creationDate", + "description", + "source", + "personnelCount", + "pointOfContact" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_EventLog_": { + "PaginatedResponse_Group_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/EventLog" + "$ref": "#/components/schemas/Group" }, "type": "array" }, @@ -9978,345 +10891,299 @@ "type": "object", "additionalProperties": false }, - "DocumentStatus": { - "type": "string", - "enum": [ - "Needs document", - "Needs update", - "Not relevant", - "OK" - ] - }, - "Document": { + "ImportableIdpGroup": { "properties": { "id": { - "type": "string", - "description": "The document's unique ID." - }, - "ownerId": { - "type": "string", - "nullable": true, - "description": "The user ID of the document's owner." - }, - "category": { - "$ref": "#/components/schemas/DocumentAndTestCategory", - "description": "The document's category." - }, - "description": { - "type": "string", - "description": "The document's description." - }, - "isSensitive": { - "type": "boolean", - "description": "Determines whether or not the document is sensitive." - }, - "title": { - "type": "string", - "description": "The document's title." + "type": "string" }, - "uploadStatus": { - "$ref": "#/components/schemas/DocumentStatus", - "description": "The document's status." + "name": { + "type": "string" }, - "uploadStatusDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the document's uploadStatus changed." + "integrationId": { + "type": "string" }, - "url": { + "externalAccountId": { "type": "string", - "nullable": true, - "description": "The URL to view the document within Vanta." + "nullable": true } }, "required": [ "id", - "ownerId", - "category", - "description", - "isSensitive", - "title", - "uploadStatus", - "uploadStatusDate", - "url" + "name", + "integrationId", + "externalAccountId" ], "type": "object", "additionalProperties": false }, - "SetOwnerForDocumentInput": { + "PaginatedImportableIdpGroupResponse": { "properties": { - "userId": { - "type": "string", - "nullable": true, - "description": "The new owner ID" + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/ImportableIdpGroup" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, "required": [ - "userId" + "results" ], "type": "object", "additionalProperties": false }, - "TimeSensitivity": { - "enum": [ - "MOST_RECENT", - "DURING_AUDIT_WINDOW" - ], - "type": "string" - }, - "RecurrenceDuration": { - "enum": [ - "P0D", - "P1D", - "P1W", - "P1M", - "P3M", - "P6M", - "P1Y", - "P2Y" + "ImportIdpGroupSuccess": { + "properties": { + "idpGroupId": { + "type": "string" + }, + "status": { + "type": "string", + "enum": [ + "SUCCESS" + ], + "nullable": false + }, + "groupId": { + "type": "string" + } + }, + "required": [ + "idpGroupId", + "status", + "groupId" ], - "type": "string" - }, - "CadenceType": { - "$ref": "#/components/schemas/RecurrenceDuration" + "type": "object", + "additionalProperties": false }, - "ReminderWindow": { + "ImportIdpGroupFailureReason": { "enum": [ - "P0D", - "P1D", - "P1W", - "P1M", - "P3M" + "NOT_FOUND", + "IMPORT_FAILED" ], "type": "string" }, - "CreateDocumentInput": { + "ImportIdpGroupError": { "properties": { - "title": { - "type": "string", - "description": "The document's title." + "idpGroupId": { + "type": "string" }, - "description": { + "status": { "type": "string", - "description": "The document's description." - }, - "timeSensitivity": { - "$ref": "#/components/schemas/TimeSensitivity", - "description": "When to upload the document.\nMust be one of: \"Most recent\", \"During audit window\"" + "enum": [ + "ERROR" + ], + "nullable": false }, - "cadence": { - "$ref": "#/components/schemas/CadenceType", - "description": "How often the document needs to be renewed.\n\nNever: P0D - The document does not need to be renewed.\nDaily: P1D - The document needs to be renewed daily.\nWeekly: P1W - The document needs to be renewed weekly.\nMonthly: P1M - The document needs to be renewed monthly.\nQuarterly: P3M - The document needs to be renewed quarterly.\nBiannually: P6M - The document needs to be renewed biannually.\nAnnually: P1Y - The document needs to be renewed annually." + "reason": { + "$ref": "#/components/schemas/ImportIdpGroupFailureReason" }, - "reminderWindow": { - "$ref": "#/components/schemas/ReminderWindow", - "description": "The number of days before the renewal date to send a reminder.\nNote that reminderWindow should be smaller than the cadence.\n\nOptions are:\nNever: P0D - No reminder will be sent.\nDay: P1D - A reminder will be sent one day before the renewal date.\nWeek: P1W - A reminder will be sent one week before the renewal date.\nMonth: P1M - A reminder will be sent one month before the renewal date.\nQuarter: P3M - A reminder will be sent one quarter before the renewal date." + "message": { + "type": "string" + } + }, + "required": [ + "idpGroupId", + "status", + "reason", + "message" + ], + "type": "object", + "additionalProperties": false + }, + "ImportIdpGroupResult": { + "anyOf": [ + { + "$ref": "#/components/schemas/ImportIdpGroupSuccess" }, - "isSensitive": { - "type": "boolean", - "description": "Determines whether or not the document is sensitive.\nThis restricts which users can access or upload files to the document.\nOnly admins are able to view or upload sensitive documents." + { + "$ref": "#/components/schemas/ImportIdpGroupError" + } + ] + }, + "ImportIdpGroupsResponse": { + "properties": { + "results": { + "items": { + "$ref": "#/components/schemas/ImportIdpGroupResult" + }, + "type": "array" } }, "required": [ - "title", - "description", - "timeSensitivity", - "cadence", - "reminderWindow", - "isSensitive" + "results" ], "type": "object", "additionalProperties": false }, - "UploadedLink": { + "CreatedFramework": { "properties": { "id": { "type": "string", - "description": "The link's unique ID" - }, - "creationDate": { - "type": "string", - "format": "date-time", - "description": "The link's creation date." - }, - "effectiveDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The link's effective date." - }, - "title": { - "type": "string", - "description": "The link's title." - }, - "url": { - "type": "string", - "description": "The link's URL." - }, - "description": { - "type": "string", - "description": "The link's description." + "description": "The created framework's unique ID." } }, "required": [ - "id", - "creationDate", - "effectiveDate", - "title", - "url", - "description" + "id" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_UploadedLink_": { + "CreateFrameworkSectionInput": { + "description": "One section of a custom framework being created.\n\nSections are identified by `shortName`, which must be unique within the\nrequest; nesting and control mappings both reference it.", "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/UploadedLink" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } + "name": { + "type": "string", + "description": "The section's display name." + }, + "shortName": { + "type": "string", + "description": "Unique identifier for this section within the request." + }, + "description": { + "type": "string", + "nullable": true, + "description": "Optional description of the section." + }, + "parentShortName": { + "type": "string", + "nullable": true, + "description": "The `shortName` of this section's parent, for a nested section, or `null`\nfor a top-level section. Must match a `shortName` present in this request." + }, + "controlShorthandNames": { + "items": { + "type": "string" }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" + "type": "array", + "description": "External IDs of existing controls to map to this section. Each must match\na control that already exists in your organization." } }, "required": [ - "results" + "name", + "shortName", + "description", + "parentShortName", + "controlShorthandNames" ], "type": "object", "additionalProperties": false }, - "CreateLinkForDocumentInput": { + "CreateFrameworkInput": { "properties": { - "url": { - "type": "string", - "description": "The link's URL" - }, - "title": { + "name": { "type": "string", - "description": "The link's title." + "description": "The framework's display name. Must be unique within your organization." }, "description": { "type": "string", - "nullable": true, - "description": "The link's description." + "description": "A description of what the framework covers." }, - "effectiveDate": { + "shortName": { "type": "string", - "format": "date-time", "nullable": true, - "description": "The link's effective date." + "description": "Optional short name used to abbreviate the framework in the UI." + }, + "sections": { + "items": { + "$ref": "#/components/schemas/CreateFrameworkSectionInput" + }, + "type": "array", + "description": "The framework's sections.", + "minItems": 1, + "maxItems": 500 } }, "required": [ - "url", - "title" + "name", + "description", + "shortName", + "sections" ], "type": "object", "additionalProperties": false }, - "UploadedFileT": { + "Framework": { "properties": { "id": { "type": "string", - "description": "Unique identifier for the document." + "description": "The framework's unique ID." }, - "fileName": { + "displayName": { "type": "string", - "nullable": true, - "description": "The file name of the document." + "description": "The framework's display name." }, - "title": { + "shorthandName": { "type": "string", - "description": "The document's title." + "description": "The short version of the framework's display name." }, "description": { "type": "string", - "nullable": true, - "description": "The document's description" - }, - "mimeType": { - "type": "string", - "description": "Mime type of the document." + "description": "The framework's description." }, - "uploadedBy": { - "properties": { - "type": { - "$ref": "#/components/schemas/UploadedDocumentUploadedByType" - }, - "id": { - "type": "string" - } - }, - "required": [ - "type", - "id" - ], - "type": "object", - "nullable": true, - "description": "The actor who uploaded this document. It could be a user or an app." + "numControlsCompleted": { + "type": "number", + "format": "double", + "description": "The number of completed controls in the framework." }, - "creationDate": { - "type": "string", - "format": "date-time", - "description": "Date of when the document was uploaded." + "numControlsTotal": { + "type": "number", + "format": "double", + "description": "The total number of controls in the framework." }, - "updatedDate": { - "type": "string", - "format": "date-time", - "description": "Date when the document was last updated." + "numDocumentsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing documents in the framework." }, - "deletionDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "Date of when the document was deleted. Is set to null if the document has not been deleted." + "numDocumentsTotal": { + "type": "number", + "format": "double", + "description": "The total number of documents in the framework." }, - "effectiveDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The document's effective date." + "numTestsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing tests in the framework." }, - "url": { - "type": "string", - "description": "The document's URL." + "numTestsTotal": { + "type": "number", + "format": "double", + "description": "The total number of tests in the framework." } }, "required": [ "id", - "fileName", - "title", + "displayName", + "shorthandName", "description", - "mimeType", - "uploadedBy", - "creationDate", - "updatedDate", - "deletionDate", - "effectiveDate", - "url" + "numControlsCompleted", + "numControlsTotal", + "numDocumentsPassing", + "numDocumentsTotal", + "numTestsPassing", + "numTestsTotal" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Document_": { + "PaginatedResponse_Framework_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/Document" + "$ref": "#/components/schemas/Framework" }, "type": "array" }, @@ -10337,138 +11204,266 @@ "type": "object", "additionalProperties": false }, - "DocumentDetail": { + "FrameworkRequirementCategory": { "properties": { "id": { "type": "string", - "description": "The document's unique ID." - }, - "ownerId": { - "type": "string", - "nullable": true, - "description": "The user ID of the document's owner." - }, - "category": { - "$ref": "#/components/schemas/DocumentAndTestCategory", - "description": "The document's category." - }, - "description": { - "type": "string", - "description": "The document's description." - }, - "isSensitive": { - "type": "boolean", - "description": "Determines whether or not the document is sensitive." - }, - "title": { - "type": "string", - "description": "The document's title." - }, - "uploadStatus": { - "$ref": "#/components/schemas/DocumentStatus", - "description": "The document's status." + "description": "The framework's requiremet category unique ID." }, - "uploadStatusDate": { + "name": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the document's uploadStatus changed." + "description": "The framework's requiremet category name." }, - "url": { + "shorthand": { "type": "string", "nullable": true, - "description": "The URL to view the document within Vanta." + "description": "The framework's short name." }, - "deactivatedStatus": { - "properties": { - "creationDate": { - "type": "string", - "format": "date-time", - "description": "The date the document was deactivated." - }, - "expiration": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the deactivation expires." - }, - "reason": { - "type": "string", - "nullable": true, - "description": "The reason for the document was deactivated." - }, - "isDeactivated": { - "type": "boolean", - "description": "Determines whether or not the document is deactivated." - } - }, - "required": [ - "creationDate", - "expiration", - "reason", - "isDeactivated" - ], - "type": "object" + "requirements": { + "items": { + "properties": { + "controls": { + "items": { + "properties": { + "description": { + "type": "string", + "description": "The control's description." + }, + "name": { + "type": "string", + "description": "The control's name." + }, + "externalId": { + "type": "string", + "nullable": true, + "description": "The control's external ID." + }, + "id": { + "type": "string", + "description": "The control's unique ID." + } + }, + "required": [ + "description", + "name", + "externalId", + "id" + ], + "type": "object" + }, + "type": "array", + "description": "The requirement's list of controls" + }, + "description": { + "type": "string", + "nullable": true, + "description": "The requirement's description" + }, + "shorthand": { + "type": "string", + "nullable": true, + "description": "The requirement's short name." + }, + "name": { + "type": "string", + "description": "The requirement's name." + }, + "id": { + "type": "string", + "description": "The requirement's unique ID." + } + }, + "required": [ + "controls", + "description", + "shorthand", + "name", + "id" + ], + "type": "object" + }, + "type": "array" + } + }, + "required": [ + "id", + "name", + "shorthand", + "requirements" + ], + "type": "object", + "additionalProperties": false + }, + "FrameworkDetail": { + "properties": { + "id": { + "type": "string", + "description": "The framework's unique ID." }, - "note": { + "displayName": { "type": "string", - "nullable": true, - "description": "A user note for the document." + "description": "The framework's display name." }, - "nextRenewalDate": { + "shorthandName": { + "type": "string", + "description": "The short version of the framework's display name." + }, + "description": { + "type": "string", + "description": "The framework's description." + }, + "numControlsCompleted": { + "type": "number", + "format": "double", + "description": "The number of completed controls in the framework." + }, + "numControlsTotal": { + "type": "number", + "format": "double", + "description": "The total number of controls in the framework." + }, + "numDocumentsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing documents in the framework." + }, + "numDocumentsTotal": { + "type": "number", + "format": "double", + "description": "The total number of documents in the framework." + }, + "numTestsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing tests in the framework." + }, + "numTestsTotal": { + "type": "number", + "format": "double", + "description": "The total number of tests in the framework." + }, + "requirementCategories": { + "items": { + "$ref": "#/components/schemas/FrameworkRequirementCategory" + }, + "type": "array", + "description": "The famework's list of requirement categories." + } + }, + "required": [ + "id", + "displayName", + "shorthandName", + "description", + "numControlsCompleted", + "numControlsTotal", + "numDocumentsPassing", + "numDocumentsTotal", + "numTestsPassing", + "numTestsTotal", + "requirementCategories" + ], + "type": "object", + "additionalProperties": false + }, + "ControlSource": { + "enum": [ + "Vanta", + "Custom" + ], + "type": "string" + }, + "Control": { + "properties": { + "id": { + "type": "string", + "description": "The control's unique ID." + }, + "externalId": { "type": "string", - "format": "date-time", "nullable": true, - "description": "When the document needs to be renewed." + "description": "The control's external ID." }, - "renewalCadence": { - "$ref": "#/components/schemas/CadenceType", - "description": "How often a document must be renewed." + "name": { + "type": "string", + "description": "The control's name." }, - "reminderWindow": { + "description": { + "type": "string", + "description": "The control's description." + }, + "source": { + "$ref": "#/components/schemas/ControlSource", + "description": "The control's source, either \"VANTA\" or \"CUSTOM\"." + }, + "domains": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The security domains that the control belongs to." + }, + "owner": { "allOf": [ { - "$ref": "#/components/schemas/ReminderWindow" + "$ref": "#/components/schemas/Owner" } ], "nullable": true, - "description": "The number of day ahead of the renewal date to send a reminder." + "description": "The control's owner." }, - "subscribers": { + "role": { + "type": "string", + "nullable": true, + "description": "The control's GDPR role, if the control is a GDPR control." + }, + "customFields": { "items": { - "type": "string" + "$ref": "#/components/schemas/CustomField" }, "type": "array", - "description": "A list of the emails subscribed to the document." + "description": "The control's custom field values, if control custom fields is included in your Vanta instance." + }, + "creationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was created. Returns null for Vanta library controls." + }, + "modificationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was last modified. Returns null for Vanta library controls." + }, + "implementationDetails": { + "type": "string", + "nullable": true, + "description": "How the control is implemented." } }, "required": [ "id", - "ownerId", - "category", + "externalId", + "name", "description", - "isSensitive", - "title", - "uploadStatus", - "uploadStatusDate", - "url", - "deactivatedStatus", - "note", - "nextRenewalDate", - "renewalCadence", - "reminderWindow", - "subscribers" + "source", + "domains", + "owner", + "customFields", + "creationDate", + "modificationDate" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_UploadedFileT_": { + "PaginatedResponse_Control_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/UploadedFileT" + "$ref": "#/components/schemas/Control" }, "type": "array" }, @@ -10489,136 +11484,90 @@ "type": "object", "additionalProperties": false }, - "DiscoveredVendorSource": { - "description": "The source of the discovered vendor.\nOKTA: The vendor was discovered via an Okta integration\nJAMF: The vendor was discovered via a JAMF integration\nGSUITE: The vendor was discovered via an GSuite integration\nVENDR: The vendor was discovered via a Vendr integration\nOFFICE: The vendor was discovered via a microsoft office integration", - "enum": [ - "OKTA", - "JAMF", - "GSUITE", - "VENDR", - "OFFICE" - ], - "type": "string" - }, - "DiscoveredVendor": { + "PaginationArgs": { "properties": { - "id": { - "type": "string", - "description": "The discovered vendor's unique ID." - }, - "name": { - "type": "string", - "description": "The discovered vendor's display name ." + "pageSize": { + "$ref": "#/components/schemas/PageSize" }, - "normalizedName": { + "pageCursor": { + "$ref": "#/components/schemas/PageCursor" + } + }, + "type": "object", + "additionalProperties": false + }, + "EventLog": { + "properties": { + "id": { "type": "string", - "description": "The discovered vendor's vendorNormalized or canonical name. This is used to group duplicate vendors together." + "description": "The event log's unique ID." }, - "category": { + "actor": { "properties": { - "name": { - "type": "string" + "type": { + "type": "string", + "description": "The actor's type." + }, + "id": { + "type": "string", + "description": "The actor's unique ID." } }, "required": [ - "name" + "type", + "id" ], "type": "object", - "nullable": true, - "description": "The discovered vendor's category." - }, - "source": { - "$ref": "#/components/schemas/DiscoveredVendorSource", - "description": "The discovered vendor's source ." + "description": "The event's initiator." }, - "discoveredDate": { + "date": { "type": "string", "format": "date-time", - "description": "The discovered vendor's imported date." - }, - "numberOfAccounts": { - "type": "number", - "format": "double", - "description": "The number of accounts in the discovered vendor." + "description": "The event's creation date." }, - "ignored": { - "properties": { - "ignoredAtDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the discovered vendor was marked as ignored." - }, - "ignoredReason": { - "type": "string", - "nullable": true, - "description": "The reason the discovered vendor was ignored." - }, - "ignoredByUserId": { - "type": "string", - "nullable": true, - "description": "The user ID who ignored the discovered vendor." - } - }, - "required": [ - "ignoredAtDate", - "ignoredReason", - "ignoredByUserId" - ], - "type": "object", - "nullable": true, - "description": "Determines whether or not the vendor is ignored." + "action": { + "type": "string", + "description": "The event's action." }, - "rejected": { - "properties": { - "rejectedByUserId": { - "type": "string", - "nullable": true, - "description": "The user ID who rejected the discovered vendor." - }, - "rejectedReason": { - "type": "string", - "nullable": true, - "description": "The reason the discovered vendor was rejected." + "targets": { + "items": { + "properties": { + "type": { + "type": "string", + "description": "The target's type." + }, + "id": { + "type": "string", + "description": "The target's unique ID." + } }, - "rejectedAtDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date the discovered vendor was marked as rejected." - } + "required": [ + "type", + "id" + ], + "type": "object" }, - "required": [ - "rejectedByUserId", - "rejectedReason", - "rejectedAtDate" - ], - "type": "object", - "nullable": true, - "description": "Determines whether or not the vendor is rejected." + "type": "array", + "description": "The list of targets of the event." } }, "required": [ "id", - "name", - "normalizedName", - "category", - "source", - "discoveredDate", - "numberOfAccounts", - "ignored", - "rejected" + "actor", + "date", + "action", + "targets" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_DiscoveredVendor_": { + "PaginatedResponse_EventLog_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/DiscoveredVendor" + "$ref": "#/components/schemas/EventLog" }, "type": "array" }, @@ -10639,231 +11588,215 @@ "type": "object", "additionalProperties": false }, - "DiscoveredVendorScope": { - "description": "The scope of a discovered vendor.\nNEEDS_REVIEW: The vendor needs review\nIGNORED: The vendor was ignored\nREJECTED: The vendor was rejected", - "enum": [ - "NEEDS_REVIEW", - "IGNORED", - "REJECTED" - ], - "type": "string" - }, - "DiscoveredVendorAccountType.USER": { + "DocumentStatus": { + "type": "string", "enum": [ - "USER" - ], - "type": "string" + "Needs document", + "Needs update", + "Not relevant", + "OK" + ] }, - "DiscoveredVendorUser": { + "Document": { "properties": { "id": { "type": "string", - "description": "The associated user's unique ID." + "description": "The document's unique ID." }, - "email": { + "ownerId": { "type": "string", - "description": "The associated user's email address." + "nullable": true, + "description": "The user ID of the document's owner." }, - "displayName": { + "category": { + "$ref": "#/components/schemas/DocumentAndTestCategory", + "description": "The document's category." + }, + "description": { "type": "string", - "description": "The associated user's display name ." + "description": "The document's description." }, - "type": { - "$ref": "#/components/schemas/DiscoveredVendorAccountType.USER", - "description": "The account type." + "isSensitive": { + "type": "boolean", + "description": "Determines whether or not the document is sensitive." + }, + "title": { + "type": "string", + "description": "The document's title." + }, + "uploadStatus": { + "$ref": "#/components/schemas/DocumentStatus", + "description": "The document's status." + }, + "uploadStatusDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date the document's uploadStatus changed." + }, + "url": { + "type": "string", + "nullable": true, + "description": "The URL to view the document within Vanta." } }, "required": [ "id", - "email", - "displayName", - "type" + "ownerId", + "category", + "description", + "isSensitive", + "title", + "uploadStatus", + "uploadStatusDate", + "url" ], "type": "object", "additionalProperties": false }, - "DiscoveredVendorAccountType.COMPUTER": { - "enum": [ - "COMPUTER" - ], - "type": "string" - }, - "DiscoveredVendorComputer": { + "SetOwnerForDocumentInput": { "properties": { - "id": { - "type": "string", - "description": "The associated computer's unique ID." - }, - "displayName": { + "userId": { "type": "string", - "description": "The associated computer's display name." - }, - "owner": { - "allOf": [ - { - "$ref": "#/components/schemas/DiscoveredVendorUser" - } - ], "nullable": true, - "description": "The associated computer's owner." - }, - "type": { - "$ref": "#/components/schemas/DiscoveredVendorAccountType.COMPUTER", - "description": "The account type." + "description": "The new owner ID" } }, "required": [ - "id", - "owner", - "type" + "userId" ], "type": "object", "additionalProperties": false }, - "DiscoveredVendorAccount": { - "anyOf": [ - { - "$ref": "#/components/schemas/DiscoveredVendorUser" - }, - { - "$ref": "#/components/schemas/DiscoveredVendorComputer" - } - ] - }, - "PaginatedResponse_DiscoveredVendorAccount_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/DiscoveredVendorAccount" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" - } - }, - "required": [ - "results" + "TimeSensitivity": { + "enum": [ + "MOST_RECENT", + "DURING_AUDIT_WINDOW" ], - "type": "object", - "additionalProperties": false + "type": "string" }, - "UserDefinedTagCategory": { - "properties": { - "id": { - "type": "string" - }, - "displayName": { - "type": "string" - } - }, - "required": [ - "id", - "displayName" + "RecurrenceDuration": { + "enum": [ + "P0D", + "P1D", + "P1W", + "P1M", + "P3M", + "P6M", + "P1Y", + "P2Y" ], - "type": "object", - "additionalProperties": false + "type": "string" }, - "ArrayResponse_UserDefinedTagCategory_": { - "properties": { - "results": { - "items": { - "$ref": "#/components/schemas/UserDefinedTagCategory" - }, - "type": "array" - } - }, - "required": [ - "results" - ], - "type": "object", - "additionalProperties": false + "CadenceType": { + "$ref": "#/components/schemas/RecurrenceDuration" }, - "CustomerTrustProductContextIdFilter": { - "type": "string", + "ReminderWindow": { "enum": [ - "EXTERNAL_TRUST_CENTER", - "DOCUMENT_SHARING", - "QUESTIONNAIRE" - ] + "P0D", + "P1D", + "P1W", + "P1M", + "P3M" + ], + "type": "string" }, - "UserDefinedTag": { + "CreateDocumentInput": { "properties": { - "id": { - "type": "string" + "title": { + "type": "string", + "description": "The document's title." }, - "category": { - "type": "string" + "description": { + "type": "string", + "description": "The document's description." }, - "displayName": { - "type": "string" - } - }, - "required": [ - "id", - "category", - "displayName" - ], - "type": "object", - "additionalProperties": false - }, - "TagCategoryWithTags": { - "properties": { - "category": { - "$ref": "#/components/schemas/UserDefinedTagCategory" + "timeSensitivity": { + "$ref": "#/components/schemas/TimeSensitivity", + "description": "When to upload the document.\nMust be one of: \"Most recent\", \"During audit window\"" }, - "tags": { - "items": { - "$ref": "#/components/schemas/UserDefinedTag" - }, - "type": "array" + "cadence": { + "$ref": "#/components/schemas/CadenceType", + "description": "How often the document needs to be renewed.\n\nNever: P0D - The document does not need to be renewed.\nDaily: P1D - The document needs to be renewed daily.\nWeekly: P1W - The document needs to be renewed weekly.\nMonthly: P1M - The document needs to be renewed monthly.\nQuarterly: P3M - The document needs to be renewed quarterly.\nBiannually: P6M - The document needs to be renewed biannually.\nAnnually: P1Y - The document needs to be renewed annually." + }, + "reminderWindow": { + "$ref": "#/components/schemas/ReminderWindow", + "description": "The number of days before the renewal date to send a reminder.\nNote that reminderWindow should be smaller than the cadence.\n\nOptions are:\nNever: P0D - No reminder will be sent.\nDay: P1D - A reminder will be sent one day before the renewal date.\nWeek: P1W - A reminder will be sent one week before the renewal date.\nMonth: P1M - A reminder will be sent one month before the renewal date.\nQuarter: P3M - A reminder will be sent one quarter before the renewal date." + }, + "isSensitive": { + "type": "boolean", + "description": "Determines whether or not the document is sensitive.\nThis restricts which users can access or upload files to the document.\nOnly admins are able to view or upload sensitive documents." } }, "required": [ - "category", - "tags" + "title", + "description", + "timeSensitivity", + "cadence", + "reminderWindow", + "isSensitive" ], "type": "object", "additionalProperties": false }, - "QuestionnaireAssignableUser": { + "UploadedLink": { "properties": { "id": { - "type": "string" + "type": "string", + "description": "The link's unique ID" }, - "displayName": { - "type": "string" + "creationDate": { + "type": "string", + "format": "date-time", + "description": "The link's creation date." + }, + "effectiveDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The link's effective date." + }, + "title": { + "type": "string", + "description": "The link's title." + }, + "url": { + "type": "string", + "description": "The link's URL." + }, + "description": { + "type": "string", + "description": "The link's description." } }, "required": [ "id", - "displayName" + "creationDate", + "effectiveDate", + "title", + "url", + "description" ], "type": "object", "additionalProperties": false }, - "QuestionnaireAssignableUsersResponse": { + "PaginatedResponse_UploadedLink_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/QuestionnaireAssignableUser" + "$ref": "#/components/schemas/UploadedLink" }, "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" } }, "required": [ - "data" + "data", + "pageInfo" ], "type": "object" } @@ -10874,318 +11807,278 @@ "type": "object", "additionalProperties": false }, - "QuestionnaireAssignableUserRole": { - "type": "string", - "enum": [ - "owner", - "approver" - ] - }, - "CustomerTrustQuestionnaireType": { - "type": "string", - "enum": [ - "SPREADSHEET", - "WEBSITE", - "DOCUMENT" - ] - }, - "QuestionnaireStatus": { - "type": "string", - "enum": [ - "APPROVED", - "IN_PROGRESS", - "IN_REVIEW", - "READY_FOR_REVIEW", - "WAITING_ON_ANSWERS", - "ON_HOLD", - "NO_LONGER_NEEDED", - "COMPLETE", - "ERROR", - "EXTRACTING_QUESTIONS", - "QUEUED_FOR_EXTRACTION", - "PROCESSING", - "QUEUED_FOR_PROCESSING", - "WAITING_ON_COLUMN_SELECTION", - "WAITING_ON_COLUMN_APPROVAL", - "QUEUED_FOR_COLUMN_DETECTION", - "DETECTING_COLUMNS" - ] - }, - "QuestionnaireUser": { + "CreateLinkForDocumentInput": { "properties": { - "id": { - "type": "string" + "url": { + "type": "string", + "description": "The link's URL" }, - "displayName": { + "title": { "type": "string", - "nullable": true + "description": "The link's title." }, - "email": { + "description": { "type": "string", - "nullable": true + "nullable": true, + "description": "The link's description." + }, + "effectiveDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The link's effective date." } }, "required": [ - "id", - "displayName", - "email" + "url", + "title" ], "type": "object", "additionalProperties": false }, - "QuestionnaireStatusChangeEntry": { + "UploadedFileT": { "properties": { - "updatedBy": { - "$ref": "#/components/schemas/QuestionnaireUser", - "description": "The user who made the status change" - }, - "updatedAt": { + "id": { "type": "string", - "format": "date-time", - "description": "The date and time when the status was changed" - }, - "status": { - "$ref": "#/components/schemas/QuestionnaireStatus", - "description": "The new status of the questionnaire" + "description": "Unique identifier for the document." }, - "message": { + "fileName": { "type": "string", "nullable": true, - "description": "An optional message associated with the status change" - } - }, - "required": [ - "updatedBy", - "updatedAt", - "status", - "message" - ], - "type": "object", - "additionalProperties": false - }, - "ActorAssignment": { - "properties": { - "type": { - "type": "string", - "enum": [ - "User", - "Team" - ] - }, - "id": { - "type": "string" + "description": "The file name of the document." }, - "displayName": { + "title": { "type": "string", - "nullable": true - } - }, - "required": [ - "type", - "id", - "displayName" - ], - "type": "object", - "additionalProperties": false - }, - "CustomerTrustQuestionnaire": { - "properties": { - "id": { - "type": "string" - }, - "displayName": { - "type": "string" - }, - "url": { - "type": "string" - }, - "type": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaireType" - }, - "status": { - "$ref": "#/components/schemas/QuestionnaireStatus" - }, - "statusLog": { - "items": { - "$ref": "#/components/schemas/QuestionnaireStatusChangeEntry" - }, - "type": "array", - "description": "The status change history log for the questionnaire.\nEntries are ordered by the most recent status change first." - }, - "ownerAssignment": { - "$ref": "#/components/schemas/ActorAssignment", - "description": "The owner assignment in actor form (User or Team)." - }, - "approverAssignment": { - "$ref": "#/components/schemas/ActorAssignment", - "description": "The approver assignment in actor form (User or Team)." + "description": "The document's title." }, - "customerTrustAccountId": { - "type": "string" + "description": { + "type": "string", + "nullable": true, + "description": "The document's description" }, - "dueDate": { + "mimeType": { "type": "string", - "format": "date-time" + "description": "Mime type of the document." }, - "metadata": { - "items": { - "properties": { - "value": { - "type": "string" - }, - "key": { - "type": "string" - } + "uploadedBy": { + "properties": { + "type": { + "$ref": "#/components/schemas/UploadedDocumentUploadedByType" }, - "required": [ - "value", - "key" - ], - "type": "object" - }, - "type": "array" - }, - "tagAndCategoryIds": { - "items": { - "$ref": "#/components/schemas/TagInput" + "id": { + "type": "string" + } }, - "type": "array", - "description": "Tags assigned to this questionnaire. Each entry contains a categoryId and tagId." + "required": [ + "type", + "id" + ], + "type": "object", + "nullable": true, + "description": "The actor who uploaded this document. It could be a user or an app." }, - "createdDate": { + "creationDate": { "type": "string", - "format": "date-time" + "format": "date-time", + "description": "Date of when the document was uploaded." }, "updatedDate": { "type": "string", - "format": "date-time" + "format": "date-time", + "description": "Date when the document was last updated." }, - "completedDate": { + "deletionDate": { "type": "string", - "format": "date-time" - } - }, - "required": [ - "id", - "displayName", - "type", - "status", - "statusLog", - "tagAndCategoryIds", - "createdDate", - "updatedDate" - ], - "type": "object", - "additionalProperties": false - }, - "ActorAssignmentInput": { - "properties": { - "type": { + "format": "date-time", + "nullable": true, + "description": "Date of when the document was deleted. Is set to null if the document has not been deleted." + }, + "effectiveDate": { "type": "string", - "enum": [ - "User", - "Team" - ] + "format": "date-time", + "nullable": true, + "description": "The document's effective date." }, - "id": { - "type": "string" + "url": { + "type": "string", + "description": "The document's URL." } }, "required": [ - "type", - "id" + "id", + "fileName", + "title", + "description", + "mimeType", + "uploadedBy", + "creationDate", + "updatedDate", + "deletionDate", + "effectiveDate", + "url" ], "type": "object", "additionalProperties": false }, - "QuestionnaireMetadata": { + "PaginatedResponse_Document_": { "properties": { - "key": { - "type": "string" - }, - "value": { - "type": "string" + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/Document" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, "required": [ - "key", - "value" + "results" ], "type": "object", "additionalProperties": false }, - "CreateWebsiteQuestionnaireInput": { - "description": "Request body for creating a website-based questionnaire from a portal URL.", + "DocumentDetail": { "properties": { - "displayName": { + "id": { "type": "string", - "description": "Display name for the questionnaire." + "description": "The document's unique ID." }, - "url": { + "ownerId": { "type": "string", - "description": "The portal URL to create the questionnaire from." - }, - "ownerAssignment": { - "$ref": "#/components/schemas/ActorAssignmentInput", - "description": "Actor to assign as the owner (user or team)." + "nullable": true, + "description": "The user ID of the document's owner." }, - "approverAssignment": { - "$ref": "#/components/schemas/ActorAssignmentInput", - "description": "Actor to assign as the approver (user or team)." + "category": { + "$ref": "#/components/schemas/DocumentAndTestCategory", + "description": "The document's category." }, - "companyUrl": { + "description": { "type": "string", - "description": "URL of the company associated with this questionnaire." + "description": "The document's description." }, - "customerTrustAccountId": { - "type": "string", - "description": "ID of the customer trust account to associate with this questionnaire." + "isSensitive": { + "type": "boolean", + "description": "Determines whether or not the document is sensitive." }, - "description": { + "title": { "type": "string", - "description": "Description of the questionnaire." + "description": "The document's title." }, - "dueDate": { + "uploadStatus": { + "$ref": "#/components/schemas/DocumentStatus", + "description": "The document's status." + }, + "uploadStatusDate": { "type": "string", "format": "date-time", - "description": "Due date for questionnaire completion (ISO 8601)." + "nullable": true, + "description": "The date the document's uploadStatus changed." }, - "metadata": { - "items": { - "$ref": "#/components/schemas/QuestionnaireMetadata" - }, - "type": "array", - "description": "Custom key-value pairs. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods. Maximum 30 entries." + "url": { + "type": "string", + "nullable": true, + "description": "The URL to view the document within Vanta." }, - "includeUntaggedEntitiesForCategoryIds": { - "items": { - "type": "string" + "deactivatedStatus": { + "properties": { + "creationDate": { + "type": "string", + "format": "date-time", + "description": "The date the document was deactivated." + }, + "expiration": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date the deactivation expires." + }, + "reason": { + "type": "string", + "nullable": true, + "description": "The reason for the document was deactivated." + }, + "isDeactivated": { + "type": "boolean", + "description": "Determines whether or not the document is deactivated." + } }, - "type": "array", - "description": "Category IDs for which to include untagged entities." + "required": [ + "creationDate", + "expiration", + "reason", + "isDeactivated" + ], + "type": "object" }, - "tagAndCategoryIds": { + "note": { + "type": "string", + "nullable": true, + "description": "A user note for the document." + }, + "nextRenewalDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the document needs to be renewed." + }, + "renewalCadence": { + "$ref": "#/components/schemas/CadenceType", + "description": "How often a document must be renewed." + }, + "reminderWindow": { + "allOf": [ + { + "$ref": "#/components/schemas/ReminderWindow" + } + ], + "nullable": true, + "description": "The number of day ahead of the renewal date to send a reminder." + }, + "subscribers": { "items": { - "$ref": "#/components/schemas/TagInput" + "type": "string" }, "type": "array", - "description": "Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags." + "description": "A list of the emails subscribed to the document." } }, "required": [ - "displayName", - "url" + "id", + "ownerId", + "category", + "description", + "isSensitive", + "title", + "uploadStatus", + "uploadStatusDate", + "url", + "deactivatedStatus", + "note", + "nextRenewalDate", + "renewalCadence", + "reminderWindow", + "subscribers" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_CustomerTrustQuestionnaire_": { + "PaginatedResponse_UploadedFileT_": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + "$ref": "#/components/schemas/UploadedFileT" }, "type": "array" }, @@ -11206,439 +12099,418 @@ "type": "object", "additionalProperties": false }, - "SettableQuestionnaireStatus": { - "type": "string", + "DiscoveredVendorSource": { + "description": "The source of the discovered vendor.\nOKTA: The vendor was discovered via an Okta integration\nJAMF: The vendor was discovered via a JAMF integration\nGSUITE: The vendor was discovered via an GSuite integration\nVENDR: The vendor was discovered via a Vendr integration\nOFFICE: The vendor was discovered via a microsoft office integration", "enum": [ - "IN_PROGRESS", - "IN_REVIEW", - "READY_FOR_REVIEW", - "WAITING_ON_ANSWERS", - "ON_HOLD", - "NO_LONGER_NEEDED" - ] - }, - "UpdateActorAssignment": { - "description": "Actor assignment for setting an owner or approver.", - "properties": { - "type": { - "type": "string", - "enum": [ - "User", - "Team" - ], - "description": "The type of actor: \"User\" for an individual user, \"Team\" for a team." - }, - "id": { - "type": "string", - "description": "The unique identifier of the user or team." - } - }, - "required": [ - "type", - "id" + "OKTA", + "JAMF", + "GSUITE", + "VENDR", + "OFFICE" ], - "type": "object", - "additionalProperties": false + "type": "string" }, - "UpdateQuestionnaireArgs": { + "DiscoveredVendor": { "properties": { - "displayName": { + "id": { "type": "string", - "description": "Display name of the questionnaire" + "description": "The discovered vendor's unique ID." }, - "dueDate": { + "name": { "type": "string", - "nullable": true, - "description": "Due date for questionnaire completion (ISO 8601 string, null to clear)" + "description": "The discovered vendor's display name ." }, - "status": { - "$ref": "#/components/schemas/SettableQuestionnaireStatus", - "description": "Status transition (limited to settable statuses)" + "normalizedName": { + "type": "string", + "description": "The discovered vendor's vendorNormalized or canonical name. This is used to group duplicate vendors together." }, - "ownerAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/UpdateActorAssignment" + "category": { + "properties": { + "name": { + "type": "string" } + }, + "required": [ + "name" ], + "type": "object", "nullable": true, - "description": "Owner assignment as Actor (null to unassign)" + "description": "The discovered vendor's category." }, - "approverAssignment": { - "allOf": [ - { - "$ref": "#/components/schemas/UpdateActorAssignment" + "source": { + "$ref": "#/components/schemas/DiscoveredVendorSource", + "description": "The discovered vendor's source ." + }, + "discoveredDate": { + "type": "string", + "format": "date-time", + "description": "The discovered vendor's imported date." + }, + "numberOfAccounts": { + "type": "number", + "format": "double", + "description": "The number of accounts in the discovered vendor." + }, + "ignored": { + "properties": { + "ignoredAtDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date the discovered vendor was marked as ignored." + }, + "ignoredReason": { + "type": "string", + "nullable": true, + "description": "The reason the discovered vendor was ignored." + }, + "ignoredByUserId": { + "type": "string", + "nullable": true, + "description": "The user ID who ignored the discovered vendor." } + }, + "required": [ + "ignoredAtDate", + "ignoredReason", + "ignoredByUserId" ], + "type": "object", "nullable": true, - "description": "Approver assignment as Actor (null to unassign, requires QuestionnaireAutomationAdvanced)" - }, - "metadata": { - "items": { - "$ref": "#/components/schemas/QuestionnaireMetadata" - }, - "type": "array", - "description": "Metadata key-value pairs" + "description": "Determines whether or not the vendor is ignored." }, - "tagAndCategoryIds": { - "items": { - "$ref": "#/components/schemas/TagInput" + "rejected": { + "properties": { + "rejectedByUserId": { + "type": "string", + "nullable": true, + "description": "The user ID who rejected the discovered vendor." + }, + "rejectedReason": { + "type": "string", + "nullable": true, + "description": "The reason the discovered vendor was rejected." + }, + "rejectedAtDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date the discovered vendor was marked as rejected." + } }, - "type": "array", - "description": "Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags." - } - }, - "type": "object", - "additionalProperties": false - }, - "CompleteQuestionnaireRequest": { - "description": "Request body for completing a questionnaire.", - "properties": { - "shouldSyncApprovedToAnswerLibrary": { - "type": "boolean", - "description": "Whether to sync approved answers to the answer library.\nDefaults to true. Ignored for non-English SPREADSHEET/DOCUMENT questionnaires." + "required": [ + "rejectedByUserId", + "rejectedReason", + "rejectedAtDate" + ], + "type": "object", + "nullable": true, + "description": "Determines whether or not the vendor is rejected." } }, + "required": [ + "id", + "name", + "normalizedName", + "category", + "source", + "discoveredDate", + "numberOfAccounts", + "ignored", + "rejected" + ], "type": "object", "additionalProperties": false }, - "ApproveQuestionnaireRequest": { - "description": "Request body for approving a questionnaire.", + "PaginatedResponse_DiscoveredVendor_": { "properties": { - "statusChangeMessage": { - "type": "string", - "description": "Optional message describing the reason for approval." + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/DiscoveredVendor" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, + "required": [ + "results" + ], "type": "object", "additionalProperties": false }, - "CustomerTrustCreateQuestionnaireExportResponse": { - "description": "Response returned when a questionnaire export is created.\nUse the `id` to poll the GET endpoint for export status and download URL.", + "DiscoveredVendorScope": { + "description": "The scope of a discovered vendor.\nNEEDS_REVIEW: The vendor needs review\nIGNORED: The vendor was ignored\nREJECTED: The vendor was rejected", + "enum": [ + "NEEDS_REVIEW", + "IGNORED", + "REJECTED" + ], + "type": "string" + }, + "DiscoveredVendorAccountType.USER": { + "enum": [ + "USER" + ], + "type": "string" + }, + "DiscoveredVendorUser": { "properties": { "id": { "type": "string", - "description": "Unique identifier for the export job. Use this ID to check export status.", - "example": "507f1f77bcf86cd799439011" + "description": "The associated user's unique ID." }, - "status": { + "email": { "type": "string", - "enum": [ - "pending", - "completed", - "failed" - ], - "description": "Processing status of the export. Newly created exports always start as `\"pending\"`.", - "example": "pending" + "description": "The associated user's email address." }, - "format": { + "displayName": { "type": "string", - "enum": [ - "original", - "csv" - ], - "description": "The requested output format for the export.", - "example": "original" + "description": "The associated user's display name ." }, - "requestedAt": { - "type": "string", - "description": "ISO 8601 timestamp indicating when the export was requested.", - "example": "2025-01-08T12:00:00.000Z" + "type": { + "$ref": "#/components/schemas/DiscoveredVendorAccountType.USER", + "description": "The account type." } }, "required": [ "id", - "status", - "format", - "requestedAt" + "email", + "displayName", + "type" ], "type": "object", "additionalProperties": false }, - "CustomerTrustCreateQuestionnaireExportInput": { - "description": "Request body for creating a questionnaire export.", + "DiscoveredVendorAccountType.COMPUTER": { + "enum": [ + "COMPUTER" + ], + "type": "string" + }, + "DiscoveredVendorComputer": { "properties": { - "questionnaireId": { + "id": { "type": "string", - "description": "Unique identifier for the questionnaire to trigger an export for.", - "example": "65a5d6e2f1a2b3c4d5e6f7a8" + "description": "The associated computer's unique ID." }, - "format": { + "displayName": { "type": "string", - "enum": [ - "original", - "csv" + "description": "The associated computer's display name." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/DiscoveredVendorUser" + } ], - "description": "The output format for the exported questionnaire.\n- `\"original\"`: Exports in the questionnaire's native format (XLSX for spreadsheets, DOCX for documents).\n- `\"csv\"`: Exports as a CSV file, suitable for data analysis or import into other systems.", - "example": "original" + "nullable": true, + "description": "The associated computer's owner." + }, + "type": { + "$ref": "#/components/schemas/DiscoveredVendorAccountType.COMPUTER", + "description": "The account type." } }, "required": [ - "questionnaireId", - "format" + "id", + "owner", + "type" ], "type": "object", "additionalProperties": false }, - "CustomerTrustExportStatusResponse": { - "description": "Detailed status and result of a questionnaire export.\nWhen `status` is `\"completed\"`, the response includes a time-limited download URL.", - "properties": { - "id": { - "type": "string", - "description": "Unique identifier for the export job.", - "example": "507f1f77bcf86cd799439011" - }, - "status": { - "type": "string", - "enum": [ - "pending", - "completed", - "failed" - ], - "description": "Processing status of the export.\n- `\"pending\"`: Export is still being processed.\n- `\"completed\"`: Export finished successfully. Download URL is available.\n- `\"failed\"`: Export failed. See `errorMessage` for details.", - "example": "completed" + "DiscoveredVendorAccount": { + "anyOf": [ + { + "$ref": "#/components/schemas/DiscoveredVendorUser" }, - "format": { - "type": "string", - "enum": [ - "original", - "csv" + { + "$ref": "#/components/schemas/DiscoveredVendorComputer" + } + ] + }, + "PaginatedResponse_DiscoveredVendorAccount_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/DiscoveredVendorAccount" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" ], - "description": "The output format of the exported file.", - "example": "original" - }, - "requestedAt": { - "type": "string", - "description": "ISO 8601 timestamp indicating when the export was requested.", - "example": "2025-01-08T12:00:00.000Z" - }, - "completedAt": { - "type": "string", - "description": "ISO 8601 timestamp indicating when the export completed successfully.\nOnly present when `status` is `\"completed\"`.", - "example": "2025-01-08T12:05:00.000Z" - }, - "downloadUrl": { - "type": "string", - "description": "Pre-signed URL for downloading the exported file. Valid for 24 hours from the time of this response.\nOnly present when `status` is `\"completed\"`.", - "example": "https://storage.example.com/exports/questionnaire-export.xlsx?token=..." - }, - "expiresAt": { - "type": "string", - "description": "ISO 8601 timestamp indicating when the download URL expires. After this time, request a new export.\nOnly present when `status` is `\"completed\"`.", - "example": "2025-01-09T12:00:00.000Z" - }, - "failedAt": { - "type": "string", - "description": "ISO 8601 timestamp indicating when the export failed.\nOnly present when `status` is `\"failed\"`.", - "example": "2025-01-08T12:03:00.000Z" - }, - "errorMessage": { - "type": "string", - "description": "Human-readable description of why the export failed.\nOnly present when `status` is `\"failed\"`.", - "example": "The questionnaire contains unsupported question types." + "type": "object" } }, "required": [ - "id", - "status", - "format", - "requestedAt" + "results" ], "type": "object", "additionalProperties": false }, - "CreateDeletionRequestResponse": { - "description": "Response returned after a data deletion request is created.", + "UserDefinedTagCategory": { "properties": { - "success": { - "type": "boolean", - "description": "Whether the deletion request was successfully enqueued." + "id": { + "type": "string" + }, + "displayName": { + "type": "string" } }, "required": [ - "success" + "id", + "displayName" ], "type": "object", "additionalProperties": false }, - "CreateDeletionRequestInput": { - "description": "Request body for creating a data deletion request.", + "ArrayResponse_UserDefinedTagCategory_": { "properties": { - "email": { - "type": "string", - "description": "Email address of the individual requesting data deletion." + "results": { + "items": { + "$ref": "#/components/schemas/UserDefinedTagCategory" + }, + "type": "array" } }, "required": [ - "email" + "results" ], "type": "object", "additionalProperties": false }, - "CustomerTrustAccountNdaStatus": { + "CustomerTrustProductContextIdFilter": { "type": "string", "enum": [ - "SIGNED", - "NOT_REQUIRED", - "INCOMPLETE" + "EXTERNAL_TRUST_CENTER", + "DOCUMENT_SHARING", + "CONTROL_SHARING", + "QUESTIONNAIRE" ] }, - "CustomerTrustAccountNDADetails": { + "CreateTagCategoryInput": { "properties": { - "ndaStatus": { - "$ref": "#/components/schemas/CustomerTrustAccountNdaStatus", - "description": "The status of the NDA for this account" - }, - "ndaSatisfiedDate": { + "displayName": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The date and time the NDA was satisfied" + "description": "Must be unique within your organization. Surrounding whitespace is trimmed.", + "minLength": 1, + "maxLength": 2000 } }, "required": [ - "ndaStatus", - "ndaSatisfiedDate" + "displayName" ], "type": "object", "additionalProperties": false }, - "CustomerTrustAccountGrantAccessOption": { - "type": "string", - "enum": [ - "INCLUDE_EVERYTHING_REQUESTED", - "INCLUDE_ONLY_CONFIGURED" - ], - "description": "How a CustomerTrustAccount determines which resources to grant its viewers access to." - }, - "CustomerTrustAccountAccessConfig": { + "UserDefinedTag": { "properties": { - "autoApprovalEnabled": { - "type": "boolean", - "description": "Whether access requests matching this account's email domain should be auto-approved" + "id": { + "type": "string" }, - "grantAccessOption": { - "allOf": [ - { - "$ref": "#/components/schemas/CustomerTrustAccountGrantAccessOption" - } - ], - "nullable": true, - "description": "How to grant resource access for auto-approved requests" + "category": { + "type": "string" + }, + "displayName": { + "type": "string" } }, "required": [ - "autoApprovalEnabled", - "grantAccessOption" + "id", + "category", + "displayName" ], "type": "object", "additionalProperties": false }, - "TagsByCategoryOutput": { + "TagCategoryWithTags": { "properties": { - "categoryId": { - "type": "string", - "description": "The tag category ID" + "category": { + "$ref": "#/components/schemas/UserDefinedTagCategory" }, - "tagIds": { + "tags": { "items": { - "type": "string" + "$ref": "#/components/schemas/UserDefinedTag" }, - "type": "array", - "description": "Tag IDs assigned in this category" + "type": "array" } }, "required": [ - "categoryId", - "tagIds" + "category", + "tags" ], "type": "object", "additionalProperties": false }, - "CustomerTrustAccountVantaApi": { - "description": "Vanta API representation of a CustomerTrustAccount.", + "CustomerTrustProductContextIdWritable": { + "type": "string", + "enum": [ + "EXTERNAL_TRUST_CENTER", + "DOCUMENT_SHARING", + "CONTROL_SHARING" + ] + }, + "AddTagCategoryProductContextInput": { + "properties": { + "productContextId": { + "$ref": "#/components/schemas/CustomerTrustProductContextIdWritable", + "description": "Product context to enable this tag category for." + } + }, + "required": [ + "productContextId" + ], + "type": "object", + "additionalProperties": false + }, + "QuestionnaireAssignableUser": { "properties": { "id": { - "type": "string", - "description": "Unique identifier for the account" - }, - "name": { - "type": "string", - "description": "Name of the account" - }, - "emailDomain": { - "type": "string", - "description": "Primary email domain associated with the account" - }, - "createdDate": { - "type": "string", - "format": "date-time", - "description": "When the account was created" - }, - "updatedDate": { - "type": "string", - "format": "date-time", - "description": "When the account was last updated" - }, - "ndaDetails": { - "$ref": "#/components/schemas/CustomerTrustAccountNDADetails", - "description": "NDA configuration for this account" - }, - "accessConfig": { - "allOf": [ - { - "$ref": "#/components/schemas/CustomerTrustAccountAccessConfig" - } - ], - "nullable": true, - "description": "Access configuration for this account" - }, - "customFields": { - "items": { - "$ref": "#/components/schemas/CustomField" - }, - "type": "array", - "description": "Custom field values for this account" + "type": "string" }, - "tagsByCategory": { - "items": { - "$ref": "#/components/schemas/TagsByCategoryOutput" - }, - "type": "array", - "description": "Tags assigned to this account, grouped by category" + "displayName": { + "type": "string" } }, "required": [ "id", - "name", - "emailDomain", - "createdDate", - "updatedDate", - "ndaDetails", - "accessConfig", - "customFields", - "tagsByCategory" + "displayName" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_CustomerTrustAccountVantaApi_": { + "QuestionnaireAssignableUsersResponse": { "properties": { "results": { "properties": { "data": { "items": { - "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + "$ref": "#/components/schemas/QuestionnaireAssignableUser" }, "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" } }, "required": [ - "data", - "pageInfo" + "data" ], "type": "object" } @@ -11649,729 +12521,5437 @@ "type": "object", "additionalProperties": false }, - "CustomerTrustAccountNDADetailsInput": { + "QuestionnaireAssignableUserRole": { + "type": "string", + "enum": [ + "owner", + "approver" + ] + }, + "CustomerTrustQuestionnaireType": { + "type": "string", + "enum": [ + "SPREADSHEET", + "WEBSITE", + "DOCUMENT" + ] + }, + "QuestionnaireStatus": { + "type": "string", + "enum": [ + "APPROVED", + "IN_PROGRESS", + "IN_REVIEW", + "READY_FOR_REVIEW", + "WAITING_ON_ANSWERS", + "ON_HOLD", + "NO_LONGER_NEEDED", + "COMPLETE", + "ERROR", + "EXTRACTING_QUESTIONS", + "QUEUED_FOR_SECTION_EXTRACTION", + "EXTRACTING_SECTIONS", + "MAPPING_SECTIONS", + "QUEUED_FOR_ANSWERING", + "GENERATING_ANSWERS", + "QUEUED_FOR_EXTRACTION", + "PROCESSING", + "QUEUED_FOR_PROCESSING", + "WAITING_ON_COLUMN_SELECTION", + "WAITING_ON_COLUMN_APPROVAL", + "QUEUED_FOR_COLUMN_DETECTION", + "DETECTING_COLUMNS" + ] + }, + "QuestionnaireUser": { "properties": { - "markNdaNotRequired": { - "type": "boolean", - "description": "Whether NDA requirement should be bypassed for access requests matching this account" + "id": { + "type": "string" + }, + "displayName": { + "type": "string", + "nullable": true + }, + "email": { + "type": "string", + "nullable": true } }, "required": [ - "markNdaNotRequired" + "id", + "displayName", + "email" ], "type": "object", "additionalProperties": false }, - "CustomerTrustAccountAccessConfigInput": { + "QuestionnaireStatusChangeEntry": { "properties": { - "autoApprovalEnabled": { - "type": "boolean", - "description": "Whether access requests matching this account's email domain should be auto-approved" + "updatedBy": { + "$ref": "#/components/schemas/QuestionnaireUser", + "description": "The user who made the status change" }, - "grantAccessOption": { - "allOf": [ - { - "$ref": "#/components/schemas/CustomerTrustAccountGrantAccessOption" - } - ], - "nullable": true, - "description": "How to grant resource access for auto-approved requests. Must be specified if autoApprovalEnabled is true" + "updatedAt": { + "type": "string", + "format": "date-time", + "description": "The date and time when the status was changed" }, - "tagsByCategory": { - "items": { - "$ref": "#/components/schemas/TagsByCategoryInput" - }, - "type": "array", - "description": "Tags to assign to this account, grouped by category.", - "deprecated": true + "status": { + "$ref": "#/components/schemas/QuestionnaireStatus", + "description": "The new status of the questionnaire" + }, + "message": { + "type": "string", + "nullable": true, + "description": "An optional message associated with the status change" } }, "required": [ - "autoApprovalEnabled" + "updatedBy", + "updatedAt", + "status", + "message" ], "type": "object", "additionalProperties": false }, - "CreateCustomerTrustAccountInput": { + "ActorAssignment": { "properties": { - "name": { - "type": "string" + "type": { + "type": "string", + "enum": [ + "User", + "Team" + ] }, - "emailDomain": { + "id": { "type": "string" }, - "ndaDetails": { - "$ref": "#/components/schemas/CustomerTrustAccountNDADetailsInput" - }, - "accessConfig": { - "$ref": "#/components/schemas/CustomerTrustAccountAccessConfigInput" - }, - "customFields": { - "items": { - "$ref": "#/components/schemas/CustomField" - }, - "type": "array" - }, - "tagsByCategory": { - "items": { - "$ref": "#/components/schemas/TagsByCategoryInput" - }, - "type": "array", - "description": "Tags to assign to this account, grouped by category" + "displayName": { + "type": "string", + "nullable": true } }, "required": [ - "name", - "emailDomain" + "type", + "id", + "displayName" ], "type": "object", "additionalProperties": false }, - "EditCustomerTrustAccountInput": { + "CustomerTrustQuestionnaire": { "properties": { - "name": { - "type": "string", - "description": "Updated name for the account" + "id": { + "type": "string" }, - "emailDomain": { - "type": "string", - "description": "Updated primary email domain for the account" + "displayName": { + "type": "string" }, - "customFields": { + "url": { + "type": "string" + }, + "type": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaireType" + }, + "status": { + "$ref": "#/components/schemas/QuestionnaireStatus" + }, + "statusLog": { "items": { - "$ref": "#/components/schemas/CustomField" + "$ref": "#/components/schemas/QuestionnaireStatusChangeEntry" }, "type": "array", - "description": "Updated custom field values for the account" + "description": "The status change history log for the questionnaire.\nEntries are ordered by the most recent status change first." }, - "tagsByCategory": { + "ownerAssignment": { + "$ref": "#/components/schemas/ActorAssignment", + "description": "The owner assignment in actor form (User or Team)." + }, + "approverAssignment": { + "$ref": "#/components/schemas/ActorAssignment", + "description": "The approver assignment in actor form (User or Team)." + }, + "customerTrustAccountId": { + "type": "string" + }, + "dueDate": { + "type": "string", + "format": "date-time" + }, + "metadata": { "items": { - "$ref": "#/components/schemas/TagsByCategoryInput" + "properties": { + "value": { + "type": "string" + }, + "key": { + "type": "string" + } + }, + "required": [ + "value", + "key" + ], + "type": "object" + }, + "type": "array" + }, + "tagAndCategoryIds": { + "items": { + "$ref": "#/components/schemas/TagInput" }, "type": "array", - "description": "Tags to assign to this account, grouped by category. Replaces existing tags per category." + "description": "Tags assigned to this questionnaire. Each entry contains a categoryId and tagId." + }, + "createdDate": { + "type": "string", + "format": "date-time" + }, + "updatedDate": { + "type": "string", + "format": "date-time" + }, + "completedDate": { + "type": "string", + "format": "date-time" } }, + "required": [ + "id", + "displayName", + "type", + "status", + "statusLog", + "tagAndCategoryIds", + "createdDate", + "updatedDate" + ], "type": "object", "additionalProperties": false }, - "ControlDomain": { - "enum": [ - "ARTIFICIAL_&_AUTONOMOUS_TECHNOLOGY", - "ASSET_MANAGEMENT", - "BUSINESS_CONTINUITY_&_DISASTER_RECOVERY", - "CAPACITY_&_PERFORMANCE_PLANNING", - "CHANGE_MANAGEMENT", - "CLOUD_SECURITY", - "COMPLIANCE", - "CONFIGURATION_MANAGEMENT", - "CONTINUOUS_MONITORING", - "CRYPTOGRAPHIC_PROTECTIONS", - "DATA_CLASSIFICATION_&_HANDLING", - "EMBEDDED_TECHNOLOGY", - "ENDPOINT_SECURITY", - "HUMAN_RESOURCES_SECURITY", - "IDENTIFICATION_&_AUTHENTICATION", - "INCIDENT_RESPONSE", - "INFORMATION_ASSURANCE", - "MAINTENANCE", - "MOBILE_DEVICE_MANAGEMENT", - "NETWORK SECURITY", - "PHYSICAL_&_ENVIRONMENTAL_SECURITY", - "PRIVACY", - "PROJECT_&_RESOURCE MANAGEMENT", - "RISK_MANAGEMENT", - "SECURE_ENGINEERING_&_ARCHITECTURE", - "SECURITY_AWARENESS_&_TRAINING", - "SECURITY_OPERATIONS", - "SECURITY_&_PRIVACY_GOVERNANCE", - "TECHNOLOGY_DEVELOPMENT_&_ACQUISITION", - "THIRD-PARTY_MANAGEMENT", - "THREAT_MANAGEMENT", - "VULNERABILITY_&_PATCH_MANAGEMENT", - "WEB_SECURITY", - "ADMINISTRATIVE", - "PHYSICAL", - "TECHNICAL", - "BASIC", - "DERIVED" - ], - "type": "string" - }, - "FrameworkId": { - "enum": [ - "AU_E_8", - "AWS_FTR", - "CCPA", - "CIS_V8", - "CPS_234", - "DORA", - "FEDRAMP", - "GDPR", - "HIPAA", - "HITRUST_E1", - "ISO_27001", - "ISO_27001_2022", - "ISO_27017", - "ISO_27018", - "ISO_27701", - "ISO_42001", - "ISO_9001", - "MSFT_SSPA", - "MVSP", - "NIS_2D", - "NIST_171", - "NIST_53", - "NIST_AI_RMF", - "NIST_CSF", - "NIST_CSF_2", - "OFDSS", - "PCI_SAQ_A", - "PCI_SAQ_A_EP", - "PCI_SAQ_D_MERCHANT", - "PCI_SAQ_D_SP", - "PCI_DDS_4", - "SOC_2", - "SOX_ITGC", - "UK_CYBER_ESSENTIALS", - "US_DATA_PRIVACY" - ], - "type": "string" - }, - "FrameworkSection": { + "ActorAssignmentInput": { "properties": { - "frameworkId": { - "anyOf": [ - { - "$ref": "#/components/schemas/FrameworkId" - }, - { - "type": "string" - } + "type": { + "type": "string", + "enum": [ + "User", + "Team" ] }, - "sectionId": { + "id": { "type": "string" } }, "required": [ - "frameworkId", - "sectionId" + "type", + "id" ], "type": "object", "additionalProperties": false }, - "GdprRole": { - "enum": [ - "BOTH", - "CONTROLLER", - "PROCESSOR" + "QuestionnaireMetadata": { + "properties": { + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + }, + "required": [ + "key", + "value" ], - "type": "string" + "type": "object", + "additionalProperties": false }, - "CreateControlInput": { + "CreateWebsiteQuestionnaireInput": { + "description": "Request body for creating a website-based questionnaire from a portal URL.", "properties": { - "externalId": { + "displayName": { "type": "string", - "description": "The control's external ID." + "description": "Display name for the questionnaire." }, - "name": { + "url": { "type": "string", - "nullable": true, - "description": "The control's name." + "description": "The portal URL to create the questionnaire from." }, - "description": { - "type": "string", - "description": "The control's description." + "ownerAssignment": { + "$ref": "#/components/schemas/ActorAssignmentInput", + "description": "Actor to assign as the owner (user or team)." }, - "effectiveDate": { - "type": "string", - "format": "date-time", - "description": "The effective date of the control." + "approverAssignment": { + "$ref": "#/components/schemas/ActorAssignmentInput", + "description": "Actor to assign as the approver (user or team)." }, - "domain": { - "$ref": "#/components/schemas/ControlDomain", - "description": "The control's category." + "companyUrl": { + "type": "string", + "description": "URL of the company associated with this questionnaire." }, - "sections": { + "customerTrustAccountId": { + "type": "string", + "description": "ID of the customer trust account to associate with this questionnaire." + }, + "description": { + "type": "string", + "description": "Description of the questionnaire." + }, + "dueDate": { + "type": "string", + "format": "date-time", + "description": "Due date for questionnaire completion (ISO 8601)." + }, + "metadata": { "items": { - "$ref": "#/components/schemas/FrameworkSection" + "$ref": "#/components/schemas/QuestionnaireMetadata" }, "type": "array", - "nullable": true, - "description": "The framework sections that the control maps to." + "description": "Custom key-value pairs. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods. Maximum 30 entries." }, - "role": { - "allOf": [ - { - "$ref": "#/components/schemas/GdprRole" - } - ], - "nullable": true, - "description": "The GDPR role of the control, which specifies whether the data is being \"collected\" or \"processed\".\nThis field should only be included for controls that are to be mapped to the GDPR framework." + "includeUntaggedEntitiesForCategoryIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Category IDs for which to include untagged entities." }, - "customFields": { + "tagAndCategoryIds": { "items": { - "$ref": "#/components/schemas/CustomField" + "$ref": "#/components/schemas/TagInput" }, "type": "array", - "description": "The control's values for custom fields." + "description": "Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags." } }, "required": [ - "externalId", - "name", - "description", - "effectiveDate", - "domain" + "displayName", + "url" ], "type": "object", "additionalProperties": false }, - "AddControlFromLibraryInput": { + "PaginatedResponse_CustomerTrustQuestionnaire_": { "properties": { - "controlId": { - "type": "string", - "description": "The ID of the control to be added." + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" } }, "required": [ - "controlId" + "results" ], "type": "object", "additionalProperties": false }, - "ControlStatus": { + "SettableQuestionnaireStatus": { + "type": "string", "enum": [ - "NO_EVIDENCE_MAPPED", - "NOT_STARTED", "IN_PROGRESS", - "COMPLETED" - ], - "type": "string" + "IN_REVIEW", + "READY_FOR_REVIEW", + "WAITING_ON_ANSWERS", + "ON_HOLD", + "NO_LONGER_NEEDED" + ] }, - "ControlDetail": { + "UpdateActorAssignment": { + "description": "Actor assignment for setting an owner or approver.", "properties": { - "id": { + "type": { "type": "string", - "description": "The control's unique ID." + "enum": [ + "User", + "Team" + ], + "description": "The type of actor: \"User\" for an individual user, \"Team\" for a team." }, - "externalId": { + "id": { "type": "string", - "nullable": true, - "description": "The control's external ID." - }, - "name": { + "description": "The unique identifier of the user or team." + } + }, + "required": [ + "type", + "id" + ], + "type": "object", + "additionalProperties": false + }, + "UpdateQuestionnaireArgs": { + "properties": { + "displayName": { "type": "string", - "description": "The control's name." + "description": "Display name of the questionnaire" }, - "description": { + "dueDate": { "type": "string", - "description": "The control's description." - }, - "source": { - "$ref": "#/components/schemas/ControlSource", - "description": "The control's source, either \"VANTA\" or \"CUSTOM\"." + "nullable": true, + "description": "Due date for questionnaire completion (ISO 8601 string, null to clear)" }, - "domains": { - "items": { - "type": "string" - }, - "type": "array", - "description": "The security domains that the control belongs to." + "status": { + "$ref": "#/components/schemas/SettableQuestionnaireStatus", + "description": "Status transition (limited to settable statuses)" }, - "owner": { + "ownerAssignment": { "allOf": [ { - "$ref": "#/components/schemas/Owner" + "$ref": "#/components/schemas/UpdateActorAssignment" } ], "nullable": true, - "description": "The control's owner." + "description": "Owner assignment as Actor (null to unassign)" }, - "role": { - "type": "string", + "approverAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/UpdateActorAssignment" + } + ], "nullable": true, - "description": "The control's GDPR role, if the control is a GDPR control." + "description": "Approver assignment as Actor (null to unassign, requires QuestionnaireAutomationAdvanced)" }, - "customFields": { + "metadata": { "items": { - "$ref": "#/components/schemas/CustomField" + "$ref": "#/components/schemas/QuestionnaireMetadata" }, "type": "array", - "description": "The control's custom field values, if control custom fields is included in your Vanta instance." - }, - "creationDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the control was created. Returns null for Vanta library controls." - }, - "modificationDate": { - "type": "string", - "format": "date-time", - "nullable": true, - "description": "When the control was last modified. Returns null for Vanta library controls." - }, - "numDocumentsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing documents that are linked to the control." - }, - "numDocumentsTotal": { - "type": "number", - "format": "double", - "description": "The total number of documents that are linked to the control." - }, - "numTestsPassing": { - "type": "number", - "format": "double", - "description": "The number of passing tests that are linked to the control." - }, - "numTestsTotal": { - "type": "number", - "format": "double", - "description": "The total number of tests that are linked to the control." - }, - "status": { - "$ref": "#/components/schemas/ControlStatus", - "description": "The status of the control as determined by number of passing tests and documents." + "description": "Metadata key-value pairs" }, - "note": { + "tagAndCategoryIds": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array", + "description": "Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags." + } + }, + "type": "object", + "additionalProperties": false + }, + "CompleteQuestionnaireRequest": { + "description": "Request body for completing a questionnaire.", + "properties": { + "shouldSyncApprovedToAnswerLibrary": { + "type": "boolean", + "description": "Whether to sync approved answers to the answer library.\nDefaults to true. Ignored for non-English SPREADSHEET/DOCUMENT questionnaires." + } + }, + "type": "object", + "additionalProperties": false + }, + "ApproveQuestionnaireRequest": { + "description": "Request body for approving a questionnaire.", + "properties": { + "statusChangeMessage": { "type": "string", - "nullable": true, - "description": "A user created note for the control." + "description": "Optional message describing the reason for approval." } }, - "required": [ - "id", - "externalId", - "name", - "description", - "source", - "domains", - "owner", - "customFields", - "creationDate", - "modificationDate", - "numDocumentsPassing", - "numDocumentsTotal", - "numTestsPassing", - "numTestsTotal", - "status", - "note" - ], "type": "object", "additionalProperties": false }, - "EditControlMetadataInput": { + "CustomerTrustCreateQuestionnaireExportResponse": { + "description": "Response returned when a questionnaire export is created.\nUse the `id` to poll the GET endpoint for export status and download URL.", "properties": { - "name": { + "id": { "type": "string", - "description": "A new name for the control." - }, - "externalId": { - "type": "string", - "description": "The new external ID for the control." + "description": "Unique identifier for the export job. Use this ID to check export status.", + "example": "507f1f77bcf86cd799439011" }, - "description": { + "status": { "type": "string", - "description": "The new description for the control." - }, - "domain": { - "$ref": "#/components/schemas/ControlDomain", - "description": "The new category for the control." + "enum": [ + "pending", + "completed", + "failed" + ], + "description": "Processing status of the export. Newly created exports always start as `\"pending\"`.", + "example": "pending" }, - "note": { + "format": { "type": "string", - "description": "The new note for the control." + "enum": [ + "original", + "csv" + ], + "description": "The requested output format for the export.", + "example": "original" }, - "customFields": { - "items": { - "$ref": "#/components/schemas/CustomField" - }, - "type": "array", - "description": "The control's new values for custom fields." - } - }, - "type": "object", - "additionalProperties": false - }, - "SetOwnerForControlInput": { - "properties": { - "userId": { + "requestedAt": { "type": "string", - "nullable": true, - "description": "The new owner's ID." + "description": "ISO 8601 timestamp indicating when the export was requested.", + "example": "2025-01-08T12:00:00.000Z" } }, "required": [ - "userId" + "id", + "status", + "format", + "requestedAt" ], "type": "object", "additionalProperties": false }, - "AddControlDocumentMappingInput": { + "CustomerTrustCreateQuestionnaireExportInput": { + "description": "Request body for creating a questionnaire export.", "properties": { - "documentId": { + "questionnaireId": { "type": "string", - "description": "The ID of the document to add to the control." - } - }, - "required": [ - "documentId" - ], - "type": "object", - "additionalProperties": false - }, - "AddControlTestMappingInput": { - "properties": { - "testId": { + "description": "Unique identifier for the questionnaire to trigger an export for.", + "example": "65a5d6e2f1a2b3c4d5e6f7a8" + }, + "format": { "type": "string", - "description": "The ID of the test to add to the control." + "enum": [ + "original", + "csv" + ], + "description": "The output format for the exported questionnaire.\n- `\"original\"`: Exports in the questionnaire's native format (XLSX for spreadsheets, DOCX for documents).\n- `\"csv\"`: Exports as a CSV file, suitable for data analysis or import into other systems.", + "example": "original" } }, "required": [ - "testId" + "questionnaireId", + "format" ], "type": "object", "additionalProperties": false }, - "Contract": { + "CustomerTrustExportStatusResponse": { + "description": "Detailed status and result of a questionnaire export.\nWhen `status` is `\"completed\"`, the response includes a time-limited download URL.", "properties": { "id": { "type": "string", - "description": "Unique identifier for the contract." + "description": "Unique identifier for the export job.", + "example": "507f1f77bcf86cd799439011" }, - "name": { + "status": { "type": "string", - "description": "Name of the contract." + "enum": [ + "pending", + "completed", + "failed" + ], + "description": "Processing status of the export.\n- `\"pending\"`: Export is still being processed.\n- `\"completed\"`: Export finished successfully. Download URL is available.\n- `\"failed\"`: Export failed. See `errorMessage` for details.", + "example": "completed" }, - "customerTrustAccountId": { + "format": { "type": "string", - "nullable": true, - "description": "The ID of the customer trust account this contract is linked to, if any." + "enum": [ + "original", + "csv" + ], + "description": "The output format of the exported file.", + "example": "original" }, - "executedDate": { + "requestedAt": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "Date this contract was executed." + "description": "ISO 8601 timestamp indicating when the export was requested.", + "example": "2025-01-08T12:00:00.000Z" }, - "creationDate": { + "completedAt": { "type": "string", - "format": "date-time", - "description": "Date this contract was created in Vanta." + "description": "ISO 8601 timestamp indicating when the export completed successfully.\nOnly present when `status` is `\"completed\"`.", + "example": "2025-01-08T12:05:00.000Z" + }, + "downloadUrl": { + "type": "string", + "description": "Pre-signed URL for downloading the exported file. Valid for 24 hours from the time of this response.\nOnly present when `status` is `\"completed\"`.", + "example": "https://storage.example.com/exports/questionnaire-export.xlsx?token=..." + }, + "expiresAt": { + "type": "string", + "description": "ISO 8601 timestamp indicating when the download URL expires. After this time, request a new export.\nOnly present when `status` is `\"completed\"`.", + "example": "2025-01-09T12:00:00.000Z" + }, + "failedAt": { + "type": "string", + "description": "ISO 8601 timestamp indicating when the export failed.\nOnly present when `status` is `\"failed\"`.", + "example": "2025-01-08T12:03:00.000Z" + }, + "errorMessage": { + "type": "string", + "description": "Human-readable description of why the export failed.\nOnly present when `status` is `\"failed\"`.", + "example": "The questionnaire contains unsupported question types." } }, "required": [ "id", - "name", - "customerTrustAccountId", - "executedDate", - "creationDate" + "status", + "format", + "requestedAt" ], "type": "object", "additionalProperties": false }, - "PaginatedResponse_Contract_": { - "properties": { - "results": { - "properties": { - "data": { - "items": { - "$ref": "#/components/schemas/Contract" - }, - "type": "array" - }, - "pageInfo": { - "$ref": "#/components/schemas/PageInfo" - } - }, - "required": [ - "data", - "pageInfo" - ], - "type": "object" - } - }, - "required": [ - "results" - ], - "type": "object", - "additionalProperties": false + "QuestionnaireResponseOriginType": { + "type": "string", + "enum": [ + "AI", + "ANSWER_LIBRARY", + "MANUAL", + "ORIGINAL_QUESTIONNAIRE", + "RESOURCE" + ] }, - "TagIdentifier": { + "JSONSchema7Version": { + "type": "string", + "description": "Meta schema\n\nRecommended values:\n- 'http://json-schema.org/schema#'\n- 'http://json-schema.org/hyper-schema#'\n- 'http://json-schema.org/draft-07/schema#'\n- 'http://json-schema.org/draft-07/hyper-schema#'" + }, + "JSONSchema7": { "properties": { - "categoryId": { + "$id": { "type": "string" }, - "categoryName": { + "$ref": { "type": "string" }, - "tagId": { - "type": "string" + "$schema": { + "$ref": "#/components/schemas/JSONSchema7Version" }, - "tagName": { + "$comment": { "type": "string" - } - }, - "required": [ - "categoryId", - "categoryName", - "tagId", - "tagName" - ], - "type": "object", - "additionalProperties": false - }, - "QuestionAnswerOutput": { - "properties": { - "question": { - "type": "string", - "description": "The question text." - }, - "lastUpdated": { - "type": "string", - "format": "date-time", - "description": "The most recent date the question or answer was updated." }, - "answer": { - "properties": { - "fullText": { - "type": "string" - }, - "multipleChoice": { - "type": "string", - "nullable": true - }, - "explanation": { - "type": "string", - "nullable": true - } + "$defs": { + "properties": {}, + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Definition" }, - "required": [ - "fullText", - "multipleChoice", - "explanation" - ], "type": "object" }, - "id": { - "type": "string", - "description": "The id of the upserted entry." + "type": { + "anyOf": [ + { + "$ref": "#/components/schemas/JSONSchema7TypeName" + }, + { + "items": { + "$ref": "#/components/schemas/JSONSchema7TypeName" + }, + "type": "array" + } + ] }, - "tagIdentifiers": { + "enum": { "items": { - "$ref": "#/components/schemas/TagIdentifier" + "$ref": "#/components/schemas/JSONSchema7Type" }, - "type": "array", - "description": "A list of tags associated with this Answer Library entry." - } - }, - "required": [ - "question", - "lastUpdated", - "answer", - "id", - "tagIdentifiers" - ], - "type": "object", - "additionalProperties": false - }, - "QuestionAnswerInput": { + "type": "array" + }, + "const": { + "$ref": "#/components/schemas/JSONSchema7Type" + }, + "multipleOf": { + "type": "number", + "format": "double" + }, + "maximum": { + "type": "number", + "format": "double" + }, + "exclusiveMaximum": { + "type": "number", + "format": "double" + }, + "minimum": { + "type": "number", + "format": "double" + }, + "exclusiveMinimum": { + "type": "number", + "format": "double" + }, + "maxLength": { + "type": "number", + "format": "double" + }, + "minLength": { + "type": "number", + "format": "double" + }, + "pattern": { + "type": "string" + }, + "items": { + "anyOf": [ + { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + { + "items": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "array" + } + ] + }, + "additionalItems": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "maxItems": { + "type": "number", + "format": "double" + }, + "minItems": { + "type": "number", + "format": "double" + }, + "uniqueItems": { + "type": "boolean" + }, + "contains": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "maxProperties": { + "type": "number", + "format": "double" + }, + "minProperties": { + "type": "number", + "format": "double" + }, + "required": { + "items": { + "type": "string" + }, + "type": "array" + }, + "properties": { + "properties": {}, + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "object" + }, + "patternProperties": { + "properties": {}, + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "object" + }, + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "dependencies": { + "properties": {}, + "additionalProperties": { + "anyOf": [ + { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + { + "items": { + "type": "string" + }, + "type": "array" + } + ] + }, + "type": "object" + }, + "propertyNames": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "if": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "then": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "else": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "allOf": { + "items": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "array" + }, + "anyOf": { + "items": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "array" + }, + "oneOf": { + "items": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "array" + }, + "not": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "format": { + "type": "string" + }, + "contentMediaType": { + "type": "string" + }, + "contentEncoding": { + "type": "string" + }, + "definitions": { + "properties": {}, + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Definition" + }, + "type": "object" + }, + "title": { + "type": "string" + }, + "description": { + "type": "string" + }, + "default": { + "$ref": "#/components/schemas/JSONSchema7Type" + }, + "readOnly": { + "type": "boolean" + }, + "writeOnly": { + "type": "boolean" + }, + "examples": { + "$ref": "#/components/schemas/JSONSchema7Type" + } + }, + "type": "object", + "additionalProperties": false + }, + "JSONSchema7Definition": { + "anyOf": [ + { + "$ref": "#/components/schemas/JSONSchema7" + }, + { + "type": "boolean" + } + ], + "description": "JSON Schema v7" + }, + "JSONSchema7TypeName": { + "type": "string", + "enum": [ + "string", + "number", + "integer", + "boolean", + "object", + "array", + "null" + ], + "description": "Primitive type" + }, + "JSONSchema7Type": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "number", + "format": "double" + }, + { + "type": "boolean" + }, + { + "$ref": "#/components/schemas/JSONSchema7Object" + }, + { + "$ref": "#/components/schemas/JSONSchema7Array" + } + ], + "nullable": true, + "description": "Primitive type" + }, + "JSONSchema7Object": { + "properties": {}, + "type": "object", + "additionalProperties": { + "$ref": "#/components/schemas/JSONSchema7Type" + } + }, + "JSONSchema7Array": { + "properties": {}, + "type": "object", + "additionalProperties": false + }, + "AnswerPartValue": { + "anyOf": [ + { + "type": "string" + }, + { + "type": "number", + "format": "double" + }, + { + "type": "boolean" + }, + { + "items": { + "type": "string" + }, + "type": "array" + } + ], + "nullable": true, + "description": "Valid runtime value types for an answer part. Array values are restricted\nto string items to match `ArrayFieldSchema.items` (which is narrowed to\n`StringFieldSchema` only)." + }, + "Record_string.AnswerPartValue_": { + "properties": {}, + "additionalProperties": { + "$ref": "#/components/schemas/AnswerPartValue" + }, + "type": "object", + "description": "Construct a type with a set of properties K of type T" + }, + "QuestionnaireResponseWithoutViewerPermissions": { + "description": "A questionnaire response without the fields that describe what the\nrequesting user may do with it. Surfaces that authenticate a client rather\nthan a user return this, since there is no user those fields could describe.", "properties": { - "question": { + "id": { "type": "string", - "description": "The question text." + "description": "The unique identifier for the questionnaire response" }, - "lastUpdated": { + "sectionId": { "type": "string", - "format": "date-time", - "description": "The most recent date the question or answer was updated." + "nullable": true, + "description": "The questionnaire section this response belongs to, if any.\nNull for standalone questions or legacy responses without a section." }, - "answer": { + "sequenceLabel": { "type": "string", - "description": "The answer text." + "description": "Sequence label for ordering responses within a questionnaire" }, - "tagAndCategoryIds": { + "question": { + "type": "string", + "description": "The actual question text" + }, + "editedBy": { + "allOf": [ + { + "$ref": "#/components/schemas/CustomerTrustUser" + } + ], + "nullable": true, + "description": "The user who last edited the question/answer" + }, + "approvedBy": { + "allOf": [ + { + "$ref": "#/components/schemas/CustomerTrustUser" + } + ], + "nullable": true, + "description": "The user who approved the current answer" + }, + "isPendingAnswerGeneration": { + "type": "boolean", + "description": "Indicates whether the answer is currently being worked on by AI." + }, + "originType": { + "$ref": "#/components/schemas/QuestionnaireResponseOriginType", + "description": "Where the current answer has came from\n- AI: generated by Vanta AI\n- Manual: written in by a user\n- Original questionnaire: included in the original import\n- Answer library: the answer was found in a matching question in the knowledge center\n- Resource: the answer was found in a matching excerpt from a document in the knowledge center" + }, + "answerSchema": { + "type": "string", + "description": "JSON Schema describing the expected answer format for this question.\nPrefer `answerPartsSchema` + `answerPartsValues` — those mirror the\napps/web GraphQL surface and let clients render against the\ncanonical composite schema." + }, + "answerPartsSchema": { + "$ref": "#/components/schemas/JSONSchema7", + "description": "Composite JSONSchema7 built from the response's stored answer parts\n(via `toCompositeSchema`). Mirrors the GraphQL `answerPartsSchema`\nfield. Absent when the response has no stored parts — clients fall\nback to the legacy `answerSchema` field." + }, + "answerPartsValues": { + "$ref": "#/components/schemas/Record_string.AnswerPartValue_", + "description": "Flat map of part-id → current value (via `toAnswerPartsValues`).\nSame key set as `answerPartsSchema.properties`, which each question\ndefines for itself. Absent when the response has no stored parts." + }, + "attachedEvidence": { "items": { - "$ref": "#/components/schemas/TagInput" + "properties": { + "uploadedDocument": { + "properties": { + "slugId": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "id": { + "type": "string" + } + }, + "required": [ + "id" + ], + "type": "object" + } + }, + "required": [ + "uploadedDocument" + ], + "type": "object" }, - "type": "array" + "type": "array", + "description": "Evidence documents attached to support this questionnaire response" + }, + "generatedAnswerLogId": { + "type": "string", + "description": "Id of the QAutoGeneratedAnswerLog that produced the current generated\nanswer on this response, if any. The browser extension API exposes the log\nbody and citations at\n`GET /questionnaires/{questionnaireId}/responses/{responseId}/generated-answer-log`." + }, + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/ActorAssignment" + } + ], + "nullable": true, + "description": "The response's owner, or null when no owner is assigned. Resolved from the\nobject-role grant rather than the response document's legacy `ownerUserId`,\nwhich the object-role registry leaves unset for Team owners." + } + }, + "required": [ + "id", + "question", + "isPendingAnswerGeneration", + "ownerAssignment" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_QuestionnaireResponseWithoutViewerPermissions_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/QuestionnaireResponseWithoutViewerPermissions" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "Record_string.unknown_": { + "properties": {}, + "additionalProperties": {}, + "type": "object", + "description": "Construct a type with a set of properties K of type T" + }, + "UpdateQuestionnaireResponseContentArgs": { + "description": "Request body for updating a questionnaire response's answer content.", + "properties": { + "answerPartsValues": { + "$ref": "#/components/schemas/Record_string.unknown_", + "description": "Map of answer part id -> value, matching the shape of the\n`answerPartsValues` read field. Values must be string, number,\nboolean, null, or string[]. A null value clears that part's value;\nids omitted from the map are left unchanged." + } + }, + "required": [ + "answerPartsValues" + ], + "type": "object", + "additionalProperties": false + }, + "UpdateQuestionnaireResponseOwnerArgs": { + "description": "Request body for reassigning (or clearing) a questionnaire response's owner.", + "properties": { + "ownerAssignment": { + "allOf": [ + { + "$ref": "#/components/schemas/UpdateActorAssignment" + } + ], + "nullable": true, + "description": "New owner, or null to clear the current owner." + } + }, + "required": [ + "ownerAssignment" + ], + "type": "object", + "additionalProperties": false + }, + "CreateDeletionRequestResponse": { + "description": "Response returned after a data deletion request is created.", + "properties": { + "isSuccessful": { + "type": "boolean", + "description": "Whether the deletion request was successfully enqueued." + } + }, + "required": [ + "isSuccessful" + ], + "type": "object", + "additionalProperties": false + }, + "CreateDeletionRequestInput": { + "description": "Request body for creating a data deletion request.", + "properties": { + "email": { + "type": "string", + "description": "Email address of the individual requesting data deletion." + } + }, + "required": [ + "email" + ], + "type": "object", + "additionalProperties": false + }, + "CustomerTrustAccountNdaStatus": { + "type": "string", + "enum": [ + "SIGNED", + "NOT_REQUIRED", + "INCOMPLETE" + ] + }, + "CustomerTrustAccountNDADetails": { + "properties": { + "ndaStatus": { + "$ref": "#/components/schemas/CustomerTrustAccountNdaStatus", + "description": "The status of the NDA for this account" + }, + "ndaSatisfiedDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "The date and time the NDA was satisfied" + } + }, + "required": [ + "ndaStatus", + "ndaSatisfiedDate" + ], + "type": "object", + "additionalProperties": false + }, + "CustomerTrustAccountGrantAccessOption": { + "type": "string", + "enum": [ + "INCLUDE_EVERYTHING_REQUESTED", + "INCLUDE_ONLY_CONFIGURED" + ], + "description": "How a CustomerTrustAccount determines which resources to grant its viewers access to." + }, + "CustomerTrustAccountAccessConfig": { + "properties": { + "autoApprovalEnabled": { + "type": "boolean", + "description": "Whether access requests matching this account's email domain should be auto-approved" + }, + "grantAccessOption": { + "allOf": [ + { + "$ref": "#/components/schemas/CustomerTrustAccountGrantAccessOption" + } + ], + "nullable": true, + "description": "How to grant resource access for auto-approved requests" + } + }, + "required": [ + "autoApprovalEnabled", + "grantAccessOption" + ], + "type": "object", + "additionalProperties": false + }, + "TagsByCategoryOutput": { + "properties": { + "categoryId": { + "type": "string", + "description": "The tag category ID" + }, + "tagIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Tag IDs assigned in this category" + } + }, + "required": [ + "categoryId", + "tagIds" + ], + "type": "object", + "additionalProperties": false + }, + "CustomerTrustAccountVantaApi": { + "description": "Vanta API representation of a CustomerTrustAccount.", + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the account" + }, + "name": { + "type": "string", + "description": "Name of the account" + }, + "emailDomain": { + "type": "string", + "description": "Primary email domain associated with the account" + }, + "createdDate": { + "type": "string", + "format": "date-time", + "description": "When the account was created" + }, + "updatedDate": { + "type": "string", + "format": "date-time", + "description": "When the account was last updated" + }, + "ndaDetails": { + "$ref": "#/components/schemas/CustomerTrustAccountNDADetails", + "description": "NDA configuration for this account" + }, + "accessConfig": { + "allOf": [ + { + "$ref": "#/components/schemas/CustomerTrustAccountAccessConfig" + } + ], + "nullable": true, + "description": "Access configuration for this account" + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "Custom field values for this account" + }, + "tagsByCategory": { + "items": { + "$ref": "#/components/schemas/TagsByCategoryOutput" + }, + "type": "array", + "description": "Tags assigned to this account, grouped by category" + } + }, + "required": [ + "id", + "name", + "emailDomain", + "createdDate", + "updatedDate", + "ndaDetails", + "accessConfig", + "customFields", + "tagsByCategory" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_CustomerTrustAccountVantaApi_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "CustomerTrustAccountNDADetailsInput": { + "properties": { + "markNdaNotRequired": { + "type": "boolean", + "description": "Whether NDA requirement should be bypassed for access requests matching this account" + } + }, + "required": [ + "markNdaNotRequired" + ], + "type": "object", + "additionalProperties": false + }, + "CustomerTrustAccountAccessConfigInput": { + "properties": { + "autoApprovalEnabled": { + "type": "boolean", + "description": "Whether access requests matching this account's email domain should be auto-approved" + }, + "grantAccessOption": { + "allOf": [ + { + "$ref": "#/components/schemas/CustomerTrustAccountGrantAccessOption" + } + ], + "nullable": true, + "description": "How to grant resource access for auto-approved requests. Must be specified if autoApprovalEnabled is true" + }, + "tagsByCategory": { + "items": { + "$ref": "#/components/schemas/TagsByCategoryInput" + }, + "type": "array", + "description": "Tags to assign to this account, grouped by category.", + "deprecated": true + } + }, + "required": [ + "autoApprovalEnabled" + ], + "type": "object", + "additionalProperties": false + }, + "CreateCustomerTrustAccountInput": { + "properties": { + "name": { + "type": "string" + }, + "emailDomain": { + "type": "string" + }, + "ndaDetails": { + "$ref": "#/components/schemas/CustomerTrustAccountNDADetailsInput" + }, + "accessConfig": { + "$ref": "#/components/schemas/CustomerTrustAccountAccessConfigInput" + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array" + }, + "tagsByCategory": { + "items": { + "$ref": "#/components/schemas/TagsByCategoryInput" + }, + "type": "array", + "description": "Tags to assign to this account, grouped by category" + } + }, + "required": [ + "name", + "emailDomain" + ], + "type": "object", + "additionalProperties": false + }, + "EditCustomerTrustAccountInput": { + "properties": { + "name": { + "type": "string", + "description": "Updated name for the account" + }, + "emailDomain": { + "type": "string", + "description": "Updated primary email domain for the account" + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "Updated custom field values for the account" + }, + "tagsByCategory": { + "items": { + "$ref": "#/components/schemas/TagsByCategoryInput" + }, + "type": "array", + "description": "Tags to assign to this account, grouped by category. Replaces existing tags per category." + } + }, + "type": "object", + "additionalProperties": false + }, + "ControlDomain": { + "enum": [ + "ARTIFICIAL_&_AUTONOMOUS_TECHNOLOGY", + "ASSET_MANAGEMENT", + "BUSINESS_CONTINUITY_&_DISASTER_RECOVERY", + "CAPACITY_&_PERFORMANCE_PLANNING", + "CHANGE_MANAGEMENT", + "CLOUD_SECURITY", + "COMPLIANCE", + "CONFIGURATION_MANAGEMENT", + "CONTINUOUS_MONITORING", + "CRYPTOGRAPHIC_PROTECTIONS", + "DATA_CLASSIFICATION_&_HANDLING", + "EMBEDDED_TECHNOLOGY", + "ENDPOINT_SECURITY", + "HUMAN_RESOURCES_SECURITY", + "IDENTIFICATION_&_AUTHENTICATION", + "INCIDENT_RESPONSE", + "INFORMATION_ASSURANCE", + "MAINTENANCE", + "MOBILE_DEVICE_MANAGEMENT", + "NETWORK SECURITY", + "PHYSICAL_&_ENVIRONMENTAL_SECURITY", + "PRIVACY", + "PROJECT_&_RESOURCE MANAGEMENT", + "RISK_MANAGEMENT", + "SECURE_ENGINEERING_&_ARCHITECTURE", + "SECURITY_AWARENESS_&_TRAINING", + "SECURITY_OPERATIONS", + "SECURITY_&_PRIVACY_GOVERNANCE", + "TECHNOLOGY_DEVELOPMENT_&_ACQUISITION", + "THIRD-PARTY_MANAGEMENT", + "THREAT_MANAGEMENT", + "VULNERABILITY_&_PATCH_MANAGEMENT", + "WEB_SECURITY", + "ADMINISTRATIVE", + "PHYSICAL", + "TECHNICAL", + "BASIC", + "DERIVED" + ], + "type": "string" + }, + "FrameworkId": { + "enum": [ + "AU_E_8", + "AWS_FTR", + "CCPA", + "CIS_V8", + "CPS_234", + "DORA", + "FEDRAMP", + "GDPR", + "HIPAA", + "HITRUST_E1", + "ISO_27001", + "ISO_27001_2022", + "ISO_27017", + "ISO_27018", + "ISO_27701", + "ISO_42001", + "ISO_9001", + "MSFT_SSPA", + "MVSP", + "NIS_2D", + "NIST_171", + "NIST_171_R3", + "NIST_53", + "NIST_AI_RMF", + "NIST_CSF", + "NIST_CSF_2", + "OFDSS", + "PCI_SAQ_A", + "PCI_SAQ_A_EP", + "PCI_SAQ_D_MERCHANT", + "PCI_SAQ_D_SP", + "PCI_DDS_4", + "SOC_2", + "SOX_ITGC", + "UK_CYBER_ESSENTIALS", + "US_DATA_PRIVACY" + ], + "type": "string" + }, + "FrameworkSection": { + "properties": { + "frameworkId": { + "anyOf": [ + { + "$ref": "#/components/schemas/FrameworkId" + }, + { + "type": "string" + } + ] + }, + "sectionId": { + "type": "string" + } + }, + "required": [ + "frameworkId", + "sectionId" + ], + "type": "object", + "additionalProperties": false + }, + "GdprRole": { + "enum": [ + "BOTH", + "CONTROLLER", + "PROCESSOR" + ], + "type": "string" + }, + "CreateControlInput": { + "properties": { + "externalId": { + "type": "string", + "description": "The control's external ID." + }, + "name": { + "type": "string", + "nullable": true, + "description": "The control's name." + }, + "description": { + "type": "string", + "description": "The control's description." + }, + "effectiveDate": { + "type": "string", + "format": "date-time", + "description": "The effective date of the control." + }, + "domain": { + "$ref": "#/components/schemas/ControlDomain", + "description": "The control's category." + }, + "sections": { + "items": { + "$ref": "#/components/schemas/FrameworkSection" + }, + "type": "array", + "nullable": true, + "description": "The framework sections that the control maps to." + }, + "role": { + "allOf": [ + { + "$ref": "#/components/schemas/GdprRole" + } + ], + "nullable": true, + "description": "The GDPR role of the control, which specifies whether the data is being \"collected\" or \"processed\".\nThis field should only be included for controls that are to be mapped to the GDPR framework." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "The control's values for custom fields." + } + }, + "required": [ + "externalId", + "name", + "description", + "effectiveDate", + "domain" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlFromLibraryInput": { + "properties": { + "controlId": { + "type": "string", + "description": "The ID of the control to be added." + } + }, + "required": [ + "controlId" + ], + "type": "object", + "additionalProperties": false + }, + "ControlStatus": { + "enum": [ + "NO_EVIDENCE_MAPPED", + "NOT_STARTED", + "IN_PROGRESS", + "COMPLETED" + ], + "type": "string" + }, + "ControlDetail": { + "properties": { + "id": { + "type": "string", + "description": "The control's unique ID." + }, + "externalId": { + "type": "string", + "nullable": true, + "description": "The control's external ID." + }, + "name": { + "type": "string", + "description": "The control's name." + }, + "description": { + "type": "string", + "description": "The control's description." + }, + "source": { + "$ref": "#/components/schemas/ControlSource", + "description": "The control's source, either \"VANTA\" or \"CUSTOM\"." + }, + "domains": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The security domains that the control belongs to." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/Owner" + } + ], + "nullable": true, + "description": "The control's owner." + }, + "role": { + "type": "string", + "nullable": true, + "description": "The control's GDPR role, if the control is a GDPR control." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "The control's custom field values, if control custom fields is included in your Vanta instance." + }, + "creationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was created. Returns null for Vanta library controls." + }, + "modificationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was last modified. Returns null for Vanta library controls." + }, + "implementationDetails": { + "type": "string", + "nullable": true, + "description": "How the control is implemented." + }, + "numDocumentsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing documents that are linked to the control." + }, + "numDocumentsTotal": { + "type": "number", + "format": "double", + "description": "The total number of documents that are linked to the control." + }, + "numTestsPassing": { + "type": "number", + "format": "double", + "description": "The number of passing tests that are linked to the control." + }, + "numTestsTotal": { + "type": "number", + "format": "double", + "description": "The total number of tests that are linked to the control." + }, + "status": { + "$ref": "#/components/schemas/ControlStatus", + "description": "The status of the control as determined by number of passing tests and documents." + }, + "note": { + "type": "string", + "nullable": true, + "description": "A user created note for the control." + } + }, + "required": [ + "id", + "externalId", + "name", + "description", + "source", + "domains", + "owner", + "customFields", + "creationDate", + "modificationDate", + "numDocumentsPassing", + "numDocumentsTotal", + "numTestsPassing", + "numTestsTotal", + "status", + "note" + ], + "type": "object", + "additionalProperties": false + }, + "EditControlMetadataInput": { + "properties": { + "name": { + "type": "string", + "description": "A new name for the control." + }, + "externalId": { + "type": "string", + "description": "The new external ID for the control." + }, + "description": { + "type": "string", + "description": "The new description for the control." + }, + "domain": { + "$ref": "#/components/schemas/ControlDomain", + "description": "The new category for the control." + }, + "note": { + "type": "string", + "description": "The new note for the control." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "The control's new values for custom fields." + } + }, + "type": "object", + "additionalProperties": false + }, + "SetOwnerForControlInput": { + "properties": { + "userId": { + "type": "string", + "nullable": true, + "description": "The new owner's ID." + } + }, + "required": [ + "userId" + ], + "type": "object", + "additionalProperties": false + }, + "DeactivatedControlFramework": { + "properties": { + "id": { + "type": "string", + "description": "The framework's unique ID. Accepted by the `frameworkMatchesAny` filter on `GET /v1/controls`." + }, + "displayName": { + "type": "string", + "description": "The framework's display name." + }, + "shorthandName": { + "type": "string", + "description": "The short version of the framework's display name." + }, + "sections": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The shorthands of the framework's sections that the control maps to." + } + }, + "required": [ + "id", + "displayName", + "shorthandName", + "sections" + ], + "type": "object", + "additionalProperties": false + }, + "DeactivatedControl": { + "properties": { + "id": { + "type": "string", + "description": "The control's unique ID." + }, + "externalId": { + "type": "string", + "nullable": true, + "description": "The control's external ID." + }, + "name": { + "type": "string", + "description": "The control's name." + }, + "description": { + "type": "string", + "description": "The control's description." + }, + "source": { + "$ref": "#/components/schemas/ControlSource", + "description": "The control's source, either \"VANTA\" or \"CUSTOM\"." + }, + "domains": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The security domains that the control belongs to." + }, + "owner": { + "allOf": [ + { + "$ref": "#/components/schemas/Owner" + } + ], + "nullable": true, + "description": "The control's owner." + }, + "role": { + "type": "string", + "nullable": true, + "description": "The control's GDPR role, if the control is a GDPR control." + }, + "customFields": { + "items": { + "$ref": "#/components/schemas/CustomField" + }, + "type": "array", + "description": "The control's custom field values, if control custom fields is included in your Vanta instance." + }, + "creationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was created. Returns null for Vanta library controls." + }, + "modificationDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "When the control was last modified. Returns null for Vanta library controls." + }, + "implementationDetails": { + "type": "string", + "nullable": true, + "description": "How the control is implemented." + }, + "frameworks": { + "items": { + "$ref": "#/components/schemas/DeactivatedControlFramework" + }, + "type": "array", + "description": "The frameworks that the control is mapped to. Empty when the control maps to no framework the organization has enabled." + }, + "deactivationReason": { + "type": "string", + "nullable": true, + "description": "The reason given when the control was deactivated. Null when no reason was recorded, including for deactivations that predate the field." + } + }, + "required": [ + "id", + "externalId", + "name", + "description", + "source", + "domains", + "owner", + "customFields", + "creationDate", + "modificationDate", + "frameworks", + "deactivationReason" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_DeactivatedControl_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/DeactivatedControl" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlDocumentMappingInput": { + "properties": { + "documentId": { + "type": "string", + "description": "The ID of the document to add to the control." + } + }, + "required": [ + "documentId" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlDocumentsMappingResult": { + "properties": { + "mappedCount": { + "type": "number", + "format": "double", + "description": "The number of mappings this request created. Documents that were already\nmapped to the control are not counted, so re-submitting the same list\nreturns 0." + } + }, + "required": [ + "mappedCount" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlDocumentsMappingInput": { + "properties": { + "documentIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The IDs of the documents to map to the control. Documents already mapped to\nthe control are ignored and are not counted in `mappedCount`.", + "minItems": 1, + "maxItems": 300 + } + }, + "required": [ + "documentIds" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlTestMappingInput": { + "properties": { + "testId": { + "type": "string", + "description": "The ID of the test to add to the control." + } + }, + "required": [ + "testId" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlTestsMappingResult": { + "properties": { + "mappedCount": { + "type": "number", + "format": "double", + "description": "The number of mappings this request created. Tests that were already\nmapped to the control are not counted, so re-submitting the same list\nreturns 0." + } + }, + "required": [ + "mappedCount" + ], + "type": "object", + "additionalProperties": false + }, + "AddControlTestsMappingInput": { + "properties": { + "testIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "The IDs of the tests to map to the control. Tests already mapped to the\ncontrol are ignored and are not counted in `mappedCount`.", + "minItems": 1, + "maxItems": 300 + } + }, + "required": [ + "testIds" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobStatus": { + "type": "string", + "enum": [ + "NOT_STARTED", + "GENERATING", + "EXPORTING", + "COMPLETED" + ], + "description": "Lifecycle of a suggestion job, from accepted through finished." + }, + "EvidenceSuggestionJobScopeAll": { + "description": "Every in-scope control in the organization.", + "properties": { + "type": { + "type": "string", + "enum": [ + "ALL" + ], + "nullable": false + } + }, + "required": [ + "type" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobScopeFramework": { + "description": "The controls mapped to one framework.", + "properties": { + "type": { + "type": "string", + "enum": [ + "FRAMEWORK" + ], + "nullable": false + }, + "frameworkId": { + "type": "string" + } + }, + "required": [ + "type", + "frameworkId" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobScopeControls": { + "description": "Exactly the controls named.", + "properties": { + "type": { + "type": "string", + "enum": [ + "CONTROLS" + ], + "nullable": false + }, + "controlIds": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "required": [ + "type", + "controlIds" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobScope": { + "anyOf": [ + { + "$ref": "#/components/schemas/EvidenceSuggestionJobScopeAll" + }, + { + "$ref": "#/components/schemas/EvidenceSuggestionJobScopeFramework" + }, + { + "$ref": "#/components/schemas/EvidenceSuggestionJobScopeControls" + } + ], + "description": "Which controls a suggestion job covers." + }, + "EvidenceSuggestionJobError": { + "properties": { + "code": { + "type": "string", + "enum": [ + "CONTROL_NOT_FOUND", + "CONTROL_IGNORED", + "AI_WORKFLOW_FAILED", + "EXPORT_FAILED" + ] + }, + "message": { + "type": "string" + }, + "controlId": { + "type": "string", + "nullable": true, + "description": "The control the error is about, or null for a job-level error." + } + }, + "required": [ + "code", + "message", + "controlId" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobResult": { + "properties": { + "completedControls": { + "type": "number", + "format": "double", + "description": "Covered controls the job has finished, successfully or not." + }, + "failedControls": { + "type": "number", + "format": "double", + "description": "Covered controls the job failed to process." + }, + "totalSuggestions": { + "type": "number", + "format": "double", + "description": "Suggestions produced so far." + }, + "errors": { + "items": { + "$ref": "#/components/schemas/EvidenceSuggestionJobError" + }, + "type": "array" + } + }, + "required": [ + "completedControls", + "failedControls", + "totalSuggestions", + "errors" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJobControlStatus": { + "type": "string", + "enum": [ + "PENDING", + "SUCCESS", + "FAILURE" + ], + "description": "Per-control progress within a job. `PENDING` at creation, then `SUCCESS` or\n`FAILURE` once the job records that control's outcome." + }, + "EvidenceSuggestionJobControl": { + "properties": { + "controlId": { + "type": "string" + }, + "status": { + "$ref": "#/components/schemas/EvidenceSuggestionJobControlStatus" + } + }, + "required": [ + "controlId", + "status" + ], + "type": "object", + "additionalProperties": false + }, + "EvidenceSuggestionJob": { + "description": "An asynchronous job that generates evidence suggestions for a set of\ncontrols.", + "properties": { + "jobId": { + "type": "string", + "description": "Poll the job by this ID to follow its progress." + }, + "status": { + "$ref": "#/components/schemas/EvidenceSuggestionJobStatus" + }, + "scope": { + "$ref": "#/components/schemas/EvidenceSuggestionJobScope" + }, + "result": { + "$ref": "#/components/schemas/EvidenceSuggestionJobResult" + }, + "controls": { + "items": { + "$ref": "#/components/schemas/EvidenceSuggestionJobControl" + }, + "type": "array" + }, + "createdAt": { + "type": "string", + "format": "date-time" + }, + "completedAt": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "Null until the job finishes." + } + }, + "required": [ + "jobId", + "status", + "scope", + "result", + "controls", + "createdAt", + "completedAt" + ], + "type": "object", + "additionalProperties": false + }, + "CreateEvidenceSuggestionJobInputAll": { + "description": "Every custom control in the organization that is not ignored. An\norganization whose controls all come from the Vanta library has nothing in\nscope and is rejected.", + "properties": { + "type": { + "type": "string", + "enum": [ + "ALL" + ], + "nullable": false + }, + "includeInactive": { + "type": "boolean", + "description": "Whether to include deactivated controls. Defaults to `false`." + } + }, + "required": [ + "type" + ], + "type": "object", + "additionalProperties": false + }, + "CreateEvidenceSuggestionJobInputFramework": { + "description": "The framework's custom controls that are not ignored.", + "properties": { + "type": { + "type": "string", + "enum": [ + "FRAMEWORK" + ], + "nullable": false + }, + "frameworkId": { + "type": "string", + "description": "A Vanta framework name, such as `soc2`, or a custom framework's ID." + }, + "includeInactive": { + "type": "boolean", + "description": "Whether to include deactivated controls. Defaults to `false`." + } + }, + "required": [ + "type", + "frameworkId" + ], + "type": "object", + "additionalProperties": false + }, + "CreateEvidenceSuggestionJobInputControls": { + "description": "Exactly the controls named.", + "properties": { + "type": { + "type": "string", + "enum": [ + "CONTROLS" + ], + "nullable": false + }, + "controlIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "Duplicates are ignored. The cap bounds how much LLM work one request can\nqueue; use `ALL` or `FRAMEWORK` to cover a larger set.", + "minItems": 1, + "maxItems": 300 + }, + "includeInactive": { + "type": "boolean", + "description": "Whether to include deactivated controls. Defaults to `false`." + } + }, + "required": [ + "type", + "controlIds" + ], + "type": "object", + "additionalProperties": false + }, + "CreateEvidenceSuggestionJobInput": { + "anyOf": [ + { + "$ref": "#/components/schemas/CreateEvidenceSuggestionJobInputAll" + }, + { + "$ref": "#/components/schemas/CreateEvidenceSuggestionJobInputFramework" + }, + { + "$ref": "#/components/schemas/CreateEvidenceSuggestionJobInputControls" + } + ], + "description": "Which controls to generate evidence suggestions for." + }, + "Contract": { + "properties": { + "id": { + "type": "string", + "description": "Unique identifier for the contract." + }, + "externalId": { + "type": "string", + "nullable": true, + "description": "Stable source-system identifier for the contract, if any." + }, + "name": { + "type": "string", + "description": "Name of the contract." + }, + "customerTrustAccountId": { + "type": "string", + "nullable": true, + "description": "The ID of the customer trust account this contract is linked to, if any." + }, + "executedDate": { + "type": "string", + "format": "date-time", + "nullable": true, + "description": "Date this contract was executed." + }, + "creationDate": { + "type": "string", + "format": "date-time", + "description": "Date this contract was created in Vanta." + } + }, + "required": [ + "id", + "externalId", + "name", + "customerTrustAccountId", + "executedDate", + "creationDate" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_Contract_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/Contract" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "BusinessUnit": { + "properties": { + "id": { + "type": "string", + "description": "The business unit's unique ID." + }, + "displayName": { + "type": "string", + "description": "The business unit's display name." + } + }, + "required": [ + "id", + "displayName" + ], + "type": "object", + "additionalProperties": false + }, + "PaginatedResponse_BusinessUnit_": { + "properties": { + "results": { + "properties": { + "data": { + "items": { + "$ref": "#/components/schemas/BusinessUnit" + }, + "type": "array" + }, + "pageInfo": { + "$ref": "#/components/schemas/PageInfo" + } + }, + "required": [ + "data", + "pageInfo" + ], + "type": "object" + } + }, + "required": [ + "results" + ], + "type": "object", + "additionalProperties": false + }, + "TagIdentifier": { + "properties": { + "categoryId": { + "type": "string" + }, + "categoryName": { + "type": "string" + }, + "tagId": { + "type": "string" + }, + "tagName": { + "type": "string" + } + }, + "required": [ + "categoryId", + "categoryName", + "tagId", + "tagName" + ], + "type": "object", + "additionalProperties": false + }, + "QuestionAnswerOutput": { + "properties": { + "question": { + "type": "string", + "description": "The question text." + }, + "lastUpdated": { + "type": "string", + "format": "date-time", + "description": "The most recent date the question or answer was updated." + }, + "answer": { + "properties": { + "fullText": { + "type": "string" + }, + "multipleChoice": { + "type": "string", + "nullable": true + }, + "explanation": { + "type": "string", + "nullable": true + } + }, + "required": [ + "fullText", + "multipleChoice", + "explanation" + ], + "type": "object" + }, + "id": { + "type": "string", + "description": "The id of the upserted entry." + }, + "tagIdentifiers": { + "items": { + "$ref": "#/components/schemas/TagIdentifier" + }, + "type": "array", + "description": "A list of tags associated with this Answer Library entry." + } + }, + "required": [ + "question", + "lastUpdated", + "answer", + "id", + "tagIdentifiers" + ], + "type": "object", + "additionalProperties": false + }, + "QuestionAnswerInput": { + "properties": { + "question": { + "type": "string", + "description": "The question text." + }, + "lastUpdated": { + "type": "string", + "format": "date-time", + "description": "The most recent date the question or answer was updated." + }, + "answer": { + "type": "string", + "description": "The answer text." + }, + "tagAndCategoryIds": { + "items": { + "$ref": "#/components/schemas/TagInput" + }, + "type": "array" + } + }, + "required": [ + "question", + "lastUpdated", + "answer" + ], + "type": "object", + "additionalProperties": false + } + }, + "securitySchemes": { + "oauth": { + "type": "oauth2", + "description": "Get an oauth token from the token url and use it as a bearer token to access the Vanta API.", + "flows": { + "clientCredentials": { + "scopes": { + "vanta-api.all:read": "Grant read-only access to all your data", + "vanta-api.all:write": "Grant read-write access to all your data", + "vanta-api.vendors:read": "Grant read-only access to your vendors and all its subresources", + "vanta-api.vendors:write": "Grant read-write access to your vendors and all its subresources", + "vanta-api.documents:read": "Grant read-only access to your documents and all its subresources", + "vanta-api.documents:list": "Grant read-only access to listing documents", + "vanta-api.documents:write": "Grant read-write access to your documents and all its subresources", + "vanta-api.documents:upload": "Grant ability to upload documents to Vanta", + "vanta-api.issues:read": "Grant read-only access to your issues", + "vanta-api.issues:write": "Grant read-write access to your issues" + }, + "tokenUrl": "https://api.vanta.com/oauth/token" + } + } + }, + "bearerAuth": { + "type": "http", + "scheme": "bearer" + } + } + }, + "info": { + "title": "Manage Vanta", + "version": "1.0.0", + "description": "The REST API lets customers query and mutate Vanta's data. Use this API to automate bulk actions, query data for custom workflows and dashboards, and bolster your security operations\n\n**Note for Vanta Gov (FedRAMP) customers:** Select `Vanta Gov (FedRAMP)` from the server dropdown to issue requests against `https://api.vanta-gov.com`. The OAuth token URL shown below defaults to the commercial host — replace it with `https://api.vanta-gov.com/oauth/token`.", + "termsOfService": "https://www.vanta.com/terms", + "license": { + "name": "UNLICENSED" + }, + "contact": { + "name": "API Support", + "url": "https://help.vanta.com/", + "email": "support@vanta.com" + } + }, + "paths": { + "/business-units": { + "get": { + "operationId": "ListBusinessUnits", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_BusinessUnit_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "00206cf50ff41cfcc8b71921", + "displayName": "Default Business Unit" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "MDAyMDZjZjUwZmY0MWNmY2M4YjcxOTIx", + "endCursor": "MDAyMDZjZjUwZmY0MWNmY2M4YjcxOTIx" + } + } + } + } + } + } + } + } + }, + "description": "Lists the business units for your organization.\nReturns 403 when business unit scoping is disabled for the domain.", + "summary": "List business units", + "tags": [ + "Business Units" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/business-units/{businessUnitId}": { + "get": { + "operationId": "GetBusinessUnit", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/BusinessUnit" + }, + "examples": { + "Example 1": { + "value": { + "id": "00206cf50ff41cfcc8b71921", + "displayName": "Default Business Unit" + } + } + } + } + } + } + }, + "description": "Get a business unit by ID.\nReturns 403 when business unit scoping is disabled for the domain.", + "summary": "Get business unit by ID", + "tags": [ + "Business Units" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "businessUnitId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/contracts": { + "post": { + "operationId": "UploadContract", + "responses": { + "201": { + "description": "Contract created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Contract" + }, + "examples": { + "Example 1": { + "value": { + "id": "65e1efde08e8478f143a8ff9", + "externalId": "sharepoint-drive-item-123", + "name": "Example Contract", + "customerTrustAccountId": null, + "executedDate": "2024-01-15T00:00:00.000Z", + "creationDate": "2024-01-01T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Upload a contract.\n\nRate limit: 10 requests / minute.", + "summary": "Upload contract", + "tags": [ + "Contracts" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "multipart/form-data": { + "schema": { + "type": "object", + "properties": { + "file": { + "type": "string", + "format": "binary", + "description": "The contract file to upload. Only PDF files are accepted." + }, + "executedDate": { + "type": "string", + "description": "ISO 8601 date indicating when the contract was executed." + }, + "accountId": { + "type": "string", + "description": "ID of the customer trust account to associate with this contract." + }, + "externalId": { + "type": "string", + "description": "Stable source-system identifier used to reject duplicate contract uploads; repeats return 409. Use the upstream document or record ID when available, such as the Microsoft Graph DriveItem ID for SharePoint or the Ironclad record ID for Ironclad. If there is no source system, generate and store a durable idempotency key. Maximum 256 characters." + } + }, + "required": [ + "file" + ] + } + } + } + } + }, + "get": { + "operationId": "ListContracts", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_Contract_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "65e1efde08e8478f143a8ff9", + "externalId": "sharepoint-drive-item-123", + "name": "Example Contract", + "customerTrustAccountId": null, + "executedDate": "2024-01-15T00:00:00.000Z", + "creationDate": "2024-01-01T00:00:00.000Z" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "65e1efde08e8478f143a8ff9", + "endCursor": "65e1efde08e8478f143a8ff9" + } + } + } + } + } + } + } + } + }, + "description": "List contracts, paginated.", + "summary": "List contracts", + "tags": [ + "Contracts" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/contracts/{contractId}": { + "get": { + "operationId": "GetContract", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Contract" + }, + "examples": { + "Example 1": { + "value": { + "id": "65e1efde08e8478f143a8ff9", + "externalId": "sharepoint-drive-item-123", + "name": "Example Contract", + "customerTrustAccountId": null, + "executedDate": "2024-01-15T00:00:00.000Z", + "creationDate": "2024-01-01T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Get a contract by ID.", + "summary": "Get contract", + "tags": [ + "Contracts" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "contractId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "DeleteContract", + "responses": { + "204": { + "description": "Contract deleted" + } + }, + "description": "Delete a contract by ID.", + "summary": "Delete contract", + "tags": [ + "Contracts" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "contractId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/controls": { + "post": { + "operationId": "CreateCustomControl", + "responses": { + "201": { + "description": "Custom Control created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Control" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + } + } + } + } + } + }, + "description": "Create a custom control.", + "summary": "Create custom control", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateControlInput" + } + } + } + } + }, + "get": { + "operationId": "ListControls", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_Control_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "totalCount": 1 + } + } + } + } + } + } + } + }, + "description": "List controls.", + "summary": "List controls", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Includes all controls belonging to one of the provided framework values in frameworkMatchesAny.", + "in": "query", + "name": "frameworkMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + } + } + ] + } + }, + "/controls/add-from-library": { + "post": { + "operationId": "AddControlFromLibrary", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Control" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + } + } + } + } + } + }, + "description": "Add a control from the Vanta library to your organization's controls.", + "summary": "Add control from Vanta library", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/AddControlFromLibraryInput" + } + } + } + } + } + }, + "/controls/controls-library": { + "get": { + "operationId": "ListLibraryControls", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_DeactivatedControl_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "frameworks": [ + { + "id": "iso27001_2022", + "displayName": "ISO 27001:2022", + "shorthandName": "ISO 27001", + "sections": [ + "A.8.24", + "A.5.33" + ] + } + ], + "deactivationReason": "Not applicable to our scope" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "totalCount": 1 + } + } + } + } + } + } + } + }, + "description": "List Vanta controls from the library.", + "summary": "List Vanta controls from the library", + "tags": [ + "Controls" + ], + "deprecated": true, + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/controls/deactivated-controls": { + "get": { + "operationId": "ListDeactivatedControls", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_DeactivatedControl_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "frameworks": [ + { + "id": "iso27001_2022", + "displayName": "ISO 27001:2022", + "shorthandName": "ISO 27001", + "sections": [ + "A.8.24", + "A.5.33" + ] + } + ], + "deactivationReason": "Not applicable to our scope" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "totalCount": 1 + } + } + } + } + } + } + } + }, + "description": "List deactivated Vanta controls (previously known as the controls library).", + "summary": "List deactivated controls", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/controls/{controlId}": { + "patch": { + "operationId": "UpdateControlMetadata", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ControlDetail" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "note": "Remember to do by Friday", + "numDocumentsPassing": 1, + "numDocumentsTotal": 1, + "numTestsPassing": 2, + "numTestsTotal": 3, + "status": "IN_PROGRESS", + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + } + } + } + } + } + }, + "description": "Update a control's metadata.", + "summary": "Update a control's metadata", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EditControlMetadataInput" + } + } + } + } + }, + "delete": { + "operationId": "DeleteControl", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Deactivates a custom or Vanta control.", + "summary": "Deactivates a control", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "get": { + "operationId": "GetControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ControlDetail" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "note": "Remember to do by Friday", + "numDocumentsPassing": 1, + "numDocumentsTotal": 1, + "numTestsPassing": 2, + "numTestsTotal": 3, + "status": "IN_PROGRESS", + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + } + } + } + } + } + }, + "description": "Get a control by an ID.", + "summary": "Get control by an ID", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/controls/{controlId}/add-document-to-control": { + "post": { + "operationId": "AddDocumentToControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "properties": { + "document": { + "$ref": "#/components/schemas/Document" + }, + "control": { + "$ref": "#/components/schemas/Control" + } + }, + "required": [ + "document", + "control" + ], + "type": "object" + }, + "examples": { + "Example 1": { + "value": { + "control": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + }, + "document": { + "id": "1", + "ownerId": "2", + "category": "Account setup", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "title": "Document Title", + "uploadStatus": "Needs document", + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "url": "https://example.com" + } + } + } + } + } + } + } + }, + "description": "Add a document to a control.", + "summary": "Add control to document mapping", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/AddControlDocumentMappingInput" + } + } + } + } + } + }, + "/controls/{controlId}/add-test-to-control": { + "post": { + "operationId": "AddTestToControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "properties": { + "test": { + "$ref": "#/components/schemas/Test" + }, + "control": { + "$ref": "#/components/schemas/Control" + } + }, + "required": [ + "test", + "control" + ], + "type": "object" + }, + "examples": { + "Example 1": { + "value": { + "control": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + }, + "test": { + "id": "aws-account-access-removed-on-termination", + "name": "AWS accounts deprovisioned when personnel leave", + "lastTestRunDate": "2024-06-18T20:17:38.463Z", + "latestFlipDate": null, + "description": "Verifies that AWS accounts linked to removed users are removed.\n", + "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", + "remediationDescription": "Remove all accounts listed from AWS.\n", + "version": { + "major": 0, + "minor": 0 + }, + "category": "Account security", + "integrations": [ + "aws" + ], + "status": "OK", + "deactivatedStatusInfo": { + "isDeactivated": false, + "deactivatedReason": null, + "lastUpdatedDate": null + }, + "remediationStatusInfo": { + "status": "PASS", + "soonestRemediateByDate": null, + "itemCount": 0 + }, + "owner": null + } + } + } + } + } + } + } + }, + "description": "Add a control to test mapping.", + "summary": "Add control to test mapping", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/AddControlTestMappingInput" + } + } + } + } + } + }, + "/controls/{controlId}/documents": { + "get": { + "operationId": "ListDocumentsForControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_Document_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "1", + "ownerId": "2", + "category": "Account setup", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "title": "Document Title", + "uploadStatus": "Needs document", + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "url": "https://example.com" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" + } + } + } + } + } + } + } + } + }, + "description": "List a control's documents.", + "summary": "List a control's documents", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/controls/{controlId}/documents/{documentId}": { + "delete": { + "operationId": "DeleteDocumentForcontrol", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Remove a document by ID from a control.", + "summary": "Remove control from document mapping", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "documentId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/controls/{controlId}/set-owner": { + "post": { + "operationId": "SetOwnerForControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Control" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + } + } + } + } + } + }, + "description": "Assign a control to a user or remove an owner from a control.", + "summary": "Set owner of a control", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/SetOwnerForControlInput" + } + } + } + } + } + }, + "/controls/{controlId}/tests": { + "get": { + "operationId": "ListTestsForControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_Test_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "aws-account-access-removed-on-termination", + "name": "AWS accounts deprovisioned when personnel leave", + "lastTestRunDate": "2024-06-18T20:17:38.463Z", + "latestFlipDate": null, + "description": "Verifies that AWS accounts linked to removed users are removed.\n", + "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", + "remediationDescription": "Remove all accounts listed from AWS.\n", + "version": { + "major": 0, + "minor": 0 + }, + "category": "Account security", + "integrations": [ + "aws" + ], + "status": "OK", + "deactivatedStatusInfo": { + "isDeactivated": false, + "deactivatedReason": null, + "lastUpdatedDate": null + }, + "remediationStatusInfo": { + "status": "PASS", + "soonestRemediateByDate": null, + "itemCount": 0 + }, + "owner": null + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" + } + } + } + } + } + } + } + } + }, + "description": "List a control's tests.", + "summary": "List a control's tests", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/controls/{controlId}/tests/{testId}": { + "delete": { + "operationId": "DeleteTestForControl", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Remove a control from test mapping.", + "summary": "Remove control from test mapping", + "tags": [ + "Controls" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "testId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/customer-trust/accounts": { + "get": { + "operationId": "ListCustomerTrustAccounts", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_CustomerTrustAccountVantaApi_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "pageInfo": { + "hasNextPage": true, + "hasPreviousPage": false, + "startCursor": "cursor1", + "endCursor": "cursor2" + }, + "data": [ + { + "id": "507f1f77bcf86cd799439011", + "name": "Acme Corporation", + "emailDomain": "acme.com", + "createdDate": "2024-01-01T00:00:00.000Z", + "updatedDate": "2024-01-02T00:00:00.000Z", + "ndaDetails": { + "ndaStatus": "SIGNED", + "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" + }, + "accessConfig": { + "autoApprovalEnabled": false, + "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" + }, + "customFields": [ + { + "label": "externalId", + "value": "12345" + } + ], + "tagsByCategory": [ + { + "categoryId": "507f1f77bcf86cd799439012", + "tagIds": [ + "507f1f77bcf86cd799439013" + ] + } + ] + } + ] + } + } + } + } + } + } + } + }, + "description": "List customer trust accounts with pagination.", + "summary": "List customer trust accounts", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "in": "query", + "name": "searchString", + "required": false, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "isAutoApprovalEnabled", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "in": "query", + "name": "customFieldsFilter", + "required": false, + "schema": { + "type": "string" + } + } + ] + }, + "post": { + "operationId": "CreateCustomerTrustAccount", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "name": "Acme Corporation", + "emailDomain": "acme.com", + "createdDate": "2024-01-01T00:00:00.000Z", + "updatedDate": "2024-01-02T00:00:00.000Z", + "ndaDetails": { + "ndaStatus": "SIGNED", + "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" + }, + "accessConfig": { + "autoApprovalEnabled": false, + "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" + }, + "customFields": [ + { + "label": "externalId", + "value": "12345" + } + ], + "tagsByCategory": [ + { + "categoryId": "507f1f77bcf86cd799439012", + "tagIds": [ + "507f1f77bcf86cd799439013" + ] + } + ] + } + } + } + } + } + } + }, + "description": "Create a new customer trust account.", + "summary": "Create customer trust account", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateCustomerTrustAccountInput" + } + } + } + } + } + }, + "/customer-trust/accounts/{accountId}": { + "get": { + "operationId": "GetCustomerTrustAccount", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "name": "Acme Corporation", + "emailDomain": "acme.com", + "createdDate": "2024-01-01T00:00:00.000Z", + "updatedDate": "2024-01-02T00:00:00.000Z", + "ndaDetails": { + "ndaStatus": "SIGNED", + "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" + }, + "accessConfig": { + "autoApprovalEnabled": false, + "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" + }, + "customFields": [ + { + "label": "externalId", + "value": "12345" + } + ], + "tagsByCategory": [ + { + "categoryId": "507f1f77bcf86cd799439012", + "tagIds": [ + "507f1f77bcf86cd799439013" + ] + } + ] + } + } + } + } + } + } + }, + "description": "Get a specific customer trust account by ID.", + "summary": "Get customer trust account", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "accountId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "DeleteCustomerTrustAccount", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Delete a customer trust account by ID.", + "summary": "Delete customer trust account", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "accountId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "patch": { + "operationId": "UpdateCustomerTrustAccount", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "name": "Acme Corporation", + "emailDomain": "acme.com", + "createdDate": "2024-01-01T00:00:00.000Z", + "updatedDate": "2024-01-02T00:00:00.000Z", + "ndaDetails": { + "ndaStatus": "SIGNED", + "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" + }, + "accessConfig": { + "autoApprovalEnabled": false, + "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" + }, + "customFields": [ + { + "label": "externalId", + "value": "12345" + } + ], + "tagsByCategory": [ + { + "categoryId": "507f1f77bcf86cd799439012", + "tagIds": [ + "507f1f77bcf86cd799439013" + ] + } + ] + } + } + } + } + } + } + }, + "description": "Update a customer trust account by ID.", + "summary": "Update customer trust account", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "accountId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EditCustomerTrustAccountInput" + } + } + } + } + } + }, + "/customer-trust/deletion-requests": { + "post": { + "operationId": "CreateDeletionRequest", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateDeletionRequestResponse" + }, + "examples": { + "Example 1": { + "value": { + "isSuccessful": true + } + } + } + } + } + } + }, + "description": "Submit a Right to Be Forgotten (RTBF) data deletion request for the specified email address.", + "summary": "Create data deletion request", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateDeletionRequestInput" + } + } + } + } + } + }, + "/customer-trust/questionnaires": { + "get": { + "operationId": "ListQuestionnaires", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_CustomerTrustQuestionnaire_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "507f1f77bcf86cd799439011", + "endCursor": "507f1f77bcf86cd799439011" + } + } + } + } + } + } + } + } + }, + "description": "List questionnaires with filtering and pagination.", + "summary": "List questionnaires", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Filter questionnaires by display name (case-insensitive, partial match).", + "in": "query", + "name": "q", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter questionnaires matching any of the provided statuses.", + "in": "query", + "name": "statusMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/QuestionnaireStatus" + } + } + }, + { + "description": "Filter questionnaires matching any of the provided types.", + "in": "query", + "name": "typeMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaireType" + } + } + }, + { + "description": "Filter to questionnaires created after this date (ISO 8601 string).", + "in": "query", + "name": "createdAfter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter to questionnaires created before this date (ISO 8601 string).", + "in": "query", + "name": "createdBefore", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter to questionnaires owned by any of the provided user IDs.", + "in": "query", + "name": "ownerIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + } + }, + { + "description": "Filter to questionnaires with an approver matching any of the provided user IDs.", + "in": "query", + "name": "approverIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + } + } + ] + } + }, + "/customer-trust/questionnaires/assignable-users": { + "get": { + "operationId": "ListAssignableUsers", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/QuestionnaireAssignableUsersResponse" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "usr_1234567890", + "displayName": "Jane Doe" + } + ] + } + } + } + } + } + } + } + }, + "description": "List users who can be assigned as owner or approver on a questionnaire.\n\nWhen a role is specified, results are filtered to users with that role's required permission.\nWhen omitted, users assignable to either role are returned.\nResults can optionally be narrowed by a search string.", + "summary": "List assignable users", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "description": "Filter by role: \"owner\" or \"approver\".", + "in": "query", + "name": "role", + "required": false, + "schema": { + "$ref": "#/components/schemas/QuestionnaireAssignableUserRole" + } + }, + { + "description": "Optional search string to filter users by name or email.", + "in": "query", + "name": "q", + "required": false, + "schema": { + "type": "string" + } + } + ] + } + }, + "/customer-trust/questionnaires/exports": { + "post": { + "operationId": "CreateQuestionnaireExport", + "responses": { + "202": { + "description": "Export created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustCreateQuestionnaireExportResponse" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "status": "pending", + "format": "original", + "requestedAt": "2025-01-08T12:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Creates an asynchronous export job for a questionnaire. The export processes in the background\nand typically completes within a few minutes depending on questionnaire size.\n\nSubscribe to the `v1.questionnaire.export-completed` and `v1.questionnaire.export-failed` webhook events to be notified when an export completes or fails.\nUse the returned `id` with the \"getQuestionnaireExport\" endpoint to retrieve the download URL once the export completes.", + "summary": "Create questionnaire export", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustCreateQuestionnaireExportInput" + } + } + } + } + } + }, + "/customer-trust/questionnaires/exports/{id}": { + "get": { + "operationId": "GetQuestionnaireExport", + "responses": { + "200": { + "description": "The export status and, if completed, the download URL.", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustExportStatusResponse" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "status": "completed", + "format": "original", + "requestedAt": "2025-01-08T12:00:00.000Z", + "completedAt": "2025-01-08T12:05:00.000Z", + "downloadUrl": "https://storage.example.com/exports/questionnaire-export.xlsx?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9&expires=1736424000", + "expiresAt": "2025-01-09T12:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Retrieves the current status and result of a questionnaire export using the id received from either the `createQuestionnaireExport` endpoint or the `v1.questionnaire.export-completed` webhook payload.\n\nThis endpoint utilizes a dynamic response schema that changes based on the value of the status field:\n\n - pending: The export is currently in the queue or processing. Only base metadata is returned.\n - completed: The export finished successfully. The response expands to include completedAt and a downloadUrl. This pre-signed URL is valid for 24 hours; if it expires, simply call this endpoint again to retrieve a fresh, active link.\n - failed: The process encountered an error. The response expands to include failedAt and an errorMessage detailing the reason for failure.\n\nDevelopers should first check the status string before attempting to access result-specific fields like downloadUrl or errorMessage.", + "summary": "Get questionnaire export status", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "description": "The unique identifier of the export job, returned from the POST endpoint.", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/customer-trust/questionnaires/file": { + "post": { + "operationId": "CreateFileQuestionnaire", + "responses": { + "201": { + "description": "File questionnaire created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Create a new file-based questionnaire from an uploaded file (.xlsx, .docx, .pdf). File type is inferred as `SPREADSHEET` or `DOCUMENT` based on the uploaded file.", + "summary": "Create file questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "multipart/form-data": { + "schema": { + "type": "object", + "properties": { + "file": { + "type": "string", + "format": "binary" + }, + "displayName": { + "type": "string", + "description": "Display name for the questionnaire." + }, + "ownerAssignment": { + "type": "string", + "description": "Owner to assign, as a JSON string: {\"type\": \"User\" | \"Team\", \"id\": \"\"}." + }, + "approverAssignment": { + "type": "string", + "description": "Approver to assign, as a JSON string: {\"type\": \"User\" | \"Team\", \"id\": \"\"}." + }, + "description": { + "type": "string", + "description": "Description of the questionnaire." + }, + "companyUrl": { + "type": "string", + "description": "URL of the company associated with this questionnaire." + }, + "dueDate": { + "type": "string", + "description": "Due date for questionnaire completion." + }, + "customerTrustAccountId": { + "type": "string", + "description": "ID of the customer trust account to associate with this questionnaire." + }, + "includeUntaggedEntitiesForCategoryIds": { + "type": "string", + "description": "Comma-separated category IDs for which to include untagged entities." + }, + "metadata": { + "type": "string", + "description": "Custom key-value pairs, as a JSON string array: [{\"key\": \"\", \"value\": \"\"}]. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods." + }, + "tagAndCategoryIds": { + "type": "string", + "description": "Tags to assign, as a JSON string array: [{\"categoryId\": \"\", \"tagId\": \"\"}]. Replaces all existing tags." + } + }, + "required": [ + "file", + "displayName" + ] + } + } + } + } + } + }, + "/customer-trust/questionnaires/website": { + "post": { + "operationId": "CreateWebsiteQuestionnaire", + "responses": { + "201": { + "description": "Website questionnaire created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Create a new website-based questionnaire from a portal URL.\n\nThe portal URL is used to fetch questionnaire content from the target website.", + "summary": "Create website questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateWebsiteQuestionnaireInput" + } + } + } + } + } + }, + "/customer-trust/questionnaires/{questionnaireId}": { + "get": { + "operationId": "GetQuestionnaire", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Retrieve a questionnaire by ID.", + "summary": "Get questionnaire by ID", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "DeleteQuestionnaire", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Delete a questionnaire by ID.", + "summary": "Delete questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "patch": { + "operationId": "UpdateQuestionnaire", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Update an existing questionnaire.\n\nUpdates one or more fields of a questionnaire.\nThis endpoint cannot be used to set a questionnaire's status to `APPROVED` or `COMPLETED`. To perform those specific transitions, please use the `approveQuestionnaire` and `completeQuestionnaire` endpoints, respectively.", + "summary": "Update questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateQuestionnaireArgs" + } + } + } + } + } + }, + "/customer-trust/questionnaires/{questionnaireId}/approve": { + "post": { + "operationId": "ApproveQuestionnaire", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Mark a questionnaire as `APPROVED` and optionally provide a `statusChangeMessage`.", + "summary": "Approve questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ApproveQuestionnaireRequest" + } + } + } + } + } + }, + "/customer-trust/questionnaires/{questionnaireId}/complete": { + "post": { + "operationId": "CompleteQuestionnaire", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439011", + "displayName": "SOC 2 Security Questionnaire", + "type": "SPREADSHEET", + "status": "IN_PROGRESS", + "statusLog": [], + "dueDate": "2024-12-31T00:00:00.000Z", + "metadata": [ + { + "key": "priority", + "value": "high" + } + ], + "tagAndCategoryIds": [], + "createdDate": "2024-12-01T00:00:00.000Z", + "updatedDate": "2024-12-14T00:00:00.000Z" + } + } + } + } + } + } + }, + "description": "Complete a questionnaire and optionally sync approved answers to the answer library.\n\nTransitions the questionnaire status to COMPLETE. If `shouldSyncApprovedToAnswerLibrary` is true\n(the default), approved answers are added to the answer library for future use. For\nnon-English SPREADSHEET or DOCUMENT questionnaires, answer library sync will be ignored.", + "summary": "Complete questionnaire", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CompleteQuestionnaireRequest" + } + } + } + } + } + }, + "/customer-trust/questionnaires/{questionnaireId}/responses": { + "get": { + "operationId": "ListQuestionnaireResponses", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_QuestionnaireResponseWithoutViewerPermissions_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "000000000000000000000001", + "question": "Do you encrypt customer data at rest?", + "isPendingAnswerGeneration": false, + "answerPartsSchema": { + "type": "object", + "properties": { + "explanation": { + "type": "string", + "title": "Explanation" + } + } + }, + "answerPartsValues": { + "explanation": "Yes, we encrypt all customer data at rest with AES-256." + }, + "ownerAssignment": { + "type": "User", + "id": "000000000000000000000002", + "displayName": "Jane Doe" + } + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "000000000000000000000001", + "endCursor": "000000000000000000000001" + } + } + } + } + } + } + } + } + }, + "description": "List the responses on a questionnaire. Each response carries its\n`answerPartsSchema` and `answerPartsValues`, which describe the parts an\nanswer is composed of and their current values.", + "summary": "List questionnaire responses", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Filter responses by question text (case-insensitive, partial match).", + "in": "query", + "name": "q", + "required": false, + "schema": { + "type": "string" + } + } + ] + } + }, + "/customer-trust/questionnaires/{questionnaireId}/responses/{responseId}": { + "get": { + "operationId": "GetQuestionnaireResponse", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/QuestionnaireResponseWithoutViewerPermissions" + }, + "examples": { + "Example 1": { + "value": { + "id": "000000000000000000000001", + "question": "Do you encrypt customer data at rest?", + "isPendingAnswerGeneration": false, + "answerPartsSchema": { + "type": "object", + "properties": { + "explanation": { + "type": "string", + "title": "Explanation" + } + } + }, + "answerPartsValues": { + "explanation": "Yes, we encrypt all customer data at rest with AES-256." + }, + "ownerAssignment": { + "type": "User", + "id": "000000000000000000000002", + "displayName": "Jane Doe" + } + } + } + } + } + } } }, - "required": [ - "question", - "lastUpdated", - "answer" + "description": "Retrieve a single questionnaire response.", + "summary": "Get questionnaire response", + "tags": [ + "Customer Trust" ], - "type": "object", - "additionalProperties": false - } - }, - "securitySchemes": { - "oauth": { - "type": "oauth2", - "description": "Get an oauth token from the token url and use it as a bearer token to access the Vanta API.", - "flows": { - "clientCredentials": { - "scopes": { - "vanta-api.all:read": "Grant read-only access to all your data", - "vanta-api.all:write": "Grant read-write access to all your data", - "vanta-api.vendors:read": "Grant read-only access to your vendors and all its subresources", - "vanta-api.vendors:write": "Grant read-write access to your vendors and all its subresources", - "vanta-api.documents:read": "Grant read-only access to your documents and all its subresources", - "vanta-api.documents:list": "Grant read-only access to listing documents", - "vanta-api.documents:write": "Grant read-write access to your documents and all its subresources", - "vanta-api.documents:upload": "Grant ability to upload documents to Vanta", - "vanta-api.issues:read": "Grant read-only access to your issues", - "vanta-api.issues:write": "Grant read-write access to your issues" - }, - "tokenUrl": "https://api.vanta.com/oauth/token" + "security": [ + { + "bearerAuth": [] } - } + ], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "responseId", + "required": true, + "schema": { + "type": "string" + } + } + ] }, - "bearerAuth": { - "type": "http", - "scheme": "bearer" - } - } - }, - "info": { - "title": "Manage Vanta", - "version": "1.0.0", - "description": "The REST API lets customers query and mutate Vanta's data. Use this API to automate bulk actions, query data for custom workflows and dashboards, and bolster your security operations\n\n**Note for Vanta Gov (FedRAMP) customers:** Select `Vanta Gov (FedRAMP)` from the server dropdown to issue requests against `https://api.vanta-gov.com`. The OAuth token URL shown below defaults to the commercial host — replace it with `https://api.vanta-gov.com/oauth/token`.", - "termsOfService": "https://www.vanta.com/terms", - "license": { - "name": "UNLICENSED" - }, - "contact": { - "name": "API Support", - "url": "https://help.vanta.com/", - "email": "support@vanta.com" - } - }, - "paths": { - "/contracts": { - "post": { - "operationId": "UploadContract", + "patch": { + "operationId": "UpdateQuestionnaireResponseContent", "responses": { - "201": { - "description": "Contract created", + "200": { + "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Contract" + "$ref": "#/components/schemas/QuestionnaireResponseWithoutViewerPermissions" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "name": "Example Contract", - "customerTrustAccountId": null, - "executedDate": "2024-01-15T00:00:00.000Z", - "creationDate": "2024-01-01T00:00:00.000Z" + "id": "000000000000000000000001", + "question": "Do you encrypt customer data at rest?", + "isPendingAnswerGeneration": false, + "answerPartsSchema": { + "type": "object", + "properties": { + "explanation": { + "type": "string", + "title": "Explanation" + } + } + }, + "answerPartsValues": { + "explanation": "Yes, we encrypt all customer data at rest with AES-256." + }, + "ownerAssignment": { + "type": "User", + "id": "000000000000000000000002", + "displayName": "Jane Doe" + } } } } @@ -12379,75 +17959,79 @@ } } }, - "description": "Upload a contract.", - "summary": "Upload contract", + "description": "Update the answer content of a questionnaire response. The edit is\nrecorded as performed by the calling application, since vanta-api\nauthenticates an OAuth client rather than a specific user.", + "summary": "Update questionnaire response content", "tags": [ - "Contracts" + "Customer Trust" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], + "parameters": [ + { + "in": "path", + "name": "questionnaireId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "responseId", + "required": true, + "schema": { + "type": "string" + } + } + ], "requestBody": { "required": true, "content": { - "multipart/form-data": { + "application/json": { "schema": { - "type": "object", - "properties": { - "file": { - "type": "string", - "format": "binary", - "description": "The contract file to upload. Only PDF files are accepted." - }, - "executedDate": { - "type": "string", - "description": "ISO 8601 date indicating when the contract was executed." - }, - "accountId": { - "type": "string", - "description": "ID of the customer trust account to associate with this contract." - } - }, - "required": [ - "file" - ] + "$ref": "#/components/schemas/UpdateQuestionnaireResponseContentArgs" } } } } - }, - "get": { - "operationId": "ListContracts", + } + }, + "/customer-trust/questionnaires/{questionnaireId}/responses/{responseId}/owner": { + "patch": { + "operationId": "UpdateQuestionnaireResponseOwner", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Contract_" + "$ref": "#/components/schemas/QuestionnaireResponseWithoutViewerPermissions" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "65e1efde08e8478f143a8ff9", - "name": "Example Contract", - "customerTrustAccountId": null, - "executedDate": "2024-01-15T00:00:00.000Z", - "creationDate": "2024-01-01T00:00:00.000Z" + "id": "000000000000000000000001", + "question": "Do you encrypt customer data at rest?", + "isPendingAnswerGeneration": false, + "answerPartsSchema": { + "type": "object", + "properties": { + "explanation": { + "type": "string", + "title": "Explanation" } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "65e1efde08e8478f143a8ff9", - "endCursor": "65e1efde08e8478f143a8ff9" } + }, + "answerPartsValues": { + "explanation": "Yes, we encrypt all customer data at rest with AES-256." + }, + "ownerAssignment": { + "type": "User", + "id": "000000000000000000000002", + "displayName": "Jane Doe" } } } @@ -12456,10 +18040,10 @@ } } }, - "description": "List contracts, paginated.", - "summary": "List contracts", + "description": "Reassign or clear the owner of a questionnaire response. The assignment is\nrecorded as performed by the calling API client, so the notification to the\nnew owner names the Vanta API rather than a user.", + "summary": "Update questionnaire response owner", "tags": [ - "Contracts" + "Customer Trust" ], "security": [ { @@ -12468,43 +18052,120 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, + "in": "path", + "name": "questionnaireId", + "required": true, "schema": { - "$ref": "#/components/schemas/PageSize" + "type": "string" } }, + { + "in": "path", + "name": "responseId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateQuestionnaireResponseOwnerArgs" + } + } + } + } + } + }, + "/customer-trust/tag-categories": { + "get": { + "operationId": "ListTagCategories", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ArrayResponse_UserDefinedTagCategory_" + }, + "examples": { + "Example 1": { + "value": { + "results": [ + { + "id": "507f1f77bcf86cd799439011", + "displayName": "Industry" + }, + { + "id": "507f1f77bcf86cd799439012", + "displayName": "Region" + } + ] + } + } + } + } + } + } + }, + "description": "List user-defined tag categories. Optionally filter by product context.", + "summary": "List tag categories", + "tags": [ + "Customer Trust" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ { "in": "query", - "name": "pageCursor", + "name": "productContextIdsMatchesAny", "required": false, "schema": { - "$ref": "#/components/schemas/PageCursor" + "type": "array", + "items": { + "$ref": "#/components/schemas/CustomerTrustProductContextIdFilter" + } } } ] } }, - "/contracts/{contractId}": { + "/customer-trust/tag-categories/{tagCategoryId}": { "get": { - "operationId": "GetContract", + "operationId": "GetTagsForCategory", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Contract" + "$ref": "#/components/schemas/TagCategoryWithTags" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "name": "Example Contract", - "customerTrustAccountId": null, - "executedDate": "2024-01-15T00:00:00.000Z", - "creationDate": "2024-01-01T00:00:00.000Z" + "category": { + "id": "507f1f77bcf86cd799439011", + "displayName": "Industry" + }, + "tags": [ + { + "id": "507f1f77bcf86cd799439013", + "category": "507f1f77bcf86cd799439011", + "displayName": "Healthcare" + }, + { + "id": "507f1f77bcf86cd799439014", + "category": "507f1f77bcf86cd799439011", + "displayName": "Finance" + } + ] } } } @@ -12512,10 +18173,10 @@ } } }, - "description": "Get a contract by ID.", - "summary": "Get contract", + "description": "Retrieve a tag category and its associated tags by category ID.", + "summary": "Get tags for category", "tags": [ - "Contracts" + "Customer Trust" ], "security": [ { @@ -12525,25 +18186,27 @@ "parameters": [ { "in": "path", - "name": "contractId", + "name": "tagCategoryId", "required": true, "schema": { "type": "string" } } ] - }, - "delete": { - "operationId": "DeleteContract", + } + }, + "/customer-trust/tag-categories/{tagCategoryId}/product-contexts": { + "post": { + "operationId": "AddTagCategoryProductContext", "responses": { "204": { - "description": "Contract deleted" + "description": "No content" } }, - "description": "Delete a contract by ID.", - "summary": "Delete contract", + "description": "Enables a tag category for a product context (e.g. document sharing,\ncontrol sharing), making it available for scoping that context's\nshareable content. Idempotent: enabling an already-enabled category is\na no-op.", + "summary": "Enable tag category for product context", "tags": [ - "Contracts" + "Customer Trust" ], "security": [ { @@ -12553,89 +18216,73 @@ "parameters": [ { "in": "path", - "name": "contractId", + "name": "tagCategoryId", "required": true, "schema": { "type": "string" } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/AddTagCategoryProductContextInput" + } + } + } + } } }, - "/controls": { - "post": { - "operationId": "CreateCustomControl", + "/customer-trust/tag-categories/{tagCategoryId}/product-contexts/{productContextId}": { + "delete": { + "operationId": "RemoveTagCategoryProductContext", "responses": { - "201": { - "description": "Custom Control created", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/Control" - }, - "examples": { - "Example 1": { - "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null - } - } - } - } - } + "204": { + "description": "No content" } }, - "description": "Create a custom control.", - "summary": "Create custom control", + "description": "Disables a tag category for a product context. Idempotent: removing a\ncategory that isn't enabled for the context is a no-op.", + "summary": "Disable tag category for product context", "tags": [ - "Controls" + "Customer Trust" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CreateControlInput" - } + "parameters": [ + { + "in": "path", + "name": "tagCategoryId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "productContextId", + "required": true, + "schema": { + "$ref": "#/components/schemas/CustomerTrustProductContextIdWritable" } } - } - }, + ] + } + }, + "/discovered-vendors": { "get": { - "operationId": "ListControls", + "operationId": "ListDiscoveredVendors", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Control_" + "$ref": "#/components/schemas/PaginatedResponse_DiscoveredVendor_" }, "examples": { "Example 1": { @@ -12643,37 +18290,29 @@ "results": { "data": [ { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" + "id": "a2f7e1b9d0c3f4e5a6c7b8d8", + "name": "Vanta", + "category": { + "name": "Engineering" }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null + "source": "JAMF", + "normalizedName": "vanta", + "discoveredDate": "2024-01-01T00:00:00.000Z", + "numberOfAccounts": 7, + "ignored": { + "ignoredByUserId": "6626afb14c912f0a50e85619", + "ignoredReason": "reason", + "ignoredAtDate": "2024-02-01T00:00:00.000Z" + }, + "rejected": null } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "totalCount": 1 + "startCursor": "6696ea0595df50d5cd6ec3b7", + "endCursor": "6696ece48eb1f98ff3d927c6" + } } } } @@ -12682,10 +18321,10 @@ } } }, - "description": "List controls.", - "summary": "List controls", + "description": "List discovered vendors.", + "summary": "List discovered vendors", "tags": [ - "Controls" + "Discovered Vendors" ], "security": [ { @@ -12694,112 +18333,43 @@ ], "parameters": [ { + "description": "Defaults to \"NEEDS_REVIEW\" if not provided", "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", + "name": "scope", "required": false, "schema": { - "$ref": "#/components/schemas/PageCursor" + "$ref": "#/components/schemas/DiscoveredVendorScope" } }, { - "description": "Includes all controls belonging to one of the provided framework values in frameworkMatchesAny.", "in": "query", - "name": "frameworkMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } - } - ] - } - }, - "/controls/add-from-library": { - "post": { - "operationId": "AddControlFromLibrary", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/Control" - }, - "examples": { - "Example 1": { - "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null - } - } - } - } - } - } - }, - "description": "Add a control from the Vanta library to your organization's controls.", - "summary": "Add control from Vanta library", - "tags": [ - "Controls" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/AddControlFromLibraryInput" - } + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } - } + ] } }, - "/controls/controls-library": { + "/discovered-vendors/{discoveredVendorId}/accounts": { "get": { - "operationId": "ListLibraryControls", + "operationId": "ListDiscoveredVendorAccounts", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Control_" + "$ref": "#/components/schemas/PaginatedResponse_DiscoveredVendorAccount_" }, "examples": { "Example 1": { @@ -12807,37 +18377,23 @@ "results": { "data": [ { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], + "id": "66c6578ce02cc3a3483024d1", + "displayName": "Example Computer", + "type": "COMPUTER", "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null + "id": "a2f7e1b9d0c3f4e5a6c7b8d8", + "displayName": "Example user", + "email": "example@example.com", + "type": "USER" + } } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "totalCount": 1 + "startCursor": "6696ea0595df50d5cd6ec3b7", + "endCursor": "6696ece48eb1f98ff3d927c6" + } } } } @@ -12846,10 +18402,10 @@ } } }, - "description": "List Vanta controls from the library.", - "summary": "List Vanta controls from the library", + "description": "List of discovered vendor accounts.", + "summary": "List of discovered vendor accounts", "tags": [ - "Controls" + "Discovered Vendors" ], "security": [ { @@ -12857,6 +18413,14 @@ } ], "parameters": [ + { + "in": "path", + "name": "discoveredVendorId", + "required": true, + "schema": { + "type": "string" + } + }, { "in": "query", "name": "pageSize", @@ -12876,48 +18440,67 @@ ] } }, - "/controls/{controlId}": { - "patch": { - "operationId": "UpdateControlMetadata", + "/discovered-vendors/{discoveredVendorId}/add-to-managed": { + "post": { + "operationId": "AddDiscoveredVendorToManaged", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ControlDetail" + "$ref": "#/components/schemas/Vendor" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" + "id": "a2f7e1b9d0c3f4e5a6c7b8d8", + "name": "Vanta", + "websiteUrl": "https://www.vanta.com/", + "accountManagerName": "John Doe", + "accountManagerEmail": "john@doe.com", + "servicesProvided": "SaaS", + "additionalNotes": "Automate compliance and streamline security reviews with the leading trust management platform.", + "authDetails": { + "method": "O_AUTH", + "passwordMFA": true, + "passwordRequiresNumber": true, + "passwordRequiresSymbol": true, + "passwordMinimumLength": 16 }, - "note": "Remember to do by Friday", - "numDocumentsPassing": 1, - "numDocumentsTotal": 1, - "numTestsPassing": 2, - "numTestsTotal": 3, - "status": "IN_PROGRESS", - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } + "securityOwnerUserId": "6626afa6490ec920099773e7", + "businessOwnerUserId": "6626afb14c912f0a50e85619", + "contractStartDate": "2024-02-01T00:00:00.000Z", + "contractRenewalDate": "2025-02-01T00:00:00.000Z", + "contractTerminationDate": null, + "lastSecurityReviewCompletionDate": "2024-01-01T00:00:00.000Z", + "nextSecurityReviewDueDate": "2025-01-01T00:00:00.000Z", + "isVisibleToAuditors": true, + "isRiskAutoScored": true, + "category": { + "displayName": "cloudMonitoring" + }, + "riskAttributeIds": [ + "6626b0298acc44f8674390da", + "6626b02ea4cd9ba80d773c20" ], - "creationDate": null, - "modificationDate": null + "status": "MANAGED", + "inherentRiskLevel": "HIGH", + "residualRiskLevel": "MEDIUM", + "vendorHeadquarters": "USA", + "contractAmount": { + "amount": 1000000, + "currency": "USD" + }, + "customFields": null, + "latestDecision": { + "status": "APPROVED", + "lastUpdatedAt": "2024-01-01T00:00:00.000Z" + }, + "linkedTaskTrackerTaskProcurementRequest": { + "service": "jira", + "url": "https://random-company.atlassian.net/browse/PROJ-123" + } } } } @@ -12925,10 +18508,10 @@ } } }, - "description": "Update a control's metadata.", - "summary": "Update a control's metadata", + "description": "Add a discovered vendor to managed vendor.", + "summary": "Adds a discovered vendor to managed vendor by ID", "tags": [ - "Controls" + "Discovered Vendors" ], "security": [ { @@ -12938,93 +18521,101 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "discoveredVendorId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/EditControlMetadataInput" + ] + } + }, + "/documents": { + "post": { + "operationId": "CreateDocument", + "responses": { + "201": { + "description": "Document created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Document" + }, + "examples": { + "Example 1": { + "value": { + "id": "1", + "ownerId": "2", + "category": "Account setup", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "title": "Document Title", + "uploadStatus": "Needs document", + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "url": "https://example.com" + } + } + } } } } - } - }, - "delete": { - "operationId": "DeleteControl", - "responses": { - "204": { - "description": "No content" - } }, - "description": "Deactivates a custom or Vanta control.", - "summary": "Deactivates a control", + "description": "Create a custom document.", + "summary": "Create a custom document", "tags": [ - "Controls" + "Documents" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "controlId", - "required": true, - "schema": { - "type": "string" + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateDocumentInput" + } } } - ] + } }, "get": { - "operationId": "GetControl", + "operationId": "ListDocuments", "responses": { "200": { "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/ControlDetail" - }, - "examples": { - "Example 1": { - "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "note": "Remember to do by Friday", - "numDocumentsPassing": 1, - "numDocumentsTotal": 1, - "numTestsPassing": 2, - "numTestsTotal": 3, - "status": "IN_PROGRESS", - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_Document_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "1", + "ownerId": "2", + "category": "Account setup", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "title": "Document Title", + "uploadStatus": "Needs document", + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "url": "https://example.com" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" } - ], - "creationDate": null, - "modificationDate": null + } } } } @@ -13032,10 +18623,10 @@ } } }, - "description": "Get a control by an ID.", - "summary": "Get control by an ID", + "description": "List documents.", + "summary": "List documents", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13044,88 +18635,60 @@ ], "parameters": [ { - "in": "path", - "name": "controlId", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Includes all documents that match one of the provided framework values in frameworkMatchesAny.", + "in": "query", + "name": "frameworkMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + } + }, + { + "description": "Includes all documents that match one of the provided status values in statusMatchesAny.", + "in": "query", + "name": "statusMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/DocumentStatus" + } } } ] } }, - "/controls/{controlId}/add-document-to-control": { - "post": { - "operationId": "AddDocumentToControl", + "/documents/{documentId}": { + "delete": { + "operationId": "DeleteDocument", "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "properties": { - "document": { - "$ref": "#/components/schemas/Document" - }, - "control": { - "$ref": "#/components/schemas/Control" - } - }, - "required": [ - "document", - "control" - ], - "type": "object" - }, - "examples": { - "Example 1": { - "value": { - "control": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null - }, - "document": { - "id": "1", - "ownerId": "2", - "category": "Account setup", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "title": "Document Title", - "uploadStatus": "Needs document", - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "url": "https://example.com" - } - } - } - } - } - } + "204": { + "description": "No content" } }, - "description": "Add a document to a control.", - "summary": "Add control to document mapping", + "description": "Delete a document by ID.", + "summary": "Delete document by ID", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13135,104 +18698,47 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/AddControlDocumentMappingInput" - } - } - } - } - } - }, - "/controls/{controlId}/add-test-to-control": { - "post": { - "operationId": "AddTestToControl", + ] + }, + "get": { + "operationId": "GetDocument", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "properties": { - "test": { - "$ref": "#/components/schemas/Test" - }, - "control": { - "$ref": "#/components/schemas/Control" - } - }, - "required": [ - "test", - "control" - ], - "type": "object" + "$ref": "#/components/schemas/DocumentDetail" }, "examples": { "Example 1": { "value": { - "control": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" - } - ], - "creationDate": null, - "modificationDate": null - }, - "test": { - "id": "aws-account-access-removed-on-termination", - "name": "AWS accounts deprovisioned when personnel leave", - "lastTestRunDate": "2024-06-18T20:17:38.463Z", - "latestFlipDate": null, - "description": "Verifies that AWS accounts linked to removed users are removed.\n", - "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", - "remediationDescription": "Remove all accounts listed from AWS.\n", - "version": { - "major": 0, - "minor": 0 - }, - "category": "Account security", - "integrations": [ - "aws" - ], - "status": "OK", - "deactivatedStatusInfo": { - "isDeactivated": false, - "deactivatedReason": null, - "lastUpdatedDate": null - }, - "remediationStatusInfo": { - "status": "PASS", - "soonestRemediateByDate": null, - "itemCount": 0 - }, - "owner": null - } + "id": "access-requests", + "title": "Access request ticket and history", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "category": "Account setup", + "uploadStatus": "Needs document", + "url": "https://example.com", + "ownerId": "1", + "note": "Example document note", + "nextRenewalDate": "2025-03-17T00:00:00.000Z", + "renewalCadence": "P1Y", + "reminderWindow": "P1M", + "deactivatedStatus": { + "isDeactivated": false, + "reason": null, + "expiration": null, + "creationDate": "2024-03-02T00:00:00.000Z" + }, + "subscribers": [] } } } @@ -13240,10 +18746,10 @@ } } }, - "description": "Add a control to test mapping.", - "summary": "Add control to test mapping", + "description": "Get a document by ID.", + "summary": "Get document by ID", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13253,35 +18759,25 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/AddControlTestMappingInput" - } - } - } - } + ] } }, - "/controls/{controlId}/documents": { + "/documents/{documentId}/controls": { "get": { - "operationId": "ListDocumentsForControl", + "operationId": "ListControlsForDocument", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Document_" + "$ref": "#/components/schemas/PaginatedResponse_Control_" }, "examples": { "Example 1": { @@ -13308,16 +18804,56 @@ } } } + }, + "Example 2": { + "value": { + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "totalCount": 1 + } + } } } } } } }, - "description": "List a control's documents.", - "summary": "List a control's documents", + "description": "List a document's associated controls.", + "summary": "List document's controls", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13327,7 +18863,7 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" @@ -13352,80 +18888,38 @@ ] } }, - "/controls/{controlId}/documents/{documentId}": { - "delete": { - "operationId": "DeleteDocumentForcontrol", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Remove a document by ID from a control.", - "summary": "Remove control from document mapping", - "tags": [ - "Controls" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "controlId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "in": "path", - "name": "documentId", - "required": true, - "schema": { - "type": "string" - } - } - ] - } - }, - "/controls/{controlId}/set-owner": { - "post": { - "operationId": "SetOwnerForControl", + "/documents/{documentId}/links": { + "get": { + "operationId": "ListLinksForDocument", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Control" + "$ref": "#/components/schemas/PaginatedResponse_UploadedLink_" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ - { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" + "results": { + "data": [ + { + "id": "1", + "creationDate": "2024-06-26T00:00:00.000Z", + "effectiveDate": "2024-07-01T00:00:00.000Z", + "title": "example link", + "url": "https://example.com/", + "description": "example link" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" } - ], - "creationDate": null, - "modificationDate": null + } } } } @@ -13433,10 +18927,10 @@ } } }, - "description": "Assign a control to a user or remove an owner from a control.", - "summary": "Set owner of a control", + "description": "List the uploaded links for a document.", + "summary": "List document's links", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13446,78 +18940,49 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/SetOwnerForControlInput" - } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } - } - } - }, - "/controls/{controlId}/tests": { - "get": { - "operationId": "ListTestsForControl", + ] + }, + "post": { + "operationId": "CreateLinkForDocument", "responses": { - "200": { - "description": "Ok", + "201": { + "description": "Link created for document", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Test_" + "$ref": "#/components/schemas/UploadedLink" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "aws-account-access-removed-on-termination", - "name": "AWS accounts deprovisioned when personnel leave", - "lastTestRunDate": "2024-06-18T20:17:38.463Z", - "latestFlipDate": null, - "description": "Verifies that AWS accounts linked to removed users are removed.\n", - "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", - "remediationDescription": "Remove all accounts listed from AWS.\n", - "version": { - "major": 0, - "minor": 0 - }, - "category": "Account security", - "integrations": [ - "aws" - ], - "status": "OK", - "deactivatedStatusInfo": { - "isDeactivated": false, - "deactivatedReason": null, - "lastUpdatedDate": null - }, - "remediationStatusInfo": { - "status": "PASS", - "soonestRemediateByDate": null, - "itemCount": 0 - }, - "owner": null - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" - } - } + "id": "1", + "creationDate": "2024-06-26T00:00:00.000Z", + "effectiveDate": "2024-07-01T00:00:00.000Z", + "title": "example link", + "url": "https://example.com/", + "description": "example link" } } } @@ -13525,10 +18990,10 @@ } } }, - "description": "List a control's tests.", - "summary": "List a control's tests", + "description": "Create a link for a document.", + "summary": "Create document link", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13538,43 +19003,37 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateLinkForDocumentInput" + } } } - ] + } } }, - "/controls/{controlId}/tests/{testId}": { + "/documents/{documentId}/links/{linkId}": { "delete": { - "operationId": "DeleteTestForControl", + "operationId": "DeleteLinkForDocument", "responses": { "204": { "description": "No content" } }, - "description": "Remove a control from test mapping.", - "summary": "Remove control from test mapping", + "description": "Remove a link from a document.", + "summary": "Remove document link", "tags": [ - "Controls" + "Documents" ], "security": [ { @@ -13584,7 +19043,7 @@ "parameters": [ { "in": "path", - "name": "controlId", + "name": "documentId", "required": true, "schema": { "type": "string" @@ -13592,7 +19051,7 @@ }, { "in": "path", - "name": "testId", + "name": "linkId", "required": true, "schema": { "type": "string" @@ -13601,59 +19060,29 @@ ] } }, - "/customer-trust/accounts": { - "get": { - "operationId": "ListCustomerTrustAccounts", + "/documents/{documentId}/set-owner": { + "post": { + "operationId": "SetOwnerForDocument", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_CustomerTrustAccountVantaApi_" + "$ref": "#/components/schemas/Document" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": true, - "hasPreviousPage": false, - "startCursor": "cursor1", - "endCursor": "cursor2" - }, - "data": [ - { - "id": "507f1f77bcf86cd799439011", - "name": "Acme Corporation", - "emailDomain": "acme.com", - "createdDate": "2024-01-01T00:00:00.000Z", - "updatedDate": "2024-01-02T00:00:00.000Z", - "ndaDetails": { - "ndaStatus": "SIGNED", - "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" - }, - "accessConfig": { - "autoApprovalEnabled": false, - "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" - }, - "customFields": [ - { - "label": "externalId", - "value": "12345" - } - ], - "tagsByCategory": [ - { - "categoryId": "507f1f77bcf86cd799439012", - "tagIds": [ - "507f1f77bcf86cd799439013" - ] - } - ] - } - ] - } + "id": "1", + "ownerId": "2", + "category": "Account setup", + "description": "Provide two examples of a recent access request and approval ", + "isSensitive": false, + "title": "Document Title", + "uploadStatus": "Needs document", + "uploadStatusDate": "2024-03-17T00:00:00.000Z", + "url": "https://example.com" } } } @@ -13661,10 +19090,10 @@ } } }, - "description": "List customer trust accounts with pagination.", - "summary": "List customer trust accounts", + "description": "Assign or unassign a user to the document.", + "summary": "Set document owner", "tags": [ - "Customer Trust" + "Documents" ], "security": [ { @@ -13673,87 +19102,84 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "in": "query", - "name": "searchString", - "required": false, + "in": "path", + "name": "documentId", + "required": true, "schema": { "type": "string" } - }, - { - "in": "query", - "name": "isAutoApprovalEnabled", - "required": false, - "schema": { - "type": "boolean" + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/SetOwnerForDocumentInput" + } } - }, + } + } + } + }, + "/documents/{documentId}/submit": { + "post": { + "operationId": "SubmitDocumentCollection", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Submit document collection.", + "summary": "Submit document collection", + "tags": [ + "Documents" + ], + "security": [ { - "in": "query", - "name": "customFieldsFilter", - "required": false, + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "documentId", + "required": true, "schema": { "type": "string" } } ] - }, + } + }, + "/documents/{documentId}/uploads": { "post": { - "operationId": "CreateCustomerTrustAccount", + "operationId": "UploadFileForDocument", "responses": { - "200": { - "description": "Ok", + "201": { + "description": "File uploaded for document", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + "$ref": "#/components/schemas/UploadedFileT" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "name": "Acme Corporation", - "emailDomain": "acme.com", - "createdDate": "2024-01-01T00:00:00.000Z", - "updatedDate": "2024-01-02T00:00:00.000Z", - "ndaDetails": { - "ndaStatus": "SIGNED", - "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" - }, - "accessConfig": { - "autoApprovalEnabled": false, - "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" - }, - "customFields": [ - { - "label": "externalId", - "value": "12345" - } - ], - "tagsByCategory": [ - { - "categoryId": "507f1f77bcf86cd799439012", - "tagIds": [ - "507f1f77bcf86cd799439013" - ] - } - ] + "id": "1", + "fileName": "Document Name", + "title": "Document title", + "description": "Document Description", + "url": "https://example.com", + "creationDate": "2024-03-17T00:00:00.000Z", + "updatedDate": "2024-03-18T00:00:00.000Z", + "effectiveDate": "2024-03-17T00:00:00.000Z", + "deletionDate": null, + "mimeType": "application/pdf", + "uploadedBy": { + "id": "66993da0cf4ba2ad40599ba7", + "type": "USER" + } } } } @@ -13761,70 +19187,93 @@ } } }, - "description": "Create a new customer trust account.", - "summary": "Create customer trust account", + "description": "Upload a file for a document.", + "summary": "Upload file for document", "tags": [ - "Customer Trust" + "Documents" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], + "parameters": [ + { + "in": "path", + "name": "documentId", + "required": true, + "schema": { + "type": "string" + } + } + ], "requestBody": { "required": true, "content": { - "application/json": { + "multipart/form-data": { "schema": { - "$ref": "#/components/schemas/CreateCustomerTrustAccountInput" + "type": "object", + "properties": { + "file": { + "type": "string", + "format": "binary" + }, + "effectiveAtDate": { + "type": "string", + "description": "Date indicating when the document is effective from." + }, + "description": { + "type": "string", + "description": "Description of the uploaded document." + } + }, + "required": [ + "file" + ] } } } } - } - }, - "/customer-trust/accounts/{accountId}": { + }, "get": { - "operationId": "GetCustomerTrustAccount", + "operationId": "ListFilesForDocument", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" + "$ref": "#/components/schemas/PaginatedResponse_UploadedFileT_" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "name": "Acme Corporation", - "emailDomain": "acme.com", - "createdDate": "2024-01-01T00:00:00.000Z", - "updatedDate": "2024-01-02T00:00:00.000Z", - "ndaDetails": { - "ndaStatus": "SIGNED", - "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" - }, - "accessConfig": { - "autoApprovalEnabled": false, - "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" - }, - "customFields": [ - { - "label": "externalId", - "value": "12345" - } - ], - "tagsByCategory": [ - { - "categoryId": "507f1f77bcf86cd799439012", - "tagIds": [ - "507f1f77bcf86cd799439013" - ] + "results": { + "data": [ + { + "id": "1", + "fileName": "Document Name", + "title": "Document title", + "description": "Document Description", + "url": "https://example.com", + "creationDate": "2024-03-17T00:00:00.000Z", + "updatedDate": "2024-03-18T00:00:00.000Z", + "effectiveDate": "2024-03-17T00:00:00.000Z", + "deletionDate": null, + "mimeType": "application/pdf", + "uploadedBy": { + "id": "66993da0cf4ba2ad40599ba7", + "type": "USER" + } + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" } - ] + } } } } @@ -13832,10 +19281,10 @@ } } }, - "description": "Get a specific customer trust account by ID.", - "summary": "Get customer trust account", + "description": "List the uploaded files for a document.", + "summary": "List document's uploads", "tags": [ - "Customer Trust" + "Documents" ], "security": [ { @@ -13845,25 +19294,43 @@ "parameters": [ { "in": "path", - "name": "accountId", + "name": "documentId", "required": true, "schema": { "type": "string" } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } } ] - }, + } + }, + "/documents/{documentId}/uploads/{uploadedFileId}": { "delete": { - "operationId": "DeleteCustomerTrustAccount", + "operationId": "DeleteFileForDocument", "responses": { "204": { "description": "No content" } }, - "description": "Delete a customer trust account by ID.", - "summary": "Delete customer trust account", + "description": "Delete a file for a document.", + "summary": "Delete file for a document", "tags": [ - "Customer Trust" + "Documents" ], "security": [ { @@ -13873,65 +19340,182 @@ "parameters": [ { "in": "path", - "name": "accountId", + "name": "documentId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "uploadedFileId", "required": true, "schema": { "type": "string" } } ] - }, - "patch": { - "operationId": "UpdateCustomerTrustAccount", + } + }, + "/documents/{documentId}/uploads/{uploadedFileId}/media": { + "get": { + "operationId": "GetUploadedfileMedia", "responses": { "200": { "description": "Ok", "content": { + "text/csv": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "text/plain": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "text/markdown": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustAccountVantaApi" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439011", - "name": "Acme Corporation", - "emailDomain": "acme.com", - "createdDate": "2024-01-01T00:00:00.000Z", - "updatedDate": "2024-01-02T00:00:00.000Z", - "ndaDetails": { - "ndaStatus": "SIGNED", - "ndaSatisfiedDate": "2024-01-02T00:00:00.000Z" - }, - "accessConfig": { - "autoApprovalEnabled": false, - "grantAccessOption": "INCLUDE_EVERYTHING_REQUESTED" - }, - "customFields": [ - { - "label": "externalId", - "value": "12345" - } - ], - "tagsByCategory": [ - { - "categoryId": "507f1f77bcf86cd799439012", - "tagIds": [ - "507f1f77bcf86cd799439013" - ] - } - ] - } - } + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/yaml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "text/x-yaml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/vnd.ms-excel": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/svg+xml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/xml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/x-pem-file": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/x-x509-ca-cert": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/x-x509-user-cert": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/bmp": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/msword": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/vnd.openxmlformats-officedocument.wordprocessingml.document": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/gzip": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/x-icon": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/vnd.microsoft.icon": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/jpeg": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/pdf": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/png": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/postscript": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/vnd.ms-powerpoint": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/vnd.openxmlformats-officedocument.presentationml.presentation": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "image/webp": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "font/woff2": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/zip": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "application/x-zip-compressed": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" } } } } }, - "description": "Update a customer trust account by ID.", - "summary": "Update customer trust account", + "description": "Download a file from a document.", + "summary": "Download file for document", "tags": [ - "Customer Trust" + "Documents" ], "security": [ { @@ -13941,35 +19525,33 @@ "parameters": [ { "in": "path", - "name": "accountId", + "name": "documentId", "required": true, "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/EditCustomerTrustAccountInput" - } + }, + { + "in": "path", + "name": "uploadedFileId", + "required": true, + "schema": { + "type": "string" } } - } + ] } }, - "/customer-trust/questionnaires": { + "/event-logs": { "get": { - "operationId": "ListQuestionnaires", + "operationId": "ListEventLogs", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_CustomerTrustQuestionnaire_" + "$ref": "#/components/schemas/PaginatedResponse_EventLog_" }, "examples": { "Example 1": { @@ -13977,28 +19559,26 @@ "results": { "data": [ { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ + "id": "69fbbae3e16190a288ee8eb0", + "actor": { + "id": "69fbbaf987273a4b462580e9", + "type": "USER" + }, + "date": "2026-05-03T21:08:22.385Z", + "action": "LOGIN_USER", + "targets": [ { - "key": "priority", - "value": "high" + "id": "email", + "type": "LOGIN_METHOD" } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + ] } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "507f1f77bcf86cd799439011", - "endCursor": "507f1f77bcf86cd799439011" + "startCursor": "eyJjcmVhdGVkQXQiOnsiJGRhdGUiOiIyMDI2LTA1LTAzVDIxOjA4OjExLjQzNFoifSwiX2lkIjp7IiRvaWQiOiI2OGZiYmFlM2UxNjA5MGEyODRlZThlYjAifX0=", + "endCursor": "eyJjcmVhdGVkQXQiOnsiJGRhdGUiOiIyMDI2LTA1LTAzVDIxOjA4OjIyLjM4NVoifSwiX2lkIjp7IiRvaWQiOiI2OWZiYmFlM2UxNjE5MGEyODhlZThlYjAifX0=" } } } @@ -14008,10 +19588,10 @@ } } }, - "description": "List questionnaires with filtering and pagination.", - "summary": "List questionnaires", + "description": "List event logs.\n\nSee the [event log reference](/reference/manage-vanta/event-log-reference) for an inexhaustive list of `actor.type`, `action`, and `targets[].type` values.", + "summary": "List event logs", "tags": [ - "Customer Trust" + "Event Logs" ], "security": [ { @@ -14036,93 +19616,28 @@ } }, { - "description": "Filter questionnaires by display name (case-insensitive, partial match).", - "in": "query", - "name": "q", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Filter questionnaires matching any of the provided statuses.", - "in": "query", - "name": "statusMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/QuestionnaireStatus" - } - } - }, - { - "description": "Filter questionnaires matching any of the provided types.", - "in": "query", - "name": "typeMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaireType" - } - } - }, - { - "description": "Filter to questionnaires created after this date (ISO 8601 string).", - "in": "query", - "name": "createdAfter", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Filter to questionnaires created before this date (ISO 8601 string).", + "description": "Filter to event logs created at or after this ISO 8601 timestamp.", "in": "query", - "name": "createdBefore", + "name": "startDate", "required": false, "schema": { + "format": "date-time", "type": "string" } - }, - { - "description": "Filter to questionnaires owned by any of the provided user IDs.", - "in": "query", - "name": "ownerIdMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } - }, - { - "description": "Filter to questionnaires with an approver matching any of the provided user IDs.", - "in": "query", - "name": "approverIdMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } } ] } }, - "/customer-trust/questionnaires/assignable-users": { + "/frameworks": { "get": { - "operationId": "ListAssignableUsers", + "operationId": "ListFrameworks", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/QuestionnaireAssignableUsersResponse" + "$ref": "#/components/schemas/PaginatedResponse_Framework_" }, "examples": { "Example 1": { @@ -14130,10 +19645,24 @@ "results": { "data": [ { - "id": "usr_1234567890", - "displayName": "Jane Doe" + "id": "soc2", + "displayName": "SOC 2", + "shorthandName": "SOC 2", + "description": "AICPA standardized framework to prove a company’s security posture to prospective customers. For all US and international businesses.", + "numControlsCompleted": 43, + "numControlsTotal": 86, + "numDocumentsPassing": 7, + "numDocumentsTotal": 16, + "numTestsPassing": 21, + "numTestsTotal": 46 } - ] + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "aXNvMjcwMDFfMjAyMg==", + "endCursor": "aXNvMjcwMDFfMjAyMg==" + } } } } @@ -14142,10 +19671,10 @@ } } }, - "description": "List users who can be assigned as owner or approver on a questionnaire.\n\nWhen a role is specified, results are filtered to users with that role's required permission.\nWhen omitted, users assignable to either role are returned.\nResults can optionally be narrowed by a search string.", - "summary": "List assignable users", + "description": "Lists available frameworks.", + "summary": "List available frameworks", "tags": [ - "Customer Trust" + "Frameworks" ], "security": [ { @@ -14154,95 +19683,71 @@ ], "parameters": [ { - "description": "Filter by role: \"owner\" or \"approver\".", - "in": "query", - "name": "role", - "required": false, - "schema": { - "$ref": "#/components/schemas/QuestionnaireAssignableUserRole" - } - }, - { - "description": "Optional search string to filter users by name or email.", "in": "query", - "name": "q", + "name": "pageSize", "required": false, "schema": { - "type": "string" - } - } - ] - } - }, - "/customer-trust/questionnaires/exports": { - "post": { - "operationId": "CreateQuestionnaireExport", - "responses": { - "202": { - "description": "Export created", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CustomerTrustCreateQuestionnaireExportResponse" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439011", - "status": "pending", - "format": "original", - "requestedAt": "2025-01-08T12:00:00.000Z" - } - } - } - } + "$ref": "#/components/schemas/PageSize" } - } - }, - "description": "Creates an asynchronous export job for a questionnaire. The export processes in the background\nand typically completes within a few minutes depending on questionnaire size.\n\nSubscribe to the `v1.questionnaire.export-completed` and `v1.questionnaire.export-failed` webhook events to be notified when an export completes or fails.\nUse the returned `id` with the \"getQuestionnaireExport\" endpoint to retrieve the download URL once the export completes.", - "summary": "Create questionnaire export", - "tags": [ - "Customer Trust" - ], - "security": [ + }, { - "bearerAuth": [] - } - ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CustomerTrustCreateQuestionnaireExportInput" - } + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } - } + ] } }, - "/customer-trust/questionnaires/exports/{id}": { + "/frameworks/{frameworkId}": { "get": { - "operationId": "GetQuestionnaireExport", + "operationId": "GetFramework", "responses": { "200": { - "description": "The export status and, if completed, the download URL.", + "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustExportStatusResponse" + "$ref": "#/components/schemas/FrameworkDetail" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "status": "completed", - "format": "original", - "requestedAt": "2025-01-08T12:00:00.000Z", - "completedAt": "2025-01-08T12:05:00.000Z", - "downloadUrl": "https://storage.example.com/exports/questionnaire-export.xlsx?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9&expires=1736424000", - "expiresAt": "2025-01-09T12:00:00.000Z" + "id": "soc2", + "displayName": "SOC 2", + "shorthandName": "SOC 2", + "description": "AICPA standardized framework to prove a company’s security posture to prospective customers. For all US and international businesses.", + "numControlsCompleted": 43, + "numControlsTotal": 86, + "numDocumentsPassing": 7, + "numDocumentsTotal": 16, + "numTestsPassing": 21, + "numTestsTotal": 46, + "requirementCategories": [ + { + "id": "CC 1.0", + "name": "Control Environment", + "shorthand": null, + "requirements": [ + { + "id": "CC 1.1", + "name": "", + "shorthand": null, + "description": "COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values.", + "controls": [ + { + "id": "background-checks-performed", + "externalId": null, + "name": "Personnel background checks performed", + "description": "The company performs background checks on new personnel." + } + ] + } + ] + } + ] } } } @@ -14250,10 +19755,10 @@ } } }, - "description": "Retrieves the current status and result of a questionnaire export using the id received from either the `createQuestionnaireExport` endpoint or the `v1.questionnaire.export-completed` webhook payload.\n\nThis endpoint utilizes a dynamic response schema that changes based on the value of the status field:\n\n - pending: The export is currently in the queue or processing. Only base metadata is returned.\n - completed: The export finished successfully. The response expands to include completedAt and a downloadUrl. This pre-signed URL is valid for 24 hours; if it expires, simply call this endpoint again to retrieve a fresh, active link.\n - failed: The process encountered an error. The response expands to include failedAt and an errorMessage detailing the reason for failure.\n\nDevelopers should first check the status string before attempting to access result-specific fields like downloadUrl or errorMessage.", - "summary": "Get questionnaire export status", + "description": "Get a framework by ID.", + "summary": "Get framework by ID", "tags": [ - "Customer Trust" + "Frameworks" ], "security": [ { @@ -14262,9 +19767,8 @@ ], "parameters": [ { - "description": "The unique identifier of the export job, returned from the POST endpoint.", "in": "path", - "name": "id", + "name": "frameworkId", "required": true, "schema": { "type": "string" @@ -14273,35 +19777,56 @@ ] } }, - "/customer-trust/questionnaires/file": { - "post": { - "operationId": "CreateFileQuestionnaire", + "/frameworks/{frameworkId}/controls": { + "get": { + "operationId": "ListControlsForFramework", "responses": { - "201": { - "description": "File questionnaire created", + "200": { + "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + "$ref": "#/components/schemas/PaginatedResponse_Control_" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" - } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "externalId": "CRY-104", + "name": "Data encryption utilized", + "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", + "source": "Vanta", + "domains": [ + "CRYPTOGRAPHIC_PROTECTIONS" + ], + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + }, + "role": "CONTROLLER", + "customFields": [ + { + "label": "Additional context", + "value": "This control is critical for GDPR compliance" + } + ], + "creationDate": null, + "modificationDate": null, + "implementationDetails": "Encryption is enforced for data at rest and in transit." + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "totalCount": 1 + } } } } @@ -14309,108 +19834,68 @@ } } }, - "description": "Create a new file-based questionnaire from an uploaded file (.xlsx, .docx, .pdf). File type is inferred as `SPREADSHEET` or `DOCUMENT` based on the uploaded file.", - "summary": "Create file questionnaire", + "description": "List a framework's controls.", + "summary": "List a framework's controls", "tags": [ - "Customer Trust" + "Frameworks" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "multipart/form-data": { - "schema": { - "type": "object", - "properties": { - "file": { - "type": "string", - "format": "binary" - }, - "displayName": { - "type": "string", - "description": "Display name for the questionnaire." - }, - "ownerAssignment": { - "type": "string", - "description": "Owner to assign, as a JSON string: {\"type\": \"User\" | \"Team\", \"id\": \"\"}." - }, - "approverAssignment": { - "type": "string", - "description": "Approver to assign, as a JSON string: {\"type\": \"User\" | \"Team\", \"id\": \"\"}." - }, - "description": { - "type": "string", - "description": "Description of the questionnaire." - }, - "companyUrl": { - "type": "string", - "description": "URL of the company associated with this questionnaire." - }, - "dueDate": { - "type": "string", - "description": "Due date for questionnaire completion." - }, - "customerTrustAccountId": { - "type": "string", - "description": "ID of the customer trust account to associate with this questionnaire." - }, - "includeUntaggedEntitiesForCategoryIds": { - "type": "string", - "description": "Comma-separated category IDs for which to include untagged entities." - }, - "metadata": { - "type": "string", - "description": "Custom key-value pairs, as a JSON string array: [{\"key\": \"\", \"value\": \"\"}]. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods." - }, - "tagAndCategoryIds": { - "type": "string", - "description": "Tags to assign, as a JSON string array: [{\"categoryId\": \"\", \"tagId\": \"\"}]. Replaces all existing tags." - } - }, - "required": [ - "file", - "displayName" - ] - } + "parameters": [ + { + "in": "path", + "name": "frameworkId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } - } + ] } - }, - "/customer-trust/questionnaires/website": { - "post": { - "operationId": "CreateWebsiteQuestionnaire", - "responses": { - "201": { - "description": "Website questionnaire created", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" - } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + }, + "/groups": { + "post": { + "operationId": "CreateGroup", + "responses": { + "201": { + "description": "Group created", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Group" + }, + "examples": { + "Example 1": { + "value": { + "id": "5f2c939a52855e725c8d5824", + "name": "Default Group", + "creationDate": "2024-03-07T18:46:05.944Z", + "description": null, + "source": "Vanta", + "personnelCount": 0, + "pointOfContact": { + "displayName": "Jane Doe", + "email": "jane@example.com" + } } } } @@ -14418,10 +19903,10 @@ } } }, - "description": "Create a new website-based questionnaire from a portal URL.\n\nThe portal URL is used to fetch questionnaire content from the target website.", - "summary": "Create website questionnaire", + "description": "Creates a group.", + "summary": "Create group", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14434,42 +19919,66 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CreateWebsiteQuestionnaireInput" + "properties": { + "pointOfContactEmail": { + "type": "string", + "nullable": true, + "description": "Email address of the group's point of contact. Must be an active administrator." + }, + "description": { + "type": "string", + "nullable": true, + "description": "Description of the group." + }, + "name": { + "type": "string", + "description": "Display name for the group. Must not duplicate an existing group's name." + } + }, + "required": [ + "name" + ], + "type": "object" } } } } - } - }, - "/customer-trust/questionnaires/{questionnaireId}": { + }, "get": { - "operationId": "GetQuestionnaire", + "operationId": "ListPersonGroups", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + "$ref": "#/components/schemas/PaginatedResponse_Group_" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" + "results": { + "data": [ + { + "id": "5f2c939a52855e725c8d5824", + "name": "Default Group", + "creationDate": "2024-03-07T18:46:05.944Z", + "description": null, + "source": "Vanta", + "personnelCount": 0, + "pointOfContact": { + "displayName": "Jane Doe", + "email": "jane@example.com" + } + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "5f2c939a52855e725c8d5824", + "endCursor": "5f2c939a52855e725c8d5824" } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + } } } } @@ -14477,10 +19986,10 @@ } } }, - "description": "Retrieve a questionnaire by ID.", - "summary": "Get questionnaire by ID", + "description": "Lists all groups by ID.", + "summary": "List groups", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14489,82 +19998,95 @@ ], "parameters": [ { - "in": "path", - "name": "questionnaireId", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } ] - }, - "delete": { - "operationId": "DeleteQuestionnaire", + } + }, + "/groups/import-from-idp": { + "post": { + "operationId": "ImportIdpGroups", "responses": { - "204": { - "description": "No content" + "200": { + "description": "IdP groups imported", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ImportIdpGroupsResponse" + } + } + } } }, - "description": "Delete a questionnaire by ID.", - "summary": "Delete questionnaire", + "description": "Imports groups from an identity provider.", + "summary": "Import IdP groups", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "questionnaireId", - "required": true, - "schema": { - "type": "string" + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "properties": { + "idpGroupIds": { + "items": { + "type": "string" + }, + "type": "array", + "description": "IdP-group resource IDs to import.", + "minItems": 1, + "maxItems": 100 + } + }, + "required": [ + "idpGroupIds" + ], + "type": "object" + } } } - ] - }, - "patch": { - "operationId": "UpdateQuestionnaire", + } + } + }, + "/groups/importable-idp-groups": { + "get": { + "operationId": "ListImportableIdpGroups", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" - } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" - } - } + "$ref": "#/components/schemas/PaginatedImportableIdpGroupResponse" } } } } }, - "description": "Update an existing questionnaire.\n\nUpdates one or more fields of a questionnaire.\nThis endpoint cannot be used to set a questionnaire's status to `APPROVED` or `COMPLETED`. To perform those specific transitions, please use the `approveQuestionnaire` and `completeQuestionnaire` endpoints, respectively.", - "summary": "Update questionnaire", + "description": "Lists IdP groups that are available to import.", + "summary": "List importable IdP groups", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14573,55 +20095,67 @@ ], "parameters": [ { - "in": "path", - "name": "questionnaireId", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "in": "query", + "name": "search", + "required": false, "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/UpdateQuestionnaireArgs" + }, + { + "in": "query", + "name": "integrationId", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" } } } - } + ] } }, - "/customer-trust/questionnaires/{questionnaireId}/approve": { - "post": { - "operationId": "ApproveQuestionnaire", + "/groups/{groupId}": { + "patch": { + "operationId": "UpdateGroup", "responses": { "200": { - "description": "Ok", + "description": "Group updated", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + "$ref": "#/components/schemas/Group" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" - } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + "id": "5f2c939a52855e725c8d5824", + "name": "Default Group", + "creationDate": "2024-03-07T18:46:05.944Z", + "description": null, + "source": "Vanta", + "personnelCount": 0, + "pointOfContact": { + "displayName": "Jane Doe", + "email": "jane@example.com" + } } } } @@ -14629,10 +20163,10 @@ } } }, - "description": "Mark a questionnaire as `APPROVED` and optionally provide a `statusChangeMessage`.", - "summary": "Approve questionnaire", + "description": "Partially updates a group. At least one field must be provided.", + "summary": "Update group", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14642,7 +20176,7 @@ "parameters": [ { "in": "path", - "name": "questionnaireId", + "name": "groupId", "required": true, "schema": { "type": "string" @@ -14654,42 +20188,51 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ApproveQuestionnaireRequest" + "properties": { + "pointOfContactEmail": { + "type": "string", + "nullable": true, + "description": "Email of an active Vanta user with the Admin role in the organization. Omit to preserve; pass null to clear." + }, + "description": { + "type": "string", + "nullable": true, + "description": "New description. Omit to preserve; pass null to clear." + }, + "name": { + "type": "string", + "description": "New display name. Omit to preserve. Names are trimmed, must be non-empty and unique, and cannot change for an IdP-managed group." + } + }, + "type": "object" } } } } - } - }, - "/customer-trust/questionnaires/{questionnaireId}/complete": { - "post": { - "operationId": "CompleteQuestionnaire", + }, + "get": { + "operationId": "GetGroup", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CustomerTrustQuestionnaire" + "$ref": "#/components/schemas/Group" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439011", - "displayName": "SOC 2 Security Questionnaire", - "type": "SPREADSHEET", - "status": "IN_PROGRESS", - "statusLog": [], - "dueDate": "2024-12-31T00:00:00.000Z", - "metadata": [ - { - "key": "priority", - "value": "high" - } - ], - "tagAndCategoryIds": [], - "createdDate": "2024-12-01T00:00:00.000Z", - "updatedDate": "2024-12-14T00:00:00.000Z" + "id": "5f2c939a52855e725c8d5824", + "name": "Default Group", + "creationDate": "2024-03-07T18:46:05.944Z", + "description": null, + "source": "Vanta", + "personnelCount": 0, + "pointOfContact": { + "displayName": "Jane Doe", + "email": "jane@example.com" + } } } } @@ -14697,10 +20240,10 @@ } } }, - "description": "Complete a questionnaire and optionally sync approved answers to the answer library.\n\nTransitions the questionnaire status to COMPLETE. If `shouldSyncApprovedToAnswerLibrary` is true\n(the default), approved answers are added to the answer library for future use. For\nnon-English SPREADSHEET or DOCUMENT questionnaires, answer library sync will be ignored.", - "summary": "Complete questionnaire", + "description": "Get a group by ID.", + "summary": "Get group by ID", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14710,47 +20253,38 @@ "parameters": [ { "in": "path", - "name": "questionnaireId", + "name": "groupId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CompleteQuestionnaireRequest" - } - } - } - } + ] } }, - "/customer-trust/tag-categories": { - "get": { - "operationId": "ListTagCategories", + "/groups/{groupId}/add-people": { + "post": { + "operationId": "AddPeopleToGroup", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ArrayResponse_UserDefinedTagCategory_" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { "results": [ { - "id": "507f1f77bcf86cd799439011", - "displayName": "Industry" + "id": "person-id-1", + "status": "SUCCESS" }, { - "id": "507f1f77bcf86cd799439012", - "displayName": "Region" + "id": "person-id-2", + "status": "ERROR", + "message": "Invalid Input" } ] } @@ -14760,10 +20294,10 @@ } } }, - "description": "List user-defined tag categories. Optionally filter by product context.", - "summary": "List tag categories", + "description": "Add people to a group.", + "summary": "Add people to group", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14772,60 +20306,227 @@ ], "parameters": [ { - "in": "query", - "name": "productContextIdsMatchesAny", - "required": false, + "in": "path", + "name": "groupId", + "required": true, "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/CustomerTrustProductContextIdFilter" + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "properties": { + "updates": { + "items": { + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ], + "type": "object" + }, + "type": "array", + "description": "List of people IDs to add a group.", + "minItems": 1, + "maxItems": 100 + } + }, + "required": [ + "updates" + ], + "type": "object" } } } - ] + } } }, - "/customer-trust/tag-categories/{tagCategoryId}": { + "/groups/{groupId}/people": { "get": { - "operationId": "GetTagsForCategory", + "operationId": "GetGroupMembers", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TagCategoryWithTags" + "items": { + "$ref": "#/components/schemas/Person" + }, + "type": "array" }, "examples": { "Example 1": { - "value": { - "category": { - "id": "507f1f77bcf86cd799439011", - "displayName": "Industry" - }, - "tags": [ - { - "id": "507f1f77bcf86cd799439013", - "category": "507f1f77bcf86cd799439011", - "displayName": "Healthcare" + "value": [ + { + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" }, - { - "id": "507f1f77bcf86cd799439014", - "category": "507f1f77bcf86cd799439011", - "displayName": "Finance" + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } + } } - ] - } + } + ] } } } } } }, - "description": "Retrieve a tag category and its associated tags by category ID.", - "summary": "Get tags for category", + "description": "List people in a group.", + "summary": "List people in a group", "tags": [ - "Customer Trust" + "Groups" ], "security": [ { @@ -14835,135 +20536,174 @@ "parameters": [ { "in": "path", - "name": "tagCategoryId", + "name": "groupId", "required": true, "schema": { "type": "string" } } ] - } - }, - "/discovered-vendors": { - "get": { - "operationId": "ListDiscoveredVendors", + }, + "post": { + "operationId": "AddPersonToGroup", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_DiscoveredVendor_" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "a2f7e1b9d0c3f4e5a6c7b8d8", - "name": "Vanta", - "category": { - "name": "Engineering" - }, - "source": "JAMF", - "normalizedName": "vanta", - "discoveredDate": "2024-01-01T00:00:00.000Z", - "numberOfAccounts": 7, - "ignored": { - "ignoredByUserId": "6626afb14c912f0a50e85619", - "ignoredReason": "reason", - "ignoredAtDate": "2024-02-01T00:00:00.000Z" - }, - "rejected": null + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" + }, + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "6696ea0595df50d5cd6ec3b7", - "endCursor": "6696ece48eb1f98ff3d927c6" } - } - } - } - } - } - } - } - }, - "description": "List discovered vendors.", - "summary": "List discovered vendors", - "tags": [ - "Discovered Vendors" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "description": "Defaults to \"NEEDS_REVIEW\" if not provided", - "in": "query", - "name": "scope", - "required": false, - "schema": { - "$ref": "#/components/schemas/DiscoveredVendorScope" - } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - } - ] - } - }, - "/discovered-vendors/{discoveredVendorId}/accounts": { - "get": { - "operationId": "ListDiscoveredVendorAccounts", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_DiscoveredVendorAccount_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "id": "66c6578ce02cc3a3483024d1", - "displayName": "Example Computer", - "type": "COMPUTER", - "owner": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d8", - "displayName": "Example user", - "email": "example@example.com", - "type": "USER" - } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "6696ea0595df50d5cd6ec3b7", - "endCursor": "6696ece48eb1f98ff3d927c6" } } } @@ -14973,10 +20713,10 @@ } } }, - "description": "List of discovered vendor accounts.", - "summary": "List of discovered vendor accounts", + "description": "Add a single person, by ID, to a group.", + "summary": "Add person to a group", "tags": [ - "Discovered Vendors" + "Groups" ], "security": [ { @@ -14986,91 +20726,196 @@ "parameters": [ { "in": "path", - "name": "discoveredVendorId", + "name": "groupId", "required": true, "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "properties": { + "id": { + "type": "string", + "description": "ID of the person to add to the group." + } + }, + "required": [ + "id" + ], + "type": "object" + } } } - ] + } } }, - "/discovered-vendors/{discoveredVendorId}/add-to-managed": { - "post": { - "operationId": "AddDiscoveredVendorToManaged", + "/groups/{groupId}/people/{personId}": { + "delete": { + "operationId": "RemovePersonFromGroup", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Vendor" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d8", - "name": "Vanta", - "websiteUrl": "https://www.vanta.com/", - "accountManagerName": "John Doe", - "accountManagerEmail": "john@doe.com", - "servicesProvided": "SaaS", - "additionalNotes": "Automate compliance and streamline security reviews with the leading trust management platform.", - "authDetails": { - "method": "O_AUTH", - "passwordMFA": true, - "passwordRequiresNumber": true, - "passwordRequiresSymbol": true, - "passwordMinimumLength": 16 - }, - "securityOwnerUserId": "6626afa6490ec920099773e7", - "businessOwnerUserId": "6626afb14c912f0a50e85619", - "contractStartDate": "2024-02-01T00:00:00.000Z", - "contractRenewalDate": "2025-02-01T00:00:00.000Z", - "contractTerminationDate": null, - "lastSecurityReviewCompletionDate": "2024-01-01T00:00:00.000Z", - "nextSecurityReviewDueDate": "2025-01-01T00:00:00.000Z", - "isVisibleToAuditors": true, - "isRiskAutoScored": true, - "category": { - "displayName": "cloudMonitoring" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" }, - "riskAttributeIds": [ - "6626b0298acc44f8674390da", - "6626b02ea4cd9ba80d773c20" + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" ], - "status": "MANAGED", - "inherentRiskLevel": "HIGH", - "residualRiskLevel": "MEDIUM", - "vendorHeadquarters": "USA", - "contractAmount": { - "amount": 1000000, - "currency": "USD" + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" }, - "customFields": null, - "latestDecision": { - "status": "APPROVED", - "lastUpdatedAt": "2024-01-01T00:00:00.000Z" + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } }, - "linkedTaskTrackerTaskProcurementRequest": { - "service": "jira", - "url": "https://random-company.atlassian.net/browse/PROJ-123" + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } + } } } } @@ -15079,10 +20924,10 @@ } } }, - "description": "Add a discovered vendor to managed vendor.", - "summary": "Adds a discovered vendor to managed vendor by ID", + "description": "Remove a single person, by ID, from a group.", + "summary": "Remove person from a group", "tags": [ - "Discovered Vendors" + "Groups" ], "security": [ { @@ -15092,224 +20937,48 @@ "parameters": [ { "in": "path", - "name": "discoveredVendorId", + "name": "groupId", "required": true, "schema": { "type": "string" } - } - ] - } - }, - "/documents": { - "post": { - "operationId": "CreateDocument", - "responses": { - "201": { - "description": "Document created", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/Document" - }, - "examples": { - "Example 1": { - "value": { - "id": "1", - "ownerId": "2", - "category": "Account setup", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "title": "Document Title", - "uploadStatus": "Needs document", - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "url": "https://example.com" - } - } - } - } - } - } - }, - "description": "Create a custom document.", - "summary": "Create a custom document", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CreateDocumentInput" - } - } - } - } - }, - "get": { - "operationId": "ListDocuments", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Document_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "id": "1", - "ownerId": "2", - "category": "Account setup", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "title": "Document Title", - "uploadStatus": "Needs document", - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "url": "https://example.com" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" - } - } - } - } - } - } - } - } - }, - "description": "List documents.", - "summary": "List documents", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "description": "Includes all documents that match one of the provided framework values in frameworkMatchesAny.", - "in": "query", - "name": "frameworkMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } }, - { - "description": "Includes all documents that match one of the provided status values in statusMatchesAny.", - "in": "query", - "name": "statusMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/DocumentStatus" - } - } - } - ] - } - }, - "/documents/{documentId}": { - "delete": { - "operationId": "DeleteDocument", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Delete a document by ID.", - "summary": "Delete document by ID", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ { "in": "path", - "name": "documentId", + "name": "personId", "required": true, "schema": { "type": "string" } } ] - }, - "get": { - "operationId": "GetDocument", + } + }, + "/groups/{groupId}/remove-people": { + "post": { + "operationId": "RemovePeopleFromGroup", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/DocumentDetail" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { - "id": "access-requests", - "title": "Access request ticket and history", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "category": "Account setup", - "uploadStatus": "Needs document", - "url": "https://example.com", - "ownerId": "1", - "note": "Example document note", - "nextRenewalDate": "2025-03-17T00:00:00.000Z", - "renewalCadence": "P1Y", - "reminderWindow": "P1M", - "deactivatedStatus": { - "isDeactivated": false, - "reason": null, - "expiration": null, - "creationDate": "2024-03-02T00:00:00.000Z" - }, - "subscribers": [] + "results": [ + { + "id": "person-id-1", + "status": "SUCCESS" + }, + { + "id": "person-id-2", + "status": "ERROR", + "message": "Invalid Input" + } + ] } } } @@ -15317,10 +20986,10 @@ } } }, - "description": "Get a document by ID.", - "summary": "Get document by ID", + "description": "Remove people from a group.", + "summary": "Remove people from group", "tags": [ - "Documents" + "Groups" ], "security": [ { @@ -15330,25 +20999,57 @@ "parameters": [ { "in": "path", - "name": "documentId", + "name": "groupId", "required": true, "schema": { "type": "string" } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "properties": { + "updates": { + "items": { + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ], + "type": "object" + }, + "type": "array", + "description": "List of people IDs to remove from a group.", + "minItems": 1, + "maxItems": 100 + } + }, + "required": [ + "updates" + ], + "type": "object" + } + } + } + } } }, - "/documents/{documentId}/controls": { + "/integrations": { "get": { - "operationId": "ListControlsForDocument", + "operationId": "ListConnectedIntegrations", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Control_" + "$ref": "#/components/schemas/PaginatedResponse_Integration_" }, "examples": { "Example 1": { @@ -15356,62 +21057,32 @@ "results": { "data": [ { - "id": "1", - "ownerId": "2", - "category": "Account setup", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "title": "Document Title", - "uploadStatus": "Needs document", - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "url": "https://example.com" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" - } - } - } - }, - "Example 2": { - "value": { - "results": { - "data": [ - { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" + "integrationId": "asana", + "displayName": "Asana", + "resourceKinds": [ + "AsanaAccount", + "AsanaTask" ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - }, - "role": "CONTROLLER", - "customFields": [ + "connections": [ { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" + "connectionId": "62ffd6793ef7978318baefa8", + "isDisabled": false, + "connectionErrorMessage": null + }, + { + "connectionId": "62fed1234ef7978318baefa9", + "isDisabled": true, + "connectionErrorMessage": "Authorization Error connecting to Asana" } - ], - "creationDate": null, - "modificationDate": null + ] } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "totalCount": 1 + "startCursor": "YXBvbGxv", + "endCursor": "YXBvbGxv" + } } } } @@ -15420,10 +21091,10 @@ } } }, - "description": "List a document's associated controls.", - "summary": "List document's controls", + "description": "Lists all integrations connected to a Vanta instance.", + "summary": "List connected integrations", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15431,14 +21102,6 @@ } ], "parameters": [ - { - "in": "path", - "name": "documentId", - "required": true, - "schema": { - "type": "string" - } - }, { "in": "query", "name": "pageSize", @@ -15458,38 +21121,38 @@ ] } }, - "/documents/{documentId}/links": { + "/integrations/{integrationId}": { "get": { - "operationId": "ListLinksForDocument", + "operationId": "GetConnectedIntegration", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_UploadedLink_" + "$ref": "#/components/schemas/Integration" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "1", - "creationDate": "2024-06-26T00:00:00.000Z", - "effectiveDate": "2024-07-01T00:00:00.000Z", - "title": "example link", - "url": "https://example.com/", - "description": "example link" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" + "integrationId": "asana", + "displayName": "Asana", + "resourceKinds": [ + "AsanaAccount", + "AsanaTask" + ], + "connections": [ + { + "connectionId": "62ffd6793ef7978318baefa8", + "isDisabled": false, + "connectionErrorMessage": null + }, + { + "connectionId": "62fed1234ef7978318baefa9", + "isDisabled": true, + "connectionErrorMessage": "Authorization Error connecting to Asana" } - } + ] } } } @@ -15497,10 +21160,10 @@ } } }, - "description": "List the uploaded links for a document.", - "summary": "List document's links", + "description": "Gets details for a specific integration by connection ID.", + "summary": "Get a connected integration", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15509,50 +21172,94 @@ ], "parameters": [ { + "description": "Unique identifier of the integration", "in": "path", - "name": "documentId", + "name": "integrationId", "required": true, "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" + } + ] + } + }, + "/integrations/{integrationId}/resource-kinds": { + "get": { + "operationId": "ListResourceKindSummaries", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "items": { + "$ref": "#/components/schemas/ResourceKindSummary" + }, + "type": "array" + }, + "examples": { + "Example 1": { + "value": [ + { + "integrationId": "asana", + "resourceKind": "AsanaAccount", + "isScopable": true, + "canUpdateDescription": true, + "canUpdateOwner": true + } + ] + } + } + } } - }, + } + }, + "description": "Lists a connected integration's resource types (kinds) such as S3Bucket or CloudwatchLogGroup.", + "summary": "List integration resource kinds", + "tags": [ + "Integrations" + ], + "security": [ { - "in": "query", - "name": "pageCursor", - "required": false, + "bearerAuth": [] + } + ], + "parameters": [ + { + "description": "Unique identifier of the integration", + "in": "path", + "name": "integrationId", + "required": true, "schema": { - "$ref": "#/components/schemas/PageCursor" + "type": "string" } } ] - }, - "post": { - "operationId": "CreateLinkForDocument", + } + }, + "/integrations/{integrationId}/resource-kinds/{resourceKind}": { + "get": { + "operationId": "GetResourceKindDetails", "responses": { - "201": { - "description": "Link created for document", + "200": { + "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/UploadedLink" + "$ref": "#/components/schemas/ResourceKindDetails" }, "examples": { "Example 1": { "value": { - "id": "1", - "creationDate": "2024-06-26T00:00:00.000Z", - "effectiveDate": "2024-07-01T00:00:00.000Z", - "title": "example link", - "url": "https://example.com/", - "description": "example link" + "integrationId": "asana", + "resourceKind": "AsanaAccount", + "isScopable": true, + "canUpdateDescription": true, + "canUpdateOwner": true, + "numResources": 123, + "numInScope": 100, + "numOwned": 100, + "numWithDescription": 100 } } } @@ -15560,10 +21267,10 @@ } } }, - "description": "Create a link for a document.", - "summary": "Create document link", + "description": "Gets details for a specific resource type (kind) such as S3Bucket or CloudwatchLogGroup.", + "summary": "Get details for resource kind", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15572,57 +21279,28 @@ ], "parameters": [ { + "description": "Unique identifier of the integration.", "in": "path", - "name": "documentId", + "name": "integrationId", "required": true, "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CreateLinkForDocumentInput" - } - } - } - } - } - }, - "/documents/{documentId}/links/{linkId}": { - "delete": { - "operationId": "DeleteLinkForDocument", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Remove a link from a document.", - "summary": "Remove document link", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ + }, { + "description": "Unique identifier of the integration resource kind.", "in": "path", - "name": "documentId", + "name": "resourceKind", "required": true, "schema": { "type": "string" } }, { - "in": "path", - "name": "linkId", - "required": true, + "description": "Unique identifier of the integration connection.", + "in": "query", + "name": "connectionId", + "required": false, "schema": { "type": "string" } @@ -15630,29 +21308,31 @@ ] } }, - "/documents/{documentId}/set-owner": { - "post": { - "operationId": "SetOwnerForDocument", + "/integrations/{integrationId}/resource-kinds/{resourceKind}/resources": { + "patch": { + "operationId": "UpdateResources", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Document" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { - "id": "1", - "ownerId": "2", - "category": "Account setup", - "description": "Provide two examples of a recent access request and approval ", - "isSensitive": false, - "title": "Document Title", - "uploadStatus": "Needs document", - "uploadStatusDate": "2024-03-17T00:00:00.000Z", - "url": "https://example.com" + "results": [ + { + "id": "RESOURCE_ID", + "status": "SUCCESS" + }, + { + "id": "OTHER_RESOURCE_ID", + "status": "ERROR", + "message": "Invalid Input" + } + ] } } } @@ -15660,10 +21340,10 @@ } } }, - "description": "Assign or unassign a user to the document.", - "summary": "Set document owner", + "description": "Updates metadata for multiple resources.", + "summary": "Update resource metadata", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15672,8 +21352,18 @@ ], "parameters": [ { + "description": "Unique identifier of the integration.", + "in": "path", + "name": "integrationId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Unique identifier of the integration resource kind.", "in": "path", - "name": "documentId", + "name": "resourceKind", "required": true, "schema": { "type": "string" @@ -15685,25 +21375,71 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/SetOwnerForDocumentInput" + "properties": { + "updates": { + "items": { + "$ref": "#/components/schemas/UpdateResourceRequest" + }, + "type": "array", + "description": "List of resource update requests.", + "minItems": 1, + "maxItems": 50 + } + }, + "required": [ + "updates" + ], + "type": "object" } } } } - } - }, - "/documents/{documentId}/submit": { - "post": { - "operationId": "SubmitDocumentCollection", + }, + "get": { + "operationId": "ListResources", "responses": { - "204": { - "description": "No content" + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_AnyResource_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "responseType": "Resource", + "resourceKind": "AsanaTask", + "resourceId": "5e7400d77a8e3731ab2d5c8e", + "connectionId": "62ffd6793ef7978318baefa8", + "displayName": "My Security Task", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-06T19:02:25.202Z" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "YXBvbGxv", + "endCursor": "YXBvbGxv" + } + } + } + } + } + } + } } }, - "description": "Submit document collection.", - "summary": "Submit document collection", + "description": "Lists resources for a specific integration and resource type (kind) such as S3Bucket or CloudwatchLogGroup.", + "summary": "List resources", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15712,55 +21448,90 @@ ], "parameters": [ { + "description": "Unique identifier of the integration.", "in": "path", - "name": "documentId", + "name": "integrationId", "required": true, "schema": { "type": "string" } - } - ] - } - }, - "/documents/{documentId}/uploads": { - "post": { - "operationId": "UploadFileForDocument", - "responses": { - "201": { - "description": "File uploaded for document", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/UploadedFileT" - }, - "examples": { - "Example 1": { - "value": { - "id": "1", - "fileName": "Document Name", - "title": "Document title", - "description": "Document Description", - "url": "https://example.com", - "creationDate": "2024-03-17T00:00:00.000Z", - "updatedDate": "2024-03-18T00:00:00.000Z", - "effectiveDate": "2024-03-17T00:00:00.000Z", - "deletionDate": null, - "mimeType": "application/pdf", - "uploadedBy": { - "id": "66993da0cf4ba2ad40599ba7", - "type": "USER" - } - } - } - } - } + }, + { + "description": "Unique identifier of the integration resource type.", + "in": "path", + "name": "resourceKind", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Unique identifier of the integration connection.", + "in": "query", + "name": "connectionId", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter resources that have a description.\nIf omitted, this will return resources both with and without a description.", + "in": "query", + "name": "hasDescription", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "description": "Filter resources that have an owner.\nIf omitted, this will return resources both with and without an owner.", + "in": "query", + "name": "hasOwner", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "description": "Filter resources that are in scope.\nIf omitted, this will return resources both in and out of scope.", + "in": "query", + "name": "isInScope", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" } } + ] + } + }, + "/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}": { + "patch": { + "operationId": "UpdateResource", + "responses": { + "204": { + "description": "No content" + } }, - "description": "Upload a file for a document.", - "summary": "Upload file for document", + "description": "Updates metadata for a specific resource such as an S3Bucket or CloudwatchLogGroup.", + "summary": "Update resource metadata", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15769,8 +21540,27 @@ ], "parameters": [ { + "description": "Unique identifier of the integration.", "in": "path", - "name": "documentId", + "name": "integrationId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Unique identifier of the integration resource kind.", + "in": "path", + "name": "resourceKind", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Unique identifier of the resource.", + "in": "path", + "name": "resourceId", "required": true, "schema": { "type": "string" @@ -15780,70 +21570,208 @@ "requestBody": { "required": true, "content": { - "multipart/form-data": { + "application/json": { "schema": { - "type": "object", "properties": { - "file": { - "type": "string", - "format": "binary" + "inScope": { + "type": "boolean", + "description": "Determines whether resources should be marked as in scope." }, - "effectiveAtDate": { + "description": { "type": "string", - "description": "Date indicating when the document is effective from." + "description": "Description to update for the resources." }, - "description": { + "ownerId": { "type": "string", - "description": "Description of the uploaded document." + "description": "Owner ID to update for the resources." } }, - "required": [ - "file" - ] + "type": "object" } } } } }, "get": { - "operationId": "ListFilesForDocument", + "operationId": "GetResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_UploadedFileT_" + "$ref": "#/components/schemas/AnyResource" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "1", - "fileName": "Document Name", - "title": "Document title", - "description": "Document Description", - "url": "https://example.com", - "creationDate": "2024-03-17T00:00:00.000Z", - "updatedDate": "2024-03-18T00:00:00.000Z", - "effectiveDate": "2024-03-17T00:00:00.000Z", - "deletionDate": null, - "mimeType": "application/pdf", - "uploadedBy": { - "id": "66993da0cf4ba2ad40599ba7", - "type": "USER" - } - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" + "responseType": "Resource", + "resourceKind": "AsanaTask", + "resourceId": "5e7400d77a8e3731ab2d5c8e", + "connectionId": "62ffd6793ef7978318baefa8", + "displayName": "My Security Task", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-06T19:02:25.202Z" + } + }, + "Example 2": { + "value": { + "responseType": "Account", + "resourceKind": "AsanaAccount", + "resourceId": "5e7400d77a8e3731ab2d5c8e", + "connectionId": "62ffd6793ef7978318baefa8", + "displayName": "Vlad's Account", + "owner": "5e56b1e0188626620a828894", + "inScope": true, + "description": null, + "creationDate": "2024-03-06T19:02:25.202Z", + "accountName": "vlads_account", + "roles": [ + "admin" + ], + "groups": [ + "admin" + ], + "isDeactivated": false, + "isMfaEnabled": null + } + }, + "Example 3": { + "value": { + "responseType": "Account", + "resourceKind": "AwsAccount", + "resourceId": "5e7400d77a8e3731ab2d5c8e", + "connectionId": "62ffd6793ef7978318baefa8", + "displayName": "Vlad's AWS Account", + "owner": "5e56b1e0188626620a828894", + "inScope": true, + "description": null, + "creationDate": "2024-03-06T19:02:25.202Z", + "accountName": "vlads_aws_account", + "roles": [ + "admin" + ], + "groups": [ + "admin" + ], + "isDeactivated": false, + "isMfaEnabled": true, + "awsUserAccountId": "ABCD1234567890", + "awsAccountNumber": "123456789012", + "accessKeys": [ + { + "accessKeyId": "EXMAPLEKEY1", + "status": "Active" + }, + { + "accessKeyId": "EXAMPLEKEY2", + "status": "Inactive" } - } + ] + } + }, + "Example 4": { + "value": { + "responseType": "Database", + "resourceKind": "DocumentDBCluster", + "resourceId": "661095bd5397b9c17793c420", + "connectionId": "661095bd5397b9c17793c41d", + "displayName": "document-db-cluster", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-27T00:56:20.483Z", + "account": "aws-account", + "areBackupsEnabled": true, + "isEncrypted": true, + "containsEphi": null, + "containsUserData": null + } + }, + "Example 5": { + "value": { + "responseType": "Device", + "resourceKind": "JamfManagedComputer", + "resourceId": "661092077f68e200f850eb6a", + "connectionId": "661092077f68e200f850eb67", + "displayName": "jamf-managed-computer", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-27T00:56:20.483Z", + "operatingSystemName": "windows", + "isEncrypted": true, + "containsEphi": true, + "containsUserData": true + } + }, + "Example 6": { + "value": { + "responseType": "PaaS", + "resourceKind": "DigitalOceanApp", + "resourceId": "66108f3890aac655f7d957ae", + "connectionId": "66108f3890aac655f7d957ab", + "displayName": "digital-ocean-app", + "owner": null, + "inScope": true, + "description": "digital ocean paas app", + "creationDate": "2024-03-27T00:56:20.483Z", + "containsEphi": null, + "containsUserData": null + } + }, + "Example 7": { + "value": { + "responseType": "Queue", + "resourceKind": "SQS", + "resourceId": "6611eafe02a95ea7f943962f", + "connectionId": "6611eafe02a95ea7f943962c", + "displayName": "aws-resource", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-27T00:56:20.483Z", + "account": "aws-account", + "region": "us-east-1", + "containsEphi": null, + "containsUserData": null + } + }, + "Example 8": { + "value": { + "responseType": "StorageBucket", + "resourceKind": "S3", + "resourceId": "6611ec449e231114e49ef91b", + "connectionId": "6611ec449e231114e49ef918", + "displayName": "aws-resource", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-27T00:56:20.483Z", + "account": "aws-account", + "region": "", + "isEncrypted": true, + "isVersioned": true, + "containsEphi": null, + "containsUserData": null + } + }, + "Example 9": { + "value": { + "responseType": "ContainerRepository", + "resourceKind": "ECRContainerRepository", + "resourceId": "661303e12990509c5874a7b9", + "connectionId": "661303e12990509c5874a7b6", + "displayName": "aws-resource", + "owner": null, + "inScope": true, + "description": null, + "creationDate": "2024-03-27T00:56:20.483Z", + "account": "aws-account", + "region": "us-east-1", + "isAutoscanEnabled": true } } } @@ -15851,56 +21779,10 @@ } } }, - "description": "List the uploaded files for a document.", - "summary": "List document's uploads", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "documentId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - } - ] - } - }, - "/documents/{documentId}/uploads/{uploadedFileId}": { - "delete": { - "operationId": "DeleteFileForDocument", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Delete a file for a document.", - "summary": "Delete file for a document", + "description": "Gets resource by its ID.", + "summary": "Get resource by ID", "tags": [ - "Documents" + "Integrations" ], "security": [ { @@ -15909,191 +21791,27 @@ ], "parameters": [ { + "description": "Unique identifier of the integration.", "in": "path", - "name": "documentId", + "name": "integrationId", "required": true, "schema": { "type": "string" } }, { + "description": "Unique identifier of the integration resource kind.", "in": "path", - "name": "uploadedFileId", - "required": true, - "schema": { - "type": "string" - } - } - ] - } - }, - "/documents/{documentId}/uploads/{uploadedFileId}/media": { - "get": { - "operationId": "GetUploadedfileMedia", - "responses": { - "200": { - "description": "Ok", - "content": { - "text/csv": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "text/plain": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "text/markdown": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/json": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/vnd.ms-excel": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/svg+xml": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/xml": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/x-pem-file": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/x-x509-ca-cert": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/x-x509-user-cert": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/bmp": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/msword": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/vnd.openxmlformats-officedocument.wordprocessingml.document": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/gzip": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/x-icon": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/vnd.microsoft.icon": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/jpeg": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/pdf": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/png": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/postscript": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/vnd.ms-powerpoint": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/vnd.openxmlformats-officedocument.presentationml.presentation": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "image/webp": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "font/woff2": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/zip": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - }, - "application/x-zip-compressed": { - "schema": { - "$ref": "#/components/schemas/NodeJS.ReadableStream" - } - } - } - } - }, - "description": "Download a file from a document.", - "summary": "Download file for document", - "tags": [ - "Documents" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "documentId", + "name": "resourceKind", "required": true, "schema": { "type": "string" } }, { + "description": "Unique identifier of the resource.", "in": "path", - "name": "uploadedFileId", + "name": "resourceId", "required": true, "schema": { "type": "string" @@ -16102,44 +21820,68 @@ ] } }, - "/event-logs": { + "/issues": { "get": { - "operationId": "ListEventLogs", + "operationId": "List", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_EventLog_" + "$ref": "#/components/schemas/PaginatedResponse_Issue_" }, "examples": { "Example 1": { "value": { "results": { - "data": [ - { - "id": "69fbbae3e16190a288ee8eb0", - "actor": { - "id": "69fbbaf987273a4b462580e9", - "type": "USER" + "pageInfo": { + "endCursor": "NjgzZTlhZjFiMTIzNDU2Nzg5MGFiY2Rl", + "hasNextPage": true, + "hasPreviousPage": false, + "startCursor": "NjgzZTlhZjFiMTIzNDU2Nzg5MGFiY2Rl" + }, + "data": [ + { + "id": "683e9af1b1234567890abcde", + "readableIssueId": "ISS-001", + "createdDate": "2026-01-15T10:00:00.000Z", + "createdBy": { + "actorType": "USER", + "actorId": "user-123" }, - "date": "2026-05-03T21:08:22.385Z", - "action": "LOGIN_USER", - "targets": [ + "lastModifiedBy": { + "actorType": "USER", + "actorId": "user-123" + }, + "lastModifiedDate": "2026-01-20T14:30:00.000Z", + "title": "Access review process needs documentation", + "description": "The access review process lacks formal documentation.", + "owners": [ { - "id": "email", - "type": "LOGIN_METHOD" + "ownerType": "USER", + "ownerId": "user-456" } - ] + ], + "severity": "MEDIUM", + "status": "IN_PROGRESS", + "rootCause": "Process was informally defined and not documented.", + "correctiveAction": "Document the access review process and train relevant staff.", + "dueDate": "2026-03-01T00:00:00.000Z", + "source": { + "sourceType": "SELF_ASSESSMENT" + }, + "controlDomain": "Identity and Access Management", + "closedMetadata": null, + "detectedDate": "2026-01-10T00:00:00.000Z", + "mappedControlIds": [], + "mappedRiskScenarioIds": [], + "mappedPolicyIds": [], + "customFields": [], + "template": "STANDARD_ISSUE", + "type": null } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "eyJjcmVhdGVkQXQiOnsiJGRhdGUiOiIyMDI2LTA1LTAzVDIxOjA4OjExLjQzNFoifSwiX2lkIjp7IiRvaWQiOiI2OGZiYmFlM2UxNjA5MGEyODRlZThlYjAifX0=", - "endCursor": "eyJjcmVhdGVkQXQiOnsiJGRhdGUiOiIyMDI2LTA1LTAzVDIxOjA4OjIyLjM4NVoifSwiX2lkIjp7IiRvaWQiOiI2OWZiYmFlM2UxNjE5MGEyODhlZThlYjAifX0=" - } + ] } } } @@ -16148,10 +21890,10 @@ } } }, - "description": "List event logs.\n\nSee the [event log reference](/reference/manage-vanta/event-log-reference) for an inexhaustive list of `actor.type`, `action`, and `targets[].type` values.", - "summary": "List event logs", + "description": "List issues on a domain (paginated).\nReturns a paginated list of issues that the authenticated app has\npermission to view, optionally filtered and sorted.", + "summary": "List issues", "tags": [ - "Event Logs" + "Issues" ], "security": [ { @@ -16176,138 +21918,351 @@ } }, { - "description": "Filter to event logs created at or after this ISO 8601 timestamp.", + "description": "Full-text search across issue title and description.", "in": "query", - "name": "startDate", + "name": "search", "required": false, "schema": { - "format": "date-time", "type": "string" - } - } - ] - } - }, - "/frameworks": { - "get": { - "operationId": "ListFrameworks", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Framework_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "id": "soc2", - "displayName": "SOC 2", - "shorthandName": "SOC 2", - "description": "AICPA standardized framework to prove a company’s security posture to prospective customers. For all US and international businesses.", - "numControlsCompleted": 43, - "numControlsTotal": 86, - "numDocumentsPassing": 7, - "numDocumentsTotal": 16, - "numTestsPassing": 21, - "numTestsTotal": 46 - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "aXNvMjcwMDFfMjAyMg==", - "endCursor": "aXNvMjcwMDFfMjAyMg==" - } - } - } - } - } + }, + "example": "weak password" + }, + { + "description": "Filter to issues matching any of the provided readable issue IDs.", + "in": "query", + "name": "readableIssueIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" } } - } - }, - "description": "Lists available frameworks.", - "summary": "List available frameworks", - "tags": [ - "Frameworks" - ], - "security": [ + }, + { + "description": "Filter to issues matching any of the provided statuses.", + "in": "query", + "name": "statusMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/IssueStatus" + } + }, + "example": [ + "IN_PROGRESS", + "CLOSED" + ] + }, + { + "description": "Filter to issues matching any of the provided severities.", + "in": "query", + "name": "severityMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/IssueSeverity" + } + }, + "example": [ + "HIGH", + "CRITICAL" + ] + }, + { + "description": "Filter to issues matching any of the provided sources.", + "in": "query", + "name": "sourceMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/SourceType" + } + }, + "example": [ + "AUDIT", + "SELF_ASSESSMENT" + ] + }, + { + "description": "Filter to issues matching any of the provided types.", + "in": "query", + "name": "typeMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/StandardIssueType" + } + }, + "example": [ + "AREA_OF_CONCERN", + "PROCESS_FOR_IMPROVEMENT" + ] + }, + { + "description": "Filter to issues owned by any of the provided owner IDs.", + "in": "query", + "name": "ownerIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + }, + "example": [ + "user-123", + "user-456" + ] + }, + { + "description": "Filter to issues matching any of the provided templates.", + "in": "query", + "name": "templateMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/IssueTemplate" + } + }, + "example": [ + "STANDARD_ISSUE", + "STANDARD_POAM" + ] + }, + { + "description": "Filter to issues closed for any of the provided reasons. Only applies\nto issues with a CLOSED status.", + "in": "query", + "name": "closeReasonMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/ClosedReason" + } + }, + "example": [ + "RESOLVED", + "OTHER" + ] + }, + { + "description": "Filter to issues closed on or after this date.", + "in": "query", + "name": "closedAfterDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-01-01T00:00:00Z" + }, + { + "description": "Filter to issues closed on or before this date.", + "in": "query", + "name": "closedBeforeDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-12-31T23:59:59Z" + }, + { + "description": "Include issues without a due date. This is functionally a no-op if dueBeforeDate or dueAfterDate are not provided.", + "in": "query", + "name": "includeIssuesWithoutDueDate", + "required": false, + "schema": { + "type": "boolean" + }, + "example": true + }, + { + "description": "Only include issues without a due date. This filter cannot be used in conjunction with dueBeforeDate or dueAfterDate.", + "in": "query", + "name": "includeOnlyIssuesWithoutDueDate", + "required": false, + "schema": { + "type": "boolean" + }, + "example": false + }, + { + "description": "Filter to issues with a due date on or after this date.", + "in": "query", + "name": "dueAfterDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-01-01T00:00:00Z" + }, + { + "description": "Filter to issues with a due date on or before this date.", + "in": "query", + "name": "dueBeforeDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-12-31T23:59:59Z" + }, + { + "description": "Filter to issues detected on or after this date.", + "in": "query", + "name": "detectedAfterDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-01-01T00:00:00Z" + }, + { + "description": "Filter to issues detected on or before this date.", + "in": "query", + "name": "detectedBeforeDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-12-31T23:59:59Z" + }, + { + "description": "Filter to issues created on or after this date.", + "in": "query", + "name": "createdAfterDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-01-01T00:00:00Z" + }, + { + "description": "Filter to issues created on or before this date.", + "in": "query", + "name": "createdBeforeDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + }, + "example": "2023-12-31T23:59:59Z" + }, + { + "description": "Filter to issues sourced from any of the provided audit IDs.", + "in": "query", + "name": "auditIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + }, + "example": [ + "audit-123", + "audit-456" + ] + }, { - "bearerAuth": [] - } - ], - "parameters": [ + "description": "Filter to issues mapped to any of the provided control IDs.", + "in": "query", + "name": "controlIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + }, + "example": [ + "control-123", + "control-456" + ] + }, { + "description": "Field to sort the results by.", "in": "query", - "name": "pageSize", + "name": "orderBy", "required": false, "schema": { - "$ref": "#/components/schemas/PageSize" + "$ref": "#/components/schemas/IssueSortField" } }, { + "description": "Direction to sort the results in. One of `asc` or `desc`. Defaults to `asc`.", "in": "query", - "name": "pageCursor", + "name": "orderDirection", "required": false, "schema": { - "$ref": "#/components/schemas/PageCursor" + "$ref": "#/components/schemas/OrderDirection" } } ] } }, - "/frameworks/{frameworkId}": { + "/issues/{issueId}": { "get": { - "operationId": "GetFramework", + "operationId": "GetIssue", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/FrameworkDetail" + "$ref": "#/components/schemas/Issue" }, "examples": { "Example 1": { "value": { - "id": "soc2", - "displayName": "SOC 2", - "shorthandName": "SOC 2", - "description": "AICPA standardized framework to prove a company’s security posture to prospective customers. For all US and international businesses.", - "numControlsCompleted": 43, - "numControlsTotal": 86, - "numDocumentsPassing": 7, - "numDocumentsTotal": 16, - "numTestsPassing": 21, - "numTestsTotal": 46, - "requirementCategories": [ + "id": "683e9af1b1234567890abcde", + "readableIssueId": "ISS-001", + "createdDate": "2026-01-15T10:00:00.000Z", + "createdBy": { + "actorType": "USER", + "actorId": "user-123" + }, + "lastModifiedBy": { + "actorType": "USER", + "actorId": "user-123" + }, + "lastModifiedDate": "2026-01-20T14:30:00.000Z", + "title": "Access review process needs documentation", + "description": "The access review process lacks formal documentation.", + "owners": [ { - "id": "CC 1.0", - "name": "Control Environment", - "shorthand": null, - "requirements": [ - { - "id": "CC 1.1", - "name": "", - "shorthand": null, - "description": "COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values.", - "controls": [ - { - "id": "background-checks-performed", - "externalId": null, - "name": "Personnel background checks performed", - "description": "The company performs background checks on new personnel." - } - ] - } - ] + "ownerType": "USER", + "ownerId": "user-456" } - ] + ], + "severity": "MEDIUM", + "status": "IN_PROGRESS", + "rootCause": "Process was informally defined and not documented.", + "correctiveAction": "Document the access review process and train relevant staff.", + "dueDate": "2026-03-01T00:00:00.000Z", + "source": { + "sourceType": "SELF_ASSESSMENT" + }, + "controlDomain": "Identity and Access Management", + "closedMetadata": null, + "detectedDate": "2026-01-10T00:00:00.000Z", + "mappedControlIds": [], + "mappedRiskScenarioIds": [], + "mappedPolicyIds": [], + "customFields": [], + "template": "STANDARD_ISSUE", + "type": null } } } @@ -16315,10 +22270,10 @@ } } }, - "description": "Get a framework by ID.", - "summary": "Get framework by ID", + "description": "Get the details of an issue by its ID.", + "summary": "Get issue by ID", "tags": [ - "Frameworks" + "Issues" ], "security": [ { @@ -16328,7 +22283,7 @@ "parameters": [ { "in": "path", - "name": "frameworkId", + "name": "issueId", "required": true, "schema": { "type": "string" @@ -16337,16 +22292,16 @@ ] } }, - "/frameworks/{frameworkId}/controls": { + "/knowledge-base/answer-library": { "get": { - "operationId": "ListControlsForFramework", + "operationId": "ListAnswerLibraryEntries", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Control_" + "$ref": "#/components/schemas/PaginatedResponse_KnowledgeBaseAnswerLibraryEntryOutput_" }, "examples": { "Example 1": { @@ -16354,37 +22309,30 @@ "results": { "data": [ { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "externalId": "CRY-104", - "name": "Data encryption utilized", - "description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.", - "source": "Vanta", - "domains": [ - "CRYPTOGRAPHIC_PROTECTIONS" - ], - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" + "id": "507f1f77bcf86cd799439031", + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationStatus": "CURRENT", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" }, - "role": "CONTROLLER", - "customFields": [ + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-10-12T16:08:42.000Z", + "lastVerified": "2024-12-01T09:00:00.000Z", + "tags": [ { - "label": "Additional context", - "value": "This control is critical for GDPR compliance" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - ], - "creationDate": null, - "modificationDate": null + ] } ], "pageInfo": { "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "totalCount": 1 + "hasPreviousPage": false + } } } } @@ -16393,10 +22341,10 @@ } } }, - "description": "List a framework's controls.", - "summary": "List a framework's controls", + "description": "List Answer Library entries. Supports full-text search, tag filtering\n(OR across the given tags), and date-range filters on last-updated and\nexpiration.\n\nEntries are returned most-recently-updated first.", + "summary": "List Answer Library entries", "tags": [ - "Frameworks" + "Knowledge Base" ], "security": [ { @@ -16404,14 +22352,6 @@ } ], "parameters": [ - { - "in": "path", - "name": "frameworkId", - "required": true, - "schema": { - "type": "string" - } - }, { "in": "query", "name": "pageSize", @@ -16427,145 +22367,92 @@ "schema": { "$ref": "#/components/schemas/PageCursor" } - } - ] - } - }, - "/groups": { - "get": { - "operationId": "ListPersonGroups", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Group_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "id": "5f2c939a52855e725c8d5824", - "name": "Default Group", - "creationDate": "2024-03-07T18:46:05.944Z" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "5f2c939a52855e725c8d5824", - "endCursor": "5f2c939a52855e725c8d5824" - } - } - } - } - } - } - } - } - }, - "description": "Lists all groups by ID.", - "summary": "List groups", - "tags": [ - "Groups" - ], - "security": [ + }, { - "bearerAuth": [] - } - ], - "parameters": [ + "description": "Full-text search across question and answer.", + "in": "query", + "name": "q", + "required": false, + "schema": { + "type": "string" + } + }, { + "description": "Only include entries updated at or after this ISO 8601 timestamp.", "in": "query", - "name": "pageSize", + "name": "lastUpdatedAfter", "required": false, "schema": { - "$ref": "#/components/schemas/PageSize" + "type": "string" } }, { + "description": "Only include entries updated at or before this ISO 8601 timestamp.", "in": "query", - "name": "pageCursor", + "name": "lastUpdatedBefore", "required": false, "schema": { - "$ref": "#/components/schemas/PageCursor" + "type": "string" } - } - ] - } - }, - "/groups/{groupId}": { - "get": { - "operationId": "GetGroup", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/Group" - }, - "examples": { - "Example 1": { - "value": { - "id": "5f2c939a52855e725c8d5824", - "name": "Default Group", - "creationDate": "2024-03-07T18:46:05.944Z" - } - } - } - } + }, + { + "description": "JSON-encoded array of `{categoryId, tagId}` pairs. Entries matching any\nof the given tags are returned (OR filter). Discover valid `categoryId`\nand `tagId` values via `GET /v1/customer-trust/tag-categories` (to list\ncategories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}`\n(to list tags within a category).", + "in": "query", + "name": "matchesTags", + "required": false, + "schema": { + "type": "string" } - } - }, - "description": "Get a group by ID.", - "summary": "Get group by ID", - "tags": [ - "Groups" - ], - "security": [ + }, { - "bearerAuth": [] - } - ], - "parameters": [ + "description": "Only include entries expiring at or before this ISO 8601 timestamp.", + "in": "query", + "name": "expiresBefore", + "required": false, + "schema": { + "type": "string" + } + }, { - "in": "path", - "name": "groupId", - "required": true, + "description": "Only include entries expiring at or after this ISO 8601 timestamp.", + "in": "query", + "name": "expiresAfter", + "required": false, "schema": { "type": "string" } } ] - } - }, - "/groups/{groupId}/add-people": { + }, "post": { - "operationId": "AddPeopleToGroup", + "operationId": "CreateAnswerLibraryEntry", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" }, "examples": { "Example 1": { "value": { - "results": [ - { - "id": "person-id-1", - "status": "SUCCESS" - }, + "id": "507f1f77bcf86cd799439031", + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationStatus": "CURRENT", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-10-12T16:08:42.000Z", + "lastVerified": "2024-12-01T09:00:00.000Z", + "tags": [ { - "id": "person-id-2", - "status": "ERROR", - "message": "Invalid Input" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } ] } @@ -16575,239 +22462,87 @@ } } }, - "description": "Add people to a group.", - "summary": "Add people to group", + "description": "Create an Answer Library entry.", + "summary": "Create Answer Library entry", "tags": [ - "Groups" + "Knowledge Base" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "groupId", - "required": true, - "schema": { - "type": "string" - } - } - ], + "parameters": [], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "properties": { - "updates": { - "items": { - "properties": { - "id": { - "type": "string" - } - }, - "required": [ - "id" - ], - "type": "object" - }, - "type": "array", - "description": "List of people IDs to add a group.", - "minItems": 1, - "maxItems": 100 - } + "$ref": "#/components/schemas/CreateAnswerLibraryEntryInput" + }, + "example": { + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041" }, - "required": [ - "updates" - ], - "type": "object" + "expirationDate": "2025-12-31T00:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" + } + ] } } - } - } - } - }, - "/groups/{groupId}/people": { - "get": { - "operationId": "GetGroupMembers", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "items": { - "$ref": "#/components/schemas/Person" - }, - "type": "array" - }, - "examples": { - "Example 1": { - "value": [ - { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" - }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null - } - } + } + } + } + }, + "/knowledge-base/answer-library/{id}": { + "get": { + "operationId": "GetAnswerLibraryEntry", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439031", + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationStatus": "CURRENT", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-10-12T16:08:42.000Z", + "lastVerified": "2024-12-01T09:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - } - ] + ] + } } } } } } }, - "description": "List people in a group.", - "summary": "List people in a group", + "description": "Get an Answer Library entry.", + "summary": "Get Answer Library entry", "tags": [ - "Groups" + "Knowledge Base" ], "security": [ { @@ -16817,7 +22552,7 @@ "parameters": [ { "in": "path", - "name": "groupId", + "name": "id", "required": true, "schema": { "type": "string" @@ -16825,168 +22560,146 @@ } ] }, - "post": { - "operationId": "AddPersonToGroup", + "patch": { + "operationId": "UpdateAnswerLibraryEntryRoute", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Person" + "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" + "id": "507f1f77bcf86cd799439031", + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationStatus": "CURRENT", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" - }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-10-12T16:08:42.000Z", + "lastVerified": "2024-12-01T09:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null - } + ] + } + } + } + } + } + } + }, + "description": "Update an Answer Library entry.", + "summary": "Update Answer Library entry", + "tags": [ + "Knowledge Base" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateAnswerLibraryEntryInput" + }, + "example": { + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationDate": "2025-12-31T00:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" + } + ] + } + } + } + } + }, + "delete": { + "operationId": "DeleteAnswerLibraryEntryRoute", + "responses": { + "204": { + "description": "Answer library entry deleted" + } + }, + "description": "Delete an Answer Library entry.", + "summary": "Delete Answer Library entry", + "tags": [ + "Knowledge Base" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/knowledge-base/answer-library/{id}/verify": { + "post": { + "operationId": "VerifyAnswerLibraryEntryRoute", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + }, + "examples": { + "Example 1": { + "value": { + "id": "507f1f77bcf86cd799439031", + "question": "Do you encrypt customer data at rest?", + "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", + "expirationStatus": "CURRENT", + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-10-12T16:08:42.000Z", + "lastVerified": "2024-12-01T09:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - } + ] } } } @@ -16994,10 +22707,10 @@ } } }, - "description": "Add a single person, by ID, to a group.", - "summary": "Add person to a group", + "description": "Mark an Answer Library entry as verified. Stamps `lastVerifiedAt` to the\ncurrent time; the entry's question, answer, tags, owner, and expiration\nare left unchanged.", + "summary": "Verify Answer Library entry", "tags": [ - "Groups" + "Knowledge Base" ], "security": [ { @@ -17007,7 +22720,7 @@ "parameters": [ { "in": "path", - "name": "groupId", + "name": "id", "required": true, "schema": { "type": "string" @@ -17015,186 +22728,92 @@ } ], "requestBody": { - "required": true, + "required": false, "content": { "application/json": { "schema": { - "properties": { - "id": { - "type": "string" - } - }, - "required": [ - "id" - ], - "type": "object" + "$ref": "#/components/schemas/VerifyAnswerLibraryEntryInput" + }, + "example": { + "expirationDate": "2025-12-31T00:00:00.000Z" } } } } } }, - "/groups/{groupId}/people/{personId}": { - "delete": { - "operationId": "RemovePersonFromGroup", + "/knowledge-base/resources": { + "get": { + "operationId": "ListKnowledgeBaseResources", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Person" + "$ref": "#/components/schemas/PaginatedResponse_TrustKnowledgeBaseResourceOutput_" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" - }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" + "results": { + "data": [ + { + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ { - "name": "Policy 2" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] + "categoryId": "507f1f77bcf86cd799439051" }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" + { + "id": "507f1f77bcf86cd799439022", + "type": "URL", + "title": "Vanta Security Overview", + "description": "Public-facing overview of Vanta's security posture.", + "url": "https://www.vanta.com/security", + "customerVisibility": "PUBLIC", + "includeSubPages": true, + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-08-01T00:00:00.000Z", + "lastUpdated": "2024-11-04T13:21:55.000Z", + "lastVerified": "2024-11-04T13:21:55.000Z", + "tags": [ { - "name": "Custom offboarding task 2" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439014" } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null + ], + "categoryId": "507f1f77bcf86cd799439052" } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false } } } @@ -17204,10 +22823,10 @@ } } }, - "description": "Remove a single person, by ID, from a group.", - "summary": "Remove person from a group", + "description": "List Knowledge Base resources (documents and webpages) in a single\npaginated response. Each entry is a discriminated union on `type` —\n\"FILE\" entries carry a `fileUrl` (presigned S3 URL, valid for one\nhour), \"URL\" entries carry the resource's `url` and `includeSubPages`.\n\nSupports full-text search, type filtering, tag filtering (OR within\na category, AND across categories), and date-range filters on\nlast-updated and expiration.\n\nResources are returned most-recently-updated first.", + "summary": "List Knowledge Base resources", "tags": [ - "Groups" + "Knowledge Base" ], "security": [ { @@ -17216,17 +22835,83 @@ ], "parameters": [ { - "in": "path", - "name": "groupId", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Full-text search across resource titles.", + "in": "query", + "name": "q", + "required": false, "schema": { "type": "string" } }, { - "in": "path", - "name": "personId", - "required": true, + "description": "Filter to FILE and/or URL resources. Repeat the param to allow either.", + "in": "query", + "name": "typeMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/KnowledgeBaseResourceTypeFilter" + } + } + }, + { + "description": "Only include resources updated at or after this ISO 8601 timestamp.", + "in": "query", + "name": "lastUpdatedAfter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Only include resources updated at or before this ISO 8601 timestamp.", + "in": "query", + "name": "lastUpdatedBefore", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "JSON-encoded array of `{categoryId, tagId}` pairs. Tags within the\nsame category are OR'd together; tags across different categories\nare AND'd. For example, passing two tags from \"Framework\" and one\ntag from \"Region\" matches resources that have either of the two\nframeworks AND the given region. Discover valid `categoryId` and\n`tagId` values via `GET /v1/customer-trust/tag-categories` (to list\ncategories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}`\n(to list tags within a category).", + "in": "query", + "name": "matchesTags", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Only include resources expiring at or before this ISO 8601 timestamp.", + "in": "query", + "name": "expiresBefore", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Only include resources expiring at or after this ISO 8601 timestamp.", + "in": "query", + "name": "expiresAfter", + "required": false, "schema": { "type": "string" } @@ -17234,31 +22919,44 @@ ] } }, - "/groups/{groupId}/remove-people": { + "/knowledge-base/resources/documents": { "post": { - "operationId": "RemovePeopleFromGroup", + "operationId": "CreateDocumentResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" }, "examples": { "Example 1": { "value": { - "results": [ - { - "id": "person-id-1", - "status": "SUCCESS" - }, + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ { - "id": "person-id-2", - "status": "ERROR", - "message": "Invalid Input" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - ] + ], + "categoryId": "507f1f77bcf86cd799439051" } } } @@ -17266,173 +22964,114 @@ } } }, - "description": "Remove people from a group.", - "summary": "Remove people from group", + "description": "Create a document (FILE-type) resource in the Trust Knowledge Base.\nAccepts the document as a multipart/form-data upload.\n\nExample: send `multipart/form-data` with a required `file` (e.g. PDF)\nand `title`; optional fields include `description`, `customerVisibility`,\n`downloadPermission`, `isUsedInQuestionnaires` (\"true\"/\"false\"),\n`expirationDate` (ISO 8601), `tags` (JSON array string), `categoryId`,\nand `ownerAssignment` (JSON object string).", + "summary": "Create document resource", "tags": [ - "Groups" + "Knowledge Base" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "groupId", - "required": true, - "schema": { - "type": "string" - } - } - ], + "parameters": [], "requestBody": { "required": true, "content": { - "application/json": { + "multipart/form-data": { "schema": { + "type": "object", "properties": { - "updates": { - "items": { - "properties": { - "id": { - "type": "string" - } - }, - "required": [ - "id" - ], - "type": "object" - }, - "type": "array", - "description": "List of people IDs to remove from a group.", - "minItems": 1, - "maxItems": 100 - } - }, - "required": [ - "updates" - ], - "type": "object" - } - } - } - } - } - }, - "/integrations": { - "get": { - "operationId": "ListConnectedIntegrations", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Integration_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "integrationId": "asana", - "displayName": "Asana", - "resourceKinds": [ - "AsanaAccount", - "AsanaTask" - ], - "connections": [ - { - "connectionId": "62ffd6793ef7978318baefa8", - "isDisabled": false, - "connectionErrorMessage": null - }, - { - "connectionId": "62fed1234ef7978318baefa9", - "isDisabled": true, - "connectionErrorMessage": "Authorization Error connecting to Asana" - } - ] - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "YXBvbGxv", - "endCursor": "YXBvbGxv" - } - } - } + "file": { + "type": "string", + "format": "binary" + }, + "title": { + "type": "string", + "minLength": 1, + "description": "Title of the document resource." + }, + "description": { + "type": "string", + "description": "Description of the document resource." + }, + "ownerAssignment": { + "type": "string", + "description": "Owner to assign as a JSON string: {\"type\":\"User\",\"id\":\"\"}." + }, + "customerVisibility": { + "type": "string", + "description": "Customer visibility on the Trust Center: PRIVATE | SHAREABLE | REQUEST_ACCESS | PUBLIC." + }, + "downloadPermission": { + "type": "string", + "description": "Trust Center download permission: VIEW_ONLY | VIEW_AND_DOWNLOAD." + }, + "isUsedInQuestionnaires": { + "type": "string", + "description": "Whether to use this resource for Questionnaire Automation answer generation (\"true\" / \"false\")." + }, + "expirationDate": { + "type": "string", + "description": "Expiration date in ISO 8601." + }, + "tags": { + "type": "string", + "description": "Tags as a JSON array: [{\"categoryId\":\"\",\"tagId\":\"\"}]." + }, + "categoryId": { + "type": "string", + "description": "Trust Center category id to associate this resource with. Only\napplied when `customerVisibility` is `REQUEST_ACCESS` or `PUBLIC`;\nother visibilities don't place the resource on the Trust Center, so\nthe category is ignored. Pass an unknown id to fall back to\nuncategorized." } - } + }, + "required": [ + "file", + "title" + ] } } } - }, - "description": "Lists all integrations connected to a Vanta instance.", - "summary": "List connected integrations", - "tags": [ - "Integrations" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - } - ] + } } }, - "/integrations/{integrationId}": { - "get": { - "operationId": "GetConnectedIntegration", + "/knowledge-base/resources/documents/{id}": { + "patch": { + "operationId": "UpdateDocumentResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Integration" + "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" }, "examples": { "Example 1": { "value": { - "integrationId": "asana", - "displayName": "Asana", - "resourceKinds": [ - "AsanaAccount", - "AsanaTask" - ], - "connections": [ - { - "connectionId": "62ffd6793ef7978318baefa8", - "isDisabled": false, - "connectionErrorMessage": null - }, + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ { - "connectionId": "62fed1234ef7978318baefa9", - "isDisabled": true, - "connectionErrorMessage": "Authorization Error connecting to Asana" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - ] + ], + "categoryId": "507f1f77bcf86cd799439051" } } } @@ -17440,10 +23079,10 @@ } } }, - "description": "Gets details for a specific integration by connection ID.", - "summary": "Get a connected integration", + "description": "Apply a partial update to a document (FILE-type) resource. Omitted\nfields are left untouched. To swap the underlying file, use\n`POST /v1/knowledge-base/resources/documents/{id}/upload`. Returns\n404 for an unknown id or a URL-type resource.", + "summary": "Update document resource", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { @@ -17452,52 +23091,81 @@ ], "parameters": [ { - "description": "Unique identifier of the integration", "in": "path", - "name": "integrationId", + "name": "id", "required": true, "schema": { "type": "string" } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateDocumentResourceInput" + }, + "example": { + "title": "SOC 2 Type II (FY24)", + "description": "Updated annual report", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true + } + } + } + } } }, - "/integrations/{integrationId}/resource-kinds": { - "get": { - "operationId": "ListResourceKindSummaries", + "/knowledge-base/resources/documents/{id}/upload": { + "post": { + "operationId": "ReplaceDocumentResourceFile", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "items": { - "$ref": "#/components/schemas/ResourceKindSummary" - }, - "type": "array" + "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" }, "examples": { "Example 1": { - "value": [ - { - "integrationId": "asana", - "resourceKind": "AsanaAccount", - "isScopable": true, - "canUpdateDescription": true, - "canUpdateOwner": true - } - ] + "value": { + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" + } + ], + "categoryId": "507f1f77bcf86cd799439051" + } } } } } } }, - "description": "Lists a connected integration's resource types (kinds) such as S3Bucket or CloudwatchLogGroup.", - "summary": "List integration resource kinds", + "description": "Replace the underlying file on a document (FILE-type) resource with\na new multipart upload. Other resource fields (title, description,\nvisibility, tags, owner, etc.) are unchanged — use PATCH for those.\nReturns 404 for an unknown id or a URL-type resource.\n\nExample: send `multipart/form-data` with a single `file` field (the\nnew document binary).", + "summary": "Replace document resource file", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { @@ -17506,40 +23174,74 @@ ], "parameters": [ { - "description": "Unique identifier of the integration", "in": "path", - "name": "integrationId", + "name": "id", "required": true, "schema": { "type": "string" } } - ] + ], + "requestBody": { + "required": true, + "content": { + "multipart/form-data": { + "schema": { + "type": "object", + "properties": { + "file": { + "type": "string", + "format": "binary", + "description": "New document binary; replaces the existing file in place." + } + }, + "required": [ + "file" + ] + } + } + } + } } }, - "/integrations/{integrationId}/resource-kinds/{resourceKind}": { - "get": { - "operationId": "GetResourceKindDetails", + "/knowledge-base/resources/webpages": { + "post": { + "operationId": "CreateWebpageResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ResourceKindDetails" + "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" }, "examples": { "Example 1": { "value": { - "integrationId": "asana", - "resourceKind": "AsanaAccount", - "isScopable": true, - "canUpdateDescription": true, - "canUpdateOwner": true, - "numResources": 123, - "numInScope": 100, - "numOwned": 100, - "numWithDescription": 100 + "id": "507f1f77bcf86cd799439022", + "type": "URL", + "title": "Vanta Security Overview", + "description": "Public-facing overview of Vanta's security posture.", + "url": "https://www.vanta.com/security", + "customerVisibility": "PUBLIC", + "includeSubPages": true, + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-08-01T00:00:00.000Z", + "lastUpdated": "2024-11-04T13:21:55.000Z", + "lastVerified": "2024-11-04T13:21:55.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439014" + } + ], + "categoryId": "507f1f77bcf86cd799439052" } } } @@ -17547,72 +23249,82 @@ } } }, - "description": "Gets details for a specific resource type (kind) such as S3Bucket or CloudwatchLogGroup.", - "summary": "Get details for resource kind", + "description": "Create a webpage (URL-type) resource in the Trust Knowledge Base.", + "summary": "Create webpage resource", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "description": "Unique identifier of the integration.", - "in": "path", - "name": "integrationId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the integration resource kind.", - "in": "path", - "name": "resourceKind", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the integration connection.", - "in": "query", - "name": "connectionId", - "required": false, - "schema": { - "type": "string" + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateWebpageResourceInput" + }, + "example": { + "title": "Security overview", + "url": "https://www.example.com/security", + "description": "Public security page", + "customerVisibility": "PUBLIC", + "includeSubPages": true, + "isUsedInQuestionnaires": true, + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439014" + } + ], + "categoryId": "507f1f77bcf86cd799439052" + } } } - ] + } } }, - "/integrations/{integrationId}/resource-kinds/{resourceKind}/resources": { + "/knowledge-base/resources/webpages/{id}": { "patch": { - "operationId": "UpdateResources", + "operationId": "UpdateWebpageResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" }, "examples": { "Example 1": { "value": { - "results": [ - { - "id": "RESOURCE_ID", - "status": "SUCCESS" - }, + "id": "507f1f77bcf86cd799439022", + "type": "URL", + "title": "Vanta Security Overview", + "description": "Public-facing overview of Vanta's security posture.", + "url": "https://www.vanta.com/security", + "customerVisibility": "PUBLIC", + "includeSubPages": true, + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-08-01T00:00:00.000Z", + "lastUpdated": "2024-11-04T13:21:55.000Z", + "lastVerified": "2024-11-04T13:21:55.000Z", + "tags": [ { - "id": "OTHER_RESOURCE_ID", - "status": "ERROR", - "message": "Invalid Input" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439014" } - ] + ], + "categoryId": "507f1f77bcf86cd799439052" } } } @@ -17620,10 +23332,10 @@ } } }, - "description": "Updates metadata for multiple resources.", - "summary": "Update resource metadata", + "description": "Apply a partial update to a webpage (URL-type) resource. Omitted\nfields are left untouched. `description`, `ownerAssignment`, and\n`expirationDate` accept `null` to clear. The resource URL is not\nupdatable here — recreate the resource if the URL needs to change.\nReturns 404 for an unknown id or a FILE-type resource.", + "summary": "Update webpage resource", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { @@ -17632,18 +23344,8 @@ ], "parameters": [ { - "description": "Unique identifier of the integration.", - "in": "path", - "name": "integrationId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the integration resource kind.", "in": "path", - "name": "resourceKind", + "name": "id", "required": true, "schema": { "type": "string" @@ -17655,60 +23357,57 @@ "content": { "application/json": { "schema": { - "properties": { - "updates": { - "items": { - "$ref": "#/components/schemas/UpdateResourceRequest" - }, - "type": "array", - "description": "List of resource update requests.", - "minItems": 1, - "maxItems": 50 - } - }, - "required": [ - "updates" - ], - "type": "object" + "$ref": "#/components/schemas/UpdateWebpageResourceInput" + }, + "example": { + "title": "Updated security overview", + "description": "Refreshed copy", + "includeSubPages": false, + "isUsedInQuestionnaires": true } } } } - }, + } + }, + "/knowledge-base/resources/{id}": { "get": { - "operationId": "ListResources", + "operationId": "GetKnowledgeBaseResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_AnyResource_" + "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "responseType": "Resource", - "resourceKind": "AsanaTask", - "resourceId": "5e7400d77a8e3731ab2d5c8e", - "connectionId": "62ffd6793ef7978318baefa8", - "displayName": "My Security Task", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-06T19:02:25.202Z" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "YXBvbGxv", - "endCursor": "YXBvbGxv" + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ + { + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - } + ], + "categoryId": "507f1f77bcf86cd799439051" } } } @@ -17716,10 +23415,10 @@ } } }, - "description": "Lists resources for a specific integration and resource type (kind) such as S3Bucket or CloudwatchLogGroup.", - "summary": "List resources", + "description": "Fetch a single Knowledge Base resource (FILE or URL) by id. Returns\nthe same `type`-discriminated union as the list endpoint, so callers\ncan branch on `type` without knowing the kind ahead of time. Returns\n404 when the resource does not exist in the domain or — for FILE\nrows — when the underlying uploaded document has been deleted.", + "summary": "Get Knowledge Base resource", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { @@ -17728,90 +23427,26 @@ ], "parameters": [ { - "description": "Unique identifier of the integration.", - "in": "path", - "name": "integrationId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the integration resource type.", "in": "path", - "name": "resourceKind", + "name": "id", "required": true, "schema": { "type": "string" } - }, - { - "description": "Unique identifier of the integration connection.", - "in": "query", - "name": "connectionId", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Filter resources that have a description.\nIf omitted, this will return resources both with and without a description.", - "in": "query", - "name": "hasDescription", - "required": false, - "schema": { - "type": "boolean" - } - }, - { - "description": "Filter resources that have an owner.\nIf omitted, this will return resources both with and without an owner.", - "in": "query", - "name": "hasOwner", - "required": false, - "schema": { - "type": "boolean" - } - }, - { - "description": "Filter resources that are in scope.\nIf omitted, this will return resources both in and out of scope.", - "in": "query", - "name": "isInScope", - "required": false, - "schema": { - "type": "boolean" - } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } } ] - } - }, - "/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}": { - "patch": { - "operationId": "UpdateResource", + }, + "delete": { + "operationId": "DeleteKnowledgeBaseResource", "responses": { "204": { "description": "No content" } }, - "description": "Updates metadata for a specific resource such as an S3Bucket or CloudwatchLogGroup.", - "summary": "Update resource metadata", + "description": "Hard-delete a Knowledge Base resource (FILE or URL) by id. Tears down\nthe row plus its associated state (uploaded document for FILE rows,\nTrust Center references, Oso facts, chunk-store entries) via\n .\n\nReturns 404 when the id is unknown in the calling token's domain.", + "summary": "Delete Knowledge Base resource", "tags": [ - "Integrations" + "Knowledge Base" ], "security": [ { @@ -17820,238 +23455,148 @@ ], "parameters": [ { - "description": "Unique identifier of the integration.", - "in": "path", - "name": "integrationId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the integration resource kind.", - "in": "path", - "name": "resourceKind", - "required": true, - "schema": { - "type": "string" - } - }, - { - "description": "Unique identifier of the resource.", "in": "path", - "name": "resourceId", + "name": "id", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "properties": { - "inScope": { - "type": "boolean", - "description": "Determines whether resources should be marked as in scope." - }, - "description": { - "type": "string", - "description": "Description to update for the resources." - }, - "ownerId": { - "type": "string", - "description": "Owner ID to update for the resources." - } - }, - "type": "object" - } - } - } - } - }, - "get": { - "operationId": "GetResource", + ] + } + }, + "/knowledge-base/resources/{id}/verify": { + "post": { + "operationId": "VerifyKnowledgeBaseResource", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/AnyResource" + "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" }, "examples": { "Example 1": { "value": { - "responseType": "Resource", - "resourceKind": "AsanaTask", - "resourceId": "5e7400d77a8e3731ab2d5c8e", - "connectionId": "62ffd6793ef7978318baefa8", - "displayName": "My Security Task", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-06T19:02:25.202Z" - } - }, - "Example 2": { - "value": { - "responseType": "Account", - "resourceKind": "AsanaAccount", - "resourceId": "5e7400d77a8e3731ab2d5c8e", - "connectionId": "62ffd6793ef7978318baefa8", - "displayName": "Vlad's Account", - "owner": "5e56b1e0188626620a828894", - "inScope": true, - "description": null, - "creationDate": "2024-03-06T19:02:25.202Z", - "accountName": "vlads_account", - "roles": [ - "admin" - ], - "groups": [ - "admin" - ], - "isDeactivated": false, - "isMfaEnabled": null - } - }, - "Example 3": { - "value": { - "responseType": "Account", - "resourceKind": "AwsAccount", - "resourceId": "5e7400d77a8e3731ab2d5c8e", - "connectionId": "62ffd6793ef7978318baefa8", - "displayName": "Vlad's AWS Account", - "owner": "5e56b1e0188626620a828894", - "inScope": true, - "description": null, - "creationDate": "2024-03-06T19:02:25.202Z", - "accountName": "vlads_aws_account", - "roles": [ - "admin" - ], - "groups": [ - "admin" - ], - "isDeactivated": false, - "isMfaEnabled": true, - "awsUserAccountId": "ABCD1234567890", - "awsAccountNumber": "123456789012", - "accessKeys": [ - { - "accessKeyId": "EXMAPLEKEY1", - "status": "Active" - }, + "id": "507f1f77bcf86cd799439021", + "type": "FILE", + "title": "SOC 2 Type II Report", + "description": "Annual SOC 2 Type II report covering 2024.", + "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", + "customerVisibility": "REQUEST_ACCESS", + "downloadPermission": "VIEW_AND_DOWNLOAD", + "isUsedInQuestionnaires": true, + "ownerAssignment": { + "type": "User", + "id": "507f1f77bcf86cd799439041", + "displayName": "Alex Rivera" + }, + "expirationStatus": "CURRENT", + "expirationDate": "2025-12-31T00:00:00.000Z", + "lastUpdated": "2024-12-15T17:42:11.000Z", + "lastVerified": "2024-12-20T09:00:00.000Z", + "tags": [ { - "accessKeyId": "EXAMPLEKEY2", - "status": "Inactive" + "categoryId": "507f1f77bcf86cd799439011", + "tagId": "507f1f77bcf86cd799439013" } - ] - } - }, - "Example 4": { - "value": { - "responseType": "Database", - "resourceKind": "DocumentDBCluster", - "resourceId": "661095bd5397b9c17793c420", - "connectionId": "661095bd5397b9c17793c41d", - "displayName": "document-db-cluster", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-27T00:56:20.483Z", - "account": "aws-account", - "areBackupsEnabled": true, - "isEncrypted": true, - "containsEphi": null, - "containsUserData": null - } - }, - "Example 5": { - "value": { - "responseType": "Device", - "resourceKind": "JamfManagedComputer", - "resourceId": "661092077f68e200f850eb6a", - "connectionId": "661092077f68e200f850eb67", - "displayName": "jamf-managed-computer", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-27T00:56:20.483Z", - "operatingSystemName": "windows", - "isEncrypted": true, - "containsEphi": true, - "containsUserData": true - } - }, - "Example 6": { - "value": { - "responseType": "PaaS", - "resourceKind": "DigitalOceanApp", - "resourceId": "66108f3890aac655f7d957ae", - "connectionId": "66108f3890aac655f7d957ab", - "displayName": "digital-ocean-app", - "owner": null, - "inScope": true, - "description": "digital ocean paas app", - "creationDate": "2024-03-27T00:56:20.483Z", - "containsEphi": null, - "containsUserData": null - } - }, - "Example 7": { - "value": { - "responseType": "Queue", - "resourceKind": "SQS", - "resourceId": "6611eafe02a95ea7f943962f", - "connectionId": "6611eafe02a95ea7f943962c", - "displayName": "aws-resource", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-27T00:56:20.483Z", - "account": "aws-account", - "region": "us-east-1", - "containsEphi": null, - "containsUserData": null - } - }, - "Example 8": { - "value": { - "responseType": "StorageBucket", - "resourceKind": "S3", - "resourceId": "6611ec449e231114e49ef91b", - "connectionId": "6611ec449e231114e49ef918", - "displayName": "aws-resource", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-27T00:56:20.483Z", - "account": "aws-account", - "region": "", - "isEncrypted": true, - "isVersioned": true, - "containsEphi": null, - "containsUserData": null + ], + "categoryId": "507f1f77bcf86cd799439051" } - }, - "Example 9": { + } + } + } + } + } + }, + "description": "Mark a Knowledge Base resource (FILE or URL) as verified. Stamps\n`lastVerifiedAt` to the current time and resets `expiresAt` forward\nby the domain's configured review cadence; the resource's content\n(title, description, file or url, tags, owner) is left unchanged.\nCaller does not need to know the resource type — the persisted\n`resourceType` is used. Returns 404 when the id is unknown in the\ndomain or — for FILE rows — when the underlying uploaded document\nhas been deleted.", + "summary": "Verify Knowledge Base resource", + "tags": [ + "Knowledge Base" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/VerifyKnowledgeBaseResourceInput" + }, + "example": { + "expirationDate": "2025-12-31T00:00:00.000Z" + } + } + } + } + } + }, + "/monitored-computers": { + "get": { + "operationId": "ListMonitoredComputers", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_MonitoredComputer_" + }, + "examples": { + "Example 1": { "value": { - "responseType": "ContainerRepository", - "resourceKind": "ECRContainerRepository", - "resourceId": "661303e12990509c5874a7b9", - "connectionId": "661303e12990509c5874a7b6", - "displayName": "aws-resource", - "owner": null, - "inScope": true, - "description": null, - "creationDate": "2024-03-27T00:56:20.483Z", - "account": "aws-account", - "region": "us-east-1", - "isAutoscanEnabled": true + "results": { + "data": [ + { + "id": "5f2c939a52855e725c8d5823", + "integrationId": "vantaAgent", + "serialNumber": "FVFGPGV2Q6L5", + "udid": "280FF071-1D7A-5752-BD3A-1A68937CD187", + "lastCheckDate": "2024-03-07T18:46:05.944Z", + "screenlock": { + "outcome": "FAIL" + }, + "diskEncryption": { + "outcome": "FAIL" + }, + "passwordManager": { + "outcome": "FAIL" + }, + "antivirusInstallation": { + "outcome": "FAIL" + }, + "operatingSystem": { + "type": "macOS", + "version": "13.2.1" + }, + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + } + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "5f2c939a52855e725c8d5823", + "endCursor": "5f2c939a52855e725c8d5823" + } + } } } } @@ -18059,10 +23604,10 @@ } } }, - "description": "Gets resource by its ID.", - "summary": "Get resource by ID", + "description": "Returns a list of computers monitored by an MDM (with an integration built\nby Vanta) or by Vanta Device Monitor. Currently this list does not include\nresources from partner or customer-built integrations.", + "summary": "List monitored computers", "tags": [ - "Integrations" + "Monitored Computers" ], "security": [ { @@ -18071,27 +23616,97 @@ ], "parameters": [ { - "description": "Unique identifier of the integration.", - "in": "path", - "name": "integrationId", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageSize" } }, { - "description": "Unique identifier of the integration resource kind.", - "in": "path", - "name": "resourceKind", - "required": true, + "in": "query", + "name": "pageCursor", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageCursor" } }, { - "description": "Unique identifier of the resource.", + "description": "Filters for monitored computers matching any status declared in the filter.", + "in": "query", + "name": "complianceStatusFilterMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/ComputerStatusFilter" + } + } + } + ] + } + }, + "/monitored-computers/{computerId}": { + "get": { + "operationId": "GetMonitoredComputer", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/MonitoredComputer" + }, + "examples": { + "Example 1": { + "value": { + "id": "5f2c939a52855e725c8d5823", + "integrationId": "vantaAgent", + "serialNumber": "FVFGPGV2Q6L5", + "udid": "280FF071-1D7A-5752-BD3A-1A68937CD187", + "lastCheckDate": "2024-03-07T18:46:05.944Z", + "screenlock": { + "outcome": "FAIL" + }, + "diskEncryption": { + "outcome": "FAIL" + }, + "passwordManager": { + "outcome": "FAIL" + }, + "antivirusInstallation": { + "outcome": "FAIL" + }, + "operatingSystem": { + "type": "macOS", + "version": "13.2.1" + }, + "owner": { + "id": "65e1efde08e8478f143a8ff9", + "emailAddress": "example-person@email.com", + "displayName": "Example Owner" + } + } + } + } + } + } + } + }, + "description": "Returns a monitored computer by ID.", + "summary": "Get monitored computer by ID", + "tags": [ + "Monitored Computers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { "in": "path", - "name": "resourceId", + "name": "computerId", "required": true, "schema": { "type": "string" @@ -18100,16 +23715,16 @@ ] } }, - "/knowledge-base/answer-library": { + "/people": { "get": { - "operationId": "ListAnswerLibraryEntries", + "operationId": "ListPeople", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_KnowledgeBaseAnswerLibraryEntryOutput_" + "$ref": "#/components/schemas/PaginatedResponse_Person_" }, "examples": { "Example 1": { @@ -18117,29 +23732,162 @@ "results": { "data": [ { - "id": "507f1f77bcf86cd799439031", - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationStatus": "CURRENT", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-10-12T16:08:42.000Z", - "lastVerified": "2024-12-01T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } } - ] + } } ], "pageInfo": { "hasNextPage": false, - "hasPreviousPage": false + "hasPreviousPage": false, + "startCursor": "65e1efde08e8478f143a8ff9", + "endCursor": "65e1efde08e8478f143a8ff9" } } } @@ -18149,10 +23897,10 @@ } } }, - "description": "List Answer Library entries. Supports full-text search, tag filtering\n(OR across the given tags), and date-range filters on last-updated and\nexpiration.", - "summary": "List Answer Library entries", + "description": "Returns a list of all people.", + "summary": "List people", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18177,90 +23925,97 @@ } }, { - "description": "Full-text search across question and answer.", + "description": "Filter individuals by those whose tasksSummary status is any of the provided values.", "in": "query", - "name": "q", + "name": "tasksSummaryStatusMatchesAny", "required": false, "schema": { - "type": "string" + "type": "array", + "items": { + "$ref": "#/components/schemas/TasksSummaryStatus" + } } }, { - "description": "Only include entries updated at or after this ISO 8601 timestamp.", + "description": "Requires taskStatusMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny\nis any of the provided taskStatus values in taskStatusMatchesAny.", "in": "query", - "name": "lastUpdatedAfter", + "name": "taskTypeMatchesAny", "required": false, "schema": { - "type": "string" + "type": "array", + "items": { + "$ref": "#/components/schemas/TaskType" + } } }, { - "description": "Only include entries updated at or before this ISO 8601 timestamp.", + "description": "Requires taskTypeMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny\nis any of the provided taskStatus values in taskStatusMatchesAny.", "in": "query", - "name": "lastUpdatedBefore", + "name": "taskStatusMatchesAny", "required": false, "schema": { - "type": "string" + "type": "array", + "items": { + "$ref": "#/components/schemas/TaskStatus" + } } }, { - "description": "JSON-encoded array of `{categoryId, tagId}` pairs. Entries matching any\nof the given tags are returned (OR filter). Discover valid `categoryId`\nand `tagId` values via `GET /v1/customer-trust/tag-categories` (to list\ncategories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}`\n(to list tags within a category).", + "description": "Filter people by email address, first name, or last name (partial match, case-insensitive).", "in": "query", - "name": "matchesTags", + "name": "emailAndNameFilter", "required": false, "schema": { "type": "string" } }, { - "description": "Only include entries expiring at or before this ISO 8601 timestamp.", + "description": "Filter people matching any of the given group IDs.", "in": "query", - "name": "expiresBefore", + "name": "groupIdsMatchesAny", "required": false, "schema": { - "type": "string" + "type": "array", + "items": { + "type": "string" + } } }, { - "description": "Only include entries expiring at or after this ISO 8601 timestamp.", + "description": "Filter people matching the given employment status.", "in": "query", - "name": "expiresAfter", + "name": "employmentStatus", "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/EmploymentStatus" } } ] - }, + } + }, + "/people/mark-as-not-people": { "post": { - "operationId": "CreateAnswerLibraryEntry", + "operationId": "MarkAsNotPeople", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439031", - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationStatus": "CURRENT", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-10-12T16:08:42.000Z", - "lastVerified": "2024-12-01T09:00:00.000Z", - "tags": [ + "results": [ { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "id": "65e1efde08e8478f143a8ff9", + "status": "SUCCESS" + }, + { + "id": "OTHER_USER_ID", + "status": "ERROR", + "message": "Invalid Input" } ] } @@ -18270,10 +24025,10 @@ } } }, - "description": "Create an Answer Library entry.", - "summary": "Create Answer Library entry", + "description": "Mark a set of accounts on the People Page as \"not a person.\" As a result,\nthese accounts will not be treated as people in Vanta, and you will not be able to\nassign them tasks or use them in tests related to your company's personnel.", + "summary": "Mark as not people", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18286,58 +24041,64 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CreateAnswerLibraryEntryInput" - }, - "example": { - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041" - }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "properties": { + "updates": { + "items": { + "properties": { + "reason": { + "type": "string", + "description": "Reason for making this change." + }, + "id": { + "type": "string", + "description": "ID of the person to change" + } + }, + "required": [ + "reason", + "id" + ], + "type": "object" + }, + "type": "array", + "description": "List of account IDs to mark as not a person", + "minItems": 1, + "maxItems": 100 } - ] + }, + "required": [ + "updates" + ], + "type": "object" } } } } } }, - "/knowledge-base/answer-library/{id}": { - "get": { - "operationId": "GetAnswerLibraryEntry", + "/people/mark-as-people": { + "post": { + "operationId": "MarkAsPeople", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439031", - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationStatus": "CURRENT", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-10-12T16:08:42.000Z", - "lastVerified": "2024-12-01T09:00:00.000Z", - "tags": [ + "results": [ { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "id": "65e1efde08e8478f143a8ff9", + "status": "SUCCESS" + }, + { + "id": "OTHER_USER_ID", + "status": "ERROR", + "message": "Invalid Input" } ] } @@ -18347,56 +24108,75 @@ } } }, - "description": "Get an Answer Library entry.", - "summary": "Get Answer Library entry", + "description": "Mark a set of accounts on the People Page as \"people.\" As a result,\nthese accounts will be treated as people in Vanta, and you will be able to\nassign them tasks and use them in tests related to your company's personnel.", + "summary": "Mark as people", "tags": [ - "Knowledge Base" + "People" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "id", - "required": true, - "schema": { - "type": "string" + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "properties": { + "updates": { + "items": { + "properties": { + "id": { + "type": "string", + "description": "ID of the person to change" + } + }, + "required": [ + "id" + ], + "type": "object" + }, + "type": "array", + "description": "List of account IDs to mark as a person", + "minItems": 1, + "maxItems": 100 + } + }, + "required": [ + "updates" + ], + "type": "object" + } } } - ] - }, - "patch": { - "operationId": "UpdateAnswerLibraryEntryRoute", + } + } + }, + "/people/offboard": { + "post": { + "operationId": "OffboardPeople", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + "$ref": "#/components/schemas/BulkResponse" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439031", - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationStatus": "CURRENT", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-10-12T16:08:42.000Z", - "lastVerified": "2024-12-01T09:00:00.000Z", - "tags": [ + "results": [ { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "id": "65e1efde08e8478f143a8ff9", + "status": "SUCCESS" + }, + { + "id": "OTHER_USER_ID", + "status": "ERROR", + "message": "Invalid Input" } ] } @@ -18406,108 +24186,220 @@ } } }, - "description": "Update an Answer Library entry.", - "summary": "Update Answer Library entry", + "description": "Offboard a list of people. A person is only eligible for offboarding completion when:\n1. They are an ex-employee.\n2. All of the person's monitored accounts are deactivated or manually overwritten as such.\n3. All of a person's custom offboarding tasks have been completed.\nAll of the person's unmonitored accounts will be automatically marked as deactivated when they\nare offboarded. If the person has unfinished offboarding tasks those will NOT automatically be\ncompleted and offboarding them will fail.", + "summary": "Offboard people", "tags": [ - "Knowledge Base" + "People" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "id", - "required": true, - "schema": { - "type": "string" - } - } - ], + "parameters": [], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/UpdateAnswerLibraryEntryInput" - }, - "example": { - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationDate": "2025-12-31T00:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "properties": { + "updates": { + "items": { + "properties": { + "acknowledgerId": { + "type": "string", + "description": "ID of the person who will be recorded as completing the offboarding for these people" + }, + "id": { + "type": "string", + "description": "ID of the person to offboard" + } + }, + "required": [ + "acknowledgerId", + "id" + ], + "type": "object" + }, + "type": "array", + "description": "List of the people to offboard.", + "minItems": 1, + "maxItems": 1000 } - ] + }, + "required": [ + "updates" + ], + "type": "object" } } } } - }, - "delete": { - "operationId": "DeleteAnswerLibraryEntryRoute", - "responses": { - "204": { - "description": "Answer library entry deleted" - } - }, - "description": "Delete an Answer Library entry.", - "summary": "Delete Answer Library entry", - "tags": [ - "Knowledge Base" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "id", - "required": true, - "schema": { - "type": "string" - } - } - ] } }, - "/knowledge-base/answer-library/{id}/verify": { - "post": { - "operationId": "VerifyAnswerLibraryEntryRoute", + "/people/{personId}": { + "get": { + "operationId": "GetPerson", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseAnswerLibraryEntryOutput" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439031", - "question": "Do you encrypt customer data at rest?", - "answer": "Yes. All customer data is encrypted at rest using AES-256, with keys managed in AWS KMS.", - "expirationStatus": "CURRENT", - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" }, - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-10-12T16:08:42.000Z", - "lastVerified": "2024-12-01T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } } - ] + } } } } @@ -18515,10 +24407,10 @@ } } }, - "description": "Mark an Answer Library entry as verified. Stamps `lastVerifiedAt` to the\ncurrent time; the entry's question, answer, tags, owner, and expiration\nare left unchanged.", - "summary": "Verify Answer Library entry", + "description": "Returns a person by ID.", + "summary": "Get person by ID", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18528,100 +24420,174 @@ "parameters": [ { "in": "path", - "name": "id", + "name": "personId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": false, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/VerifyAnswerLibraryEntryInput" - }, - "example": { - "expirationDate": "2025-12-31T00:00:00.000Z" - } - } - } - } - } - }, - "/knowledge-base/resources": { - "get": { - "operationId": "ListKnowledgeBaseResources", + ] + }, + "patch": { + "operationId": "UpdatePerson", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_TrustKnowledgeBaseResourceOutput_" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" + }, + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ + "incompleteTrainings": [ { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "name": "Security training 1" + }, + { + "name": "Security training 2" } ], - "categoryId": "507f1f77bcf86cd799439051" + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] }, - { - "id": "507f1f77bcf86cd799439022", - "type": "URL", - "title": "Vanta Security Overview", - "description": "Public-facing overview of Vanta's security posture.", - "url": "https://www.vanta.com/security", - "customerVisibility": "PUBLIC", - "includeSubPages": true, - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-08-01T00:00:00.000Z", - "lastUpdated": "2024-11-04T13:21:55.000Z", - "lastVerified": "2024-11-04T13:21:55.000Z", - "tags": [ + "incompleteCustomTasks": [ { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439014" + "name": "Custom task 1" + }, + { + "name": "Custom task 2" } ], - "categoryId": "507f1f77bcf86cd799439052" + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false } } } @@ -18631,10 +24597,10 @@ } } }, - "description": "List Knowledge Base resources (documents and webpages) in a single\npaginated response. Each entry is a discriminated union on `type` —\n\"FILE\" entries carry a `fileUrl` (presigned S3 URL, valid for one\nhour), \"URL\" entries carry the resource's `url` and `includeSubPages`.\n\nSupports full-text search, type filtering, tag filtering (OR within\na category, AND across categories), and date-range filters on\nlast-updated and expiration.", - "summary": "List Knowledge Base resources", + "description": "Update a person's basic information.", + "summary": "Update person metadata", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18643,243 +24609,215 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "description": "Full-text search across resource titles.", - "in": "query", - "name": "q", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Filter to FILE and/or URL resources. Repeat the param to allow either.", - "in": "query", - "name": "typeMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/KnowledgeBaseResourceTypeFilter" - } - } - }, - { - "description": "Only include resources updated at or after this ISO 8601 timestamp.", - "in": "query", - "name": "lastUpdatedAfter", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Only include resources updated at or before this ISO 8601 timestamp.", - "in": "query", - "name": "lastUpdatedBefore", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "JSON-encoded array of `{categoryId, tagId}` pairs. Tags within the\nsame category are OR'd together; tags across different categories\nare AND'd. For example, passing two tags from \"Framework\" and one\ntag from \"Region\" matches resources that have either of the two\nframeworks AND the given region. Discover valid `categoryId` and\n`tagId` values via `GET /v1/customer-trust/tag-categories` (to list\ncategories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}`\n(to list tags within a category).", - "in": "query", - "name": "matchesTags", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Only include resources expiring at or before this ISO 8601 timestamp.", - "in": "query", - "name": "expiresBefore", - "required": false, - "schema": { - "type": "string" - } - }, - { - "description": "Only include resources expiring at or after this ISO 8601 timestamp.", - "in": "query", - "name": "expiresAfter", - "required": false, + "in": "path", + "name": "personId", + "required": true, "schema": { "type": "string" } } - ] - } - }, - "/knowledge-base/resources/documents": { - "post": { - "operationId": "CreateDocumentResource", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" - } - ], - "categoryId": "507f1f77bcf86cd799439051" - } - } - } - } - } - } - }, - "description": "Create a document (FILE-type) resource in the Trust Knowledge Base.\nAccepts the document as a multipart/form-data upload.\n\nExample: send `multipart/form-data` with a required `file` (e.g. PDF)\nand `title`; optional fields include `description`, `customerVisibility`,\n`downloadPermission`, `isUsedInQuestionnaires` (\"true\"/\"false\"),\n`expirationDate` (ISO 8601), `tags` (JSON array string), `categoryId`,\nand `ownerAssignment` (JSON object string).", - "summary": "Create document resource", - "tags": [ - "Knowledge Base" - ], - "security": [ - { - "bearerAuth": [] - } ], - "parameters": [], "requestBody": { "required": true, "content": { - "multipart/form-data": { + "application/json": { "schema": { - "type": "object", "properties": { - "file": { - "type": "string", - "format": "binary" - }, - "title": { - "type": "string", - "minLength": 1, - "description": "Title of the document resource." - }, - "description": { - "type": "string", - "description": "Description of the document resource." - }, - "ownerAssignment": { - "type": "string", - "description": "Owner to assign as a JSON string: {\"type\":\"User\",\"id\":\"\"}." - }, - "customerVisibility": { - "type": "string", - "description": "Customer visibility on the Trust Center: PRIVATE | SHAREABLE | REQUEST_ACCESS | PUBLIC." - }, - "downloadPermission": { - "type": "string", - "description": "Trust Center download permission: VIEW_ONLY | VIEW_AND_DOWNLOAD." - }, - "isUsedInQuestionnaires": { - "type": "string", - "description": "Whether to use this resource for Questionnaire Automation answer generation (\"true\" / \"false\")." - }, - "expirationDate": { - "type": "string", - "description": "Expiration date in ISO 8601." - }, - "tags": { - "type": "string", - "description": "Tags as a JSON array: [{\"categoryId\":\"\",\"tagId\":\"\"}]." + "name": { + "properties": { + "last": { + "type": "string" + }, + "first": { + "type": "string" + } + }, + "required": [ + "last", + "first" + ], + "type": "object" }, - "categoryId": { - "type": "string", - "description": "Trust Center category id to associate this resource with. Only\napplied when `customerVisibility` is `REQUEST_ACCESS` or `PUBLIC`;\nother visibilities don't place the resource on the Trust Center, so\nthe category is ignored. Pass an unknown id to fall back to\nuncategorized." + "employment": { + "properties": { + "startDate": { + "type": "string", + "format": "date-time" + } + }, + "type": "object" } }, - "required": [ - "file", - "title" - ] + "type": "object" } } } } } }, - "/knowledge-base/resources/documents/{id}": { - "patch": { - "operationId": "UpdateDocumentResource", + "/people/{personId}/clear-leave": { + "post": { + "operationId": "ClearLeaveForPerson", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" - } + "leaveInfo": null, + "groupIds": [ + "5f2c939a52855e725c8d5824" ], - "categoryId": "507f1f77bcf86cd799439051" + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } + }, + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } + } + } } } } @@ -18887,10 +24825,10 @@ } } }, - "description": "Apply a partial update to a document (FILE-type) resource. Omitted\nfields are left untouched. To swap the underlying file, use\n`POST /v1/knowledge-base/resources/documents/{id}/upload`. Returns\n404 for an unknown id or a URL-type resource.", - "summary": "Update document resource", + "description": "Remove leave information on a person. The person will become active in Vanta, and will be considered in certain tests related to personnel.", + "summary": "Remove leave information", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18900,69 +24838,182 @@ "parameters": [ { "in": "path", - "name": "id", + "name": "personId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/UpdateDocumentResourceInput" - }, - "example": { - "title": "SOC 2 Type II (FY24)", - "description": "Updated annual report", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true - } - } - } - } + ] } }, - "/knowledge-base/resources/documents/{id}/upload": { + "/people/{personId}/set-leave": { "post": { - "operationId": "ReplaceDocumentResourceFile", + "operationId": "SetLeaveForPerson", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseDocumentResourceOutput" + "$ref": "#/components/schemas/Person" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "65e1efde08e8478f143a8ff9", + "userId": "65e1efde08e8478f143a9001", + "emailAddress": "example-person@email.com", + "employment": { + "endDate": null, + "jobTitle": "Customer success manager", + "startDate": "2021-01-01T00:00:00.000Z", + "status": "CURRENT" + }, + "groupIds": [ + "5f2c939a52855e725c8d5824" + ], + "name": { + "display": "Example Person", + "last": "Person", + "first": "Example" + }, + "sources": { + "emailAddress": { + "integrationId": "gsuiteadmin", + "resourceId": "660c701d3d344e660b032306", + "type": "INTEGRATION" + }, + "employment": { + "startDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + }, + "endDate": { + "integrationId": "gusto", + "resourceId": "660c70783d344e660b032323", + "type": "INTEGRATION" + } + } }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" + "tasksSummary": { + "completionDate": null, + "dueDate": "2021-12-01T00:00:00.000Z", + "status": "OVERDUE", + "details": { + "completeTrainings": { + "taskType": "COMPLETE_TRAININGS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Training Vanta tests have been disabled for this person" + }, + "incompleteTrainings": [ + { + "name": "Security training 1" + }, + { + "name": "Security training 2" + } + ], + "completedTrainings": [ + { + "name": "Security training 3" + }, + { + "name": "Security training 4" + } + ] + }, + "acceptPolicies": { + "taskType": "ACCEPT_POLICIES", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "unacceptedPolicies": [ + { + "name": "Policy 1" + }, + { + "name": "Policy 2" + } + ], + "acceptedPolicies": [ + { + "name": "Policy 3" + }, + { + "name": "Policy 4" + } + ] + }, + "completeCustomTasks": { + "taskType": "COMPLETE_CUSTOM_TASKS", + "status": "OVERDUE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": { + "date": "2021-11-01T00:00:00.000Z", + "reason": "Custom task Vanta tests have been disabled for this person" + }, + "incompleteCustomTasks": [ + { + "name": "Custom task 1" + }, + { + "name": "Custom task 2" + } + ], + "completedCustomTasks": [ + { + "name": "Custom task 3" + }, + { + "name": "Custom task 4" + } + ] + }, + "completeOffboardingCustomTasks": { + "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null, + "incompleteCustomOffboardingTasks": [], + "completedCustomOffboardingTasks": [ + { + "name": "Custom offboarding task 1" + }, + { + "name": "Custom offboarding task 2" + } + ] + }, + "installDeviceMonitoring": { + "taskType": "INSTALL_DEVICE_MONITORING", + "status": "DUE_SOON", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": null, + "disabled": null + }, + "completeBackgroundChecks": { + "taskType": "COMPLETE_BACKGROUND_CHECKS", + "status": "COMPLETE", + "dueDate": "2021-12-01T00:00:00.000Z", + "completionDate": "2021-11-01T00:00:00.000Z", + "disabled": null + } } - ], - "categoryId": "507f1f77bcf86cd799439051" + }, + "leaveInfo": { + "startDate": "2021-01-01T00:00:00.000Z", + "endDate": null, + "status": "ACTIVE" + } } } } @@ -18970,10 +25021,10 @@ } } }, - "description": "Replace the underlying file on a document (FILE-type) resource with\na new multipart upload. Other resource fields (title, description,\nvisibility, tags, owner, etc.) are unchanged — use PATCH for those.\nReturns 404 for an unknown id or a URL-type resource.\n\nExample: send `multipart/form-data` with a single `file` field (the\nnew document binary).", - "summary": "Replace document resource file", + "description": "Set leave information on a person. A person on leave is inactive in Vanta and will not\nbe considered in certain personnel-related tests. If the person has existing leave information, it will be\ncleared and replaced.", + "summary": "Set leave information", "tags": [ - "Knowledge Base" + "People" ], "security": [ { @@ -18983,7 +25034,7 @@ "parameters": [ { "in": "path", - "name": "id", + "name": "personId", "required": true, "schema": { "type": "string" @@ -18993,63 +25044,53 @@ "requestBody": { "required": true, "content": { - "multipart/form-data": { + "application/json": { "schema": { - "type": "object", "properties": { - "file": { + "endDate": { "type": "string", - "format": "binary", - "description": "New document binary; replaces the existing file in place." + "format": "date-time", + "nullable": true, + "description": "The end date of the person's leave. If left empty, the leave is considered indefinite." + }, + "startDate": { + "type": "string", + "format": "date-time", + "description": "The start date of the person's leave." } }, "required": [ - "file" - ] + "endDate", + "startDate" + ], + "type": "object" } } } } } }, - "/knowledge-base/resources/webpages": { - "post": { - "operationId": "CreateWebpageResource", + "/personnel-notification-settings": { + "get": { + "operationId": "GetSettings", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" + "$ref": "#/components/schemas/PersonnelNotificationSettings" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439022", - "type": "URL", - "title": "Vanta Security Overview", - "description": "Public-facing overview of Vanta's security posture.", - "url": "https://www.vanta.com/security", - "customerVisibility": "PUBLIC", - "includeSubPages": true, - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-08-01T00:00:00.000Z", - "lastUpdated": "2024-11-04T13:21:55.000Z", - "lastVerified": "2024-11-04T13:21:55.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439014" - } + "enabled": true, + "employeeDigestFrequency": "WEEKLY", + "enabledChannels": [ + "EMAIL", + "SLACK" ], - "categoryId": "507f1f77bcf86cd799439052" + "nextReminderAt": "2026-08-17T09:00:00.000Z" } } } @@ -19057,82 +25098,38 @@ } } }, - "description": "Create a webpage (URL-type) resource in the Trust Knowledge Base.", - "summary": "Create webpage resource", + "description": "Returns the organization's personnel reminder and employee-digest settings.", + "summary": "Get personnel notification settings", "tags": [ - "Knowledge Base" + "Personnel Notification Settings" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/CreateWebpageResourceInput" - }, - "example": { - "title": "Security overview", - "url": "https://www.example.com/security", - "description": "Public security page", - "customerVisibility": "PUBLIC", - "includeSubPages": true, - "isUsedInQuestionnaires": true, - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439014" - } - ], - "categoryId": "507f1f77bcf86cd799439052" - } - } - } - } - } - }, - "/knowledge-base/resources/webpages/{id}": { - "patch": { - "operationId": "UpdateWebpageResource", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/KnowledgeBaseWebpageResourceOutput" - }, - "examples": { - "Example 1": { - "value": { - "id": "507f1f77bcf86cd799439022", - "type": "URL", - "title": "Vanta Security Overview", - "description": "Public-facing overview of Vanta's security posture.", - "url": "https://www.vanta.com/security", - "customerVisibility": "PUBLIC", - "includeSubPages": true, - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-08-01T00:00:00.000Z", - "lastUpdated": "2024-11-04T13:21:55.000Z", - "lastVerified": "2024-11-04T13:21:55.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439014" - } + "parameters": [] + }, + "patch": { + "operationId": "UpdateSettings", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PersonnelNotificationSettings" + }, + "examples": { + "Example 1": { + "value": { + "enabled": true, + "employeeDigestFrequency": "WEEKLY", + "enabledChannels": [ + "EMAIL", + "SLACK" ], - "categoryId": "507f1f77bcf86cd799439052" + "nextReminderAt": "2026-08-17T09:00:00.000Z" } } } @@ -19140,82 +25137,73 @@ } } }, - "description": "Apply a partial update to a webpage (URL-type) resource. Omitted\nfields are left untouched. `description`, `ownerAssignment`, and\n`expirationDate` accept `null` to clear. The resource URL is not\nupdatable here — recreate the resource if the URL needs to change.\nReturns 404 for an unknown id or a FILE-type resource.", - "summary": "Update webpage resource", + "description": "Partially updates the organization's personnel reminder and employee-digest settings.\nOmitted fields remain unchanged.", + "summary": "Update personnel notification settings", "tags": [ - "Knowledge Base" + "Personnel Notification Settings" ], "security": [ { "bearerAuth": [] } ], - "parameters": [ - { - "in": "path", - "name": "id", - "required": true, - "schema": { - "type": "string" - } - } - ], + "parameters": [], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/UpdateWebpageResourceInput" - }, - "example": { - "title": "Updated security overview", - "description": "Refreshed copy", - "includeSubPages": false, - "isUsedInQuestionnaires": true + "$ref": "#/components/schemas/UpdatePersonnelNotificationSettingsInput" } } } } } }, - "/knowledge-base/resources/{id}": { + "/policies": { "get": { - "operationId": "GetKnowledgeBaseResource", + "operationId": "ListPolicies", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" + "$ref": "#/components/schemas/PaginatedResponse_Policy_" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" - }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" - } - ], - "categoryId": "507f1f77bcf86cd799439051" + "results": { + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=" + }, + "data": [ + { + "id": "code-of-conduct-bsi", + "name": "Code of Conduct", + "description": "Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.", + "status": "OK", + "approvedAtDate": "2024-01-15T10:30:00.000Z", + "latestVersion": { + "status": "APPROVED" + }, + "latestApprovedVersion": { + "versionId": "65f1a8b2c3d4e5f60718293a", + "documents": [ + { + "language": "EN", + "slugId": "a1b2c3d4e5f6g7h8i9j0k1l2", + "url": "https://app.vanta.com/c/my-domain/doc/Policy-a1b2c3d4e5f6g7h8i9j0k1l2" + } + ] + } + } + ] + } } } } @@ -19223,10 +25211,10 @@ } } }, - "description": "Fetch a single Knowledge Base resource (FILE or URL) by id. Returns\nthe same `type`-discriminated union as the list endpoint, so callers\ncan branch on `type` without knowing the kind ahead of time. Returns\n404 when the resource does not exist in the domain or — for FILE\nrows — when the underlying uploaded document has been deleted.", - "summary": "Get Knowledge Base resource", + "description": "Lists all policies.", + "summary": "List policies", "tags": [ - "Knowledge Base" + "Policies" ], "security": [ { @@ -19235,82 +25223,56 @@ ], "parameters": [ { - "in": "path", - "name": "id", - "required": true, + "in": "query", + "name": "pageSize", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageSize" } - } - ] - }, - "delete": { - "operationId": "DeleteKnowledgeBaseResource", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Hard-delete a Knowledge Base resource (FILE or URL) by id. Tears down\nthe row plus its associated state (uploaded document for FILE rows,\nTrust Center references, Oso facts, chunk-store entries) via\n .\n\nReturns 404 when the id is unknown in the calling token's domain.", - "summary": "Delete Knowledge Base resource", - "tags": [ - "Knowledge Base" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ + }, { - "in": "path", - "name": "id", - "required": true, + "in": "query", + "name": "pageCursor", + "required": false, "schema": { - "type": "string" + "$ref": "#/components/schemas/PageCursor" } } ] } }, - "/knowledge-base/resources/{id}/verify": { - "post": { - "operationId": "VerifyKnowledgeBaseResource", + "/policies/{policyId}": { + "get": { + "operationId": "GetPolicy", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustKnowledgeBaseResourceOutput" + "$ref": "#/components/schemas/Policy" }, "examples": { "Example 1": { "value": { - "id": "507f1f77bcf86cd799439021", - "type": "FILE", - "title": "SOC 2 Type II Report", - "description": "Annual SOC 2 Type II report covering 2024.", - "fileUrl": "https://vanta-uploaded-documents.s3.amazonaws.com/507f1f77bcf86cd799439021?X-Amz-Expires=3600&X-Amz-Signature=...", - "customerVisibility": "REQUEST_ACCESS", - "downloadPermission": "VIEW_AND_DOWNLOAD", - "isUsedInQuestionnaires": true, - "ownerAssignment": { - "type": "User", - "id": "507f1f77bcf86cd799439041", - "displayName": "Alex Rivera" + "id": "code-of-conduct-bsi", + "name": "Code of Conduct", + "description": "Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.", + "status": "OK", + "approvedAtDate": "2024-01-15T10:30:00.000Z", + "latestVersion": { + "status": "APPROVED" }, - "expirationStatus": "CURRENT", - "expirationDate": "2025-12-31T00:00:00.000Z", - "lastUpdated": "2024-12-15T17:42:11.000Z", - "lastVerified": "2024-12-20T09:00:00.000Z", - "tags": [ - { - "categoryId": "507f1f77bcf86cd799439011", - "tagId": "507f1f77bcf86cd799439013" - } - ], - "categoryId": "507f1f77bcf86cd799439051" + "latestApprovedVersion": { + "versionId": "65f1a8b2c3d4e5f60718293a", + "documents": [ + { + "language": "EN", + "slugId": "a1b2c3d4e5f6g7h8i9j0k1l2", + "url": "https://app.vanta.com/c/my-domain/doc/Policy-a1b2c3d4e5f6g7h8i9j0k1l2" + } + ] + } } } } @@ -19318,10 +25280,10 @@ } } }, - "description": "Mark a Knowledge Base resource (FILE or URL) as verified. Stamps\n`lastVerifiedAt` to the current time and resets `expiresAt` forward\nby the domain's configured review cadence; the resource's content\n(title, description, file or url, tags, owner) is left unchanged.\nCaller does not need to know the resource type — the persisted\n`resourceType` is used. Returns 404 when the id is unknown in the\ndomain or — for FILE rows — when the underlying uploaded document\nhas been deleted.", - "summary": "Verify Knowledge Base resource", + "description": "Gets a policy by ID. Policy IDs can be found in Vanta in URL bar after /policies/.", + "summary": "Get policy by ID", "tags": [ - "Knowledge Base" + "Policies" ], "security": [ { @@ -19331,78 +25293,43 @@ "parameters": [ { "in": "path", - "name": "id", + "name": "policyId", "required": true, "schema": { "type": "string" - } - } - ], - "requestBody": { - "required": false, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/VerifyKnowledgeBaseResourceInput" - }, - "example": { - "expirationDate": "2025-12-31T00:00:00.000Z" - } - } + }, + "example": "code-of-conduct-bsi" } - } - } - }, - "/monitored-computers": { - "get": { - "operationId": "ListMonitoredComputers", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/PaginatedResponse_MonitoredComputer_" - }, - "examples": { - "Example 1": { - "value": { - "results": { - "data": [ - { - "id": "5f2c939a52855e725c8d5823", - "integrationId": "vantaAgent", - "serialNumber": "FVFGPGV2Q6L5", - "udid": "280FF071-1D7A-5752-BD3A-1A68937CD187", - "lastCheckDate": "2024-03-07T18:46:05.944Z", - "screenlock": { - "outcome": "FAIL" - }, - "diskEncryption": { - "outcome": "FAIL" - }, - "passwordManager": { - "outcome": "FAIL" - }, - "antivirusInstallation": { - "outcome": "FAIL" - }, - "operatingSystem": { - "type": "macOS", - "version": "13.2.1" - }, - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - } + ] + } + }, + "/program-scopes": { + "get": { + "operationId": "ListProgramScopes", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_ProgramScope_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "6a1c939a52855e725c8d5824", + "businessUnitId": "5f2c939a52855e725c8d5824", + "frameworkId": "soc2" } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "5f2c939a52855e725c8d5823", - "endCursor": "5f2c939a52855e725c8d5823" + "startCursor": "NmExYzkzOWE1Mjg1NWU3MjVjOGQ1ODI0", + "endCursor": "NmExYzkzOWE1Mjg1NWU3MjVjOGQ1ODI0" } } } @@ -19412,10 +25339,10 @@ } } }, - "description": "Returns a list of computers monitored by an MDM (with an integration built\nby Vanta) or by Vanta Device Monitor. Currently this list does not include\nresources from partner or customer-built integrations.", - "summary": "List monitored computers", + "description": "Lists the program scopes for your organization. A program scope pairs a\nbusiness unit with a framework that business unit is in scope for.\nWhen business unit scoping is disabled, businessUnitId is null.", + "summary": "List program scopes", "tags": [ - "Monitored Computers" + "Program Scopes" ], "security": [ { @@ -19440,60 +25367,53 @@ } }, { - "description": "Filters for monitored computers matching any status declared in the filter.", "in": "query", - "name": "complianceStatusFilterMatchesAny", + "name": "businessUnitIdMatchesAny", "required": false, "schema": { "type": "array", "items": { - "$ref": "#/components/schemas/ComputerStatusFilter" + "type": "string" } - } + }, + "example": [ + "5f2c939a52855e725c8d5824" + ] + }, + { + "in": "query", + "name": "frameworkIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + }, + "example": [ + "soc2" + ] } ] } }, - "/monitored-computers/{computerId}": { + "/program-scopes/{programScopeId}": { "get": { - "operationId": "GetMonitoredComputer", + "operationId": "GetProgramScope", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/MonitoredComputer" + "$ref": "#/components/schemas/ProgramScope" }, "examples": { "Example 1": { "value": { - "id": "5f2c939a52855e725c8d5823", - "integrationId": "vantaAgent", - "serialNumber": "FVFGPGV2Q6L5", - "udid": "280FF071-1D7A-5752-BD3A-1A68937CD187", - "lastCheckDate": "2024-03-07T18:46:05.944Z", - "screenlock": { - "outcome": "FAIL" - }, - "diskEncryption": { - "outcome": "FAIL" - }, - "passwordManager": { - "outcome": "FAIL" - }, - "antivirusInstallation": { - "outcome": "FAIL" - }, - "operatingSystem": { - "type": "macOS", - "version": "13.2.1" - }, - "owner": { - "id": "65e1efde08e8478f143a8ff9", - "emailAddress": "example-person@email.com", - "displayName": "Example Owner" - } + "id": "6a1c939a52855e725c8d5824", + "businessUnitId": "5f2c939a52855e725c8d5824", + "frameworkId": "soc2" } } } @@ -19501,10 +25421,10 @@ } } }, - "description": "Returns a monitored computer by ID.", - "summary": "Get monitored computer by ID", + "description": "Get a program scope by ID.\nWhen business unit scoping is disabled, businessUnitId is null.", + "summary": "Get program scope by ID", "tags": [ - "Monitored Computers" + "Program Scopes" ], "security": [ { @@ -19514,7 +25434,7 @@ "parameters": [ { "in": "path", - "name": "computerId", + "name": "programScopeId", "required": true, "schema": { "type": "string" @@ -19523,16 +25443,16 @@ ] } }, - "/people": { + "/risk-scenarios": { "get": { - "operationId": "ListPeople", + "operationId": "ListRiskScenario", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Person_" + "$ref": "#/components/schemas/PaginatedResponse_RiskScenario_" }, "examples": { "Example 1": { @@ -19540,162 +25460,66 @@ "results": { "data": [ { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ + { + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null - } + { + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" } - } + ] } ], "pageInfo": { "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "65e1efde08e8478f143a8ff9", - "endCursor": "65e1efde08e8478f143a8ff9" + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "1" } } } @@ -19705,10 +25529,10 @@ } } }, - "description": "Returns a list of all people.", - "summary": "List people", + "description": "List risk scenarios.", + "summary": "List risk scenarios", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { @@ -19733,97 +25557,395 @@ } }, { - "description": "Filter individuals by those whose tasksSummary status is any of the provided values.", "in": "query", - "name": "tasksSummaryStatusMatchesAny", + "name": "includeIgnored", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "description": "Use \"No owner\" to filter scenarios without owner assigned.", + "in": "query", + "name": "ownerMatchesAny", "required": false, "schema": { "type": "array", "items": { - "$ref": "#/components/schemas/TasksSummaryStatus" + "type": "string" } } }, { - "description": "Requires taskStatusMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny\nis any of the provided taskStatus values in taskStatusMatchesAny.", "in": "query", - "name": "taskTypeMatchesAny", + "name": "searchString", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Use \"Uncategorized\" to filter scenarios without any category.", + "in": "query", + "name": "categoryMatchesAny", "required": false, "schema": { "type": "array", "items": { - "$ref": "#/components/schemas/TaskType" + "type": "string" } } }, { - "description": "Requires taskTypeMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny\nis any of the provided taskStatus values in taskStatusMatchesAny.", + "description": "Use \"Uncategorized\" to filter scenarios with none of Confidentiality, Integrity or Availability assigned.", "in": "query", - "name": "taskStatusMatchesAny", + "name": "ciaCategoryMatchesAny", "required": false, "schema": { "type": "array", "items": { - "$ref": "#/components/schemas/TaskStatus" + "anyOf": [ + { + "$ref": "#/components/schemas/CIA" + }, + { + "$ref": "#/components/schemas/UNCATEGORIZED" + } + ] } } }, { - "description": "Filter people by email address, first name, or last name (partial match, case-insensitive).", + "description": "Use \"No treatment type\" to filter scenarios without treatment specified.", "in": "query", - "name": "emailAndNameFilter", + "name": "treatmentTypeMatchesAny", "required": false, "schema": { - "type": "string" + "type": "array", + "items": { + "anyOf": [ + { + "$ref": "#/components/schemas/Treatment" + }, + { + "$ref": "#/components/schemas/NO_TREATMENT_TYPE" + } + ] + } } }, { - "description": "Filter people matching any of the given group IDs.", "in": "query", - "name": "groupIdsMatchesAny", + "name": "inherentScoreGroupMatchesAny", "required": false, "schema": { "type": "array", "items": { - "type": "string" + "$ref": "#/components/schemas/ScoreGroup" } } }, { - "description": "Filter people matching the given employment status.", "in": "query", - "name": "employmentStatus", + "name": "residualScoreGroupMatchesAny", "required": false, "schema": { - "$ref": "#/components/schemas/EmploymentStatus" + "type": "array", + "items": { + "$ref": "#/components/schemas/ScoreGroup" + } + } + }, + { + "in": "query", + "name": "reviewStatusMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/ReviewStatus" + } + } + }, + { + "description": "Filter by risk scenario type. Defaults to \"Risk Scenario\".\nOnly returns enterprise risks when explicitly set to \"Enterprise Risk\".", + "in": "query", + "name": "type", + "required": false, + "schema": { + "$ref": "#/components/schemas/RiskScenarioType" + } + }, + { + "description": "Default to order by description alphabetically.", + "in": "query", + "name": "orderBy", + "required": false, + "schema": { + "type": "string", + "enum": [ + "description", + "createdAt" + ] + } + } + ] + }, + "post": { + "operationId": "CreateRiskScenario", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/RiskScenario" + }, + "examples": { + "Example 1": { + "value": { + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" + ], + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ + { + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null + }, + { + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + } + ] + } + } + } + } + } + } + }, + "description": "Create a new risk scenario.", + "summary": "Create risk scenario", + "tags": [ + "Risk Scenarios" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/CreateRiskScenarioInput" + } + } + } + } + } + }, + "/risk-scenarios/{riskScenarioId}": { + "get": { + "operationId": "GetRiskScenario", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/RiskScenario" + }, + "examples": { + "Example 1": { + "value": { + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" + ], + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ + { + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null + }, + { + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + } + ] + } + } + } + } + } + } + }, + "description": "Get a risk scenario by ID (can be the Risk ID or the object ID).", + "summary": "Get risk scenario by ID", + "tags": [ + "Risk Scenarios" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" } } ] - } - }, - "/people/mark-as-not-people": { - "post": { - "operationId": "MarkAsNotPeople", + }, + "patch": { + "operationId": "UpdateRiskScenario", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/RiskScenario" }, "examples": { "Example 1": { "value": { - "results": [ + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" + ], + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ { - "id": "65e1efde08e8478f143a8ff9", - "status": "SUCCESS" + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null }, { - "id": "OTHER_USER_ID", - "status": "ERROR", - "message": "Invalid Input" + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" } ] } @@ -19833,80 +25955,103 @@ } } }, - "description": "Mark a set of accounts on the People Page as \"not a person.\" As a result,\nthese accounts will not be treated as people in Vanta, and you will not be able to\nassign them tasks or use them in tests related to your company's personnel.", - "summary": "Mark as not people", + "description": "Update a risk scenario.", + "summary": "Update risk scenario", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + } + ], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "properties": { - "updates": { - "items": { - "properties": { - "reason": { - "type": "string", - "description": "Reason for making this change." - }, - "id": { - "type": "string", - "description": "ID of the person to change" - } - }, - "required": [ - "reason", - "id" - ], - "type": "object" - }, - "type": "array", - "description": "List of account IDs to mark as not a person", - "minItems": 1, - "maxItems": 100 - } - }, - "required": [ - "updates" - ], - "type": "object" + "$ref": "#/components/schemas/UpdateRiskScenarioInput" } } } } } }, - "/people/mark-as-people": { + "/risk-scenarios/{riskScenarioId}/cancel-approval-request": { "post": { - "operationId": "MarkAsPeople", + "operationId": "CancelRiskScenarioApprovalRequest", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/RiskScenario" }, "examples": { "Example 1": { "value": { - "results": [ + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" + ], + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ { - "id": "65e1efde08e8478f143a8ff9", - "status": "SUCCESS" + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null }, { - "id": "OTHER_USER_ID", - "status": "ERROR", - "message": "Invalid Input" + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" } ] } @@ -19916,77 +26061,119 @@ } } }, - "description": "Mark a set of accounts on the People Page as \"people.\" As a result,\nthese accounts will be treated as people in Vanta, and you will be able to\nassign them tasks and use them in tests related to your company's personnel.", - "summary": "Mark as people", + "description": "Cancel approval request for a risk scenario.", + "summary": "Cancel risk scenario approval request", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "properties": { - "updates": { - "items": { - "properties": { - "id": { - "type": "string", - "description": "ID of the person to change" - } - }, - "required": [ - "id" - ], - "type": "object" - }, - "type": "array", - "description": "List of account IDs to mark as a person", - "minItems": 1, - "maxItems": 100 - } - }, - "required": [ - "updates" - ], - "type": "object" - } + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" } } - } + ] } }, - "/people/offboard": { - "post": { - "operationId": "OffboardPeople", + "/risk-scenarios/{riskScenarioId}/controls": { + "get": { + "operationId": "ListRiskScenarioControls", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/BulkResponse" + "$ref": "#/components/schemas/PaginatedResponse_RiskScenarioControl_" }, "examples": { "Example 1": { "value": { - "results": [ - { - "id": "65e1efde08e8478f143a8ff9", - "status": "SUCCESS" - }, - { - "id": "OTHER_USER_ID", - "status": "ERROR", - "message": "Invalid Input" + "results": { + "data": [ + { + "controlId": "A.12.2.1", + "controlType": "TREATMENT_PLAN" + }, + { + "controlId": "5f3a1c8b9d4e2f6a7b8c9d11", + "controlType": "EXISTING" + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "1", + "endCursor": "2" } - ] + } + } + } + } + } + } + } + }, + "description": "List the controls associated with a risk scenario.\n\nEach item is a `{ controlId, controlType }` relationship. `controlType` is\n`TREATMENT_PLAN` for controls that are part of the risk's treatment plan,\nand `EXISTING` for controls linked without a treatment-plan designation.", + "summary": "List risk scenario controls", + "tags": [ + "Risk Scenarios" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + }, + "post": { + "operationId": "CreateRiskScenarioControl", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/RiskScenarioControl" + }, + "examples": { + "Example 1": { + "value": { + "controlId": "A.12.2.1", + "controlType": "TREATMENT_PLAN" } } } @@ -19994,220 +26181,54 @@ } } }, - "description": "Offboard a list of people. A person is only eligible for offboarding completion when:\n1. They are an ex-employee.\n2. All of the person's monitored accounts are deactivated or manually overwritten as such.\n3. All of a person's custom offboarding tasks have been completed.\nAll of the person's unmonitored accounts will be automatically marked as deactivated when they\nare offboarded. If the person has unfinished offboarding tasks those will NOT automatically be\ncompleted and offboarding them will fail.", - "summary": "Offboard people", + "description": "Associate a control with a risk scenario.\n\nBody: `{ controlId, controlType? }`. `controlType` is `TREATMENT_PLAN`\nfor a control that is part of the risk's treatment plan; omit it (or pass\n`EXISTING`) to associate the control as a plain existing control.\n\n`controlId` may be a Vanta control shorthand, custom-control shorthand,\nor object ID; it resolves to a single canonical control before any write.\n\nBehavior on conflict with an existing association:\n- Same resolved control already associated with the same `controlType`:\n\n the request is a no-op and the existing relationship is returned (200).\n- Same resolved control associated with the other `controlType`: the\n\n request is rejected with a hint to use `PATCH` instead (422).", + "summary": "Add a control to a risk scenario", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + } + ], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "properties": { - "updates": { - "items": { - "properties": { - "acknowledgerId": { - "type": "string", - "description": "ID of the person who will be recorded as completing the offboarding for these people" - }, - "id": { - "type": "string", - "description": "ID of the person to offboard" - } - }, - "required": [ - "acknowledgerId", - "id" - ], - "type": "object" - }, - "type": "array", - "description": "List of the people to offboard.", - "minItems": 1, - "maxItems": 1000 - } - }, - "required": [ - "updates" - ], - "type": "object" + "$ref": "#/components/schemas/CreateRiskScenarioControlInput" } } } } } }, - "/people/{personId}": { - "get": { - "operationId": "GetPerson", + "/risk-scenarios/{riskScenarioId}/controls/{controlId}": { + "patch": { + "operationId": "UpdateRiskScenarioControl", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Person" + "$ref": "#/components/schemas/RiskScenarioControl" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" - }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null - } - } - } + "controlId": "A.12.2.1", + "controlType": "TREATMENT_PLAN" } } } @@ -20215,10 +26236,56 @@ } } }, - "description": "Returns a person by ID.", - "summary": "Get person by ID", + "description": "Change the `controlType` on an existing risk-scenario / control\nassociation.\n\nBody: `{ controlType }`. The server atomically moves the resolved control\nbetween the treatment-plan and existing-control sets in a single update —\nthere is no intermediate unlinked state. `PATCH { \"controlType\": \"EXISTING\" }`\nremoves the control from the treatment plan but keeps it linked as an\nexisting control; use `DELETE` to unlink it entirely.\n\nReturns 404 if the control is not currently associated with the scenario.\nSetting the `controlType` it already has is a 200 no-op.", + "summary": "Change a risk scenario control's controlType", + "tags": [ + "Risk Scenarios" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateRiskScenarioControlInput" + } + } + } + } + }, + "delete": { + "operationId": "DeleteRiskScenarioControl", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Remove a control from a risk scenario.\n\nFully unlinks the control regardless of whether it is currently a\n`TREATMENT_PLAN` or an `EXISTING` control. To only drop the\ntreatment-plan designation while keeping the control linked, use\n`PATCH { \"controlType\": \"EXISTING\" }` instead. Deleting an already-unlinked\ncontrol is an idempotent no-op (204).", + "summary": "Remove a control from a risk scenario", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { @@ -20228,176 +26295,90 @@ "parameters": [ { "in": "path", - "name": "personId", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "controlId", "required": true, "schema": { "type": "string" } } ] - }, - "patch": { - "operationId": "UpdatePerson", + } + }, + "/risk-scenarios/{riskScenarioId}/submit-for-approval": { + "post": { + "operationId": "SubmitRiskForApproval", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Person" + "$ref": "#/components/schemas/RiskScenario" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" + "riskId": "assets-not-identified-and-protected", + "description": "Assets are not identified and protected according to company requirements.", + "detailedDescription": null, + "isSensitive": false, + "likelihood": 4, + "impact": 4, + "residualLikelihood": 2, + "residualImpact": 1, + "categories": [ + "Access control" ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" + "ciaCategories": [ + "Confidentiality" + ], + "treatment": "Avoid", + "owner": null, + "note": null, + "riskRegister": "Default", + "customFields": [], + "isArchived": false, + "reviewStatus": "DRAFT", + "requiredApprovers": [], + "type": "Risk Scenario", + "identificationDate": "2024-03-07T18:46:05.944Z", + "scoreBreakdown": [ + { + "id": "inherent-risk", + "kind": "SCORE", + "name": "Inherent risk", + "score": 16, + "status": null, + "scoreLabel": "High", + "parentId": null }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null - } + { + "id": "impact", + "kind": "DIMENSION", + "name": "Impact", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" + }, + { + "id": "likelihood", + "kind": "DIMENSION", + "name": "Likelihood", + "score": 4, + "status": "SCORED", + "scoreLabel": "High", + "parentId": "inherent-risk" } - } + ] } } } @@ -20405,226 +26386,90 @@ } } }, - "description": "Update a person's basic information.", - "summary": "Update person metadata", + "description": "Submit a risk scenario for approval.", + "summary": "Submit risk scenario for approval", "tags": [ - "People" + "Risk Scenarios" ], "security": [ { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "personId", - "required": true, - "schema": { - "type": "string" - } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "properties": { - "name": { - "properties": { - "last": { - "type": "string" - }, - "first": { - "type": "string" - } - }, - "required": [ - "last", - "first" - ], - "type": "object" - }, - "employment": { - "properties": { - "startDate": { - "type": "string", - "format": "date-time" - } - }, - "type": "object" - } - }, - "type": "object" + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "riskScenarioId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/SubmitRiskForApprovalInput" } } } } } }, - "/people/{personId}/clear-leave": { - "post": { - "operationId": "ClearLeaveForPerson", + "/tests": { + "get": { + "operationId": "ListTests", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Person" + "$ref": "#/components/schemas/PaginatedResponse_Test_" }, "examples": { "Example 1": { "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "leaveInfo": null, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" + "results": { + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=" }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" + "data": [ + { + "id": "aws-account-access-removed-on-termination", + "name": "AWS accounts deprovisioned when personnel leave", + "lastTestRunDate": "2024-06-18T20:17:38.463Z", + "latestFlipDate": null, + "description": "Verifies that AWS accounts linked to removed users are removed.\n", + "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", + "remediationDescription": "Remove all accounts listed from AWS.\n", + "version": { + "major": 0, + "minor": 0 }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } + "category": "Account security", + "integrations": [ + "aws" ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" + "status": "OK", + "deactivatedStatusInfo": { + "isDeactivated": false, + "deactivatedReason": null, + "lastUpdatedDate": null }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null + "remediationStatusInfo": { + "status": "PASS", + "soonestRemediateByDate": null, + "itemCount": 0 + }, + "owner": null } - } + ] } } } @@ -20633,10 +26478,151 @@ } } }, - "description": "Remove leave information on a person. The person will become active in Vanta, and will be considered in certain tests related to personnel.", - "summary": "Remove leave information", + "description": "Lists all tests based on applied filters.", + "summary": "List tests", + "tags": [ + "Tests" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Filter tests by test status.\nPossible values: OK (Test passed), DEACTIVATED (Test is deactivated), NEEDS_ATTENTION (Test failed), IN_PROGRESS (Test is in progress), INVALID (Test is invalid), NOT_APPLICABLE (Test is not applicable)", + "in": "query", + "name": "statusFilter", + "required": false, + "schema": { + "$ref": "#/components/schemas/TestStatus" + } + }, + { + "description": "Filter tests by framework.", + "in": "query", + "name": "frameworkFilter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter tests by integration.", + "in": "query", + "name": "integrationFilter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter tests by control ID.", + "in": "query", + "name": "controlFilter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter tests by owner ID.", + "in": "query", + "name": "ownerFilter", + "required": false, + "schema": { + "type": "string" + } + }, + { + "description": "Filter tests by category.", + "in": "query", + "name": "categoryFilter", + "required": false, + "schema": { + "$ref": "#/components/schemas/TestCategory" + } + }, + { + "description": "Filter tests by rollout status.\nA test in rollout is an upcoming test that does not have its history tracked yet.", + "in": "query", + "name": "isInRollout", + "required": false, + "schema": { + "type": "boolean" + } + } + ] + } + }, + "/tests/{testId}": { + "get": { + "operationId": "GetTest", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/Test" + }, + "examples": { + "Example 1": { + "value": { + "id": "aws-account-access-removed-on-termination", + "name": "AWS accounts deprovisioned when personnel leave", + "lastTestRunDate": "2024-06-18T20:17:38.463Z", + "latestFlipDate": null, + "description": "Verifies that AWS accounts linked to removed users are removed.\n", + "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", + "remediationDescription": "Remove all accounts listed from AWS.\n", + "version": { + "major": 0, + "minor": 0 + }, + "category": "Account security", + "integrations": [ + "aws" + ], + "status": "OK", + "deactivatedStatusInfo": { + "isDeactivated": false, + "deactivatedReason": null, + "lastUpdatedDate": null + }, + "remediationStatusInfo": { + "status": "PASS", + "soonestRemediateByDate": null, + "itemCount": 0 + }, + "owner": null + } + } + } + } + } + } + }, + "description": "Gets a test by ID. Test IDs can be found in Vanta in URL bar after /tests/.", + "summary": "Get test by ID", "tags": [ - "People" + "Tests" ], "security": [ { @@ -20646,181 +26632,48 @@ "parameters": [ { "in": "path", - "name": "personId", + "name": "testId", "required": true, "schema": { "type": "string" - } + }, + "example": "aws-account-access-removed-on-termination" } ] } }, - "/people/{personId}/set-leave": { - "post": { - "operationId": "SetLeaveForPerson", + "/tests/{testId}/entities": { + "get": { + "operationId": "GetTestEntities", "responses": { "200": { "description": "Ok", "content": { "application/json": { - "schema": { - "$ref": "#/components/schemas/Person" - }, - "examples": { - "Example 1": { - "value": { - "id": "65e1efde08e8478f143a8ff9", - "userId": "65e1efde08e8478f143a9001", - "emailAddress": "example-person@email.com", - "employment": { - "endDate": null, - "jobTitle": "Customer success manager", - "startDate": "2021-01-01T00:00:00.000Z", - "status": "CURRENT" - }, - "groupIds": [ - "5f2c939a52855e725c8d5824" - ], - "name": { - "display": "Example Person", - "last": "Person", - "first": "Example" - }, - "sources": { - "emailAddress": { - "integrationId": "gsuiteadmin", - "resourceId": "660c701d3d344e660b032306", - "type": "INTEGRATION" - }, - "employment": { - "startDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - }, - "endDate": { - "integrationId": "gusto", - "resourceId": "660c70783d344e660b032323", - "type": "INTEGRATION" - } - } - }, - "tasksSummary": { - "completionDate": null, - "dueDate": "2021-12-01T00:00:00.000Z", - "status": "OVERDUE", - "details": { - "completeTrainings": { - "taskType": "COMPLETE_TRAININGS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Training Vanta tests have been disabled for this person" - }, - "incompleteTrainings": [ - { - "name": "Security training 1" - }, - { - "name": "Security training 2" - } - ], - "completedTrainings": [ - { - "name": "Security training 3" - }, - { - "name": "Security training 4" - } - ] - }, - "acceptPolicies": { - "taskType": "ACCEPT_POLICIES", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "unacceptedPolicies": [ - { - "name": "Policy 1" - }, - { - "name": "Policy 2" - } - ], - "acceptedPolicies": [ - { - "name": "Policy 3" - }, - { - "name": "Policy 4" - } - ] - }, - "completeCustomTasks": { - "taskType": "COMPLETE_CUSTOM_TASKS", - "status": "OVERDUE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": { - "date": "2021-11-01T00:00:00.000Z", - "reason": "Custom task Vanta tests have been disabled for this person" - }, - "incompleteCustomTasks": [ - { - "name": "Custom task 1" - }, - { - "name": "Custom task 2" - } - ], - "completedCustomTasks": [ - { - "name": "Custom task 3" - }, - { - "name": "Custom task 4" - } - ] - }, - "completeOffboardingCustomTasks": { - "taskType": "COMPLETE_CUSTOM_OFFBOARDING_TASKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null, - "incompleteCustomOffboardingTasks": [], - "completedCustomOffboardingTasks": [ - { - "name": "Custom offboarding task 1" - }, - { - "name": "Custom offboarding task 2" - } - ] - }, - "installDeviceMonitoring": { - "taskType": "INSTALL_DEVICE_MONITORING", - "status": "DUE_SOON", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": null, - "disabled": null - }, - "completeBackgroundChecks": { - "taskType": "COMPLETE_BACKGROUND_CHECKS", - "status": "COMPLETE", - "dueDate": "2021-12-01T00:00:00.000Z", - "completionDate": "2021-11-01T00:00:00.000Z", - "disabled": null + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_TestResourceEntity_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "startCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "data": [ + { + "id": "65fc81a3359c8508c9af880f", + "entityStatus": "FAILING", + "displayName": "account-123456789012", + "responseType": "AWS account", + "deactivatedReason": null, + "lastUpdatedDate": "2024-06-18T20:17:38.463Z", + "createdDate": "2024-06-18T20:17:38.463Z" } - } - }, - "leaveInfo": { - "startDate": "2021-01-01T00:00:00.000Z", - "endDate": null, - "status": "ACTIVE" + ] } } } @@ -20829,10 +26682,10 @@ } } }, - "description": "Set leave information on a person. A person on leave is inactive in Vanta and will not\nbe considered in certain personnel-related tests. If the person has existing leave information, it will be\ncleared and replaced.", - "summary": "Set leave information", + "description": "Gets a list of tested items (entities) for a test by test ID. An entity is a tested item that can have its own outcome.\nFor example, for a test that makes sure that all S3 buckets are versioned, an individual S3 bucket would be an entity.", + "summary": "Get test entities by test ID", "tags": [ - "People" + "Tests" ], "security": [ { @@ -20842,7 +26695,72 @@ "parameters": [ { "in": "path", - "name": "personId", + "name": "testId", + "required": true, + "schema": { + "type": "string" + }, + "example": "aws-account-access-removed-on-termination" + }, + { + "description": "The status of the test entities. Defaults to FAILING.\nPossible values: FAILING, DEACTIVATED", + "in": "query", + "name": "entityStatus", + "required": false, + "schema": { + "$ref": "#/components/schemas/EntityStatus" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/tests/{testId}/entities/{entityId}/deactivate": { + "post": { + "operationId": "DeactivateTestEntity", + "responses": { + "202": { + "description": "Deactivation request accepted" + } + }, + "description": "Deactivates a single test item (test entity).\nThere may be a delay in the deactivation of the test entity until the next test run.\nUse the /vulnerabilities/deactivate endpoint for vulnerabilities.", + "summary": "Deactivate test entity", + "tags": [ + "Tests" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "testId", + "required": true, + "schema": { + "type": "string" + }, + "example": "aws-account-access-removed-on-termination" + }, + { + "in": "path", + "name": "entityId", "required": true, "schema": { "type": "string" @@ -20855,21 +26773,19 @@ "application/json": { "schema": { "properties": { - "endDate": { + "deactivateReason": { "type": "string", - "format": "date-time", - "nullable": true, - "description": "The end date of the person's leave. If left empty, the leave is considered indefinite." + "description": "Reason for deactivating the entity.", + "minLength": 1 }, - "startDate": { + "deactivateUntilDate": { "type": "string", "format": "date-time", - "description": "The start date of the person's leave." + "description": "Date until which the entity should be deactivated. If not provided, the entity will be deactivated indefinitely." } }, "required": [ - "endDate", - "startDate" + "deactivateReason" ], "type": "object" } @@ -20878,50 +26794,80 @@ } } }, - "/policies": { + "/tests/{testId}/entities/{entityId}/reactivate": { + "post": { + "operationId": "ReactivateTestEntity", + "responses": { + "202": { + "description": "Reactivation request accepted" + } + }, + "description": "Reactivates a single tested item (test entity).\nThere may be a delay in the reactivation of the test entity until the next test run.\nUse the /vulnerabilities/reactivate endpoint for vulnerabilities.", + "summary": "Reactivate test entity", + "tags": [ + "Tests" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "testId", + "required": true, + "schema": { + "type": "string" + }, + "example": "aws-account-access-removed-on-termination" + }, + { + "in": "path", + "name": "entityId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/trust-centers/{slugId}": { "get": { - "operationId": "ListPolicies", + "operationId": "GetTrustCenter", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Policy_" + "$ref": "#/components/schemas/TrustCenter" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=" - }, - "data": [ - { - "id": "code-of-conduct-bsi", - "name": "Code of Conduct", - "description": "Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.", - "status": "OK", - "approvedAtDate": "2024-01-15T10:30:00.000Z", - "latestVersion": { - "status": "APPROVED" - }, - "latestApprovedVersion": { - "versionId": "65f1a8b2c3d4e5f60718293a", - "documents": [ - { - "language": "EN", - "slugId": "a1b2c3d4e5f6g7h8i9j0k1l2", - "url": "https://app.vanta.com/c/my-domain/doc/Policy-a1b2c3d4e5f6g7h8i9j0k1l2" - } - ] - } - } - ] - } + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "title": "Trust Center", + "companyDescription": "Company description", + "privacyPolicy": "Privacy policy", + "awsMarketplaceListing": "https://aws.amazon.com/marketplace/pp/example", + "customDomain": "trustcenter.com", + "isPublic": true, + "bannerSetting": { + "setting": "GRADIENT", + "startColor": "#000000", + "endColor": "#FFFFFF" + }, + "customTheme": { + "primary": "#000000", + "secondary": "#FFFFFF" + }, + "contactEmail": "security@example.com", + "customHeading": "Welcome to our Trust Center", + "controlVisibilityMode": "SHOW_OK_ONLY", + "creationDate": "2020-01-01T00:00:00.000Z", + "updatedDate": "2020-01-01T00:00:00.000Z" } } } @@ -20929,10 +26875,10 @@ } } }, - "description": "Lists all policies.", - "summary": "List policies", + "description": "Gets a Trust Center by slug ID.", + "summary": "Get Trust Center", "tags": [ - "Policies" + "Trust Centers" ], "security": [ { @@ -20941,56 +26887,50 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, + "in": "path", + "name": "slugId", + "required": true, "schema": { - "$ref": "#/components/schemas/PageCursor" - } + "type": "string" + }, + "example": "a2f7e1b9d0c3f4e5a6c7b8d9" } ] - } - }, - "/policies/{policyId}": { - "get": { - "operationId": "GetPolicy", + }, + "patch": { + "operationId": "UpdateTrustCenter", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Policy" + "$ref": "#/components/schemas/TrustCenter" }, - "examples": { - "Example 1": { - "value": { - "id": "code-of-conduct-bsi", - "name": "Code of Conduct", - "description": "Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.", - "status": "OK", - "approvedAtDate": "2024-01-15T10:30:00.000Z", - "latestVersion": { - "status": "APPROVED" + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "title": "Trust Center", + "companyDescription": "Company description", + "privacyPolicy": "Privacy policy", + "awsMarketplaceListing": "https://aws.amazon.com/marketplace/pp/example", + "customDomain": "trustcenter.com", + "isPublic": true, + "bannerSetting": { + "setting": "GRADIENT", + "startColor": "#000000", + "endColor": "#FFFFFF" }, - "latestApprovedVersion": { - "versionId": "65f1a8b2c3d4e5f60718293a", - "documents": [ - { - "language": "EN", - "slugId": "a1b2c3d4e5f6g7h8i9j0k1l2", - "url": "https://app.vanta.com/c/my-domain/doc/Policy-a1b2c3d4e5f6g7h8i9j0k1l2" - } - ] - } + "customTheme": { + "primary": "#000000", + "secondary": "#FFFFFF" + }, + "contactEmail": "security@example.com", + "customHeading": "Welcome to our Trust Center", + "controlVisibilityMode": "SHOW_OK_ONLY", + "creationDate": "2020-01-01T00:00:00.000Z", + "updatedDate": "2020-01-01T00:00:00.000Z" } } } @@ -20998,10 +26938,10 @@ } } }, - "description": "Gets a policy by ID. Policy IDs can be found in Vanta in URL bar after /policies/.", - "summary": "Get policy by ID", + "description": "Updates a Trust Center by slug ID.", + "summary": "Update Trust Center", "tags": [ - "Policies" + "Trust Centers" ], "security": [ { @@ -21011,65 +26951,59 @@ "parameters": [ { "in": "path", - "name": "policyId", + "name": "slugId", "required": true, "schema": { "type": "string" - }, - "example": "code-of-conduct-bsi" + } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateTrustCenterInput" + } + } + } + } } }, - "/risk-scenarios": { + "/trust-centers/{slugId}/access-requests": { "get": { - "operationId": "ListRiskScenario", + "operationId": "ListTrustCenterAccessRequests", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_RiskScenario_" + "$ref": "#/components/schemas/PaginatedResponse_TrustCenterAccessRequest_" }, "examples": { "Example 1": { "value": { "results": { + "pageInfo": { + "hasNextPage": true, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, "data": [ { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "email": "exampleviewer@company.com", + "name": "Example Viewer", + "companyName": "Viewer Company, Inc.", + "reason": "I'm an existing customer", + "requestedResources": null, + "accessLevel": "FULL_ACCESS", + "creationDate": "2020-01-01T00:00:00.000Z", + "updatedDate": "2020-01-01T00:00:00.000Z" } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "1" - } + ] } } } @@ -21078,10 +27012,10 @@ } } }, - "description": "List risk scenarios.", - "summary": "List risk scenarios", + "description": "Gets a list of access requests for a Trust Center.", + "summary": "List Trust Center access requests", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21090,193 +27024,55 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "in": "query", - "name": "includeIgnored", - "required": false, - "schema": { - "type": "boolean" - } - }, - { - "description": "Use \"No owner\" to filter scenarios without owner assigned.", - "in": "query", - "name": "ownerMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } - }, - { - "in": "query", - "name": "searchString", - "required": false, + "in": "path", + "name": "slugId", + "required": true, "schema": { "type": "string" } }, { - "description": "Use \"Uncategorized\" to filter scenarios without any category.", - "in": "query", - "name": "categoryMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "type": "string" - } - } - }, - { - "description": "Use \"Uncategorized\" to filter scenarios with none of Confidentiality, Integrity or Availability assigned.", - "in": "query", - "name": "ciaCategoryMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "anyOf": [ - { - "$ref": "#/components/schemas/CIA" - }, - { - "$ref": "#/components/schemas/UNCATEGORIZED" - } - ] - } - } - }, - { - "description": "Use \"No treatment type\" to filter scenarios without treatment specified.", - "in": "query", - "name": "treatmentTypeMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "anyOf": [ - { - "$ref": "#/components/schemas/Treatment" - }, - { - "$ref": "#/components/schemas/NO_TREATMENT_TYPE" - } - ] - } - } - }, - { - "in": "query", - "name": "inherentScoreGroupMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/ScoreGroup" - } - } - }, - { - "in": "query", - "name": "residualScoreGroupMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/ScoreGroup" - } - } - }, - { - "in": "query", - "name": "reviewStatusMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/ReviewStatus" - } - } - }, - { - "description": "Filter by risk scenario type. Defaults to \"Risk Scenario\".\nOnly returns enterprise risks when explicitly set to \"Enterprise Risk\".", "in": "query", - "name": "type", + "name": "pageSize", "required": false, "schema": { - "$ref": "#/components/schemas/RiskScenarioType" + "$ref": "#/components/schemas/PageSize" } }, { - "description": "Default to order by description alphabetically.", "in": "query", - "name": "orderBy", + "name": "pageCursor", "required": false, "schema": { - "type": "string", - "enum": [ - "description", - "createdAt" - ] + "$ref": "#/components/schemas/PageCursor" } } ] - }, - "post": { - "operationId": "CreateRiskScenario", + } + }, + "/trust-centers/{slugId}/access-requests/{accessRequestId}": { + "get": { + "operationId": "GetTrustCenterAccessRequest", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenario" + "$ref": "#/components/schemas/TrustCenterAccessRequest" }, "examples": { "Example 1": { "value": { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "email": "exampleviewer@company.com", + "name": "Example Viewer", + "companyName": "Viewer Company, Inc.", + "reason": "I'm an existing customer", + "requestedResources": null, + "accessLevel": "FULL_ACCESS", + "creationDate": "2020-01-01T00:00:00.000Z", + "updatedDate": "2020-01-01T00:00:00.000Z" } } } @@ -21284,67 +27080,168 @@ } } }, - "description": "Create a new risk scenario.", - "summary": "Create risk scenario", + "description": "Gets a specific access request for a Trust Center.", + "summary": "Get Trust Center access request", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { "bearerAuth": [] } ], - "parameters": [], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "accessRequestId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/trust-centers/{slugId}/access-requests/{accessRequestId}/approve": { + "post": { + "operationId": "ApproveTrustCenterAccessRequest", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Approves an access request on a Trust Center.", + "summary": "Approve Trust Center access request", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "accessRequestId", + "required": true, + "schema": { + "type": "string" + } + } + ], "requestBody": { "required": true, "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CreateRiskScenarioInput" + "$ref": "#/components/schemas/ApproveTrustCenterAccessRequestInput" } } } } } }, - "/risk-scenarios/{riskScenarioId}": { + "/trust-centers/{slugId}/access-requests/{accessRequestId}/deny": { + "post": { + "operationId": "DenyTrustCenterAccessRequest", + "responses": { + "204": { + "description": "No content" + } + }, + "description": "Denies an access request on a Trust Center. The requester is only notified\nby email when `sendEmail` is true.", + "summary": "Deny Trust Center access request", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "accessRequestId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/DenyTrustCenterAccessRequestInput" + } + } + } + } + } + }, + "/trust-centers/{slugId}/activity": { "get": { - "operationId": "GetRiskScenario", + "operationId": "ListTrustCenterActivityEvents", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenario" + "$ref": "#/components/schemas/PaginatedResponse_TrustCenterActivityEvent_" }, "examples": { "Example 1": { "value": { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "results": { + "pageInfo": { + "hasNextPage": true, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "data": [ + { + "id": "4b1e7a8c3d9f6a2b5c8d0e3f", + "date": "2020-01-01T00:00:00.000Z", + "eventType": "PAGE_VIEW", + "details": { + "page": "OVERVIEW" + }, + "viewerEmail": "exampleviewer@company.com", + "viewerId": "a2f7e1b9d0c3f4e5a6c7b8d9", + "countryCode": "US", + "city": "San Francisco" + } + ] + } } } } @@ -21352,10 +27249,10 @@ } } }, - "description": "Get a risk scenario by ID (can be the Risk ID or the object ID).", - "summary": "Get risk scenario by ID", + "description": "Gets a list of viewer activity events on a Trust Center.", + "summary": "List Trust Center viewer activity events", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21365,51 +27262,94 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "in": "query", + "name": "eventTypesMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/ActivityEventType" + } + } + }, + { + "description": "Only include activity events that occurred on or after the specified date and time.", + "in": "query", + "name": "afterDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + } + }, + { + "description": "Only include activity events that occurred before the specified date and time.", + "in": "query", + "name": "beforeDate", + "required": false, + "schema": { + "format": "date-time", + "type": "string" + } } ] - }, - "patch": { - "operationId": "UpdateRiskScenario", + } + }, + "/trust-centers/{slugId}/chatbot/conversations": { + "get": { + "operationId": "ListChatbotConversations", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenario" + "$ref": "#/components/schemas/PaginatedResponse_TrustCenterChatbotConversation_" }, "examples": { "Example 1": { "value": { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "results": { + "pageInfo": { + "hasNextPage": true, + "hasPreviousPage": false, + "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", + "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" + }, + "data": [ + { + "id": "4b1e7a8c3d9f6a2b5c8d0e3f", + "firstMessage": "What security certifications do you have?", + "numMessages": 4, + "userEmail": "viewer@company.com", + "isPublicConversation": false, + "createdAt": "2024-01-15T10:30:00.000Z" + } + ] + } } } } @@ -21417,10 +27357,10 @@ } } }, - "description": "Update a risk scenario.", - "summary": "Update risk scenario", + "description": "Gets a paginated list of chatbot conversations on a Trust Center.", + "summary": "List Trust Center chatbot conversations", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21430,63 +27370,63 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/UpdateRiskScenarioInput" - } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Search conversations by message content.", + "in": "query", + "name": "searchString", + "required": false, + "schema": { + "type": "string" } } - } + ] } }, - "/risk-scenarios/{riskScenarioId}/cancel-approval-request": { - "post": { - "operationId": "CancelRiskScenarioApprovalRequest", + "/trust-centers/{slugId}/chatbot/conversations/{conversationId}": { + "get": { + "operationId": "GetChatbotConversationMessages", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenario" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterChatbotMessage_" }, "examples": { "Example 1": { "value": { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "results": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "role": "USER", + "message": "What security certifications do you have?", + "createdAt": "2024-01-15T10:30:00.000Z", + "references": [] + } + ] } } } @@ -21494,10 +27434,10 @@ } } }, - "description": "Cancel approval request for a risk scenario.", - "summary": "Cancel risk scenario approval request", + "description": "Gets the messages for a specific chatbot conversation on a Trust Center.", + "summary": "Get Trust Center chatbot conversation messages", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21507,7 +27447,15 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "conversationId", "required": true, "schema": { "type": "string" @@ -21516,38 +27464,29 @@ ] } }, - "/risk-scenarios/{riskScenarioId}/controls": { + "/trust-centers/{slugId}/compliance-frameworks": { "get": { - "operationId": "ListRiskScenarioControls", + "operationId": "ListComplianceFrameworks", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_RiskScenarioControl_" + "$ref": "#/components/schemas/TrustCenterComplianceFrameworkListResponse" }, "examples": { "Example 1": { "value": { - "results": { - "data": [ - { - "controlId": "A.12.2.1", - "controlType": "TREATMENT_PLAN" - }, - { - "controlId": "5f3a1c8b9d4e2f6a7b8c9d11", - "controlType": "EXISTING" - } - ], - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "startCursor": "1", - "endCursor": "2" + "results": [ + { + "id": "b3c8d4e5f6a7b8c9d0e1f2a3", + "name": "SOC 2 Type II", + "standard": "soc2", + "description": "Service Organization Control 2 Type II compliance" } - } + ], + "isSectionVisible": true } } } @@ -21555,10 +27494,10 @@ } } }, - "description": "List the controls associated with a risk scenario.\n\nEach item is a `{ controlId, controlType }` relationship. `controlType` is\n`TREATMENT_PLAN` for controls that are part of the risk's treatment plan,\nand `EXISTING` for controls linked without a treatment-plan designation.", - "summary": "List risk scenario controls", + "description": "Gets the list of compliance frameworks on a Trust Center.", + "summary": "List Trust Center compliance frameworks", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21568,45 +27507,31 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } } ] }, "post": { - "operationId": "CreateRiskScenarioControl", + "operationId": "CreateComplianceFramework", "responses": { - "200": { - "description": "Ok", + "201": { + "description": "Trust Center compliance framework created", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenarioControl" + "$ref": "#/components/schemas/TrustCenterComplianceFramework" }, "examples": { "Example 1": { "value": { - "controlId": "A.12.2.1", - "controlType": "TREATMENT_PLAN" + "id": "b3c8d4e5f6a7b8c9d0e1f2a3", + "name": "SOC 2 Type II", + "standard": "soc2", + "description": "Service Organization Control 2 Type II compliance" } } } @@ -21614,10 +27539,10 @@ } } }, - "description": "Associate a control with a risk scenario.\n\nBody: `{ controlId, controlType? }`. `controlType` is `TREATMENT_PLAN`\nfor a control that is part of the risk's treatment plan; omit it (or pass\n`EXISTING`) to associate the control as a plain existing control.\n\n`controlId` may be a Vanta control shorthand, custom-control shorthand,\nor object ID; it resolves to a single canonical control before any write.\n\nBehavior on conflict with an existing association:\n- Same resolved control already associated with the same `controlType`:\n\n the request is a no-op and the existing relationship is returned (200).\n- Same resolved control associated with the other `controlType`: the\n\n request is rejected with a hint to use `PATCH` instead (422).", - "summary": "Add a control to a risk scenario", + "description": "Adds a compliance framework to a Trust Center.", + "summary": "Create Trust Center compliance framework", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21627,7 +27552,7 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" @@ -21639,29 +27564,31 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/CreateRiskScenarioControlInput" + "$ref": "#/components/schemas/CreateComplianceFrameworkInput" } } } } } }, - "/risk-scenarios/{riskScenarioId}/controls/{controlId}": { + "/trust-centers/{slugId}/compliance-frameworks/{frameworkId}": { "patch": { - "operationId": "UpdateRiskScenarioControl", + "operationId": "UpdateComplianceFramework", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/RiskScenarioControl" + "$ref": "#/components/schemas/TrustCenterComplianceFramework" }, "examples": { "Example 1": { "value": { - "controlId": "A.12.2.1", - "controlType": "TREATMENT_PLAN" + "id": "b3c8d4e5f6a7b8c9d0e1f2a3", + "name": "SOC 2 Type II", + "standard": "soc2", + "description": "Service Organization Control 2 Type II compliance" } } } @@ -21669,10 +27596,10 @@ } } }, - "description": "Change the `controlType` on an existing risk-scenario / control\nassociation.\n\nBody: `{ controlType }`. The server atomically moves the resolved control\nbetween the treatment-plan and existing-control sets in a single update —\nthere is no intermediate unlinked state. `PATCH { \"controlType\": \"EXISTING\" }`\nremoves the control from the treatment plan but keeps it linked as an\nexisting control; use `DELETE` to unlink it entirely.\n\nReturns 404 if the control is not currently associated with the scenario.\nSetting the `controlType` it already has is a 200 no-op.", - "summary": "Change a risk scenario control's controlType", + "description": "Updates a compliance framework on a Trust Center.", + "summary": "Update Trust Center compliance framework", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21682,7 +27609,7 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" @@ -21690,7 +27617,7 @@ }, { "in": "path", - "name": "controlId", + "name": "frameworkId", "required": true, "schema": { "type": "string" @@ -21702,23 +27629,23 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/UpdateRiskScenarioControlInput" + "$ref": "#/components/schemas/UpdateComplianceFrameworkInput" } } } } }, "delete": { - "operationId": "DeleteRiskScenarioControl", + "operationId": "DeleteComplianceFramework", "responses": { "204": { "description": "No content" } }, - "description": "Remove a control from a risk scenario.\n\nFully unlinks the control regardless of whether it is currently a\n`TREATMENT_PLAN` or an `EXISTING` control. To only drop the\ntreatment-plan designation while keeping the control linked, use\n`PATCH { \"controlType\": \"EXISTING\" }` instead. Deleting an already-unlinked\ncontrol is an idempotent no-op (204).", - "summary": "Remove a control from a risk scenario", + "description": "Removes a compliance framework from a Trust Center.", + "summary": "Delete Trust Center compliance framework", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21728,61 +27655,38 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", "required": true, "schema": { "type": "string" } }, { - "in": "path", - "name": "controlId", - "required": true, - "schema": { - "type": "string" - } - } - ] - } - }, - "/risk-scenarios/{riskScenarioId}/submit-for-approval": { - "post": { - "operationId": "SubmitRiskForApproval", - "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/RiskScenario" - }, - "examples": { - "Example 1": { - "value": { - "riskId": "assets-not-identified-and-protected", - "description": "Assets are not identified and protected according to company requirements.", - "detailedDescription": null, - "isSensitive": false, - "likelihood": 4, - "impact": 4, - "residualLikelihood": 2, - "residualImpact": 1, - "categories": [ - "Access control" - ], - "ciaCategories": [ - "Confidentiality" - ], - "treatment": "Avoid", - "owner": null, - "note": null, - "riskRegister": "Default", - "customFields": [], - "isArchived": false, - "reviewStatus": "DRAFT", - "requiredApprovers": [], - "type": "Risk Scenario", - "identificationDate": "2024-03-07T18:46:05.944Z" + "in": "path", + "name": "frameworkId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/trust-centers/{slugId}/compliance-frameworks/{frameworkId}/badge": { + "post": { + "operationId": "UploadComplianceFrameworkBadge", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/BadgeUploadResponse" + }, + "examples": { + "Example 1": { + "value": { + "isSuccessful": true } } } @@ -21790,10 +27694,10 @@ } } }, - "description": "Submit a risk scenario for approval.", - "summary": "Submit risk scenario for approval", + "description": "Uploads a badge image for a compliance framework on a Trust Center.", + "summary": "Upload Trust Center compliance framework badge", "tags": [ - "Risk Scenarios" + "Trust Centers" ], "security": [ { @@ -21803,7 +27707,15 @@ "parameters": [ { "in": "path", - "name": "riskScenarioId", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "frameworkId", "required": true, "schema": { "type": "string" @@ -21813,68 +27725,46 @@ "requestBody": { "required": true, "content": { - "application/json": { + "multipart/form-data": { "schema": { - "$ref": "#/components/schemas/SubmitRiskForApprovalInput" + "type": "object", + "properties": { + "file": { + "type": "string", + "format": "binary" + } + }, + "required": [ + "file" + ] } } } } } }, - "/tests": { + "/trust-centers/{slugId}/control-categories": { "get": { - "operationId": "ListTests", + "operationId": "GetTrustCenterControlCategories", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_Test_" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterControlCategory_" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=" - }, - "data": [ - { - "id": "aws-account-access-removed-on-termination", - "name": "AWS accounts deprovisioned when personnel leave", - "lastTestRunDate": "2024-06-18T20:17:38.463Z", - "latestFlipDate": null, - "description": "Verifies that AWS accounts linked to removed users are removed.\n", - "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", - "remediationDescription": "Remove all accounts listed from AWS.\n", - "version": { - "major": 0, - "minor": 0 - }, - "category": "Account security", - "integrations": [ - "aws" - ], - "status": "OK", - "deactivatedStatusInfo": { - "isDeactivated": false, - "deactivatedReason": null, - "lastUpdatedDate": null - }, - "remediationStatusInfo": { - "status": "PASS", - "soonestRemediateByDate": null, - "itemCount": 0 - }, - "owner": null - } - ] - } + "results": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] } } } @@ -21882,10 +27772,10 @@ } } }, - "description": "Lists all tests based on applied filters.", - "summary": "List tests", + "description": "Gets a list of control categories on a Trust Center.", + "summary": "List Trust Center control categories", "tags": [ - "Tests" + "Trust Centers" ], "security": [ { @@ -21894,128 +27784,93 @@ ], "parameters": [ { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "description": "Filter tests by test status.\nPossible values: OK (Test passed), DEACTIVATED (Test is deactivated), NEEDS_ATTENTION (Test failed), IN_PROGRESS (Test is in progress), INVALID (Test is invalid), NOT_APPLICABLE (Test is not applicable)", - "in": "query", - "name": "statusFilter", - "required": false, - "schema": { - "$ref": "#/components/schemas/TestStatus" - } - }, - { - "description": "Filter tests by framework.", - "in": "query", - "name": "frameworkFilter", - "required": false, + "in": "path", + "name": "slugId", + "required": true, "schema": { "type": "string" } - }, - { - "description": "Filter tests by integration.", - "in": "query", - "name": "integrationFilter", - "required": false, - "schema": { - "type": "string" + } + ] + }, + "post": { + "operationId": "AddTrustCenterControlCategory", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/TrustCenterControlCategory" + }, + "examples": { + "Example 1": { + "value": { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + } + } + } } - }, + } + }, + "description": "Adds a control category to a Trust Center.", + "summary": "Add Trust Center control category", + "tags": [ + "Trust Centers" + ], + "security": [ { - "description": "Filter tests by control ID.", - "in": "query", - "name": "controlFilter", - "required": false, - "schema": { - "type": "string" - } - }, + "bearerAuth": [] + } + ], + "parameters": [ { - "description": "Filter tests by owner ID.", - "in": "query", - "name": "ownerFilter", - "required": false, + "in": "path", + "name": "slugId", + "required": true, "schema": { "type": "string" } - }, - { - "description": "Filter tests by category.", - "in": "query", - "name": "categoryFilter", - "required": false, - "schema": { - "$ref": "#/components/schemas/TestCategory" - } - }, - { - "description": "Filter tests by rollout status.\nA test in rollout is an upcoming test that does not have its history tracked yet.", - "in": "query", - "name": "isInRollout", - "required": false, - "schema": { - "type": "boolean" + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/AddTrustCenterControlCategoryInput" + } } } - ] + } } }, - "/tests/{testId}": { - "get": { - "operationId": "GetTest", + "/trust-centers/{slugId}/control-categories/order": { + "put": { + "operationId": "UpsertTrustCenterControlCategoriesOrder", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/Test" - }, - "examples": { - "Example 1": { - "value": { - "id": "aws-account-access-removed-on-termination", - "name": "AWS accounts deprovisioned when personnel leave", - "lastTestRunDate": "2024-06-18T20:17:38.463Z", - "latestFlipDate": null, - "description": "Verifies that AWS accounts linked to removed users are removed.\n", - "failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.", - "remediationDescription": "Remove all accounts listed from AWS.\n", - "version": { - "major": 0, - "minor": 0 - }, - "category": "Account security", - "integrations": [ - "aws" - ], - "status": "OK", - "deactivatedStatusInfo": { - "isDeactivated": false, - "deactivatedReason": null, - "lastUpdatedDate": null - }, - "remediationStatusInfo": { - "status": "PASS", - "soonestRemediateByDate": null, - "itemCount": 0 - }, - "owner": null + "$ref": "#/components/schemas/ArrayResponse_TrustCenterControlCategory_" + }, + "examples": { + "Example 1": { + "value": { + "results": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] } } } @@ -22023,10 +27878,10 @@ } } }, - "description": "Gets a test by ID. Test IDs can be found in Vanta in URL bar after /tests/.", - "summary": "Get test by ID", + "description": "Reorders control categories on a Trust Center. The request body must\ncontain the complete set of category IDs in the desired order.", + "summary": "Reorder Trust Center control categories", "tags": [ - "Tests" + "Trust Centers" ], "security": [ { @@ -22036,49 +27891,43 @@ "parameters": [ { "in": "path", - "name": "testId", + "name": "slugId", "required": true, "schema": { "type": "string" - }, - "example": "aws-account-access-removed-on-termination" + } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ReorderTrustCenterControlCategoriesInput" + } + } + } + } } }, - "/tests/{testId}/entities": { + "/trust-centers/{slugId}/control-categories/{categoryId}": { "get": { - "operationId": "GetTestEntities", + "operationId": "GetTrustCenterControlCategory", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_TestResourceEntity_" + "$ref": "#/components/schemas/TrustCenterControlCategory" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": false, - "hasPreviousPage": false, - "endCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "startCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "data": [ - { - "id": "65fc81a3359c8508c9af880f", - "entityStatus": "FAILING", - "displayName": "account-123456789012", - "responseType": "AWS account", - "deactivatedReason": null, - "lastUpdatedDate": "2024-06-18T20:17:38.463Z", - "createdDate": "2024-06-18T20:17:38.463Z" - } - ] - } + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null } } } @@ -22086,10 +27935,10 @@ } } }, - "description": "Gets a list of tested items (entities) for a test by test ID. An entity is a tested item that can have its own outcome.\nFor example, for a test that makes sure that all S3 buckets are versioned, an individual S3 bucket would be an entity.", - "summary": "Get test entities by test ID", + "description": "Gets a specific control category on a Trust Center.", + "summary": "Get Trust Center control category", "tags": [ - "Tests" + "Trust Centers" ], "security": [ { @@ -22099,53 +27948,50 @@ "parameters": [ { "in": "path", - "name": "testId", + "name": "slugId", "required": true, "schema": { "type": "string" - }, - "example": "aws-account-access-removed-on-termination" - }, - { - "description": "The status of the test entities. Defaults to FAILING.\nPossible values: FAILING, DEACTIVATED", - "in": "query", - "name": "entityStatus", - "required": false, - "schema": { - "$ref": "#/components/schemas/EntityStatus" - } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" } }, { - "in": "query", - "name": "pageCursor", - "required": false, + "in": "path", + "name": "categoryId", + "required": true, "schema": { - "$ref": "#/components/schemas/PageCursor" + "type": "string" } } ] - } - }, - "/tests/{testId}/entities/{entityId}/deactivate": { - "post": { - "operationId": "DeactivateTestEntity", + }, + "patch": { + "operationId": "UpdateTrustCenterControlCategory", "responses": { - "202": { - "description": "Deactivation request accepted" + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/TrustCenterControlCategory" + }, + "examples": { + "Example 1": { + "value": { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + } + } + } + } } }, - "description": "Deactivates a single test item (test entity).\nThere may be a delay in the deactivation of the test entity until the next test run.\nUse the /vulnerabilities/deactivate endpoint for vulnerabilities.", - "summary": "Deactivate test entity", + "description": "Updates a control category on a Trust Center.", + "summary": "Update Trust Center control category", "tags": [ - "Tests" + "Trust Centers" ], "security": [ { @@ -22155,16 +28001,15 @@ "parameters": [ { "in": "path", - "name": "testId", + "name": "slugId", "required": true, "schema": { "type": "string" - }, - "example": "aws-account-access-removed-on-termination" + } }, { "in": "path", - "name": "entityId", + "name": "categoryId", "required": true, "schema": { "type": "string" @@ -22176,40 +28021,23 @@ "content": { "application/json": { "schema": { - "properties": { - "deactivateReason": { - "type": "string", - "description": "Reason for deactivating the entity.", - "minLength": 1 - }, - "deactivateUntilDate": { - "type": "string", - "format": "date-time", - "description": "Date until which the entity should be deactivated. If not provided, the entity will be deactivated indefinitely." - } - }, - "required": [ - "deactivateReason" - ], - "type": "object" + "$ref": "#/components/schemas/EditTrustCenterControlCategoryInput" } } } } - } - }, - "/tests/{testId}/entities/{entityId}/reactivate": { - "post": { - "operationId": "ReactivateTestEntity", + }, + "delete": { + "operationId": "DeleteTrustCenterControlCategory", "responses": { - "202": { - "description": "Reactivation request accepted" + "204": { + "description": "No content" } }, - "description": "Reactivates a single tested item (test entity).\nThere may be a delay in the reactivation of the test entity until the next test run.\nUse the /vulnerabilities/reactivate endpoint for vulnerabilities.", - "summary": "Reactivate test entity", + "description": "Removes a control category from a Trust Center along with all of the\ncontrols in the category.", + "summary": "Delete Trust Center control category", "tags": [ - "Tests" + "Trust Centers" ], "security": [ { @@ -22219,16 +28047,15 @@ "parameters": [ { "in": "path", - "name": "testId", + "name": "slugId", "required": true, "schema": { "type": "string" - }, - "example": "aws-account-access-removed-on-termination" + } }, { "in": "path", - "name": "entityId", + "name": "categoryId", "required": true, "schema": { "type": "string" @@ -22237,40 +28064,24 @@ ] } }, - "/trust-centers/{slugId}": { - "get": { - "operationId": "GetTrustCenter", + "/trust-centers/{slugId}/control-categories/{categoryId}/controls": { + "patch": { + "operationId": "UpdateTrustCenterControlsInCategory", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenter" + "$ref": "#/components/schemas/TrustCenterControlCategory" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "title": "Trust Center", - "companyDescription": "Company description", - "privacyPolicy": "Privacy policy", - "awsMarketplaceListing": "https://aws.amazon.com/marketplace/pp/example", - "customDomain": "trustcenter.com", - "isPublic": true, - "bannerSetting": { - "setting": "GRADIENT", - "startColor": "#000000", - "endColor": "#FFFFFF" - }, - "customTheme": { - "primary": "#000000", - "secondary": "#FFFFFF" - }, - "contactEmail": "security@example.com", - "customHeading": "Welcome to our Trust Center", - "creationDate": "2020-01-01T00:00:00.000Z", - "updatedDate": "2020-01-01T00:00:00.000Z" + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null } } } @@ -22278,8 +28089,8 @@ } } }, - "description": "Gets a Trust Center by slug ID.", - "summary": "Get Trust Center", + "description": "Bulk add or remove controls from a control category on a Trust Center.", + "summary": "Bulk edit controls in a category", "tags": [ "Trust Centers" ], @@ -22295,44 +28106,47 @@ "required": true, "schema": { "type": "string" - }, - "example": "a2f7e1b9d0c3f4e5a6c7b8d9" + } + }, + { + "in": "path", + "name": "categoryId", + "required": true, + "schema": { + "type": "string" + } } - ] - }, - "patch": { - "operationId": "UpdateTrustCenter", + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/BulkEditControlsInCategoryInput" + } + } + } + } + } + }, + "/trust-centers/{slugId}/control-categories/{categoryId}/controls/order": { + "put": { + "operationId": "UpsertTrustCenterControlsInCategoryOrder", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenter" + "$ref": "#/components/schemas/TrustCenterControlCategory" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "title": "Trust Center", - "companyDescription": "Company description", - "privacyPolicy": "Privacy policy", - "awsMarketplaceListing": "https://aws.amazon.com/marketplace/pp/example", - "customDomain": "trustcenter.com", - "isPublic": true, - "bannerSetting": { - "setting": "GRADIENT", - "startColor": "#000000", - "endColor": "#FFFFFF" - }, - "customTheme": { - "primary": "#000000", - "secondary": "#FFFFFF" - }, - "contactEmail": "security@example.com", - "customHeading": "Welcome to our Trust Center", - "creationDate": "2020-01-01T00:00:00.000Z", - "updatedDate": "2020-01-01T00:00:00.000Z" + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null } } } @@ -22340,8 +28154,8 @@ } } }, - "description": "Updates a Trust Center by slug ID.", - "summary": "Update Trust Center", + "description": "Reorders controls within a control category on a Trust Center. The\nrequest body must contain the complete set of control IDs in the\ncategory in the desired order.", + "summary": "Reorder controls in a Trust Center control category", "tags": [ "Trust Centers" ], @@ -22353,7 +28167,15 @@ "parameters": [ { "in": "path", - "name": "slugId", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "categoryId", "required": true, "schema": { "type": "string" @@ -22365,23 +28187,23 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/UpdateTrustCenterInput" + "$ref": "#/components/schemas/ReorderTrustCenterControlsInput" } } } } } }, - "/trust-centers/{slugId}/access-requests": { + "/trust-centers/{slugId}/controls": { "get": { - "operationId": "ListTrustCenterAccessRequests", + "operationId": "ListTrustCenterControls", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_TrustCenterAccessRequest_" + "$ref": "#/components/schemas/PaginatedResponse_TrustCenterControl_" }, "examples": { "Example 1": { @@ -22396,14 +28218,16 @@ "data": [ { "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "email": "exampleviewer@company.com", - "name": "Example Viewer", - "companyName": "Viewer Company, Inc.", - "reason": "I'm an existing customer", - "requestedResources": null, - "accessLevel": "FULL_ACCESS", - "creationDate": "2020-01-01T00:00:00.000Z", - "updatedDate": "2020-01-01T00:00:00.000Z" + "name": "Control name", + "description": "Control description", + "categories": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] } ] } @@ -22414,8 +28238,8 @@ } } }, - "description": "Gets a list of access requests for a Trust Center.", - "summary": "List Trust Center access requests", + "description": "Gets a list of controls on a Trust Center.", + "summary": "List Trust Center controls", "tags": [ "Trust Centers" ], @@ -22450,31 +28274,31 @@ } } ] - } - }, - "/trust-centers/{slugId}/access-requests/{accessRequestId}": { - "get": { - "operationId": "GetTrustCenterAccessRequest", + }, + "post": { + "operationId": "AddControlToTrustCenter", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenterAccessRequest" + "$ref": "#/components/schemas/TrustCenterControl" }, "examples": { "Example 1": { "value": { "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "email": "exampleviewer@company.com", - "name": "Example Viewer", - "companyName": "Viewer Company, Inc.", - "reason": "I'm an existing customer", - "requestedResources": null, - "accessLevel": "FULL_ACCESS", - "creationDate": "2020-01-01T00:00:00.000Z", - "updatedDate": "2020-01-01T00:00:00.000Z" + "name": "Control name", + "description": "Control description", + "categories": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] } } } @@ -22482,46 +28306,8 @@ } } }, - "description": "Gets a specific access request for a Trust Center.", - "summary": "Get Trust Center access request", - "tags": [ - "Trust Centers" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "slugId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "in": "path", - "name": "accessRequestId", - "required": true, - "schema": { - "type": "string" - } - } - ] - } - }, - "/trust-centers/{slugId}/access-requests/{accessRequestId}/approve": { - "post": { - "operationId": "ApproveTrustCenterAccessRequest", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Approves an access request on a Trust Center.", - "summary": "Approve Trust Center access request", + "description": "Adds a control to a Trust Center.", + "summary": "Add Trust Center control", "tags": [ "Trust Centers" ], @@ -22538,14 +28324,6 @@ "schema": { "type": "string" } - }, - { - "in": "path", - "name": "accessRequestId", - "required": true, - "schema": { - "type": "string" - } } ], "requestBody": { @@ -22553,23 +28331,51 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ApproveTrustCenterAccessRequestInput" + "$ref": "#/components/schemas/AddControlToTrustCenterInput" } } } } } }, - "/trust-centers/{slugId}/access-requests/{accessRequestId}/deny": { + "/trust-centers/{slugId}/controls/tags": { "post": { - "operationId": "DenyTrustCenterAccessRequest", + "operationId": "BulkAddTagsToControls", "responses": { - "204": { - "description": "No content" + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ArrayResponse_TrustCenterControl_" + }, + "examples": { + "Example 1": { + "value": { + "results": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "name": "Control name", + "description": "Control description", + "categories": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] + } + ] + } + } + } + } + } } }, - "description": "Denies an access request on a Trust Center.", - "summary": "Deny Trust Center access request", + "description": "Adds tags to multiple controls on a Trust Center. Limited to 100 controls per request.", + "summary": "Bulk add tags to Trust Center controls", "tags": [ "Trust Centers" ], @@ -22586,64 +28392,47 @@ "schema": { "type": "string" } - }, - { - "in": "path", - "name": "accessRequestId", - "required": true, - "schema": { - "type": "string" - } } ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/DenyTrustCenterAccessRequestInput" + "$ref": "#/components/schemas/BulkTagControlsInput" } } } } - } - }, - "/trust-centers/{slugId}/activity": { - "get": { - "operationId": "ListTrustCenterActivityEvents", + }, + "delete": { + "operationId": "BulkRemoveTagsFromControls", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_TrustCenterActivityEvent_" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterControl_" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": true, - "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "data": [ - { - "id": "4b1e7a8c3d9f6a2b5c8d0e3f", - "date": "2020-01-01T00:00:00.000Z", - "eventType": "PAGE_VIEW", - "details": { - "page": "OVERVIEW" - }, - "viewerEmail": "exampleviewer@company.com", - "viewerId": "a2f7e1b9d0c3f4e5a6c7b8d9", - "countryCode": "US", - "city": "San Francisco" - } - ] - } + "results": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "name": "Control name", + "description": "Control description", + "categories": [ + { + "id": "93d69894dd525f806d7e5c48", + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null + } + ] + } + ] } } } @@ -22651,8 +28440,8 @@ } } }, - "description": "Gets a list of viewer activity events on a Trust Center.", - "summary": "List Trust Center viewer activity events", + "description": "Removes tags from multiple controls on a Trust Center. Limited to 100 controls per request.", + "summary": "Bulk remove tags from Trust Center controls", "tags": [ "Trust Centers" ], @@ -22669,75 +28458,43 @@ "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } - }, - { - "in": "query", - "name": "eventTypesMatchesAny", - "required": false, - "schema": { - "type": "array", - "items": { - "$ref": "#/components/schemas/ActivityEventType" + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/BulkTagControlsInput" } } - }, - { - "description": "Only include activity events that occurred on or after the specified date and time.", - "in": "query", - "name": "afterDate", - "required": false, - "schema": { - "format": "date-time", - "type": "string" - } - }, - { - "description": "Only include activity events that occurred before the specified date and time.", - "in": "query", - "name": "beforeDate", - "required": false, - "schema": { - "format": "date-time", - "type": "string" - } } - ] + } } }, - "/trust-centers/{slugId}/control-categories": { + "/trust-centers/{slugId}/controls/{controlId}": { "get": { - "operationId": "GetTrustCenterControlCategories", + "operationId": "GetTrustCenterControl", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/ArrayResponse_TrustCenterControlCategory_" + "$ref": "#/components/schemas/TrustCenterControl" }, "examples": { "Example 1": { "value": { - "results": [ + "id": "a2f7e1b9d0c3f4e5a6c7b8d9", + "name": "Control name", + "description": "Control description", + "categories": [ { "id": "93d69894dd525f806d7e5c48", - "name": "Category name" + "name": "Category name", + "visibility": "PUBLIC", + "statusVisibilityOverride": null } ] } @@ -22747,8 +28504,8 @@ } } }, - "description": "Gets a list of control categories on a Trust Center.", - "summary": "List Trust Center control categories", + "description": "Gets a specific control on a Trust Center.", + "summary": "Get Trust Center control", "tags": [ "Trust Centers" ], @@ -22765,33 +28522,26 @@ "schema": { "type": "string" } + }, + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" + } } ] }, - "post": { - "operationId": "AddTrustCenterControlCategory", + "delete": { + "operationId": "DeleteTrustCenterControl", "responses": { - "200": { - "description": "Ok", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/TrustCenterControlCategory" - }, - "examples": { - "Example 1": { - "value": { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" - } - } - } - } - } + "204": { + "description": "No content" } }, - "description": "Adds a control category to a Trust Center.", - "summary": "Add Trust Center control category", + "description": "Removes a specific control from a Trust Center. This removes the control\nfrom all of the control categories that is in.", + "summary": "Delete Trust Center control", "tags": [ "Trust Centers" ], @@ -22808,36 +28558,38 @@ "schema": { "type": "string" } - } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/AddOrEditTrustCenterControlCategoryInput" - } + }, + { + "in": "path", + "name": "controlId", + "required": true, + "schema": { + "type": "string" } } - } + ] } }, - "/trust-centers/{slugId}/control-categories/{categoryId}": { + "/trust-centers/{slugId}/data-collected": { "get": { - "operationId": "GetTrustCenterControlCategory", + "operationId": "ListTrustCenterDataCollected", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenterControlCategory" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterDataCollected_" }, "examples": { "Example 1": { "value": { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" + "results": [ + { + "dataCollected": "Email Address", + "status": "COLLECTED" + } + ] } } } @@ -22845,8 +28597,8 @@ } } }, - "description": "Gets a specific control category on a Trust Center.", - "summary": "Get Trust Center control category", + "description": "Gets the list of data-collected disclosures on a Trust Center.", + "summary": "List Trust Center data collected", "tags": [ "Trust Centers" ], @@ -22863,32 +28615,28 @@ "schema": { "type": "string" } - }, - { - "in": "path", - "name": "categoryId", - "required": true, - "schema": { - "type": "string" - } } ] }, - "patch": { - "operationId": "UpdateTrustCenterControlCategory", + "put": { + "operationId": "UpsertTrustCenterDataCollected", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenterControlCategory" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterDataCollected_" }, "examples": { "Example 1": { "value": { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" + "results": [ + { + "dataCollected": "Email Address", + "status": "COLLECTED" + } + ] } } } @@ -22896,8 +28644,8 @@ } } }, - "description": "Updates a control category on a Trust Center.", - "summary": "Update Trust Center control category", + "description": "Replaces all data-collected disclosures on a Trust Center with the\nprovided list. This is a full replacement — any existing disclosures\nnot included in the request body will be removed. To add or remove a\nsingle entry, first GET the current list, modify it, then PUT the\nupdated list back.", + "summary": "Set Trust Center data collected", "tags": [ "Trust Centers" ], @@ -22914,14 +28662,6 @@ "schema": { "type": "string" } - }, - { - "in": "path", - "name": "categoryId", - "required": true, - "schema": { - "type": "string" - } } ], "requestBody": { @@ -22929,84 +28669,33 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/AddOrEditTrustCenterControlCategoryInput" + "$ref": "#/components/schemas/SetDataCollectedInput" } } } } - }, - "delete": { - "operationId": "DeleteTrustCenterControlCategory", - "responses": { - "204": { - "description": "No content" - } - }, - "description": "Removes a control category from a Trust Center along with all of the\ncontrols in the category.", - "summary": "Delete Trust Center control category", - "tags": [ - "Trust Centers" - ], - "security": [ - { - "bearerAuth": [] - } - ], - "parameters": [ - { - "in": "path", - "name": "slugId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "in": "path", - "name": "categoryId", - "required": true, - "schema": { - "type": "string" - } - } - ] } }, - "/trust-centers/{slugId}/controls": { + "/trust-centers/{slugId}/faq-categories": { "get": { - "operationId": "ListTrustCenterControls", + "operationId": "ListTrustCenterFaqCategories", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_TrustCenterControl_" + "$ref": "#/components/schemas/ArrayResponse_TrustCenterFaqCategory_" }, "examples": { "Example 1": { "value": { - "results": { - "pageInfo": { - "hasNextPage": true, - "hasPreviousPage": false, - "startCursor": "YXJyYXljb25uZWN0aW9uOjA=", - "endCursor": "YXJyYXljb25uZWN0aW9uOjE=" - }, - "data": [ - { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "name": "Control name", - "description": "Control description", - "categories": [ - { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" - } - ] - } - ] - } + "results": [ + { + "id": "71a3b8d2ef904c1a6d5e7f30", + "name": "Security" + } + ] } } } @@ -23014,8 +28703,8 @@ } } }, - "description": "Gets a list of controls on a Trust Center.", - "summary": "List Trust Center controls", + "description": "Gets a list of FAQ categories on a Trust Center.", + "summary": "List Trust Center FAQ categories", "tags": [ "Trust Centers" ], @@ -23032,47 +28721,24 @@ "schema": { "type": "string" } - }, - { - "in": "query", - "name": "pageSize", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageSize" - } - }, - { - "in": "query", - "name": "pageCursor", - "required": false, - "schema": { - "$ref": "#/components/schemas/PageCursor" - } } ] }, "post": { - "operationId": "AddControlToTrustCenter", + "operationId": "AddTrustCenterFaqCategory", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenterControl" + "$ref": "#/components/schemas/TrustCenterFaqCategory" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "name": "Control name", - "description": "Control description", - "categories": [ - { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" - } - ] + "id": "71a3b8d2ef904c1a6d5e7f30", + "name": "Security" } } } @@ -23080,8 +28746,8 @@ } } }, - "description": "Adds a control to a Trust Center.", - "summary": "Add Trust Center control", + "description": "Adds an FAQ category to a Trust Center.", + "summary": "Add Trust Center FAQ category", "tags": [ "Trust Centers" ], @@ -23105,36 +28771,29 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/AddControlToTrustCenterInput" + "$ref": "#/components/schemas/AddTrustCenterFaqCategoryInput" } } } } } }, - "/trust-centers/{slugId}/controls/{controlId}": { - "get": { - "operationId": "GetTrustCenterControl", + "/trust-centers/{slugId}/faq-categories/{categoryId}": { + "patch": { + "operationId": "UpdateTrustCenterFaqCategory", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/TrustCenterControl" + "$ref": "#/components/schemas/TrustCenterFaqCategory" }, "examples": { "Example 1": { "value": { - "id": "a2f7e1b9d0c3f4e5a6c7b8d9", - "name": "Control name", - "description": "Control description", - "categories": [ - { - "id": "93d69894dd525f806d7e5c48", - "name": "Category name" - } - ] + "id": "71a3b8d2ef904c1a6d5e7f30", + "name": "Security" } } } @@ -23142,8 +28801,8 @@ } } }, - "description": "Gets a specific control on a Trust Center.", - "summary": "Get Trust Center control", + "description": "Updates an FAQ category on a Trust Center.", + "summary": "Update Trust Center FAQ category", "tags": [ "Trust Centers" ], @@ -23163,23 +28822,33 @@ }, { "in": "path", - "name": "controlId", + "name": "categoryId", "required": true, "schema": { "type": "string" } } - ] + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/EditTrustCenterFaqCategoryInput" + } + } + } + } }, "delete": { - "operationId": "DeleteTrustCenterControl", + "operationId": "DeleteTrustCenterFaqCategory", "responses": { "204": { "description": "No content" } }, - "description": "Removes a specific control from a Trust Center. This removes the control\nfrom all of the control categories that is in.", - "summary": "Delete Trust Center control", + "description": "Removes an FAQ category from a Trust Center. FAQs in the\ndeleted category are moved to uncategorized.", + "summary": "Delete Trust Center FAQ category", "tags": [ "Trust Centers" ], @@ -23199,7 +28868,7 @@ }, { "in": "path", - "name": "controlId", + "name": "categoryId", "required": true, "schema": { "type": "string" @@ -23450,8 +29119,60 @@ "description": "No content" } }, - "description": "Remove a specific FAQ from the Trust Center by ID.", - "summary": "Delete Trust Center FAQ", + "description": "Remove a specific FAQ from the Trust Center by ID.", + "summary": "Delete Trust Center FAQ", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "faqId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/trust-centers/{slugId}/favicon": { + "post": { + "operationId": "UploadTrustCenterFavicon", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UploadFaviconResponse" + }, + "examples": { + "Example 1": { + "value": { + "isSuccessful": true + } + } + } + } + } + } + }, + "description": "Uploads a favicon for a Trust Center. The Trust Center must have a custom\ndomain configured.", + "summary": "Upload Trust Center favicon", "tags": [ "Trust Centers" ], @@ -23468,16 +29189,27 @@ "schema": { "type": "string" } - }, - { - "in": "path", - "name": "faqId", - "required": true, - "schema": { - "type": "string" + } + ], + "requestBody": { + "required": true, + "content": { + "multipart/form-data": { + "schema": { + "type": "object", + "properties": { + "favicon": { + "type": "string", + "format": "binary" + } + }, + "required": [ + "favicon" + ] + } } } - ] + } } }, "/trust-centers/{slugId}/historical-access-requests": { @@ -24148,6 +29880,16 @@ "$ref": "#/components/schemas/NodeJS.ReadableStream" } }, + "application/yaml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, + "text/x-yaml": { + "schema": { + "$ref": "#/components/schemas/NodeJS.ReadableStream" + } + }, "application/vnd.ms-excel": { "schema": { "$ref": "#/components/schemas/NodeJS.ReadableStream" @@ -25591,6 +31333,66 @@ } } }, + "/trust-centers/{slugId}/videos": { + "put": { + "operationId": "UpsertTrustCenterVideos", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ArrayResponse_TrustCenterVideo_" + }, + "examples": { + "Example 1": { + "value": { + "results": [ + { + "url": "https://www.youtube.com/watch?v=dQw4w9WgXcQ", + "title": "Product security overview", + "description": "An overview of our security practices" + } + ] + } + } + } + } + } + } + }, + "description": "Configures the videos displayed on a Trust Center. Replaces all\nexisting videos with the provided list.", + "summary": "Set Trust Center videos", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/SetTrustCenterVideosInput" + } + } + } + } + } + }, "/trust-centers/{slugId}/viewers": { "get": { "operationId": "ListTrustCenterViewers", @@ -25904,10 +31706,194 @@ } } }, - "description": "Updates a viewer's access on a Trust Center.", - "summary": "Update Trust Center viewer", + "description": "Updates a viewer's access on a Trust Center.", + "summary": "Update Trust Center viewer", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "viewerId", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/UpdateTrustCenterViewerInput" + } + } + } + } + } + }, + "/trust-centers/{slugId}/viewers/{viewerId}/send-invite-reminder": { + "post": { + "operationId": "SendTrustCenterViewerInviteReminder", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/InviteReminderResponse" + }, + "examples": { + "Example 1": { + "value": { + "isSuccessful": true + } + } + } + } + } + } + }, + "description": "Resends the invite email for a Trust Center viewer.", + "summary": "Send Trust Center viewer invite reminder", + "tags": [ + "Trust Centers" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "slugId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "viewerId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/users": { + "get": { + "operationId": "ListUsers", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_User_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "69c55d93ca5e7c5217d4c993", + "email": "example-user@email.com", + "displayName": "Example User", + "isActive": true + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "69c55d93ca5e7c5217d4c993", + "endCursor": "69c55d93ca5e7c5217d4c993" + } + } + } + } + } + } + } + } + }, + "description": "Returns a list of all active users.", + "summary": "List active users", + "tags": [ + "Users" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + } + ] + } + }, + "/users/{userId}": { + "get": { + "operationId": "GetUser", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/User" + }, + "examples": { + "Example 1": { + "value": { + "id": "69c55d93ca5e7c5217d4c993", + "email": "example-user@email.com", + "displayName": "Example User", + "isActive": true + } + } + } + } + } + } + }, + "description": "Returns a user by ID.", + "summary": "Get user by ID", "tags": [ - "Trust Centers" + "Users" ], "security": [ { @@ -25917,43 +31903,25 @@ "parameters": [ { "in": "path", - "name": "slugId", - "required": true, - "schema": { - "type": "string" - } - }, - { - "in": "path", - "name": "viewerId", + "name": "userId", "required": true, "schema": { "type": "string" } } - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/UpdateTrustCenterViewerInput" - } - } - } - } + ] } }, - "/users": { + "/vendor-assessment-types": { "get": { - "operationId": "ListUsers", + "operationId": "ListVendorAssessmentTypes", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/PaginatedResponse_User_" + "$ref": "#/components/schemas/PaginatedResponse_VendorAssessmentType_" }, "examples": { "Example 1": { @@ -25961,17 +31929,17 @@ "results": { "data": [ { - "id": "69c55d93ca5e7c5217d4c993", - "email": "example-user@email.com", - "displayName": "Example User", - "isActive": true + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": "Assessment of a vendor's security posture.", + "status": "ACTIVE" } ], "pageInfo": { "hasNextPage": false, "hasPreviousPage": false, - "startCursor": "69c55d93ca5e7c5217d4c993", - "endCursor": "69c55d93ca5e7c5217d4c993" + "startCursor": "NjY5NmVhMDU5NWRmNTBkNWNkNmVjM2I4", + "endCursor": "NjY5NmVhMDU5NWRmNTBkNWNkNmVjM2I4" } } } @@ -25981,10 +31949,10 @@ } } }, - "description": "Returns a list of all active users.", - "summary": "List active users", + "description": "Lists the domain's assessment types. Returns both active and archived\ntypes by default; pass the `status` query parameter to filter server-side.", + "summary": "List assessment types", "tags": [ - "Users" + "Vendor Assessment Types" ], "security": [ { @@ -26007,28 +31975,37 @@ "schema": { "$ref": "#/components/schemas/PageCursor" } + }, + { + "description": "Filter assessment types to a single lifecycle status", + "in": "query", + "name": "status", + "required": false, + "schema": { + "$ref": "#/components/schemas/VendorAssessmentTypeLifecycleStatus" + } } ] } }, - "/users/{userId}": { + "/vendor-assessment-types/{assessmentTypeId}": { "get": { - "operationId": "GetUser", + "operationId": "GetVendorAssessmentTypeById", "responses": { "200": { "description": "Ok", "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/User" + "$ref": "#/components/schemas/VendorAssessmentType" }, "examples": { "Example 1": { "value": { - "id": "69c55d93ca5e7c5217d4c993", - "email": "example-user@email.com", - "displayName": "Example User", - "isActive": true + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": "Assessment of a vendor's security posture.", + "status": "ACTIVE" } } } @@ -26036,10 +32013,10 @@ } } }, - "description": "Returns a user by ID.", - "summary": "Get user by ID", + "description": "Gets an assessment type by ID.", + "summary": "Get assessment type by ID", "tags": [ - "Users" + "Vendor Assessment Types" ], "security": [ { @@ -26049,7 +32026,7 @@ "parameters": [ { "in": "path", - "name": "userId", + "name": "assessmentTypeId", "required": true, "schema": { "type": "string" @@ -26085,7 +32062,11 @@ "Other" ], "enabled": true, - "riskLevel": "LOW" + "riskLevel": "LOW", + "riskSection": { + "id": "b3a8f2c0e1d4a5b6c7d8e9f0", + "name": "Types of data processed" + } } ], "pageInfo": { @@ -26568,6 +32549,202 @@ } } }, + "/vendors/{vendorId}/assessments": { + "get": { + "operationId": "GetAssessmentsByVendorId", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/PaginatedResponse_VendorAssessment_" + }, + "examples": { + "Example 1": { + "value": { + "results": { + "data": [ + { + "id": "a2f7e1b9d0c3f4e5a6c7b8d8", + "vendorId": "6696e9bca247cbdf1c8e5054", + "status": "COMPLETED", + "completedByUserId": "6696ea0595df50d5cd6ec3b7", + "startDate": "2024-02-01T00:00:00.000Z", + "dueDate": "2024-03-01T00:00:00.000Z", + "overrideDueDate": "2024-03-15T00:00:00.000Z", + "completionDate": "2024-03-10T00:00:00.000Z", + "createdDate": "2024-01-25T00:00:00.000Z", + "decision": { + "status": "APPROVED", + "lastUpdatedAt": "2024-03-17T00:00:00.000Z", + "comments": "No major concerns, limited sharing of data, low security risk." + }, + "assessmentType": { + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": null + }, + "owner": { + "id": "6696ea0595df50d5cd6ec3b9", + "type": "USER", + "displayName": "Jane Doe", + "email": "jane.doe@example.com" + } + } + ], + "pageInfo": { + "hasNextPage": false, + "hasPreviousPage": false, + "startCursor": "6696ea0595df50d5cd6ec3b7", + "endCursor": "6696ece48eb1f98ff3d927c6" + } + } + } + } + } + } + } + } + }, + "description": "Returns a vendor's assessments across all assessment types.", + "summary": "List assessments by vendor ID", + "tags": [ + "Vendors" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "vendorId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "query", + "name": "pageSize", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageSize" + } + }, + { + "in": "query", + "name": "pageCursor", + "required": false, + "schema": { + "$ref": "#/components/schemas/PageCursor" + } + }, + { + "description": "Filter assessments to any of the given assessment type IDs", + "in": "query", + "name": "typeIdMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "type": "string" + } + } + }, + { + "description": "Filter assessments to any of the given statuses", + "in": "query", + "name": "statusMatchesAny", + "required": false, + "schema": { + "type": "array", + "items": { + "$ref": "#/components/schemas/AssessmentStatus" + } + } + } + ] + } + }, + "/vendors/{vendorId}/assessments/{assessmentId}": { + "get": { + "operationId": "GetAssessmentById", + "responses": { + "200": { + "description": "Ok", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/VendorAssessment" + }, + "examples": { + "Example 1": { + "value": { + "id": "a2f7e1b9d0c3f4e5a6c7b8d8", + "vendorId": "6696e9bca247cbdf1c8e5054", + "status": "COMPLETED", + "completedByUserId": "6696ea0595df50d5cd6ec3b7", + "startDate": "2024-02-01T00:00:00.000Z", + "dueDate": "2024-03-01T00:00:00.000Z", + "overrideDueDate": "2024-03-15T00:00:00.000Z", + "completionDate": "2024-03-10T00:00:00.000Z", + "createdDate": "2024-01-25T00:00:00.000Z", + "decision": { + "status": "APPROVED", + "lastUpdatedAt": "2024-03-17T00:00:00.000Z", + "comments": "No major concerns, limited sharing of data, low security risk." + }, + "assessmentType": { + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": null + }, + "owner": { + "id": "6696ea0595df50d5cd6ec3b9", + "type": "USER", + "displayName": "Jane Doe", + "email": "jane.doe@example.com" + } + } + } + } + } + } + } + }, + "description": "Returns a single assessment for a vendor.", + "summary": "Get assessment by ID", + "tags": [ + "Vendors" + ], + "security": [ + { + "bearerAuth": [] + } + ], + "parameters": [ + { + "in": "path", + "name": "vendorId", + "required": true, + "schema": { + "type": "string" + } + }, + { + "in": "path", + "name": "assessmentId", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, "/vendors/{vendorId}/documents": { "get": { "operationId": "ListVendorDocuments", @@ -27036,6 +33213,17 @@ "decision": { "status": "APPROVED", "lastUpdatedAt": "2024-03-17T00:00:00.000Z" + }, + "assessmentType": { + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": null + }, + "owner": { + "id": "6696ea0595df50d5cd6ec3b9", + "type": "USER", + "displayName": "Jane Doe", + "email": "jane.doe@example.com" } } ], @@ -27117,6 +33305,17 @@ "decision": { "status": "APPROVED", "lastUpdatedAt": "2024-03-17T00:00:00.000Z" + }, + "assessmentType": { + "id": "6696ea0595df50d5cd6ec3b8", + "name": "Security", + "description": null + }, + "owner": { + "id": "6696ea0595df50d5cd6ec3b9", + "type": "USER", + "displayName": "Jane Doe", + "email": "jane.doe@example.com" } } } @@ -27574,15 +33773,6 @@ } ], "parameters": [ - { - "description": "Filter vulnerabilities by search query", - "in": "query", - "name": "q", - "required": false, - "schema": { - "type": "string" - } - }, { "in": "query", "name": "pageSize", @@ -27615,7 +33805,8 @@ "required": false, "schema": { "type": "string" - } + }, + "example": "CVE-2025-55182" }, { "description": "Filter vulnerabilities that have an available fix.", @@ -27633,10 +33824,11 @@ "required": false, "schema": { "type": "string" - } + }, + "example": "bind-export-libs:9.11.4" }, { - "description": "Filter vulnerabilities with a fix due after a specific timestamp", + "description": "Filter vulnerabilities with a fix due after a specific timestamp.", "in": "query", "name": "slaDeadlineAfterDate", "required": false, @@ -27646,7 +33838,7 @@ } }, { - "description": "Filter vulnerabilities with a fix due before a specific timestamp", + "description": "Filter vulnerabilities with a fix due before a specific timestamp.", "in": "query", "name": "slaDeadlineBeforeDate", "required": false, @@ -27690,6 +33882,15 @@ "schema": { "type": "string" } + }, + { + "description": "Full-text filter on the vulnerability's name and description.", + "in": "query", + "name": "q", + "required": false, + "schema": { + "type": "string" + } } ] } @@ -27748,7 +33949,7 @@ "$ref": "#/components/schemas/VulnerabilityDeactivateRequest" }, "type": "array", - "description": "List of vulnerabilities to deactivate", + "description": "List of vulnerabilities to deactivate.", "minItems": 1, "maxItems": 50 } @@ -28354,4 +34555,4 @@ "description": "Vanta Gov (FedRAMP)" } ] -} \ No newline at end of file +} diff --git a/src/generated/client.gen.ts b/src/generated/client.gen.ts deleted file mode 100644 index 9ca917a..0000000 --- a/src/generated/client.gen.ts +++ /dev/null @@ -1,18 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import { type ClientOptions, type Config, createClient, createConfig } from './client/index.js'; -import type { ClientOptions as ClientOptions2 } from './types.gen.js'; - -/** - * The `createClientConfig()` function will be called on client initialization - * and the returned object will become the client's initial configuration. - * - * You may want to initialize your client this way instead of calling - * `setConfig()`. This is useful for example if you're using Next.js - * to ensure your client always has the correct values. - */ -export type CreateClientConfig = (override?: Config) => Config & T>; - -export const client = createClient(createConfig({ - baseUrl: 'https://api.vanta.com/v1' -})); diff --git a/src/generated/client/client.gen.ts b/src/generated/client/client.gen.ts deleted file mode 100644 index 6796130..0000000 --- a/src/generated/client/client.gen.ts +++ /dev/null @@ -1,268 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import { createSseClient } from '../core/serverSentEvents.gen.js'; -import type { HttpMethod } from '../core/types.gen.js'; -import { getValidRequestBody } from '../core/utils.gen.js'; -import type { - Client, - Config, - RequestOptions, - ResolvedRequestOptions, -} from './types.gen.js'; -import { - buildUrl, - createConfig, - createInterceptors, - getParseAs, - mergeConfigs, - mergeHeaders, - setAuthParams, -} from './utils.gen.js'; - -type ReqInit = Omit & { - body?: any; - headers: ReturnType; -}; - -export const createClient = (config: Config = {}): Client => { - let _config = mergeConfigs(createConfig(), config); - - const getConfig = (): Config => ({ ..._config }); - - const setConfig = (config: Config): Config => { - _config = mergeConfigs(_config, config); - return getConfig(); - }; - - const interceptors = createInterceptors< - Request, - Response, - unknown, - ResolvedRequestOptions - >(); - - const beforeRequest = async (options: RequestOptions) => { - const opts = { - ..._config, - ...options, - fetch: options.fetch ?? _config.fetch ?? globalThis.fetch, - headers: mergeHeaders(_config.headers, options.headers), - serializedBody: undefined, - }; - - if (opts.security) { - await setAuthParams({ - ...opts, - security: opts.security, - }); - } - - if (opts.requestValidator) { - await opts.requestValidator(opts); - } - - if (opts.body !== undefined && opts.bodySerializer) { - opts.serializedBody = opts.bodySerializer(opts.body); - } - - // remove Content-Type header if body is empty to avoid sending invalid requests - if (opts.body === undefined || opts.serializedBody === '') { - opts.headers.delete('Content-Type'); - } - - const url = buildUrl(opts); - - return { opts, url }; - }; - - const request: Client['request'] = async (options) => { - // @ts-expect-error - const { opts, url } = await beforeRequest(options); - const requestInit: ReqInit = { - redirect: 'follow', - ...opts, - body: getValidRequestBody(opts), - }; - - let request = new Request(url, requestInit); - - for (const fn of interceptors.request.fns) { - if (fn) { - request = await fn(request, opts); - } - } - - // fetch must be assigned here, otherwise it would throw the error: - // TypeError: Failed to execute 'fetch' on 'Window': Illegal invocation - const _fetch = opts.fetch!; - let response = await _fetch(request); - - for (const fn of interceptors.response.fns) { - if (fn) { - response = await fn(response, request, opts); - } - } - - const result = { - request, - response, - }; - - if (response.ok) { - const parseAs = - (opts.parseAs === 'auto' - ? getParseAs(response.headers.get('Content-Type')) - : opts.parseAs) ?? 'json'; - - if ( - response.status === 204 || - response.headers.get('Content-Length') === '0' - ) { - let emptyData: any; - switch (parseAs) { - case 'arrayBuffer': - case 'blob': - case 'text': - emptyData = await response[parseAs](); - break; - case 'formData': - emptyData = new FormData(); - break; - case 'stream': - emptyData = response.body; - break; - case 'json': - default: - emptyData = {}; - break; - } - return opts.responseStyle === 'data' - ? emptyData - : { - data: emptyData, - ...result, - }; - } - - let data: any; - switch (parseAs) { - case 'arrayBuffer': - case 'blob': - case 'formData': - case 'json': - case 'text': - data = await response[parseAs](); - break; - case 'stream': - return opts.responseStyle === 'data' - ? response.body - : { - data: response.body, - ...result, - }; - } - - if (parseAs === 'json') { - if (opts.responseValidator) { - await opts.responseValidator(data); - } - - if (opts.responseTransformer) { - data = await opts.responseTransformer(data); - } - } - - return opts.responseStyle === 'data' - ? data - : { - data, - ...result, - }; - } - - const textError = await response.text(); - let jsonError: unknown; - - try { - jsonError = JSON.parse(textError); - } catch { - // noop - } - - const error = jsonError ?? textError; - let finalError = error; - - for (const fn of interceptors.error.fns) { - if (fn) { - finalError = (await fn(error, response, request, opts)) as string; - } - } - - finalError = finalError || ({} as string); - - if (opts.throwOnError) { - throw finalError; - } - - // TODO: we probably want to return error and improve types - return opts.responseStyle === 'data' - ? undefined - : { - error: finalError, - ...result, - }; - }; - - const makeMethodFn = - (method: Uppercase) => (options: RequestOptions) => - request({ ...options, method }); - - const makeSseFn = - (method: Uppercase) => async (options: RequestOptions) => { - const { opts, url } = await beforeRequest(options); - return createSseClient({ - ...opts, - body: opts.body as BodyInit | null | undefined, - headers: opts.headers as unknown as Record, - method, - onRequest: async (url, init) => { - let request = new Request(url, init); - for (const fn of interceptors.request.fns) { - if (fn) { - request = await fn(request, opts); - } - } - return request; - }, - url, - }); - }; - - return { - buildUrl, - connect: makeMethodFn('CONNECT'), - delete: makeMethodFn('DELETE'), - get: makeMethodFn('GET'), - getConfig, - head: makeMethodFn('HEAD'), - interceptors, - options: makeMethodFn('OPTIONS'), - patch: makeMethodFn('PATCH'), - post: makeMethodFn('POST'), - put: makeMethodFn('PUT'), - request, - setConfig, - sse: { - connect: makeSseFn('CONNECT'), - delete: makeSseFn('DELETE'), - get: makeSseFn('GET'), - head: makeSseFn('HEAD'), - options: makeSseFn('OPTIONS'), - patch: makeSseFn('PATCH'), - post: makeSseFn('POST'), - put: makeSseFn('PUT'), - trace: makeSseFn('TRACE'), - }, - trace: makeMethodFn('TRACE'), - } as Client; -}; diff --git a/src/generated/client/index.ts b/src/generated/client/index.ts deleted file mode 100644 index b4e8e87..0000000 --- a/src/generated/client/index.ts +++ /dev/null @@ -1,26 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -export type { Auth } from '../core/auth.gen.js'; -export type { QuerySerializerOptions } from '../core/bodySerializer.gen.js'; -export { - formDataBodySerializer, - jsonBodySerializer, - urlSearchParamsBodySerializer, -} from '../core/bodySerializer.gen.js'; -export { buildClientParams } from '../core/params.gen.js'; -export { serializeQueryKeyValue } from '../core/queryKeySerializer.gen.js'; -export { createClient } from './client.gen.js'; -export type { - Client, - ClientOptions, - Config, - CreateClientConfig, - Options, - OptionsLegacyParser, - RequestOptions, - RequestResult, - ResolvedRequestOptions, - ResponseStyle, - TDataShape, -} from './types.gen.js'; -export { createConfig, mergeHeaders } from './utils.gen.js'; diff --git a/src/generated/client/types.gen.ts b/src/generated/client/types.gen.ts deleted file mode 100644 index d68ab68..0000000 --- a/src/generated/client/types.gen.ts +++ /dev/null @@ -1,268 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import type { Auth } from '../core/auth.gen.js'; -import type { - ServerSentEventsOptions, - ServerSentEventsResult, -} from '../core/serverSentEvents.gen.js'; -import type { - Client as CoreClient, - Config as CoreConfig, -} from '../core/types.gen.js'; -import type { Middleware } from './utils.gen.js'; - -export type ResponseStyle = 'data' | 'fields'; - -export interface Config - extends Omit, - CoreConfig { - /** - * Base URL for all requests made by this client. - */ - baseUrl?: T['baseUrl']; - /** - * Fetch API implementation. You can use this option to provide a custom - * fetch instance. - * - * @default globalThis.fetch - */ - fetch?: typeof fetch; - /** - * Please don't use the Fetch client for Next.js applications. The `next` - * options won't have any effect. - * - * Install {@link https://www.npmjs.com/package/@hey-api/client-next `@hey-api/client-next`} instead. - */ - next?: never; - /** - * Return the response data parsed in a specified format. By default, `auto` - * will infer the appropriate method from the `Content-Type` response header. - * You can override this behavior with any of the {@link Body} methods. - * Select `stream` if you don't want to parse response data at all. - * - * @default 'auto' - */ - parseAs?: - | 'arrayBuffer' - | 'auto' - | 'blob' - | 'formData' - | 'json' - | 'stream' - | 'text'; - /** - * Should we return only data or multiple fields (data, error, response, etc.)? - * - * @default 'fields' - */ - responseStyle?: ResponseStyle; - /** - * Throw an error instead of returning it in the response? - * - * @default false - */ - throwOnError?: T['throwOnError']; -} - -export interface RequestOptions< - TData = unknown, - TResponseStyle extends ResponseStyle = 'fields', - ThrowOnError extends boolean = boolean, - Url extends string = string, -> extends Config<{ - responseStyle: TResponseStyle; - throwOnError: ThrowOnError; - }>, - Pick< - ServerSentEventsOptions, - | 'onSseError' - | 'onSseEvent' - | 'sseDefaultRetryDelay' - | 'sseMaxRetryAttempts' - | 'sseMaxRetryDelay' - > { - /** - * Any body that you want to add to your request. - * - * {@link https://developer.mozilla.org/docs/Web/API/fetch#body} - */ - body?: unknown; - path?: Record; - query?: Record; - /** - * Security mechanism(s) to use for the request. - */ - security?: ReadonlyArray; - url: Url; -} - -export interface ResolvedRequestOptions< - TResponseStyle extends ResponseStyle = 'fields', - ThrowOnError extends boolean = boolean, - Url extends string = string, -> extends RequestOptions { - serializedBody?: string; -} - -export type RequestResult< - TData = unknown, - TError = unknown, - ThrowOnError extends boolean = boolean, - TResponseStyle extends ResponseStyle = 'fields', -> = ThrowOnError extends true - ? Promise< - TResponseStyle extends 'data' - ? TData extends Record - ? TData[keyof TData] - : TData - : { - data: TData extends Record - ? TData[keyof TData] - : TData; - request: Request; - response: Response; - } - > - : Promise< - TResponseStyle extends 'data' - ? - | (TData extends Record - ? TData[keyof TData] - : TData) - | undefined - : ( - | { - data: TData extends Record - ? TData[keyof TData] - : TData; - error: undefined; - } - | { - data: undefined; - error: TError extends Record - ? TError[keyof TError] - : TError; - } - ) & { - request: Request; - response: Response; - } - >; - -export interface ClientOptions { - baseUrl?: string; - responseStyle?: ResponseStyle; - throwOnError?: boolean; -} - -type MethodFn = < - TData = unknown, - TError = unknown, - ThrowOnError extends boolean = false, - TResponseStyle extends ResponseStyle = 'fields', ->( - options: Omit, 'method'>, -) => RequestResult; - -type SseFn = < - TData = unknown, - TError = unknown, - ThrowOnError extends boolean = false, - TResponseStyle extends ResponseStyle = 'fields', ->( - options: Omit, 'method'>, -) => Promise>; - -type RequestFn = < - TData = unknown, - TError = unknown, - ThrowOnError extends boolean = false, - TResponseStyle extends ResponseStyle = 'fields', ->( - options: Omit, 'method'> & - Pick< - Required>, - 'method' - >, -) => RequestResult; - -type BuildUrlFn = < - TData extends { - body?: unknown; - path?: Record; - query?: Record; - url: string; - }, ->( - options: Pick & Options, -) => string; - -export type Client = CoreClient< - RequestFn, - Config, - MethodFn, - BuildUrlFn, - SseFn -> & { - interceptors: Middleware; -}; - -/** - * The `createClientConfig()` function will be called on client initialization - * and the returned object will become the client's initial configuration. - * - * You may want to initialize your client this way instead of calling - * `setConfig()`. This is useful for example if you're using Next.js - * to ensure your client always has the correct values. - */ -export type CreateClientConfig = ( - override?: Config, -) => Config & T>; - -export interface TDataShape { - body?: unknown; - headers?: unknown; - path?: unknown; - query?: unknown; - url: string; -} - -type OmitKeys = Pick>; - -export type Options< - TData extends TDataShape = TDataShape, - ThrowOnError extends boolean = boolean, - TResponse = unknown, - TResponseStyle extends ResponseStyle = 'fields', -> = OmitKeys< - RequestOptions, - 'body' | 'path' | 'query' | 'url' -> & - Omit; - -export type OptionsLegacyParser< - TData = unknown, - ThrowOnError extends boolean = boolean, - TResponseStyle extends ResponseStyle = 'fields', -> = TData extends { body?: any } - ? TData extends { headers?: any } - ? OmitKeys< - RequestOptions, - 'body' | 'headers' | 'url' - > & - TData - : OmitKeys< - RequestOptions, - 'body' | 'url' - > & - TData & - Pick, 'headers'> - : TData extends { headers?: any } - ? OmitKeys< - RequestOptions, - 'headers' | 'url' - > & - TData & - Pick, 'body'> - : OmitKeys, 'url'> & - TData; diff --git a/src/generated/client/utils.gen.ts b/src/generated/client/utils.gen.ts deleted file mode 100644 index 48f1c97..0000000 --- a/src/generated/client/utils.gen.ts +++ /dev/null @@ -1,331 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import { getAuthToken } from '../core/auth.gen.js'; -import type { QuerySerializerOptions } from '../core/bodySerializer.gen.js'; -import { jsonBodySerializer } from '../core/bodySerializer.gen.js'; -import { - serializeArrayParam, - serializeObjectParam, - serializePrimitiveParam, -} from '../core/pathSerializer.gen.js'; -import { getUrl } from '../core/utils.gen.js'; -import type { Client, ClientOptions, Config, RequestOptions } from './types.gen.js'; - -export const createQuerySerializer = ({ - allowReserved, - array, - object, -}: QuerySerializerOptions = {}) => { - const querySerializer = (queryParams: T) => { - const search: string[] = []; - if (queryParams && typeof queryParams === 'object') { - for (const name in queryParams) { - const value = queryParams[name]; - - if (value === undefined || value === null) { - continue; - } - - if (Array.isArray(value)) { - const serializedArray = serializeArrayParam({ - allowReserved, - explode: true, - name, - style: 'form', - value, - ...array, - }); - if (serializedArray) search.push(serializedArray); - } else if (typeof value === 'object') { - const serializedObject = serializeObjectParam({ - allowReserved, - explode: true, - name, - style: 'deepObject', - value: value as Record, - ...object, - }); - if (serializedObject) search.push(serializedObject); - } else { - const serializedPrimitive = serializePrimitiveParam({ - allowReserved, - name, - value: value as string, - }); - if (serializedPrimitive) search.push(serializedPrimitive); - } - } - } - return search.join('&'); - }; - return querySerializer; -}; - -/** - * Infers parseAs value from provided Content-Type header. - */ -export const getParseAs = ( - contentType: string | null, -): Exclude => { - if (!contentType) { - // If no Content-Type header is provided, the best we can do is return the raw response body, - // which is effectively the same as the 'stream' option. - return 'stream'; - } - - const cleanContent = contentType.split(';')[0]?.trim(); - - if (!cleanContent) { - return; - } - - if ( - cleanContent.startsWith('application/json') || - cleanContent.endsWith('+json') - ) { - return 'json'; - } - - if (cleanContent === 'multipart/form-data') { - return 'formData'; - } - - if ( - ['application/', 'audio/', 'image/', 'video/'].some((type) => - cleanContent.startsWith(type), - ) - ) { - return 'blob'; - } - - if (cleanContent.startsWith('text/')) { - return 'text'; - } - - return; -}; - -const checkForExistence = ( - options: Pick & { - headers: Headers; - }, - name?: string, -): boolean => { - if (!name) { - return false; - } - if ( - options.headers.has(name) || - options.query?.[name] || - options.headers.get('Cookie')?.includes(`${name}=`) - ) { - return true; - } - return false; -}; - -export const setAuthParams = async ({ - security, - ...options -}: Pick, 'security'> & - Pick & { - headers: Headers; - }) => { - for (const auth of security) { - if (checkForExistence(options, auth.name)) { - continue; - } - - const token = await getAuthToken(auth, options.auth); - - if (!token) { - continue; - } - - const name = auth.name ?? 'Authorization'; - - switch (auth.in) { - case 'query': - if (!options.query) { - options.query = {}; - } - options.query[name] = token; - break; - case 'cookie': - options.headers.append('Cookie', `${name}=${token}`); - break; - case 'header': - default: - options.headers.set(name, token); - break; - } - } -}; - -export const buildUrl: Client['buildUrl'] = (options) => - getUrl({ - baseUrl: options.baseUrl as string, - path: options.path, - query: options.query, - querySerializer: - typeof options.querySerializer === 'function' - ? options.querySerializer - : createQuerySerializer(options.querySerializer), - url: options.url, - }); - -export const mergeConfigs = (a: Config, b: Config): Config => { - const config = { ...a, ...b }; - if (config.baseUrl?.endsWith('/')) { - config.baseUrl = config.baseUrl.substring(0, config.baseUrl.length - 1); - } - config.headers = mergeHeaders(a.headers, b.headers); - return config; -}; - -const headersEntries = (headers: Headers): Array<[string, string]> => { - const entries: Array<[string, string]> = []; - headers.forEach((value, key) => { - entries.push([key, value]); - }); - return entries; -}; - -export const mergeHeaders = ( - ...headers: Array['headers'] | undefined> -): Headers => { - const mergedHeaders = new Headers(); - for (const header of headers) { - if (!header) { - continue; - } - - const iterator = - header instanceof Headers - ? headersEntries(header) - : Object.entries(header); - - for (const [key, value] of iterator) { - if (value === null) { - mergedHeaders.delete(key); - } else if (Array.isArray(value)) { - for (const v of value) { - mergedHeaders.append(key, v as string); - } - } else if (value !== undefined) { - // assume object headers are meant to be JSON stringified, i.e. their - // content value in OpenAPI specification is 'application/json' - mergedHeaders.set( - key, - typeof value === 'object' ? JSON.stringify(value) : (value as string), - ); - } - } - } - return mergedHeaders; -}; - -type ErrInterceptor = ( - error: Err, - response: Res, - request: Req, - options: Options, -) => Err | Promise; - -type ReqInterceptor = ( - request: Req, - options: Options, -) => Req | Promise; - -type ResInterceptor = ( - response: Res, - request: Req, - options: Options, -) => Res | Promise; - -class Interceptors { - fns: Array = []; - - clear(): void { - this.fns = []; - } - - eject(id: number | Interceptor): void { - const index = this.getInterceptorIndex(id); - if (this.fns[index]) { - this.fns[index] = null; - } - } - - exists(id: number | Interceptor): boolean { - const index = this.getInterceptorIndex(id); - return Boolean(this.fns[index]); - } - - getInterceptorIndex(id: number | Interceptor): number { - if (typeof id === 'number') { - return this.fns[id] ? id : -1; - } - return this.fns.indexOf(id); - } - - update( - id: number | Interceptor, - fn: Interceptor, - ): number | Interceptor | false { - const index = this.getInterceptorIndex(id); - if (this.fns[index]) { - this.fns[index] = fn; - return id; - } - return false; - } - - use(fn: Interceptor): number { - this.fns.push(fn); - return this.fns.length - 1; - } -} - -export interface Middleware { - error: Interceptors>; - request: Interceptors>; - response: Interceptors>; -} - -export const createInterceptors = (): Middleware< - Req, - Res, - Err, - Options -> => ({ - error: new Interceptors>(), - request: new Interceptors>(), - response: new Interceptors>(), -}); - -const defaultQuerySerializer = createQuerySerializer({ - allowReserved: false, - array: { - explode: true, - style: 'form', - }, - object: { - explode: true, - style: 'deepObject', - }, -}); - -const defaultHeaders = { - 'Content-Type': 'application/json', -}; - -export const createConfig = ( - override: Config & T> = {}, -): Config & T> => ({ - ...jsonBodySerializer, - headers: defaultHeaders, - parseAs: 'auto', - querySerializer: defaultQuerySerializer, - ...override, -}); diff --git a/src/generated/core/auth.gen.ts b/src/generated/core/auth.gen.ts deleted file mode 100644 index f8a7326..0000000 --- a/src/generated/core/auth.gen.ts +++ /dev/null @@ -1,42 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -export type AuthToken = string | undefined; - -export interface Auth { - /** - * Which part of the request do we use to send the auth? - * - * @default 'header' - */ - in?: 'header' | 'query' | 'cookie'; - /** - * Header or query parameter name. - * - * @default 'Authorization' - */ - name?: string; - scheme?: 'basic' | 'bearer'; - type: 'apiKey' | 'http'; -} - -export const getAuthToken = async ( - auth: Auth, - callback: ((auth: Auth) => Promise | AuthToken) | AuthToken, -): Promise => { - const token = - typeof callback === 'function' ? await callback(auth) : callback; - - if (!token) { - return; - } - - if (auth.scheme === 'bearer') { - return `Bearer ${token}`; - } - - if (auth.scheme === 'basic') { - return `Basic ${btoa(token)}`; - } - - return token; -}; diff --git a/src/generated/core/bodySerializer.gen.ts b/src/generated/core/bodySerializer.gen.ts deleted file mode 100644 index b2f0d38..0000000 --- a/src/generated/core/bodySerializer.gen.ts +++ /dev/null @@ -1,92 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import type { - ArrayStyle, - ObjectStyle, - SerializerOptions, -} from './pathSerializer.gen.js'; - -export type QuerySerializer = (query: Record) => string; - -export type BodySerializer = (body: any) => any; - -export interface QuerySerializerOptions { - allowReserved?: boolean; - array?: SerializerOptions; - object?: SerializerOptions; -} - -const serializeFormDataPair = ( - data: FormData, - key: string, - value: unknown, -): void => { - if (typeof value === 'string' || value instanceof Blob) { - data.append(key, value); - } else if (value instanceof Date) { - data.append(key, value.toISOString()); - } else { - data.append(key, JSON.stringify(value)); - } -}; - -const serializeUrlSearchParamsPair = ( - data: URLSearchParams, - key: string, - value: unknown, -): void => { - if (typeof value === 'string') { - data.append(key, value); - } else { - data.append(key, JSON.stringify(value)); - } -}; - -export const formDataBodySerializer = { - bodySerializer: | Array>>( - body: T, - ): FormData => { - const data = new FormData(); - - Object.entries(body).forEach(([key, value]) => { - if (value === undefined || value === null) { - return; - } - if (Array.isArray(value)) { - value.forEach((v) => serializeFormDataPair(data, key, v)); - } else { - serializeFormDataPair(data, key, value); - } - }); - - return data; - }, -}; - -export const jsonBodySerializer = { - bodySerializer: (body: T): string => - JSON.stringify(body, (_key, value) => - typeof value === 'bigint' ? value.toString() : value, - ), -}; - -export const urlSearchParamsBodySerializer = { - bodySerializer: | Array>>( - body: T, - ): string => { - const data = new URLSearchParams(); - - Object.entries(body).forEach(([key, value]) => { - if (value === undefined || value === null) { - return; - } - if (Array.isArray(value)) { - value.forEach((v) => serializeUrlSearchParamsPair(data, key, v)); - } else { - serializeUrlSearchParamsPair(data, key, value); - } - }); - - return data.toString(); - }, -}; diff --git a/src/generated/core/params.gen.ts b/src/generated/core/params.gen.ts deleted file mode 100644 index 71c88e8..0000000 --- a/src/generated/core/params.gen.ts +++ /dev/null @@ -1,153 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -type Slot = 'body' | 'headers' | 'path' | 'query'; - -export type Field = - | { - in: Exclude; - /** - * Field name. This is the name we want the user to see and use. - */ - key: string; - /** - * Field mapped name. This is the name we want to use in the request. - * If omitted, we use the same value as `key`. - */ - map?: string; - } - | { - in: Extract; - /** - * Key isn't required for bodies. - */ - key?: string; - map?: string; - }; - -export interface Fields { - allowExtra?: Partial>; - args?: ReadonlyArray; -} - -export type FieldsConfig = ReadonlyArray; - -const extraPrefixesMap: Record = { - $body_: 'body', - $headers_: 'headers', - $path_: 'path', - $query_: 'query', -}; -const extraPrefixes = Object.entries(extraPrefixesMap); - -type KeyMap = Map< - string, - { - in: Slot; - map?: string; - } ->; - -const buildKeyMap = (fields: FieldsConfig, map?: KeyMap): KeyMap => { - if (!map) { - map = new Map(); - } - - for (const config of fields) { - if ('in' in config) { - if (config.key) { - map.set(config.key, { - in: config.in, - map: config.map, - }); - } - } else if (config.args) { - buildKeyMap(config.args, map); - } - } - - return map; -}; - -interface Params { - body: unknown; - headers: Record; - path: Record; - query: Record; -} - -const stripEmptySlots = (params: Params) => { - for (const [slot, value] of Object.entries(params)) { - if (value && typeof value === 'object' && !Object.keys(value).length) { - delete params[slot as Slot]; - } - } -}; - -export const buildClientParams = ( - args: ReadonlyArray, - fields: FieldsConfig, -) => { - const params: Params = { - body: {}, - headers: {}, - path: {}, - query: {}, - }; - - const map = buildKeyMap(fields); - - let config: FieldsConfig[number] | undefined; - - for (const [index, arg] of args.entries()) { - if (fields[index]) { - config = fields[index]; - } - - if (!config) { - continue; - } - - if ('in' in config) { - if (config.key) { - const field = map.get(config.key)!; - const name = field.map || config.key; - (params[field.in] as Record)[name] = arg; - } else { - params.body = arg; - } - } else { - for (const [key, value] of Object.entries(arg ?? {})) { - const field = map.get(key); - - if (field) { - const name = field.map || key; - (params[field.in] as Record)[name] = value; - } else { - const extra = extraPrefixes.find(([prefix]) => - key.startsWith(prefix), - ); - - if (extra) { - const [prefix, slot] = extra; - (params[slot] as Record)[ - key.slice(prefix.length) - ] = value; - } else { - for (const [slot, allowed] of Object.entries( - config.allowExtra ?? {}, - )) { - if (allowed) { - (params[slot as Slot] as Record)[key] = value; - break; - } - } - } - } - } - } - } - - stripEmptySlots(params); - - return params; -}; diff --git a/src/generated/core/pathSerializer.gen.ts b/src/generated/core/pathSerializer.gen.ts deleted file mode 100644 index 8d99931..0000000 --- a/src/generated/core/pathSerializer.gen.ts +++ /dev/null @@ -1,181 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -interface SerializeOptions - extends SerializePrimitiveOptions, - SerializerOptions {} - -interface SerializePrimitiveOptions { - allowReserved?: boolean; - name: string; -} - -export interface SerializerOptions { - /** - * @default true - */ - explode: boolean; - style: T; -} - -export type ArrayStyle = 'form' | 'spaceDelimited' | 'pipeDelimited'; -export type ArraySeparatorStyle = ArrayStyle | MatrixStyle; -type MatrixStyle = 'label' | 'matrix' | 'simple'; -export type ObjectStyle = 'form' | 'deepObject'; -type ObjectSeparatorStyle = ObjectStyle | MatrixStyle; - -interface SerializePrimitiveParam extends SerializePrimitiveOptions { - value: string; -} - -export const separatorArrayExplode = (style: ArraySeparatorStyle) => { - switch (style) { - case 'label': - return '.'; - case 'matrix': - return ';'; - case 'simple': - return ','; - default: - return '&'; - } -}; - -export const separatorArrayNoExplode = (style: ArraySeparatorStyle) => { - switch (style) { - case 'form': - return ','; - case 'pipeDelimited': - return '|'; - case 'spaceDelimited': - return '%20'; - default: - return ','; - } -}; - -export const separatorObjectExplode = (style: ObjectSeparatorStyle) => { - switch (style) { - case 'label': - return '.'; - case 'matrix': - return ';'; - case 'simple': - return ','; - default: - return '&'; - } -}; - -export const serializeArrayParam = ({ - allowReserved, - explode, - name, - style, - value, -}: SerializeOptions & { - value: unknown[]; -}) => { - if (!explode) { - const joinedValues = ( - allowReserved ? value : value.map((v) => encodeURIComponent(v as string)) - ).join(separatorArrayNoExplode(style)); - switch (style) { - case 'label': - return `.${joinedValues}`; - case 'matrix': - return `;${name}=${joinedValues}`; - case 'simple': - return joinedValues; - default: - return `${name}=${joinedValues}`; - } - } - - const separator = separatorArrayExplode(style); - const joinedValues = value - .map((v) => { - if (style === 'label' || style === 'simple') { - return allowReserved ? v : encodeURIComponent(v as string); - } - - return serializePrimitiveParam({ - allowReserved, - name, - value: v as string, - }); - }) - .join(separator); - return style === 'label' || style === 'matrix' - ? separator + joinedValues - : joinedValues; -}; - -export const serializePrimitiveParam = ({ - allowReserved, - name, - value, -}: SerializePrimitiveParam) => { - if (value === undefined || value === null) { - return ''; - } - - if (typeof value === 'object') { - throw new Error( - 'Deeply-nested arrays/objects aren’t supported. Provide your own `querySerializer()` to handle these.', - ); - } - - return `${name}=${allowReserved ? value : encodeURIComponent(value)}`; -}; - -export const serializeObjectParam = ({ - allowReserved, - explode, - name, - style, - value, - valueOnly, -}: SerializeOptions & { - value: Record | Date; - valueOnly?: boolean; -}) => { - if (value instanceof Date) { - return valueOnly ? value.toISOString() : `${name}=${value.toISOString()}`; - } - - if (style !== 'deepObject' && !explode) { - let values: string[] = []; - Object.entries(value).forEach(([key, v]) => { - values = [ - ...values, - key, - allowReserved ? (v as string) : encodeURIComponent(v as string), - ]; - }); - const joinedValues = values.join(','); - switch (style) { - case 'form': - return `${name}=${joinedValues}`; - case 'label': - return `.${joinedValues}`; - case 'matrix': - return `;${name}=${joinedValues}`; - default: - return joinedValues; - } - } - - const separator = separatorObjectExplode(style); - const joinedValues = Object.entries(value) - .map(([key, v]) => - serializePrimitiveParam({ - allowReserved, - name: style === 'deepObject' ? `${name}[${key}]` : key, - value: v as string, - }), - ) - .join(separator); - return style === 'label' || style === 'matrix' - ? separator + joinedValues - : joinedValues; -}; diff --git a/src/generated/core/queryKeySerializer.gen.ts b/src/generated/core/queryKeySerializer.gen.ts deleted file mode 100644 index d3bb683..0000000 --- a/src/generated/core/queryKeySerializer.gen.ts +++ /dev/null @@ -1,136 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -/** - * JSON-friendly union that mirrors what Pinia Colada can hash. - */ -export type JsonValue = - | null - | string - | number - | boolean - | JsonValue[] - | { [key: string]: JsonValue }; - -/** - * Replacer that converts non-JSON values (bigint, Date, etc.) to safe substitutes. - */ -export const queryKeyJsonReplacer = (_key: string, value: unknown) => { - if ( - value === undefined || - typeof value === 'function' || - typeof value === 'symbol' - ) { - return undefined; - } - if (typeof value === 'bigint') { - return value.toString(); - } - if (value instanceof Date) { - return value.toISOString(); - } - return value; -}; - -/** - * Safely stringifies a value and parses it back into a JsonValue. - */ -export const stringifyToJsonValue = (input: unknown): JsonValue | undefined => { - try { - const json = JSON.stringify(input, queryKeyJsonReplacer); - if (json === undefined) { - return undefined; - } - return JSON.parse(json) as JsonValue; - } catch { - return undefined; - } -}; - -/** - * Detects plain objects (including objects with a null prototype). - */ -const isPlainObject = (value: unknown): value is Record => { - if (value === null || typeof value !== 'object') { - return false; - } - const prototype = Object.getPrototypeOf(value as object); - return prototype === Object.prototype || prototype === null; -}; - -/** - * Turns URLSearchParams into a sorted JSON object for deterministic keys. - */ -const serializeSearchParams = (params: URLSearchParams): JsonValue => { - const entries = Array.from(params.entries()).sort(([a], [b]) => - a.localeCompare(b), - ); - const result: Record = {}; - - for (const [key, value] of entries) { - const existing = result[key]; - if (existing === undefined) { - result[key] = value; - continue; - } - - if (Array.isArray(existing)) { - (existing as string[]).push(value); - } else { - result[key] = [existing, value]; - } - } - - return result; -}; - -/** - * Normalizes any accepted value into a JSON-friendly shape for query keys. - */ -export const serializeQueryKeyValue = ( - value: unknown, -): JsonValue | undefined => { - if (value === null) { - return null; - } - - if ( - typeof value === 'string' || - typeof value === 'number' || - typeof value === 'boolean' - ) { - return value; - } - - if ( - value === undefined || - typeof value === 'function' || - typeof value === 'symbol' - ) { - return undefined; - } - - if (typeof value === 'bigint') { - return value.toString(); - } - - if (value instanceof Date) { - return value.toISOString(); - } - - if (Array.isArray(value)) { - return stringifyToJsonValue(value); - } - - if ( - typeof URLSearchParams !== 'undefined' && - value instanceof URLSearchParams - ) { - return serializeSearchParams(value); - } - - if (isPlainObject(value)) { - return stringifyToJsonValue(value); - } - - return undefined; -}; diff --git a/src/generated/core/serverSentEvents.gen.ts b/src/generated/core/serverSentEvents.gen.ts deleted file mode 100644 index d73aa0f..0000000 --- a/src/generated/core/serverSentEvents.gen.ts +++ /dev/null @@ -1,264 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import type { Config } from './types.gen.js'; - -export type ServerSentEventsOptions = Omit< - RequestInit, - 'method' -> & - Pick & { - /** - * Fetch API implementation. You can use this option to provide a custom - * fetch instance. - * - * @default globalThis.fetch - */ - fetch?: typeof fetch; - /** - * Implementing clients can call request interceptors inside this hook. - */ - onRequest?: (url: string, init: RequestInit) => Promise; - /** - * Callback invoked when a network or parsing error occurs during streaming. - * - * This option applies only if the endpoint returns a stream of events. - * - * @param error The error that occurred. - */ - onSseError?: (error: unknown) => void; - /** - * Callback invoked when an event is streamed from the server. - * - * This option applies only if the endpoint returns a stream of events. - * - * @param event Event streamed from the server. - * @returns Nothing (void). - */ - onSseEvent?: (event: StreamEvent) => void; - serializedBody?: RequestInit['body']; - /** - * Default retry delay in milliseconds. - * - * This option applies only if the endpoint returns a stream of events. - * - * @default 3000 - */ - sseDefaultRetryDelay?: number; - /** - * Maximum number of retry attempts before giving up. - */ - sseMaxRetryAttempts?: number; - /** - * Maximum retry delay in milliseconds. - * - * Applies only when exponential backoff is used. - * - * This option applies only if the endpoint returns a stream of events. - * - * @default 30000 - */ - sseMaxRetryDelay?: number; - /** - * Optional sleep function for retry backoff. - * - * Defaults to using `setTimeout`. - */ - sseSleepFn?: (ms: number) => Promise; - url: string; - }; - -export interface StreamEvent { - data: TData; - event?: string; - id?: string; - retry?: number; -} - -export type ServerSentEventsResult< - TData = unknown, - TReturn = void, - TNext = unknown, -> = { - stream: AsyncGenerator< - TData extends Record ? TData[keyof TData] : TData, - TReturn, - TNext - >; -}; - -export const createSseClient = ({ - onRequest, - onSseError, - onSseEvent, - responseTransformer, - responseValidator, - sseDefaultRetryDelay, - sseMaxRetryAttempts, - sseMaxRetryDelay, - sseSleepFn, - url, - ...options -}: ServerSentEventsOptions): ServerSentEventsResult => { - let lastEventId: string | undefined; - - const sleep = - sseSleepFn ?? - ((ms: number) => new Promise((resolve) => setTimeout(resolve, ms))); - - const createStream = async function* () { - let retryDelay: number = sseDefaultRetryDelay ?? 3000; - let attempt = 0; - const signal = options.signal ?? new AbortController().signal; - - while (true) { - if (signal.aborted) break; - - attempt++; - - const headers = - options.headers instanceof Headers - ? options.headers - : new Headers(options.headers as Record | undefined); - - if (lastEventId !== undefined) { - headers.set('Last-Event-ID', lastEventId); - } - - try { - const requestInit: RequestInit = { - redirect: 'follow', - ...options, - body: options.serializedBody, - headers, - signal, - }; - let request = new Request(url, requestInit); - if (onRequest) { - request = await onRequest(url, requestInit); - } - // fetch must be assigned here, otherwise it would throw the error: - // TypeError: Failed to execute 'fetch' on 'Window': Illegal invocation - const _fetch = options.fetch ?? globalThis.fetch; - const response = await _fetch(request); - - if (!response.ok) - throw new Error( - `SSE failed: ${response.status} ${response.statusText}`, - ); - - if (!response.body) throw new Error('No body in SSE response'); - - const reader = response.body - .pipeThrough(new TextDecoderStream()) - .getReader(); - - let buffer = ''; - - const abortHandler = () => { - try { - reader.cancel(); - } catch { - // noop - } - }; - - signal.addEventListener('abort', abortHandler); - - try { - while (true) { - const { done, value } = await reader.read(); - if (done) break; - buffer += value; - - const chunks = buffer.split('\n\n'); - buffer = chunks.pop() ?? ''; - - for (const chunk of chunks) { - const lines = chunk.split('\n'); - const dataLines: Array = []; - let eventName: string | undefined; - - for (const line of lines) { - if (line.startsWith('data:')) { - dataLines.push(line.replace(/^data:\s*/, '')); - } else if (line.startsWith('event:')) { - eventName = line.replace(/^event:\s*/, ''); - } else if (line.startsWith('id:')) { - lastEventId = line.replace(/^id:\s*/, ''); - } else if (line.startsWith('retry:')) { - const parsed = Number.parseInt( - line.replace(/^retry:\s*/, ''), - 10, - ); - if (!Number.isNaN(parsed)) { - retryDelay = parsed; - } - } - } - - let data: unknown; - let parsedJson = false; - - if (dataLines.length) { - const rawData = dataLines.join('\n'); - try { - data = JSON.parse(rawData); - parsedJson = true; - } catch { - data = rawData; - } - } - - if (parsedJson) { - if (responseValidator) { - await responseValidator(data); - } - - if (responseTransformer) { - data = await responseTransformer(data); - } - } - - onSseEvent?.({ - data, - event: eventName, - id: lastEventId, - retry: retryDelay, - }); - - if (dataLines.length) { - yield data as any; - } - } - } - } finally { - signal.removeEventListener('abort', abortHandler); - reader.releaseLock(); - } - - break; // exit loop on normal completion - } catch (error) { - // connection failed or aborted; retry after delay - onSseError?.(error); - - if ( - sseMaxRetryAttempts !== undefined && - attempt >= sseMaxRetryAttempts - ) { - break; // stop after firing error - } - - // exponential backoff: double retry each attempt, cap at 30s - const backoff = Math.min( - retryDelay * 2 ** (attempt - 1), - sseMaxRetryDelay ?? 30000, - ); - await sleep(backoff); - } - } - }; - - const stream = createStream(); - - return { stream }; -}; diff --git a/src/generated/core/types.gen.ts b/src/generated/core/types.gen.ts deleted file mode 100644 index cc8a9e6..0000000 --- a/src/generated/core/types.gen.ts +++ /dev/null @@ -1,118 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import type { Auth, AuthToken } from './auth.gen.js'; -import type { - BodySerializer, - QuerySerializer, - QuerySerializerOptions, -} from './bodySerializer.gen.js'; - -export type HttpMethod = - | 'connect' - | 'delete' - | 'get' - | 'head' - | 'options' - | 'patch' - | 'post' - | 'put' - | 'trace'; - -export type Client< - RequestFn = never, - Config = unknown, - MethodFn = never, - BuildUrlFn = never, - SseFn = never, -> = { - /** - * Returns the final request URL. - */ - buildUrl: BuildUrlFn; - getConfig: () => Config; - request: RequestFn; - setConfig: (config: Config) => Config; -} & { - [K in HttpMethod]: MethodFn; -} & ([SseFn] extends [never] - ? { sse?: never } - : { sse: { [K in HttpMethod]: SseFn } }); - -export interface Config { - /** - * Auth token or a function returning auth token. The resolved value will be - * added to the request payload as defined by its `security` array. - */ - auth?: ((auth: Auth) => Promise | AuthToken) | AuthToken; - /** - * A function for serializing request body parameter. By default, - * {@link JSON.stringify()} will be used. - */ - bodySerializer?: BodySerializer | null; - /** - * An object containing any HTTP headers that you want to pre-populate your - * `Headers` object with. - * - * {@link https://developer.mozilla.org/docs/Web/API/Headers/Headers#init See more} - */ - headers?: - | RequestInit['headers'] - | Record< - string, - | string - | number - | boolean - | (string | number | boolean)[] - | null - | undefined - | unknown - >; - /** - * The request method. - * - * {@link https://developer.mozilla.org/docs/Web/API/fetch#method See more} - */ - method?: Uppercase; - /** - * A function for serializing request query parameters. By default, arrays - * will be exploded in form style, objects will be exploded in deepObject - * style, and reserved characters are percent-encoded. - * - * This method will have no effect if the native `paramsSerializer()` Axios - * API function is used. - * - * {@link https://swagger.io/docs/specification/serialization/#query View examples} - */ - querySerializer?: QuerySerializer | QuerySerializerOptions; - /** - * A function validating request data. This is useful if you want to ensure - * the request conforms to the desired shape, so it can be safely sent to - * the server. - */ - requestValidator?: (data: unknown) => Promise; - /** - * A function transforming response data before it's returned. This is useful - * for post-processing data, e.g. converting ISO strings into Date objects. - */ - responseTransformer?: (data: unknown) => Promise; - /** - * A function validating response data. This is useful if you want to ensure - * the response conforms to the desired shape, so it can be safely passed to - * the transformers and returned to the user. - */ - responseValidator?: (data: unknown) => Promise; -} - -type IsExactlyNeverOrNeverUndefined = [T] extends [never] - ? true - : [T] extends [never | undefined] - ? [undefined] extends [T] - ? false - : true - : false; - -export type OmitNever> = { - [K in keyof T as IsExactlyNeverOrNeverUndefined extends true - ? never - : K]: T[K]; -}; diff --git a/src/generated/core/utils.gen.ts b/src/generated/core/utils.gen.ts deleted file mode 100644 index 3029f7b..0000000 --- a/src/generated/core/utils.gen.ts +++ /dev/null @@ -1,143 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import type { BodySerializer, QuerySerializer } from './bodySerializer.gen.js'; -import { - type ArraySeparatorStyle, - serializeArrayParam, - serializeObjectParam, - serializePrimitiveParam, -} from './pathSerializer.gen.js'; - -export interface PathSerializer { - path: Record; - url: string; -} - -export const PATH_PARAM_RE = /\{[^{}]+\}/g; - -export const defaultPathSerializer = ({ path, url: _url }: PathSerializer) => { - let url = _url; - const matches = _url.match(PATH_PARAM_RE); - if (matches) { - for (const match of matches) { - let explode = false; - let name = match.substring(1, match.length - 1); - let style: ArraySeparatorStyle = 'simple'; - - if (name.endsWith('*')) { - explode = true; - name = name.substring(0, name.length - 1); - } - - if (name.startsWith('.')) { - name = name.substring(1); - style = 'label'; - } else if (name.startsWith(';')) { - name = name.substring(1); - style = 'matrix'; - } - - const value = path[name]; - - if (value === undefined || value === null) { - continue; - } - - if (Array.isArray(value)) { - url = url.replace( - match, - serializeArrayParam({ explode, name, style, value }), - ); - continue; - } - - if (typeof value === 'object') { - url = url.replace( - match, - serializeObjectParam({ - explode, - name, - style, - value: value as Record, - valueOnly: true, - }), - ); - continue; - } - - if (style === 'matrix') { - url = url.replace( - match, - `;${serializePrimitiveParam({ - name, - value: value as string, - })}`, - ); - continue; - } - - const replaceValue = encodeURIComponent( - style === 'label' ? `.${value as string}` : (value as string), - ); - url = url.replace(match, replaceValue); - } - } - return url; -}; - -export const getUrl = ({ - baseUrl, - path, - query, - querySerializer, - url: _url, -}: { - baseUrl?: string; - path?: Record; - query?: Record; - querySerializer: QuerySerializer; - url: string; -}) => { - const pathUrl = _url.startsWith('/') ? _url : `/${_url}`; - let url = (baseUrl ?? '') + pathUrl; - if (path) { - url = defaultPathSerializer({ path, url }); - } - let search = query ? querySerializer(query) : ''; - if (search.startsWith('?')) { - search = search.substring(1); - } - if (search) { - url += `?${search}`; - } - return url; -}; - -export function getValidRequestBody(options: { - body?: unknown; - bodySerializer?: BodySerializer | null; - serializedBody?: unknown; -}) { - const hasBody = options.body !== undefined; - const isSerializedBody = hasBody && options.bodySerializer; - - if (isSerializedBody) { - if ('serializedBody' in options) { - const hasSerializedBody = - options.serializedBody !== undefined && options.serializedBody !== ''; - - return hasSerializedBody ? options.serializedBody : null; - } - - // not all clients implement a serializedBody property (i.e. client-axios) - return options.body !== '' ? options.body : null; - } - - // plain/text body - if (hasBody) { - return options.body; - } - - // no body was provided - return undefined; -} diff --git a/src/generated/index.ts b/src/generated/index.ts deleted file mode 100644 index 5556b3a..0000000 --- a/src/generated/index.ts +++ /dev/null @@ -1,4 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -export type * from './types.gen.js'; -export * from './sdk.gen.js'; diff --git a/src/generated/sdk.gen.ts b/src/generated/sdk.gen.ts deleted file mode 100644 index 53bf35a..0000000 --- a/src/generated/sdk.gen.ts +++ /dev/null @@ -1,4113 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -import { client } from './client.gen.js'; -import { type Client, formDataBodySerializer, type Options as Options2, type TDataShape } from './client/index.js'; -import type { AcknowledgeSlaMissVulnerabilityRemediationsData, AcknowledgeSlaMissVulnerabilityRemediationsResponses, AddControlFromLibraryData, AddControlFromLibraryResponses, AddControlToTrustCenterData, AddControlToTrustCenterResponses, AddDiscoveredVendorToManagedData, AddDiscoveredVendorToManagedResponses, AddDocumentToControlData, AddDocumentToControlResponses, AddPeopleToGroupData, AddPeopleToGroupResponses, AddPersonToGroupData, AddPersonToGroupResponses, AddTestToControlData, AddTestToControlResponses, AddTrustCenterControlCategoryData, AddTrustCenterControlCategoryResponses, AddTrustCenterResourceCategoryData, AddTrustCenterResourceCategoryResponses, AddTrustCenterViewerData, AddTrustCenterViewerResponses, ApproveQuestionnaireData, ApproveQuestionnaireResponses, ApproveTrustCenterAccessRequestData, ApproveTrustCenterAccessRequestResponses, CancelRiskScenarioApprovalRequestData, CancelRiskScenarioApprovalRequestResponses, ClearLeaveForPersonData, ClearLeaveForPersonResponses, CompleteQuestionnaireData, CompleteQuestionnaireResponses, CreateAnswerLibraryEntryData, CreateAnswerLibraryEntryResponses, CreateCustomControlData, CreateCustomControlResponses, CreateCustomerTrustAccountData, CreateCustomerTrustAccountResponses, CreateDocumentData, CreateDocumentResourceData, CreateDocumentResourceResponses, CreateDocumentResponses, CreateFileQuestionnaireData, CreateFileQuestionnaireResponses, CreateLinkForDocumentData, CreateLinkForDocumentResponses, CreateQuestionnaireExportData, CreateQuestionnaireExportResponses, CreateRiskScenarioControlData, CreateRiskScenarioControlResponses, CreateRiskScenarioData, CreateRiskScenarioResponses, CreateTrustCenterFaqData, CreateTrustCenterFaqResponses, CreateTrustCenterResourceData, CreateTrustCenterResourceResponses, CreateTrustCenterSubprocessorData, CreateTrustCenterSubprocessorResponses, CreateTrustCenterSubscriberData, CreateTrustCenterSubscriberGroupData, CreateTrustCenterSubscriberGroupResponses, CreateTrustCenterSubscriberResponses, CreateTrustCenterUpdateData, CreateTrustCenterUpdateResponses, CreateVendorData, CreateVendorFindingData, CreateVendorFindingResponses, CreateVendorResponses, CreateWebpageResourceData, CreateWebpageResourceResponses, CreateWebsiteQuestionnaireData, CreateWebsiteQuestionnaireResponses, DeactivateTestEntityData, DeactivateTestEntityResponses, DeactivateVulnerabilitiesData, DeactivateVulnerabilitiesResponses, DeleteAnswerLibraryEntryRouteData, DeleteAnswerLibraryEntryRouteResponses, DeleteByIdData, DeleteByIdResponses, DeleteContractData, DeleteContractResponses, DeleteControlData, DeleteControlResponses, DeleteCustomerTrustAccountData, DeleteCustomerTrustAccountResponses, DeleteDocumentData, DeleteDocumentForcontrolData, DeleteDocumentForcontrolResponses, DeleteDocumentResponses, DeleteFileForDocumentData, DeleteFileForDocumentResponses, DeleteFindingByIdData, DeleteFindingByIdResponses, DeleteKnowledgeBaseResourceData, DeleteKnowledgeBaseResourceResponses, DeleteLinkForDocumentData, DeleteLinkForDocumentResponses, DeleteQuestionnaireData, DeleteQuestionnaireResponses, DeleteRiskScenarioControlData, DeleteRiskScenarioControlResponses, DeleteSecurityReviewDocumentByIdData, DeleteSecurityReviewDocumentByIdResponses, DeleteTestForControlData, DeleteTestForControlResponses, DeleteTrustCenterControlCategoryData, DeleteTrustCenterControlCategoryResponses, DeleteTrustCenterControlData, DeleteTrustCenterControlResponses, DeleteTrustCenterFaqData, DeleteTrustCenterFaqResponses, DeleteTrustCenterResourceCategoryData, DeleteTrustCenterResourceCategoryResponses, DeleteTrustCenterResourceData, DeleteTrustCenterResourceResponses, DeleteTrustCenterSubprocessorData, DeleteTrustCenterSubprocessorResponses, DeleteTrustCenterSubscriberData, DeleteTrustCenterSubscriberGroupData, DeleteTrustCenterSubscriberGroupResponses, DeleteTrustCenterSubscriberResponses, DeleteTrustCenterUpdateData, DeleteTrustCenterUpdateResponses, DenyTrustCenterAccessRequestData, DenyTrustCenterAccessRequestResponses, GetAnswerLibraryEntryData, GetAnswerLibraryEntryResponses, GetConnectedIntegrationData, GetConnectedIntegrationResponses, GetContractData, GetContractResponses, GetControlData, GetControlResponses, GetCustomerTrustAccountData, GetCustomerTrustAccountResponses, GetDocumentData, GetDocumentResponses, GetFrameworkData, GetFrameworkResponses, GetGroupData, GetGroupMembersData, GetGroupMembersResponses, GetGroupResponses, GetKnowledgeBaseResourceData, GetKnowledgeBaseResourceResponses, GetMonitoredComputerData, GetMonitoredComputerResponses, GetPersonData, GetPersonResponses, GetPolicyData, GetPolicyResponses, GetQuestionnaireData, GetQuestionnaireExportData, GetQuestionnaireExportResponses, GetQuestionnaireResponses, GetResourceData, GetResourceKindDetailsData, GetResourceKindDetailsResponses, GetResourceResponses, GetRiskScenarioData, GetRiskScenarioResponses, GetSecurityReviewDocumentsData, GetSecurityReviewDocumentsResponses, GetSecurityReviewsByIdData, GetSecurityReviewsByIdResponses, GetSecurityReviewsByVendorIdData, GetSecurityReviewsByVendorIdResponses, GetTagsForCategoryData, GetTagsForCategoryResponses, GetTestData, GetTestEntitiesData, GetTestEntitiesResponses, GetTestResponses, GetTrustCenterAccessRequestData, GetTrustCenterAccessRequestResponses, GetTrustCenterControlCategoriesData, GetTrustCenterControlCategoriesResponses, GetTrustCenterControlCategoryData, GetTrustCenterControlCategoryResponses, GetTrustCenterControlData, GetTrustCenterControlResponses, GetTrustCenterData, GetTrustCenterFaqData, GetTrustCenterFaqResponses, GetTrustCenterResourceData, GetTrustCenterResourceMediaData, GetTrustCenterResourceMediaResponses, GetTrustCenterResourceResponses, GetTrustCenterResponses, GetTrustCenterSubprocessorData, GetTrustCenterSubprocessorResponses, GetTrustCenterSubscriberData, GetTrustCenterSubscriberGroupData, GetTrustCenterSubscriberGroupResponses, GetTrustCenterSubscriberResponses, GetTrustCenterUpdateData, GetTrustCenterUpdateResponses, GetTrustCenterViewerData, GetTrustCenterViewerResponses, GetUploadedfileMediaData, GetUploadedfileMediaResponses, GetUserData, GetUserResponses, GetVendorData, GetVendorResponses, GetVulnerabilityData, GetVulnerabilityResponses, GetVulnerableAssetData, GetVulnerableAssetResponses, ListAnswerLibraryEntriesData, ListAnswerLibraryEntriesResponses, ListAssignableUsersData, ListAssignableUsersResponses, ListConnectedIntegrationsData, ListConnectedIntegrationsResponses, ListContractsData, ListContractsResponses, ListControlsData, ListControlsForDocumentData, ListControlsForDocumentResponses, ListControlsForFrameworkData, ListControlsForFrameworkResponses, ListControlsResponses, ListCustomerTrustAccountsData, ListCustomerTrustAccountsResponses, ListDiscoveredVendorAccountsData, ListDiscoveredVendorAccountsResponses, ListDiscoveredVendorsData, ListDiscoveredVendorsResponses, ListDocumentsData, ListDocumentsForControlData, ListDocumentsForControlResponses, ListDocumentsResponses, ListEventLogsData, ListEventLogsResponses, ListFilesForDocumentData, ListFilesForDocumentResponses, ListFrameworksData, ListFrameworksResponses, ListKnowledgeBaseResourcesData, ListKnowledgeBaseResourcesResponses, ListLibraryControlsData, ListLibraryControlsResponses, ListLinksForDocumentData, ListLinksForDocumentResponses, ListMonitoredComputersData, ListMonitoredComputersResponses, ListPeopleData, ListPeopleResponses, ListPersonGroupsData, ListPersonGroupsResponses, ListPoliciesData, ListPoliciesResponses, ListQuestionnairesData, ListQuestionnairesResponses, ListResourceKindSummariesData, ListResourceKindSummariesResponses, ListResourcesData, ListResourcesResponses, ListRiskScenarioControlsData, ListRiskScenarioControlsResponses, ListRiskScenarioData, ListRiskScenarioResponses, ListTagCategoriesData, ListTagCategoriesResponses, ListTestsData, ListTestsForControlData, ListTestsForControlResponses, ListTestsResponses, ListTrustCenterAccessRequestsData, ListTrustCenterAccessRequestsResponses, ListTrustCenterActivityEventsData, ListTrustCenterActivityEventsResponses, ListTrustCenterControlsData, ListTrustCenterControlsResponses, ListTrustCenterFaqsData, ListTrustCenterFaqsResponses, ListTrustCenterHistoricalAccessRequestsData, ListTrustCenterHistoricalAccessRequestsResponses, ListTrustCenterResourceCategoriesData, ListTrustCenterResourceCategoriesResponses, ListTrustCenterResourcesData, ListTrustCenterResourcesResponses, ListTrustCenterSubprocessorsData, ListTrustCenterSubprocessorsResponses, ListTrustCenterSubscriberGroupsData, ListTrustCenterSubscriberGroupsResponses, ListTrustCenterSubscribersData, ListTrustCenterSubscribersResponses, ListTrustCenterUpdatesData, ListTrustCenterUpdatesResponses, ListTrustCenterViewersData, ListTrustCenterViewersResponses, ListUsersData, ListUsersResponses, ListVendorDocumentsData, ListVendorDocumentsResponses, ListVendorFindingsData, ListVendorFindingsResponses, ListVendorRiskAttributesData, ListVendorRiskAttributesResponses, ListVendorsData, ListVendorsResponses, ListVulnerabilitiesData, ListVulnerabilitiesResponses, ListVulnerabilityRemediationsData, ListVulnerabilityRemediationsResponses, ListVulnerableAssetsData, ListVulnerableAssetsResponses, MarkAsNotPeopleData, MarkAsNotPeopleResponses, MarkAsPeopleData, MarkAsPeopleResponses, OffboardPeopleData, OffboardPeopleResponses, ReactivateTestEntityData, ReactivateTestEntityResponses, ReactivateVulnerabilitiesData, ReactivateVulnerabilitiesResponses, RemovePeopleFromGroupData, RemovePeopleFromGroupResponses, RemovePersonFromGroupData, RemovePersonFromGroupResponses, RemoveTrustCenterViewerData, RemoveTrustCenterViewerResponses, ReplaceDocumentResourceFileData, ReplaceDocumentResourceFileResponses, SendNotificationsToAllSubscribersData, SendNotificationsToAllSubscribersResponses, SendTrustCenterUpdateNotificationsData, SendTrustCenterUpdateNotificationsResponses, SetLeaveForPersonData, SetLeaveForPersonResponses, SetOwnerForControlData, SetOwnerForControlResponses, SetOwnerForDocumentData, SetOwnerForDocumentResponses, SetStatusForVendorData, SetStatusForVendorResponses, SubmitDocumentCollectionData, SubmitDocumentCollectionResponses, SubmitRiskForApprovalData, SubmitRiskForApprovalResponses, UpdateAnswerLibraryEntryRouteData, UpdateAnswerLibraryEntryRouteResponses, UpdateControlMetadataData, UpdateControlMetadataResponses, UpdateCustomerTrustAccountData, UpdateCustomerTrustAccountResponses, UpdateDocumentResourceData, UpdateDocumentResourceResponses, UpdatePersonData, UpdatePersonResponses, UpdateQuestionnaireData, UpdateQuestionnaireResponses, UpdateResourceData, UpdateResourceResponses, UpdateResourcesData, UpdateResourcesResponses, UpdateRiskScenarioControlData, UpdateRiskScenarioControlResponses, UpdateRiskScenarioData, UpdateRiskScenarioResponses, UpdateTrustCenterControlCategoryData, UpdateTrustCenterControlCategoryResponses, UpdateTrustCenterData, UpdateTrustCenterFaqData, UpdateTrustCenterFaqResponses, UpdateTrustCenterResourceCategoryData, UpdateTrustCenterResourceCategoryResponses, UpdateTrustCenterResourceData, UpdateTrustCenterResourceResponses, UpdateTrustCenterResponses, UpdateTrustCenterSubprocessorData, UpdateTrustCenterSubprocessorResponses, UpdateTrustCenterSubscriberGroupData, UpdateTrustCenterSubscriberGroupResponses, UpdateTrustCenterUpdateData, UpdateTrustCenterUpdateResponses, UpdateTrustCenterViewerData, UpdateTrustCenterViewerResponses, UpdateVendorData, UpdateVendorFindingData, UpdateVendorFindingResponses, UpdateVendorResponses, UpdateWebpageResourceData, UpdateWebpageResourceResponses, UploadContractData, UploadContractResponses, UploadDocumentForSecurityReviewData, UploadDocumentForSecurityReviewResponses, UploadDocumentToVendorData, UploadDocumentToVendorResponses, UploadFileForDocumentData, UploadFileForDocumentResponses, UpsertGroupsForTrustCenterSubscriberData, UpsertGroupsForTrustCenterSubscriberResponses, UpsertTrustCenterResourceCategoriesOrderData, UpsertTrustCenterResourceCategoriesOrderResponses, VerifyAnswerLibraryEntryRouteData, VerifyAnswerLibraryEntryRouteResponses, VerifyKnowledgeBaseResourceData, VerifyKnowledgeBaseResourceResponses } from './types.gen.js'; - -export type Options = Options2 & { - /** - * You can provide a client instance returned by `createClient()` instead of - * individual options. This might be also useful if you want to implement a - * custom client. - */ - client?: Client; - /** - * You can pass arbitrary values through the `meta` object. This can be - * used to access values that aren't defined as part of the SDK function. - */ - meta?: Record; -}; - -/** - * List contracts - * - * List contracts, paginated. - */ -export const listContracts = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/contracts', - ...options - }); -}; - -/** - * Upload contract - * - * Upload a contract. - */ -export const uploadContract = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/contracts', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Delete contract - * - * Delete a contract by ID. - */ -export const deleteContract = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/contracts/{contractId}', - ...options - }); -}; - -/** - * Get contract - * - * Get a contract by ID. - */ -export const getContract = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/contracts/{contractId}', - ...options - }); -}; - -/** - * List controls - * - * List controls. - */ -export const listControls = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls', - ...options - }); -}; - -/** - * Create custom control - * - * Create a custom control. - */ -export const createCustomControl = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Add control from Vanta library - * - * Add a control from the Vanta library to your organization's controls. - */ -export const addControlFromLibrary = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/add-from-library', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Vanta controls from the library - * - * List Vanta controls from the library. - */ -export const listLibraryControls = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/controls-library', - ...options - }); -}; - -/** - * Deactivates a control - * - * Deactivates a custom or Vanta control. - */ -export const deleteControl = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}', - ...options - }); -}; - -/** - * Get control by an ID - * - * Get a control by an ID. - */ -export const getControl = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}', - ...options - }); -}; - -/** - * Update a control's metadata - * - * Update a control's metadata. - */ -export const updateControlMetadata = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Add control to document mapping - * - * Add a document to a control. - */ -export const addDocumentToControl = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/add-document-to-control', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Add control to test mapping - * - * Add a control to test mapping. - */ -export const addTestToControl = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/add-test-to-control', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List a control's documents - * - * List a control's documents. - */ -export const listDocumentsForControl = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/documents', - ...options - }); -}; - -/** - * Remove control from document mapping - * - * Remove a document by ID from a control. - */ -export const deleteDocumentForcontrol = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/documents/{documentId}', - ...options - }); -}; - -/** - * Set owner of a control - * - * Assign a control to a user or remove an owner from a control. - */ -export const setOwnerForControl = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/set-owner', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List a control's tests - * - * List a control's tests. - */ -export const listTestsForControl = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/tests', - ...options - }); -}; - -/** - * Remove control from test mapping - * - * Remove a control from test mapping. - */ -export const deleteTestForControl = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/controls/{controlId}/tests/{testId}', - ...options - }); -}; - -/** - * List customer trust accounts - * - * List customer trust accounts with pagination. - */ -export const listCustomerTrustAccounts = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/accounts', - ...options - }); -}; - -/** - * Create customer trust account - * - * Create a new customer trust account. - */ -export const createCustomerTrustAccount = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/accounts', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete customer trust account - * - * Delete a customer trust account by ID. - */ -export const deleteCustomerTrustAccount = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/accounts/{accountId}', - ...options - }); -}; - -/** - * Get customer trust account - * - * Get a specific customer trust account by ID. - */ -export const getCustomerTrustAccount = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/accounts/{accountId}', - ...options - }); -}; - -/** - * Update customer trust account - * - * Update a customer trust account by ID. - */ -export const updateCustomerTrustAccount = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/accounts/{accountId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List questionnaires - * - * List questionnaires with filtering and pagination. - */ -export const listQuestionnaires = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires', - ...options - }); -}; - -/** - * List assignable users - * - * List users who can be assigned as owner or approver on a questionnaire. - * - * When a role is specified, results are filtered to users with that role's required permission. - * When omitted, users assignable to either role are returned. - * Results can optionally be narrowed by a search string. - */ -export const listAssignableUsers = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/assignable-users', - ...options - }); -}; - -/** - * Create questionnaire export - * - * Creates an asynchronous export job for a questionnaire. The export processes in the background - * and typically completes within a few minutes depending on questionnaire size. - * - * Subscribe to the `v1.questionnaire.export-completed` and `v1.questionnaire.export-failed` webhook events to be notified when an export completes or fails. - * Use the returned `id` with the "getQuestionnaireExport" endpoint to retrieve the download URL once the export completes. - */ -export const createQuestionnaireExport = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/exports', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get questionnaire export status - * - * Retrieves the current status and result of a questionnaire export using the id received from either the `createQuestionnaireExport` endpoint or the `v1.questionnaire.export-completed` webhook payload. - * - * This endpoint utilizes a dynamic response schema that changes based on the value of the status field: - * - * - pending: The export is currently in the queue or processing. Only base metadata is returned. - * - completed: The export finished successfully. The response expands to include completedAt and a downloadUrl. This pre-signed URL is valid for 24 hours; if it expires, simply call this endpoint again to retrieve a fresh, active link. - * - failed: The process encountered an error. The response expands to include failedAt and an errorMessage detailing the reason for failure. - * - * Developers should first check the status string before attempting to access result-specific fields like downloadUrl or errorMessage. - */ -export const getQuestionnaireExport = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/exports/{id}', - ...options - }); -}; - -/** - * Create file questionnaire - * - * Create a new file-based questionnaire from an uploaded file (.xlsx, .docx, .pdf). File type is inferred as `SPREADSHEET` or `DOCUMENT` based on the uploaded file. - */ -export const createFileQuestionnaire = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/file', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Create website questionnaire - * - * Create a new website-based questionnaire from a portal URL. - * - * The portal URL is used to fetch questionnaire content from the target website. - */ -export const createWebsiteQuestionnaire = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/website', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete questionnaire - * - * Delete a questionnaire by ID. - */ -export const deleteQuestionnaire = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/{questionnaireId}', - ...options - }); -}; - -/** - * Get questionnaire by ID - * - * Retrieve a questionnaire by ID. - */ -export const getQuestionnaire = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/{questionnaireId}', - ...options - }); -}; - -/** - * Update questionnaire - * - * Update an existing questionnaire. - * - * Updates one or more fields of a questionnaire. - * This endpoint cannot be used to set a questionnaire's status to `APPROVED` or `COMPLETED`. To perform those specific transitions, please use the `approveQuestionnaire` and `completeQuestionnaire` endpoints, respectively. - */ -export const updateQuestionnaire = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/{questionnaireId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Approve questionnaire - * - * Mark a questionnaire as `APPROVED` and optionally provide a `statusChangeMessage`. - */ -export const approveQuestionnaire = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/{questionnaireId}/approve', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Complete questionnaire - * - * Complete a questionnaire and optionally sync approved answers to the answer library. - * - * Transitions the questionnaire status to COMPLETE. If `shouldSyncApprovedToAnswerLibrary` is true - * (the default), approved answers are added to the answer library for future use. For - * non-English SPREADSHEET or DOCUMENT questionnaires, answer library sync will be ignored. - */ -export const completeQuestionnaire = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/questionnaires/{questionnaireId}/complete', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List tag categories - * - * List user-defined tag categories. Optionally filter by product context. - */ -export const listTagCategories = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/tag-categories', - ...options - }); -}; - -/** - * Get tags for category - * - * Retrieve a tag category and its associated tags by category ID. - */ -export const getTagsForCategory = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/customer-trust/tag-categories/{tagCategoryId}', - ...options - }); -}; - -/** - * List discovered vendors - * - * List discovered vendors. - */ -export const listDiscoveredVendors = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/discovered-vendors', - ...options - }); -}; - -/** - * List of discovered vendor accounts - * - * List of discovered vendor accounts. - */ -export const listDiscoveredVendorAccounts = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/discovered-vendors/{discoveredVendorId}/accounts', - ...options - }); -}; - -/** - * Adds a discovered vendor to managed vendor by ID - * - * Add a discovered vendor to managed vendor. - */ -export const addDiscoveredVendorToManaged = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/discovered-vendors/{discoveredVendorId}/add-to-managed', - ...options - }); -}; - -/** - * List documents - * - * List documents. - */ -export const listDocuments = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents', - ...options - }); -}; - -/** - * Create a custom document - * - * Create a custom document. - */ -export const createDocument = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete document by ID - * - * Delete a document by ID. - */ -export const deleteDocument = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}', - ...options - }); -}; - -/** - * Get document by ID - * - * Get a document by ID. - */ -export const getDocument = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}', - ...options - }); -}; - -/** - * List document's controls - * - * List a document's associated controls. - */ -export const listControlsForDocument = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/controls', - ...options - }); -}; - -/** - * List document's links - * - * List the uploaded links for a document. - */ -export const listLinksForDocument = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/links', - ...options - }); -}; - -/** - * Create document link - * - * Create a link for a document. - */ -export const createLinkForDocument = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/links', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Remove document link - * - * Remove a link from a document. - */ -export const deleteLinkForDocument = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/links/{linkId}', - ...options - }); -}; - -/** - * Set document owner - * - * Assign or unassign a user to the document. - */ -export const setOwnerForDocument = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/set-owner', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Submit document collection - * - * Submit document collection. - */ -export const submitDocumentCollection = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/submit', - ...options - }); -}; - -/** - * List document's uploads - * - * List the uploaded files for a document. - */ -export const listFilesForDocument = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/uploads', - ...options - }); -}; - -/** - * Upload file for document - * - * Upload a file for a document. - */ -export const uploadFileForDocument = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/uploads', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Delete file for a document - * - * Delete a file for a document. - */ -export const deleteFileForDocument = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/uploads/{uploadedFileId}', - ...options - }); -}; - -/** - * Download file for document - * - * Download a file from a document. - */ -export const getUploadedfileMedia = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/documents/{documentId}/uploads/{uploadedFileId}/media', - ...options - }); -}; - -/** - * List event logs - * - * List event logs. - * - * See the [event log reference](/reference/manage-vanta/event-log-reference) for an inexhaustive list of `actor.type`, `action`, and `targets[].type` values. - */ -export const listEventLogs = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/event-logs', - ...options - }); -}; - -/** - * List available frameworks - * - * Lists available frameworks. - */ -export const listFrameworks = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/frameworks', - ...options - }); -}; - -/** - * Get framework by ID - * - * Get a framework by ID. - */ -export const getFramework = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/frameworks/{frameworkId}', - ...options - }); -}; - -/** - * List a framework's controls - * - * List a framework's controls. - */ -export const listControlsForFramework = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/frameworks/{frameworkId}/controls', - ...options - }); -}; - -/** - * List groups - * - * Lists all groups by ID. - */ -export const listPersonGroups = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups', - ...options - }); -}; - -/** - * Get group by ID - * - * Get a group by ID. - */ -export const getGroup = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}', - ...options - }); -}; - -/** - * Add people to group - * - * Add people to a group. - */ -export const addPeopleToGroup = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}/add-people', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List people in a group - * - * List people in a group. - */ -export const getGroupMembers = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}/people', - ...options - }); -}; - -/** - * Add person to a group - * - * Add a single person, by ID, to a group. - */ -export const addPersonToGroup = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}/people', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Remove person from a group - * - * Remove a single person, by ID, from a group. - */ -export const removePersonFromGroup = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}/people/{personId}', - ...options - }); -}; - -/** - * Remove people from group - * - * Remove people from a group. - */ -export const removePeopleFromGroup = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/groups/{groupId}/remove-people', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List connected integrations - * - * Lists all integrations connected to a Vanta instance. - */ -export const listConnectedIntegrations = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations', - ...options - }); -}; - -/** - * Get a connected integration - * - * Gets details for a specific integration by connection ID. - */ -export const getConnectedIntegration = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}', - ...options - }); -}; - -/** - * List integration resource kinds - * - * Lists a connected integration's resource types (kinds) such as S3Bucket or CloudwatchLogGroup. - */ -export const listResourceKindSummaries = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds', - ...options - }); -}; - -/** - * Get details for resource kind - * - * Gets details for a specific resource type (kind) such as S3Bucket or CloudwatchLogGroup. - */ -export const getResourceKindDetails = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}', - ...options - }); -}; - -/** - * List resources - * - * Lists resources for a specific integration and resource type (kind) such as S3Bucket or CloudwatchLogGroup. - */ -export const listResources = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources', - ...options - }); -}; - -/** - * Update resource metadata - * - * Updates metadata for multiple resources. - */ -export const updateResources = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get resource by ID - * - * Gets resource by its ID. - */ -export const getResource = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}', - ...options - }); -}; - -/** - * Update resource metadata - * - * Updates metadata for a specific resource such as an S3Bucket or CloudwatchLogGroup. - */ -export const updateResource = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Answer Library entries - * - * List Answer Library entries. Supports full-text search, tag filtering - * (OR across the given tags), and date-range filters on last-updated and - * expiration. - */ -export const listAnswerLibraryEntries = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library', - ...options - }); -}; - -/** - * Create Answer Library entry - * - * Create an Answer Library entry. - */ -export const createAnswerLibraryEntry = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Answer Library entry - * - * Delete an Answer Library entry. - */ -export const deleteAnswerLibraryEntryRoute = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library/{id}', - ...options - }); -}; - -/** - * Get Answer Library entry - * - * Get an Answer Library entry. - */ -export const getAnswerLibraryEntry = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library/{id}', - ...options - }); -}; - -/** - * Update Answer Library entry - * - * Update an Answer Library entry. - */ -export const updateAnswerLibraryEntryRoute = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library/{id}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Verify Answer Library entry - * - * Mark an Answer Library entry as verified. Stamps `lastVerifiedAt` to the - * current time; the entry's question, answer, tags, owner, and expiration - * are left unchanged. - */ -export const verifyAnswerLibraryEntryRoute = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/answer-library/{id}/verify', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Knowledge Base resources - * - * List Knowledge Base resources (documents and webpages) in a single - * paginated response. Each entry is a discriminated union on `type` — - * "FILE" entries carry a `fileUrl` (presigned S3 URL, valid for one - * hour), "URL" entries carry the resource's `url` and `includeSubPages`. - * - * Supports full-text search, type filtering, tag filtering (OR within - * a category, AND across categories), and date-range filters on - * last-updated and expiration. - */ -export const listKnowledgeBaseResources = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources', - ...options - }); -}; - -/** - * Create document resource - * - * Create a document (FILE-type) resource in the Trust Knowledge Base. - * Accepts the document as a multipart/form-data upload. - * - * Example: send `multipart/form-data` with a required `file` (e.g. PDF) - * and `title`; optional fields include `description`, `customerVisibility`, - * `downloadPermission`, `isUsedInQuestionnaires` ("true"/"false"), - * `expirationDate` (ISO 8601), `tags` (JSON array string), `categoryId`, - * and `ownerAssignment` (JSON object string). - */ -export const createDocumentResource = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/documents', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Update document resource - * - * Apply a partial update to a document (FILE-type) resource. Omitted - * fields are left untouched. To swap the underlying file, use - * `POST /v1/knowledge-base/resources/documents/{id}/upload`. Returns - * 404 for an unknown id or a URL-type resource. - */ -export const updateDocumentResource = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/documents/{id}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Replace document resource file - * - * Replace the underlying file on a document (FILE-type) resource with - * a new multipart upload. Other resource fields (title, description, - * visibility, tags, owner, etc.) are unchanged — use PATCH for those. - * Returns 404 for an unknown id or a URL-type resource. - * - * Example: send `multipart/form-data` with a single `file` field (the - * new document binary). - */ -export const replaceDocumentResourceFile = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/documents/{id}/upload', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Create webpage resource - * - * Create a webpage (URL-type) resource in the Trust Knowledge Base. - */ -export const createWebpageResource = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/webpages', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Update webpage resource - * - * Apply a partial update to a webpage (URL-type) resource. Omitted - * fields are left untouched. `description`, `ownerAssignment`, and - * `expirationDate` accept `null` to clear. The resource URL is not - * updatable here — recreate the resource if the URL needs to change. - * Returns 404 for an unknown id or a FILE-type resource. - */ -export const updateWebpageResource = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/webpages/{id}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Knowledge Base resource - * - * Hard-delete a Knowledge Base resource (FILE or URL) by id. Tears down - * the row plus its associated state (uploaded document for FILE rows, - * Trust Center references, Oso facts, chunk-store entries) via - * . - * - * Returns 404 when the id is unknown in the calling token's domain. - */ -export const deleteKnowledgeBaseResource = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/{id}', - ...options - }); -}; - -/** - * Get Knowledge Base resource - * - * Fetch a single Knowledge Base resource (FILE or URL) by id. Returns - * the same `type`-discriminated union as the list endpoint, so callers - * can branch on `type` without knowing the kind ahead of time. Returns - * 404 when the resource does not exist in the domain or — for FILE - * rows — when the underlying uploaded document has been deleted. - */ -export const getKnowledgeBaseResource = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/{id}', - ...options - }); -}; - -/** - * Verify Knowledge Base resource - * - * Mark a Knowledge Base resource (FILE or URL) as verified. Stamps - * `lastVerifiedAt` to the current time and resets `expiresAt` forward - * by the domain's configured review cadence; the resource's content - * (title, description, file or url, tags, owner) is left unchanged. - * Caller does not need to know the resource type — the persisted - * `resourceType` is used. Returns 404 when the id is unknown in the - * domain or — for FILE rows — when the underlying uploaded document - * has been deleted. - */ -export const verifyKnowledgeBaseResource = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/knowledge-base/resources/{id}/verify', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List monitored computers - * - * Returns a list of computers monitored by an MDM (with an integration built - * by Vanta) or by Vanta Device Monitor. Currently this list does not include - * resources from partner or customer-built integrations. - */ -export const listMonitoredComputers = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/monitored-computers', - ...options - }); -}; - -/** - * Get monitored computer by ID - * - * Returns a monitored computer by ID. - */ -export const getMonitoredComputer = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/monitored-computers/{computerId}', - ...options - }); -}; - -/** - * List people - * - * Returns a list of all people. - */ -export const listPeople = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people', - ...options - }); -}; - -/** - * Mark as not people - * - * Mark a set of accounts on the People Page as "not a person." As a result, - * these accounts will not be treated as people in Vanta, and you will not be able to - * assign them tasks or use them in tests related to your company's personnel. - */ -export const markAsNotPeople = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/mark-as-not-people', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Mark as people - * - * Mark a set of accounts on the People Page as "people." As a result, - * these accounts will be treated as people in Vanta, and you will be able to - * assign them tasks and use them in tests related to your company's personnel. - */ -export const markAsPeople = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/mark-as-people', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Offboard people - * - * Offboard a list of people. A person is only eligible for offboarding completion when: - * 1. They are an ex-employee. - * 2. All of the person's monitored accounts are deactivated or manually overwritten as such. - * 3. All of a person's custom offboarding tasks have been completed. - * All of the person's unmonitored accounts will be automatically marked as deactivated when they - * are offboarded. If the person has unfinished offboarding tasks those will NOT automatically be - * completed and offboarding them will fail. - */ -export const offboardPeople = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/offboard', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get person by ID - * - * Returns a person by ID. - */ -export const getPerson = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/{personId}', - ...options - }); -}; - -/** - * Update person metadata - * - * Update a person's basic information. - */ -export const updatePerson = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/{personId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Remove leave information - * - * Remove leave information on a person. The person will become active in Vanta, and will be considered in certain tests related to personnel. - */ -export const clearLeaveForPerson = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/{personId}/clear-leave', - ...options - }); -}; - -/** - * Set leave information - * - * Set leave information on a person. A person on leave is inactive in Vanta and will not - * be considered in certain personnel-related tests. If the person has existing leave information, it will be - * cleared and replaced. - */ -export const setLeaveForPerson = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/people/{personId}/set-leave', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List policies - * - * Lists all policies. - */ -export const listPolicies = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/policies', - ...options - }); -}; - -/** - * Get policy by ID - * - * Gets a policy by ID. Policy IDs can be found in Vanta in URL bar after /policies/. - */ -export const getPolicy = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/policies/{policyId}', - ...options - }); -}; - -/** - * List risk scenarios - * - * List risk scenarios. - */ -export const listRiskScenario = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios', - ...options - }); -}; - -/** - * Create risk scenario - * - * Create a new risk scenario. - */ -export const createRiskScenario = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get risk scenario by ID - * - * Get a risk scenario by ID (can be the Risk ID or the object ID). - */ -export const getRiskScenario = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}', - ...options - }); -}; - -/** - * Update risk scenario - * - * Update a risk scenario. - */ -export const updateRiskScenario = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Cancel risk scenario approval request - * - * Cancel approval request for a risk scenario. - */ -export const cancelRiskScenarioApprovalRequest = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/cancel-approval-request', - ...options - }); -}; - -/** - * List risk scenario controls - * - * List the controls associated with a risk scenario. - * - * Each item is a `{ controlId, controlType }` relationship. `controlType` is - * `TREATMENT_PLAN` for controls that are part of the risk's treatment plan, - * and `EXISTING` for controls linked without a treatment-plan designation. - */ -export const listRiskScenarioControls = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/controls', - ...options - }); -}; - -/** - * Add a control to a risk scenario - * - * Associate a control with a risk scenario. - * - * Body: `{ controlId, controlType? }`. `controlType` is `TREATMENT_PLAN` - * for a control that is part of the risk's treatment plan; omit it (or pass - * `EXISTING`) to associate the control as a plain existing control. - * - * `controlId` may be a Vanta control shorthand, custom-control shorthand, - * or object ID; it resolves to a single canonical control before any write. - * - * Behavior on conflict with an existing association: - * - Same resolved control already associated with the same `controlType`: - * - * the request is a no-op and the existing relationship is returned (200). - * - Same resolved control associated with the other `controlType`: the - * - * request is rejected with a hint to use `PATCH` instead (422). - */ -export const createRiskScenarioControl = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/controls', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Remove a control from a risk scenario - * - * Remove a control from a risk scenario. - * - * Fully unlinks the control regardless of whether it is currently a - * `TREATMENT_PLAN` or an `EXISTING` control. To only drop the - * treatment-plan designation while keeping the control linked, use - * `PATCH { "controlType": "EXISTING" }` instead. Deleting an already-unlinked - * control is an idempotent no-op (204). - */ -export const deleteRiskScenarioControl = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/controls/{controlId}', - ...options - }); -}; - -/** - * Change a risk scenario control's controlType - * - * Change the `controlType` on an existing risk-scenario / control - * association. - * - * Body: `{ controlType }`. The server atomically moves the resolved control - * between the treatment-plan and existing-control sets in a single update — - * there is no intermediate unlinked state. `PATCH { "controlType": "EXISTING" }` - * removes the control from the treatment plan but keeps it linked as an - * existing control; use `DELETE` to unlink it entirely. - * - * Returns 404 if the control is not currently associated with the scenario. - * Setting the `controlType` it already has is a 200 no-op. - */ -export const updateRiskScenarioControl = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/controls/{controlId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Submit risk scenario for approval - * - * Submit a risk scenario for approval. - */ -export const submitRiskForApproval = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/risk-scenarios/{riskScenarioId}/submit-for-approval', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List tests - * - * Lists all tests based on applied filters. - */ -export const listTests = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/tests', - ...options - }); -}; - -/** - * Get test by ID - * - * Gets a test by ID. Test IDs can be found in Vanta in URL bar after /tests/. - */ -export const getTest = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/tests/{testId}', - ...options - }); -}; - -/** - * Get test entities by test ID - * - * Gets a list of tested items (entities) for a test by test ID. An entity is a tested item that can have its own outcome. - * For example, for a test that makes sure that all S3 buckets are versioned, an individual S3 bucket would be an entity. - */ -export const getTestEntities = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/tests/{testId}/entities', - ...options - }); -}; - -/** - * Deactivate test entity - * - * Deactivates a single test item (test entity). - * There may be a delay in the deactivation of the test entity until the next test run. - * Use the /vulnerabilities/deactivate endpoint for vulnerabilities. - */ -export const deactivateTestEntity = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/tests/{testId}/entities/{entityId}/deactivate', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Reactivate test entity - * - * Reactivates a single tested item (test entity). - * There may be a delay in the reactivation of the test entity until the next test run. - * Use the /vulnerabilities/reactivate endpoint for vulnerabilities. - */ -export const reactivateTestEntity = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/tests/{testId}/entities/{entityId}/reactivate', - ...options - }); -}; - -/** - * Get Trust Center - * - * Gets a Trust Center by slug ID. - */ -export const getTrustCenter = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}', - ...options - }); -}; - -/** - * Update Trust Center - * - * Updates a Trust Center by slug ID. - */ -export const updateTrustCenter = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center access requests - * - * Gets a list of access requests for a Trust Center. - */ -export const listTrustCenterAccessRequests = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/access-requests', - ...options - }); -}; - -/** - * Get Trust Center access request - * - * Gets a specific access request for a Trust Center. - */ -export const getTrustCenterAccessRequest = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}', - ...options - }); -}; - -/** - * Approve Trust Center access request - * - * Approves an access request on a Trust Center. - */ -export const approveTrustCenterAccessRequest = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}/approve', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Deny Trust Center access request - * - * Denies an access request on a Trust Center. - */ -export const denyTrustCenterAccessRequest = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}/deny', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center viewer activity events - * - * Gets a list of viewer activity events on a Trust Center. - */ -export const listTrustCenterActivityEvents = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/activity', - ...options - }); -}; - -/** - * List Trust Center control categories - * - * Gets a list of control categories on a Trust Center. - */ -export const getTrustCenterControlCategories = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/control-categories', - ...options - }); -}; - -/** - * Add Trust Center control category - * - * Adds a control category to a Trust Center. - */ -export const addTrustCenterControlCategory = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/control-categories', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center control category - * - * Removes a control category from a Trust Center along with all of the - * controls in the category. - */ -export const deleteTrustCenterControlCategory = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/control-categories/{categoryId}', - ...options - }); -}; - -/** - * Get Trust Center control category - * - * Gets a specific control category on a Trust Center. - */ -export const getTrustCenterControlCategory = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/control-categories/{categoryId}', - ...options - }); -}; - -/** - * Update Trust Center control category - * - * Updates a control category on a Trust Center. - */ -export const updateTrustCenterControlCategory = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/control-categories/{categoryId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center controls - * - * Gets a list of controls on a Trust Center. - */ -export const listTrustCenterControls = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/controls', - ...options - }); -}; - -/** - * Add Trust Center control - * - * Adds a control to a Trust Center. - */ -export const addControlToTrustCenter = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/controls', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center control - * - * Removes a specific control from a Trust Center. This removes the control - * from all of the control categories that is in. - */ -export const deleteTrustCenterControl = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/controls/{controlId}', - ...options - }); -}; - -/** - * Get Trust Center control - * - * Gets a specific control on a Trust Center. - */ -export const getTrustCenterControl = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/controls/{controlId}', - ...options - }); -}; - -/** - * List Trust Center FAQs - * - * Gets a list of FAQs on a Trust Center. - */ -export const listTrustCenterFaqs = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/faqs', - ...options - }); -}; - -/** - * Create Trust Center FAQ - * - * Adds an FAQ to a Trust Center. - */ -export const createTrustCenterFaq = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/faqs', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center FAQ - * - * Remove a specific FAQ from the Trust Center by ID. - */ -export const deleteTrustCenterFaq = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/faqs/{faqId}', - ...options - }); -}; - -/** - * Get Trust Center FAQ - * - * Gets a specific FAQ on the Trust Center by ID. - */ -export const getTrustCenterFaq = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/faqs/{faqId}', - ...options - }); -}; - -/** - * Update Trust Center FAQ - * - * Update a specific FAQ on the Trust Center by ID. - */ -export const updateTrustCenterFaq = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/faqs/{faqId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List historical Trust Center access requests - * - * Gets a list of historical (approved or denied) access requests for a Trust Center. - */ -export const listTrustCenterHistoricalAccessRequests = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/historical-access-requests', - ...options - }); -}; - -/** - * List Trust Center resource categories - * - * Gets a list of resource categories on a Trust Center. - */ -export const listTrustCenterResourceCategories = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resource-categories', - ...options - }); -}; - -/** - * Add Trust Center resource category - * - * Adds a resource category to a Trust Center. - */ -export const addTrustCenterResourceCategory = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resource-categories', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Reorder Trust Center resource categories - * - * Reorders resource categories on a Trust Center. The request body must - * contain the complete set of category IDs in the desired order. - */ -export const upsertTrustCenterResourceCategoriesOrder = (options: Options) => { - return (options.client ?? client).put({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resource-categories/order', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center resource category - * - * Removes a resource category from a Trust Center. Resources in the - * deleted category are moved to uncategorized. - */ -export const deleteTrustCenterResourceCategory = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resource-categories/{categoryId}', - ...options - }); -}; - -/** - * Update Trust Center resource category - * - * Updates a resource category on a Trust Center. - */ -export const updateTrustCenterResourceCategory = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resource-categories/{categoryId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center resources - * - * Gets a list of resources on a Trust Center. - */ -export const listTrustCenterResources = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources', - ...options - }); -}; - -/** - * Create Trust Center document - * - * Adds a document to a Trust Center. - */ -export const createTrustCenterResource = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Delete Trust Center document - * - * Removes a specific document from a Trust Center. - */ -export const deleteTrustCenterResource = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources/{resourceId}', - ...options - }); -}; - -/** - * Get Trust Center document - * - * Gets a specific document on a Trust Center. - */ -export const getTrustCenterResource = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources/{resourceId}', - ...options - }); -}; - -/** - * Update Trust Center document - * - * Updates a specific document on a Trust Center. - */ -export const updateTrustCenterResource = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources/{resourceId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get uploaded media for Trust Center document - * - * Gets the actual given uploaded document for a Trust Center. - */ -export const getTrustCenterResourceMedia = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/resources/{resourceId}/media', - ...options - }); -}; - -/** - * List Trust Center subprocessors - * - * Gets the list of subprocessors on a Trust Center. - */ -export const listTrustCenterSubprocessors = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subprocessors', - ...options - }); -}; - -/** - * Create Trust Center subprocessor - * - * Adds a subprocessor to a Trust Center. - */ -export const createTrustCenterSubprocessor = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subprocessors', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center subprocessor - * - * Removes a subprocessor from a Trust Center. - */ -export const deleteTrustCenterSubprocessor = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}', - ...options - }); -}; - -/** - * Get Trust Center subprocessor - * - * Gets a specific subprocessor on a Trust Center. - */ -export const getTrustCenterSubprocessor = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}', - ...options - }); -}; - -/** - * Update Trust Center subprocessor - * - * Updates a subprocessor on a Trust Center. - */ -export const updateTrustCenterSubprocessor = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center subscriber groups - * - * Gets a list of subscriber groups on a Trust Center. - */ -export const listTrustCenterSubscriberGroups = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscriber-groups', - ...options - }); -}; - -/** - * Create Trust Center subscriber group - * - * Adds a subscriber group to a Trust Center. - */ -export const createTrustCenterSubscriberGroup = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscriber-groups', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center subscriber group - * - * Removes a subscriber group from a Trust Center. - */ -export const deleteTrustCenterSubscriberGroup = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}', - ...options - }); -}; - -/** - * Get Trust Center subscriber group - * - * Get a subscriber group by ID. - */ -export const getTrustCenterSubscriberGroup = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}', - ...options - }); -}; - -/** - * Edit Trust Center subscriber group - * - * Edits a Trust Center subscriber group. - */ -export const updateTrustCenterSubscriberGroup = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center subscribers - * - * Gets a list of subscribers on a Trust Center. - */ -export const listTrustCenterSubscribers = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscribers', - ...options - }); -}; - -/** - * Create Trust Center subscriber - * - * Adds a subscriber to a Trust Center. - */ -export const createTrustCenterSubscriber = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscribers', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center subscriber - * - * Removes a subscriber from a Trust Center. - */ -export const deleteTrustCenterSubscriber = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscribers/{subscriberId}', - ...options - }); -}; - -/** - * Get Trust Center subscriber - * - * Gets a specific subscriber on a Trust Center. - */ -export const getTrustCenterSubscriber = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscribers/{subscriberId}', - ...options - }); -}; - -/** - * Set groups for a Trust Center subscriber - * - * Sets groups on a subscriber. - */ -export const upsertGroupsForTrustCenterSubscriber = (options: Options) => { - return (options.client ?? client).put({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/subscribers/{subscriberId}/groups', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center updates - * - * Gets a list of updates on a Trust Center. - */ -export const listTrustCenterUpdates = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates', - ...options - }); -}; - -/** - * Create Trust Center update - * - * Adds an update to a Trust Center. - */ -export const createTrustCenterUpdate = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete Trust Center update - * - * Removes an update from a Trust Center. - */ -export const deleteTrustCenterUpdate = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates/{updateId}', - ...options - }); -}; - -/** - * Get Trust Center update - * - * Gets a specific update on a Trust Center. - */ -export const getTrustCenterUpdate = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates/{updateId}', - ...options - }); -}; - -/** - * Update Trust Center update - * - * Updates an update on a Trust Center. - */ -export const updateTrustCenterUpdate = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates/{updateId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Send Trust Center update notifications to all subscribers - * - * Sends notifications for a specific Trust Center update to all subscribers. - */ -export const sendNotificationsToAllSubscribers = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates/{updateId}/notify-all-subscribers', - ...options - }); -}; - -/** - * Send Trust Center update notifications to specific subscribers - * - * Sends notifications for a specific Trust Center update to specific subscribers. - * At least one subscriber group or email address is required. - * - * The total number of resolved, deduplicated recipient emails must not exceed 5,000. - * If exceeded, a 422 error is returned. Narrow your filters or split across multiple requests. - */ -export const sendTrustCenterUpdateNotifications = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/updates/{updateId}/notify-specific-subscribers', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List Trust Center viewers - * - * Gets a list of viewers that have been granted access to a Trust Center. - */ -export const listTrustCenterViewers = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/viewers', - ...options - }); -}; - -/** - * Add Trust Center viewer - * - * Adds a viewer and grants them access to a Trust Center. - */ -export const addTrustCenterViewer = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/viewers', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Remove Trust Center viewer - * - * Revokes a viewer's access to a Trust Center. - */ -export const removeTrustCenterViewer = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/viewers/{viewerId}', - ...options - }); -}; - -/** - * Get Trust Center viewer - * - * Gets a specific viewer for a Trust Center. - */ -export const getTrustCenterViewer = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/viewers/{viewerId}', - ...options - }); -}; - -/** - * Update Trust Center viewer - * - * Updates a viewer's access on a Trust Center. - */ -export const updateTrustCenterViewer = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/trust-centers/{slugId}/viewers/{viewerId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List active users - * - * Returns a list of all active users. - */ -export const listUsers = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/users', - ...options - }); -}; - -/** - * Get user by ID - * - * Returns a user by ID. - */ -export const getUser = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/users/{userId}', - ...options - }); -}; - -/** - * List vendor risk attributes - * - * Returns a list of vendor risk attributes. - */ -export const listVendorRiskAttributes = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendor-risk-attributes', - ...options - }); -}; - -/** - * List vendors - * - * List of vendors. - */ -export const listVendors = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors', - ...options - }); -}; - -/** - * Create a vendor - * - * Add vendor with metadata. - */ -export const createVendor = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete vendor by ID - * - * Deletes a vendor. - */ -export const deleteById = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}', - ...options - }); -}; - -/** - * Get vendor by ID - * - * Get a vendor. - */ -export const getVendor = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}', - ...options - }); -}; - -/** - * Update vendor by ID - * - * Update vendor. - */ -export const updateVendor = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List vendor documents - * - * Returns a vendor's list of documents. - */ -export const listVendorDocuments = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/documents', - ...options - }); -}; - -/** - * Add document to a vendor - * - * Add document to a vendor. - */ -export const uploadDocumentToVendor = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/documents', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * List vendor findings - * - * Lists a vendor's findings. - */ -export const listVendorFindings = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/findings', - ...options - }); -}; - -/** - * Add a vendor finding - * - * Add vendor finding. - */ -export const createVendorFinding = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/findings', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Delete finding by ID - * - * Deletes a finding. - */ -export const deleteFindingById = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/findings/{findingId}', - ...options - }); -}; - -/** - * Update vendor finding - * - * Update vendor finding. - */ -export const updateVendorFinding = (options: Options) => { - return (options.client ?? client).patch({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/findings/{findingId}', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List security reviews by vendor ID - * - * Returns a vendor's security reviews. - */ -export const getSecurityReviewsByVendorId = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/security-reviews', - ...options - }); -}; - -/** - * Get security review by ID - * - * Returns a security review. - */ -export const getSecurityReviewsById = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}', - ...options - }); -}; - -/** - * List security review documents - * - * Lists a security review's documents. - */ -export const getSecurityReviewDocuments = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents', - ...options - }); -}; - -/** - * Add document to security review - * - * Add document to a security review. - */ -export const uploadDocumentForSecurityReview = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Delete a security review document by ID - * - * Delete a security review document. - */ -export const deleteSecurityReviewDocumentById = (options: Options) => { - return (options.client ?? client).delete({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents/{documentId}', - ...options - }); -}; - -/** - * Set vendor status - * - * Sets the status of a vendor, which can be MANAGED, ARCHIVED, or IN_PROCUREMENT. - */ -export const setStatusForVendor = (options: Options) => { - return (options.client ?? client).post({ - ...formDataBodySerializer, - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vendors/{vendorId}/set-status', - ...options, - headers: { - 'Content-Type': null, - ...options.headers - } - }); -}; - -/** - * Get vulnerabilities - * - * List all vulnerabilities based on selected filters. - */ -export const listVulnerabilities = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerabilities', - ...options - }); -}; - -/** - * Deactivate vulnerability monitoring for a vulnerability - * - * Deactivate monitoring for select vulnerabilities. - * Vanta will not monitor a deactivated vulnerability until it is reactivated. - */ -export const deactivateVulnerabilities = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerabilities/deactivate', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Reactivate vulnerability monitoring - * - * Reactivate vulnerabilities and resume Vanta monitoring. - */ -export const reactivateVulnerabilities = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerabilities/reactivate', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * Get vulnerability by ID - * - * Gets a vulnerability by an ID. - */ -export const getVulnerability = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerabilities/{vulnerabilityId}', - ...options - }); -}; - -/** - * List vulnerability remediations - * - * List all vulnerability remediations based on selected filters. - */ -export const listVulnerabilityRemediations = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerability-remediations', - ...options - }); -}; - -/** - * Acknowledge SLA miss - * - * Acknowledge an SLA miss for a vulnerability remediation. - */ -export const acknowledgeSlaMissVulnerabilityRemediations = (options: Options) => { - return (options.client ?? client).post({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerability-remediations/acknowledge-sla-miss', - ...options, - headers: { - 'Content-Type': 'application/json', - ...options.headers - } - }); -}; - -/** - * List assets associated with vulnerabilities - * - * List assets that Vanta monitors that are associated with vulnerabilities. - */ -export const listVulnerableAssets = (options?: Options) => { - return (options?.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerable-assets', - ...options - }); -}; - -/** - * Get vulnerable asset by ID - * - * Gets a vulnerable asset by ID. - */ -export const getVulnerableAsset = (options: Options) => { - return (options.client ?? client).get({ - security: [ - { - scheme: 'bearer', - type: 'http' - } - ], - url: '/vulnerable-assets/{vulnerableAssetId}', - ...options - }); -}; diff --git a/src/generated/types.gen.ts b/src/generated/types.gen.ts deleted file mode 100644 index f1d0699..0000000 --- a/src/generated/types.gen.ts +++ /dev/null @@ -1,10520 +0,0 @@ -// This file is auto-generated by @hey-api/openapi-ts - -export type ClientOptions = { - baseUrl: 'https://api.vanta.com/v1' | 'https://api.vanta-gov.com/v1' | (string & {}); -}; - -/** - * VulnerableAssetType describes the types of assets a vulnerability is on. - */ -export type VulnerableAssetType = 'SERVER' | 'SERVERLESS_FUNCTION' | 'CONTAINER' | 'CONTAINER_REPOSITORY' | 'CONTAINER_REPOSITORY_IMAGE' | 'CODE_REPOSITORY' | 'MANIFEST_FILE' | 'WORKSTATION' | 'OTHER'; - -export type KeyValuePair = { - /** - * Key of key-value pair. - */ - key: string; - /** - * Value of key-value pair. - */ - value: string; -}; - -export type VulnerableAssetScanner = { - /** - * The scanned asset's Vanta resource id. - */ - resourceId: string; - /** - * Integration that the the vulnerable asset is scanned by. - */ - integrationId: string; - /** - * Digest of the scanned container image. - */ - imageDigest: string | null; - /** - * Push date of the scanned container image. - */ - imagePushedAtDate: string | null; - /** - * Tags of the scanned container image. - */ - imageTags: Array | null; - /** - * Tags of the scanned asset. - */ - assetTags: Array | null; - /** - * The parent account or organization of the scanned asset. - */ - parentAccountOrOrganization: string | null; - /** - * BIOS UUID of the scanned asset. - */ - biosUuid: string | null; - /** - * IPV4s of the scanned asset. - */ - ipv4s: Array | null; - /** - * IPV6s of the scanned asset. - */ - ipv6s: Array | null; - /** - * Mac addresses of the scanned asset. - */ - macAddresses: Array | null; - /** - * Host names of the scanned asset. - */ - hostnames: Array | null; - /** - * fqdns of the scanned asset. - */ - fqdns: Array | null; - /** - * Operating systems of the scanned asset. - */ - operatingSystems: Array | null; - /** - * The asset's identifier code. - */ - targetId: string | null; -}; - -export type VulnerableAsset = { - /** - * Unique identifier for the vulnerable asset. - */ - id: string; - /** - * Display name of the vulnerable asset. - */ - name: string; - assetType: VulnerableAssetType; - /** - * Whether the vulnerable asset has been scanned. - */ - hasBeenScanned: boolean; - /** - * Only relevant for container repositories. This field sets the container image tag that vulnerabilities will be retrieved for. If null, the latest image will be retrieved. - */ - imageScanTag: string | null; - /** - * The integrations that are scanning this vulnerable asset. - */ - scanners: Array; -}; - -/** - * Provides information about the pagination of a dataset. - */ -export type PageInfo = { - /** - * The cursor that points to the end of the current page, or null if there is no such cursor. - */ - endCursor: string | null; - /** - * Indicates if there is another page after the current page. - */ - hasNextPage: boolean; - /** - * Indicates if there is a page before the current page. - */ - hasPreviousPage: boolean; - /** - * The cursor that points to the start of the current page, or null if there is no such cursor. - */ - startCursor: string | null; -}; - -export type PaginatedResponseVulnerableAsset = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Controls the maximum number of items returned in one response from the API. - */ -export type PageSize = number; - -/** - * A marker or pointer, telling the API where to start fetching items for the subsequent page in a paginated dataset. - * Note that the requested page will not include the item that corresponds to this cursor but will start from the one immediately - * after this cursor. - */ -export type PageCursor = string; - -export type VulnerabilityRemediation = { - /** - * Unique identifier for the remediation. - */ - id: string; - /** - * Unique identifier for the vulnerability that the remediation is for. - */ - vulnerabilityId: string; - /** - * Unique identifier for the vulnerable asset that the remediation is for. - */ - vulnerableAssetId: string; - /** - * Severity of the vulnerability. - */ - severity: string; - /** - * Date when the vulnerability was first detected. - */ - detectedDate: string | null; - /** - * Date when the vulnerability should be remediated by. - */ - slaDeadlineDate: string | null; - /** - * Date when the vulnerability was remediated. - */ - remediationDate: string | null; -}; - -export type PaginatedResponseVulnerabilityRemediation = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * ExternalFindingSeverity describes the severity of an external finding (Vulnerability or Security Alert) - */ -export type ExternalFindingSeverity = 'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM'; - -export type ResultLineStatusSuccess = 'SUCCESS'; - -export type SuccessResponse = { - /** - * Id of the record - */ - id: string; - status: ResultLineStatusSuccess; -}; - -export type ResultLineStatusError = 'ERROR'; - -export type ExcludeResultLineStatusSuccess = ResultLineStatusError; - -export type NonSuccessResponse = { - /** - * Id of the record - */ - id: string; - status: ExcludeResultLineStatusSuccess; - /** - * Message an error message - */ - message: string; -}; - -export type UpdateResponse = SuccessResponse | NonSuccessResponse; - -export type BulkResponse = { - /** - * List of results matching the length and order of the request - */ - results: Array; -}; - -export type VulnerabilityType = 'CONFIGURATION' | 'COMMON' | 'GROUPED'; - -export type ExternalFindingSeverityType = 'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM'; - -export type Vulnerability = { - /** - * Unique identifier for the vulnerability. - */ - id: string; - /** - * Display name of the vulnerability. - */ - name: string; - /** - * Description of the vulnerability. - */ - description: string; - /** - * Integration that the vulnerability is scanned by. - */ - integrationId: string; - /** - * Identifier for the package that the vulnerability is found on. - * Only relevant to vulnerabilities of type COMMON or GROUPED. - */ - packageIdentifier: string | null; - vulnerabilityType: VulnerabilityType; - /** - * Unique identifier for the underlying resource that the vulnerability is found on. - */ - targetId: string; - /** - * Date when the vulnerability was first detected by Vanta. - */ - firstDetectedDate: string; - /** - * Date when the vulnerability was first detected by the source. - */ - sourceDetectedDate: string | null; - /** - * Date when the vulnerability was last detected. - */ - lastDetectedDate: string | null; - severity: ExternalFindingSeverityType; - /** - * CVSS severity score of the vulnerability. - */ - cvssSeverityScore: number | null; - /** - * Scanner score of the vulnerability. - */ - scannerScore: number | null; - /** - * Whether the vulnerability is fixable. - */ - isFixable: boolean; - /** - * Date when the vulnerability should be remediated by. - */ - remediateByDate: string | null; - /** - * Related vulnerabilities. - * Only relevant to vulnerabilities of type GROUPED. - */ - relatedVulns: Array; - /** - * Related URLs. - */ - relatedUrls: Array; - /** - * External URL for the vulnerability. - */ - externalURL: string; - /** - * Scanning tool that detected the vulnerability - */ - scanSource?: string; - /** - * Metadata for the deactivation of the vulnerability. - */ - deactivateMetadata: { - /** - * Whether the vulnerability is deactivated indefinitely. - */ - isVulnDeactivatedIndefinitely: boolean; - /** - * Date when the vulnerability will be reactivated. - */ - deactivatedUntilDate: string | null; - /** - * Reason for deactivating the vulnerability. - */ - deactivationReason: string; - /** - * Date when the vulnerability was deactivated. - */ - deactivatedOnDate: string; - /** - * Identifier of the user who deactivated the vulnerability. - */ - deactivatedBy: string; - } | null; - /** - * Package version that remediates the vulnerability when reported by the scanner. - * Null when unknown or not applicable. - */ - fixedVersion: string | null; - /** - * Identifier for the affected asset in the source system that detected the vulnerability. - */ - externalId: string | null; -}; - -export type PaginatedResponseVulnerability = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type VulnerabilityDeactivateRequest = { - /** - * ID of the vulnerability to deactivate. - */ - id: string; - /** - * Date until which the vulnerability should be deactivated. - */ - deactivateUntilDate?: string; - /** - * Reason for deactivating the vulnerability. - */ - deactivateReason: string; - /** - * Determines whether or not vulnerabilities should reactivate when they become fixable. - */ - shouldReactivateWhenFixable: boolean; -}; - -/** - * The authentication method a vendor uses: - * - AUTH_0: The vendor authenticates using Auth0 - * - AZURE_AD: The vendor authenticates using Azure Active Directory - * - G_SUITE: The vendor authenticates using Google Workspace - * - O_AUTH: The vendor authenticates using OAuth - * - O365: The vendor authenticates using Office 365 - * - OKTA: The vendor authenticates using Okta - * - ONE_LOGIN: The vendor authenticates using OneLogin - * - OWA: The vendor authenticates using OWA - * - SSO: The vendor authenticates using SSO - * - USERNAME_PASSWORD: The vendor authenticates using usernames and passwords - */ -export type VendorAuthenticationMethod = 'AUTH_0' | 'AZURE_AD' | 'GOOGLE_WORKSPACE' | 'O_AUTH' | 'O365' | 'OKTA' | 'ONE_LOGIN' | 'OWA' | 'SSO' | 'USERNAME_PASSWORD' | 'OTHER'; - -/** - * The current state of a vendor: - * - MANAGED: The vendor is actively managed. - * - ARCHIVED: The vendor has been archived - * - IN_PROCUREMENT: The vendor is in the procurement process - */ -export type VendorStatus = 'MANAGED' | 'ARCHIVED' | 'IN_PROCUREMENT'; - -/** - * The risk level of a vendor: - * - CRITICAL: The vendor has a critical security risk - * - HIGH: The vendor has a high security risk - * - MEDIUM: The vendor has a medium security risk - * - LOW: The vendor has a low security risk - * - UNSCORED: The vendor has not been given a risk level - */ -export type VendorRiskLevel = 'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM' | 'UNSCORED'; - -export type CountryCode = 'EUE' | 'AND' | 'ARE' | 'AFG' | 'ATG' | 'AIA' | 'ALB' | 'ARM' | 'AGO' | 'ATA' | 'ARG' | 'ASM' | 'AUT' | 'AUS' | 'ABW' | 'ALA' | 'AZE' | 'BIH' | 'BRB' | 'BGD' | 'BEL' | 'BFA' | 'BGR' | 'BHR' | 'BDI' | 'BEN' | 'BLM' | 'BMU' | 'BRN' | 'BOL' | 'BES' | 'BRA' | 'BHS' | 'BTN' | 'BVT' | 'BWA' | 'BLR' | 'BLZ' | 'CAN' | 'CCK' | 'COD' | 'CAF' | 'COG' | 'CHE' | 'CIV' | 'COK' | 'CHL' | 'CMR' | 'CHN' | 'COL' | 'CRI' | 'CUB' | 'CPV' | 'CUW' | 'CXR' | 'CYP' | 'CZE' | 'DEU' | 'DJI' | 'DNK' | 'DMA' | 'DOM' | 'DZA' | 'ECU' | 'EST' | 'EGY' | 'ESH' | 'ERI' | 'ESP' | 'ETH' | 'FIN' | 'FJI' | 'FLK' | 'FSM' | 'FRO' | 'FRA' | 'GAB' | 'ENG' | 'SCT' | 'GBR' | 'WAL' | 'NIR' | 'GRD' | 'GEO' | 'GUF' | 'GGY' | 'GHA' | 'GIB' | 'GRL' | 'GMB' | 'GIN' | 'GLP' | 'GNQ' | 'GRC' | 'SGS' | 'GTM' | 'GUM' | 'GNB' | 'GUY' | 'HKG' | 'HMD' | 'HND' | 'HRV' | 'HTI' | 'HUN' | 'IDN' | 'IRL' | 'ISR' | 'IMN' | 'IND' | 'IOT' | 'IRQ' | 'IRN' | 'ISL' | 'ITA' | 'JEY' | 'JAM' | 'JOR' | 'JPN' | 'KEN' | 'KGZ' | 'KHM' | 'KIR' | 'COM' | 'KNA' | 'PRK' | 'KOR' | 'KWT' | 'CYM' | 'KAZ' | 'LAO' | 'LBN' | 'LCA' | 'LIE' | 'LKA' | 'LBR' | 'LSO' | 'LTU' | 'LUX' | 'LVA' | 'LBY' | 'MAR' | 'MCO' | 'MDA' | 'MNE' | 'MAF' | 'MDG' | 'MHL' | 'MKD' | 'MLI' | 'MMR' | 'MNG' | 'MAC' | 'MNP' | 'MTQ' | 'MRT' | 'MSR' | 'MLT' | 'MUS' | 'MDV' | 'MWI' | 'MEX' | 'MYS' | 'MOZ' | 'NAM' | 'NCL' | 'NER' | 'NFK' | 'NGA' | 'NIC' | 'NLD' | 'NOR' | 'NPL' | 'NRU' | 'NIU' | 'NZL' | 'OMN' | 'PAN' | 'PER' | 'PYF' | 'PNG' | 'PHL' | 'PAK' | 'POL' | 'SPM' | 'PCN' | 'PRI' | 'PSE' | 'PRT' | 'PLW' | 'PRY' | 'QAT' | 'REU' | 'ROU' | 'SRB' | 'RUS' | 'RWA' | 'SAU' | 'SLB' | 'SYC' | 'SDN' | 'SWE' | 'SGP' | 'SHN' | 'SVN' | 'SJM' | 'SVK' | 'SLE' | 'SMR' | 'SEN' | 'SOM' | 'SUR' | 'SSD' | 'STP' | 'SLV' | 'SXM' | 'SYR' | 'SWZ' | 'TCA' | 'TCD' | 'ATF' | 'TGO' | 'THA' | 'TJK' | 'TKL' | 'TLS' | 'TKM' | 'TUN' | 'TON' | 'TUR' | 'TTO' | 'TUV' | 'TWN' | 'TZA' | 'UKR' | 'UGA' | 'UMI' | 'USA' | 'URY' | 'UZB' | 'VAT' | 'VCT' | 'VEN' | 'VGB' | 'VIR' | 'VNM' | 'VUT' | 'WLF' | 'WSM' | 'YEM' | 'MYT' | 'ZAF' | 'ZMB' | 'ZWE'; - -export type CurrencyCode = 'ARS' | 'AUD' | 'BRL' | 'CAD' | 'COP' | 'CZK' | 'DKK' | 'EUR' | 'GBP' | 'ILS' | 'INR' | 'JPY' | 'MXN' | 'NOK' | 'NZD' | 'PHP' | 'PKR' | 'PLN' | 'RSD' | 'SEK' | 'SGD' | 'UAH' | 'USD' | 'ZAR'; - -export type VendorContractAmount = { - /** - * The amount of the contract. - */ - amount: number; - currency: CurrencyCode; -}; - -export type CustomField = { - label: string; - value: string | Array; -}; - -export type VendorDecisionStatus = 'APPROVED' | 'CONDITIONALLY_APPROVED' | 'NOT_APPROVED'; - -/** - * The decision for a vendor. - */ -export type VendorDecision = { - status: VendorDecisionStatus; - lastUpdatedAt: string; -}; - -export type Vendor = { - /** - * The vendor's unique ID. - */ - id: string; - /** - * The vendor's display name. - */ - name: string; - /** - * The vendor's website URL. - */ - websiteUrl: string | null; - /** - * The vendor's external account manager name. - */ - accountManagerName: string | null; - /** - * The vendor's external account manager email. - */ - accountManagerEmail: string | null; - /** - * Services provided by the vendor. - */ - servicesProvided: string | null; - /** - * Any additional notes about the vendor - */ - additionalNotes: string | null; - /** - * The vendor's security owner's Vanta user ID. - */ - securityOwnerUserId: string | null; - /** - * The vendor's business owner's Vanta user ID. - */ - businessOwnerUserId: string | null; - /** - * The date the contract with the vendor began. - */ - contractStartDate: string | null; - /** - * The date the contract with the vendor is up for renewal. - */ - contractRenewalDate: string | null; - /** - * The date the contract with the vendor was terminated. - */ - contractTerminationDate: string | null; - /** - * The next due date for a security review. - */ - nextSecurityReviewDueDate: string | null; - /** - * The most recent date a security review was completed. - */ - lastSecurityReviewCompletionDate: string | null; - /** - * Whether or not auditors can view this vendor. - */ - isVisibleToAuditors: boolean | null; - /** - * Whether or not the vendor's risk is automatically scored. - */ - isRiskAutoScored: boolean | null; - /** - * The list of risk attribute IDs the vendor has been assigned to. - */ - riskAttributeIds: Array; - /** - * The vendor's category. - */ - category: { - displayName: string; - } | null; - /** - * The vendor's authentication details. - */ - authDetails: { - /** - * Minimum number for chacters required for passwords for this vendor. - */ - passwordMinimumLength: number | null; - /** - * Whether or not the vendor requires passwords to have a symbol. - */ - passwordRequiresSymbol: boolean | null; - /** - * Whether or not the vendor requires passwords to have a number. - */ - passwordRequiresNumber: boolean | null; - /** - * Whether or not the vendor requires passwords to have multi factor authentication. - */ - passwordMFA: boolean | null; - /** - * The vendor's authentication method. - */ - method: VendorAuthenticationMethod | null; - }; - status: VendorStatus; - inherentRiskLevel: VendorRiskLevel; - residualRiskLevel: VendorRiskLevel; - /** - * The vendor's headquarters. - */ - vendorHeadquarters: CountryCode | null; - /** - * The contract amount for the vendor. - */ - contractAmount: VendorContractAmount | null; - /** - * The vendor's custom fields. - */ - customFields: Array | null; - /** - * The vendor's latest decision status. Null means no decision has been made. - */ - latestDecision: VendorDecision | null; - /** - * The task tracker procurement request associated with this vendor (if linked). - */ - linkedTaskTrackerTaskProcurementRequest: { - url: string; - service: string; - } | null; -}; - -/** - * Framework scoping configuration for a vendor. - * Determines which compliance frameworks the vendor applies to. - */ -export type VendorFrameworkScope = { - /** - * The scope type: - * - ALL: Vendor applies to all frameworks - * - PARTIAL: Vendor applies to specific frameworks (requires frameworkIds) - * - NONE: Vendor excluded from all frameworks - */ - scopeType: 'ALL' | 'PARTIAL' | 'NONE'; - /** - * Framework IDs the vendor applies to. Required when scopeType is PARTIAL. - */ - frameworkIds?: Array; -}; - -export type CreateVendorInput = { - /** - * Display name of the vendor. - */ - name: string; - /** - * The url of the vendor's website. - */ - websiteUrl?: string; - /** - * Name of the external account manager for this vendor. - */ - accountManagerName?: string; - /** - * Email of the external account manager for this vendor. - */ - accountManagerEmail?: string; - /** - * The Vanta user ID of the security owner of this vendor. - */ - securityOwnerUserId?: string; - /** - * Services provided by the vendor. - */ - servicesProvided?: string; - /** - * Miscellaneous notes about the vendor - */ - additionalNotes?: string; - /** - * The Vanta user ID of the business owner of this vendor. - */ - businessOwnerUserId?: string; - /** - * When the contract with the vendor is up for renewal. - */ - contractStartDate?: string; - /** - * When the contract with the vendor is up for renewal. - */ - contractRenewalDate?: string; - /** - * When the contract with the vendor was terminated. - */ - contractTerminationDate?: string; - /** - * Whether or not auditors can view this vendor. - */ - isVisibleToAuditors?: boolean; - /** - * The authentication details about the vendor. - */ - authDetails?: { - /** - * Minimum number for chacters required for passwords for this vendor. - */ - passwordMinimumLength?: number; - /** - * Whether or not the vendor requires passwords to have a symbol. - */ - passwordRequiresSymbol?: boolean; - /** - * Whether or not the vendor requires passwords to have a number. - */ - passwordRequiresNumber?: boolean; - /** - * Whether or not the vendor requires password multi factor authentication. - */ - passwordMFA?: boolean; - method?: VendorAuthenticationMethod; - }; - status?: VendorStatus; - /** - * The vendor's category. - */ - category?: string; - inherentRiskLevel?: VendorRiskLevel; - residualRiskLevel?: VendorRiskLevel; - vendorHeadquarters?: CountryCode; - contractAmount?: VendorContractAmount; - /** - * The custom fields for the vendor. - * For more information on how to set custom fields via the API, visit https://developer.vanta.com/docs/guides/use-custom-fields-with-vendors - */ - customFields?: Array; - frameworkScope?: VendorFrameworkScope; -}; - -export type PaginatedResponseVendor = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type UpdateVendorInput = { - /** - * Display name of the vendor. - */ - name?: string; - /** - * The url of the vendor's website. - */ - websiteUrl?: string | null; - /** - * Name of the external account manager for this vendor. - */ - accountManagerName?: string | null; - /** - * Email of the external account manager for this vendor. - */ - accountManagerEmail?: string; - /** - * The Vanta user ID of the security owner of this vendor. - */ - securityOwnerUserId?: string | null; - /** - * Services provided by the vendor. - */ - servicesProvided?: string | null; - /** - * Miscellaneous notes about the vendor - */ - additionalNotes?: string | null; - /** - * The Vanta user ID of the business owner of this vendor. - */ - businessOwnerUserId?: string | null; - /** - * When the contract with the vendor is up for renewal. - */ - contractStartDate?: string | null; - /** - * When the contract with the vendor is up for renewal. - */ - contractRenewalDate?: string | null; - /** - * When the contract with the vendor was terminated. - */ - contractTerminationDate?: string | null; - /** - * Whether or not auditors can view this vendor. - */ - isVisibleToAuditors?: boolean; - /** - * The authentication details about the vendor. - */ - authDetails?: { - /** - * Minimum number for chacters required for passwords for this vendor. - */ - passwordMinimumLength?: number; - /** - * Whether or not the vendor requires passwords to have a symbol. - */ - passwordRequiresSymbol?: boolean; - /** - * Whether or not the vendor requires passwords to have a number. - */ - passwordRequiresNumber?: boolean; - /** - * Whether or not the vendor requires password multi factor authentication. - */ - passwordMFA?: boolean; - /** - * The authentication method the vendor uses. - */ - method?: VendorAuthenticationMethod | null; - }; - status?: VendorStatus; - /** - * The vendor's category. - */ - category?: string; - /** - * The inherent risk level of the vendor. - * Setting it to null means it will be auto-scored by Vanta based on the risk attributes and rubric - */ - inherentRiskLevel?: VendorRiskLevel | null; - residualRiskLevel?: VendorRiskLevel; - /** - * A list of risk attribute ids the vendor has been assigned. - */ - riskAttributeIds?: Array; - /** - * The vendor's headquarters. - */ - vendorHeadquarters?: CountryCode | null; - /** - * The contract amount for the vendor. - */ - contractAmount?: VendorContractAmount | null; - /** - * The custom fields for the vendor. - * For more information on how to set custom fields via the API, visit https://developer.vanta.com/docs/guides/use-custom-fields-with-vendors - */ - customFields?: Array; - frameworkScope?: VendorFrameworkScope; -}; - -export type UploadedDocumentUploadedByType = 'USER' | 'APPLICATION'; - -export type VendorDocument = { - /** - * Unique identifier for the document. - */ - id: string; - /** - * The file name of the document. - */ - fileName: string | null; - /** - * The document's title. - */ - title: string; - /** - * The document's description - */ - description: string | null; - /** - * Mime type of the document. - */ - mimeType: string; - /** - * The actor who uploaded this document. It could be a user or an app. - */ - uploadedBy: { - type: UploadedDocumentUploadedByType; - id: string; - } | null; - /** - * Date of when the document was uploaded. - */ - creationDate: string; - /** - * Date when the document was last updated. - */ - updatedDate: string; - /** - * Date of when the document was deleted. Is set to null if the document has not been deleted. - */ - deletionDate: string | null; - /** - * Type of the vendor document. - */ - type: string; - /** - * URL link to the document - */ - url: string; -}; - -export type PaginatedResponseVendorDocument = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The current decision made for the security review: - * - APPROVED: The security review has been approved. - * - NOT_APPROVED: The security review has been marked not approved. - * - CONDITIONALLY_APPROVED: The security review has been conditionally approved. - */ -export type SecurityReviewDecision = 'APPROVED' | 'NOT_APPROVED' | 'CONDITIONALLY_APPROVED'; - -export type SecurityReview = { - /** - * Unique identifier for the security review. - */ - id: string; - /** - * Unique identifier for the vendor. - */ - vendorId: string; - /** - * Notes about the security review's decision status. - */ - decisionNotes: string | null; - /** - * Comments about the security review. - */ - comments: string | null; - /** - * The Vanta user ID of the person who completed this review. - */ - completedByUserId: string | null; - /** - * The timestamp of the when the security review was started. - */ - startDate: string | null; - /** - * The timestamp of the when the security review is due. - */ - dueDate: string | null; - /** - * A manual override timestamp of the when the security review is due. - */ - overrideDueDate: string | null; - /** - * The timestamp of the when the security review was marked as completed. - */ - completionDate: string | null; - /** - * An object containing information about the decision of the review. - */ - decision: { - /** - * The timestamp of when the security review decision was last set. - */ - lastUpdatedAt: string; - status: SecurityReviewDecision; - } | null; -}; - -export type PaginatedResponseSecurityReview = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The status of the finding: - * - ACCEPT: The finding and its risk has been accepted and no follow up is required. - * - REMEDIATE: The finding needs to be remediated in some way. - * - NONE: The finding is not related to an observed risk that needs to be accepted or remediated. - */ -export type FindingRiskStatus = 'ACCEPT' | 'REMEDIATE' | 'NONE'; - -/** - * The current state of a finding remediation: - * - OPEN: The finding has not been remediated and still needs to be addressed. - * - CLOSED: The finding has been remediated and no further action is needed. - */ -export type FindingRemediationState = 'OPEN' | 'CLOSED'; - -export type VendorFinding = { - /** - * Unique identifier for the finding. - */ - id: string; - /** - * Unique identifier for the vendor. - */ - vendorId: string; - /** - * Unique identifier for a security review. - */ - securityReviewId: string | null; - /** - * Unique identifier for a document. - */ - documentId: string | null; - /** - * The content of the finding. - */ - content: string; - riskStatus: FindingRiskStatus; - /** - * Remediation information about the finding. Will only be populated if riskStatus is set to "REMEDIATE". - */ - remediation: { - state: FindingRemediationState; - /** - * A string containing the information needed to properly remediate the finding. - */ - requirementNotes: string | null; - } | null; -}; - -export type PaginatedResponseVendorFinding = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type CreateFindingInput = { - /** - * The content of the finding. - */ - content: string; - riskStatus: FindingRiskStatus; - /** - * Remediation information about the finding. Will only be populated if riskStatus is set to "REMEDIATE". - */ - remediation?: { - state?: FindingRemediationState; - /** - * A string containing the information needed to properly remediate the finding. - */ - requirementNotes?: string; - }; - /** - * Unique identifier for a security review. - */ - securityReviewId?: string; - /** - * Unique identifier for a document. - */ - documentId?: string; -}; - -export type UpdateFindingInput = { - /** - * The content of the finding. - */ - content?: string; - riskStatus?: FindingRiskStatus; - /** - * Remediation information about the finding. Will only be populated if riskStatus is set to "REMEDIATE". - */ - remediation?: { - state?: FindingRemediationState; - /** - * A string containing the information needed to properly remediate the finding. - */ - requirementNotes?: string; - }; -}; - -export type VendorRiskAttribute = { - /** - * Unique identifier for the risk attribute. - */ - id: string; - /** - * Display name of the risk attribute. - */ - name: string; - /** - * Description of the risk attribute. - */ - description: string; - /** - * Vendor categories this risk attribute applies to. - */ - vendorCategories: Array; - /** - * Whether or not this risk attribute is enabled. - */ - enabled: boolean; - riskLevel: VendorRiskLevel; -}; - -export type PaginatedResponseVendorRiskAttribute = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type User = { - id: string; - email: string; - displayName: string; - isActive: boolean; -}; - -export type PaginatedResponseUser = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Possible banner settings for the Trust Center. - * - CUSTOM_IMAGE: Banner is a custom uploaded image. - * - GRADIENT: Banner is a gradient between two colors. - * - MINIMAL: No banner. - * - VANTA: Legacy Vanta-themed banner. No longer selectable as a banner style. - */ -export type BannerSetting = 'CUSTOM_IMAGE' | 'GRADIENT' | 'MINIMAL' | 'VANTA'; - -export type TrustCenter = { - /** - * Unique identifier for the Trust Center. - */ - id: string; - /** - * Custom title set for the Trust Center. - */ - title: string | null; - /** - * Company description displayed in the Trust Center header. - */ - companyDescription: string | null; - /** - * URL of the Trust Center company's privacy policy. - */ - privacyPolicy: string | null; - /** - * URL of the Trust Center company's AWS Marketplace listing. - */ - awsMarketplaceListing: string | null; - /** - * Custom domain that the Trust Center can be found at, e.g. trust.vanta.com. - */ - customDomain: string | null; - /** - * Whether the Trust Center is public. - */ - isPublic: boolean; - /** - * Information about the Trust Center's banner. - */ - bannerSetting: { - /** - * End color of the banner. Only applies if setting is GRADIENT. - */ - endColor: string | null; - /** - * Start color of the banner. Only applies if setting is GRADIENT. - */ - startColor: string | null; - /** - * Banner setting option. - */ - setting: BannerSetting | null; - }; - /** - * Custom theme colors chosen for the Trust Center. - */ - customTheme: { - /** - * Secondary color selected for the theme. - */ - secondary: string | null; - /** - * Primary color selected for the theme. - */ - primary: string | null; - }; - /** - * Contact email displayed on the Trust Center. - */ - contactEmail: string | null; - /** - * Custom heading displayed on the Trust Center. - */ - customHeading: string | null; - /** - * Date the Trust Center was created. - */ - creationDate: string; - /** - * Date the Trust Center was last updated. - */ - updatedDate: string; -}; - -export type BannerSettingGradient = 'GRADIENT'; - -export type BannerSettingMinimal = 'MINIMAL'; - -export type ApiSelectableBannerSetting = BannerSettingGradient | BannerSettingMinimal; - -export type UpdateTrustCenterInput = { - /** - * Custom title for the Trust Center. If null is passed in, the current - * custom title is unset and the default title is restored. - */ - title?: string | null; - /** - * Company description displayed in the Trust Center header. If null is passed - * in, the current company description is unset. - */ - companyDescription?: string | null; - /** - * The banner configuration of the Trust Center. - */ - bannerSetting?: { - /** - * End color of the banner. Only applies if setting is GRADIENT. - */ - endColor?: string; - /** - * Start color of the banner. Only applies if setting is GRADIENT. - */ - startColor?: string; - setting: ApiSelectableBannerSetting; - }; - /** - * The custom theme configuration for the Trust Center. - */ - customTheme?: { - /** - * Secondary color for the theme. If null is passed in, resets to default. - */ - secondary?: string | null; - /** - * Primary color for the theme. If null is passed in, resets to default. - */ - primary?: string | null; - }; - /** - * Privacy policy URL to set on the Trust Center. If null is passed in, unsets - * the current privacy policy. - */ - privacyPolicy?: string | null; - /** - * AWS Marketplace listing URL to set on the Trust Center. If null is passed - * in, unsets the current AWS Marketplace listing. - */ - awsMarketplaceListing?: string | null; - /** - * Whether the Trust Center is public or not. - */ - isPublic?: boolean; - /** - * Contact email displayed on the Trust Center. If null is passed in, unsets - * the current contact email. - */ - contactEmail?: string | null; - /** - * Custom heading displayed on the Trust Center. If null is passed in, unsets - * the current custom heading. - */ - customHeading?: string | null; -}; - -export type ActivityEventType = 'PAGE_VIEW' | 'RESOURCE_DOWNLOAD' | 'RESOURCE_VIEW' | 'VIDEO_PLAY'; - -export type TrustCenterPage = 'COMPLIANCE' | 'CONTROLS' | 'FAQ' | 'MEDIA' | 'OVERVIEW' | 'RESOURCES' | 'SUBPROCESSORS' | 'UPDATES'; - -export type TrustCenterActivityEvent = { - /** - * Unique identifier for the activity event. - */ - id: string; - /** - * Date and time the event occurred. - */ - date: string; - eventType: ActivityEventType; - /** - * Additional details about the event. Details vary based on event type. - */ - details: { - page: TrustCenterPage; - } | { - /** - * Title of the resource that this event pertains to. - */ - resourceName: string; - /** - * ID of the resource that this event pertains to. - */ - resourceId: string; - } | { - /** - * Title of the video that was played. - */ - videoTitle: string; - } | null; - /** - * ID of the viewer who produced the event. - */ - viewerId: string | null; - /** - * Email of the viewer who produced the event. - */ - viewerEmail: string | null; - /** - * City from which the request originated. - */ - city: string | null; - /** - * Country code from which the request originated. - */ - countryCode: string | null; -}; - -export type PaginatedResponseTrustCenterActivityEvent = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The access level of the viewer. - * FULL_ACCESS means having access to all resources on the trust center. - * PARTIAL_ACCESS means having access to all public resources and a select list of requestable resources. - */ -export type ViewerAccessLevel = 'FULL_ACCESS' | 'PARTIAL_ACCESS'; - -/** - * The provider for a viewer's NDA. This can also be a provider that bypassed - * the NDA requirement, e.g. SFDC. - */ -export type ViewerNdaProvider = 'DOCUSIGN' | 'ONE_CLICK' | 'SFDC_BYPASS' | 'HUBSPOT_BYPASS' | 'IRONCLAD_BYPASS'; - -/** - * An external service that a Trust Center viewer may be associated with. - */ -export type ExternalService = 'SALESFORCE' | 'HUBSPOT' | 'IRONCLAD'; - -export type CustomerTrustUser = { - id: string; - organizationId: string; - email: string; - givenName: string | null; - familyName: string | null; -}; - -export type TrustCenterViewer = { - /** - * Unique identifier for the viewer. - */ - id: string; - /** - * Email of the viewer. - */ - email: string; - /** - * Name of the viewer. - */ - name: string | null; - /** - * Name of the viewer's company. - */ - companyName: string | null; - /** - * IDs for the resources this viewer has access to. If null, the - * viewer has access to all resources on the Trust Center. - */ - resourceIds: Array | null; - accessLevel: ViewerAccessLevel; - /** - * NDA-related information for the viewer. - */ - ndaInfo: { - /** - * Contains information about the DocuSign NDA if that is the NDA - * provider. - */ - docuSign: { - /** - * Unique ID used to identify and validate incoming webhook requests. - */ - webhookId: string; - /** - * ID of the created envelope in DocuSign. - */ - envelopeId: string; - /** - * ID of the DocuSign account. - */ - accountId: string; - /** - * eSignature API URL for the DocuSign account. - */ - accountBaseUrl: string; - } | null; - /** - * Contains information about the click-wrap NDA if that is the NDA - * provider. - */ - oneClick: { - /** - * ID for the NDA document that was signed. - */ - ndaUploadedDocumentId: string | null; - /** - * Name of the person who signed the NDA. - */ - name: string; - /** - * The date the NDA document was signed. - */ - date: string; - } | null; - provider: ViewerNdaProvider; - /** - * The date the NDA was satisfied. - */ - satisfiedDate: string | null; - } | null; - /** - * Objects in external services that the viewer is associated with. - */ - externalServiceAssociations: Array<{ - /** - * The type of object in the external service the viewer was linked to. - */ - objectType: string; - /** - * The ID of the user in the external service. - */ - id: string; - service: ExternalService; - }> | null; - /** - * Date the viewer was created. - */ - creationDate: string; - /** - * Date the viewer was last updated. - */ - updatedDate: string; - /** - * Expiration date for the viewer's access. - */ - expirationDate: string | null; - /** - * User that shared the Trust Center with this viewer. - */ - addedByUser: CustomerTrustUser | null; - /** - * ID of the Customer Trust Account associated with this viewer. - */ - customerTrustAccountId: string | null; -}; - -export type PaginatedResponseTrustCenterViewer = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type AddTrustCenterViewerInput = { - /** - * Email of the viewer. - */ - email: string; - /** - * Name of the viewer. - */ - name: string; - /** - * Name of the viewer's company. - */ - companyName: string; - /** - * Whether to require an NDA for the viewer. - */ - isNdaRequired: boolean; - /** - * The date access should expire for this viewer. If a date isn't provided, - * access will not expire. - */ - expirationDate?: string; - /** - * Identifiers for the resources that this viewer should have access to. If - * this field is omitted, the viewer will have access to all resources on the - * Trust Center. - */ - resourceIds?: Array; - accessLevel: ViewerAccessLevel; - /** - * ID of a Customer Trust Account to associate with this viewer. - */ - customerTrustAccountId?: string; -}; - -export type UpdateTrustCenterViewerInput = { - accessLevel?: ViewerAccessLevel; - /** - * Identifiers for the resources that this viewer should have access to. - */ - resourceIds?: Array; - /** - * The date access should expire for this viewer. Set to null to remove - * expiration. - */ - expirationDate?: string | null; - /** - * Whether to require an NDA for the viewer. - */ - isNdaRequired?: boolean; - /** - * ID of a Customer Trust Account to associate with this viewer. - * Set to null to remove the association. - * Omit to leave unchanged. - */ - customerTrustAccountId?: string | null; -}; - -export type TrustCenterVideo = { - /** - * Canonical URL for the video. - */ - url: string; - /** - * Title of the video. - */ - title: string; - /** - * Description of the video. - */ - description?: string | null; -}; - -export type ArrayResponseTrustCenterVideo = { - results: Array; -}; - -export type SetTrustCenterVideoItem = { - /** - * Full video URL (e.g. "https://www.youtube.com/watch?v=dQw4w9WgXcQ" or "https://vimeo.com/123456"). Supported platforms: YouTube, Vimeo. - */ - url: string; - /** - * Title of the video. - */ - title: string; - /** - * Description of the video. - */ - description?: string; -}; - -export type SetTrustCenterVideosInput = { - /** - * The videos to display on the Trust Center. Replaces all existing videos. - */ - videos: Array; -}; - -/** - * The possible categories for a Trust Center update. - */ -export type UpdateCategory = 'GENERAL' | 'COMPLIANCE' | 'SECURITY' | 'PRIVACY' | 'INCIDENT' | 'ROADMAP'; - -/** - * Visibility of a Trust Center update. - */ -export type UpdateVisibilityType = 'PUBLIC' | 'PRIVATE'; - -export type TrustCenterUpdateApiResponse = { - /** - * Unique identifier for the update. - */ - id: string; - /** - * Title of the update. - */ - title: string; - /** - * Description of the update. - */ - description: string; - category: UpdateCategory; - /** - * Date the update was created. - */ - creationDate: string; - /** - * Date the viewer was last updated. - */ - updatedDate: string; - visibilityType: UpdateVisibilityType; - /** - * Emails to notify about the update. - */ - notifiedEmails?: Array; -}; - -export type PaginatedResponseTrustCenterUpdateApiResponse = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Target recipients for notifications - */ -export type UpdateNotificationTarget = 'ALL' | 'GROUPS' | 'NONE'; - -export type AddTrustCenterUpdateInput = { - /** - * Title of the update. - */ - title: string; - /** - * Description of the update. - */ - description: string; - category: UpdateCategory; - visibilityType?: UpdateVisibilityType; - /** - * Additional one-off email addresses to notify. These are always sent regardless of `notificationTarget`. - */ - notifiedEmails?: Array; - notificationTarget?: UpdateNotificationTarget; - /** - * IDs of subscriber groups to notify. Required when `notificationTarget` is `GROUPS`. - */ - subscriberGroupIds?: Array; -}; - -export type EditTrustCenterUpdateInput = { - /** - * Title of the update. - */ - title: string; - /** - * Description of the update. - */ - description: string; - category: UpdateCategory; - visibilityType?: UpdateVisibilityType; -}; - -export type NotifySpecificSubscribersResponse = { - /** - * The number of subscribers who will receive this notification. - */ - recipientCount: number; -}; - -/** - * A single custom field filter condition. - */ -export type CustomerTrustAccountCustomFieldFilter = { - /** - * The custom field label. - */ - label: string; - /** - * The value(s) to match against. Provide an array to match any of multiple values. - */ - value: string | Array; -}; - -export type TagsByCategoryInput = { - /** - * The tag category ID - */ - categoryId: string; - /** - * Tag IDs to assign. An empty array removes all tags for the category. - */ - tagIds: Array; -}; - -/** - * Account selectors for narrowing `GROUPS` notifications to subscribers with a matching linked account. - */ -export type CustomerTrustAccountsInput = { - /** - * Filter accounts by custom field label/value pairs. - * When `value` is an array, accounts matching any of the values are included. - * When multiple entries are provided, accounts must satisfy all of them. - */ - customFieldsFilter?: Array; - /** - * Narrow the candidate accounts resolved from `customFieldsFilter` - * to those with matching tags. - * Within a category entry, accounts matching any of the `tagIds` are included. - * When multiple entries are provided, accounts must satisfy all of them. - */ - tagsByCategory?: Array; -}; - -/** - * Input for sending notifications to specific subscribers of a Trust Center update. - * - * **Recipient limit:** The total number of deduplicated recipient emails resolved from - * subscriber groups, account filters, and additional emails must not exceed **5,000**. - * If the resolved recipient count exceeds this limit, the request will return a **422** error. - * To notify more recipients, narrow your filters or split across multiple requests. - */ -export type SendTrustCenterUpdateNotificationsInput = { - /** - * Additional email addresses to notify about this Trust Center update in addition to the existing Trust Center subscribers. - * Duplicate emails are deduplicated to ensure each recipient gets only one notification. - */ - emails: Array; - /** - * IDs of subscriber groups to notify. When `customerTrustAccounts` is also provided, - * only subscribers in these groups whose linked account matches are notified. - */ - subscriberGroupIds: Array; - customerTrustAccounts?: CustomerTrustAccountsInput; -}; - -export type SubscriberGroup = { - /** - * Unique identifier for the group. - */ - id: string; - /** - * Name of the group. - */ - name: string; -}; - -export type TrustCenterSubscriber = { - /** - * Unique identifier for the subscriber. - */ - id: string; - /** - * Email of the subscriber. - */ - email: string; - /** - * Whether the subscriber's email has been verified. - */ - isEmailVerified: boolean; - /** - * When the subscriber was created. - */ - creationDate: string; - /** - * The ID of the customer trust account this subscriber is linked to, if any. - */ - customerTrustAccountId: string | null; - /** - * Groups this subscriber belongs to. - */ - groups: Array; -}; - -export type PaginatedResponseTrustCenterSubscriber = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type AddTrustCenterSubscriberInput = { - /** - * Email of the subscriber. - */ - email: string; - /** - * Optional: Link subscriber to a customer trust account by ID. - */ - customerTrustAccountId?: string; - /** - * When true, the subscriber is created as already verified and no - * verification email is sent. Defaults to false. - */ - shouldSkipEmailVerification?: boolean; -}; - -export type SetGroupsForTrustCenterSubscriberInput = { - /** - * Group IDs to set for the subscriber. The subscriber will be removed from - * any groups not included in this list. - */ - groupIds: Array; -}; - -export type TrustCenterSubscriberGroup = { - /** - * Unique identifier for the subscriber group. - */ - id: string; - /** - * Name of the subscriber group. - */ - name: string; - /** - * List of subscriber IDs in the group. - */ - subscriberIds: Array; - /** - * When the subscriber group was created. - */ - creationDate: string; -}; - -export type EditTrustCenterSubscriberGroupInput = { - /** - * Updated name of the subscriber group. - */ - name: string; -}; - -export type CreateTrustCenterSubscriberGroupInput = { - /** - * Name of the subscriber group. - */ - name: string; - /** - * List of subscriber IDs in the group. - */ - subscriberIds: Array; -}; - -export type PaginatedResponseTrustCenterSubscriberGroup = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type TrustCenterSubprocessor = { - /** - * Unique identifier for the subprocessor. - */ - id: string; - /** - * Name of the subprocessor. - */ - name: string; - /** - * Description of the subprocessor. - */ - description: string | null; - /** - * Where this subprocessor is deployed. - */ - location: string | null; - /** - * The purpose that the subprocessor serves. - */ - purpose: string | null; - /** - * URL of the subprocessor. - */ - url: string | null; -}; - -export type ArrayResponseTrustCenterSubprocessor = { - results: Array; -}; - -export type AddTrustCenterSubprocessorInput = { - /** - * Name of the subprocessor. - */ - name: string; - /** - * URL of the subprocessor. - */ - url?: string; - /** - * Description of the subprocessor. - */ - description?: string; - /** - * Where this subprocessor is deployed. - */ - location?: string; - /** - * The purpose that the subprocessor serves. - */ - purpose?: string; -}; - -export type EditTrustCenterSubprocessorInput = { - /** - * What to set the subprocessor description to. If null is passed in, the - * subprocessor's current description is unset. - */ - description?: string | null; - /** - * What to set the subprocessor location to. If null is passed in, the - * subprocessor's current description is unset. - */ - location?: string | null; - /** - * What to set the subprocessor purpose to. If null is passed in, the - * subprocessor's current description is unset. - */ - purpose?: string | null; -}; - -export type TrustCenterResource = { - /** - * Unique identifier for the document. - */ - id: string; - /** - * The file name of the document. - */ - fileName: string | null; - /** - * The document's title. - */ - title: string; - /** - * The document's description - */ - description: string | null; - /** - * Mime type of the document. - */ - mimeType: string; - /** - * Date of when the document was uploaded. - */ - creationDate: string; - /** - * Date when the document was last updated. - */ - updatedDate: string; - /** - * Boolean determining whether the document is publicly available. - */ - isPublic: boolean; -}; - -export type ArrayResponseTrustCenterResource = { - results: Array; -}; - -export type EditTrustCenterResourceInput = { - /** - * Title of the Trust Center document. - */ - title?: string; - /** - * Boolean determining whether the document is publicly available. - */ - isPublic?: boolean; - /** - * Description of the uploaded document. - */ - description?: string; -}; - -export type NodeJsReadableStream = { - readable: boolean; -}; - -export type TrustCenterResourceCategory = { - /** - * Unique identifier for the resource category. - */ - id: string; - /** - * Name of the category. - */ - name: string; -}; - -export type ArrayResponseTrustCenterResourceCategory = { - results: Array; -}; - -export type AddTrustCenterResourceCategoryInput = { - /** - * Name of the category. - */ - name: string; -}; - -export type EditTrustCenterResourceCategoryInput = { - /** - * New name for the category. - */ - name: string; -}; - -export type ReorderTrustCenterResourceCategoriesInput = { - /** - * Ordered list of all resource category IDs representing the desired order. - */ - categoryIds: Array; -}; - -/** - * Response returned after a favicon upload. - */ -export type UploadFaviconResponse = { - /** - * Whether the favicon was successfully uploaded. - */ - success: boolean; -}; - -export type TrustCenterFaqCategory = { - /** - * Unique identifier for the FAQ category. - */ - id: string; - /** - * Name of the category. - */ - name: string; -}; - -export type TrustCenterFaq = { - /** - * Unique identifier for the Trust Center FAQ. - */ - id: string; - /** - * The FAQ question. - */ - question: string; - /** - * The FAQ answer. - */ - answer: string; - /** - * The category this FAQ belongs to, or null if uncategorized. - */ - category: TrustCenterFaqCategory | null; -}; - -export type ArrayResponseTrustCenterFaq = { - results: Array; -}; - -export type AddOrEditTrustCenterFaqInput = { - /** - * The FAQ question. - */ - question: string; - /** - * The FAQ answer. - */ - answer: string; - /** - * The category to place this FAQ in. Pass null to move to uncategorized. Omit to leave unchanged (on update) or default to uncategorized (on create). - */ - categoryId?: string | null; -}; - -export type ArrayResponseTrustCenterFaqCategory = { - results: Array; -}; - -export type AddTrustCenterFaqCategoryInput = { - /** - * Name of the category. - */ - name: string; -}; - -export type EditTrustCenterFaqCategoryInput = { - /** - * New name for the category. - */ - name: string; -}; - -/** - * Enum representing if and how the data collected is shown on the trust center - */ -export type DataCollectedStatus = 'COLLECTED' | 'HIDDEN' | 'NOT_COLLECTED'; - -export type TrustCenterDataCollected = { - /** - * Name of the data type being disclosed. - */ - dataCollected: string; - status: DataCollectedStatus; -}; - -export type ArrayResponseTrustCenterDataCollected = { - results: Array; -}; - -export type DataCollectedInputItem = { - /** - * Name of the data type being disclosed. - */ - dataCollected: string; - status: DataCollectedStatus; -}; - -export type SetDataCollectedInput = { - /** - * List of data-collected disclosures to set on the Trust Center. - */ - dataCollected: Array; - /** - * Custom heading for the data collected section. If null is passed in, unsets the current heading. - */ - dataCollectedHeading?: string | null; -}; - -export type TrustCenterControlCategory = { - /** - * Unique identifier for the control category. - */ - id: string; - /** - * Name of the category. - */ - name: string; -}; - -export type ArrayResponseTrustCenterControlCategory = { - results: Array; -}; - -export type AddOrEditTrustCenterControlCategoryInput = { - /** - * Name of the category. - */ - name: string; -}; - -/** - * Request body for bulk editing controls in a category. - */ -export type BulkEditControlsInCategoryInput = { - /** - * IDs of controls to add to the category. - */ - controlsToAdd: Array; - /** - * IDs of controls to remove from the category. - */ - controlsToRemove: Array; -}; - -export type ReorderTrustCenterControlCategoriesInput = { - /** - * Ordered list of all control category IDs representing the desired order. - */ - orderedCategoryIds: Array; -}; - -export type TrustCenterControl = { - /** - * Unique identifier for the control. - */ - id: string; - /** - * The name of the control, usually a summary of the description. - */ - name: string; - /** - * The description of the control. - */ - description: string; - /** - * The Trust Center control categories that the control belongs to. - */ - categories: Array | null; -}; - -export type PaginatedResponseTrustCenterControl = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type AddControlToTrustCenterInput = { - /** - * ID of the control to add to the Trust Center. - */ - controlId: string; - /** - * IDs of the categories to add the control to. This cannot be empty. - */ - categoryIds: Array; -}; - -export type ArrayResponseTrustCenterControl = { - results: Array; -}; - -export type BulkTagControlsInput = { - /** - * IDs of the controls to tag. Maximum 100. - */ - controlIds: Array; - /** - * ID of the tag category. - */ - tagCategory: string; - /** - * IDs of the tags to add or remove. - */ - tags: Array; -}; - -export type ReorderTrustCenterControlsInput = { - /** - * Ordered list of all control IDs in the category representing the desired order. - */ - orderedControlIds: Array; -}; - -export type TrustCenterComplianceFramework = { - /** - * Unique identifier for the framework. - */ - id: string; - /** - * Display name of the framework. - */ - name: string; - /** - * Compliance standard associated with this framework. - */ - standard: string | null; - /** - * Description of the framework. - */ - description: string | null; -}; - -export type ArrayResponseTrustCenterComplianceFramework = { - results: Array; -}; - -export type CreateComplianceFrameworkInput = { - /** - * Display name of the framework. - */ - name: string; - /** - * Compliance standard to associate with this framework. - */ - standard?: 'aiact' | 'aiuc1' | 'aue8' | 'awsFTR' | 'ccpa' | 'cisv8' | 'cjis' | 'cmmc2' | 'cps234' | 'cri' | 'dora' | 'fedRAMPr5' | 'fedramp' | 'fedramp20x' | 'fedramp20x_2026' | 'gdpr' | 'hipaa' | 'hitruste1' | 'iso9001' | 'iso27001' | 'iso27001_2022' | 'iso27017' | 'iso27018' | 'iso27701' | 'iso27701_2025' | 'iso42001' | 'msftSSPA' | 'mvsp' | 'nis2d' | 'nist53' | 'nist171' | 'nistAiRmf' | 'nistCSF' | 'nistcsf2' | 'ofdss' | 'pciDss4' | 'pciSaqA' | 'pciSaqAEP' | 'pciSaqDMerchant' | 'pciSaqDSP' | 'soc2' | 'soxITGC' | 't23nycrr500' | 'tisax' | 'iso22301' | 'trust' | 'ukCyberEssentials' | 'ukCyberEssentials33' | 'usDataPrivacy' | 'fedrampKSI' | null; - /** - * Description of the framework. - */ - description?: string; -}; - -export type UpdateComplianceFrameworkInput = { - /** - * Display name of the framework. - */ - name?: string; - /** - * Compliance standard to associate with this framework. Pass null to unset. - */ - standard?: 'aiact' | 'aiuc1' | 'aue8' | 'awsFTR' | 'ccpa' | 'cisv8' | 'cjis' | 'cmmc2' | 'cps234' | 'cri' | 'dora' | 'fedRAMPr5' | 'fedramp' | 'fedramp20x' | 'fedramp20x_2026' | 'gdpr' | 'hipaa' | 'hitruste1' | 'iso9001' | 'iso27001' | 'iso27001_2022' | 'iso27017' | 'iso27018' | 'iso27701' | 'iso27701_2025' | 'iso42001' | 'msftSSPA' | 'mvsp' | 'nis2d' | 'nist53' | 'nist171' | 'nistAiRmf' | 'nistCSF' | 'nistcsf2' | 'ofdss' | 'pciDss4' | 'pciSaqA' | 'pciSaqAEP' | 'pciSaqDMerchant' | 'pciSaqDSP' | 'soc2' | 'soxITGC' | 't23nycrr500' | 'tisax' | 'iso22301' | 'trust' | 'ukCyberEssentials' | 'ukCyberEssentials33' | 'usDataPrivacy' | 'fedrampKSI' | null; - /** - * Description of the framework. Pass null to unset. - */ - description?: string | null; -}; - -export type BadgeUploadResponse = { - /** - * Whether the upload succeeded. - */ - success: boolean; -}; - -export type TrustCenterChatbotConversation = { - /** - * Unique identifier for the conversation. - */ - id: string; - /** - * The user's first message in the conversation. - */ - firstMessage: string; - /** - * Total number of messages in the conversation. - */ - numMessages: number; - /** - * Email address of the user who started the conversation, or null for public conversations. - */ - userEmail: string | null; - /** - * Whether this conversation occurred on a public chatbot. - */ - isPublicConversation: boolean; - /** - * Date and time the conversation was created. - */ - createdAt: string; -}; - -export type PaginatedResponseTrustCenterChatbotConversation = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type ChatbotMessageRole = 'USER' | 'ASSISTANT'; - -export type TrustCenterChatbotMessage = { - /** - * Unique identifier for the message. - */ - id: string; - role: ChatbotMessageRole; - /** - * The message content. - */ - message: string; - /** - * Date and time the message was created. - */ - createdAt: string; - /** - * Resource IDs referenced by this message. - */ - references: Array; -}; - -export type ArrayResponseTrustCenterChatbotMessage = { - results: Array; -}; - -export type TrustCenterAccessRequest = { - /** - * Unique identifier for the access request. - */ - id: string; - /** - * Email of the requester. - */ - email: string; - /** - * Name of the requester. - */ - name: string; - /** - * Name of the requester's company. - */ - companyName: string; - /** - * Reason for the access request. - */ - reason: string; - /** - * IDs for the resources that the viewer requested access to. - */ - requestedResources: Array | null; - accessLevel: ViewerAccessLevel; - /** - * Date the access request was created. - */ - creationDate: string; - /** - * Date the access request was last updated. - */ - updatedDate: string; -}; - -export type PaginatedResponseTrustCenterAccessRequest = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Enum representing the outcome states of a historical trust center access request - */ -export type HistoricalAccessRequestOutcome = 'APPROVED' | 'DENIED'; - -export type TrustCenterAccessRequestHistorical = { - /** - * Unique identifier for the access request. - */ - id: string; - /** - * Email of the requester. - */ - email: string; - /** - * Name of the requester. - */ - name: string; - /** - * Name of the requester's company. - */ - companyName: string; - /** - * Reason for the access request. - */ - reason: string; - /** - * IDs for the resources that the viewer requested access to. - */ - requestedResources: Array | null; - accessLevel: ViewerAccessLevel; - /** - * Date the access request was created. - */ - creationDate: string; - /** - * Date the access request was last updated. - */ - updatedDate: string; - outcome: HistoricalAccessRequestOutcome; - /** - * Reason provided when the access request was denied. Null if not denied or no reason was given. - */ - manualDenialReason: string | null; -}; - -export type PaginatedResponseTrustCenterAccessRequestHistorical = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type ApproveTrustCenterAccessRequestInput = { - /** - * The date access should expire for this viewer. If a date isn't provided, - * access will not expire. - */ - expirationDate?: string; - /** - * Whether to require an NDA for the viewer. Defaults to true. - */ - isNdaRequired?: boolean; - /** - * Identifiers for the resources that this viewer should have access to. If - * this field is omitted, the viewer will have access to all resources that - * they requested. - */ - resourceIds?: Array; - accessLevel?: ViewerAccessLevel; -}; - -export type DenyTrustCenterAccessRequestInput = { - /** - * Reason for denying the access request. - */ - reason?: string; -}; - -export type DocumentAndTestCategory = 'Accounts access' | 'Account security' | 'Account setup' | 'Computers' | 'Custom' | 'Data storage' | 'Employees' | 'Infrastructure' | 'IT' | 'Logging' | 'Monitoring alerts' | 'People' | 'Policies' | 'Risk analysis' | 'Software development' | 'CSPM alert management' | 'Vendors' | 'Vulnerability management'; - -export type TestStatus = 'OK' | 'DEACTIVATED' | 'NEEDS_ATTENTION' | 'IN_PROGRESS' | 'INVALID' | 'NOT_APPLICABLE'; - -export type DeactivatedStatusInfo = { - /** - * The deactivated status of the test. - */ - isDeactivated: boolean; - /** - * The reason for deactivation. - */ - deactivatedReason: string | null; - /** - * The date of the last update to the deactivated status. - */ - lastUpdatedDate: string | null; -}; - -/** - * Enum for the possible test remediation statuses - */ -export type TestRemediationStatus = 'DISABLED' | 'DUE_SOON' | 'INVALID' | 'IN_PROGRESS' | 'NA' | 'NEEDS_WORK' | 'OVERDUE' | 'PASS'; - -export type RemediationStatusInfo = { - status: TestRemediationStatus; - /** - * The soonest date by which the remediation should be completed. - */ - soonestRemediateByDate: string | null; - /** - * The number of items that need remediation. - */ - itemCount: number; -}; - -export type Owner = { - /** - * Unique identifier for the person. - */ - id: string; - /** - * Name of the person that is shown in product. - */ - displayName: string; - /** - * Email address of the person. - */ - emailAddress: string; -}; - -export type Test = { - /** - * The test's unique ID. - */ - id: string; - /** - * The test's name. - */ - name: string; - /** - * The timestamp of the last test run. - */ - lastTestRunDate: string; - /** - * The most recent date when the test flipped. - */ - latestFlipDate: string | null; - /** - * The test's description. - */ - description: string; - /** - * The test's failure description. - */ - failureDescription: string; - /** - * The test's remediation description. - */ - remediationDescription: string; - /** - * The test's version. - */ - version: { - /** - * The minor version number. - */ - minor: number; - /** - * The major version number. - */ - major: number; - }; - category: DocumentAndTestCategory; - /** - * This test's third-party integration dependencies. - */ - integrations: Array; - status: TestStatus; - deactivatedStatusInfo: DeactivatedStatusInfo; - remediationStatusInfo: RemediationStatusInfo; - /** - * The test's owner. - */ - owner: Owner | null; -}; - -export type PaginatedResponseTest = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Categories for tests. - */ -export type TestCategory = 'ACCOUNTS_ACCESS' | 'ACCOUNT_SECURITY' | 'ACCOUNT_SETUP' | 'COMPUTERS' | 'CUSTOM' | 'DATA_STORAGE' | 'EMPLOYEES' | 'INFRASTRUCTURE' | 'IT' | 'LOGGING' | 'MONITORING_ALERTS' | 'PEOPLE' | 'POLICIES' | 'RISK_ANALYSIS' | 'SECURITY_ALERT_MANAGEMENT' | 'SOFTWARE_DEVELOPMENT' | 'VENDORS' | 'VULNERABILITY_MANAGEMENT'; - -export type EntityStatus = 'FAILING' | 'DEACTIVATED'; - -export type TestResourceEntity = { - /** - * The identifier for the entity. - */ - id: string; - entityStatus: EntityStatus; - /** - * The display name of the entity. - */ - displayName: string; - /** - * The response type of the entity. - */ - responseType: string; - /** - * The reason for deactivation. - */ - deactivatedReason: string | null; - /** - * The date of the last update to the test entity. - * Falls back to the test run date if there is no remediation timeline. - */ - lastUpdatedDate: string; - /** - * The date where the test entity was first detected. - * Falls back to the test run date if there is no remediation timeline. - */ - createdDate: string; -}; - -export type PaginatedResponseTestResourceEntity = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type Cia = 'Confidentiality' | 'Integrity' | 'Availability'; - -export type Treatment = 'Mitigate' | 'Transfer' | 'Avoid' | 'Accept'; - -export type CustomAttribute = { - label: string; - value: string | Array; -}; - -export type ReviewStatus = 'APPROVED' | 'DRAFT' | 'NOT_REVIEWED' | 'AWAITING_SUBMISSION' | 'PENDING_APPROVAL' | 'REQUESTED_CHANGES'; - -export type RiskScenarioType = 'Risk Scenario' | 'Enterprise Risk'; - -export type RiskScenario = { - /** - * The unique ID of the risk specified by the user. Used to reference and update existing risks. - */ - riskId: string; - /** - * This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities. - * Document actual issues or likely scenarios based on your specific environment or a potential vulnerability. - * - * Naming note: in the UI, `description` is labelled "Title" and - * `detailedDescription` is labelled "Description". The field names - * are preserved for backwards compatibility with the public REST API - * and existing data. - */ - description: string; - /** - * Optional long-form description providing extended context for the risk scenario. - * Maximum 10000 characters. - * - * Naming note: in the UI, `description` is labelled "Title" and - * `detailedDescription` is labelled "Description". The field names - * are preserved for backwards compatibility with the public REST API - * and existing data. - */ - detailedDescription?: string | null; - /** - * If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions. - * - * @deprecated - */ - isSensitive: boolean | null; - /** - * Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings. - * A value of `null` indicates that no score has been assigned. - */ - likelihood: number | null; - /** - * Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings. - * A value of `null` indicates that no score has been assigned. - */ - impact: number | null; - /** - * Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - * A value of `null` indicates that no score has been assigned. - */ - residualLikelihood: number | null; - /** - * Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - * A value of `null` indicates that no score has been assigned. - */ - residualImpact: number | null; - /** - * The list of categories this risk scenario belongs to. - */ - categories: Array; - /** - * A list of the following for the type of risk documented: - * - Confidentiality: Risk to data stores, customer/sensitive information, etc. - * - Integrity: Risk to accuracy or integrity of system settings and/or data - * - Availability: Risk to normal service operations and critical system functionality - */ - ciaCategories: Array; - /** - * Indicate how your leadership team wants to address an identified risk. Please note: not all risks need to be addressed immediately (or at all). Your Risk Treatment decision will depend on multiple factors, such as your organization's risk tolerance and the value of the asset that the risk is associated with. The options are: - * - Mitigate: Identify controls to put in place or tasks to be done that will reduce the risk score. - * - Transfer: Move risk outside of your organization's set of responsibilities e.g. get cyber liability insurance. - * - Avoid: Stop doing the activity which is causing the risk to your organization and its assets. - * - Accept: Decide to live with the risk and take no further actions. - Accept: decide to live with the risk; this may be because it is highly unlikely, has a low financial or operational impact, or the cost and effort to treat the risk far exceeds the value of the asset - */ - treatment: Treatment | null; - /** - * The email of the person responsible for tracking and mitigating this risk scenario. - */ - owner: string | null; - /** - * Additional context about the risk scenario and why it has specific impact and likelihood scores. - */ - note: string | null; - /** - * Name of the risk register associated with this scenario. - */ - riskRegister: string | null; - /** - * The list of custom fields. - * You can reference existing custom fields in the Risk Management settings and/or create new ones. - * The format is: - * - {label: "field-name", value: "string-representation"} for text, date, number and currency fields - * - {label: "field-name", value: ["option1", "option2"]} for picklist fields - */ - customFields: Array; - /** - * Whether this scenario is archived. - */ - isArchived: boolean; - reviewStatus: ReviewStatus; - /** - * The list of required approvers for this risk scenario. - */ - requiredApprovers: Array; - type: RiskScenarioType; - /** - * The date this risk was identified. Matches the "Identified Date" field in the Vanta UI. Set by the customer when a risk is created; defaults to the scenario's creation time when not explicitly provided. - */ - identificationDate: string; -}; - -export type PaginatedResponseRiskScenario = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type Uncategorized = 'Uncategorized'; - -export type NoTreatmentType = 'No treatment type'; - -export type ScoreGroup = 'Very low' | 'Low' | 'Med' | 'High' | 'Critical'; - -export type CreateRiskScenarioInput = { - /** - * This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities. - * Document actual issues or likely scenarios based on your specific environment or a potential vulnerability. - */ - description: string; - /** - * Optional long-form description providing extended context for the risk scenario. - * Maximum 10000 characters. - */ - detailedDescription?: string; - /** - * The unique ID of the risk. Used to reference and update existing risks. - * We will auto-generate one if one isn't specified. - */ - riskId?: string; - /** - * If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions. - * - * @deprecated - */ - isSensitive?: boolean; - /** - * Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings. - */ - likelihood?: number; - /** - * Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings. - */ - impact?: number; - /** - * Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - */ - residualLikelihood?: number; - /** - * Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - */ - residualImpact?: number; - /** - * The list of categories this risk scenario belongs to. - * Each element in the list will become a new custom category if it doesn't match an existing one. - * You can reference the current category options in the Risk Management settings and/or enter new values. - */ - categories?: Array; - /** - * Enter a list of the following for the type of risk documented: - * - Confidentiality: Risk to data stores, customer/sensitive information, etc. - * - Integrity: Risk to accuracy or integrity of system settings and/or data - * - Availability: Risk to normal service operations and critical system functionality - */ - ciaCategories?: Array; - treatment?: Treatment; - /** - * The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user. - */ - owner?: string; - /** - * Additional context about the risk scenario and why it has specific impact and likelihood scores. - */ - note?: string; - /** - * Name of the risk register to associate with this scenario. - * - * This field must be set if the organization has multiple registers. - */ - riskRegister?: string; - /** - * The list of custom attributes. - * You can reference existing custom attributes in the Risk Management settings and/or create new ones. - * The format is: - * - {label: "field-name", value: "string-representation"} for text, date, number and currency fields - * - {label: "field-name", value: ["option1", "option2"]} for picklist fields - */ - customFields?: Array; - type?: RiskScenarioType; - /** - * The date this risk was identified. Matches the "Identified Date" field in the Vanta UI. Defaults to the scenario's creation time if omitted. - */ - identificationDate?: string; -}; - -export type UpdateRiskScenarioInput = { - /** - * This describes an actual or potential risk to your organization's people, processes, technology, data, and facilities. - * Document actual issues or likely scenarios based on your specific environment or a potential vulnerability. - */ - description?: string; - /** - * Optional long-form description providing extended context for the risk scenario. - * Maximum 10000 characters. - */ - detailedDescription?: string; - /** - * If set to true this risk can only be seen by its owner or users with Admin, RiskSensitiveManage or RiskSensitiveView permissions. - * - * @deprecated - */ - isSensitive?: boolean; - /** - * Represents the probability of an incident occurring due to this risk or vulnerability, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater likelihood. The range can be customized in the Risk Management settings. - */ - likelihood?: number; - /** - * Represents the potential severity of harm to your organization’s operations if this risk is exploited, expressed as a numerical score. - * Defaults to a range of 1-5, where higher values indicate greater impact. The range can be customized in the Risk Management settings. - */ - impact?: number; - /** - * Represents the adjusted probability of this risk being exploited or affecting operations after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - */ - residualLikelihood?: number; - /** - * Represents the adjusted severity of harm to your organization’s operations if this risk is exploited after implementing risk treatments, such as controls or mitigations. - * Expressed as a numerical score, defaulting to a range of 1-5. The range can be customized in the Risk Management settings. - */ - residualImpact?: number; - /** - * The list of categories this risk scenario belongs to. - * Each element in the list will become a new custom category if it doesn't match an existing one. - * You can reference the current category options in the Risk Management settings and/or enter new values. - */ - categories?: Array; - /** - * Enter a list of the following for the type of risk documented: - * - Confidentiality: Risk to data stores, customer/sensitive information, etc. - * - Integrity: Risk to accuracy or integrity of system settings and/or data - * - Availability: Risk to normal service operations and critical system functionality - */ - ciaCategories?: Array; - treatment?: Treatment; - /** - * The person responsible for tracking and mitigating this risk scenario. This should be the email address of a valid Vanta user. - */ - owner?: string | null; - /** - * Additional context about the risk scenario and why it has specific impact and likelihood scores. - */ - note?: string; - /** - * Name of the risk register to associate with this scenario. - */ - riskRegister?: string; - /** - * The list of custom fields. - * You can reference custom fields in the Risk Management settings and/or create new one. - * The format is: - * - {label: "field-name", value: "string-representation"} for text, date, number and currency fields - * - {label: "field-name", value: ["option1", "option2"]} for picklist fields - */ - customFields?: Array; - type?: RiskScenarioType; - /** - * The date this risk was identified. Matches the "Identified Date" field in the Vanta UI. Omitting the field leaves the existing value unchanged. - */ - identificationDate?: string; -}; - -export type SubmitRiskForApprovalInput = { - /** - * Optional comment to include with the approval request. - */ - comment?: string; -}; - -export type RiskScenarioControlType = 'EXISTING' | 'TREATMENT_PLAN'; - -/** - * A control's association with a risk scenario. - * - * The relationship identity is `(riskScenarioId, controlId)`; `controlType` - * is mutable state on that relationship. A given control can have at most one - * association per risk scenario. - */ -export type RiskScenarioControl = { - /** - * The control's shorthand identifier (e.g. `"A.12.2.1"`) when it has one, - * falling back to the canonical Vanta control id (Mongo object id) otherwise. - */ - controlId: string; - controlType: RiskScenarioControlType; -}; - -export type PaginatedResponseRiskScenarioControl = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type CreateRiskScenarioControlInput = { - /** - * Control to associate with the risk scenario. Accepts Vanta control - * shorthands (e.g. `"A.12.2.1"`), custom-control shorthand names, or - * object IDs. - */ - controlId: string; - controlType?: RiskScenarioControlType; -}; - -export type UpdateRiskScenarioControlInput = { - controlType: RiskScenarioControlType; -}; - -export type PolicyStatus = 'OK' | 'NEEDS_REMEDIATION'; - -export type PolicyVersionStatus = 'NOT_STARTED' | 'DRAFT' | 'PENDING_APPROVAL' | 'APPROVED' | 'RENEW_SOON' | 'EXPIRED'; - -export type PolicyLatestVersion = { - status: PolicyVersionStatus; -}; - -export type PolicyLocale = 'CS' | 'CY' | 'DA' | 'DE' | 'EN' | 'ES' | 'FI' | 'FR' | 'HU' | 'IS' | 'IT' | 'JA' | 'KO' | 'NL' | 'NO' | 'NOT_SPECIFIED' | 'PL' | 'PT' | 'ET' | 'RO' | 'AR' | 'SK' | 'SV' | 'TR' | 'ZH'; - -export type PolicyDocument = { - /** - * The language of the policy document. - */ - language: PolicyLocale | null; - /** - * The slug ID of the policy document. - */ - slugId: string; - /** - * The URL of the policy document. - */ - url: string; -}; - -export type PolicyLatestApprovedVersion = { - /** - * The ID of the latest approved version of the policy. - */ - versionId: string; - /** - * Available document versions for this policy, organized by language. - */ - documents: Array; -}; - -export type Policy = { - /** - * The policy's unique ID. - */ - id: string; - /** - * The policy's name. - */ - name: string; - /** - * The policy's description. - */ - description: string; - status: PolicyStatus; - /** - * The policy's most recent date of approval, if applicable. - */ - approvedAtDate: string | null; - latestVersion: PolicyLatestVersion; - /** - * The latest approved version of the policy, if available. - */ - latestApprovedVersion: PolicyLatestApprovedVersion | null; -}; - -export type PaginatedResponsePolicy = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The employment status of a person: - * - UPCOMING: The person is not yet employed and will start employment in the future. - * - CURRENT: The person is currently employed. - * - ON_LEAVE: The person is on leave. - * - INACTIVE: The person's employment is inactive. - * - FORMER: The person was previously employed. - */ -export type EmploymentStatus = 'UPCOMING' | 'CURRENT' | 'ON_LEAVE' | 'INACTIVE' | 'FORMER'; - -/** - * User can be active or upcoming leave period - */ -export type LeaveStatus = 'ACTIVE' | 'UPCOMING'; - -export type LeaveInfo = { - /** - * The start of the person's leave. - */ - startDate: string; - /** - * The end of the person's leave. Null endDate implies indefinite leave. - */ - endDate: string | null; - status: LeaveStatus; -}; - -export type PersonInfoSourceTypeVanta = 'VANTA'; - -/** - * The person's information comes from what is set in Vanta. - */ -export type VantaBasedPersonInfoSource = { - type: PersonInfoSourceTypeVanta; -}; - -export type PersonInfoSourceTypeScim = 'SCIM'; - -/** - * The person's information comes from SCIM. - */ -export type ScimBasedPersonInfoSource = { - type: PersonInfoSourceTypeScim; -}; - -export type PersonInfoSourceTypeIntegration = 'INTEGRATION'; - -/** - * The person's information comes from an integration. - */ -export type IntegrationBasedPersonInfoSource = { - integrationId: string; - resourceId: string | null; - type: PersonInfoSourceTypeIntegration; -}; - -/** - * The source of the person's information. - */ -export type PersonInfoSource = VantaBasedPersonInfoSource | ScimBasedPersonInfoSource | IntegrationBasedPersonInfoSource; - -/** - * The overall status of a person's outstanding tasks: - * - NONE: There are no tasks. - * - DUE_SOON: At least one task is due soon. - * - OVERDUE: At least one task is overdue. Has a higher priority than DUE_SOON. - * - COMPLETE: All tasks are complete. - * - PAUSED: All tasks are paused. - * - OFFBOARDING_DUE_SOON: At least one offboarding task is due soon. - * - OFFBOARDING_OVERDUE: At least one offboarding task is overdue. Has a higher priority than OFFBOARDING_DUE_SOON. - * - OFFBOARDING_COMPLETE: All offboarding tasks are complete. - */ -export type TasksSummaryStatus = 'COMPLETE' | 'DUE_SOON' | 'NONE' | 'OFFBOARDING_COMPLETE' | 'OFFBOARDING_DUE_SOON' | 'OFFBOARDING_OVERDUE' | 'OVERDUE' | 'PAUSED'; - -export type TaskTypeCompleteTrainings = 'COMPLETE_TRAININGS'; - -/** - * A person's security training. - */ -export type Training = { - name: string; -}; - -/** - * The type a task summary falls into. - * COMPLETE_TRAININGS: The task summary containing security trainings. - * ACCEPT_POLICIES: The task summary containing policy acceptance. - * COMPLETE_CUSTOM_TASKS: The task summary containing custom tasks. - * INSTALL_DEVICE_MONITORING: The task summary containing device monitoring installation. - * COMPLETE_BACKGROUND_CHECKS: The task summary containing background checks. - */ -export type TaskType = 'COMPLETE_TRAININGS' | 'ACCEPT_POLICIES' | 'COMPLETE_CUSTOM_TASKS' | 'COMPLETE_CUSTOM_OFFBOARDING_TASKS' | 'INSTALL_DEVICE_MONITORING' | 'COMPLETE_BACKGROUND_CHECKS'; - -/** - * The status of a task. - * - COMPLETE: The task has been completed. - * - DUE_SOON: The task is due soon. - * - OVERDUE: The task is overdue. - * - NONE: The task is not assigned. - */ -export type TaskStatus = 'COMPLETE' | 'DUE_SOON' | 'OVERDUE' | 'NONE'; - -/** - * Task summary for completing all trainings. - */ -export type CompleteTrainingsTaskSummary = { - taskType: TaskTypeCompleteTrainings; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; - /** - * Incomplete security trainings that are relevant given a person's requirements. - */ - incompleteTrainings: Array; - /** - * Security trainings that have been completed and are relevant given a person's current requirements. - */ - completedTrainings: Array; -}; - -export type TaskTypeAcceptPolicies = 'ACCEPT_POLICIES'; - -/** - * Policy acceptance details for a person. - */ -export type AcceptPoliciesTaskSummary = { - taskType: TaskTypeAcceptPolicies; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; - /** - * Unaccepted policies that are relevant to the person. - */ - unacceptedPolicies: Array<{ - name: string; - }>; - /** - * Accepted policies that are relevant to the person. - */ - acceptedPolicies: Array<{ - name: string; - }>; -}; - -export type TaskTypeCompleteCustomTasks = 'COMPLETE_CUSTOM_TASKS'; - -/** - * A custom task. - */ -export type CustomTask = { - name: string; -}; - -/** - * Task summary for completing all custom tasks. - */ -export type CompleteCustomTasksTaskSummary = { - taskType: TaskTypeCompleteCustomTasks; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; - /** - * Incomplete custom tasks that are relevant given a person's requirements. - */ - incompleteCustomTasks: Array; - /** - * Custom tasks that have been completed and are relevant given a person's current requirements. - */ - completedCustomTasks: Array; -}; - -export type TaskTypeCompleteCustomOffboardingTasks = 'COMPLETE_CUSTOM_OFFBOARDING_TASKS'; - -/** - * Task summary for completing all offboarding custom tasks. - */ -export type CompleteOffboardingCustomTasksTaskSummary = { - taskType: TaskTypeCompleteCustomOffboardingTasks; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; - /** - * Incomplete custom tasks that are relevant given a person's requirements. - */ - incompleteCustomOffboardingTasks: Array; - /** - * Custom tasks that have been completed and are relevant given a person's current requirements. - */ - completedCustomOffboardingTasks: Array; -}; - -export type TaskTypeInstallDeviceMonitoring = 'INSTALL_DEVICE_MONITORING'; - -/** - * Task summary for installing device monitoring. - */ -export type InstallDeviceMonitoringTaskSummary = { - taskType: TaskTypeInstallDeviceMonitoring; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; -}; - -export type TaskTypeCompleteBackgroundChecks = 'COMPLETE_BACKGROUND_CHECKS'; - -/** - * Task summary for completing background checks. - */ -export type CompleteBackgroundChecksTaskSummary = { - taskType: TaskTypeCompleteBackgroundChecks; - status: TaskStatus; - /** - * The due date of the task. - */ - dueDate: string | null; - /** - * The date the task was completed. - */ - completionDate: string | null; - /** - * If the task is disabled, the reason and date when it was disabled. - */ - disabled: { - date: string; - reason: string | null; - } | null; -}; - -/** - * All detailed information about a person's tasks, split across task categories. - */ -export type TaskSummaryDetails = { - completeTrainings: CompleteTrainingsTaskSummary; - acceptPolicies: AcceptPoliciesTaskSummary; - completeCustomTasks: CompleteCustomTasksTaskSummary; - completeOffboardingCustomTasks: CompleteOffboardingCustomTasksTaskSummary; - installDeviceMonitoring: InstallDeviceMonitoringTaskSummary; - completeBackgroundChecks: CompleteBackgroundChecksTaskSummary; -}; - -export type Person = { - id: string; - /** - * The ID of the Vanta user account associated with this person, if one exists. - */ - userId: string | null; - emailAddress: string; - employment: { - status: EmploymentStatus; - /** - * The date the person's employment started. - */ - startDate: string; - /** - * The person's job title. - */ - jobTitle: string | null; - /** - * If present, the date the person's employment ended. - */ - endDate: string | null; - }; - /** - * If present, the user's active/upcoming leave. Empty if the user has no active/upcoming leave. - */ - leaveInfo: LeaveInfo | null; - /** - * The id of each group the user belongs to. This includes both manually created groups in Vanta and groups imported from an identity provider. - */ - groupIds: Array; - name: { - /** - * The person's first (given) name. - */ - first: string | null; - /** - * The person's last (family) name. - */ - last: string | null; - /** - * The person's display name, used in Vanta. - */ - display: string; - }; - /** - * The sources of the person's information. - */ - sources: { - employment: { - endDate: PersonInfoSource; - startDate: PersonInfoSource; - }; - emailAddress: PersonInfoSource; - }; - /** - * The person's tasks summary, which aggregates their current status across - * all of their relevant tasks. - */ - tasksSummary: { - details: TaskSummaryDetails; - status: TasksSummaryStatus; - /** - * The due date of the person's earliest-due task. - */ - dueDate: string | null; - /** - * The date when person's tasks were completed. - */ - completionDate: string | null; - }; -}; - -export type PaginatedResponsePerson = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The possible outcomes of a status check. The outcome can be one of the following: - * FAIL: The check is failing. - * IN_PROGRESS: The check needs further data from the given computer in order to evaluate. The field(s) needed from a computer to calculate the ComputerStatusOutcome were null. - * NA: The check is not applicable for the given computer. - * PASS: The check is passing. - */ -export type ComputerStatusOutcome = 'FAIL' | 'IN_PROGRESS' | 'NA' | 'PASS'; - -/** - * The a status check for a computer. Representation for screenlock, diskEncryption, passwordManager, and antivirusInstallation. - */ -export type ComputerStatus = { - outcome: ComputerStatusOutcome; -}; - -/** - * The possible types of the operating system. One of `mac_OS`, `linux`, or `windows`. - */ -export type OperatingSystemType = 'macOS' | 'linux' | 'windows'; - -/** - * The computer's operating system type and version. - */ -export type OperatingSystem = { - type: OperatingSystemType; - /** - * The version of the operating system. - */ - version: string | null; -}; - -export type MonitoredComputer = { - /** - * Unique identifier for the monitored computer. - */ - id: string; - /** - * Hard-coded enums for Vanta-built integrations or application IDs for 3rd-party-built integrations. - */ - integrationId: string; - /** - * Date of the computer's most recent report. - */ - lastCheckDate: string | null; - screenlock: ComputerStatus; - diskEncryption: ComputerStatus; - passwordManager: ComputerStatus; - antivirusInstallation: ComputerStatus; - /** - * The computer's operating system name and version. - */ - operatingSystem: OperatingSystem | null; - /** - * The name, unique identifier, and email address of the computer's owner. - */ - owner: Owner | null; - /** - * The serial number of the computer. This value may be null if it is not reported by the device. - */ - serialNumber: string | null; - /** - * The universal device id of the computer. - */ - udid: string | null; -}; - -export type PaginatedResponseMonitoredComputer = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * Enum representing computer compliance statuses that can be utilized as a filter. The meanings are as follows: - * AV_NOT_INSTALLED: The computer does not have antivirus software installed. - * HD_NOT_ENCRYPTED: The computer's harddrive is not encrypted. - * LAST_CHECK_OVER_14_DAYS: No data has been received from computer for over 14 days. - * PWM_NOT_INSTALLED: The computer does not have a password manager installed. - * SCREENLOCK_NOT_CONFIGURED: The computer does not have screenlock configured appropriately. - */ -export type ComputerStatusFilter = 'PWM_NOT_INSTALLED' | 'HD_NOT_ENCRYPTED' | 'AV_NOT_INSTALLED' | 'SCREENLOCK_NOT_CONFIGURED' | 'LAST_CHECK_OVER_14_DAYS'; - -export type KnowledgeBaseResourceActorAssignment = { - type: 'User' | 'Team'; - id: string; - displayName: string | null; -}; - -/** - * Customer-facing expiration status used by knowledge-base API responses - * (answer library entries and resources). Derived from the persisted - * `expiresAt` field at read time. - */ -export type KnowledgeBaseExpirationStatus = 'CURRENT' | 'EXPIRED'; - -export type TagInput = { - categoryId: string; - tagId: string; -}; - -export type KnowledgeBaseWebpageResourceOutput = { - id: string; - type: 'URL'; - title: string; - description: string | null; - url: string; - customerVisibility: 'PRIVATE' | 'SHAREABLE' | 'REQUEST_ACCESS' | 'PUBLIC' | null; - includeSubPages: boolean | null; - isUsedInQuestionnaires: boolean | null; - ownerAssignment: KnowledgeBaseResourceActorAssignment | null; - expirationStatus: KnowledgeBaseExpirationStatus; - expirationDate: string | null; - lastUpdated: string; - lastVerified: string | null; - tags: Array; - /** - * Trust Center category id the resource is currently filed under, or - * `null` if uncategorized (or not on the Trust Center, which is the case - * for `PRIVATE` / `SHAREABLE` resources). - */ - categoryId: string | null; -}; - -export type KnowledgeBaseResourceActorAssignmentInput = { - /** - * The type of actor. Currently only "User" is supported. - */ - type: 'User'; - /** - * The unique identifier of the user. - */ - id: string; -}; - -/** - * Customer-facing visibility of a knowledge-base resource on the - * Trust Center. Use {@link CUSTOMER_VISIBILITY_TO_DB} to translate to - * {@link TrustCenterResourceVisibility} when persisting. - */ -export type KnowledgeBaseCustomerVisibility = 'PRIVATE' | 'SHAREABLE' | 'REQUEST_ACCESS' | 'PUBLIC'; - -export type CreateWebpageResourceInput = { - /** - * The title of the webpage resource. - */ - title: string; - /** - * The URL of the webpage. - */ - url: string; - /** - * A description for the webpage resource. - */ - description?: string; - ownerAssignment?: KnowledgeBaseResourceActorAssignmentInput; - customerVisibility?: KnowledgeBaseCustomerVisibility; - /** - * Whether to scan sub-pages one level deep alongside the primary URL. - */ - includeSubPages?: boolean; - /** - * Whether the resource should be used for question-answering in - * Questionnaire Automation. - */ - isUsedInQuestionnaires?: boolean; - /** - * Expiration date in ISO 8601 format. - */ - expirationDate?: string; - /** - * Tags to associate with the resource. - */ - tags?: Array; - /** - * Trust Center category id to associate this resource with. Pass `null` - * to keep the resource uncategorized. Only valid when `customerVisibility` - * is REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return - * an InvalidInputError. - */ - categoryId?: string | null; -}; - -export type UpdateWebpageResourceInput = { - /** - * The title of the webpage resource. - */ - title?: string; - /** - * A description for the webpage resource. Pass `null` to clear. - */ - description?: string | null; - /** - * The actor to assign as owner. Pass `null` to clear. Currently only type - * "User" is supported. - */ - ownerAssignment?: KnowledgeBaseResourceActorAssignmentInput | null; - customerVisibility?: KnowledgeBaseCustomerVisibility; - /** - * Whether to scan sub-pages one level deep alongside the primary URL. - */ - includeSubPages?: boolean; - /** - * Whether the resource should be used for question-answering in - * Questionnaire Automation. - */ - isUsedInQuestionnaires?: boolean; - /** - * Expiration date in ISO 8601 format. Pass `null` to clear. - */ - expirationDate?: string | null; - /** - * Tags to associate with the resource. A non-empty array replaces the - * existing tag set; pass `[]` to clear all tags. - */ - tags?: Array; - /** - * Trust Center category id to associate this resource with. Pass `null` - * to move the resource to uncategorized. Only valid when the resource's - * effective visibility (after applying any patched `customerVisibility`) - * is REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return - * an InvalidInputError. - */ - categoryId?: string | null; -}; - -export type KnowledgeBaseDocumentResourceOutput = { - id: string; - type: 'FILE'; - title: string; - description: string | null; - /** - * Presigned S3 URL for the underlying document. Expires after 1 hour due - * to AWS IAM Role limitations on presigned URL lifetimes. Re-fetch the - * resource to obtain a fresh URL once this one expires. - */ - fileUrl: string; - customerVisibility: 'PRIVATE' | 'SHAREABLE' | 'REQUEST_ACCESS' | 'PUBLIC' | null; - downloadPermission: 'VIEW_ONLY' | 'VIEW_AND_DOWNLOAD' | null; - isUsedInQuestionnaires: boolean | null; - ownerAssignment: KnowledgeBaseResourceActorAssignment | null; - expirationStatus: KnowledgeBaseExpirationStatus; - expirationDate: string | null; - lastUpdated: string; - lastVerified: string | null; - tags: Array; - /** - * Trust Center category id the resource is currently filed under, or - * `null` if uncategorized (or not on the Trust Center, which is the case - * for `PRIVATE` / `SHAREABLE` resources). - */ - categoryId: string | null; -}; - -/** - * Discriminated union over `type` of all resource kinds in the Trust - * Knowledge Base (currently FILE and URL). - */ -export type TrustKnowledgeBaseResourceOutput = KnowledgeBaseDocumentResourceOutput | KnowledgeBaseWebpageResourceOutput; - -export type PaginatedResponseTrustKnowledgeBaseResourceOutput = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type KnowledgeBaseResourceTypeFilter = 'FILE' | 'URL'; - -export type VerifyKnowledgeBaseResourceInput = { - /** - * The expiration date in ISO 8601 format. If omitted, falls back to the - * configured review cadence. - */ - expirationDate?: string; -}; - -/** - * Customer-facing download permission for a knowledge-base resource on - * the Trust Center. Use {@link DOWNLOAD_PERMISSION_TO_DB} to translate - * to {@link TrustKnowledgeBaseResourceDownloadSetting} when persisting. - */ -export type KnowledgeBaseResourceDownloadPermission = 'VIEW_ONLY' | 'VIEW_AND_DOWNLOAD'; - -export type UpdateDocumentResourceInput = { - /** - * The title of the document resource. - */ - title?: string; - /** - * A description for the document resource. Pass `null` to clear. - */ - description?: string | null; - /** - * The actor to assign as owner. Pass `null` to clear. Currently only type - * "User" is supported. - */ - ownerAssignment?: KnowledgeBaseResourceActorAssignmentInput | null; - customerVisibility?: KnowledgeBaseCustomerVisibility; - downloadPermission?: KnowledgeBaseResourceDownloadPermission; - /** - * Whether the resource should be used for question-answering in - * Questionnaire Automation. - */ - isUsedInQuestionnaires?: boolean; - /** - * Expiration date in ISO 8601 format. Pass `null` to clear. - */ - expirationDate?: string | null; - /** - * Tags to associate with the resource. A non-empty array replaces the - * existing tag set; pass `[]` to clear all tags. - */ - tags?: Array; - /** - * Trust Center category id to associate this resource with. Pass `null` - * to move the resource to uncategorized. Only valid when the resource's - * effective visibility (after applying any patched `customerVisibility`) - * is REQUEST_ACCESS or PUBLIC; other combinations and unknown ids return - * an InvalidInputError. - */ - categoryId?: string | null; -}; - -export type AnswerLibraryActorAssignment = { - type: 'User' | 'Team'; - id: string; - displayName: string | null; -}; - -export type KnowledgeBaseAnswerLibraryEntryOutput = { - id: string; - question: string; - answer: string; - expirationStatus: 'CURRENT' | 'EXPIRED'; - ownerAssignment: AnswerLibraryActorAssignment | null; - expirationDate: string | null; - lastUpdated: string; - lastVerified: string | null; - tags: Array; -}; - -export type PaginatedResponseKnowledgeBaseAnswerLibraryEntryOutput = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type AnswerLibraryActorAssignmentInput = { - /** - * The type of actor. Currently only "User" is supported. - */ - type: 'User'; - /** - * The unique identifier of the user or team. - */ - id: string; -}; - -export type CreateAnswerLibraryEntryInput = { - /** - * The question text. - */ - question: string; - /** - * The answer text. - */ - answer: string; - ownerAssignment?: AnswerLibraryActorAssignmentInput; - /** - * The expiration date in ISO 8601 format. - */ - expirationDate?: string; - /** - * Tags to associate with the entry. Discover valid `categoryId` and `tagId` - * values via `GET /v1/customer-trust/tag-categories` (to list categories) - * and `GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags - * within a category). - */ - tags?: Array; -}; - -export type UpdateAnswerLibraryEntryInput = { - /** - * The question text. - */ - question?: string; - /** - * The answer text. - */ - answer?: string; - /** - * The actor to assign as owner. Pass `null` to clear. Currently only type - * "User" is supported. - */ - ownerAssignment?: AnswerLibraryActorAssignmentInput | null; - /** - * The expiration date in ISO 8601 format. Pass `null` to clear. - */ - expirationDate?: string | null; - /** - * Tags to associate with the entry. Replaces the existing tag set. Pass - * `[]` to clear all tags. Discover valid `categoryId` and `tagId` values - * via `GET /v1/customer-trust/tag-categories` (to list categories) and - * `GET /v1/customer-trust/tag-categories/{tagCategoryId}` (to list tags - * within a category). - */ - tags?: Array; -}; - -export type VerifyAnswerLibraryEntryInput = { - /** - * The expiration date in ISO 8601 format. If omitted, falls back to the - * configured review cadence. - */ - expirationDate?: string; -}; - -/** - * Extract from T those types that are assignable to U - */ -export type ExtractIssueTemplateStandardIssue = 'STANDARD_ISSUE'; - -export type StandardIssueType = 'AREA_OF_CONCERN' | 'MAJOR_NONCONFORMITY' | 'MINOR_NONCONFORMITY' | 'OPP_FOR_IMPROVEMENT' | 'EXCEPTION' | 'PROCESS_FOR_IMPROVEMENT'; - -export type ActorType = 'USER' | 'WORKFLOW_GENERATED'; - -export type Actor = { - actorType: ActorType; - actorId: string; -}; - -export type OwnerType = 'USER' | 'TEAM'; - -export type IssueOwner = { - ownerType: OwnerType; - ownerId: string; -}; - -export type IssueSeverity = 'CRITICAL' | 'HIGH' | 'MEDIUM' | 'LOW' | 'NO_SEVERITY'; - -export type IssueStatus = 'NOT_STARTED' | 'IN_PROGRESS' | 'CLOSED'; - -export type SourceType = 'AUDIT' | 'AUDIT_EXTERNAL' | 'INCIDENT' | 'EXTERNAL_PARTY' | 'SELF_ASSESSMENT' | 'OTHER'; - -export type Source = { - sourceType: SourceType; - sourceId?: string; -}; - -export type ClosedReason = 'RESOLVED' | 'DUPLICATE' | 'ACCEPTED' | 'OTHER'; - -export type ClosedMetadata = { - reason: ClosedReason; - comment: string; - closedAt: string; -}; - -export type IssueCustomField = { - label: string; - value: string | Array; -}; - -export type StandardIssue = { - id: string; - readableIssueId: string; - createdAt: string; - createdBy: Actor; - lastModifiedBy: Actor; - lastModifiedAt: string; - title: string; - description: string; - owners: Array; - severity: IssueSeverity; - status: IssueStatus; - rootCause: string | null; - correctiveAction: string | null; - dueDate: string | null; - source: Source | null; - controlDomain: string | null; - closedMetadata: ClosedMetadata | null; - detectedAt: string | null; - mappedControlIds: Array; - mappedRiskScenarioIds: Array; - mappedPolicyIds: Array; - customFields: Array; - template: ExtractIssueTemplateStandardIssue; - type: StandardIssueType | null; -}; - -/** - * Extract from T those types that are assignable to U - */ -export type ExtractIssueTemplateStandardPoam = 'STANDARD_POAM'; - -export type StandardPoam = { - id: string; - readableIssueId: string; - createdAt: string; - createdBy: Actor; - lastModifiedBy: Actor; - lastModifiedAt: string; - title: string; - description: string; - owners: Array; - severity: IssueSeverity; - status: IssueStatus; - rootCause: string | null; - correctiveAction: string | null; - dueDate: string | null; - source: Source | null; - controlDomain: string | null; - closedMetadata: ClosedMetadata | null; - detectedAt: string | null; - mappedControlIds: Array; - mappedRiskScenarioIds: Array; - mappedPolicyIds: Array; - customFields: Array; - template: ExtractIssueTemplateStandardPoam; - requiredResources: string | null; - systemsDescription: string | null; -}; - -export type Issue = StandardIssue | StandardPoam; - -export type PaginatedResponseIssue = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type IssueTemplate = 'STANDARD_ISSUE' | 'STANDARD_POAM'; - -export type IssueSortField = 'DUE_DATE' | 'CREATED_AT' | 'DETECTED_AT' | 'LAST_MODIFIED_AT' | 'STATUS' | 'SEVERITY'; - -/** - * Sort direction shared across the external REST API surface. - * - * `"asc"` for ascending, `"desc"` for descending. Endpoints expose this as the - * `orderDirection` / `sortDirection` query parameter and map it onto whatever - * internal direction representation the underlying service expects. - */ -export type OrderDirection = 'asc' | 'desc'; - -export type Connection = { - /** - * The unique identifier for the Connection. - */ - connectionId: string; - /** - * Whether the Connection has been disabled by Vanta. - */ - isDisabled: boolean; - /** - * An error message that may accompany disabled Connections. - */ - connectionErrorMessage: string | null; -}; - -export type Integration = { - /** - * A unique identifier for the Integration. - */ - integrationId: string; - /** - * The Integration's display name. - */ - displayName: string; - /** - * A list of string identifiers for the resource types ingested by the Integration. - */ - resourceKinds: Array; - /** - * A list of installed Connections. - */ - connections: Array; -}; - -export type PaginatedResponseIntegration = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type ResourceKindSummary = { - /** - * The unique identifier for the Integration that ingests this resource. - */ - integrationId: string; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * Whether resources of this type may be scoped out of an audit. - */ - isScopable: boolean; - /** - * Whether resources of this type may be assigned a description. - */ - canUpdateDescription: boolean; - /** - * Whether resources of this type may be assigned an owner. - */ - canUpdateOwner: boolean; -}; - -export type ResourceKindDetails = { - /** - * The unique identifier for the Integration that ingests this resource. - */ - integrationId: string; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * Whether resources of this type may be scoped out of an audit. - */ - isScopable: boolean; - /** - * Whether resources of this type may be assigned a description. - */ - canUpdateDescription: boolean; - /** - * Whether resources of this type may be assigned an owner. - */ - canUpdateOwner: boolean; - /** - * The count of resources of the given type. - */ - numResources: number; - /** - * The count of resources of the given type that are in scope for audits. - */ - numInScope: number; - /** - * The count of resources of the given type that have been assigned an owner in Vanta. - */ - numOwned: number; - /** - * The count of resources of the given type that have been given a description in Vanta. - */ - numWithDescription: number; -}; - -export type UpdateResourceRequest = { - /** - * ID of the resource to update. - */ - id: string; - /** - * Owner ID to update for the resource. - */ - ownerId?: string; - /** - * Description to update for the resource. - */ - description?: string; - /** - * Determines whether resources should be marked in scope or not. - */ - inScope?: boolean; -}; - -export type ResourceResponseType = 'Account' | 'AutoScalingGroup' | 'ClusterDeployment' | 'ComputeInstance' | 'ContainerCluster' | 'ContainerRepository' | 'Database' | 'Device' | 'GitRepository' | 'KubernetesCluster' | 'LoadBalancer' | 'PaaS' | 'Resource' | 'Queue' | 'ServerlessFunction' | 'StorageBucket'; - -export type Resource = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; -}; - -export type CloudInfrastructure = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Resource - */ - account: string; - /** - * Region in which the Resource is located - */ - region: string; -}; - -/** - * A CloudInfrastructure resource backed by a machine image — e.g. a virtual - * machine or a Kubernetes node. Carries the machine image identifier and - * human-readable image name when available. - */ -export type ComputeInstance = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Resource - */ - account: string; - /** - * Region in which the Resource is located - */ - region: string; - /** - * The machine image identifier the resource was launched from (e.g. an AWS - * AMI ID, a GCP image self-link, or an Azure publisher/offer/sku/version - * composite). Null when the image could not be resolved. - */ - machineImageId?: string | null; - /** - * A human-readable name describing the machine image's OS and version (e.g. - * an AMI name or GCP image name). Null when no descriptive name is available. - */ - machineImageName?: string | null; -}; - -export type ContainerRepository = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Resource - */ - account: string; - /** - * Region in which the Resource is located - */ - region: string; - /** - * Whether autoscans have been enabled - */ - isAutoscanEnabled: boolean | null; -}; - -export type Database = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Database - */ - account: string; - /** - * Whether backups are enabled for the Database - */ - areBackupsEnabled: boolean | null; - /** - * Whether the Database is encrypted - */ - isEncrypted: boolean; - /** - * Whether the Database contains Ephi - */ - containsEphi: boolean | null; - /** - * Whether the Database contains user data - */ - containsUserData: boolean | null; -}; - -export type Device = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the operating system - */ - operatingSystemName: string; - /** - * Whether the Device is encrypted - */ - isEncrypted: boolean | null; - /** - * Whether the Device contains Ephi - */ - containsEphi: boolean | null; - /** - * Whether the Device contains user data - */ - containsUserData: boolean | null; -}; - -export type PaaS = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Whether the PaaS contains Ephi - */ - containsEphi: boolean | null; - /** - * Whether the PaaS contains user data - */ - containsUserData: boolean | null; -}; - -export type Queue = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Resource - */ - account: string; - /** - * Region in which the Resource is located - */ - region: string; - /** - * Whether the Queue contains Ephi - */ - containsEphi: boolean | null; - /** - * Whether the Queue contains user data - */ - containsUserData: boolean | null; -}; - -export type StorageBucket = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name of the account associated with the Resource - */ - account: string; - /** - * Region in which the Resource is located - */ - region: string; - /** - * Whether the StorageBucket is encrypted - */ - isEncrypted: boolean; - /** - * Whether the StorageBucket contains Ephi - */ - containsEphi: boolean | null; - /** - * Whether the StorageBucket contains user data - */ - containsUserData: boolean | null; - /** - * Whether the StorageBucket is versioned - */ - isVersioned: boolean | null; -}; - -export type Account = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name associated with the Account - */ - accountName: string; - /** - * Any role(s) assigned to the Account - */ - roles: Array; - /** - * Any groups to which the Account belongs - */ - groups: Array; - /** - * Whether the account has been deactivated/disabled/deleted. - */ - isDeactivated: boolean; - /** - * Whether MFA has been enabled for the account. - */ - isMfaEnabled: boolean | null; -}; - -export type AccessKeyInfo = { - /** - * The access key ID - */ - accessKeyId: string; - /** - * The status of the access key - */ - status: string; -}; - -export type AwsAccount = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Name associated with the Account - */ - accountName: string; - /** - * Any role(s) assigned to the Account - */ - roles: Array; - /** - * Any groups to which the Account belongs - */ - groups: Array; - /** - * Whether the account has been deactivated/disabled/deleted. - */ - isDeactivated: boolean; - /** - * Whether MFA has been enabled for the account. - */ - isMfaEnabled: boolean | null; - /** - * The AWS user account ID associated with the account - */ - awsUserAccountId: string; - /** - * AWS account number (12 digit number) that uniquely identifies your AWS account - */ - awsAccountNumber: string; - /** - * The list of access keys associated with the AWS account - */ - accessKeys: Array; -}; - -export type OrganizationSubunit = { - responseType: ResourceResponseType; - /** - * The identifier for the resource type, unique within the scope of an Integration. - */ - resourceKind: string; - /** - * The unique identifier for the Resource. - */ - resourceId: string; - /** - * The unique identifier for the Connection used to ingest the Resource if it exists. - */ - connectionId: string | null; - /** - * The Resource's display name. - */ - displayName: string; - /** - * The unique identifier for the owner of the resource in Vanta. - */ - owner: string | null; - /** - * Whether the resource is in scope for audits. - */ - inScope: boolean; - /** - * The description of the resource in Vanta. - */ - description: string | null; - /** - * When Vanta first ingested the Resource. - */ - creationDate: string; - /** - * When the resource was deleted/removed from the integration, if applicable. - * This field is only present when the resource has been deleted. - */ - deletedDate?: string | null; - /** - * Account ID corresponding to the subunit. Could be null if the subunit is not an account, e.g. a subscription - */ - accountId: string | null; -}; - -export type AnyResource = Resource | CloudInfrastructure | ComputeInstance | ContainerRepository | Database | Device | PaaS | Queue | StorageBucket | Account | AwsAccount | OrganizationSubunit; - -export type PaginatedResponseAnyResource = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type Group = { - /** - * The group's unique ID. - */ - id: string; - /** - * The group's name. - */ - name: string; - /** - * The group's creation date. - */ - creationDate: string | null; -}; - -export type PaginatedResponseGroup = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type Framework = { - /** - * The framework's unique ID. - */ - id: string; - /** - * The framework's display name. - */ - displayName: string; - /** - * The short version of the framework's display name. - */ - shorthandName: string; - /** - * The framework's description. - */ - description: string; - /** - * The number of completed controls in the framework. - */ - numControlsCompleted: number; - /** - * The total number of controls in the framework. - */ - numControlsTotal: number; - /** - * The number of passing documents in the framework. - */ - numDocumentsPassing: number; - /** - * The total number of documents in the framework. - */ - numDocumentsTotal: number; - /** - * The number of passing tests in the framework. - */ - numTestsPassing: number; - /** - * The total number of tests in the framework. - */ - numTestsTotal: number; -}; - -export type PaginatedResponseFramework = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type FrameworkRequirementCategory = { - /** - * The framework's requiremet category unique ID. - */ - id: string; - /** - * The framework's requiremet category name. - */ - name: string; - /** - * The framework's short name. - */ - shorthand: string | null; - requirements: Array<{ - /** - * The requirement's list of controls - */ - controls: Array<{ - /** - * The control's description. - */ - description: string; - /** - * The control's name. - */ - name: string; - /** - * The control's external ID. - */ - externalId: string | null; - /** - * The control's unique ID. - */ - id: string; - }>; - /** - * The requirement's description - */ - description: string | null; - /** - * The requirement's short name. - */ - shorthand: string | null; - /** - * The requirement's name. - */ - name: string; - /** - * The requirement's unique ID. - */ - id: string; - }>; -}; - -export type FrameworkDetail = { - /** - * The framework's unique ID. - */ - id: string; - /** - * The framework's display name. - */ - displayName: string; - /** - * The short version of the framework's display name. - */ - shorthandName: string; - /** - * The framework's description. - */ - description: string; - /** - * The number of completed controls in the framework. - */ - numControlsCompleted: number; - /** - * The total number of controls in the framework. - */ - numControlsTotal: number; - /** - * The number of passing documents in the framework. - */ - numDocumentsPassing: number; - /** - * The total number of documents in the framework. - */ - numDocumentsTotal: number; - /** - * The number of passing tests in the framework. - */ - numTestsPassing: number; - /** - * The total number of tests in the framework. - */ - numTestsTotal: number; - /** - * The famework's list of requirement categories. - */ - requirementCategories: Array; -}; - -export type ControlSource = 'Vanta' | 'Custom'; - -export type Control = { - /** - * The control's unique ID. - */ - id: string; - /** - * The control's external ID. - */ - externalId: string | null; - /** - * The control's name. - */ - name: string; - /** - * The control's description. - */ - description: string; - source: ControlSource; - /** - * The security domains that the control belongs to. - */ - domains: Array; - /** - * The control's owner. - */ - owner: Owner | null; - /** - * The control's GDPR role, if the control is a GDPR control. - */ - role?: string | null; - /** - * The control's custom field values, if control custom fields is included in your Vanta instance. - */ - customFields: Array; - /** - * When the control was created. Returns null for Vanta library controls. - */ - creationDate: string | null; - /** - * When the control was last modified. Returns null for Vanta library controls. - */ - modificationDate: string | null; -}; - -export type PaginatedResponseControl = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type PaginationArgs = { - pageSize?: PageSize; - pageCursor?: PageCursor; -}; - -export type EventLog = { - /** - * The event log's unique ID. - */ - id: string; - /** - * The event's initiator. - */ - actor: { - /** - * The actor's type. - */ - type: string; - /** - * The actor's unique ID. - */ - id: string; - }; - /** - * The event's creation date. - */ - date: string; - /** - * The event's action. - */ - action: string; - /** - * The list of targets of the event. - */ - targets: Array<{ - /** - * The target's type. - */ - type: string; - /** - * The target's unique ID. - */ - id: string; - }>; -}; - -export type PaginatedResponseEventLog = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type DocumentStatus = 'Needs document' | 'Needs update' | 'Not relevant' | 'OK'; - -export type Document = { - /** - * The document's unique ID. - */ - id: string; - /** - * The user ID of the document's owner. - */ - ownerId: string | null; - category: DocumentAndTestCategory; - /** - * The document's description. - */ - description: string; - /** - * Determines whether or not the document is sensitive. - */ - isSensitive: boolean; - /** - * The document's title. - */ - title: string; - uploadStatus: DocumentStatus; - /** - * The date the document's uploadStatus changed. - */ - uploadStatusDate: string | null; - /** - * The URL to view the document within Vanta. - */ - url: string | null; -}; - -export type SetOwnerForDocumentInput = { - /** - * The new owner ID - */ - userId: string | null; -}; - -export type TimeSensitivity = 'MOST_RECENT' | 'DURING_AUDIT_WINDOW'; - -export type RecurrenceDuration = 'P0D' | 'P1D' | 'P1W' | 'P1M' | 'P3M' | 'P6M' | 'P1Y' | 'P2Y'; - -export type CadenceType = RecurrenceDuration; - -export type ReminderWindow = 'P0D' | 'P1D' | 'P1W' | 'P1M' | 'P3M'; - -export type CreateDocumentInput = { - /** - * The document's title. - */ - title: string; - /** - * The document's description. - */ - description: string; - timeSensitivity: TimeSensitivity; - cadence: RecurrenceDuration; - reminderWindow: ReminderWindow; - /** - * Determines whether or not the document is sensitive. - * This restricts which users can access or upload files to the document. - * Only admins are able to view or upload sensitive documents. - */ - isSensitive: boolean; -}; - -export type UploadedLink = { - /** - * The link's unique ID - */ - id: string; - /** - * The link's creation date. - */ - creationDate: string; - /** - * The link's effective date. - */ - effectiveDate: string | null; - /** - * The link's title. - */ - title: string; - /** - * The link's URL. - */ - url: string; - /** - * The link's description. - */ - description: string; -}; - -export type PaginatedResponseUploadedLink = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type CreateLinkForDocumentInput = { - /** - * The link's URL - */ - url: string; - /** - * The link's title. - */ - title: string; - /** - * The link's description. - */ - description?: string | null; - /** - * The link's effective date. - */ - effectiveDate?: string | null; -}; - -export type UploadedFileT = { - /** - * Unique identifier for the document. - */ - id: string; - /** - * The file name of the document. - */ - fileName: string | null; - /** - * The document's title. - */ - title: string; - /** - * The document's description - */ - description: string | null; - /** - * Mime type of the document. - */ - mimeType: string; - /** - * The actor who uploaded this document. It could be a user or an app. - */ - uploadedBy: { - type: UploadedDocumentUploadedByType; - id: string; - } | null; - /** - * Date of when the document was uploaded. - */ - creationDate: string; - /** - * Date when the document was last updated. - */ - updatedDate: string; - /** - * Date of when the document was deleted. Is set to null if the document has not been deleted. - */ - deletionDate: string | null; - /** - * The document's effective date. - */ - effectiveDate: string | null; - /** - * The document's URL. - */ - url: string; -}; - -export type PaginatedResponseDocument = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type DocumentDetail = { - /** - * The document's unique ID. - */ - id: string; - /** - * The user ID of the document's owner. - */ - ownerId: string | null; - category: DocumentAndTestCategory; - /** - * The document's description. - */ - description: string; - /** - * Determines whether or not the document is sensitive. - */ - isSensitive: boolean; - /** - * The document's title. - */ - title: string; - uploadStatus: DocumentStatus; - /** - * The date the document's uploadStatus changed. - */ - uploadStatusDate: string | null; - /** - * The URL to view the document within Vanta. - */ - url: string | null; - deactivatedStatus: { - /** - * The date the document was deactivated. - */ - creationDate: string; - /** - * The date the deactivation expires. - */ - expiration: string | null; - /** - * The reason for the document was deactivated. - */ - reason: string | null; - /** - * Determines whether or not the document is deactivated. - */ - isDeactivated: boolean; - }; - /** - * A user note for the document. - */ - note: string | null; - /** - * When the document needs to be renewed. - */ - nextRenewalDate: string | null; - renewalCadence: RecurrenceDuration; - /** - * The number of day ahead of the renewal date to send a reminder. - */ - reminderWindow: ReminderWindow | null; - /** - * A list of the emails subscribed to the document. - */ - subscribers: Array; -}; - -export type PaginatedResponseUploadedFileT = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The source of the discovered vendor. - * OKTA: The vendor was discovered via an Okta integration - * JAMF: The vendor was discovered via a JAMF integration - * GSUITE: The vendor was discovered via an GSuite integration - * VENDR: The vendor was discovered via a Vendr integration - * OFFICE: The vendor was discovered via a microsoft office integration - */ -export type DiscoveredVendorSource = 'OKTA' | 'JAMF' | 'GSUITE' | 'VENDR' | 'OFFICE'; - -export type DiscoveredVendor = { - /** - * The discovered vendor's unique ID. - */ - id: string; - /** - * The discovered vendor's display name . - */ - name: string; - /** - * The discovered vendor's vendorNormalized or canonical name. This is used to group duplicate vendors together. - */ - normalizedName: string; - /** - * The discovered vendor's category. - */ - category: { - name: string; - } | null; - source: DiscoveredVendorSource; - /** - * The discovered vendor's imported date. - */ - discoveredDate: string; - /** - * The number of accounts in the discovered vendor. - */ - numberOfAccounts: number; - /** - * Determines whether or not the vendor is ignored. - */ - ignored: { - /** - * The date the discovered vendor was marked as ignored. - */ - ignoredAtDate: string | null; - /** - * The reason the discovered vendor was ignored. - */ - ignoredReason: string | null; - /** - * The user ID who ignored the discovered vendor. - */ - ignoredByUserId: string | null; - } | null; - /** - * Determines whether or not the vendor is rejected. - */ - rejected: { - /** - * The user ID who rejected the discovered vendor. - */ - rejectedByUserId: string | null; - /** - * The reason the discovered vendor was rejected. - */ - rejectedReason: string | null; - /** - * The date the discovered vendor was marked as rejected. - */ - rejectedAtDate: string | null; - } | null; -}; - -export type PaginatedResponseDiscoveredVendor = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -/** - * The scope of a discovered vendor. - * NEEDS_REVIEW: The vendor needs review - * IGNORED: The vendor was ignored - * REJECTED: The vendor was rejected - */ -export type DiscoveredVendorScope = 'NEEDS_REVIEW' | 'IGNORED' | 'REJECTED'; - -export type DiscoveredVendorAccountTypeUser = 'USER'; - -export type DiscoveredVendorUser = { - /** - * The associated user's unique ID. - */ - id: string; - /** - * The associated user's email address. - */ - email: string; - /** - * The associated user's display name . - */ - displayName: string; - type: DiscoveredVendorAccountTypeUser; -}; - -export type DiscoveredVendorAccountTypeComputer = 'COMPUTER'; - -export type DiscoveredVendorComputer = { - /** - * The associated computer's unique ID. - */ - id: string; - /** - * The associated computer's display name. - */ - displayName?: string; - /** - * The associated computer's owner. - */ - owner: DiscoveredVendorUser | null; - type: DiscoveredVendorAccountTypeComputer; -}; - -export type DiscoveredVendorAccount = DiscoveredVendorUser | DiscoveredVendorComputer; - -export type PaginatedResponseDiscoveredVendorAccount = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type UserDefinedTagCategory = { - id: string; - displayName: string; -}; - -export type ArrayResponseUserDefinedTagCategory = { - results: Array; -}; - -export type CustomerTrustProductContextIdFilter = 'EXTERNAL_TRUST_CENTER' | 'DOCUMENT_SHARING' | 'QUESTIONNAIRE'; - -export type UserDefinedTag = { - id: string; - category: string; - displayName: string; -}; - -export type TagCategoryWithTags = { - category: UserDefinedTagCategory; - tags: Array; -}; - -export type QuestionnaireAssignableUser = { - id: string; - displayName: string; -}; - -export type QuestionnaireAssignableUsersResponse = { - results: { - data: Array; - }; -}; - -export type QuestionnaireAssignableUserRole = 'owner' | 'approver'; - -export type CustomerTrustQuestionnaireType = 'SPREADSHEET' | 'WEBSITE' | 'DOCUMENT'; - -export type QuestionnaireStatus = 'APPROVED' | 'IN_PROGRESS' | 'IN_REVIEW' | 'READY_FOR_REVIEW' | 'WAITING_ON_ANSWERS' | 'ON_HOLD' | 'NO_LONGER_NEEDED' | 'COMPLETE' | 'ERROR' | 'EXTRACTING_QUESTIONS' | 'QUEUED_FOR_EXTRACTION' | 'PROCESSING' | 'QUEUED_FOR_PROCESSING' | 'WAITING_ON_COLUMN_SELECTION' | 'WAITING_ON_COLUMN_APPROVAL' | 'QUEUED_FOR_COLUMN_DETECTION' | 'DETECTING_COLUMNS'; - -export type QuestionnaireUser = { - id: string; - displayName: string | null; - email: string | null; -}; - -export type QuestionnaireStatusChangeEntry = { - updatedBy: QuestionnaireUser; - /** - * The date and time when the status was changed - */ - updatedAt: string; - status: QuestionnaireStatus; - /** - * An optional message associated with the status change - */ - message: string | null; -}; - -export type ActorAssignment = { - type: 'User' | 'Team'; - id: string; - displayName: string | null; -}; - -export type CustomerTrustQuestionnaire = { - id: string; - displayName: string; - url?: string; - type: CustomerTrustQuestionnaireType; - status: QuestionnaireStatus; - /** - * The status change history log for the questionnaire. - * Entries are ordered by the most recent status change first. - */ - statusLog: Array; - ownerAssignment?: ActorAssignment; - approverAssignment?: ActorAssignment; - customerTrustAccountId?: string; - dueDate?: string; - metadata?: Array<{ - value: string; - key: string; - }>; - /** - * Tags assigned to this questionnaire. Each entry contains a categoryId and tagId. - */ - tagAndCategoryIds: Array; - createdDate: string; - updatedDate: string; - completedDate?: string; -}; - -export type ActorAssignmentInput = { - type: 'User' | 'Team'; - id: string; -}; - -export type QuestionnaireMetadata = { - key: string; - value: string; -}; - -/** - * Request body for creating a website-based questionnaire from a portal URL. - */ -export type CreateWebsiteQuestionnaireInput = { - /** - * Display name for the questionnaire. - */ - displayName: string; - /** - * The portal URL to create the questionnaire from. - */ - url: string; - ownerAssignment?: ActorAssignmentInput; - approverAssignment?: ActorAssignmentInput; - /** - * URL of the company associated with this questionnaire. - */ - companyUrl?: string; - /** - * ID of the customer trust account to associate with this questionnaire. - */ - customerTrustAccountId?: string; - /** - * Description of the questionnaire. - */ - description?: string; - /** - * Due date for questionnaire completion (ISO 8601). - */ - dueDate?: string; - /** - * Custom key-value pairs. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods. Maximum 30 entries. - */ - metadata?: Array; - /** - * Category IDs for which to include untagged entities. - */ - includeUntaggedEntitiesForCategoryIds?: Array; - /** - * Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags. - */ - tagAndCategoryIds?: Array; -}; - -export type PaginatedResponseCustomerTrustQuestionnaire = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type SettableQuestionnaireStatus = 'IN_PROGRESS' | 'IN_REVIEW' | 'READY_FOR_REVIEW' | 'WAITING_ON_ANSWERS' | 'ON_HOLD' | 'NO_LONGER_NEEDED'; - -/** - * Actor assignment for setting an owner or approver. - */ -export type UpdateActorAssignment = { - /** - * The type of actor: "User" for an individual user, "Team" for a team. - */ - type: 'User' | 'Team'; - /** - * The unique identifier of the user or team. - */ - id: string; -}; - -export type UpdateQuestionnaireArgs = { - /** - * Display name of the questionnaire - */ - displayName?: string; - /** - * Due date for questionnaire completion (ISO 8601 string, null to clear) - */ - dueDate?: string | null; - status?: SettableQuestionnaireStatus; - /** - * Owner assignment as Actor (null to unassign) - */ - ownerAssignment?: UpdateActorAssignment | null; - /** - * Approver assignment as Actor (null to unassign, requires QuestionnaireAutomationAdvanced) - */ - approverAssignment?: UpdateActorAssignment | null; - /** - * Metadata key-value pairs - */ - metadata?: Array; - /** - * Tags to assign to the questionnaire. Each entry must include a categoryId and tagId. Replaces all existing tags. - */ - tagAndCategoryIds?: Array; -}; - -/** - * Request body for completing a questionnaire. - */ -export type CompleteQuestionnaireRequest = { - /** - * Whether to sync approved answers to the answer library. - * Defaults to true. Ignored for non-English SPREADSHEET/DOCUMENT questionnaires. - */ - shouldSyncApprovedToAnswerLibrary?: boolean; -}; - -/** - * Request body for approving a questionnaire. - */ -export type ApproveQuestionnaireRequest = { - /** - * Optional message describing the reason for approval. - */ - statusChangeMessage?: string; -}; - -/** - * Response returned when a questionnaire export is created. - * Use the `id` to poll the GET endpoint for export status and download URL. - */ -export type CustomerTrustCreateQuestionnaireExportResponse = { - /** - * Unique identifier for the export job. Use this ID to check export status. - */ - id: string; - /** - * Processing status of the export. Newly created exports always start as `"pending"`. - */ - status: 'pending' | 'completed' | 'failed'; - /** - * The requested output format for the export. - */ - format: 'original' | 'csv'; - /** - * ISO 8601 timestamp indicating when the export was requested. - */ - requestedAt: string; -}; - -/** - * Request body for creating a questionnaire export. - */ -export type CustomerTrustCreateQuestionnaireExportInput = { - /** - * Unique identifier for the questionnaire to trigger an export for. - */ - questionnaireId: string; - /** - * The output format for the exported questionnaire. - * - `"original"`: Exports in the questionnaire's native format (XLSX for spreadsheets, DOCX for documents). - * - `"csv"`: Exports as a CSV file, suitable for data analysis or import into other systems. - */ - format: 'original' | 'csv'; -}; - -/** - * Detailed status and result of a questionnaire export. - * When `status` is `"completed"`, the response includes a time-limited download URL. - */ -export type CustomerTrustExportStatusResponse = { - /** - * Unique identifier for the export job. - */ - id: string; - /** - * Processing status of the export. - * - `"pending"`: Export is still being processed. - * - `"completed"`: Export finished successfully. Download URL is available. - * - `"failed"`: Export failed. See `errorMessage` for details. - */ - status: 'pending' | 'completed' | 'failed'; - /** - * The output format of the exported file. - */ - format: 'original' | 'csv'; - /** - * ISO 8601 timestamp indicating when the export was requested. - */ - requestedAt: string; - /** - * ISO 8601 timestamp indicating when the export completed successfully. - * Only present when `status` is `"completed"`. - */ - completedAt?: string; - /** - * Pre-signed URL for downloading the exported file. Valid for 24 hours from the time of this response. - * Only present when `status` is `"completed"`. - */ - downloadUrl?: string; - /** - * ISO 8601 timestamp indicating when the download URL expires. After this time, request a new export. - * Only present when `status` is `"completed"`. - */ - expiresAt?: string; - /** - * ISO 8601 timestamp indicating when the export failed. - * Only present when `status` is `"failed"`. - */ - failedAt?: string; - /** - * Human-readable description of why the export failed. - * Only present when `status` is `"failed"`. - */ - errorMessage?: string; -}; - -/** - * Response returned after a data deletion request is created. - */ -export type CreateDeletionRequestResponse = { - /** - * Whether the deletion request was successfully enqueued. - */ - success: boolean; -}; - -/** - * Request body for creating a data deletion request. - */ -export type CreateDeletionRequestInput = { - /** - * Email address of the individual requesting data deletion. - */ - email: string; -}; - -export type CustomerTrustAccountNdaStatus = 'SIGNED' | 'NOT_REQUIRED' | 'INCOMPLETE'; - -export type CustomerTrustAccountNdaDetails = { - ndaStatus: CustomerTrustAccountNdaStatus; - /** - * The date and time the NDA was satisfied - */ - ndaSatisfiedDate: string | null; -}; - -/** - * How a CustomerTrustAccount determines which resources to grant its viewers access to. - */ -export type CustomerTrustAccountGrantAccessOption = 'INCLUDE_EVERYTHING_REQUESTED' | 'INCLUDE_ONLY_CONFIGURED'; - -export type CustomerTrustAccountAccessConfig = { - /** - * Whether access requests matching this account's email domain should be auto-approved - */ - autoApprovalEnabled: boolean; - /** - * How to grant resource access for auto-approved requests - */ - grantAccessOption: CustomerTrustAccountGrantAccessOption | null; -}; - -export type TagsByCategoryOutput = { - /** - * The tag category ID - */ - categoryId: string; - /** - * Tag IDs assigned in this category - */ - tagIds: Array; -}; - -/** - * Vanta API representation of a CustomerTrustAccount. - */ -export type CustomerTrustAccountVantaApi = { - /** - * Unique identifier for the account - */ - id: string; - /** - * Name of the account - */ - name: string; - /** - * Primary email domain associated with the account - */ - emailDomain: string; - /** - * When the account was created - */ - createdDate: string; - /** - * When the account was last updated - */ - updatedDate: string; - ndaDetails: CustomerTrustAccountNdaDetails; - /** - * Access configuration for this account - */ - accessConfig: CustomerTrustAccountAccessConfig | null; - /** - * Custom field values for this account - */ - customFields: Array; - /** - * Tags assigned to this account, grouped by category - */ - tagsByCategory: Array; -}; - -export type PaginatedResponseCustomerTrustAccountVantaApi = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type CustomerTrustAccountNdaDetailsInput = { - /** - * Whether NDA requirement should be bypassed for access requests matching this account - */ - markNdaNotRequired: boolean; -}; - -export type CustomerTrustAccountAccessConfigInput = { - /** - * Whether access requests matching this account's email domain should be auto-approved - */ - autoApprovalEnabled: boolean; - /** - * How to grant resource access for auto-approved requests. Must be specified if autoApprovalEnabled is true - */ - grantAccessOption?: CustomerTrustAccountGrantAccessOption | null; - /** - * Tags to assign to this account, grouped by category. - * - * @deprecated - */ - tagsByCategory?: Array; -}; - -export type CreateCustomerTrustAccountInput = { - name: string; - emailDomain: string; - ndaDetails?: CustomerTrustAccountNdaDetailsInput; - accessConfig?: CustomerTrustAccountAccessConfigInput; - customFields?: Array; - /** - * Tags to assign to this account, grouped by category - */ - tagsByCategory?: Array; -}; - -export type EditCustomerTrustAccountInput = { - /** - * Updated name for the account - */ - name?: string; - /** - * Updated primary email domain for the account - */ - emailDomain?: string; - /** - * Updated custom field values for the account - */ - customFields?: Array; - /** - * Tags to assign to this account, grouped by category. Replaces existing tags per category. - */ - tagsByCategory?: Array; -}; - -export type ControlDomain = 'ARTIFICIAL_&_AUTONOMOUS_TECHNOLOGY' | 'ASSET_MANAGEMENT' | 'BUSINESS_CONTINUITY_&_DISASTER_RECOVERY' | 'CAPACITY_&_PERFORMANCE_PLANNING' | 'CHANGE_MANAGEMENT' | 'CLOUD_SECURITY' | 'COMPLIANCE' | 'CONFIGURATION_MANAGEMENT' | 'CONTINUOUS_MONITORING' | 'CRYPTOGRAPHIC_PROTECTIONS' | 'DATA_CLASSIFICATION_&_HANDLING' | 'EMBEDDED_TECHNOLOGY' | 'ENDPOINT_SECURITY' | 'HUMAN_RESOURCES_SECURITY' | 'IDENTIFICATION_&_AUTHENTICATION' | 'INCIDENT_RESPONSE' | 'INFORMATION_ASSURANCE' | 'MAINTENANCE' | 'MOBILE_DEVICE_MANAGEMENT' | 'NETWORK SECURITY' | 'PHYSICAL_&_ENVIRONMENTAL_SECURITY' | 'PRIVACY' | 'PROJECT_&_RESOURCE MANAGEMENT' | 'RISK_MANAGEMENT' | 'SECURE_ENGINEERING_&_ARCHITECTURE' | 'SECURITY_AWARENESS_&_TRAINING' | 'SECURITY_OPERATIONS' | 'SECURITY_&_PRIVACY_GOVERNANCE' | 'TECHNOLOGY_DEVELOPMENT_&_ACQUISITION' | 'THIRD-PARTY_MANAGEMENT' | 'THREAT_MANAGEMENT' | 'VULNERABILITY_&_PATCH_MANAGEMENT' | 'WEB_SECURITY' | 'ADMINISTRATIVE' | 'PHYSICAL' | 'TECHNICAL' | 'BASIC' | 'DERIVED'; - -export type FrameworkId = 'AU_E_8' | 'AWS_FTR' | 'CCPA' | 'CIS_V8' | 'CPS_234' | 'DORA' | 'FEDRAMP' | 'GDPR' | 'HIPAA' | 'HITRUST_E1' | 'ISO_27001' | 'ISO_27001_2022' | 'ISO_27017' | 'ISO_27018' | 'ISO_27701' | 'ISO_42001' | 'ISO_9001' | 'MSFT_SSPA' | 'MVSP' | 'NIS_2D' | 'NIST_171' | 'NIST_53' | 'NIST_AI_RMF' | 'NIST_CSF' | 'NIST_CSF_2' | 'OFDSS' | 'PCI_SAQ_A' | 'PCI_SAQ_A_EP' | 'PCI_SAQ_D_MERCHANT' | 'PCI_SAQ_D_SP' | 'PCI_DDS_4' | 'SOC_2' | 'SOX_ITGC' | 'UK_CYBER_ESSENTIALS' | 'US_DATA_PRIVACY'; - -export type FrameworkSection = { - frameworkId: FrameworkId | string; - sectionId: string; -}; - -export type GdprRole = 'BOTH' | 'CONTROLLER' | 'PROCESSOR'; - -export type CreateControlInput = { - /** - * The control's external ID. - */ - externalId: string; - /** - * The control's name. - */ - name: string | null; - /** - * The control's description. - */ - description: string; - /** - * The effective date of the control. - */ - effectiveDate: string; - domain: ControlDomain; - /** - * The framework sections that the control maps to. - */ - sections?: Array | null; - /** - * The GDPR role of the control, which specifies whether the data is being "collected" or "processed". - * This field should only be included for controls that are to be mapped to the GDPR framework. - */ - role?: GdprRole | null; - /** - * The control's values for custom fields. - */ - customFields?: Array; -}; - -export type AddControlFromLibraryInput = { - /** - * The ID of the control to be added. - */ - controlId: string; -}; - -export type ControlStatus = 'NO_EVIDENCE_MAPPED' | 'NOT_STARTED' | 'IN_PROGRESS' | 'COMPLETED'; - -export type ControlDetail = { - /** - * The control's unique ID. - */ - id: string; - /** - * The control's external ID. - */ - externalId: string | null; - /** - * The control's name. - */ - name: string; - /** - * The control's description. - */ - description: string; - source: ControlSource; - /** - * The security domains that the control belongs to. - */ - domains: Array; - /** - * The control's owner. - */ - owner: Owner | null; - /** - * The control's GDPR role, if the control is a GDPR control. - */ - role?: string | null; - /** - * The control's custom field values, if control custom fields is included in your Vanta instance. - */ - customFields: Array; - /** - * When the control was created. Returns null for Vanta library controls. - */ - creationDate: string | null; - /** - * When the control was last modified. Returns null for Vanta library controls. - */ - modificationDate: string | null; - /** - * The number of passing documents that are linked to the control. - */ - numDocumentsPassing: number; - /** - * The total number of documents that are linked to the control. - */ - numDocumentsTotal: number; - /** - * The number of passing tests that are linked to the control. - */ - numTestsPassing: number; - /** - * The total number of tests that are linked to the control. - */ - numTestsTotal: number; - status: ControlStatus; - /** - * A user created note for the control. - */ - note: string | null; -}; - -export type EditControlMetadataInput = { - /** - * A new name for the control. - */ - name?: string; - /** - * The new external ID for the control. - */ - externalId?: string; - /** - * The new description for the control. - */ - description?: string; - domain?: ControlDomain; - /** - * The new note for the control. - */ - note?: string; - /** - * The control's new values for custom fields. - */ - customFields?: Array; -}; - -export type SetOwnerForControlInput = { - /** - * The new owner's ID. - */ - userId: string | null; -}; - -export type AddControlDocumentMappingInput = { - /** - * The ID of the document to add to the control. - */ - documentId: string; -}; - -export type AddControlTestMappingInput = { - /** - * The ID of the test to add to the control. - */ - testId: string; -}; - -export type Contract = { - /** - * Unique identifier for the contract. - */ - id: string; - /** - * Name of the contract. - */ - name: string; - /** - * The ID of the customer trust account this contract is linked to, if any. - */ - customerTrustAccountId: string | null; - /** - * Date this contract was executed. - */ - executedDate: string | null; - /** - * Date this contract was created in Vanta. - */ - creationDate: string; -}; - -export type PaginatedResponseContract = { - results: { - data: Array; - pageInfo: PageInfo; - }; -}; - -export type TagIdentifier = { - categoryId: string; - categoryName: string; - tagId: string; - tagName: string; -}; - -export type QuestionAnswerOutput = { - /** - * The question text. - */ - question: string; - /** - * The most recent date the question or answer was updated. - */ - lastUpdated: string; - answer: { - fullText: string; - multipleChoice: string | null; - explanation: string | null; - }; - /** - * The id of the upserted entry. - */ - id: string; - /** - * A list of tags associated with this Answer Library entry. - */ - tagIdentifiers: Array; -}; - -export type QuestionAnswerInput = { - /** - * The question text. - */ - question: string; - /** - * The most recent date the question or answer was updated. - */ - lastUpdated: string; - /** - * The answer text. - */ - answer: string; - tagAndCategoryIds?: Array; -}; - -export type ListContractsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/contracts'; -}; - -export type ListContractsResponses = { - /** - * Ok - */ - 200: PaginatedResponseContract; -}; - -export type ListContractsResponse = ListContractsResponses[keyof ListContractsResponses]; - -export type UploadContractData = { - body: { - /** - * The contract file to upload. Only PDF files are accepted. - */ - file: Blob | File; - /** - * ISO 8601 date indicating when the contract was executed. - */ - executedDate?: string; - /** - * ID of the customer trust account to associate with this contract. - */ - accountId?: string; - }; - path?: never; - query?: never; - url: '/contracts'; -}; - -export type UploadContractResponses = { - /** - * Contract created - */ - 201: Contract; -}; - -export type UploadContractResponse = UploadContractResponses[keyof UploadContractResponses]; - -export type DeleteContractData = { - body?: never; - path: { - contractId: string; - }; - query?: never; - url: '/contracts/{contractId}'; -}; - -export type DeleteContractResponses = { - /** - * Contract deleted - */ - 204: void; -}; - -export type DeleteContractResponse = DeleteContractResponses[keyof DeleteContractResponses]; - -export type GetContractData = { - body?: never; - path: { - contractId: string; - }; - query?: never; - url: '/contracts/{contractId}'; -}; - -export type GetContractResponses = { - /** - * Ok - */ - 200: Contract; -}; - -export type GetContractResponse = GetContractResponses[keyof GetContractResponses]; - -export type ListControlsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Includes all controls belonging to one of the provided framework values in frameworkMatchesAny. - */ - frameworkMatchesAny?: Array; - }; - url: '/controls'; -}; - -export type ListControlsResponses = { - /** - * Ok - */ - 200: PaginatedResponseControl; -}; - -export type ListControlsResponse = ListControlsResponses[keyof ListControlsResponses]; - -export type CreateCustomControlData = { - body: CreateControlInput; - path?: never; - query?: never; - url: '/controls'; -}; - -export type CreateCustomControlResponses = { - /** - * Custom Control created - */ - 201: Control; -}; - -export type CreateCustomControlResponse = CreateCustomControlResponses[keyof CreateCustomControlResponses]; - -export type AddControlFromLibraryData = { - body: AddControlFromLibraryInput; - path?: never; - query?: never; - url: '/controls/add-from-library'; -}; - -export type AddControlFromLibraryResponses = { - /** - * Ok - */ - 200: Control; -}; - -export type AddControlFromLibraryResponse = AddControlFromLibraryResponses[keyof AddControlFromLibraryResponses]; - -export type ListLibraryControlsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/controls/controls-library'; -}; - -export type ListLibraryControlsResponses = { - /** - * Ok - */ - 200: PaginatedResponseControl; -}; - -export type ListLibraryControlsResponse = ListLibraryControlsResponses[keyof ListLibraryControlsResponses]; - -export type DeleteControlData = { - body?: never; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}'; -}; - -export type DeleteControlResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteControlResponse = DeleteControlResponses[keyof DeleteControlResponses]; - -export type GetControlData = { - body?: never; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}'; -}; - -export type GetControlResponses = { - /** - * Ok - */ - 200: ControlDetail; -}; - -export type GetControlResponse = GetControlResponses[keyof GetControlResponses]; - -export type UpdateControlMetadataData = { - body: EditControlMetadataInput; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}'; -}; - -export type UpdateControlMetadataResponses = { - /** - * Ok - */ - 200: ControlDetail; -}; - -export type UpdateControlMetadataResponse = UpdateControlMetadataResponses[keyof UpdateControlMetadataResponses]; - -export type AddDocumentToControlData = { - body: AddControlDocumentMappingInput; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}/add-document-to-control'; -}; - -export type AddDocumentToControlResponses = { - /** - * Ok - */ - 200: { - document: Document; - control: Control; - }; -}; - -export type AddDocumentToControlResponse = AddDocumentToControlResponses[keyof AddDocumentToControlResponses]; - -export type AddTestToControlData = { - body: AddControlTestMappingInput; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}/add-test-to-control'; -}; - -export type AddTestToControlResponses = { - /** - * Ok - */ - 200: { - test: Test; - control: Control; - }; -}; - -export type AddTestToControlResponse = AddTestToControlResponses[keyof AddTestToControlResponses]; - -export type ListDocumentsForControlData = { - body?: never; - path: { - controlId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/controls/{controlId}/documents'; -}; - -export type ListDocumentsForControlResponses = { - /** - * Ok - */ - 200: PaginatedResponseDocument; -}; - -export type ListDocumentsForControlResponse = ListDocumentsForControlResponses[keyof ListDocumentsForControlResponses]; - -export type DeleteDocumentForcontrolData = { - body?: never; - path: { - controlId: string; - documentId: string; - }; - query?: never; - url: '/controls/{controlId}/documents/{documentId}'; -}; - -export type DeleteDocumentForcontrolResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteDocumentForcontrolResponse = DeleteDocumentForcontrolResponses[keyof DeleteDocumentForcontrolResponses]; - -export type SetOwnerForControlData = { - body: SetOwnerForControlInput; - path: { - controlId: string; - }; - query?: never; - url: '/controls/{controlId}/set-owner'; -}; - -export type SetOwnerForControlResponses = { - /** - * Ok - */ - 200: Control; -}; - -export type SetOwnerForControlResponse = SetOwnerForControlResponses[keyof SetOwnerForControlResponses]; - -export type ListTestsForControlData = { - body?: never; - path: { - controlId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/controls/{controlId}/tests'; -}; - -export type ListTestsForControlResponses = { - /** - * Ok - */ - 200: PaginatedResponseTest; -}; - -export type ListTestsForControlResponse = ListTestsForControlResponses[keyof ListTestsForControlResponses]; - -export type DeleteTestForControlData = { - body?: never; - path: { - controlId: string; - testId: string; - }; - query?: never; - url: '/controls/{controlId}/tests/{testId}'; -}; - -export type DeleteTestForControlResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTestForControlResponse = DeleteTestForControlResponses[keyof DeleteTestForControlResponses]; - -export type ListCustomerTrustAccountsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - searchString?: string; - isAutoApprovalEnabled?: boolean; - customFieldsFilter?: string; - }; - url: '/customer-trust/accounts'; -}; - -export type ListCustomerTrustAccountsResponses = { - /** - * Ok - */ - 200: PaginatedResponseCustomerTrustAccountVantaApi; -}; - -export type ListCustomerTrustAccountsResponse = ListCustomerTrustAccountsResponses[keyof ListCustomerTrustAccountsResponses]; - -export type CreateCustomerTrustAccountData = { - body: CreateCustomerTrustAccountInput; - path?: never; - query?: never; - url: '/customer-trust/accounts'; -}; - -export type CreateCustomerTrustAccountResponses = { - /** - * Ok - */ - 200: CustomerTrustAccountVantaApi; -}; - -export type CreateCustomerTrustAccountResponse = CreateCustomerTrustAccountResponses[keyof CreateCustomerTrustAccountResponses]; - -export type DeleteCustomerTrustAccountData = { - body?: never; - path: { - accountId: string; - }; - query?: never; - url: '/customer-trust/accounts/{accountId}'; -}; - -export type DeleteCustomerTrustAccountResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteCustomerTrustAccountResponse = DeleteCustomerTrustAccountResponses[keyof DeleteCustomerTrustAccountResponses]; - -export type GetCustomerTrustAccountData = { - body?: never; - path: { - accountId: string; - }; - query?: never; - url: '/customer-trust/accounts/{accountId}'; -}; - -export type GetCustomerTrustAccountResponses = { - /** - * Ok - */ - 200: CustomerTrustAccountVantaApi; -}; - -export type GetCustomerTrustAccountResponse = GetCustomerTrustAccountResponses[keyof GetCustomerTrustAccountResponses]; - -export type UpdateCustomerTrustAccountData = { - body: EditCustomerTrustAccountInput; - path: { - accountId: string; - }; - query?: never; - url: '/customer-trust/accounts/{accountId}'; -}; - -export type UpdateCustomerTrustAccountResponses = { - /** - * Ok - */ - 200: CustomerTrustAccountVantaApi; -}; - -export type UpdateCustomerTrustAccountResponse = UpdateCustomerTrustAccountResponses[keyof UpdateCustomerTrustAccountResponses]; - -export type ListQuestionnairesData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter questionnaires by display name (case-insensitive, partial match). - */ - q?: string; - /** - * Filter questionnaires matching any of the provided statuses. - */ - statusMatchesAny?: Array; - /** - * Filter questionnaires matching any of the provided types. - */ - typeMatchesAny?: Array; - /** - * Filter to questionnaires created after this date (ISO 8601 string). - */ - createdAfter?: string; - /** - * Filter to questionnaires created before this date (ISO 8601 string). - */ - createdBefore?: string; - /** - * Filter to questionnaires owned by any of the provided user IDs. - */ - ownerIdMatchesAny?: Array; - /** - * Filter to questionnaires with an approver matching any of the provided user IDs. - */ - approverIdMatchesAny?: Array; - }; - url: '/customer-trust/questionnaires'; -}; - -export type ListQuestionnairesResponses = { - /** - * Ok - */ - 200: PaginatedResponseCustomerTrustQuestionnaire; -}; - -export type ListQuestionnairesResponse = ListQuestionnairesResponses[keyof ListQuestionnairesResponses]; - -export type ListAssignableUsersData = { - body?: never; - path?: never; - query?: { - /** - * Filter by role: "owner" or "approver". - */ - role?: QuestionnaireAssignableUserRole; - /** - * Optional search string to filter users by name or email. - */ - q?: string; - }; - url: '/customer-trust/questionnaires/assignable-users'; -}; - -export type ListAssignableUsersResponses = { - /** - * Ok - */ - 200: QuestionnaireAssignableUsersResponse; -}; - -export type ListAssignableUsersResponse = ListAssignableUsersResponses[keyof ListAssignableUsersResponses]; - -export type CreateQuestionnaireExportData = { - body: CustomerTrustCreateQuestionnaireExportInput; - path?: never; - query?: never; - url: '/customer-trust/questionnaires/exports'; -}; - -export type CreateQuestionnaireExportResponses = { - /** - * Export created - */ - 202: CustomerTrustCreateQuestionnaireExportResponse; -}; - -export type CreateQuestionnaireExportResponse = CreateQuestionnaireExportResponses[keyof CreateQuestionnaireExportResponses]; - -export type GetQuestionnaireExportData = { - body?: never; - path: { - /** - * The unique identifier of the export job, returned from the POST endpoint. - */ - id: string; - }; - query?: never; - url: '/customer-trust/questionnaires/exports/{id}'; -}; - -export type GetQuestionnaireExportResponses = { - /** - * The export status and, if completed, the download URL. - */ - 200: CustomerTrustExportStatusResponse; -}; - -export type GetQuestionnaireExportResponse = GetQuestionnaireExportResponses[keyof GetQuestionnaireExportResponses]; - -export type CreateFileQuestionnaireData = { - body: { - file: Blob | File; - /** - * Display name for the questionnaire. - */ - displayName: string; - /** - * Owner to assign, as a JSON string: {"type": "User" | "Team", "id": ""}. - */ - ownerAssignment?: string; - /** - * Approver to assign, as a JSON string: {"type": "User" | "Team", "id": ""}. - */ - approverAssignment?: string; - /** - * Description of the questionnaire. - */ - description?: string; - /** - * URL of the company associated with this questionnaire. - */ - companyUrl?: string; - /** - * Due date for questionnaire completion. - */ - dueDate?: string; - /** - * ID of the customer trust account to associate with this questionnaire. - */ - customerTrustAccountId?: string; - /** - * Comma-separated category IDs for which to include untagged entities. - */ - includeUntaggedEntitiesForCategoryIds?: string; - /** - * Custom key-value pairs, as a JSON string array: [{"key": "", "value": ""}]. Keys and values may contain alphanumeric characters, hyphens, underscores, and periods. - */ - metadata?: string; - /** - * Tags to assign, as a JSON string array: [{"categoryId": "", "tagId": ""}]. Replaces all existing tags. - */ - tagAndCategoryIds?: string; - }; - path?: never; - query?: never; - url: '/customer-trust/questionnaires/file'; -}; - -export type CreateFileQuestionnaireResponses = { - /** - * File questionnaire created - */ - 201: CustomerTrustQuestionnaire; -}; - -export type CreateFileQuestionnaireResponse = CreateFileQuestionnaireResponses[keyof CreateFileQuestionnaireResponses]; - -export type CreateWebsiteQuestionnaireData = { - body: CreateWebsiteQuestionnaireInput; - path?: never; - query?: never; - url: '/customer-trust/questionnaires/website'; -}; - -export type CreateWebsiteQuestionnaireResponses = { - /** - * Website questionnaire created - */ - 201: CustomerTrustQuestionnaire; -}; - -export type CreateWebsiteQuestionnaireResponse = CreateWebsiteQuestionnaireResponses[keyof CreateWebsiteQuestionnaireResponses]; - -export type DeleteQuestionnaireData = { - body?: never; - path: { - questionnaireId: string; - }; - query?: never; - url: '/customer-trust/questionnaires/{questionnaireId}'; -}; - -export type DeleteQuestionnaireResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteQuestionnaireResponse = DeleteQuestionnaireResponses[keyof DeleteQuestionnaireResponses]; - -export type GetQuestionnaireData = { - body?: never; - path: { - questionnaireId: string; - }; - query?: never; - url: '/customer-trust/questionnaires/{questionnaireId}'; -}; - -export type GetQuestionnaireResponses = { - /** - * Ok - */ - 200: CustomerTrustQuestionnaire; -}; - -export type GetQuestionnaireResponse = GetQuestionnaireResponses[keyof GetQuestionnaireResponses]; - -export type UpdateQuestionnaireData = { - body: UpdateQuestionnaireArgs; - path: { - questionnaireId: string; - }; - query?: never; - url: '/customer-trust/questionnaires/{questionnaireId}'; -}; - -export type UpdateQuestionnaireResponses = { - /** - * Ok - */ - 200: CustomerTrustQuestionnaire; -}; - -export type UpdateQuestionnaireResponse = UpdateQuestionnaireResponses[keyof UpdateQuestionnaireResponses]; - -export type ApproveQuestionnaireData = { - body: ApproveQuestionnaireRequest; - path: { - questionnaireId: string; - }; - query?: never; - url: '/customer-trust/questionnaires/{questionnaireId}/approve'; -}; - -export type ApproveQuestionnaireResponses = { - /** - * Ok - */ - 200: CustomerTrustQuestionnaire; -}; - -export type ApproveQuestionnaireResponse = ApproveQuestionnaireResponses[keyof ApproveQuestionnaireResponses]; - -export type CompleteQuestionnaireData = { - body: CompleteQuestionnaireRequest; - path: { - questionnaireId: string; - }; - query?: never; - url: '/customer-trust/questionnaires/{questionnaireId}/complete'; -}; - -export type CompleteQuestionnaireResponses = { - /** - * Ok - */ - 200: CustomerTrustQuestionnaire; -}; - -export type CompleteQuestionnaireResponse = CompleteQuestionnaireResponses[keyof CompleteQuestionnaireResponses]; - -export type ListTagCategoriesData = { - body?: never; - path?: never; - query?: { - productContextIdsMatchesAny?: Array; - }; - url: '/customer-trust/tag-categories'; -}; - -export type ListTagCategoriesResponses = { - /** - * Ok - */ - 200: ArrayResponseUserDefinedTagCategory; -}; - -export type ListTagCategoriesResponse = ListTagCategoriesResponses[keyof ListTagCategoriesResponses]; - -export type GetTagsForCategoryData = { - body?: never; - path: { - tagCategoryId: string; - }; - query?: never; - url: '/customer-trust/tag-categories/{tagCategoryId}'; -}; - -export type GetTagsForCategoryResponses = { - /** - * Ok - */ - 200: TagCategoryWithTags; -}; - -export type GetTagsForCategoryResponse = GetTagsForCategoryResponses[keyof GetTagsForCategoryResponses]; - -export type ListDiscoveredVendorsData = { - body?: never; - path?: never; - query?: { - /** - * Defaults to "NEEDS_REVIEW" if not provided - */ - scope?: DiscoveredVendorScope; - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/discovered-vendors'; -}; - -export type ListDiscoveredVendorsResponses = { - /** - * Ok - */ - 200: PaginatedResponseDiscoveredVendor; -}; - -export type ListDiscoveredVendorsResponse = ListDiscoveredVendorsResponses[keyof ListDiscoveredVendorsResponses]; - -export type ListDiscoveredVendorAccountsData = { - body?: never; - path: { - discoveredVendorId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/discovered-vendors/{discoveredVendorId}/accounts'; -}; - -export type ListDiscoveredVendorAccountsResponses = { - /** - * Ok - */ - 200: PaginatedResponseDiscoveredVendorAccount; -}; - -export type ListDiscoveredVendorAccountsResponse = ListDiscoveredVendorAccountsResponses[keyof ListDiscoveredVendorAccountsResponses]; - -export type AddDiscoveredVendorToManagedData = { - body?: never; - path: { - discoveredVendorId: string; - }; - query?: never; - url: '/discovered-vendors/{discoveredVendorId}/add-to-managed'; -}; - -export type AddDiscoveredVendorToManagedResponses = { - /** - * Ok - */ - 200: Vendor; -}; - -export type AddDiscoveredVendorToManagedResponse = AddDiscoveredVendorToManagedResponses[keyof AddDiscoveredVendorToManagedResponses]; - -export type ListDocumentsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Includes all documents that match one of the provided framework values in frameworkMatchesAny. - */ - frameworkMatchesAny?: Array; - /** - * Includes all documents that match one of the provided status values in statusMatchesAny. - */ - statusMatchesAny?: Array; - }; - url: '/documents'; -}; - -export type ListDocumentsResponses = { - /** - * Ok - */ - 200: PaginatedResponseDocument; -}; - -export type ListDocumentsResponse = ListDocumentsResponses[keyof ListDocumentsResponses]; - -export type CreateDocumentData = { - body: CreateDocumentInput; - path?: never; - query?: never; - url: '/documents'; -}; - -export type CreateDocumentResponses = { - /** - * Document created - */ - 201: Document; -}; - -export type CreateDocumentResponse = CreateDocumentResponses[keyof CreateDocumentResponses]; - -export type DeleteDocumentData = { - body?: never; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}'; -}; - -export type DeleteDocumentResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteDocumentResponse = DeleteDocumentResponses[keyof DeleteDocumentResponses]; - -export type GetDocumentData = { - body?: never; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}'; -}; - -export type GetDocumentResponses = { - /** - * Ok - */ - 200: DocumentDetail; -}; - -export type GetDocumentResponse = GetDocumentResponses[keyof GetDocumentResponses]; - -export type ListControlsForDocumentData = { - body?: never; - path: { - documentId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/documents/{documentId}/controls'; -}; - -export type ListControlsForDocumentResponses = { - /** - * Ok - */ - 200: PaginatedResponseControl; -}; - -export type ListControlsForDocumentResponse = ListControlsForDocumentResponses[keyof ListControlsForDocumentResponses]; - -export type ListLinksForDocumentData = { - body?: never; - path: { - documentId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/documents/{documentId}/links'; -}; - -export type ListLinksForDocumentResponses = { - /** - * Ok - */ - 200: PaginatedResponseUploadedLink; -}; - -export type ListLinksForDocumentResponse = ListLinksForDocumentResponses[keyof ListLinksForDocumentResponses]; - -export type CreateLinkForDocumentData = { - body: CreateLinkForDocumentInput; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}/links'; -}; - -export type CreateLinkForDocumentResponses = { - /** - * Link created for document - */ - 201: UploadedLink; -}; - -export type CreateLinkForDocumentResponse = CreateLinkForDocumentResponses[keyof CreateLinkForDocumentResponses]; - -export type DeleteLinkForDocumentData = { - body?: never; - path: { - documentId: string; - linkId: string; - }; - query?: never; - url: '/documents/{documentId}/links/{linkId}'; -}; - -export type DeleteLinkForDocumentResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteLinkForDocumentResponse = DeleteLinkForDocumentResponses[keyof DeleteLinkForDocumentResponses]; - -export type SetOwnerForDocumentData = { - body: SetOwnerForDocumentInput; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}/set-owner'; -}; - -export type SetOwnerForDocumentResponses = { - /** - * Ok - */ - 200: Document; -}; - -export type SetOwnerForDocumentResponse = SetOwnerForDocumentResponses[keyof SetOwnerForDocumentResponses]; - -export type SubmitDocumentCollectionData = { - body?: never; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}/submit'; -}; - -export type SubmitDocumentCollectionResponses = { - /** - * No content - */ - 204: void; -}; - -export type SubmitDocumentCollectionResponse = SubmitDocumentCollectionResponses[keyof SubmitDocumentCollectionResponses]; - -export type ListFilesForDocumentData = { - body?: never; - path: { - documentId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/documents/{documentId}/uploads'; -}; - -export type ListFilesForDocumentResponses = { - /** - * Ok - */ - 200: PaginatedResponseUploadedFileT; -}; - -export type ListFilesForDocumentResponse = ListFilesForDocumentResponses[keyof ListFilesForDocumentResponses]; - -export type UploadFileForDocumentData = { - body: { - file: Blob | File; - /** - * Date indicating when the document is effective from. - */ - effectiveAtDate?: string; - /** - * Description of the uploaded document. - */ - description?: string; - }; - path: { - documentId: string; - }; - query?: never; - url: '/documents/{documentId}/uploads'; -}; - -export type UploadFileForDocumentResponses = { - /** - * File uploaded for document - */ - 201: UploadedFileT; -}; - -export type UploadFileForDocumentResponse = UploadFileForDocumentResponses[keyof UploadFileForDocumentResponses]; - -export type DeleteFileForDocumentData = { - body?: never; - path: { - documentId: string; - uploadedFileId: string; - }; - query?: never; - url: '/documents/{documentId}/uploads/{uploadedFileId}'; -}; - -export type DeleteFileForDocumentResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteFileForDocumentResponse = DeleteFileForDocumentResponses[keyof DeleteFileForDocumentResponses]; - -export type GetUploadedfileMediaData = { - body?: never; - path: { - documentId: string; - uploadedFileId: string; - }; - query?: never; - url: '/documents/{documentId}/uploads/{uploadedFileId}/media'; -}; - -export type GetUploadedfileMediaResponses = { - /** - * Ok - */ - 200: NodeJsReadableStream; -}; - -export type GetUploadedfileMediaResponse = GetUploadedfileMediaResponses[keyof GetUploadedfileMediaResponses]; - -export type ListEventLogsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter to event logs created at or after this ISO 8601 timestamp. - */ - startDate?: string; - }; - url: '/event-logs'; -}; - -export type ListEventLogsResponses = { - /** - * Ok - */ - 200: PaginatedResponseEventLog; -}; - -export type ListEventLogsResponse = ListEventLogsResponses[keyof ListEventLogsResponses]; - -export type ListFrameworksData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/frameworks'; -}; - -export type ListFrameworksResponses = { - /** - * Ok - */ - 200: PaginatedResponseFramework; -}; - -export type ListFrameworksResponse = ListFrameworksResponses[keyof ListFrameworksResponses]; - -export type GetFrameworkData = { - body?: never; - path: { - frameworkId: string; - }; - query?: never; - url: '/frameworks/{frameworkId}'; -}; - -export type GetFrameworkResponses = { - /** - * Ok - */ - 200: FrameworkDetail; -}; - -export type GetFrameworkResponse = GetFrameworkResponses[keyof GetFrameworkResponses]; - -export type ListControlsForFrameworkData = { - body?: never; - path: { - frameworkId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/frameworks/{frameworkId}/controls'; -}; - -export type ListControlsForFrameworkResponses = { - /** - * Ok - */ - 200: PaginatedResponseControl; -}; - -export type ListControlsForFrameworkResponse = ListControlsForFrameworkResponses[keyof ListControlsForFrameworkResponses]; - -export type ListPersonGroupsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/groups'; -}; - -export type ListPersonGroupsResponses = { - /** - * Ok - */ - 200: PaginatedResponseGroup; -}; - -export type ListPersonGroupsResponse = ListPersonGroupsResponses[keyof ListPersonGroupsResponses]; - -export type GetGroupData = { - body?: never; - path: { - groupId: string; - }; - query?: never; - url: '/groups/{groupId}'; -}; - -export type GetGroupResponses = { - /** - * Ok - */ - 200: Group; -}; - -export type GetGroupResponse = GetGroupResponses[keyof GetGroupResponses]; - -export type AddPeopleToGroupData = { - body: { - /** - * List of people IDs to add a group. - */ - updates: Array<{ - id: string; - }>; - }; - path: { - groupId: string; - }; - query?: never; - url: '/groups/{groupId}/add-people'; -}; - -export type AddPeopleToGroupResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type AddPeopleToGroupResponse = AddPeopleToGroupResponses[keyof AddPeopleToGroupResponses]; - -export type GetGroupMembersData = { - body?: never; - path: { - groupId: string; - }; - query?: never; - url: '/groups/{groupId}/people'; -}; - -export type GetGroupMembersResponses = { - /** - * Ok - */ - 200: Array; -}; - -export type GetGroupMembersResponse = GetGroupMembersResponses[keyof GetGroupMembersResponses]; - -export type AddPersonToGroupData = { - body: { - id: string; - }; - path: { - groupId: string; - }; - query?: never; - url: '/groups/{groupId}/people'; -}; - -export type AddPersonToGroupResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type AddPersonToGroupResponse = AddPersonToGroupResponses[keyof AddPersonToGroupResponses]; - -export type RemovePersonFromGroupData = { - body?: never; - path: { - groupId: string; - personId: string; - }; - query?: never; - url: '/groups/{groupId}/people/{personId}'; -}; - -export type RemovePersonFromGroupResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type RemovePersonFromGroupResponse = RemovePersonFromGroupResponses[keyof RemovePersonFromGroupResponses]; - -export type RemovePeopleFromGroupData = { - body: { - /** - * List of people IDs to remove from a group. - */ - updates: Array<{ - id: string; - }>; - }; - path: { - groupId: string; - }; - query?: never; - url: '/groups/{groupId}/remove-people'; -}; - -export type RemovePeopleFromGroupResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type RemovePeopleFromGroupResponse = RemovePeopleFromGroupResponses[keyof RemovePeopleFromGroupResponses]; - -export type ListConnectedIntegrationsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/integrations'; -}; - -export type ListConnectedIntegrationsResponses = { - /** - * Ok - */ - 200: PaginatedResponseIntegration; -}; - -export type ListConnectedIntegrationsResponse = ListConnectedIntegrationsResponses[keyof ListConnectedIntegrationsResponses]; - -export type GetConnectedIntegrationData = { - body?: never; - path: { - /** - * Unique identifier of the integration - */ - integrationId: string; - }; - query?: never; - url: '/integrations/{integrationId}'; -}; - -export type GetConnectedIntegrationResponses = { - /** - * Ok - */ - 200: Integration; -}; - -export type GetConnectedIntegrationResponse = GetConnectedIntegrationResponses[keyof GetConnectedIntegrationResponses]; - -export type ListResourceKindSummariesData = { - body?: never; - path: { - /** - * Unique identifier of the integration - */ - integrationId: string; - }; - query?: never; - url: '/integrations/{integrationId}/resource-kinds'; -}; - -export type ListResourceKindSummariesResponses = { - /** - * Ok - */ - 200: Array; -}; - -export type ListResourceKindSummariesResponse = ListResourceKindSummariesResponses[keyof ListResourceKindSummariesResponses]; - -export type GetResourceKindDetailsData = { - body?: never; - path: { - /** - * Unique identifier of the integration. - */ - integrationId: string; - /** - * Unique identifier of the integration resource kind. - */ - resourceKind: string; - }; - query?: { - /** - * Unique identifier of the integration connection. - */ - connectionId?: string; - }; - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}'; -}; - -export type GetResourceKindDetailsResponses = { - /** - * Ok - */ - 200: ResourceKindDetails; -}; - -export type GetResourceKindDetailsResponse = GetResourceKindDetailsResponses[keyof GetResourceKindDetailsResponses]; - -export type ListResourcesData = { - body?: never; - path: { - /** - * Unique identifier of the integration. - */ - integrationId: string; - /** - * Unique identifier of the integration resource type. - */ - resourceKind: string; - }; - query?: { - /** - * Unique identifier of the integration connection. - */ - connectionId?: string; - /** - * Filter resources that have a description. - * If omitted, this will return resources both with and without a description. - */ - hasDescription?: boolean; - /** - * Filter resources that have an owner. - * If omitted, this will return resources both with and without an owner. - */ - hasOwner?: boolean; - /** - * Filter resources that are in scope. - * If omitted, this will return resources both in and out of scope. - */ - isInScope?: boolean; - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources'; -}; - -export type ListResourcesResponses = { - /** - * Ok - */ - 200: PaginatedResponseAnyResource; -}; - -export type ListResourcesResponse = ListResourcesResponses[keyof ListResourcesResponses]; - -export type UpdateResourcesData = { - body: { - /** - * List of resource update requests. - */ - updates: Array; - }; - path: { - /** - * Unique identifier of the integration. - */ - integrationId: string; - /** - * Unique identifier of the integration resource kind. - */ - resourceKind: string; - }; - query?: never; - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources'; -}; - -export type UpdateResourcesResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type UpdateResourcesResponse = UpdateResourcesResponses[keyof UpdateResourcesResponses]; - -export type GetResourceData = { - body?: never; - path: { - /** - * Unique identifier of the integration. - */ - integrationId: string; - /** - * Unique identifier of the integration resource kind. - */ - resourceKind: string; - /** - * Unique identifier of the resource. - */ - resourceId: string; - }; - query?: never; - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}'; -}; - -export type GetResourceResponses = { - /** - * Ok - */ - 200: AnyResource; -}; - -export type GetResourceResponse = GetResourceResponses[keyof GetResourceResponses]; - -export type UpdateResourceData = { - body: { - /** - * Determines whether resources should be marked as in scope. - */ - inScope?: boolean; - /** - * Description to update for the resources. - */ - description?: string; - /** - * Owner ID to update for the resources. - */ - ownerId?: string; - }; - path: { - /** - * Unique identifier of the integration. - */ - integrationId: string; - /** - * Unique identifier of the integration resource kind. - */ - resourceKind: string; - /** - * Unique identifier of the resource. - */ - resourceId: string; - }; - query?: never; - url: '/integrations/{integrationId}/resource-kinds/{resourceKind}/resources/{resourceId}'; -}; - -export type UpdateResourceResponses = { - /** - * No content - */ - 204: void; -}; - -export type UpdateResourceResponse = UpdateResourceResponses[keyof UpdateResourceResponses]; - -export type ListAnswerLibraryEntriesData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Full-text search across question and answer. - */ - q?: string; - /** - * Only include entries updated at or after this ISO 8601 timestamp. - */ - lastUpdatedAfter?: string; - /** - * Only include entries updated at or before this ISO 8601 timestamp. - */ - lastUpdatedBefore?: string; - /** - * JSON-encoded array of `{categoryId, tagId}` pairs. Entries matching any - * of the given tags are returned (OR filter). Discover valid `categoryId` - * and `tagId` values via `GET /v1/customer-trust/tag-categories` (to list - * categories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}` - * (to list tags within a category). - */ - matchesTags?: string; - /** - * Only include entries expiring at or before this ISO 8601 timestamp. - */ - expiresBefore?: string; - /** - * Only include entries expiring at or after this ISO 8601 timestamp. - */ - expiresAfter?: string; - }; - url: '/knowledge-base/answer-library'; -}; - -export type ListAnswerLibraryEntriesResponses = { - /** - * Ok - */ - 200: PaginatedResponseKnowledgeBaseAnswerLibraryEntryOutput; -}; - -export type ListAnswerLibraryEntriesResponse = ListAnswerLibraryEntriesResponses[keyof ListAnswerLibraryEntriesResponses]; - -export type CreateAnswerLibraryEntryData = { - body: CreateAnswerLibraryEntryInput; - path?: never; - query?: never; - url: '/knowledge-base/answer-library'; -}; - -export type CreateAnswerLibraryEntryResponses = { - /** - * Ok - */ - 200: KnowledgeBaseAnswerLibraryEntryOutput; -}; - -export type CreateAnswerLibraryEntryResponse = CreateAnswerLibraryEntryResponses[keyof CreateAnswerLibraryEntryResponses]; - -export type DeleteAnswerLibraryEntryRouteData = { - body?: never; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/answer-library/{id}'; -}; - -export type DeleteAnswerLibraryEntryRouteResponses = { - /** - * Answer library entry deleted - */ - 204: void; -}; - -export type DeleteAnswerLibraryEntryRouteResponse = DeleteAnswerLibraryEntryRouteResponses[keyof DeleteAnswerLibraryEntryRouteResponses]; - -export type GetAnswerLibraryEntryData = { - body?: never; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/answer-library/{id}'; -}; - -export type GetAnswerLibraryEntryResponses = { - /** - * Ok - */ - 200: KnowledgeBaseAnswerLibraryEntryOutput; -}; - -export type GetAnswerLibraryEntryResponse = GetAnswerLibraryEntryResponses[keyof GetAnswerLibraryEntryResponses]; - -export type UpdateAnswerLibraryEntryRouteData = { - body: UpdateAnswerLibraryEntryInput; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/answer-library/{id}'; -}; - -export type UpdateAnswerLibraryEntryRouteResponses = { - /** - * Ok - */ - 200: KnowledgeBaseAnswerLibraryEntryOutput; -}; - -export type UpdateAnswerLibraryEntryRouteResponse = UpdateAnswerLibraryEntryRouteResponses[keyof UpdateAnswerLibraryEntryRouteResponses]; - -export type VerifyAnswerLibraryEntryRouteData = { - body?: VerifyAnswerLibraryEntryInput; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/answer-library/{id}/verify'; -}; - -export type VerifyAnswerLibraryEntryRouteResponses = { - /** - * Ok - */ - 200: KnowledgeBaseAnswerLibraryEntryOutput; -}; - -export type VerifyAnswerLibraryEntryRouteResponse = VerifyAnswerLibraryEntryRouteResponses[keyof VerifyAnswerLibraryEntryRouteResponses]; - -export type ListKnowledgeBaseResourcesData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Full-text search across resource titles. - */ - q?: string; - /** - * Filter to FILE and/or URL resources. Repeat the param to allow either. - */ - typeMatchesAny?: Array; - /** - * Only include resources updated at or after this ISO 8601 timestamp. - */ - lastUpdatedAfter?: string; - /** - * Only include resources updated at or before this ISO 8601 timestamp. - */ - lastUpdatedBefore?: string; - /** - * JSON-encoded array of `{categoryId, tagId}` pairs. Tags within the - * same category are OR'd together; tags across different categories - * are AND'd. For example, passing two tags from "Framework" and one - * tag from "Region" matches resources that have either of the two - * frameworks AND the given region. Discover valid `categoryId` and - * `tagId` values via `GET /v1/customer-trust/tag-categories` (to list - * categories) and `GET /v1/customer-trust/tag-categories/{tagCategoryId}` - * (to list tags within a category). - */ - matchesTags?: string; - /** - * Only include resources expiring at or before this ISO 8601 timestamp. - */ - expiresBefore?: string; - /** - * Only include resources expiring at or after this ISO 8601 timestamp. - */ - expiresAfter?: string; - }; - url: '/knowledge-base/resources'; -}; - -export type ListKnowledgeBaseResourcesResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustKnowledgeBaseResourceOutput; -}; - -export type ListKnowledgeBaseResourcesResponse = ListKnowledgeBaseResourcesResponses[keyof ListKnowledgeBaseResourcesResponses]; - -export type CreateDocumentResourceData = { - body: { - file: Blob | File; - /** - * Title of the document resource. - */ - title: string; - /** - * Description of the document resource. - */ - description?: string; - /** - * Owner to assign as a JSON string: {"type":"User","id":""}. - */ - ownerAssignment?: string; - /** - * Customer visibility on the Trust Center: PRIVATE | SHAREABLE | REQUEST_ACCESS | PUBLIC. - */ - customerVisibility?: string; - /** - * Trust Center download permission: VIEW_ONLY | VIEW_AND_DOWNLOAD. - */ - downloadPermission?: string; - /** - * Whether to use this resource for Questionnaire Automation answer generation ("true" / "false"). - */ - isUsedInQuestionnaires?: string; - /** - * Expiration date in ISO 8601. - */ - expirationDate?: string; - /** - * Tags as a JSON array: [{"categoryId":"","tagId":""}]. - */ - tags?: string; - /** - * Trust Center category id to associate this resource with. Only - * applied when `customerVisibility` is `REQUEST_ACCESS` or `PUBLIC`; - * other visibilities don't place the resource on the Trust Center, so - * the category is ignored. Pass an unknown id to fall back to - * uncategorized. - */ - categoryId?: string; - }; - path?: never; - query?: never; - url: '/knowledge-base/resources/documents'; -}; - -export type CreateDocumentResourceResponses = { - /** - * Ok - */ - 200: KnowledgeBaseDocumentResourceOutput; -}; - -export type CreateDocumentResourceResponse = CreateDocumentResourceResponses[keyof CreateDocumentResourceResponses]; - -export type UpdateDocumentResourceData = { - body: UpdateDocumentResourceInput; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/documents/{id}'; -}; - -export type UpdateDocumentResourceResponses = { - /** - * Ok - */ - 200: KnowledgeBaseDocumentResourceOutput; -}; - -export type UpdateDocumentResourceResponse = UpdateDocumentResourceResponses[keyof UpdateDocumentResourceResponses]; - -export type ReplaceDocumentResourceFileData = { - body: { - /** - * New document binary; replaces the existing file in place. - */ - file: Blob | File; - }; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/documents/{id}/upload'; -}; - -export type ReplaceDocumentResourceFileResponses = { - /** - * Ok - */ - 200: KnowledgeBaseDocumentResourceOutput; -}; - -export type ReplaceDocumentResourceFileResponse = ReplaceDocumentResourceFileResponses[keyof ReplaceDocumentResourceFileResponses]; - -export type CreateWebpageResourceData = { - body: CreateWebpageResourceInput; - path?: never; - query?: never; - url: '/knowledge-base/resources/webpages'; -}; - -export type CreateWebpageResourceResponses = { - /** - * Ok - */ - 200: KnowledgeBaseWebpageResourceOutput; -}; - -export type CreateWebpageResourceResponse = CreateWebpageResourceResponses[keyof CreateWebpageResourceResponses]; - -export type UpdateWebpageResourceData = { - body: UpdateWebpageResourceInput; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/webpages/{id}'; -}; - -export type UpdateWebpageResourceResponses = { - /** - * Ok - */ - 200: KnowledgeBaseWebpageResourceOutput; -}; - -export type UpdateWebpageResourceResponse = UpdateWebpageResourceResponses[keyof UpdateWebpageResourceResponses]; - -export type DeleteKnowledgeBaseResourceData = { - body?: never; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/{id}'; -}; - -export type DeleteKnowledgeBaseResourceResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteKnowledgeBaseResourceResponse = DeleteKnowledgeBaseResourceResponses[keyof DeleteKnowledgeBaseResourceResponses]; - -export type GetKnowledgeBaseResourceData = { - body?: never; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/{id}'; -}; - -export type GetKnowledgeBaseResourceResponses = { - /** - * Ok - */ - 200: TrustKnowledgeBaseResourceOutput; -}; - -export type GetKnowledgeBaseResourceResponse = GetKnowledgeBaseResourceResponses[keyof GetKnowledgeBaseResourceResponses]; - -export type VerifyKnowledgeBaseResourceData = { - body?: VerifyKnowledgeBaseResourceInput; - path: { - id: string; - }; - query?: never; - url: '/knowledge-base/resources/{id}/verify'; -}; - -export type VerifyKnowledgeBaseResourceResponses = { - /** - * Ok - */ - 200: TrustKnowledgeBaseResourceOutput; -}; - -export type VerifyKnowledgeBaseResourceResponse = VerifyKnowledgeBaseResourceResponses[keyof VerifyKnowledgeBaseResourceResponses]; - -export type ListMonitoredComputersData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filters for monitored computers matching any status declared in the filter. - */ - complianceStatusFilterMatchesAny?: Array; - }; - url: '/monitored-computers'; -}; - -export type ListMonitoredComputersResponses = { - /** - * Ok - */ - 200: PaginatedResponseMonitoredComputer; -}; - -export type ListMonitoredComputersResponse = ListMonitoredComputersResponses[keyof ListMonitoredComputersResponses]; - -export type GetMonitoredComputerData = { - body?: never; - path: { - computerId: string; - }; - query?: never; - url: '/monitored-computers/{computerId}'; -}; - -export type GetMonitoredComputerResponses = { - /** - * Ok - */ - 200: MonitoredComputer; -}; - -export type GetMonitoredComputerResponse = GetMonitoredComputerResponses[keyof GetMonitoredComputerResponses]; - -export type ListPeopleData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter individuals by those whose tasksSummary status is any of the provided values. - */ - tasksSummaryStatusMatchesAny?: Array; - /** - * Requires taskStatusMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny - * is any of the provided taskStatus values in taskStatusMatchesAny. - */ - taskTypeMatchesAny?: Array; - /** - * Requires taskTypeMatchesAny. Includes all people for whom any of the provided taskType values in taskTypeMatchesAny - * is any of the provided taskStatus values in taskStatusMatchesAny. - */ - taskStatusMatchesAny?: Array; - /** - * Filter people by email address, first name, or last name (partial match, case-insensitive). - */ - emailAndNameFilter?: string; - /** - * Filter people matching any of the given group IDs. - */ - groupIdsMatchesAny?: Array; - /** - * Filter people matching the given employment status. - */ - employmentStatus?: EmploymentStatus; - }; - url: '/people'; -}; - -export type ListPeopleResponses = { - /** - * Ok - */ - 200: PaginatedResponsePerson; -}; - -export type ListPeopleResponse = ListPeopleResponses[keyof ListPeopleResponses]; - -export type MarkAsNotPeopleData = { - body: { - /** - * List of account IDs to mark as not a person - */ - updates: Array<{ - /** - * Reason for making this change. - */ - reason: string; - /** - * ID of the person to change - */ - id: string; - }>; - }; - path?: never; - query?: never; - url: '/people/mark-as-not-people'; -}; - -export type MarkAsNotPeopleResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type MarkAsNotPeopleResponse = MarkAsNotPeopleResponses[keyof MarkAsNotPeopleResponses]; - -export type MarkAsPeopleData = { - body: { - /** - * List of account IDs to mark as a person - */ - updates: Array<{ - /** - * ID of the person to change - */ - id: string; - }>; - }; - path?: never; - query?: never; - url: '/people/mark-as-people'; -}; - -export type MarkAsPeopleResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type MarkAsPeopleResponse = MarkAsPeopleResponses[keyof MarkAsPeopleResponses]; - -export type OffboardPeopleData = { - body: { - /** - * List of the people to offboard. - */ - updates: Array<{ - /** - * ID of the person who will be recorded as completing the offboarding for these people - */ - acknowledgerId: string; - /** - * ID of the person to offboard - */ - id: string; - }>; - }; - path?: never; - query?: never; - url: '/people/offboard'; -}; - -export type OffboardPeopleResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type OffboardPeopleResponse = OffboardPeopleResponses[keyof OffboardPeopleResponses]; - -export type GetPersonData = { - body?: never; - path: { - personId: string; - }; - query?: never; - url: '/people/{personId}'; -}; - -export type GetPersonResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type GetPersonResponse = GetPersonResponses[keyof GetPersonResponses]; - -export type UpdatePersonData = { - body: { - name?: { - last: string; - first: string; - }; - employment?: { - startDate?: string; - }; - }; - path: { - personId: string; - }; - query?: never; - url: '/people/{personId}'; -}; - -export type UpdatePersonResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type UpdatePersonResponse = UpdatePersonResponses[keyof UpdatePersonResponses]; - -export type ClearLeaveForPersonData = { - body?: never; - path: { - personId: string; - }; - query?: never; - url: '/people/{personId}/clear-leave'; -}; - -export type ClearLeaveForPersonResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type ClearLeaveForPersonResponse = ClearLeaveForPersonResponses[keyof ClearLeaveForPersonResponses]; - -export type SetLeaveForPersonData = { - body: { - /** - * The end date of the person's leave. If left empty, the leave is considered indefinite. - */ - endDate: string | null; - /** - * The start date of the person's leave. - */ - startDate: string; - }; - path: { - personId: string; - }; - query?: never; - url: '/people/{personId}/set-leave'; -}; - -export type SetLeaveForPersonResponses = { - /** - * Ok - */ - 200: Person; -}; - -export type SetLeaveForPersonResponse = SetLeaveForPersonResponses[keyof SetLeaveForPersonResponses]; - -export type ListPoliciesData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/policies'; -}; - -export type ListPoliciesResponses = { - /** - * Ok - */ - 200: PaginatedResponsePolicy; -}; - -export type ListPoliciesResponse = ListPoliciesResponses[keyof ListPoliciesResponses]; - -export type GetPolicyData = { - body?: never; - path: { - policyId: string; - }; - query?: never; - url: '/policies/{policyId}'; -}; - -export type GetPolicyResponses = { - /** - * Ok - */ - 200: Policy; -}; - -export type GetPolicyResponse = GetPolicyResponses[keyof GetPolicyResponses]; - -export type ListRiskScenarioData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - includeIgnored?: boolean; - /** - * Use "No owner" to filter scenarios without owner assigned. - */ - ownerMatchesAny?: Array; - searchString?: string; - /** - * Use "Uncategorized" to filter scenarios without any category. - */ - categoryMatchesAny?: Array; - /** - * Use "Uncategorized" to filter scenarios with none of Confidentiality, Integrity or Availability assigned. - */ - ciaCategoryMatchesAny?: Array; - /** - * Use "No treatment type" to filter scenarios without treatment specified. - */ - treatmentTypeMatchesAny?: Array; - inherentScoreGroupMatchesAny?: Array; - residualScoreGroupMatchesAny?: Array; - reviewStatusMatchesAny?: Array; - /** - * Filter by risk scenario type. Defaults to "Risk Scenario". - * Only returns enterprise risks when explicitly set to "Enterprise Risk". - */ - type?: RiskScenarioType; - /** - * Default to order by description alphabetically. - */ - orderBy?: 'description' | 'createdAt'; - }; - url: '/risk-scenarios'; -}; - -export type ListRiskScenarioResponses = { - /** - * Ok - */ - 200: PaginatedResponseRiskScenario; -}; - -export type ListRiskScenarioResponse = ListRiskScenarioResponses[keyof ListRiskScenarioResponses]; - -export type CreateRiskScenarioData = { - body: CreateRiskScenarioInput; - path?: never; - query?: never; - url: '/risk-scenarios'; -}; - -export type CreateRiskScenarioResponses = { - /** - * Ok - */ - 200: RiskScenario; -}; - -export type CreateRiskScenarioResponse = CreateRiskScenarioResponses[keyof CreateRiskScenarioResponses]; - -export type GetRiskScenarioData = { - body?: never; - path: { - riskScenarioId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}'; -}; - -export type GetRiskScenarioResponses = { - /** - * Ok - */ - 200: RiskScenario; -}; - -export type GetRiskScenarioResponse = GetRiskScenarioResponses[keyof GetRiskScenarioResponses]; - -export type UpdateRiskScenarioData = { - body: UpdateRiskScenarioInput; - path: { - riskScenarioId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}'; -}; - -export type UpdateRiskScenarioResponses = { - /** - * Ok - */ - 200: RiskScenario; -}; - -export type UpdateRiskScenarioResponse = UpdateRiskScenarioResponses[keyof UpdateRiskScenarioResponses]; - -export type CancelRiskScenarioApprovalRequestData = { - body?: never; - path: { - riskScenarioId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}/cancel-approval-request'; -}; - -export type CancelRiskScenarioApprovalRequestResponses = { - /** - * Ok - */ - 200: RiskScenario; -}; - -export type CancelRiskScenarioApprovalRequestResponse = CancelRiskScenarioApprovalRequestResponses[keyof CancelRiskScenarioApprovalRequestResponses]; - -export type ListRiskScenarioControlsData = { - body?: never; - path: { - riskScenarioId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/risk-scenarios/{riskScenarioId}/controls'; -}; - -export type ListRiskScenarioControlsResponses = { - /** - * Ok - */ - 200: PaginatedResponseRiskScenarioControl; -}; - -export type ListRiskScenarioControlsResponse = ListRiskScenarioControlsResponses[keyof ListRiskScenarioControlsResponses]; - -export type CreateRiskScenarioControlData = { - body: CreateRiskScenarioControlInput; - path: { - riskScenarioId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}/controls'; -}; - -export type CreateRiskScenarioControlResponses = { - /** - * Ok - */ - 200: RiskScenarioControl; -}; - -export type CreateRiskScenarioControlResponse = CreateRiskScenarioControlResponses[keyof CreateRiskScenarioControlResponses]; - -export type DeleteRiskScenarioControlData = { - body?: never; - path: { - riskScenarioId: string; - controlId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}/controls/{controlId}'; -}; - -export type DeleteRiskScenarioControlResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteRiskScenarioControlResponse = DeleteRiskScenarioControlResponses[keyof DeleteRiskScenarioControlResponses]; - -export type UpdateRiskScenarioControlData = { - body: UpdateRiskScenarioControlInput; - path: { - riskScenarioId: string; - controlId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}/controls/{controlId}'; -}; - -export type UpdateRiskScenarioControlResponses = { - /** - * Ok - */ - 200: RiskScenarioControl; -}; - -export type UpdateRiskScenarioControlResponse = UpdateRiskScenarioControlResponses[keyof UpdateRiskScenarioControlResponses]; - -export type SubmitRiskForApprovalData = { - body: SubmitRiskForApprovalInput; - path: { - riskScenarioId: string; - }; - query?: never; - url: '/risk-scenarios/{riskScenarioId}/submit-for-approval'; -}; - -export type SubmitRiskForApprovalResponses = { - /** - * Ok - */ - 200: RiskScenario; -}; - -export type SubmitRiskForApprovalResponse = SubmitRiskForApprovalResponses[keyof SubmitRiskForApprovalResponses]; - -export type ListTestsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter tests by test status. - * Possible values: OK (Test passed), DEACTIVATED (Test is deactivated), NEEDS_ATTENTION (Test failed), IN_PROGRESS (Test is in progress), INVALID (Test is invalid), NOT_APPLICABLE (Test is not applicable) - */ - statusFilter?: TestStatus; - /** - * Filter tests by framework. - */ - frameworkFilter?: string; - /** - * Filter tests by integration. - */ - integrationFilter?: string; - /** - * Filter tests by control ID. - */ - controlFilter?: string; - /** - * Filter tests by owner ID. - */ - ownerFilter?: string; - /** - * Filter tests by category. - */ - categoryFilter?: TestCategory; - /** - * Filter tests by rollout status. - * A test in rollout is an upcoming test that does not have its history tracked yet. - */ - isInRollout?: boolean; - }; - url: '/tests'; -}; - -export type ListTestsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTest; -}; - -export type ListTestsResponse = ListTestsResponses[keyof ListTestsResponses]; - -export type GetTestData = { - body?: never; - path: { - testId: string; - }; - query?: never; - url: '/tests/{testId}'; -}; - -export type GetTestResponses = { - /** - * Ok - */ - 200: Test; -}; - -export type GetTestResponse = GetTestResponses[keyof GetTestResponses]; - -export type GetTestEntitiesData = { - body?: never; - path: { - testId: string; - }; - query?: { - /** - * The status of the test entities. Defaults to FAILING. - * Possible values: FAILING, DEACTIVATED - */ - entityStatus?: EntityStatus; - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/tests/{testId}/entities'; -}; - -export type GetTestEntitiesResponses = { - /** - * Ok - */ - 200: PaginatedResponseTestResourceEntity; -}; - -export type GetTestEntitiesResponse = GetTestEntitiesResponses[keyof GetTestEntitiesResponses]; - -export type DeactivateTestEntityData = { - body: { - /** - * Reason for deactivating the entity. - */ - deactivateReason: string; - /** - * Date until which the entity should be deactivated. If not provided, the entity will be deactivated indefinitely. - */ - deactivateUntilDate?: string; - }; - path: { - testId: string; - entityId: string; - }; - query?: never; - url: '/tests/{testId}/entities/{entityId}/deactivate'; -}; - -export type DeactivateTestEntityResponses = { - /** - * Deactivation request accepted - */ - 202: unknown; -}; - -export type ReactivateTestEntityData = { - body?: never; - path: { - testId: string; - entityId: string; - }; - query?: never; - url: '/tests/{testId}/entities/{entityId}/reactivate'; -}; - -export type ReactivateTestEntityResponses = { - /** - * Reactivation request accepted - */ - 202: unknown; -}; - -export type GetTrustCenterData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}'; -}; - -export type GetTrustCenterResponses = { - /** - * Ok - */ - 200: TrustCenter; -}; - -export type GetTrustCenterResponse = GetTrustCenterResponses[keyof GetTrustCenterResponses]; - -export type UpdateTrustCenterData = { - body: UpdateTrustCenterInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}'; -}; - -export type UpdateTrustCenterResponses = { - /** - * Ok - */ - 200: TrustCenter; -}; - -export type UpdateTrustCenterResponse = UpdateTrustCenterResponses[keyof UpdateTrustCenterResponses]; - -export type ListTrustCenterAccessRequestsData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/trust-centers/{slugId}/access-requests'; -}; - -export type ListTrustCenterAccessRequestsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterAccessRequest; -}; - -export type ListTrustCenterAccessRequestsResponse = ListTrustCenterAccessRequestsResponses[keyof ListTrustCenterAccessRequestsResponses]; - -export type GetTrustCenterAccessRequestData = { - body?: never; - path: { - slugId: string; - accessRequestId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}'; -}; - -export type GetTrustCenterAccessRequestResponses = { - /** - * Ok - */ - 200: TrustCenterAccessRequest; -}; - -export type GetTrustCenterAccessRequestResponse = GetTrustCenterAccessRequestResponses[keyof GetTrustCenterAccessRequestResponses]; - -export type ApproveTrustCenterAccessRequestData = { - body: ApproveTrustCenterAccessRequestInput; - path: { - slugId: string; - accessRequestId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}/approve'; -}; - -export type ApproveTrustCenterAccessRequestResponses = { - /** - * No content - */ - 204: void; -}; - -export type ApproveTrustCenterAccessRequestResponse = ApproveTrustCenterAccessRequestResponses[keyof ApproveTrustCenterAccessRequestResponses]; - -export type DenyTrustCenterAccessRequestData = { - body?: DenyTrustCenterAccessRequestInput; - path: { - slugId: string; - accessRequestId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/access-requests/{accessRequestId}/deny'; -}; - -export type DenyTrustCenterAccessRequestResponses = { - /** - * No content - */ - 204: void; -}; - -export type DenyTrustCenterAccessRequestResponse = DenyTrustCenterAccessRequestResponses[keyof DenyTrustCenterAccessRequestResponses]; - -export type ListTrustCenterActivityEventsData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - eventTypesMatchesAny?: Array; - /** - * Only include activity events that occurred on or after the specified date and time. - */ - afterDate?: string; - /** - * Only include activity events that occurred before the specified date and time. - */ - beforeDate?: string; - }; - url: '/trust-centers/{slugId}/activity'; -}; - -export type ListTrustCenterActivityEventsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterActivityEvent; -}; - -export type ListTrustCenterActivityEventsResponse = ListTrustCenterActivityEventsResponses[keyof ListTrustCenterActivityEventsResponses]; - -export type GetTrustCenterControlCategoriesData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/control-categories'; -}; - -export type GetTrustCenterControlCategoriesResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterControlCategory; -}; - -export type GetTrustCenterControlCategoriesResponse = GetTrustCenterControlCategoriesResponses[keyof GetTrustCenterControlCategoriesResponses]; - -export type AddTrustCenterControlCategoryData = { - body: AddOrEditTrustCenterControlCategoryInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/control-categories'; -}; - -export type AddTrustCenterControlCategoryResponses = { - /** - * Ok - */ - 200: TrustCenterControlCategory; -}; - -export type AddTrustCenterControlCategoryResponse = AddTrustCenterControlCategoryResponses[keyof AddTrustCenterControlCategoryResponses]; - -export type DeleteTrustCenterControlCategoryData = { - body?: never; - path: { - slugId: string; - categoryId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/control-categories/{categoryId}'; -}; - -export type DeleteTrustCenterControlCategoryResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterControlCategoryResponse = DeleteTrustCenterControlCategoryResponses[keyof DeleteTrustCenterControlCategoryResponses]; - -export type GetTrustCenterControlCategoryData = { - body?: never; - path: { - slugId: string; - categoryId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/control-categories/{categoryId}'; -}; - -export type GetTrustCenterControlCategoryResponses = { - /** - * Ok - */ - 200: TrustCenterControlCategory; -}; - -export type GetTrustCenterControlCategoryResponse = GetTrustCenterControlCategoryResponses[keyof GetTrustCenterControlCategoryResponses]; - -export type UpdateTrustCenterControlCategoryData = { - body: AddOrEditTrustCenterControlCategoryInput; - path: { - slugId: string; - categoryId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/control-categories/{categoryId}'; -}; - -export type UpdateTrustCenterControlCategoryResponses = { - /** - * Ok - */ - 200: TrustCenterControlCategory; -}; - -export type UpdateTrustCenterControlCategoryResponse = UpdateTrustCenterControlCategoryResponses[keyof UpdateTrustCenterControlCategoryResponses]; - -export type ListTrustCenterControlsData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/trust-centers/{slugId}/controls'; -}; - -export type ListTrustCenterControlsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterControl; -}; - -export type ListTrustCenterControlsResponse = ListTrustCenterControlsResponses[keyof ListTrustCenterControlsResponses]; - -export type AddControlToTrustCenterData = { - body: AddControlToTrustCenterInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/controls'; -}; - -export type AddControlToTrustCenterResponses = { - /** - * Ok - */ - 200: TrustCenterControl; -}; - -export type AddControlToTrustCenterResponse = AddControlToTrustCenterResponses[keyof AddControlToTrustCenterResponses]; - -export type DeleteTrustCenterControlData = { - body?: never; - path: { - slugId: string; - controlId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/controls/{controlId}'; -}; - -export type DeleteTrustCenterControlResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterControlResponse = DeleteTrustCenterControlResponses[keyof DeleteTrustCenterControlResponses]; - -export type GetTrustCenterControlData = { - body?: never; - path: { - slugId: string; - controlId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/controls/{controlId}'; -}; - -export type GetTrustCenterControlResponses = { - /** - * Ok - */ - 200: TrustCenterControl; -}; - -export type GetTrustCenterControlResponse = GetTrustCenterControlResponses[keyof GetTrustCenterControlResponses]; - -export type ListTrustCenterFaqsData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/faqs'; -}; - -export type ListTrustCenterFaqsResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterFaq; -}; - -export type ListTrustCenterFaqsResponse = ListTrustCenterFaqsResponses[keyof ListTrustCenterFaqsResponses]; - -export type CreateTrustCenterFaqData = { - body: AddOrEditTrustCenterFaqInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/faqs'; -}; - -export type CreateTrustCenterFaqResponses = { - /** - * Trust Center FAQ created - */ - 201: TrustCenterFaq; -}; - -export type CreateTrustCenterFaqResponse = CreateTrustCenterFaqResponses[keyof CreateTrustCenterFaqResponses]; - -export type DeleteTrustCenterFaqData = { - body?: never; - path: { - slugId: string; - faqId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/faqs/{faqId}'; -}; - -export type DeleteTrustCenterFaqResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterFaqResponse = DeleteTrustCenterFaqResponses[keyof DeleteTrustCenterFaqResponses]; - -export type GetTrustCenterFaqData = { - body?: never; - path: { - slugId: string; - faqId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/faqs/{faqId}'; -}; - -export type GetTrustCenterFaqResponses = { - /** - * Ok - */ - 200: TrustCenterFaq; -}; - -export type GetTrustCenterFaqResponse = GetTrustCenterFaqResponses[keyof GetTrustCenterFaqResponses]; - -export type UpdateTrustCenterFaqData = { - body: AddOrEditTrustCenterFaqInput; - path: { - slugId: string; - faqId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/faqs/{faqId}'; -}; - -export type UpdateTrustCenterFaqResponses = { - /** - * Ok - */ - 200: TrustCenterFaq; -}; - -export type UpdateTrustCenterFaqResponse = UpdateTrustCenterFaqResponses[keyof UpdateTrustCenterFaqResponses]; - -export type ListTrustCenterHistoricalAccessRequestsData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/trust-centers/{slugId}/historical-access-requests'; -}; - -export type ListTrustCenterHistoricalAccessRequestsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterAccessRequestHistorical; -}; - -export type ListTrustCenterHistoricalAccessRequestsResponse = ListTrustCenterHistoricalAccessRequestsResponses[keyof ListTrustCenterHistoricalAccessRequestsResponses]; - -export type ListTrustCenterResourceCategoriesData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resource-categories'; -}; - -export type ListTrustCenterResourceCategoriesResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterResourceCategory; -}; - -export type ListTrustCenterResourceCategoriesResponse = ListTrustCenterResourceCategoriesResponses[keyof ListTrustCenterResourceCategoriesResponses]; - -export type AddTrustCenterResourceCategoryData = { - body: AddTrustCenterResourceCategoryInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resource-categories'; -}; - -export type AddTrustCenterResourceCategoryResponses = { - /** - * Ok - */ - 200: TrustCenterResourceCategory; -}; - -export type AddTrustCenterResourceCategoryResponse = AddTrustCenterResourceCategoryResponses[keyof AddTrustCenterResourceCategoryResponses]; - -export type UpsertTrustCenterResourceCategoriesOrderData = { - body: ReorderTrustCenterResourceCategoriesInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resource-categories/order'; -}; - -export type UpsertTrustCenterResourceCategoriesOrderResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterResourceCategory; -}; - -export type UpsertTrustCenterResourceCategoriesOrderResponse = UpsertTrustCenterResourceCategoriesOrderResponses[keyof UpsertTrustCenterResourceCategoriesOrderResponses]; - -export type DeleteTrustCenterResourceCategoryData = { - body?: never; - path: { - slugId: string; - categoryId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resource-categories/{categoryId}'; -}; - -export type DeleteTrustCenterResourceCategoryResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterResourceCategoryResponse = DeleteTrustCenterResourceCategoryResponses[keyof DeleteTrustCenterResourceCategoryResponses]; - -export type UpdateTrustCenterResourceCategoryData = { - body: EditTrustCenterResourceCategoryInput; - path: { - slugId: string; - categoryId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resource-categories/{categoryId}'; -}; - -export type UpdateTrustCenterResourceCategoryResponses = { - /** - * Ok - */ - 200: TrustCenterResourceCategory; -}; - -export type UpdateTrustCenterResourceCategoryResponse = UpdateTrustCenterResourceCategoryResponses[keyof UpdateTrustCenterResourceCategoryResponses]; - -export type ListTrustCenterResourcesData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources'; -}; - -export type ListTrustCenterResourcesResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterResource; -}; - -export type ListTrustCenterResourcesResponse = ListTrustCenterResourcesResponses[keyof ListTrustCenterResourcesResponses]; - -export type CreateTrustCenterResourceData = { - body: { - file: Blob | File; - /** - * Title of the Trust Center document. - */ - title: string; - /** - * Boolean determining whether the document is publicly available. - */ - isPublic: string; - /** - * Description of the uploaded document. - */ - description?: string; - }; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources'; -}; - -export type CreateTrustCenterResourceResponses = { - /** - * Trust Center document created - */ - 201: TrustCenterResource; -}; - -export type CreateTrustCenterResourceResponse = CreateTrustCenterResourceResponses[keyof CreateTrustCenterResourceResponses]; - -export type DeleteTrustCenterResourceData = { - body?: never; - path: { - slugId: string; - resourceId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources/{resourceId}'; -}; - -export type DeleteTrustCenterResourceResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterResourceResponse = DeleteTrustCenterResourceResponses[keyof DeleteTrustCenterResourceResponses]; - -export type GetTrustCenterResourceData = { - body?: never; - path: { - slugId: string; - resourceId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources/{resourceId}'; -}; - -export type GetTrustCenterResourceResponses = { - /** - * Ok - */ - 200: TrustCenterResource; -}; - -export type GetTrustCenterResourceResponse = GetTrustCenterResourceResponses[keyof GetTrustCenterResourceResponses]; - -export type UpdateTrustCenterResourceData = { - body: EditTrustCenterResourceInput; - path: { - slugId: string; - resourceId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources/{resourceId}'; -}; - -export type UpdateTrustCenterResourceResponses = { - /** - * Ok - */ - 200: TrustCenterResource; -}; - -export type UpdateTrustCenterResourceResponse = UpdateTrustCenterResourceResponses[keyof UpdateTrustCenterResourceResponses]; - -export type GetTrustCenterResourceMediaData = { - body?: never; - path: { - slugId: string; - resourceId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/resources/{resourceId}/media'; -}; - -export type GetTrustCenterResourceMediaResponses = { - /** - * Ok - */ - 200: NodeJsReadableStream; -}; - -export type GetTrustCenterResourceMediaResponse = GetTrustCenterResourceMediaResponses[keyof GetTrustCenterResourceMediaResponses]; - -export type ListTrustCenterSubprocessorsData = { - body?: never; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subprocessors'; -}; - -export type ListTrustCenterSubprocessorsResponses = { - /** - * Ok - */ - 200: ArrayResponseTrustCenterSubprocessor; -}; - -export type ListTrustCenterSubprocessorsResponse = ListTrustCenterSubprocessorsResponses[keyof ListTrustCenterSubprocessorsResponses]; - -export type CreateTrustCenterSubprocessorData = { - body: AddTrustCenterSubprocessorInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subprocessors'; -}; - -export type CreateTrustCenterSubprocessorResponses = { - /** - * Trust Center subprocessor created - */ - 201: TrustCenterSubprocessor | null; -}; - -export type CreateTrustCenterSubprocessorResponse = CreateTrustCenterSubprocessorResponses[keyof CreateTrustCenterSubprocessorResponses]; - -export type DeleteTrustCenterSubprocessorData = { - body?: never; - path: { - slugId: string; - subprocessorId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}'; -}; - -export type DeleteTrustCenterSubprocessorResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterSubprocessorResponse = DeleteTrustCenterSubprocessorResponses[keyof DeleteTrustCenterSubprocessorResponses]; - -export type GetTrustCenterSubprocessorData = { - body?: never; - path: { - slugId: string; - subprocessorId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}'; -}; - -export type GetTrustCenterSubprocessorResponses = { - /** - * Ok - */ - 200: TrustCenterSubprocessor; -}; - -export type GetTrustCenterSubprocessorResponse = GetTrustCenterSubprocessorResponses[keyof GetTrustCenterSubprocessorResponses]; - -export type UpdateTrustCenterSubprocessorData = { - body: EditTrustCenterSubprocessorInput; - path: { - slugId: string; - subprocessorId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subprocessors/{subprocessorId}'; -}; - -export type UpdateTrustCenterSubprocessorResponses = { - /** - * Ok - */ - 200: TrustCenterSubprocessor; -}; - -export type UpdateTrustCenterSubprocessorResponse = UpdateTrustCenterSubprocessorResponses[keyof UpdateTrustCenterSubprocessorResponses]; - -export type ListTrustCenterSubscriberGroupsData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/trust-centers/{slugId}/subscriber-groups'; -}; - -export type ListTrustCenterSubscriberGroupsResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterSubscriberGroup; -}; - -export type ListTrustCenterSubscriberGroupsResponse = ListTrustCenterSubscriberGroupsResponses[keyof ListTrustCenterSubscriberGroupsResponses]; - -export type CreateTrustCenterSubscriberGroupData = { - body: CreateTrustCenterSubscriberGroupInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscriber-groups'; -}; - -export type CreateTrustCenterSubscriberGroupResponses = { - /** - * Trust Center subscriber group created - */ - 201: TrustCenterSubscriberGroup; -}; - -export type CreateTrustCenterSubscriberGroupResponse = CreateTrustCenterSubscriberGroupResponses[keyof CreateTrustCenterSubscriberGroupResponses]; - -export type DeleteTrustCenterSubscriberGroupData = { - body?: never; - path: { - slugId: string; - subscriberGroupId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}'; -}; - -export type DeleteTrustCenterSubscriberGroupResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterSubscriberGroupResponse = DeleteTrustCenterSubscriberGroupResponses[keyof DeleteTrustCenterSubscriberGroupResponses]; - -export type GetTrustCenterSubscriberGroupData = { - body?: never; - path: { - slugId: string; - subscriberGroupId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}'; -}; - -export type GetTrustCenterSubscriberGroupResponses = { - /** - * Ok - */ - 200: TrustCenterSubscriberGroup; -}; - -export type GetTrustCenterSubscriberGroupResponse = GetTrustCenterSubscriberGroupResponses[keyof GetTrustCenterSubscriberGroupResponses]; - -export type UpdateTrustCenterSubscriberGroupData = { - body: EditTrustCenterSubscriberGroupInput; - path: { - slugId: string; - subscriberGroupId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscriber-groups/{subscriberGroupId}'; -}; - -export type UpdateTrustCenterSubscriberGroupResponses = { - /** - * Ok - */ - 200: TrustCenterSubscriberGroup; -}; - -export type UpdateTrustCenterSubscriberGroupResponse = UpdateTrustCenterSubscriberGroupResponses[keyof UpdateTrustCenterSubscriberGroupResponses]; - -export type ListTrustCenterSubscribersData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - customerTrustAccountId?: string; - }; - url: '/trust-centers/{slugId}/subscribers'; -}; - -export type ListTrustCenterSubscribersResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterSubscriber; -}; - -export type ListTrustCenterSubscribersResponse = ListTrustCenterSubscribersResponses[keyof ListTrustCenterSubscribersResponses]; - -export type CreateTrustCenterSubscriberData = { - body: AddTrustCenterSubscriberInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscribers'; -}; - -export type CreateTrustCenterSubscriberResponses = { - /** - * Trust Center subscriber created - */ - 201: TrustCenterSubscriber; -}; - -export type CreateTrustCenterSubscriberResponse = CreateTrustCenterSubscriberResponses[keyof CreateTrustCenterSubscriberResponses]; - -export type DeleteTrustCenterSubscriberData = { - body?: never; - path: { - slugId: string; - subscriberId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscribers/{subscriberId}'; -}; - -export type DeleteTrustCenterSubscriberResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterSubscriberResponse = DeleteTrustCenterSubscriberResponses[keyof DeleteTrustCenterSubscriberResponses]; - -export type GetTrustCenterSubscriberData = { - body?: never; - path: { - slugId: string; - subscriberId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscribers/{subscriberId}'; -}; - -export type GetTrustCenterSubscriberResponses = { - /** - * Ok - */ - 200: TrustCenterSubscriber; -}; - -export type GetTrustCenterSubscriberResponse = GetTrustCenterSubscriberResponses[keyof GetTrustCenterSubscriberResponses]; - -export type UpsertGroupsForTrustCenterSubscriberData = { - body: SetGroupsForTrustCenterSubscriberInput; - path: { - slugId: string; - subscriberId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/subscribers/{subscriberId}/groups'; -}; - -export type UpsertGroupsForTrustCenterSubscriberResponses = { - /** - * Trust Center subscriber assigned to groups - */ - 200: TrustCenterSubscriber; -}; - -export type UpsertGroupsForTrustCenterSubscriberResponse = UpsertGroupsForTrustCenterSubscriberResponses[keyof UpsertGroupsForTrustCenterSubscriberResponses]; - -export type ListTrustCenterUpdatesData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/trust-centers/{slugId}/updates'; -}; - -export type ListTrustCenterUpdatesResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterUpdateApiResponse; -}; - -export type ListTrustCenterUpdatesResponse = ListTrustCenterUpdatesResponses[keyof ListTrustCenterUpdatesResponses]; - -export type CreateTrustCenterUpdateData = { - body: AddTrustCenterUpdateInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates'; -}; - -export type CreateTrustCenterUpdateResponses = { - /** - * Trust Center update created - */ - 201: TrustCenterUpdateApiResponse; -}; - -export type CreateTrustCenterUpdateResponse = CreateTrustCenterUpdateResponses[keyof CreateTrustCenterUpdateResponses]; - -export type DeleteTrustCenterUpdateData = { - body?: never; - path: { - slugId: string; - updateId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates/{updateId}'; -}; - -export type DeleteTrustCenterUpdateResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteTrustCenterUpdateResponse = DeleteTrustCenterUpdateResponses[keyof DeleteTrustCenterUpdateResponses]; - -export type GetTrustCenterUpdateData = { - body?: never; - path: { - slugId: string; - updateId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates/{updateId}'; -}; - -export type GetTrustCenterUpdateResponses = { - /** - * Ok - */ - 200: TrustCenterUpdateApiResponse; -}; - -export type GetTrustCenterUpdateResponse = GetTrustCenterUpdateResponses[keyof GetTrustCenterUpdateResponses]; - -export type UpdateTrustCenterUpdateData = { - body: EditTrustCenterUpdateInput; - path: { - slugId: string; - updateId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates/{updateId}'; -}; - -export type UpdateTrustCenterUpdateResponses = { - /** - * Ok - */ - 200: TrustCenterUpdateApiResponse; -}; - -export type UpdateTrustCenterUpdateResponse = UpdateTrustCenterUpdateResponses[keyof UpdateTrustCenterUpdateResponses]; - -export type SendNotificationsToAllSubscribersData = { - body?: never; - path: { - slugId: string; - updateId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates/{updateId}/notify-all-subscribers'; -}; - -export type SendNotificationsToAllSubscribersResponses = { - /** - * No content - */ - 204: void; -}; - -export type SendNotificationsToAllSubscribersResponse = SendNotificationsToAllSubscribersResponses[keyof SendNotificationsToAllSubscribersResponses]; - -export type SendTrustCenterUpdateNotificationsData = { - body: SendTrustCenterUpdateNotificationsInput; - path: { - slugId: string; - updateId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/updates/{updateId}/notify-specific-subscribers'; -}; - -export type SendTrustCenterUpdateNotificationsResponses = { - /** - * Ok - */ - 200: NotifySpecificSubscribersResponse; -}; - -export type SendTrustCenterUpdateNotificationsResponse = SendTrustCenterUpdateNotificationsResponses[keyof SendTrustCenterUpdateNotificationsResponses]; - -export type ListTrustCenterViewersData = { - body?: never; - path: { - slugId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - includeRemoved?: boolean; - }; - url: '/trust-centers/{slugId}/viewers'; -}; - -export type ListTrustCenterViewersResponses = { - /** - * Ok - */ - 200: PaginatedResponseTrustCenterViewer; -}; - -export type ListTrustCenterViewersResponse = ListTrustCenterViewersResponses[keyof ListTrustCenterViewersResponses]; - -export type AddTrustCenterViewerData = { - body: AddTrustCenterViewerInput; - path: { - slugId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/viewers'; -}; - -export type AddTrustCenterViewerResponses = { - /** - * Ok - */ - 200: TrustCenterViewer; -}; - -export type AddTrustCenterViewerResponse = AddTrustCenterViewerResponses[keyof AddTrustCenterViewerResponses]; - -export type RemoveTrustCenterViewerData = { - body?: never; - path: { - slugId: string; - viewerId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/viewers/{viewerId}'; -}; - -export type RemoveTrustCenterViewerResponses = { - /** - * No content - */ - 204: void; -}; - -export type RemoveTrustCenterViewerResponse = RemoveTrustCenterViewerResponses[keyof RemoveTrustCenterViewerResponses]; - -export type GetTrustCenterViewerData = { - body?: never; - path: { - slugId: string; - viewerId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/viewers/{viewerId}'; -}; - -export type GetTrustCenterViewerResponses = { - /** - * Ok - */ - 200: TrustCenterViewer; -}; - -export type GetTrustCenterViewerResponse = GetTrustCenterViewerResponses[keyof GetTrustCenterViewerResponses]; - -export type UpdateTrustCenterViewerData = { - body: UpdateTrustCenterViewerInput; - path: { - slugId: string; - viewerId: string; - }; - query?: never; - url: '/trust-centers/{slugId}/viewers/{viewerId}'; -}; - -export type UpdateTrustCenterViewerResponses = { - /** - * Ok - */ - 200: TrustCenterViewer; -}; - -export type UpdateTrustCenterViewerResponse = UpdateTrustCenterViewerResponses[keyof UpdateTrustCenterViewerResponses]; - -export type ListUsersData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/users'; -}; - -export type ListUsersResponses = { - /** - * Ok - */ - 200: PaginatedResponseUser; -}; - -export type ListUsersResponse = ListUsersResponses[keyof ListUsersResponses]; - -export type GetUserData = { - body?: never; - path: { - userId: string; - }; - query?: never; - url: '/users/{userId}'; -}; - -export type GetUserResponses = { - /** - * Ok - */ - 200: User; -}; - -export type GetUserResponse = GetUserResponses[keyof GetUserResponses]; - -export type ListVendorRiskAttributesData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/vendor-risk-attributes'; -}; - -export type ListVendorRiskAttributesResponses = { - /** - * Ok - */ - 200: PaginatedResponseVendorRiskAttribute; -}; - -export type ListVendorRiskAttributesResponse = ListVendorRiskAttributesResponses[keyof ListVendorRiskAttributesResponses]; - -export type ListVendorsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter vendors by name (case-insensitive, partial match) - */ - name?: string; - /** - * Filter vendors by status (can specify multiple) - */ - statusMatchesAny?: Array; - }; - url: '/vendors'; -}; - -export type ListVendorsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVendor; -}; - -export type ListVendorsResponse = ListVendorsResponses[keyof ListVendorsResponses]; - -export type CreateVendorData = { - body: CreateVendorInput; - path?: never; - query?: never; - url: '/vendors'; -}; - -export type CreateVendorResponses = { - /** - * Ok - */ - 200: Vendor; -}; - -export type CreateVendorResponse = CreateVendorResponses[keyof CreateVendorResponses]; - -export type DeleteByIdData = { - body?: never; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}'; -}; - -export type DeleteByIdResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteByIdResponse = DeleteByIdResponses[keyof DeleteByIdResponses]; - -export type GetVendorData = { - body?: never; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}'; -}; - -export type GetVendorResponses = { - /** - * Ok - */ - 200: Vendor; -}; - -export type GetVendorResponse = GetVendorResponses[keyof GetVendorResponses]; - -export type UpdateVendorData = { - body: UpdateVendorInput; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}'; -}; - -export type UpdateVendorResponses = { - /** - * Ok - */ - 200: Vendor; -}; - -export type UpdateVendorResponse = UpdateVendorResponses[keyof UpdateVendorResponses]; - -export type ListVendorDocumentsData = { - body?: never; - path: { - vendorId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/vendors/{vendorId}/documents'; -}; - -export type ListVendorDocumentsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVendorDocument; -}; - -export type ListVendorDocumentsResponse = ListVendorDocumentsResponses[keyof ListVendorDocumentsResponses]; - -export type UploadDocumentToVendorData = { - body: { - file: Blob | File; - /** - * Type of the vendor document. - */ - type: string; - /** - * The document's title. - */ - title?: string; - /** - * The document's description. - */ - description?: string; - }; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}/documents'; -}; - -export type UploadDocumentToVendorResponses = { - /** - * Ok - */ - 200: VendorDocument; -}; - -export type UploadDocumentToVendorResponse = UploadDocumentToVendorResponses[keyof UploadDocumentToVendorResponses]; - -export type ListVendorFindingsData = { - body?: never; - path: { - vendorId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter findings by security review ID - */ - securityReviewId?: string; - /** - * Filter findings by document ID - */ - documentId?: string; - }; - url: '/vendors/{vendorId}/findings'; -}; - -export type ListVendorFindingsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVendorFinding; -}; - -export type ListVendorFindingsResponse = ListVendorFindingsResponses[keyof ListVendorFindingsResponses]; - -export type CreateVendorFindingData = { - body: CreateFindingInput; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}/findings'; -}; - -export type CreateVendorFindingResponses = { - /** - * Ok - */ - 200: VendorFinding; -}; - -export type CreateVendorFindingResponse = CreateVendorFindingResponses[keyof CreateVendorFindingResponses]; - -export type DeleteFindingByIdData = { - body?: never; - path: { - vendorId: string; - findingId: string; - }; - query?: never; - url: '/vendors/{vendorId}/findings/{findingId}'; -}; - -export type DeleteFindingByIdResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteFindingByIdResponse = DeleteFindingByIdResponses[keyof DeleteFindingByIdResponses]; - -export type UpdateVendorFindingData = { - body: UpdateFindingInput; - path: { - vendorId: string; - findingId: string; - }; - query?: never; - url: '/vendors/{vendorId}/findings/{findingId}'; -}; - -export type UpdateVendorFindingResponses = { - /** - * Ok - */ - 200: VendorFinding; -}; - -export type UpdateVendorFindingResponse = UpdateVendorFindingResponses[keyof UpdateVendorFindingResponses]; - -export type GetSecurityReviewsByVendorIdData = { - body?: never; - path: { - vendorId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/vendors/{vendorId}/security-reviews'; -}; - -export type GetSecurityReviewsByVendorIdResponses = { - /** - * Ok - */ - 200: PaginatedResponseSecurityReview; -}; - -export type GetSecurityReviewsByVendorIdResponse = GetSecurityReviewsByVendorIdResponses[keyof GetSecurityReviewsByVendorIdResponses]; - -export type GetSecurityReviewsByIdData = { - body?: never; - path: { - vendorId: string; - securityReviewId: string; - }; - query?: never; - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}'; -}; - -export type GetSecurityReviewsByIdResponses = { - /** - * Ok - */ - 200: SecurityReview; -}; - -export type GetSecurityReviewsByIdResponse = GetSecurityReviewsByIdResponses[keyof GetSecurityReviewsByIdResponses]; - -export type GetSecurityReviewDocumentsData = { - body?: never; - path: { - vendorId: string; - securityReviewId: string; - }; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - }; - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents'; -}; - -export type GetSecurityReviewDocumentsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVendorDocument; -}; - -export type GetSecurityReviewDocumentsResponse = GetSecurityReviewDocumentsResponses[keyof GetSecurityReviewDocumentsResponses]; - -export type UploadDocumentForSecurityReviewData = { - body: { - file: Blob | File; - /** - * Type of the vendor document. - */ - type: string; - /** - * The document's title. - */ - title?: string; - /** - * The document's description. - */ - description?: string; - }; - path: { - vendorId: string; - securityReviewId: string; - }; - query?: never; - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents'; -}; - -export type UploadDocumentForSecurityReviewResponses = { - /** - * Ok - */ - 200: VendorDocument; -}; - -export type UploadDocumentForSecurityReviewResponse = UploadDocumentForSecurityReviewResponses[keyof UploadDocumentForSecurityReviewResponses]; - -export type DeleteSecurityReviewDocumentByIdData = { - body?: never; - path: { - vendorId: string; - securityReviewId: string; - documentId: string; - }; - query?: never; - url: '/vendors/{vendorId}/security-reviews/{securityReviewId}/documents/{documentId}'; -}; - -export type DeleteSecurityReviewDocumentByIdResponses = { - /** - * No content - */ - 204: void; -}; - -export type DeleteSecurityReviewDocumentByIdResponse = DeleteSecurityReviewDocumentByIdResponses[keyof DeleteSecurityReviewDocumentByIdResponses]; - -export type SetStatusForVendorData = { - body: { - /** - * Status of the vendor - */ - status: string; - }; - path: { - vendorId: string; - }; - query?: never; - url: '/vendors/{vendorId}/set-status'; -}; - -export type SetStatusForVendorResponses = { - /** - * Ok - */ - 200: Vendor; -}; - -export type SetStatusForVendorResponse = SetStatusForVendorResponses[keyof SetStatusForVendorResponses]; - -export type ListVulnerabilitiesData = { - body?: never; - path?: never; - query?: { - /** - * Filter vulnerabilities by search query - */ - q?: string; - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter vulnerabilities by deactivation status. - */ - isDeactivated?: boolean; - /** - * Filter vulnerabilities based on a specific external ID. - */ - externalVulnerabilityId?: string; - /** - * Filter vulnerabilities that have an available fix. - */ - isFixAvailable?: boolean; - /** - * Filter vulnerabilities that are from a specific package. - */ - packageIdentifier?: string; - /** - * Filter vulnerabilities with a fix due after a specific timestamp - */ - slaDeadlineAfterDate?: string; - /** - * Filter vulnerabilities with a fix due before a specific timestamp - */ - slaDeadlineBeforeDate?: string; - /** - * Filter vulnerabilities by severity. - * Possible values: CRITICAL, HIGH, MEDIUM, LOW. - */ - severity?: ExternalFindingSeverity; - /** - * Filter vulnerabilities by the vulnerability scanner that detected them. - */ - integrationId?: string; - /** - * Filter vulnerabilities without an SLA due date. - */ - includeVulnerabilitiesWithoutSlas?: boolean; - /** - * Filter vulnerabilities by a specific asset ID. - */ - vulnerableAssetId?: string; - }; - url: '/vulnerabilities'; -}; - -export type ListVulnerabilitiesResponses = { - /** - * Ok - */ - 200: PaginatedResponseVulnerability; -}; - -export type ListVulnerabilitiesResponse = ListVulnerabilitiesResponses[keyof ListVulnerabilitiesResponses]; - -export type DeactivateVulnerabilitiesData = { - body: { - /** - * List of vulnerabilities to deactivate - */ - updates: Array; - }; - path?: never; - query?: never; - url: '/vulnerabilities/deactivate'; -}; - -export type DeactivateVulnerabilitiesResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type DeactivateVulnerabilitiesResponse = DeactivateVulnerabilitiesResponses[keyof DeactivateVulnerabilitiesResponses]; - -export type ReactivateVulnerabilitiesData = { - body: { - /** - * List of vulnerability IDs to reactivate. - */ - updates: Array<{ - /** - * ID of the vulnerability to reactivate. - */ - id: string; - }>; - }; - path?: never; - query?: never; - url: '/vulnerabilities/reactivate'; -}; - -export type ReactivateVulnerabilitiesResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type ReactivateVulnerabilitiesResponse = ReactivateVulnerabilitiesResponses[keyof ReactivateVulnerabilitiesResponses]; - -export type GetVulnerabilityData = { - body?: never; - path: { - vulnerabilityId: string; - }; - query?: never; - url: '/vulnerabilities/{vulnerabilityId}'; -}; - -export type GetVulnerabilityResponses = { - /** - * Ok - */ - 200: Vulnerability; -}; - -export type GetVulnerabilityResponse = GetVulnerabilityResponses[keyof GetVulnerabilityResponses]; - -export type ListVulnerabilityRemediationsData = { - body?: never; - path?: never; - query?: { - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter vulnerability remediations based on a specific scanner integration. - */ - integrationId?: string; - /** - * Filter vulnerability remediations by severity. - * Possible values: CRITICAL, HIGH, MEDIUM, LOW. - */ - severity?: ExternalFindingSeverity; - /** - * Filter vulnerability remediations by remediation status. - */ - isRemediatedOnTime?: boolean; - /** - * Filter vulnerability remediations that occurred after a specific timestamp. - */ - remediatedAfterDate?: string; - /** - * Filter vulnerability remediations that occurred before a specific timestamp. - */ - remediatedBeforeDate?: string; - }; - url: '/vulnerability-remediations'; -}; - -export type ListVulnerabilityRemediationsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVulnerabilityRemediation; -}; - -export type ListVulnerabilityRemediationsResponse = ListVulnerabilityRemediationsResponses[keyof ListVulnerabilityRemediationsResponses]; - -export type AcknowledgeSlaMissVulnerabilityRemediationsData = { - body: { - /** - * List of vulnerability remediation IDs. - */ - updates: Array<{ - /** - * SLA miss acknowledgement comment. This comment should describe why the SLA was missed. - */ - slaViolationComment: string; - /** - * Remediation IDs - */ - id: string; - }>; - }; - path?: never; - query?: never; - url: '/vulnerability-remediations/acknowledge-sla-miss'; -}; - -export type AcknowledgeSlaMissVulnerabilityRemediationsResponses = { - /** - * Ok - */ - 200: BulkResponse; -}; - -export type AcknowledgeSlaMissVulnerabilityRemediationsResponse = AcknowledgeSlaMissVulnerabilityRemediationsResponses[keyof AcknowledgeSlaMissVulnerabilityRemediationsResponses]; - -export type ListVulnerableAssetsData = { - body?: never; - path?: never; - query?: { - /** - * Filter vulnerable assets by search query. - */ - q?: string; - pageSize?: PageSize; - pageCursor?: PageCursor; - /** - * Filter vulnerable assets by specific vulnerability scanner. - */ - integrationId?: string; - /** - * Filter vulnerable assets by asset type. - * Possible values: CODE_REPOSITORY, CONTAINER_REPOSITORY, CONTAINER_REPOSITORY_IMAGE, MANIFEST_FILE, SERVER, SERVERLESS_FUNCTION, WORKSTATION. - */ - assetType?: VulnerableAssetType; - /** - * Filter vulnerable assets by... - */ - assetExternalAccountId?: string; - }; - url: '/vulnerable-assets'; -}; - -export type ListVulnerableAssetsResponses = { - /** - * Ok - */ - 200: PaginatedResponseVulnerableAsset; -}; - -export type ListVulnerableAssetsResponse = ListVulnerableAssetsResponses[keyof ListVulnerableAssetsResponses]; - -export type GetVulnerableAssetData = { - body?: never; - path: { - vulnerableAssetId: string; - }; - query?: never; - url: '/vulnerable-assets/{vulnerableAssetId}'; -}; - -export type GetVulnerableAssetResponses = { - /** - * Ok - */ - 200: VulnerableAsset; -}; - -export type GetVulnerableAssetResponse = GetVulnerableAssetResponses[keyof GetVulnerableAssetResponses];