API Reference
This page is the reference for every API behind Intelligence:
- the gRPC-web services, from the protos in
grpc/operators/core/api/proto/runink/core/{atlas,ask}/v1/; - the policy class of each RPC, from
atlasPoliciesininternal/console/atlas_grpc.go; - the Intelligence JSON routes, from
registerRoutesininternal/console/console.go.
Transport
The Atlas services and Ask are served as gRPC-web inside the console process:
- Same origin and session. They share the origin of the Flutter bundle and the session cookie of every
/api/*call. There is no separate port and no mux pattern: the/handler recognises a gRPC-web request by content type (serveAtlasGRPCWeb) and hands it to an in-processgrpc.Serverwrapped by improbable’sgrpcweb. - No CORS. The origin function grants none. A request whose
Originnames another site gets HTTP 403cross-origin gRPC-web is not served by the console. - One identity lookup. The session cookie is read once in the HTTP layer (
sessionEmail) and carried on the request context. With sign-in configured, a call without a valid session isUNAUTHENTICATED(unauthorized — the console session is not valid; sign in again). - Message cap. One message may be up to 16 MiB.
- Reading failures are not errors. “We could not look” is a normal response with
provenance.source = DATA_SOURCE_UNAVAILABLEand anunmeasured[]reason. Error statuses are reserved for bad requests (INVALID_ARGUMENT,NOT_FOUND,FAILED_PRECONDITION), refusals (UNAUTHENTICATED,PERMISSION_DENIED) andUNIMPLEMENTED.
Classes (see Rule governance):
- read: any admitted identity.
- attributable: a session on a console with sign-in.
- decider: attributable, and then the handler enforces four eyes.
- admin:
CORE_ATLAS_ADMINS.
A method missing from the table is admin-write.
CapexService (runink.core.atlas.v1)
| RPC | Class | Audit action |
|---|---|---|
GetFeeds | read | |
StageFeed | admin | atlas.capex.stage |
PullFeed | admin (dials a connection) | atlas.capex.pull |
PreviewIngest | read | |
CommitIngest | admin | atlas.capex.commit |
ClearFeed | admin | atlas.capex.clear |
GetConfig | read | |
UpdateConfig | admin | atlas.capex.config.update |
GetSummary | read | |
ListFindings | read | |
TraceFinding | read | |
GetRuleBook | read | |
GetAnalystDashboard | read | |
GetCfoDashboard | read | |
ListScanRuns | read |
GovernanceService
| RPC | Class | Audit action |
|---|---|---|
ListRules | read | |
ProposeRuleChange | attributable | atlas.rules.propose |
DecideRuleChange | decider (the rule owner or an Atlas admin, never the proposer) | atlas.rules.decide |
ListRuleChanges | read | |
SetRuleOwner | admin | atlas.rules.owner |
ListRemediations | read | |
DryRunRemediation | read (writes nothing) | |
DecideRemediation | decider | atlas.remediation.decide |
ListDecisions | read |
WorkspaceService
| RPC | Class | Audit action |
|---|---|---|
GetWorkspace | read | |
UpdateWorkspace | admin | atlas.workspace.update |
CompleteOnboarding | admin | atlas.workspace.onboarding.complete |
ResetWorkspace | admin | atlas.workspace.reset |
ListDqEngines | read | |
ListRegisteredAgents | read | |
RegisterAgent | admin | atlas.agents.register |
UpdateRegisteredAgent | admin | atlas.agents.update |
RemoveRegisteredAgent | admin | atlas.agents.remove |
PlaybookService
| RPC | Class | Audit action |
|---|---|---|
ListPlaybooks, GetPlaybook | read | |
CreatePlaybook | admin | atlas.playbooks.create |
UpdatePlaybook | admin | atlas.playbooks.update |
DeletePlaybook | admin | atlas.playbooks.delete |
DraftFromFindings | admin | atlas.playbooks.draft |
ActivatePlaybook | decider (an Atlas admin who did not author or last edit it) | atlas.playbooks.activate |
PausePlaybook | admin | atlas.playbooks.pause |
ResumePlaybook | admin | atlas.playbooks.resume |
RunNow | admin | atlas.playbooks.run |
CancelRun | admin | atlas.playbooks.run.cancel |
ListRuns, GetRun | read | |
DecideApproval | decider (the named approver or an Atlas admin, never the initiator) | atlas.playbooks.approval.decide |
ListDispatchableAgents | read | |
ListEvents | read |
ResolveService (deprecated alias) and EstateService
runink.core.atlas.v1.ResolveService stays registered for one release. The page itself uses runink.ui.estate.v1.EstateService (from org-runink/ui). The two share classes and audit actions.
| ResolveService RPC | EstateService RPC | Class | Audit action |
|---|---|---|---|
ListSources | ListSources | read | |
GetSourceDescription | GetSourceDescription | read | |
GetAccessPatterns | GetAccessPatterns | read | |
GetEstate | GetEstateMap | read | |
GetReconciliation | GetReconciliation | read | |
TestSource | TestSource | admin (dials) | atlas.resolve.test |
ExploreSource | ExploreSource | admin (dials) | atlas.resolve.explore |
ReadAccessPatterns | ReadAccessPatterns | admin (dials) | atlas.resolve.access |
MapEstate | MapEstate | admin (dials, returns at once) | atlas.resolve.map |
The four dialing requests and PullFeed carry an optional runner field. See Resolve.
AskService (runink.core.ask.v1)
| RPC | Class |
|---|---|
Describe | read |
Ask (server stream) | a session on a console with sign-in (consoleStreamInterceptor) |
Any other streaming method is refused: the console serves no streaming RPCs except AskService/Ask.
Intelligence HTTP routes
These routes return JSON. The GET reports answer 200 even when they could not read their source, and say so in the body as source:"unavailable" / complete:false, with an unmeasured[] list.
| Route | Method | Auth | What it is |
|---|---|---|---|
/api/swarm | GET | session | Agent swarm: fleet health, roster, run/latency rollup |
/api/domains | GET | session | Data domains clustered from the connection registry |
/api/governance | GET | session | Estate governance: ownership, credential storage, namespace posture |
/api/data-lineage | GET | session | Declared topology and observed flows |
/api/data-lineage/edges | POST | bearer CORE_HEALTH_INGEST_TOKEN | Apps’ observed-lineage ingest |
/api/compliance | GET | session | Per-control findings. Never a score, never a framework mapping |
/api/maturity | GET | session | Five measured dimensions, plus a composite only when all five are measured |
/api/rules-recon | GET [?tenant=] | session | Business-rule reconciliation |
/api/rules-recon/inputs | GET | bearer CORE_RECON_INGEST_TOKEN | The recon agent’s read door: rule book and engine |
/api/rules-recon/report | POST | bearer CORE_RECON_INGEST_TOKEN | The recon agent’s report ingest |
/api/governance-runs | GET [?repo=] | session | Run history for the governance-family agents |
/api/data-governance-findings | GET / POST | session (GET), App token via authorizeReporter (POST) | datagov findings |
/api/playbook-runs/step-report | POST | App token (authorizeReporter) | A dispatched agent reports its step |
/api/playbook-events | POST | App token (authorizeReporter) | Any agent raises an event |
/api/lineage | GET [?sha=] | session | Deploy lineage per image |
A read and a machine ingest are deliberately registered as separate exact paths, not one handler switching on the method. A guard applied to the wrong verb is how this kind of code goes wrong quietly. /api/data-governance-findings is the one exception: both verbs act on the same findings store, so the split happens inside the handler.
Token-door errors:
| Condition | Response |
|---|---|
| Recon token unset | 503: rules-reconciliation ingest is not configured (CORE_RECON_INGEST_TOKEN unset) |
| Wrong token | 403: bad ingest token (compared in constant time) |
| App-token door with no bearer | 401: missing bearer token |