Skip to content

API Reference

This page is the reference for every API behind Intelligence:

  • the gRPC-web services, from the protos in grpc/operators/core/api/proto/runink/core/{atlas,ask}/v1/;
  • the policy class of each RPC, from atlasPolicies in internal/console/atlas_grpc.go;
  • the Intelligence JSON routes, from registerRoutes in internal/console/console.go.

Transport

The Atlas services and Ask are served as gRPC-web inside the console process:

  • Same origin and session. They share the origin of the Flutter bundle and the session cookie of every /api/* call. There is no separate port and no mux pattern: the / handler recognises a gRPC-web request by content type (serveAtlasGRPCWeb) and hands it to an in-process grpc.Server wrapped by improbable’s grpcweb.
  • No CORS. The origin function grants none. A request whose Origin names another site gets HTTP 403 cross-origin gRPC-web is not served by the console.
  • One identity lookup. The session cookie is read once in the HTTP layer (sessionEmail) and carried on the request context. With sign-in configured, a call without a valid session is UNAUTHENTICATED (unauthorized — the console session is not valid; sign in again).
  • Message cap. One message may be up to 16 MiB.
  • Reading failures are not errors. “We could not look” is a normal response with provenance.source = DATA_SOURCE_UNAVAILABLE and an unmeasured[] reason. Error statuses are reserved for bad requests (INVALID_ARGUMENT, NOT_FOUND, FAILED_PRECONDITION), refusals (UNAUTHENTICATED, PERMISSION_DENIED) and UNIMPLEMENTED.

Classes (see Rule governance):

  • read: any admitted identity.
  • attributable: a session on a console with sign-in.
  • decider: attributable, and then the handler enforces four eyes.
  • admin: CORE_ATLAS_ADMINS.

A method missing from the table is admin-write.

CapexService (runink.core.atlas.v1)

RPCClassAudit action
GetFeedsread
StageFeedadminatlas.capex.stage
PullFeedadmin (dials a connection)atlas.capex.pull
PreviewIngestread
CommitIngestadminatlas.capex.commit
ClearFeedadminatlas.capex.clear
GetConfigread
UpdateConfigadminatlas.capex.config.update
GetSummaryread
ListFindingsread
TraceFindingread
GetRuleBookread
GetAnalystDashboardread
GetCfoDashboardread
ListScanRunsread

GovernanceService

RPCClassAudit action
ListRulesread
ProposeRuleChangeattributableatlas.rules.propose
DecideRuleChangedecider (the rule owner or an Atlas admin, never the proposer)atlas.rules.decide
ListRuleChangesread
SetRuleOwneradminatlas.rules.owner
ListRemediationsread
DryRunRemediationread (writes nothing)
DecideRemediationdecideratlas.remediation.decide
ListDecisionsread

WorkspaceService

RPCClassAudit action
GetWorkspaceread
UpdateWorkspaceadminatlas.workspace.update
CompleteOnboardingadminatlas.workspace.onboarding.complete
ResetWorkspaceadminatlas.workspace.reset
ListDqEnginesread
ListRegisteredAgentsread
RegisterAgentadminatlas.agents.register
UpdateRegisteredAgentadminatlas.agents.update
RemoveRegisteredAgentadminatlas.agents.remove

PlaybookService

RPCClassAudit action
ListPlaybooks, GetPlaybookread
CreatePlaybookadminatlas.playbooks.create
UpdatePlaybookadminatlas.playbooks.update
DeletePlaybookadminatlas.playbooks.delete
DraftFromFindingsadminatlas.playbooks.draft
ActivatePlaybookdecider (an Atlas admin who did not author or last edit it)atlas.playbooks.activate
PausePlaybookadminatlas.playbooks.pause
ResumePlaybookadminatlas.playbooks.resume
RunNowadminatlas.playbooks.run
CancelRunadminatlas.playbooks.run.cancel
ListRuns, GetRunread
DecideApprovaldecider (the named approver or an Atlas admin, never the initiator)atlas.playbooks.approval.decide
ListDispatchableAgentsread
ListEventsread

ResolveService (deprecated alias) and EstateService

runink.core.atlas.v1.ResolveService stays registered for one release. The page itself uses runink.ui.estate.v1.EstateService (from org-runink/ui). The two share classes and audit actions.

ResolveService RPCEstateService RPCClassAudit action
ListSourcesListSourcesread
GetSourceDescriptionGetSourceDescriptionread
GetAccessPatternsGetAccessPatternsread
GetEstateGetEstateMapread
GetReconciliationGetReconciliationread
TestSourceTestSourceadmin (dials)atlas.resolve.test
ExploreSourceExploreSourceadmin (dials)atlas.resolve.explore
ReadAccessPatternsReadAccessPatternsadmin (dials)atlas.resolve.access
MapEstateMapEstateadmin (dials, returns at once)atlas.resolve.map

The four dialing requests and PullFeed carry an optional runner field. See Resolve.

AskService (runink.core.ask.v1)

RPCClass
Describeread
Ask (server stream)a session on a console with sign-in (consoleStreamInterceptor)

Any other streaming method is refused: the console serves no streaming RPCs except AskService/Ask.

Intelligence HTTP routes

These routes return JSON. The GET reports answer 200 even when they could not read their source, and say so in the body as source:"unavailable" / complete:false, with an unmeasured[] list.

RouteMethodAuthWhat it is
/api/swarmGETsessionAgent swarm: fleet health, roster, run/latency rollup
/api/domainsGETsessionData domains clustered from the connection registry
/api/governanceGETsessionEstate governance: ownership, credential storage, namespace posture
/api/data-lineageGETsessionDeclared topology and observed flows
/api/data-lineage/edgesPOSTbearer CORE_HEALTH_INGEST_TOKENApps’ observed-lineage ingest
/api/complianceGETsessionPer-control findings. Never a score, never a framework mapping
/api/maturityGETsessionFive measured dimensions, plus a composite only when all five are measured
/api/rules-reconGET [?tenant=]sessionBusiness-rule reconciliation
/api/rules-recon/inputsGETbearer CORE_RECON_INGEST_TOKENThe recon agent’s read door: rule book and engine
/api/rules-recon/reportPOSTbearer CORE_RECON_INGEST_TOKENThe recon agent’s report ingest
/api/governance-runsGET [?repo=]sessionRun history for the governance-family agents
/api/data-governance-findingsGET / POSTsession (GET), App token via authorizeReporter (POST)datagov findings
/api/playbook-runs/step-reportPOSTApp token (authorizeReporter)A dispatched agent reports its step
/api/playbook-eventsPOSTApp token (authorizeReporter)Any agent raises an event
/api/lineageGET [?sha=]sessionDeploy lineage per image

A read and a machine ingest are deliberately registered as separate exact paths, not one handler switching on the method. A guard applied to the wrong verb is how this kind of code goes wrong quietly. /api/data-governance-findings is the one exception: both verbs act on the same findings store, so the split happens inside the handler.

Token-door errors:

ConditionResponse
Recon token unset503: rules-reconciliation ingest is not configured (CORE_RECON_INGEST_TOKEN unset)
Wrong token403: bad ingest token (compared in constant time)
App-token door with no bearer401: missing bearer token