arazzo: 1.1.0
$self: https://neotask.ai/arazzo.yaml
info:
  title: Neotask agent workflows
  version: 1.5.0
  summary: Machine-executable Neotask Agent API journeys and per-operation workflows.
  description: "Launch state: Live. Agents can register at /auth.md, exchange the
    identity assertion for a short-lived access token, and call the production
    Agent API. Configure the exact bearer audience required by each referenced
    OpenAPI operation. Human-session steps require the separately documented
    signed-in user credential."
sourceDescriptions:
  - name: agentApi
    url: ./openapi.yaml
    type: openapi
workflows:
  - workflowId: discover-and-authenticate
    summary: Discover Neotask and verify an agent credential.
    description: Read auth.md and the protected-resource metadata first. Configure
      the workflow runner with the short-lived Agent API bearer, then verify it
      against the current account.
    steps:
      - stepId: 01-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentProfile
    x-neotask-explicit-selection-required: false
  - workflowId: inspect-account-and-effective-access
    summary: Read the account, capability manifest, and current setup journey.
    description: Use the server-derived capability response as the authority before
      choosing a mutation or requesting human action.
    steps:
      - stepId: 01-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-get-agent-onboarding
        description: Returns a server-derived onboarding snapshot with bounded resource
          summaries, effective next actions, and current blockers for the
          authenticated agent.
        operationId: getAgentOnboarding
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/onboarding
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentProfile
      - getAgentCapabilities
      - getAgentOnboarding
    x-neotask-explicit-selection-required: false
  - workflowId: create-starter-agent
    summary: Create a starter agent with a currently allowed model.
    description: Choose a model returned by the effective model catalog. Keep the
      starter agent free of external integrations, user secrets, browser
      actions, email, destructive tools, and paid-only models.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_03_create_agent_Idempotency_Key
        - input_03_create_agent_request
        - input_04_get_agent_agentRef
      properties:
        input_03_create_agent_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_create_agent_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCreateRequest
        input_04_get_agent_agentRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-list-agent-models
        description: Returns the server-derived model catalog for the authenticated
          account, including plan, credential, availability, and Free Neotask
          Matrix state.
        operationId: listAgentModels
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/models
        x-neotask-method: GET
        x-neotask-required-scope: neotask:models:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-create-agent
        description: Creates a standalone agent under the current ordinary plan and
          model policy.
        operationId: createAgent
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_create_agent_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_create_agent_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents
        x-neotask-method: POST
        x-neotask-required-scope: neotask:agents:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-get-agent
        description: Returns one managed agent owned by the verified tenant.
        operationId: getAgent
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_04_get_agent_agentRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:agents:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCapabilities
      - listAgentModels
      - createAgent
      - getAgent
    x-neotask-explicit-selection-required: false
  - workflowId: create-starter-task
    summary: Create a starter task for an existing tenant-owned agent.
    description: Use only agent references returned by this account. The request
      body is explicit workflow input and remains subject to the current tool
      and model policy.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_task_Idempotency_Key
        - input_02_create_task_request
      properties:
        input_02_create_task_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_task_request:
          $ref: ./openapi.yaml#/components/schemas/TaskCreateRequest
    steps:
      - stepId: 01-list-agents
        description: Lists only agents inside the tenant derived from the verified
          credential.
        operationId: listAgents
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents
        x-neotask-method: GET
        x-neotask-required-scope: neotask:agents:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-task
        description: Creates a tenant-scoped task under the current ordinary plan and
          model policy.
        operationId: createTask
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_task_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_task_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/tasks
        x-neotask-method: POST
        x-neotask-required-scope: neotask:tasks:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-list-tasks
        description: Lists standalone tasks owned by the verified tenant, optionally
          filtered by a standalone agent identifier. Company tasks require the
          company endpoints and company read scope.
        operationId: listTasks
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/tasks
        x-neotask-method: GET
        x-neotask-required-scope: neotask:tasks:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgents
      - createTask
      - listTasks
    x-neotask-explicit-selection-required: false
  - workflowId: run-first-task
    summary: Request a first run and recover its durable state.
    description: Check effective access before dispatch. A client disconnect does
      not cancel the run. Recover state through the durable run resource and
      bounded JSON event page.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_run_Idempotency_Key
        - input_02_create_run_request
        - input_03_get_run_runId
        - input_04_list_agent_run_events_runRef
      properties:
        input_02_create_run_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_run_request:
          $ref: ./openapi.yaml#/components/schemas/RunCreateRequest
        input_03_get_run_runId:
          type: string
          maxLength: 200
        input_04_list_agent_run_events_runRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-run
        description: Starts work through the trusted Gateway boundary after current
          quota and model checks.
        operationId: createRun
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_run_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_run_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:runs:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-get-run
        description: Reads one run only after tenant and task ownership checks.
        operationId: getRun
        parameters:
          - name: runId
            in: path
            value: $inputs.input_03_get_run_runId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runs/{runId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:runs:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 04-list-agent-run-events
        description: Returns ordered lifecycle events for one standalone-agent run after
          an opaque cursor.
        operationId: listAgentRunEvents
        parameters:
          - name: runRef
            in: path
            value: $inputs.input_04_list_agent_run_events_runRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runs/{runRef}/events
        x-neotask-method: GET
        x-neotask-required-scope: neotask:runs:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCapabilities
      - createRun
      - getRun
      - listAgentRunEvents
    x-neotask-explicit-selection-required: false
  - workflowId: run-temporarily-disabled
    summary: Handle a run whose concrete execution owner is unavailable.
    description: This branch expects the run request to fail closed with HTTP 503.
      Re-read capabilities and wait for an eligible runner instead of bypassing
      Site policy or blindly retrying.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_run_Idempotency_Key
        - input_02_create_run_request
      properties:
        input_02_create_run_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_run_request:
          $ref: ./openapi.yaml#/components/schemas/RunCreateRequest
    steps:
      - stepId: 01-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-run
        description: Starts work through the trusted Gateway boundary after current
          quota and model checks.
        operationId: createRun
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_run_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_run_request
        successCriteria:
          - condition: $statusCode == 503
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:runs:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - getAgentCapabilities
      - createRun
    x-neotask-explicit-selection-required: false
  - workflowId: claim-agent-trial-registration
    summary: Verify the same Tenant after a human claims an Agent Trial.
    description: Complete the verification URI and user-code ceremony described by
      auth.md outside this API, exchange the post-claim credential, then prove
      that the same account and resources were promoted without duplication. If
      the claim cannot be promoted in place, the credential returns
      identity_conflict with reason claim_move_confirmation_required until a
      signed-in person confirms the move at the returned action URL, which goes
      only to the claimer; then prove that the agent and its resources belong to
      the confirming account.
    steps:
      - stepId: 01-get-agent-onboarding
        description: Returns a server-derived onboarding snapshot with bounded resource
          summaries, effective next actions, and current blockers for the
          authenticated agent.
        operationId: getAgentOnboarding
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/onboarding
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentOnboarding
      - getAgentProfile
      - getAgentCapabilities
    x-neotask-explicit-selection-required: false
  - workflowId: claim-service-auth-registration
    summary: Verify a service-auth registration after human claim.
    description: A pending service-auth identity has no product authority. After the
      documented claim ceremony and token exchange, verify the promoted account
      before requesting product operations.
    steps:
      - stepId: 01-get-agent-onboarding
        description: Returns a server-derived onboarding snapshot with bounded resource
          summaries, effective next actions, and current blockers for the
          authenticated agent.
        operationId: getAgentOnboarding
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/onboarding
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentOnboarding
      - getAgentProfile
      - getAgentCapabilities
    x-neotask-explicit-selection-required: false
  - workflowId: pair-human-account-control
    summary: Create and inspect a same-Tenant human-control handoff.
    description: Relay only the opaque server-created URL. The handoff cannot choose
      or merge a Tenant, and the agent cannot complete the human confirmation
      step.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_agent_account_pairing_handoff_Idempotency_Key
        - input_01_create_agent_account_pairing_handoff_request
        - input_02_get_agent_account_pairing_handoff_handoffRef
      properties:
        input_01_create_agent_account_pairing_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_agent_account_pairing_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAccountPairingHandoffCreateRequest
        input_02_get_agent_account_pairing_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
    steps:
      - stepId: 01-create-agent-account-pairing-handoff
        description: Creates a short-lived, single-use handoff URL for an already
          claimed agent registration.
        operationId: createAgentAccountPairingHandoff
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_agent_account_pairing_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_agent_account_pairing_handoff_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/account/pairing-handoffs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:account:pair
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 02-get-agent-account-pairing-handoff
        description: Returns the status of a pairing handoff owned by the authenticated
          agent registration.
        operationId: getAgentAccountPairingHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_02_get_agent_account_pairing_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/account/pairing-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:account:pair
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - createAgentAccountPairingHandoff
      - getAgentAccountPairingHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: attach-electron-to-existing-account
    summary: Offer signed desktop downloads and attach Electron to the existing account.
    description: Use only signed download choices returned by the Site. Pair
      Electron through the same-Tenant handoff; do not create a second
      subscription or workspace.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_agent_account_pairing_handoff_Idempotency_Key
        - input_02_create_agent_account_pairing_handoff_request
        - input_03_get_agent_account_pairing_handoff_handoffRef
      properties:
        input_02_create_agent_account_pairing_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_agent_account_pairing_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAccountPairingHandoffCreateRequest
        input_03_get_agent_account_pairing_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
    steps:
      - stepId: 01-list-desktop-download-options
        description: Returns the reviewed desktop release options after the
          authenticated human has confirmed control of the claimed account.
        operationId: listDesktopDownloadOptions
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/desktop/downloads
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-agent-account-pairing-handoff
        description: Creates a short-lived, single-use handoff URL for an already
          claimed agent registration.
        operationId: createAgentAccountPairingHandoff
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_agent_account_pairing_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_agent_account_pairing_handoff_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/account/pairing-handoffs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:account:pair
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-get-agent-account-pairing-handoff
        description: Returns the status of a pairing handoff owned by the authenticated
          agent registration.
        operationId: getAgentAccountPairingHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_03_get_agent_account_pairing_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/account/pairing-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:account:pair
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listDesktopDownloadOptions
      - createAgentAccountPairingHandoff
      - getAgentAccountPairingHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: rotate-credential
    summary: Verify access after credential rotation.
    description: Rotate or refresh through the auth.md authority outside this API.
      Use the new audience-bound credential for these verification calls and
      stop using superseded material.
    steps:
      - stepId: 01-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentProfile
      - getAgentCapabilities
    x-neotask-explicit-selection-required: false
  - workflowId: revoke-registration
    summary: Revoke the current agent registration.
    description: Select this lifecycle workflow explicitly. Revocation invalidates
      product authority and must not be retried with the revoked credential.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_revoke_agent_registration_Idempotency_Key
      properties:
        input_02_revoke_agent_registration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-get-agent-profile
        description: Returns the server-verified agent principal, linked account,
          current plan snapshot, and the capabilities URL.
        operationId: getAgentProfile
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/me
        x-neotask-method: GET
        x-neotask-required-scope: neotask:profile:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-revoke-agent-registration
        description: Immediately disables the current agent registration inside Neotask.
        operationId: revokeAgentRegistration
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_revoke_agent_registration_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/registration
        x-neotask-method: DELETE
        x-neotask-required-scope: neotask:registration:revoke
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - getAgentProfile
      - revokeAgentRegistration
    x-neotask-explicit-selection-required: true
  - workflowId: request-human-upgrade
    summary: Create an opaque paid-plan handoff for a verified human.
    description: The agent requests the handoff; nothing is purchased until the
      signed-in account owner inspects and confirms it with a separate
      web-session credential. Confirmation starts Stripe Checkout for an account
      without a subscription, or upgrades an existing Stripe subscription in
      place (prorated, applied only once paid); an account never gets a second
      subscription. The request returns payment_processing while another payment
      for the account is in progress, app_store_subscription when the App Store
      bills the plan, billing_action_required when the subscription needs
      billing action first, and manual_review_required after an unverified
      failed payment; none is relayed as a link. After payment the agent retries
      its original operation; the handoff request returns already_active once
      the plan includes it.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_request_agent_checkout_handoff_request
        - input_03_inspect_agent_checkout_handoff_handoffRef
        - input_04_confirm_agent_checkout_handoff_handoffRef
        - input_04_confirm_agent_checkout_handoff_request
      properties:
        input_02_request_agent_checkout_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCheckoutHandoffRequest
        input_03_inspect_agent_checkout_handoff_handoffRef:
          type: string
          pattern: ^[A-Za-z0-9_-]{43}$
        input_04_confirm_agent_checkout_handoff_handoffRef:
          type: string
          pattern: ^[A-Za-z0-9_-]{43}$
        input_04_confirm_agent_checkout_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCheckoutConfirmationRequest
    steps:
      - stepId: 01-get-agent-capabilities
        description: Returns the server-verified identity, linked account, ordinary plan
          limits, allowed models, capability states, and effective access for
          every Agent API v1 operation.
        operationId: getAgentCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-request-agent-checkout-handoff
        description: Returns a short-lived opaque handoff that a claimed agent may relay
          to its signed-in human; payment credentials never cross the agent API.
        operationId: requestAgentCheckoutHandoff
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_request_agent_checkout_handoff_request
        successCriteria:
          - condition: $statusCode == 402
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/checkout-handoffs/request
        x-neotask-method: POST
        x-neotask-required-scope: neotask:billing:handoff
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-inspect-agent-checkout-handoff
        description: Discloses handoff details only to the human account that owns the
          linked tenant.
        operationId: inspectAgentCheckoutHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_03_inspect_agent_checkout_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/checkout-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: null
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
      - stepId: 04-confirm-agent-checkout-handoff
        description: "After tenant, claim, plan, expiry, and replay checks: for an
          account without a Stripe subscription, creates or reuses one Stripe
          Checkout session; for an existing Stripe subscriber, upgrades that
          same subscription in place (prorated, applied only once paid)."
        operationId: confirmAgentCheckoutHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_04_confirm_agent_checkout_handoff_handoffRef
        requestBody:
          contentType: application/json
          payload: $inputs.input_04_confirm_agent_checkout_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/checkout-handoffs/{handoffRef}
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: null
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCapabilities
      - requestAgentCheckoutHandoff
      - inspectAgentCheckoutHandoff
      - confirmAgentCheckoutHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: read-human-upgrade-return-status
    summary: Read the post-payment status on the human upgrade return page.
    description: Starts on the signed-in /agent-upgrade/complete page with the
      session_id Stripe appended to that return URL, or the plan_change id of an
      in-place upgrade, using the human web-session credential. It only reads
      whether the signed webhook recorded this payment; agents never run it.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_read_agent_checkout_completion_request
      properties:
        input_01_read_agent_checkout_completion_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCheckoutCompletionRequest
    steps:
      - stepId: 01-read-agent-checkout-completion
        description: Used by the signed-in human return page after Stripe Checkout
          (sessionId) or after an in-place upgrade of an existing subscription
          (planChangeId). Re-reads the session or subscription from Stripe,
          requires its server-authored tenant binding to match the signed-in
          tenant, and reports whether the signed Stripe webhook has applied the
          plan. It never changes the plan.
        operationId: readAgentCheckoutCompletion
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_read_agent_checkout_completion_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/checkout-handoffs/completion
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: null
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - readAgentCheckoutCompletion
    x-neotask-explicit-selection-required: false
  - workflowId: managed-agent-chat-and-recovery
    summary: Create a conversation turn and recover ordered events.
    description: Create a tenant-owned conversation and turn, then recover its
      durable status and bounded JSON event history. Streaming remains an
      optional projection over the same cursor namespace.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_agent_conversation_Idempotency_Key
        - input_02_create_agent_conversation_request
        - input_03_create_agent_conversation_turn_conversationRef
        - input_03_create_agent_conversation_turn_Idempotency_Key
        - input_03_create_agent_conversation_turn_request
        - input_04_get_agent_conversation_turn_conversationRef
        - input_04_get_agent_conversation_turn_turnRef
        - input_05_list_agent_conversation_turn_events_conversationRef
        - input_05_list_agent_conversation_turn_events_turnRef
      properties:
        input_02_create_agent_conversation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_agent_conversation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentConversationCreateRequest
        input_03_create_agent_conversation_turn_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_03_create_agent_conversation_turn_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_create_agent_conversation_turn_request:
          $ref: ./openapi.yaml#/components/schemas/AgentConversationTurnCreateRequest
        input_04_get_agent_conversation_turn_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_04_get_agent_conversation_turn_turnRef:
          type: string
          minLength: 1
          maxLength: 200
        input_05_list_agent_conversation_turn_events_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_05_list_agent_conversation_turn_events_turnRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-list-agents
        description: Lists only agents inside the tenant derived from the verified
          credential.
        operationId: listAgents
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents
        x-neotask-method: GET
        x-neotask-required-scope: neotask:agents:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-agent-conversation
        description: Creates a durable conversation backed by the existing tenant
          session store.
        operationId: createAgentConversation
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_agent_conversation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_agent_conversation_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations
        x-neotask-method: POST
        x-neotask-required-scope: neotask:conversations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-create-agent-conversation-turn
        description: Creates a durable turn and queues its run through the trusted
          runner dispatch.
        operationId: createAgentConversationTurn
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_03_create_agent_conversation_turn_conversationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_create_agent_conversation_turn_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_create_agent_conversation_turn_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/turns
        x-neotask-method: POST
        x-neotask-required-scope: neotask:conversations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-get-agent-conversation-turn
        description: Returns one durable conversation turn and its current execution state.
        operationId: getAgentConversationTurn
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_04_get_agent_conversation_turn_conversationRef
          - name: turnRef
            in: path
            value: $inputs.input_04_get_agent_conversation_turn_turnRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/turns/{turnRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-list-agent-conversation-turn-events
        description: Returns ordered events for one tenant-scoped conversation turn
          after an opaque cursor.
        operationId: listAgentConversationTurnEvents
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_05_list_agent_conversation_turn_events_conversationRef
          - name: turnRef
            in: path
            value: $inputs.input_05_list_agent_conversation_turn_events_turnRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/turns/{turnRef}/events
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgents
      - createAgentConversation
      - createAgentConversationTurn
      - getAgentConversationTurn
      - listAgentConversationTurnEvents
    x-neotask-explicit-selection-required: false
  - workflowId: manage-agent-tools-and-model
    summary: Inspect effective tools and set an allowed model.
    description: Read the server-owned policy and catalogs before changing an agent.
      A model catalog entry or bearer scope does not bypass claim, plan, or
      tool-policy checks.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_03_get_agent_effective_tools_agentRef
        - input_04_get_agent_tool_policy_agentRef
        - input_05_update_agent_tool_policy_agentRef
        - input_05_update_agent_tool_policy_Idempotency_Key
        - input_05_update_agent_tool_policy_request
        - input_06_set_agent_model_agentRef
        - input_06_set_agent_model_Idempotency_Key
        - input_06_set_agent_model_request
      properties:
        input_03_get_agent_effective_tools_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_04_get_agent_tool_policy_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_05_update_agent_tool_policy_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_05_update_agent_tool_policy_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_05_update_agent_tool_policy_request:
          $ref: ./openapi.yaml#/components/schemas/AgentToolPolicyUpdateRequest
        input_06_set_agent_model_agentRef:
          type: string
          maxLength: 256
        input_06_set_agent_model_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_06_set_agent_model_request:
          $ref: ./openapi.yaml#/components/schemas/AgentModelSetRequest
    steps:
      - stepId: 01-list-agent-skills
        description: Returns the server-derived skill catalog for the authenticated
          account, including required connections, local dependencies, and setup
          state.
        operationId: listAgentSkills
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/skills
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-list-agent-models
        description: Returns the server-derived model catalog for the authenticated
          account, including plan, credential, availability, and Free Neotask
          Matrix state.
        operationId: listAgentModels
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/models
        x-neotask-method: GET
        x-neotask-required-scope: neotask:models:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-get-agent-effective-tools
        description: Returns MCP permissions. Pass runRef to read complete prepared-tool
          availability for one owned selected-agent run.
        operationId: getAgentEffectiveTools
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_03_get_agent_effective_tools_agentRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/tools
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 04-get-agent-tool-policy
        description: Returns the MCP policy, runtime tool restrictions, and their shared
          revision for a managed agent.
        operationId: getAgentToolPolicy
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_04_get_agent_tool_policy_agentRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/tool-policy
        x-neotask-method: GET
        x-neotask-required-scope: neotask:agents:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-update-agent-tool-policy
        description: Narrows MCP or runtime tool restrictions with revision-checked
          writes. An agent cannot widen either policy.
        operationId: updateAgentToolPolicy
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_05_update_agent_tool_policy_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_05_update_agent_tool_policy_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_05_update_agent_tool_policy_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/tool-policy
        x-neotask-method: PATCH
        x-neotask-required-scope: neotask:agents:configure
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 06-set-agent-model
        description: Selects an allowed model for an agent owned by the authenticated
          tenant after current authority, plan, and platform policy checks;
          provider setup remains separately reported by the model catalog.
        operationId: setAgentModel
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_06_set_agent_model_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_06_set_agent_model_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_06_set_agent_model_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/model
        x-neotask-method: PUT
        x-neotask-required-scope: neotask:models:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - listAgentSkills
      - listAgentModels
      - getAgentEffectiveTools
      - getAgentToolPolicy
      - updateAgentToolPolicy
      - setAgentModel
    x-neotask-explicit-selection-required: false
  - workflowId: manage-cron-schedule
    summary: Create, run, inspect, and disable a cron schedule.
    description: Use the ordinary plan gate and server-owned agent policy. Every
      mutation uses its own idempotency key and every resource reference comes
      from this Tenant.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_agent_cron_job_Idempotency_Key
        - input_02_create_agent_cron_job_request
        - input_03_get_agent_cron_job_cronJobRef
        - input_04_run_agent_cron_job_cronJobRef
        - input_04_run_agent_cron_job_Idempotency_Key
        - input_04_run_agent_cron_job_request
        - input_05_list_agent_cron_job_runs_cronJobRef
        - input_06_disable_agent_cron_job_cronJobRef
        - input_06_disable_agent_cron_job_Idempotency_Key
        - input_06_disable_agent_cron_job_request
      properties:
        input_02_create_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronJobCreateRequest
        input_03_get_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_04_run_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_04_run_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_04_run_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronRunRequest
        input_05_list_agent_cron_job_runs_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_06_disable_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_06_disable_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_06_disable_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronJobDisableRequest
    steps:
      - stepId: 01-list-agent-cron-jobs
        description: Lists cron schedules owned by the verified claimed tenant.
        operationId: listAgentCronJobs
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron
        x-neotask-method: GET
        x-neotask-required-scope: neotask:cron:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-agent-cron-job
        description: Creates a tenant-scoped cron schedule for an existing task.
        operationId: createAgentCronJob
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron
        x-neotask-method: POST
        x-neotask-required-scope: neotask:cron:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-get-agent-cron-job
        description: Reads one cron schedule scoped to the verified claimed tenant.
        operationId: getAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_03_get_agent_cron_job_cronJobRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:cron:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 04-run-agent-cron-job
        description: Queues one schedule-attributed run through the existing trusted
          runner outbox.
        operationId: runAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_04_run_agent_cron_job_cronJobRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_04_run_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_04_run_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}/runs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:cron:run
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 05-list-agent-cron-job-runs
        description: Lists durable schedule-attributed runs for one tenant-scoped cron
          schedule.
        operationId: listAgentCronJobRuns
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_05_list_agent_cron_job_runs_cronJobRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}/runs
        x-neotask-method: GET
        x-neotask-required-scope: neotask:cron:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 06-disable-agent-cron-job
        description: Disables an existing tenant-scoped cron schedule without deleting
          its run history.
        operationId: disableAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_06_disable_agent_cron_job_cronJobRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_06_disable_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_06_disable_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}/disable
        x-neotask-method: POST
        x-neotask-required-scope: neotask:cron:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - listAgentCronJobs
      - createAgentCronJob
      - getAgentCronJob
      - runAgentCronJob
      - listAgentCronJobRuns
      - disableAgentCronJob
    x-neotask-explicit-selection-required: true
  - workflowId: manage-automation
    summary: Create and control a durable automation flow.
    description: Choose a server-advertised template, create the flow, then use its
      durable status and run history for control and recovery.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_agent_automation_Idempotency_Key
        - input_02_create_agent_automation_request
        - input_03_start_agent_automation_automationRef
        - input_03_start_agent_automation_Idempotency_Key
        - input_03_start_agent_automation_request
        - input_04_get_agent_automation_status_automationRef
        - input_05_list_agent_automation_runs_automationRef
        - input_06_pause_agent_automation_automationRef
        - input_06_pause_agent_automation_Idempotency_Key
        - input_06_pause_agent_automation_request
        - input_07_resume_agent_automation_automationRef
        - input_07_resume_agent_automation_Idempotency_Key
        - input_07_resume_agent_automation_request
      properties:
        input_02_create_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationCreateRequest
        input_03_start_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_03_start_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_start_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationStartRequest
        input_04_get_agent_automation_status_automationRef:
          type: string
          maxLength: 128
        input_05_list_agent_automation_runs_automationRef:
          type: string
          maxLength: 128
        input_06_pause_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_06_pause_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_06_pause_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationRevisionRequest
        input_07_resume_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_07_resume_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_07_resume_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationRevisionRequest
    steps:
      - stepId: 01-list-agent-automation-catalog
        description: Returns the bounded Task Flow and automation kinds that the claimed
          Agent API account may create.
        operationId: listAgentAutomationCatalog
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/catalog
        x-neotask-method: GET
        x-neotask-required-scope: neotask:automations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-agent-automation
        description: Creates a tenant-scoped Task Flow or automation from a bounded
          natural-language instruction.
        operationId: createAgentAutomation
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_agent_automation_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows
        x-neotask-method: POST
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-start-agent-automation
        description: Queues one active Task Flow or automation through the trusted Site
          runner outbox with its DB-authoritative descriptor.
        operationId: startAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_03_start_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_start_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_start_agent_automation_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/start
        x-neotask-method: POST
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-get-agent-automation-status
        description: Returns current automation lifecycle state and the most recent
          durable run.
        operationId: getAgentAutomationStatus
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_04_get_agent_automation_status_automationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/status
        x-neotask-method: GET
        x-neotask-required-scope: neotask:automations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-list-agent-automation-runs
        description: Lists durable runs attributed to one tenant-scoped Task Flow or
          automation.
        operationId: listAgentAutomationRuns
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_05_list_agent_automation_runs_automationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/runs
        x-neotask-method: GET
        x-neotask-required-scope: neotask:automations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 06-pause-agent-automation
        description: Pauses a tenant-scoped automation with optimistic revision fencing.
        operationId: pauseAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_06_pause_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_06_pause_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_06_pause_agent_automation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/pause
        x-neotask-method: POST
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 07-resume-agent-automation
        description: Resumes a paused automation with optimistic revision fencing.
        operationId: resumeAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_07_resume_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_07_resume_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_07_resume_agent_automation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/resume
        x-neotask-method: POST
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - listAgentAutomationCatalog
      - createAgentAutomation
      - startAgentAutomation
      - getAgentAutomationStatus
      - listAgentAutomationRuns
      - pauseAgentAutomation
      - resumeAgentAutomation
    x-neotask-explicit-selection-required: false
  - workflowId: manage-autonomy-goal
    summary: Create and steer an autonomy goal under current policy.
    description: Autonomy requires both the ordinary plan feature and a concrete
      trusted control owner. Approval waits remain durable and Site policy wins
      after restart.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_agent_autonomy_goal_Idempotency_Key
        - input_01_create_agent_autonomy_goal_request
        - input_02_start_agent_autonomy_goal_goalRef
        - input_02_start_agent_autonomy_goal_Idempotency_Key
        - input_02_start_agent_autonomy_goal_request
        - input_03_get_agent_autonomy_goal_status_goalRef
        - input_04_steer_agent_autonomy_goal_goalRef
        - input_04_steer_agent_autonomy_goal_Idempotency_Key
        - input_04_steer_agent_autonomy_goal_request
        - input_05_list_agent_autonomy_goal_runs_goalRef
        - input_06_pause_agent_autonomy_goal_goalRef
        - input_06_pause_agent_autonomy_goal_Idempotency_Key
        - input_06_pause_agent_autonomy_goal_request
        - input_07_resume_agent_autonomy_goal_goalRef
        - input_07_resume_agent_autonomy_goal_Idempotency_Key
        - input_07_resume_agent_autonomy_goal_request
      properties:
        input_01_create_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutonomyGoalCreateRequest
        input_02_start_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_02_start_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_start_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
        input_03_get_agent_autonomy_goal_status_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_04_steer_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_04_steer_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_04_steer_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutonomyGoalSteerRequest
        input_05_list_agent_autonomy_goal_runs_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_06_pause_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_06_pause_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_06_pause_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
        input_07_resume_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_07_resume_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_07_resume_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
    steps:
      - stepId: 01-create-agent-autonomy-goal
        description: Creates one company-scoped autonomy goal with server-owned identity
          and durable idempotency.
        operationId: createAgentAutonomyGoal
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 02-start-agent-autonomy-goal
        description: Starts one autonomy goal through the trusted runner when the
          concrete runtime owner is ready.
        operationId: startAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_02_start_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_start_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_start_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/start
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-get-agent-autonomy-goal-status
        description: Returns the goal state, task-plan summary, and current run state
          for the verified tenant.
        operationId: getAgentAutonomyGoalStatus
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_03_get_agent_autonomy_goal_status_goalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/status
        x-neotask-method: GET
        x-neotask-required-scope: neotask:autonomy:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 04-steer-agent-autonomy-goal
        description: Sends a bounded instruction to an active goal through the trusted
          runner control owner.
        operationId: steerAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_04_steer_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_04_steer_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_04_steer_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/steer
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:steer
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 05-list-agent-autonomy-goal-runs
        description: Lists durable runs associated with one company-scoped autonomy goal.
        operationId: listAgentAutonomyGoalRuns
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_05_list_agent_autonomy_goal_runs_goalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/runs
        x-neotask-method: GET
        x-neotask-required-scope: neotask:autonomy:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 06-pause-agent-autonomy-goal
        description: Pauses an autonomy goal at a durable Site checkpoint.
        operationId: pauseAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_06_pause_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_06_pause_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_06_pause_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/pause
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 07-resume-agent-autonomy-goal
        description: Resumes a paused autonomy goal from its latest durable Site checkpoint.
        operationId: resumeAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_07_resume_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_07_resume_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_07_resume_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/resume
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - createAgentAutonomyGoal
      - startAgentAutonomyGoal
      - getAgentAutonomyGoalStatus
      - steerAgentAutonomyGoal
      - listAgentAutonomyGoalRuns
      - pauseAgentAutonomyGoal
      - resumeAgentAutonomyGoal
    x-neotask-explicit-selection-required: false
  - workflowId: relay-and-recover-approval
    summary: Inspect an approval, relay human action, and recover events.
    description: The handoff grants no authority to the agent. Keep the approval
      reference stable across disconnects and recover through the durable
      approval resource and JSON event page.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_get_agent_approval_approvalRef
        - input_03_create_agent_approval_handoff_approvalRef
        - input_03_create_agent_approval_handoff_Idempotency_Key
        - input_03_create_agent_approval_handoff_request
        - input_04_get_agent_approval_handoff_approvalRef
        - input_04_get_agent_approval_handoff_handoffRef
        - input_05_list_agent_approval_events_approvalRef
      properties:
        input_02_get_agent_approval_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_03_create_agent_approval_handoff_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_03_create_agent_approval_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_create_agent_approval_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentApprovalHandoffCreateRequest
        input_04_get_agent_approval_handoff_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_04_get_agent_approval_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_05_list_agent_approval_events_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-list-agent-approvals
        description: Lists approval requests belonging to the authenticated agent
          principal without exposing secrets or unrelated tenant data.
        operationId: listAgentApprovals
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-approval
        description: Reads one approval request inside the authenticated principal
          boundary and redacts credential-shaped values.
        operationId: getAgentApproval
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_02_get_agent_approval_approvalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-create-agent-approval-handoff
        description: Creates a short-lived opaque relay URL for a signed-in human to
          review one pending approval. The handoff carries no decision
          authority.
        operationId: createAgentApprovalHandoff
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_03_create_agent_approval_handoff_approvalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_create_agent_approval_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_create_agent_approval_handoff_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/human-handoffs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:approvals:handoff
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-get-agent-approval-handoff
        description: Reads a tenant- and principal-bound approval handoff together with
          the current durable approval state.
        operationId: getAgentApprovalHandoff
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_04_get_agent_approval_handoff_approvalRef
          - name: handoffRef
            in: path
            value: $inputs.input_04_get_agent_approval_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/human-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-list-agent-approval-events
        description: Recovers ordered approval-state events from the durable approval
          owner through an opaque after-exclusive cursor.
        operationId: listAgentApprovalEvents
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_05_list_agent_approval_events_approvalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/events
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentApprovals
      - getAgentApproval
      - createAgentApprovalHandoff
      - getAgentApprovalHandoff
      - listAgentApprovalEvents
    x-neotask-explicit-selection-required: false
  - workflowId: enroll-and-rotate-runner
    summary: Enroll a standalone runner and rotate its credential safely.
    description: Runner enrollment returns secret material only through the reviewed
      secret-store path. Public bearer credentials never replace runner HMAC or
      reach the Gateway execution transport.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_runner_enrollment_Idempotency_Key
        - input_01_create_runner_enrollment_request
        - input_03_rotate_agent_runner_runnerId
        - input_03_rotate_agent_runner_Idempotency_Key
        - input_03_rotate_agent_runner_request
      properties:
        input_01_create_runner_enrollment_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_runner_enrollment_request:
          $ref: ./openapi.yaml#/components/schemas/AgentRunnerEnrollmentRequest
        input_03_rotate_agent_runner_runnerId:
          type: string
          minLength: 1
          maxLength: 256
        input_03_rotate_agent_runner_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_rotate_agent_runner_request:
          $ref: ./openapi.yaml#/components/schemas/AgentRunnerRotateRequest
    steps:
      - stepId: 01-create-runner-enrollment
        description: Creates a tenant-scoped runner enrollment after ordinary device
          policy and the human installation review, or the one-local-runner
          bound for an unclaimed Agent Trial.
        operationId: createRunnerEnrollment
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_runner_enrollment_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_runner_enrollment_request
        successCriteria:
          - condition: $statusCode == 201 || $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runners
        x-neotask-method: POST
        x-neotask-required-scope: neotask:runners:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 02-list-agent-runners
        description: Lists safe metadata for runners inside the tenant derived from the
          verified credential.
        operationId: listAgentRunners
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runners
        x-neotask-method: GET
        x-neotask-required-scope: neotask:runners:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-rotate-agent-runner
        description: Atomically replaces the runner HMAC credential and invalidates the
          previous generation.
        operationId: rotateAgentRunner
        parameters:
          - name: runnerId
            in: path
            value: $inputs.input_03_rotate_agent_runner_runnerId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_rotate_agent_runner_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_rotate_agent_runner_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runners/{runnerId}/rotate
        x-neotask-method: POST
        x-neotask-required-scope: neotask:runners:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - createRunnerEnrollment
      - listAgentRunners
      - rotateAgentRunner
    x-neotask-explicit-selection-required: true
  - workflowId: connect-and-manage-integration
    summary: Start provider authorization and attach the resulting connection.
    description: Use only providers, scopes, targets, and opaque human-action URLs
      returned by the Site. Provider credentials never enter workflow inputs.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_create_agent_integration_attempt_Idempotency_Key
        - input_02_create_agent_integration_attempt_request
        - input_03_get_agent_integration_attempt_attemptId
        - input_05_attach_agent_integration_connectionId
        - input_05_attach_agent_integration_Idempotency_Key
        - input_05_attach_agent_integration_request
      properties:
        input_02_create_agent_integration_attempt_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_create_agent_integration_attempt_request:
          $ref: ./openapi.yaml#/components/schemas/AgentIntegrationAttemptCreateRequest
        input_03_get_agent_integration_attempt_attemptId:
          type: string
          pattern: ^ia_[A-Za-z0-9_-]+$
        input_05_attach_agent_integration_connectionId:
          type: string
          pattern: ^ic_[A-Za-z0-9_-]+$
        input_05_attach_agent_integration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_05_attach_agent_integration_request:
          $ref: ./openapi.yaml#/components/schemas/AgentIntegrationAttachRequest
    steps:
      - stepId: 01-list-agent-integration-catalog
        description: Lists the server-reviewed integration catalog, supported
          authentication handoff types, capabilities, and eligible
          tenant/company targets.
        operationId: listAgentIntegrationCatalog
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/catalog
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-create-agent-integration-attempt
        description: Starts a reviewed provider OAuth handoff and returns an opaque,
          short-lived human-action URL while keeping provider tokens
          server-side.
        operationId: createAgentIntegrationAttempt
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_create_agent_integration_attempt_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_create_agent_integration_attempt_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/attempts
        x-neotask-method: POST
        x-neotask-required-scope: neotask:integrations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-get-agent-integration-attempt
        description: Reads the current state of a provider integration attempt owned by
          this authenticated registration.
        operationId: getAgentIntegrationAttempt
        parameters:
          - name: attemptId
            in: path
            value: $inputs.input_03_get_agent_integration_attempt_attemptId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/attempts/{attemptId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:integrations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 04-list-agent-integration-connections
        description: Lists verified provider connections in the claimed tenant or a
          company scope resolved by the server.
        operationId: listAgentIntegrationConnections
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/connections
        x-neotask-method: GET
        x-neotask-required-scope: neotask:integrations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-attach-agent-integration
        description: Attaches an existing verified connection to an agent only inside
          the server-derived tenant/company scope.
        operationId: attachAgentIntegration
        parameters:
          - name: connectionId
            in: path
            value: $inputs.input_05_attach_agent_integration_connectionId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_05_attach_agent_integration_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_05_attach_agent_integration_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/connections/{connectionId}/attach
        x-neotask-method: POST
        x-neotask-required-scope: neotask:integrations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - listAgentIntegrationCatalog
      - createAgentIntegrationAttempt
      - getAgentIntegrationAttempt
      - listAgentIntegrationConnections
      - attachAgentIntegration
    x-neotask-explicit-selection-required: false
  - workflowId: join-and-use-coordination-mail
    summary: Join company-scoped Coordination Mail and exchange one message.
    description: Mail requires a claimed account and an active, server-derived
      company membership. Keep internal relay credentials, daemon paths, and
      cross-company federation outside the public API.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_request_agent_mail_membership_Idempotency_Key
        - input_02_request_agent_mail_membership_request
        - input_03_join_agent_mail_membership_Idempotency_Key
        - input_03_join_agent_mail_membership_request
        - input_07_send_agent_mail_message_Idempotency_Key
        - input_07_send_agent_mail_message_request
      properties:
        input_02_request_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_02_request_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipRequest
        input_03_join_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_join_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipJoinRequest
        input_07_send_agent_mail_message_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_07_send_agent_mail_message_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMessageCreateRequest
    steps:
      - stepId: 01-get-agent-mail-capabilities
        description: Returns current company Mail availability and effective access for
          each Mail action.
        operationId: getAgentMailCapabilities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/capabilities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-request-agent-mail-membership
        description: Creates a pending same-company Mail membership request for the
          claimed agent.
        operationId: requestAgentMailMembership
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_02_request_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_02_request_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200 || $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership-requests
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 03-join-agent-mail-membership
        description: Activates an approved Mail membership owned by this claimed agent
          and binds its server-derived identity.
        operationId: joinAgentMailMembership
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_join_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_join_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership/join
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-get-agent-mail-membership
        description: Lists this claimed agent’s same-tenant Mail memberships and
          lifecycle states.
        operationId: getAgentMailMembership
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 05-list-agent-mail-identities
        description: Lists active agent identities inside the authenticated company
          boundary.
        operationId: listAgentMailIdentities
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/identities
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 06-list-agent-mail-peers
        description: Lists active peers that the current agent may address inside its
          company.
        operationId: listAgentMailPeers
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/peers
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 07-send-agent-mail-message
        description: Sends a bounded Markdown message to active agent recipients inside
          the authenticated company.
        operationId: sendAgentMailMessage
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_07_send_agent_mail_message_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_07_send_agent_mail_message_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/messages
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 08-list-agent-mail-inbox
        description: Lists messages delivered to the authenticated agent inside its company.
        operationId: listAgentMailInbox
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/inbox
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 09-get-agent-mail-events
        description: Returns ordered message events visible to the authenticated sender
          or recipient.
        operationId: getAgentMailEvents
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/events
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMailCapabilities
      - requestAgentMailMembership
      - joinAgentMailMembership
      - getAgentMailMembership
      - listAgentMailIdentities
      - listAgentMailPeers
      - sendAgentMailMessage
      - listAgentMailInbox
      - getAgentMailEvents
    x-neotask-explicit-selection-required: false
  - workflowId: recover-coordination-mail-delivery
    summary: Recover a Mail delivery and acknowledge it once.
    description: Read the message and delivery state through tenant-scoped
      references, then acknowledge and mark it read with separate idempotency
      keys.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_02_get_agent_mail_delivery_messageId
        - input_03_acknowledge_agent_mail_delivery_messageId
        - input_03_acknowledge_agent_mail_delivery_Idempotency_Key
        - input_03_acknowledge_agent_mail_delivery_request
        - input_04_mark_agent_mail_read_messageId
        - input_04_mark_agent_mail_read_Idempotency_Key
        - input_04_mark_agent_mail_read_request
      properties:
        input_02_get_agent_mail_delivery_messageId:
          type: string
          maxLength: 128
        input_03_acknowledge_agent_mail_delivery_messageId:
          type: string
          maxLength: 128
        input_03_acknowledge_agent_mail_delivery_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_03_acknowledge_agent_mail_delivery_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailEmptyMutationRequest
        input_04_mark_agent_mail_read_messageId:
          type: string
          maxLength: 128
        input_04_mark_agent_mail_read_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_04_mark_agent_mail_read_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailEmptyMutationRequest
    steps:
      - stepId: 01-list-agent-mail-inbox
        description: Lists messages delivered to the authenticated agent inside its company.
        operationId: listAgentMailInbox
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/inbox
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 02-get-agent-mail-delivery
        description: Returns delivery state to the sender or the authenticated recipient
          of one company message.
        operationId: getAgentMailDelivery
        parameters:
          - name: messageId
            in: path
            value: $inputs.input_02_get_agent_mail_delivery_messageId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/deliveries/{messageId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
      - stepId: 03-acknowledge-agent-mail-delivery
        description: Advances the authenticated recipient delivery to acknowledged
          without moving a later state backward.
        operationId: acknowledgeAgentMailDelivery
        parameters:
          - name: messageId
            in: path
            value: $inputs.input_03_acknowledge_agent_mail_delivery_messageId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_03_acknowledge_agent_mail_delivery_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_03_acknowledge_agent_mail_delivery_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/deliveries/{messageId}/ack
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
      - stepId: 04-mark-agent-mail-read
        description: Advances the authenticated recipient delivery to read without
          moving a later state backward.
        operationId: markAgentMailRead
        parameters:
          - name: messageId
            in: path
            value: $inputs.input_04_mark_agent_mail_read_messageId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_04_mark_agent_mail_read_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_04_mark_agent_mail_read_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/messages/{messageId}/read
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - listAgentMailInbox
      - getAgentMailDelivery
      - acknowledgeAgentMailDelivery
      - markAgentMailRead
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-companies
    summary: List authorized companies
    description: List authorized companies after claim, plan and current
      company-access checks. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    steps:
      - stepId: 01-list-agent-companies
        description: List authorized companies after claim, plan and current
          company-access checks.
        operationId: listAgentCompanies
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentCompanies
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-company
    summary: Read a company overview
    description: Read a company overview after claim, plan and current
      company-access checks. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_company_companyRef
      properties:
        input_01_get_agent_company_companyRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-agent-company
        description: Read a company overview after claim, plan and current
          company-access checks.
        operationId: getAgentCompany
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_get_agent_company_companyRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCompany
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-company-agents
    summary: List configured company agents
    description: List configured company agents after claim, plan and current
      company-access checks. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_agent_company_agents_companyRef
      properties:
        input_01_list_agent_company_agents_companyRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-list-agent-company-agents
        description: List configured company agents after claim, plan and current
          company-access checks.
        operationId: listAgentCompanyAgents
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_list_agent_company_agents_companyRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}/agents
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentCompanyAgents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-company-tasks
    summary: List company tasks
    description: List company tasks after claim, plan and current company-access
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_agent_company_tasks_companyRef
      properties:
        input_01_list_agent_company_tasks_companyRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-list-agent-company-tasks
        description: List company tasks after claim, plan and current company-access checks.
        operationId: listAgentCompanyTasks
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_list_agent_company_tasks_companyRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}/tasks
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentCompanyTasks
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-company-task
    summary: Read a company task
    description: Read a company task after claim, plan and current company-access
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_company_task_companyRef
        - input_01_get_agent_company_task_taskRef
      properties:
        input_01_get_agent_company_task_companyRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_get_agent_company_task_taskRef:
          type: string
          minLength: 1
          maxLength: 2048
    steps:
      - stepId: 01-get-agent-company-task
        description: Read a company task after claim, plan and current company-access
          checks.
        operationId: getAgentCompanyTask
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_get_agent_company_task_companyRef
          - name: taskRef
            in: path
            value: $inputs.input_01_get_agent_company_task_taskRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}/tasks/{taskRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCompanyTask
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-company-runs
    summary: List company runs
    description: List company runs after claim, plan and current company-access
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_agent_company_runs_companyRef
      properties:
        input_01_list_agent_company_runs_companyRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-list-agent-company-runs
        description: List company runs after claim, plan and current company-access checks.
        operationId: listAgentCompanyRuns
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_list_agent_company_runs_companyRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}/runs
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentCompanyRuns
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-company-run
    summary: Read a company run
    description: Read a company run after claim, plan and current company-access
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_company_run_companyRef
        - input_01_get_agent_company_run_runRef
      properties:
        input_01_get_agent_company_run_companyRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_get_agent_company_run_runRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-agent-company-run
        description: Read a company run after claim, plan and current company-access checks.
        operationId: getAgentCompanyRun
        parameters:
          - name: companyRef
            in: path
            value: $inputs.input_01_get_agent_company_run_companyRef
          - name: runRef
            in: path
            value: $inputs.input_01_get_agent_company_run_runRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/companies/{companyRef}/runs/{runRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:companies:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCompanyRun
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-insight-boards
    summary: List saved boards in the verified company boundary.
    description: List saved boards in the verified company boundary. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    steps:
      - stepId: 01-list-insight-boards
        description: List saved boards in the verified company boundary.
        operationId: listInsightBoards
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards
        x-neotask-method: GET
        x-neotask-required-scope: neotask:boards:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listInsightBoards
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-insight-board
    summary: Read one saved board in the verified company boundary.
    description: Read one saved board in the verified company boundary. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_insight_board_boardId
      properties:
        input_01_get_insight_board_boardId:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-insight-board
        description: Read one saved board in the verified company boundary.
        operationId: getInsightBoard
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_get_insight_board_boardId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:boards:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getInsightBoard
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-insight-board-publication
    summary: Read hosted publication state without a link secret.
    description: Read hosted publication state without a link secret. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_insight_board_publication_boardId
      properties:
        input_01_get_insight_board_publication_boardId:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-insight-board-publication
        description: Read hosted publication state without a link secret.
        operationId: getInsightBoardPublication
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_get_insight_board_publication_boardId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/publication
        x-neotask-method: GET
        x-neotask-required-scope: neotask:boards:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getInsightBoardPublication
    x-neotask-explicit-selection-required: false
  - workflowId: operation-publish-insight-board
    summary: Publish a saved version; public links require an exact human approval.
    description: Publish a saved version; public links require an exact human
      approval. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_publish_insight_board_boardId
        - input_01_publish_insight_board_Idempotency_Key
        - input_01_publish_insight_board_request
      properties:
        input_01_publish_insight_board_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_publish_insight_board_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_publish_insight_board_request:
          $ref: ./openapi.yaml#/components/schemas/publishInsightBoard.request.v1
    steps:
      - stepId: 01-publish-insight-board
        description: Publish a saved version; public links require an exact human approval.
        operationId: publishInsightBoard
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_publish_insight_board_boardId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_publish_insight_board_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_publish_insight_board_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/publish
        x-neotask-method: POST
        x-neotask-required-scope: neotask:boards:publish
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - publishInsightBoard
    x-neotask-explicit-selection-required: false
  - workflowId: operation-unpublish-insight-board
    summary: Unpublish the hosted board and revoke its active links.
    description: Unpublish the hosted board and revoke its active links. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_unpublish_insight_board_boardId
        - input_01_unpublish_insight_board_Idempotency_Key
        - input_01_unpublish_insight_board_request
      properties:
        input_01_unpublish_insight_board_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_unpublish_insight_board_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_unpublish_insight_board_request:
          $ref: ./openapi.yaml#/components/schemas/unpublishInsightBoard.request.v1
    steps:
      - stepId: 01-unpublish-insight-board
        description: Unpublish the hosted board and revoke its active links.
        operationId: unpublishInsightBoard
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_unpublish_insight_board_boardId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_unpublish_insight_board_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_unpublish_insight_board_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/unpublish
        x-neotask-method: POST
        x-neotask-required-scope: neotask:boards:publish
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - unpublishInsightBoard
    x-neotask-explicit-selection-required: false
  - workflowId: operation-rotate-insight-board-link
    summary: Rotate the hosted link; the new secret is returned once.
    description: Rotate the hosted link; the new secret is returned once. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_rotate_insight_board_link_boardId
        - input_01_rotate_insight_board_link_Idempotency_Key
        - input_01_rotate_insight_board_link_request
      properties:
        input_01_rotate_insight_board_link_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_rotate_insight_board_link_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_rotate_insight_board_link_request:
          $ref: ./openapi.yaml#/components/schemas/rotateInsightBoardLink.request.v1
    steps:
      - stepId: 01-rotate-insight-board-link
        description: Rotate the hosted link; the new secret is returned once.
        operationId: rotateInsightBoardLink
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_rotate_insight_board_link_boardId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_rotate_insight_board_link_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_rotate_insight_board_link_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/rotate-link
        x-neotask-method: POST
        x-neotask-required-scope: neotask:boards:publish
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - rotateInsightBoardLink
    x-neotask-explicit-selection-required: true
  - workflowId: operation-set-insight-board-visibility
    summary: Change visibility; public access requires an exact human approval.
    description: Change visibility; public access requires an exact human approval.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_set_insight_board_visibility_boardId
        - input_01_set_insight_board_visibility_Idempotency_Key
        - input_01_set_insight_board_visibility_request
      properties:
        input_01_set_insight_board_visibility_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_set_insight_board_visibility_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_set_insight_board_visibility_request:
          $ref: ./openapi.yaml#/components/schemas/setInsightBoardVisibility.request.v1
    steps:
      - stepId: 01-set-insight-board-visibility
        description: Change visibility; public access requires an exact human approval.
        operationId: setInsightBoardVisibility
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_set_insight_board_visibility_boardId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_set_insight_board_visibility_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_set_insight_board_visibility_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/visibility
        x-neotask-method: PUT
        x-neotask-required-scope: neotask:boards:share
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - setInsightBoardVisibility
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-insight-board-grants
    summary: List viewer-only grants for one board.
    description: List viewer-only grants for one board. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_insight_board_grants_boardId
      properties:
        input_01_list_insight_board_grants_boardId:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-list-insight-board-grants
        description: List viewer-only grants for one board.
        operationId: listInsightBoardGrants
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_list_insight_board_grants_boardId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/grants
        x-neotask-method: GET
        x-neotask-required-scope: neotask:boards:share
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listInsightBoardGrants
    x-neotask-explicit-selection-required: false
  - workflowId: operation-create-insight-board-grant
    summary: Create one viewer-only grant subject to publication caps.
    description: Create one viewer-only grant subject to publication caps. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_insight_board_grant_boardId
        - input_01_create_insight_board_grant_Idempotency_Key
        - input_01_create_insight_board_grant_request
      properties:
        input_01_create_insight_board_grant_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_create_insight_board_grant_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_insight_board_grant_request:
          $ref: ./openapi.yaml#/components/schemas/createInsightBoardGrant.request.v1
    steps:
      - stepId: 01-create-insight-board-grant
        description: Create one viewer-only grant subject to publication caps.
        operationId: createInsightBoardGrant
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_create_insight_board_grant_boardId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_insight_board_grant_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_insight_board_grant_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/grants
        x-neotask-method: POST
        x-neotask-required-scope: neotask:boards:share
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - createInsightBoardGrant
    x-neotask-explicit-selection-required: false
  - workflowId: operation-revoke-insight-board-grant
    summary: Revoke one grant so the next viewer request is denied.
    description: Revoke one grant so the next viewer request is denied. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_insight_board_grant_boardId
        - input_01_revoke_insight_board_grant_grantId
        - input_01_revoke_insight_board_grant_Idempotency_Key
        - input_01_revoke_insight_board_grant_request
      properties:
        input_01_revoke_insight_board_grant_boardId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_insight_board_grant_grantId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_insight_board_grant_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_insight_board_grant_request:
          $ref: ./openapi.yaml#/components/schemas/revokeInsightBoardGrant.request.v1
    steps:
      - stepId: 01-revoke-insight-board-grant
        description: Revoke one grant so the next viewer request is denied.
        operationId: revokeInsightBoardGrant
        parameters:
          - name: boardId
            in: path
            value: $inputs.input_01_revoke_insight_board_grant_boardId
          - name: grantId
            in: path
            value: $inputs.input_01_revoke_insight_board_grant_grantId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_insight_board_grant_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_insight_board_grant_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/boards/{boardId}/grants/{grantId}
        x-neotask-method: DELETE
        x-neotask-required-scope: neotask:boards:share
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeInsightBoardGrant
    x-neotask-explicit-selection-required: true
  - workflowId: operation-update-agent
    summary: Update one managed agent
    description: Updates editable managed-agent metadata after authority and scope
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_agent_agentRef
        - input_01_update_agent_Idempotency_Key
        - input_01_update_agent_request
      properties:
        input_01_update_agent_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_update_agent_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_agent_request:
          $ref: ./openapi.yaml#/components/schemas/ManagedAgentUpdateRequest
    steps:
      - stepId: 01-update-agent
        description: Updates editable managed-agent metadata after authority and scope
          checks.
        operationId: updateAgent
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_update_agent_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_agent_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_agent_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: neotask:agents:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateAgent
    x-neotask-explicit-selection-required: false
  - workflowId: operation-archive-agent
    summary: Archive a managed agent
    description: Archives a managed agent while retaining its durable history for
      restoration. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_archive_agent_agentRef
        - input_01_archive_agent_Idempotency_Key
      properties:
        input_01_archive_agent_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_archive_agent_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-archive-agent
        description: Archives a managed agent while retaining its durable history for
          restoration.
        operationId: archiveAgent
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_archive_agent_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_archive_agent_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/archive
        x-neotask-method: POST
        x-neotask-required-scope: neotask:agents:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - archiveAgent
    x-neotask-explicit-selection-required: true
  - workflowId: operation-restore-agent
    summary: Restore a managed agent
    description: Restores an archived managed agent after authority and scope
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_restore_agent_agentRef
        - input_01_restore_agent_Idempotency_Key
      properties:
        input_01_restore_agent_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_restore_agent_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-restore-agent
        description: Restores an archived managed agent after authority and scope checks.
        operationId: restoreAgent
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_restore_agent_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_restore_agent_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/restore
        x-neotask-method: POST
        x-neotask-required-scope: neotask:agents:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - restoreAgent
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-conversations
    summary: List agent conversations
    description: Lists conversations owned by the verified tenant with bounded
      pagination. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    steps:
      - stepId: 01-list-agent-conversations
        description: Lists conversations owned by the verified tenant with bounded
          pagination.
        operationId: listAgentConversations
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentConversations
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-conversation
    summary: Read an agent conversation
    description: Returns one conversation metadata record in the verified tenant.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_conversation_conversationRef
      properties:
        input_01_get_agent_conversation_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-get-agent-conversation
        description: Returns one conversation metadata record in the verified tenant.
        operationId: getAgentConversation
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_get_agent_conversation_conversationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentConversation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-archive-agent-conversation
    summary: Archive an agent conversation
    description: Archives a conversation while preserving its messages and audit
      history. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_archive_agent_conversation_conversationRef
        - input_01_archive_agent_conversation_Idempotency_Key
      properties:
        input_01_archive_agent_conversation_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_01_archive_agent_conversation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-archive-agent-conversation
        description: Archives a conversation while preserving its messages and audit
          history.
        operationId: archiveAgentConversation
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_archive_agent_conversation_conversationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_archive_agent_conversation_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/archive
        x-neotask-method: POST
        x-neotask-required-scope: neotask:conversations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - archiveAgentConversation
    x-neotask-explicit-selection-required: true
  - workflowId: operation-restore-agent-conversation
    summary: Restore an agent conversation
    description: Restores an archived conversation in the verified tenant. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_restore_agent_conversation_conversationRef
        - input_01_restore_agent_conversation_Idempotency_Key
      properties:
        input_01_restore_agent_conversation_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_01_restore_agent_conversation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-restore-agent-conversation
        description: Restores an archived conversation in the verified tenant.
        operationId: restoreAgentConversation
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_restore_agent_conversation_conversationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_restore_agent_conversation_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/restore
        x-neotask-method: POST
        x-neotask-required-scope: neotask:conversations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - restoreAgentConversation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-conversation-messages
    summary: List conversation messages
    description: Returns ordered messages from the canonical tenant message store.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_agent_conversation_messages_conversationRef
      properties:
        input_01_list_agent_conversation_messages_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-list-agent-conversation-messages
        description: Returns ordered messages from the canonical tenant message store.
        operationId: listAgentConversationMessages
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_list_agent_conversation_messages_conversationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/messages
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentConversationMessages
    x-neotask-explicit-selection-required: false
  - workflowId: operation-cancel-agent-conversation-turn
    summary: Cancel a conversation turn
    description: Records a durable cancel request for an active conversation turn.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_conversation_turn_conversationRef
        - input_01_cancel_agent_conversation_turn_turnRef
        - input_01_cancel_agent_conversation_turn_Idempotency_Key
      properties:
        input_01_cancel_agent_conversation_turn_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_01_cancel_agent_conversation_turn_turnRef:
          type: string
          minLength: 1
          maxLength: 200
        input_01_cancel_agent_conversation_turn_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-cancel-agent-conversation-turn
        description: Records a durable cancel request for an active conversation turn.
        operationId: cancelAgentConversationTurn
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_cancel_agent_conversation_turn_conversationRef
          - name: turnRef
            in: path
            value: $inputs.input_01_cancel_agent_conversation_turn_turnRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_conversation_turn_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/turns/{turnRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:conversations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentConversationTurn
    x-neotask-explicit-selection-required: true
  - workflowId: operation-stream-agent-conversation-turn-events
    summary: Stream conversation turn events
    description: Returns a finite SSE replay for one conversation turn and closes
      after the current event page. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_stream_agent_conversation_turn_events_conversationRef
        - input_01_stream_agent_conversation_turn_events_turnRef
      properties:
        input_01_stream_agent_conversation_turn_events_conversationRef:
          type: string
          minLength: 1
          maxLength: 200
        input_01_stream_agent_conversation_turn_events_turnRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-stream-agent-conversation-turn-events
        description: Returns a finite SSE replay for one conversation turn and closes
          after the current event page.
        operationId: streamAgentConversationTurnEvents
        parameters:
          - name: conversationRef
            in: path
            value: $inputs.input_01_stream_agent_conversation_turn_events_conversationRef
          - name: turnRef
            in: path
            value: $inputs.input_01_stream_agent_conversation_turn_events_turnRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/conversations/{conversationRef}/turns/{turnRef}/events/stream
        x-neotask-method: GET
        x-neotask-required-scope: neotask:conversations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - streamAgentConversationTurnEvents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-agent-cron-job
    summary: Update a cron schedule
    description: Updates the name, expression, timezone, or enabled state of a
      tenant-scoped schedule. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_agent_cron_job_cronJobRef
        - input_01_update_agent_cron_job_Idempotency_Key
        - input_01_update_agent_cron_job_request
      properties:
        input_01_update_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_01_update_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronJobUpdateRequest
    steps:
      - stepId: 01-update-agent-cron-job
        description: Updates the name, expression, timezone, or enabled state of a
          tenant-scoped schedule.
        operationId: updateAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_01_update_agent_cron_job_cronJobRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: neotask:cron:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateAgentCronJob
    x-neotask-explicit-selection-required: false
  - workflowId: operation-delete-agent-cron-job
    summary: Delete a cron schedule
    description: Deletes a tenant-scoped cron schedule and detaches its task
      schedule fields. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_delete_agent_cron_job_cronJobRef
        - input_01_delete_agent_cron_job_Idempotency_Key
        - input_01_delete_agent_cron_job_request
      properties:
        input_01_delete_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_01_delete_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_delete_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronJobDeleteRequest
    steps:
      - stepId: 01-delete-agent-cron-job
        description: Deletes a tenant-scoped cron schedule and detaches its task
          schedule fields.
        operationId: deleteAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_01_delete_agent_cron_job_cronJobRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_delete_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_delete_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}
        x-neotask-method: DELETE
        x-neotask-required-scope: neotask:cron:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - deleteAgentCronJob
    x-neotask-explicit-selection-required: true
  - workflowId: operation-enable-agent-cron-job
    summary: Enable a cron schedule
    description: Enables an existing tenant-scoped cron schedule. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_enable_agent_cron_job_cronJobRef
        - input_01_enable_agent_cron_job_Idempotency_Key
        - input_01_enable_agent_cron_job_request
      properties:
        input_01_enable_agent_cron_job_cronJobRef:
          type: string
          minLength: 1
          maxLength: 128
        input_01_enable_agent_cron_job_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_enable_agent_cron_job_request:
          $ref: ./openapi.yaml#/components/schemas/AgentCronJobEnableRequest
    steps:
      - stepId: 01-enable-agent-cron-job
        description: Enables an existing tenant-scoped cron schedule.
        operationId: enableAgentCronJob
        parameters:
          - name: cronJobRef
            in: path
            value: $inputs.input_01_enable_agent_cron_job_cronJobRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_enable_agent_cron_job_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_enable_agent_cron_job_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/cron/{cronJobRef}/enable
        x-neotask-method: POST
        x-neotask-required-scope: neotask:cron:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - enableAgentCronJob
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-automations
    summary: List Task Flows and automations
    description: Lists active or paused Task Flows and automations owned by the
      verified claimed tenant. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    steps:
      - stepId: 01-list-agent-automations
        description: Lists active or paused Task Flows and automations owned by the
          verified claimed tenant.
        operationId: listAgentAutomations
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows
        x-neotask-method: GET
        x-neotask-required-scope: neotask:automations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentAutomations
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-automation
    summary: Read one Task Flow or automation
    description: Returns one tenant-scoped Task Flow or automation and its most
      recent run projection. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_automation_automationRef
      properties:
        input_01_get_agent_automation_automationRef:
          type: string
          maxLength: 128
    steps:
      - stepId: 01-get-agent-automation
        description: Returns one tenant-scoped Task Flow or automation and its most
          recent run projection.
        operationId: getAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_01_get_agent_automation_automationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:automations:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentAutomation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-agent-automation
    summary: Update a Task Flow or automation
    description: Updates a bounded automation definition using optimistic revision
      fencing. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_agent_automation_automationRef
        - input_01_update_agent_automation_Idempotency_Key
        - input_01_update_agent_automation_request
      properties:
        input_01_update_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_01_update_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationUpdateRequest
    steps:
      - stepId: 01-update-agent-automation
        description: Updates a bounded automation definition using optimistic revision
          fencing.
        operationId: updateAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_01_update_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_agent_automation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateAgentAutomation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-delete-agent-automation
    summary: Archive a Task Flow or automation
    description: Archives a tenant-scoped automation while retaining its task and
      run history. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_delete_agent_automation_automationRef
        - input_01_delete_agent_automation_Idempotency_Key
        - input_01_delete_agent_automation_request
      properties:
        input_01_delete_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_01_delete_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_delete_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationRevisionRequest
    steps:
      - stepId: 01-delete-agent-automation
        description: Archives a tenant-scoped automation while retaining its task and
          run history.
        operationId: deleteAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_01_delete_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_delete_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_delete_agent_automation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}
        x-neotask-method: DELETE
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - deleteAgentAutomation
    x-neotask-explicit-selection-required: true
  - workflowId: operation-cancel-agent-automation
    summary: Cancel an active automation run
    description: Cancels the current non-terminal run through the Site-owned tenant
      and principal fence. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_automation_automationRef
        - input_01_cancel_agent_automation_Idempotency_Key
        - input_01_cancel_agent_automation_request
      properties:
        input_01_cancel_agent_automation_automationRef:
          type: string
          maxLength: 128
        input_01_cancel_agent_automation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_cancel_agent_automation_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutomationRevisionRequest
    steps:
      - stepId: 01-cancel-agent-automation
        description: Cancels the current non-terminal run through the Site-owned tenant
          and principal fence.
        operationId: cancelAgentAutomation
        parameters:
          - name: automationRef
            in: path
            value: $inputs.input_01_cancel_agent_automation_automationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_automation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_agent_automation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/automations/flows/{automationRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:automations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentAutomation
    x-neotask-explicit-selection-required: true
  - workflowId: operation-stream-agent-run-events
    summary: Stream run events
    description: Returns a finite SSE replay for one standalone-agent run and closes
      after the current event page. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_stream_agent_run_events_runRef
      properties:
        input_01_stream_agent_run_events_runRef:
          type: string
          minLength: 1
          maxLength: 200
    steps:
      - stepId: 01-stream-agent-run-events
        description: Returns a finite SSE replay for one standalone-agent run and closes
          after the current event page.
        operationId: streamAgentRunEvents
        parameters:
          - name: runRef
            in: path
            value: $inputs.input_01_stream_agent_run_events_runRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runs/{runRef}/events/stream
        x-neotask-method: GET
        x-neotask-required-scope: neotask:runs:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - streamAgentRunEvents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-autonomy-goals
    summary: List autonomy goals
    description: Lists company-scoped autonomy goals after the verified claim and
      ordinary auto_companies plan checks. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    steps:
      - stepId: 01-list-agent-autonomy-goals
        description: Lists company-scoped autonomy goals after the verified claim and
          ordinary auto_companies plan checks.
        operationId: listAgentAutonomyGoals
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals
        x-neotask-method: GET
        x-neotask-required-scope: neotask:autonomy:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentAutonomyGoals
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-autonomy-goal
    summary: Read an autonomy goal
    description: Returns one company-scoped autonomy goal for the verified tenant.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_autonomy_goal_goalRef
      properties:
        input_01_get_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
    steps:
      - stepId: 01-get-agent-autonomy-goal
        description: Returns one company-scoped autonomy goal for the verified tenant.
        operationId: getAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_01_get_agent_autonomy_goal_goalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:autonomy:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentAutonomyGoal
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-agent-autonomy-goal
    summary: Update an autonomy goal
    description: Updates editable fields on a company-scoped autonomy goal with
      optimistic state checks. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_agent_autonomy_goal_goalRef
        - input_01_update_agent_autonomy_goal_Idempotency_Key
        - input_01_update_agent_autonomy_goal_request
      properties:
        input_01_update_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_01_update_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAutonomyGoalUpdateRequest
    steps:
      - stepId: 01-update-agent-autonomy-goal
        description: Updates editable fields on a company-scoped autonomy goal with
          optimistic state checks.
        operationId: updateAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_01_update_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateAgentAutonomyGoal
    x-neotask-explicit-selection-required: false
  - workflowId: operation-cancel-agent-autonomy-goal
    summary: Cancel an autonomy goal
    description: Cancels an autonomy goal and its active run through the trusted
      runner control owner. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_autonomy_goal_goalRef
        - input_01_cancel_agent_autonomy_goal_Idempotency_Key
        - input_01_cancel_agent_autonomy_goal_request
      properties:
        input_01_cancel_agent_autonomy_goal_goalRef:
          type: string
          minLength: 1
          maxLength: 128
        input_01_cancel_agent_autonomy_goal_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_cancel_agent_autonomy_goal_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
    steps:
      - stepId: 01-cancel-agent-autonomy-goal
        description: Cancels an autonomy goal and its active run through the trusted
          runner control owner.
        operationId: cancelAgentAutonomyGoal
        parameters:
          - name: goalRef
            in: path
            value: $inputs.input_01_cancel_agent_autonomy_goal_goalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_autonomy_goal_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_agent_autonomy_goal_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/autonomy/goals/{goalRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:autonomy:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentAutonomyGoal
    x-neotask-explicit-selection-required: true
  - workflowId: operation-cancel-agent-approval-handoff
    summary: Cancel a human approval handoff
    description: Cancels a pending approval handoff without changing the underlying
      approval request. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_approval_handoff_approvalRef
        - input_01_cancel_agent_approval_handoff_handoffRef
        - input_01_cancel_agent_approval_handoff_Idempotency_Key
        - input_01_cancel_agent_approval_handoff_request
      properties:
        input_01_cancel_agent_approval_handoff_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_cancel_agent_approval_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_cancel_agent_approval_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_cancel_agent_approval_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentApprovalHandoffCancelRequest
    steps:
      - stepId: 01-cancel-agent-approval-handoff
        description: Cancels a pending approval handoff without changing the underlying
          approval request.
        operationId: cancelAgentApprovalHandoff
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_cancel_agent_approval_handoff_approvalRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_cancel_agent_approval_handoff_handoffRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_approval_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_agent_approval_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/human-handoffs/{handoffRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:approvals:handoff
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentApprovalHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: operation-stream-agent-approval-events
    summary: Stream approval events
    description: Streams the same ordered approval event projection over SSE;
      reconnect with Last-Event-ID in the same cursor namespace. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_stream_agent_approval_events_approvalRef
      properties:
        input_01_stream_agent_approval_events_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-stream-agent-approval-events
        description: Streams the same ordered approval event projection over SSE;
          reconnect with Last-Event-ID in the same cursor namespace.
        operationId: streamAgentApprovalEvents
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_stream_agent_approval_events_approvalRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/events/stream
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - streamAgentApprovalEvents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-effective-agent-approval-policy
    summary: Read effective approval policy
    description: Returns the tenant default, per-agent override, exact deterministic
      rules, revisions, and immutable human-only hard gates. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_effective_agent_approval_policy_agentRef
      properties:
        input_01_get_effective_agent_approval_policy_agentRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-effective-agent-approval-policy
        description: Returns the tenant default, per-agent override, exact deterministic
          rules, revisions, and immutable human-only hard gates.
        operationId: getEffectiveAgentApprovalPolicy
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_get_effective_agent_approval_policy_agentRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/approval-policy
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getEffectiveAgentApprovalPolicy
    x-neotask-explicit-selection-required: false
  - workflowId: operation-create-agent-approval-settings-handoff
    summary: Request a human approval-settings change
    description: Creates an opaque, short-lived URL that a claimed agent can relay
      to its human. The URL carries no authority and the human must apply any
      change through the signed-in settings surface. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_agent_approval_settings_handoff_agentRef
        - input_01_create_agent_approval_settings_handoff_Idempotency_Key
        - input_01_create_agent_approval_settings_handoff_request
      properties:
        input_01_create_agent_approval_settings_handoff_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_create_agent_approval_settings_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_agent_approval_settings_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentApprovalSettingsHandoffRequest
    steps:
      - stepId: 01-create-agent-approval-settings-handoff
        description: Creates an opaque, short-lived URL that a claimed agent can relay
          to its human. The URL carries no authority and the human must apply
          any change through the signed-in settings surface.
        operationId: createAgentApprovalSettingsHandoff
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_create_agent_approval_settings_handoff_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_agent_approval_settings_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_agent_approval_settings_handoff_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/approval-settings-handoffs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:approvals:handoff
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - createAgentApprovalSettingsHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-approval-settings-handoff
    summary: Read a human approval-settings handoff
    description: Returns the status of an opaque settings handoff created by this
      claimed principal. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_approval_settings_handoff_agentRef
        - input_01_get_agent_approval_settings_handoff_handoffRef
      properties:
        input_01_get_agent_approval_settings_handoff_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_get_agent_approval_settings_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
    steps:
      - stepId: 01-get-agent-approval-settings-handoff
        description: Returns the status of an opaque settings handoff created by this
          claimed principal.
        operationId: getAgentApprovalSettingsHandoff
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_get_agent_approval_settings_handoff_agentRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_get_agent_approval_settings_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/approval-settings-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:approvals:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentApprovalSettingsHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-cancel-agent-approval-settings-handoff
    summary: Cancel a human approval-settings handoff
    description: Cancels a pending opaque settings handoff before the human applies
      it. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_approval_settings_handoff_agentRef
        - input_01_cancel_agent_approval_settings_handoff_handoffRef
        - input_01_cancel_agent_approval_settings_handoff_Idempotency_Key
      properties:
        input_01_cancel_agent_approval_settings_handoff_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_cancel_agent_approval_settings_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_cancel_agent_approval_settings_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
    steps:
      - stepId: 01-cancel-agent-approval-settings-handoff
        description: Cancels a pending opaque settings handoff before the human applies it.
        operationId: cancelAgentApprovalSettingsHandoff
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_cancel_agent_approval_settings_handoff_agentRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_cancel_agent_approval_settings_handoff_handoffRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_approval_settings_handoff_Idempotency_Key
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/agents/{agentRef}/approval-settings-handoffs/{handoffRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:approvals:handoff
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentApprovalSettingsHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: operation-decide-agent-approval
    summary: Decide an eligible agent approval
    description: Records an approve or deny decision only when the current policy
      and an exact, finite human-created delegation authorize this principal,
      operation, tool, normalized arguments, scope, revision, and remaining use.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_decide_agent_approval_approvalRef
        - input_01_decide_agent_approval_Idempotency_Key
        - input_01_decide_agent_approval_request
      properties:
        input_01_decide_agent_approval_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_decide_agent_approval_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_decide_agent_approval_request:
          $ref: ./openapi.yaml#/components/schemas/AgentApprovalDecisionRequest
    steps:
      - stepId: 01-decide-agent-approval
        description: Records an approve or deny decision only when the current policy
          and an exact, finite human-created delegation authorize this
          principal, operation, tool, normalized arguments, scope, revision, and
          remaining use.
        operationId: decideAgentApproval
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_decide_agent_approval_approvalRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_decide_agent_approval_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_decide_agent_approval_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/approvals/{approvalRef}/decisions
        x-neotask-method: POST
        x-neotask-required-scope: neotask:approvals:decide
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - decideAgentApproval
    x-neotask-explicit-selection-required: true
  - workflowId: operation-get-usage
    summary: Read current plan usage
    description: Returns the ordinary account message allowance and current usage.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    steps:
      - stepId: 01-get-usage
        description: Returns the ordinary account message allowance and current usage.
        operationId: getUsage
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/usage
        x-neotask-method: GET
        x-neotask-required-scope: neotask:usage:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getUsage
    x-neotask-explicit-selection-required: false
  - workflowId: operation-request-agent-skill-configuration
    summary: Request human skill configuration
    description: Returns a pending human-action request describing missing skill
      configuration without accepting secret values from the agent. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_request_agent_skill_configuration_skillId
        - input_01_request_agent_skill_configuration_Idempotency_Key
        - input_01_request_agent_skill_configuration_request
      properties:
        input_01_request_agent_skill_configuration_skillId:
          type: string
          pattern: ^[A-Za-z0-9][A-Za-z0-9._-]*$
        input_01_request_agent_skill_configuration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_request_agent_skill_configuration_request:
          $ref: ./openapi.yaml#/components/schemas/AgentSkillConfigurationRequest
    steps:
      - stepId: 01-request-agent-skill-configuration
        description: Returns a pending human-action request describing missing skill
          configuration without accepting secret values from the agent.
        operationId: requestAgentSkillConfiguration
        parameters:
          - name: skillId
            in: path
            value: $inputs.input_01_request_agent_skill_configuration_skillId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_request_agent_skill_configuration_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_request_agent_skill_configuration_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/skills/{skillId}/configure
        x-neotask-method: POST
        x-neotask-required-scope: neotask:skills:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - requestAgentSkillConfiguration
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-mcp-catalog
    summary: List the reviewed MCP catalog
    description: Returns reviewed MCP providers and safe tool metadata for the
      authenticated agent. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    steps:
      - stepId: 01-get-agent-mcp-catalog
        description: Returns reviewed MCP providers and safe tool metadata for the
          authenticated agent.
        operationId: getAgentMcpCatalog
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mcp/catalog
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMcpCatalog
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-cli-metadata
    summary: Read agent CLI metadata
    description: Returns the CLI contract, authentication audiences, safe command
      metadata, and truthful signed-distribution status. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    steps:
      - stepId: 01-get-agent-cli-metadata
        description: Returns the CLI contract, authentication audiences, safe command
          metadata, and truthful signed-distribution status.
        operationId: getAgentCliMetadata
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/cli
        x-neotask-method: GET
        x-neotask-required-scope: neotask:catalog:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentCliMetadata
    x-neotask-explicit-selection-required: false
  - workflowId: operation-approve-agent-mail-membership
    summary: Approve a company Mail membership
    description: Records an account owner or administrator approval for a pending
      same-company Mail membership. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_approve_agent_mail_membership_membershipId
        - input_01_approve_agent_mail_membership_Idempotency_Key
        - input_01_approve_agent_mail_membership_request
      properties:
        input_01_approve_agent_mail_membership_membershipId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_approve_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_approve_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipMutationRequest
    steps:
      - stepId: 01-approve-agent-mail-membership
        description: Records an account owner or administrator approval for a pending
          same-company Mail membership.
        operationId: approveAgentMailMembership
        parameters:
          - name: membershipId
            in: path
            value: $inputs.input_01_approve_agent_mail_membership_membershipId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_approve_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_approve_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership/{membershipId}/approve
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - approveAgentMailMembership
    x-neotask-explicit-selection-required: true
  - workflowId: operation-suspend-agent-mail-membership
    summary: Suspend a company Mail membership
    description: Suspends a same-company Mail membership and deactivates its public
      identity without deleting history. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_suspend_agent_mail_membership_membershipId
        - input_01_suspend_agent_mail_membership_Idempotency_Key
        - input_01_suspend_agent_mail_membership_request
      properties:
        input_01_suspend_agent_mail_membership_membershipId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_suspend_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_suspend_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipMutationRequest
    steps:
      - stepId: 01-suspend-agent-mail-membership
        description: Suspends a same-company Mail membership and deactivates its public
          identity without deleting history.
        operationId: suspendAgentMailMembership
        parameters:
          - name: membershipId
            in: path
            value: $inputs.input_01_suspend_agent_mail_membership_membershipId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_suspend_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_suspend_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership/{membershipId}/suspend
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - suspendAgentMailMembership
    x-neotask-explicit-selection-required: true
  - workflowId: operation-leave-agent-mail-membership
    summary: Leave a company Mail membership
    description: Ends this claimed agent’s same-company Mail membership and future
      delivery while preserving audit history. This one-step workflow exists so
      the mounted operation retains executable Arazzo coverage without placing
      it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_leave_agent_mail_membership_Idempotency_Key
        - input_01_leave_agent_mail_membership_request
      properties:
        input_01_leave_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_leave_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipLeaveRequest
    steps:
      - stepId: 01-leave-agent-mail-membership
        description: Ends this claimed agent’s same-company Mail membership and future
          delivery while preserving audit history.
        operationId: leaveAgentMailMembership
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_leave_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_leave_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership/leave
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - leaveAgentMailMembership
    x-neotask-explicit-selection-required: true
  - workflowId: operation-revoke-agent-mail-membership
    summary: Revoke a company Mail membership
    description: Revokes a same-company Mail membership as an account owner or
      administrator. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_agent_mail_membership_membershipId
        - input_01_revoke_agent_mail_membership_Idempotency_Key
        - input_01_revoke_agent_mail_membership_request
      properties:
        input_01_revoke_agent_mail_membership_membershipId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_agent_mail_membership_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_agent_mail_membership_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailMembershipMutationRequest
    steps:
      - stepId: 01-revoke-agent-mail-membership
        description: Revokes a same-company Mail membership as an account owner or
          administrator.
        operationId: revokeAgentMailMembership
        parameters:
          - name: membershipId
            in: path
            value: $inputs.input_01_revoke_agent_mail_membership_membershipId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_agent_mail_membership_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_agent_mail_membership_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/membership/{membershipId}/revoke
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeAgentMailMembership
    x-neotask-explicit-selection-required: true
  - workflowId: operation-get-agent-mail-identity
    summary: Read the current Mail identity
    description: Returns the server-derived Mail identity and company for the
      authenticated agent. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    steps:
      - stepId: 01-get-agent-mail-identity
        description: Returns the server-derived Mail identity and company for the
          authenticated agent.
        operationId: getAgentMailIdentity
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/identities/self
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMailIdentity
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-mail-peer
    summary: Read an addressable Mail peer
    description: Reads one active peer only inside the authenticated company. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_mail_peer_peerId
      properties:
        input_01_get_agent_mail_peer_peerId:
          type: string
          maxLength: 256
    steps:
      - stepId: 01-get-agent-mail-peer
        description: Reads one active peer only inside the authenticated company.
        operationId: getAgentMailPeer
        parameters:
          - name: peerId
            in: path
            value: $inputs.input_01_get_agent_mail_peer_peerId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/peers/{peerId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMailPeer
    x-neotask-explicit-selection-required: false
  - workflowId: operation-reply-agent-mail-message
    summary: Reply to a company Mail message
    description: Replies inside an existing thread after the server verifies that
      the agent is a participant. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_reply_agent_mail_message_messageId
        - input_01_reply_agent_mail_message_Idempotency_Key
        - input_01_reply_agent_mail_message_request
      properties:
        input_01_reply_agent_mail_message_messageId:
          type: string
          maxLength: 128
        input_01_reply_agent_mail_message_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_reply_agent_mail_message_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailReplyRequest
    steps:
      - stepId: 01-reply-agent-mail-message
        description: Replies inside an existing thread after the server verifies that
          the agent is a participant.
        operationId: replyAgentMailMessage
        parameters:
          - name: messageId
            in: path
            value: $inputs.input_01_reply_agent_mail_message_messageId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_reply_agent_mail_message_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_reply_agent_mail_message_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/messages/{messageId}/reply
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - replyAgentMailMessage
    x-neotask-explicit-selection-required: false
  - workflowId: operation-cancel-agent-account-pairing-handoff
    summary: Cancel a human account pairing handoff
    description: Cancels a pending pairing handoff before a human can confirm it.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_account_pairing_handoff_handoffRef
        - input_01_cancel_agent_account_pairing_handoff_Idempotency_Key
        - input_01_cancel_agent_account_pairing_handoff_request
      properties:
        input_01_cancel_agent_account_pairing_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_cancel_agent_account_pairing_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_cancel_agent_account_pairing_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentAccountPairingHandoffCancelRequest
    steps:
      - stepId: 01-cancel-agent-account-pairing-handoff
        description: Cancels a pending pairing handoff before a human can confirm it.
        operationId: cancelAgentAccountPairingHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_01_cancel_agent_account_pairing_handoff_handoffRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_account_pairing_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_agent_account_pairing_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/account/pairing-handoffs/{handoffRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:account:pair
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentAccountPairingHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: operation-revoke-agent-runner
    summary: Revoke an enrolled runner
    description: Revokes a runner after current HMAC and account security approval
      checks. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_agent_runner_runnerId
        - input_01_revoke_agent_runner_Idempotency_Key
        - input_01_revoke_agent_runner_request
      properties:
        input_01_revoke_agent_runner_runnerId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_agent_runner_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_agent_runner_request:
          $ref: ./openapi.yaml#/components/schemas/AgentRunnerRevokeRequest
    steps:
      - stepId: 01-revoke-agent-runner
        description: Revokes a runner after current HMAC and account security approval
          checks.
        operationId: revokeAgentRunner
        parameters:
          - name: runnerId
            in: path
            value: $inputs.input_01_revoke_agent_runner_runnerId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_agent_runner_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_agent_runner_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/runners/{runnerId}
        x-neotask-method: DELETE
        x-neotask-required-scope: neotask:runners:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeAgentRunner
    x-neotask-explicit-selection-required: true
  - workflowId: operation-cancel-agent-integration-attempt
    summary: Cancel a provider integration attempt
    description: Cancels a pending provider integration attempt and fences stale
      OAuth callbacks. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_agent_integration_attempt_attemptId
        - input_01_cancel_agent_integration_attempt_Idempotency_Key
        - input_01_cancel_agent_integration_attempt_request
      properties:
        input_01_cancel_agent_integration_attempt_attemptId:
          type: string
          pattern: ^ia_[A-Za-z0-9_-]+$
        input_01_cancel_agent_integration_attempt_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_cancel_agent_integration_attempt_request:
          $ref: ./openapi.yaml#/components/schemas/AgentIntegrationAttemptCancelRequest
    steps:
      - stepId: 01-cancel-agent-integration-attempt
        description: Cancels a pending provider integration attempt and fences stale
          OAuth callbacks.
        operationId: cancelAgentIntegrationAttempt
        parameters:
          - name: attemptId
            in: path
            value: $inputs.input_01_cancel_agent_integration_attempt_attemptId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_cancel_agent_integration_attempt_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_agent_integration_attempt_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/attempts/{attemptId}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: neotask:integrations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - cancelAgentIntegrationAttempt
    x-neotask-explicit-selection-required: true
  - workflowId: operation-detach-agent-integration
    summary: Detach a verified integration
    description: Detaches a connection from an agent while retaining the
      tenant-scoped audit record and encrypted provider state. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_detach_agent_integration_connectionId
        - input_01_detach_agent_integration_Idempotency_Key
        - input_01_detach_agent_integration_request
      properties:
        input_01_detach_agent_integration_connectionId:
          type: string
          pattern: ^ic_[A-Za-z0-9_-]+$
        input_01_detach_agent_integration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_detach_agent_integration_request:
          $ref: ./openapi.yaml#/components/schemas/AgentIntegrationDetachRequest
    steps:
      - stepId: 01-detach-agent-integration
        description: Detaches a connection from an agent while retaining the
          tenant-scoped audit record and encrypted provider state.
        operationId: detachAgentIntegration
        parameters:
          - name: connectionId
            in: path
            value: $inputs.input_01_detach_agent_integration_connectionId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_detach_agent_integration_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_detach_agent_integration_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/connections/{connectionId}/detach
        x-neotask-method: POST
        x-neotask-required-scope: neotask:integrations:write
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - detachAgentIntegration
    x-neotask-explicit-selection-required: true
  - workflowId: operation-revoke-agent-integration
    summary: Revoke a verified integration
    description: Revokes a verified provider connection only after the existing
      human account-security approval authority grants the action. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_agent_integration_connectionId
        - input_01_revoke_agent_integration_Idempotency_Key
        - input_01_revoke_agent_integration_request
      properties:
        input_01_revoke_agent_integration_connectionId:
          type: string
          pattern: ^ic_[A-Za-z0-9_-]+$
        input_01_revoke_agent_integration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_agent_integration_request:
          $ref: ./openapi.yaml#/components/schemas/AgentIntegrationRevokeRequest
    steps:
      - stepId: 01-revoke-agent-integration
        description: Revokes a verified provider connection only after the existing
          human account-security approval authority grants the action.
        operationId: revokeAgentIntegration
        parameters:
          - name: connectionId
            in: path
            value: $inputs.input_01_revoke_agent_integration_connectionId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_agent_integration_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_agent_integration_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/integrations/connections/{connectionId}/revoke
        x-neotask-method: POST
        x-neotask-required-scope: neotask:integrations:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeAgentIntegration
    x-neotask-explicit-selection-required: true
  - workflowId: operation-get-agent-mail-thread
    summary: Read a Mail thread
    description: Returns one participant-authorized company Mail thread and its
      ordered messages. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_mail_thread_threadId
      properties:
        input_01_get_agent_mail_thread_threadId:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-agent-mail-thread
        description: Returns one participant-authorized company Mail thread and its
          ordered messages.
        operationId: getAgentMailThread
        parameters:
          - name: threadId
            in: path
            value: $inputs.input_01_get_agent_mail_thread_threadId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/threads/{threadId}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMailThread
    x-neotask-explicit-selection-required: false
  - workflowId: operation-search-agent-mail-threads
    summary: Search Mail threads
    description: Searches subject and body text within the verified company Mail
      boundary. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_search_agent_mail_threads_request
      properties:
        input_01_search_agent_mail_threads_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailThreadSearchRequest
    steps:
      - stepId: 01-search-agent-mail-threads
        description: Searches subject and body text within the verified company Mail
          boundary.
        operationId: searchAgentMailThreads
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_search_agent_mail_threads_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/threads/search
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - searchAgentMailThreads
    x-neotask-explicit-selection-required: false
  - workflowId: operation-summarize-agent-mail-thread
    summary: Summarize a Mail thread
    description: Returns a deterministic bounded summary from a participant-visible
      thread without a hidden model call. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_summarize_agent_mail_thread_threadId
        - input_01_summarize_agent_mail_thread_request
      properties:
        input_01_summarize_agent_mail_thread_threadId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_summarize_agent_mail_thread_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailThreadSummaryRequest
    steps:
      - stepId: 01-summarize-agent-mail-thread
        description: Returns a deterministic bounded summary from a participant-visible
          thread without a hidden model call.
        operationId: summarizeAgentMailThread
        parameters:
          - name: threadId
            in: path
            value: $inputs.input_01_summarize_agent_mail_thread_threadId
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_summarize_agent_mail_thread_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/threads/{threadId}/summarize
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - summarizeAgentMailThread
    x-neotask-explicit-selection-required: false
  - workflowId: operation-request-agent-mail-contact
    summary: Request Mail contact
    description: Creates a same-company contact request for an active agent. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_request_agent_mail_contact_Idempotency_Key
        - input_01_request_agent_mail_contact_request
      properties:
        input_01_request_agent_mail_contact_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_request_agent_mail_contact_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailContactRequest
    steps:
      - stepId: 01-request-agent-mail-contact
        description: Creates a same-company contact request for an active agent.
        operationId: requestAgentMailContact
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_request_agent_mail_contact_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_request_agent_mail_contact_request
        successCriteria:
          - condition: $statusCode == 200 || $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/contacts/requests
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:contacts
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - requestAgentMailContact
    x-neotask-explicit-selection-required: false
  - workflowId: operation-respond-agent-mail-contact
    summary: Respond to a Mail contact request
    description: Accepts or denies a pending same-company contact request. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_respond_agent_mail_contact_contactId
        - input_01_respond_agent_mail_contact_Idempotency_Key
        - input_01_respond_agent_mail_contact_request
      properties:
        input_01_respond_agent_mail_contact_contactId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_respond_agent_mail_contact_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_respond_agent_mail_contact_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailContactResponseRequest
    steps:
      - stepId: 01-respond-agent-mail-contact
        description: Accepts or denies a pending same-company contact request.
        operationId: respondAgentMailContact
        parameters:
          - name: contactId
            in: path
            value: $inputs.input_01_respond_agent_mail_contact_contactId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_respond_agent_mail_contact_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_respond_agent_mail_contact_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/contacts/{contactId}/respond
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:contacts
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - respondAgentMailContact
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-mail-contacts
    summary: List Mail contacts
    description: Lists same-company contact requests visible to the authenticated
      agent. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    steps:
      - stepId: 01-list-agent-mail-contacts
        description: Lists same-company contact requests visible to the authenticated agent.
        operationId: listAgentMailContacts
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/contacts
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:contacts
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentMailContacts
    x-neotask-explicit-selection-required: false
  - workflowId: operation-set-agent-mail-contact-policy
    summary: Set Mail contact policy
    description: Sets the account-security-controlled contact policy for the
      verified company. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_set_agent_mail_contact_policy_Idempotency_Key
        - input_01_set_agent_mail_contact_policy_request
      properties:
        input_01_set_agent_mail_contact_policy_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_set_agent_mail_contact_policy_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailContactPolicyRequest
    steps:
      - stepId: 01-set-agent-mail-contact-policy
        description: Sets the account-security-controlled contact policy for the
          verified company.
        operationId: setAgentMailContactPolicy
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_set_agent_mail_contact_policy_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_set_agent_mail_contact_policy_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/contacts/policy
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:contacts
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - setAgentMailContactPolicy
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-agent-mail-sectors
    summary: List Mail sectors
    description: Lists company-scoped coordination Mail sectors. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    steps:
      - stepId: 01-list-agent-mail-sectors
        description: Lists company-scoped coordination Mail sectors.
        operationId: listAgentMailSectors
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/sectors
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:sectors
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listAgentMailSectors
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-agent-mail-sector-feed
    summary: Read a Mail sector feed
    description: Returns messages addressed to one company-scoped Mail sector. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_agent_mail_sector_feed_sectorId
      properties:
        input_01_get_agent_mail_sector_feed_sectorId:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-agent-mail-sector-feed
        description: Returns messages addressed to one company-scoped Mail sector.
        operationId: getAgentMailSectorFeed
        parameters:
          - name: sectorId
            in: path
            value: $inputs.input_01_get_agent_mail_sector_feed_sectorId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/sectors/{sectorId}/feed
        x-neotask-method: GET
        x-neotask-required-scope: neotask:mail:sectors
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getAgentMailSectorFeed
    x-neotask-explicit-selection-required: false
  - workflowId: operation-broadcast-agent-mail-sector
    summary: Broadcast to a Mail sector
    description: Sends a bounded message to active members of a company Mail sector.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_broadcast_agent_mail_sector_sectorId
        - input_01_broadcast_agent_mail_sector_Idempotency_Key
        - input_01_broadcast_agent_mail_sector_request
      properties:
        input_01_broadcast_agent_mail_sector_sectorId:
          type: string
          minLength: 1
          maxLength: 256
        input_01_broadcast_agent_mail_sector_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_broadcast_agent_mail_sector_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailSectorBroadcastRequest
    steps:
      - stepId: 01-broadcast-agent-mail-sector
        description: Sends a bounded message to active members of a company Mail sector.
        operationId: broadcastAgentMailSector
        parameters:
          - name: sectorId
            in: path
            value: $inputs.input_01_broadcast_agent_mail_sector_sectorId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_broadcast_agent_mail_sector_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_broadcast_agent_mail_sector_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/sectors/{sectorId}/broadcast
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:sectors
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - broadcastAgentMailSector
    x-neotask-explicit-selection-required: false
  - workflowId: operation-announce-agent-mail-handoff
    summary: Announce a Mail handoff
    description: Stores a durable task, run, or goal-linked handoff announcement for
      an approved company audience. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_announce_agent_mail_handoff_Idempotency_Key
        - input_01_announce_agent_mail_handoff_request
      properties:
        input_01_announce_agent_mail_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_announce_agent_mail_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailHandoffRequest
    steps:
      - stepId: 01-announce-agent-mail-handoff
        description: Stores a durable task, run, or goal-linked handoff announcement for
          an approved company audience.
        operationId: announceAgentMailHandoff
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_announce_agent_mail_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_announce_agent_mail_handoff_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/handoffs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:handoffs
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - announceAgentMailHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-attach-agent-mail-trace
    summary: Attach Mail handoff trace
    description: Attaches identifier-only, authority-checked trace metadata to an
      owned Mail handoff. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_attach_agent_mail_trace_handoffRef
        - input_01_attach_agent_mail_trace_Idempotency_Key
        - input_01_attach_agent_mail_trace_request
      properties:
        input_01_attach_agent_mail_trace_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_attach_agent_mail_trace_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_attach_agent_mail_trace_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailTraceRequest
    steps:
      - stepId: 01-attach-agent-mail-trace
        description: Attaches identifier-only, authority-checked trace metadata to an
          owned Mail handoff.
        operationId: attachAgentMailTrace
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_01_attach_agent_mail_trace_handoffRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_attach_agent_mail_trace_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_attach_agent_mail_trace_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/handoffs/{handoffRef}/trace
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:handoffs
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - attachAgentMailTrace
    x-neotask-explicit-selection-required: false
  - workflowId: operation-wait-for-agent-mail-events
    summary: Wait for Mail events
    description: Performs one finite bounded wait and returns resumable Mail events.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_wait_for_agent_mail_events_request
      properties:
        input_01_wait_for_agent_mail_events_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailEventsRequest
    steps:
      - stepId: 01-wait-for-agent-mail-events
        description: Performs one finite bounded wait and returns resumable Mail events.
        operationId: waitForAgentMailEvents
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_wait_for_agent_mail_events_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/events/wait
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - waitForAgentMailEvents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-recover-agent-mail-events
    summary: Recover Mail events
    description: Recovers ordered Mail events from an opaque cursor. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_recover_agent_mail_events_request
      properties:
        input_01_recover_agent_mail_events_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailEventsRequest
    steps:
      - stepId: 01-recover-agent-mail-events
        description: Recovers ordered Mail events from an opaque cursor.
        operationId: recoverAgentMailEvents
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_recover_agent_mail_events_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/events/recover
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - recoverAgentMailEvents
    x-neotask-explicit-selection-required: false
  - workflowId: operation-export-agent-mail-data
    summary: Export Mail data
    description: Creates a bounded company-scoped export after account-security
      authorization and excludes access secrets. This one-step workflow exists
      so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_export_agent_mail_data_Idempotency_Key
        - input_01_export_agent_mail_data_request
      properties:
        input_01_export_agent_mail_data_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_export_agent_mail_data_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailExportRequest
    steps:
      - stepId: 01-export-agent-mail-data
        description: Creates a bounded company-scoped export after account-security
          authorization and excludes access secrets.
        operationId: exportAgentMailData
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_export_agent_mail_data_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_export_agent_mail_data_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/export
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - exportAgentMailData
    x-neotask-explicit-selection-required: false
  - workflowId: operation-erase-agent-mail-data
    summary: Erase Mail data
    description: Erases company-scoped coordination Mail data after account-security
      authorization and records a durable receipt. This one-step workflow exists
      so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_erase_agent_mail_data_Idempotency_Key
        - input_01_erase_agent_mail_data_request
      properties:
        input_01_erase_agent_mail_data_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_erase_agent_mail_data_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailErasureRequest
    steps:
      - stepId: 01-erase-agent-mail-data
        description: Erases company-scoped coordination Mail data after account-security
          authorization and records a durable receipt.
        operationId: eraseAgentMailData
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_erase_agent_mail_data_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_erase_agent_mail_data_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/erase
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - eraseAgentMailData
    x-neotask-explicit-selection-required: true
  - workflowId: operation-revoke-agent-mail-access
    summary: Revoke Mail access
    description: Revokes company Mail membership and deactivates identities after
      account-security authorization. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_agent_mail_access_Idempotency_Key
        - input_01_revoke_agent_mail_access_request
      properties:
        input_01_revoke_agent_mail_access_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_agent_mail_access_request:
          $ref: ./openapi.yaml#/components/schemas/AgentMailAccessRevocationRequest
    steps:
      - stepId: 01-revoke-agent-mail-access
        description: Revokes company Mail membership and deactivates identities after
          account-security authorization.
        operationId: revokeAgentMailAccess
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_agent_mail_access_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_agent_mail_access_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/mail/access/revoke
        x-neotask-method: POST
        x-neotask-required-scope: neotask:mail:security
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeAgentMailAccess
    x-neotask-explicit-selection-required: true
  - workflowId: operation-search-construct-packages
    summary: Search Construct packages
    description: "Searches the plugins and skills this account may see in Construct,
      with the same visibility filter as the desktop and web catalog. Query: q,
      family, category, official, sort, limit, cursor. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow."
    steps:
      - stepId: 01-search-construct-packages
        description: "Searches the plugins and skills this account may see in Construct,
          with the same visibility filter as the desktop and web catalog. Query:
          q, family, category, official, sort, limit, cursor."
        operationId: searchConstructPackages
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/packages/search
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - searchConstructPackages
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-construct-package
    summary: Read a Construct package
    description: Returns one visible package with its formatted showcase (what it
      does and how to use it), its README, channel heads, install guidance,
      security provenance and this account's entitlement. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_construct_package_ref
      properties:
        input_01_get_construct_package_ref:
          type: string
    steps:
      - stepId: 01-get-construct-package
        description: Returns one visible package with its formatted showcase (what it
          does and how to use it), its README, channel heads, install guidance,
          security provenance and this account's entitlement.
        operationId: getConstructPackage
        parameters:
          - name: ref
            in: path
            value: $inputs.input_01_get_construct_package_ref
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/packages/{ref}
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getConstructPackage
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-construct-package-versions
    summary: List Construct package versions
    description: "Lists visible releases of one package, newest first, with channel,
      moderation state and per-target signatures. Query: channel, limit, cursor.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_list_construct_package_versions_ref
      properties:
        input_01_list_construct_package_versions_ref:
          type: string
    steps:
      - stepId: 01-list-construct-package-versions
        description: "Lists visible releases of one package, newest first, with channel,
          moderation state and per-target signatures. Query: channel, limit,
          cursor."
        operationId: listConstructPackageVersions
        parameters:
          - name: ref
            in: path
            value: $inputs.input_01_list_construct_package_versions_ref
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/packages/{ref}/versions
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listConstructPackageVersions
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-construct-release-readiness
    summary: Read Construct release readiness
    description: "Returns the readiness checks of a visible release: scan,
      signatures, compatibility, targets and channel state. Query: version,
      channel. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_construct_release_readiness_ref
      properties:
        input_01_get_construct_release_readiness_ref:
          type: string
    steps:
      - stepId: 01-get-construct-release-readiness
        description: "Returns the readiness checks of a visible release: scan,
          signatures, compatibility, targets and channel state. Query: version,
          channel."
        operationId: getConstructReleaseReadiness
        parameters:
          - name: ref
            in: path
            value: $inputs.input_01_get_construct_release_readiness_ref
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/packages/{ref}/release-readiness
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:read
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getConstructReleaseReadiness
    x-neotask-explicit-selection-required: false
  - workflowId: operation-match-construct-content
    summary: Match installed content to a release
    description: Reports which visible release carries exactly the given content
      digest (construct-api/1 section 4.8), so a skill installed before the
      Construct migration can be adopted. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_match_construct_content_ref
        - input_01_match_construct_content_request
      properties:
        input_01_match_construct_content_ref:
          type: string
        input_01_match_construct_content_request:
          $ref: ./openapi.yaml#/components/schemas/matchConstructContent.request.v1
    steps:
      - stepId: 01-match-construct-content
        description: Reports which visible release carries exactly the given content
          digest (construct-api/1 section 4.8), so a skill installed before the
          Construct migration can be adopted.
        operationId: matchConstructContent
        parameters:
          - name: ref
            in: path
            value: $inputs.input_01_match_construct_content_ref
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_match_construct_content_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/packages/{ref}/content-match
        x-neotask-method: POST
        x-neotask-required-scope: neotask:construct:install
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - matchConstructContent
    x-neotask-explicit-selection-required: false
  - workflowId: operation-resolve-construct-artifact
    summary: Resolve a Construct install
    description: "Runs the Construct resolve algorithm for this account and host,
      then returns the selected release, its signed release manifest and a
      60-second download capability. Query: package (required), version,
      installedReleaseSeq, installedVersion, channel, mode, and together
      gatewayVersion, pluginApiVersion, hostTarget and manifestVersions. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_resolve_construct_artifact_package
      properties:
        input_01_resolve_construct_artifact_package:
          type: string
    steps:
      - stepId: 01-resolve-construct-artifact
        description: "Runs the Construct resolve algorithm for this account and host,
          then returns the selected release, its signed release manifest and a
          60-second download capability. Query: package (required), version,
          installedReleaseSeq, installedVersion, channel, mode, and together
          gatewayVersion, pluginApiVersion, hostTarget and manifestVersions."
        operationId: resolveConstructArtifact
        parameters:
          - name: package
            in: query
            value: $inputs.input_01_resolve_construct_artifact_package
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/resolve
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:install
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - resolveConstructArtifact
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-construct-grant-manifest
    summary: Read the signed grant manifest
    description: "Returns the account's effective Construct grants signed with the
      grants key and bound to one Gateway installation for six hours
      (construct-api/1 section 4.3). Query: installationId (22 characters of
      A-Z, a-z, 0-9, _ and -). This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_construct_grant_manifest_installationId
      properties:
        input_01_get_construct_grant_manifest_installationId:
          type: string
          pattern: ^[A-Za-z0-9_-]{22}$
    steps:
      - stepId: 01-get-construct-grant-manifest
        description: "Returns the account's effective Construct grants signed with the
          grants key and bound to one Gateway installation for six hours
          (construct-api/1 section 4.3). Query: installationId (22 characters of
          A-Z, a-z, 0-9, _ and -)."
        operationId: getConstructGrantManifest
        parameters:
          - name: installationId
            in: query
            value: $inputs.input_01_get_construct_grant_manifest_installationId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/entitlements/manifest
        x-neotask-method: GET
        x-neotask-required-scope: neotask:construct:install
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getConstructGrantManifest
    x-neotask-explicit-selection-required: false
  - workflowId: operation-report-construct-install
    summary: Report a Construct install
    description: "Records an install, update or uninstall of a visible release for
      usage statistics. Body: package, version, releaseSeq, targetKey, channel,
      event, installationId, source (cli from the standalone CLI) and
      gatewayVersion. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_report_construct_install_Idempotency_Key
        - input_01_report_construct_install_request
      properties:
        input_01_report_construct_install_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_report_construct_install_request:
          $ref: ./openapi.yaml#/components/schemas/reportConstructInstall.request.v1
    steps:
      - stepId: 01-report-construct-install
        description: "Records an install, update or uninstall of a visible release for
          usage statistics. Body: package, version, releaseSeq, targetKey,
          channel, event, installationId, source (cli from the standalone CLI)
          and gatewayVersion."
        operationId: reportConstructInstall
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_report_construct_install_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_report_construct_install_request
        successCriteria:
          - condition: $statusCode == 202
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/installs
        x-neotask-method: POST
        x-neotask-required-scope: neotask:construct:install
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - reportConstructInstall
    x-neotask-explicit-selection-required: false
  - workflowId: operation-report-construct-package
    summary: Report a Construct package
    description: "Files a moderation report about a visible package or one of its
      releases. Body: package, optional version, reason (malware, security,
      credential_theft, impersonation, spam, license, broken or other) and
      details (up to 4,000 characters). This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_report_construct_package_Idempotency_Key
        - input_01_report_construct_package_request
      properties:
        input_01_report_construct_package_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_report_construct_package_request:
          $ref: ./openapi.yaml#/components/schemas/reportConstructPackage.request.v1
    steps:
      - stepId: 01-report-construct-package
        description: "Files a moderation report about a visible package or one of its
          releases. Body: package, optional version, reason (malware, security,
          credential_theft, impersonation, spam, license, broken or other) and
          details (up to 4,000 characters)."
        operationId: reportConstructPackage
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_report_construct_package_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_report_construct_package_request
        successCriteria:
          - condition: $statusCode == 200 || $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/agent/v1/construct/reports
        x-neotask-method: POST
        x-neotask-required-scope: neotask:construct:feedback
        x-neotask-required-role-policy: null
        x-neotask-auth-class: agent_bearer
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - reportConstructPackage
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-human-agent-integration-credential-handoff
    summary: "Integrations: Inspect credential setup"
    description: Shows an authenticated owner or admin the safe state of an API-key
      handoff without returning credential material. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_human_agent_integration_credential_handoff_attemptId
      properties:
        input_01_get_human_agent_integration_credential_handoff_attemptId:
          type: string
          pattern: ^ia_[A-Za-z0-9_-]+$
    steps:
      - stepId: 01-get-human-agent-integration-credential-handoff
        description: Shows an authenticated owner or admin the safe state of an API-key
          handoff without returning credential material.
        operationId: getHumanAgentIntegrationCredentialHandoff
        parameters:
          - name: attemptId
            in: path
            value: $inputs.input_01_get_human_agent_integration_credential_handoff_attemptId
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-integrations/{attemptId}/credential
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_integration_credentials
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getHumanAgentIntegrationCredentialHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-complete-human-agent-integration-credential-handoff
    summary: "Integrations: Save a provider API key"
    description: Encrypts a provider API key for the authenticated tenant and
      returns only its fingerprint and verification state. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_complete_human_agent_integration_credential_handoff_attemptId
        - input_01_complete_human_agent_integration_credential_handoff_Idempotency_Key
        - input_01_complete_human_agent_integration_credential_handoff_request
      properties:
        input_01_complete_human_agent_integration_credential_handoff_attemptId:
          type: string
          pattern: ^ia_[A-Za-z0-9_-]+$
        input_01_complete_human_agent_integration_credential_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_complete_human_agent_integration_credential_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentIntegrationCredentialRequest
    steps:
      - stepId: 01-complete-human-agent-integration-credential-handoff
        description: Encrypts a provider API key for the authenticated tenant and
          returns only its fingerprint and verification state.
        operationId: completeHumanAgentIntegrationCredentialHandoff
        parameters:
          - name: attemptId
            in: path
            value: $inputs.input_01_complete_human_agent_integration_credential_handoff_attemptId
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_complete_human_agent_integration_credential_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_complete_human_agent_integration_credential_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-integrations/{attemptId}/credential
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_integration_credentials
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - completeHumanAgentIntegrationCredentialHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-human-agent-account-pairing-handoff
    summary: "Account: Inspect an agent pairing"
    description: Shows a safe account-pairing summary to an authenticated owner or
      admin without exposing credentials or internal identifiers. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_human_agent_account_pairing_handoff_handoffRef
      properties:
        input_01_get_human_agent_account_pairing_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
    steps:
      - stepId: 01-get-human-agent-account-pairing-handoff
        description: Shows a safe account-pairing summary to an authenticated owner or
          admin without exposing credentials or internal identifiers.
        operationId: getHumanAgentAccountPairingHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_01_get_human_agent_account_pairing_handoff_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-pairing-handoffs/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_pairing
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getHumanAgentAccountPairingHandoff
    x-neotask-explicit-selection-required: false
  - workflowId: operation-confirm-human-agent-account-pairing-handoff
    summary: "Account: Confirm an agent pairing"
    description: Binds a claimed agent to the authenticated existing tenant exactly
      once and preserves the tenant boundary. This one-step workflow exists so
      the mounted operation retains executable Arazzo coverage without placing
      it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_confirm_human_agent_account_pairing_handoff_handoffRef
        - input_01_confirm_human_agent_account_pairing_handoff_Idempotency_Key
        - input_01_confirm_human_agent_account_pairing_handoff_request
      properties:
        input_01_confirm_human_agent_account_pairing_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_confirm_human_agent_account_pairing_handoff_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_confirm_human_agent_account_pairing_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentAccountPairingConfirmRequest
    steps:
      - stepId: 01-confirm-human-agent-account-pairing-handoff
        description: Binds a claimed agent to the authenticated existing tenant exactly
          once and preserves the tenant boundary.
        operationId: confirmHumanAgentAccountPairingHandoff
        parameters:
          - name: handoffRef
            in: path
            value: $inputs.input_01_confirm_human_agent_account_pairing_handoff_handoffRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_confirm_human_agent_account_pairing_handoff_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_confirm_human_agent_account_pairing_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-pairing-handoffs/{handoffRef}/confirm
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_pairing
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - confirmHumanAgentAccountPairingHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: operation-list-human-agent-registrations
    summary: "Account: List agent registrations"
    description: Lists registrations in the authenticated tenant with safe labels,
      lifecycle state, and last-used timestamps; provider identity and
      credentials remain private. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    steps:
      - stepId: 01-list-human-agent-registrations
        description: Lists registrations in the authenticated tenant with safe labels,
          lifecycle state, and last-used timestamps; provider identity and
          credentials remain private.
        operationId: listHumanAgentRegistrations
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/registrations
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listHumanAgentRegistrations
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-human-agent-registration-label
    summary: "Account: Label an agent registration"
    description: Updates only the human-owned display label for a tenant agent
      registration. This one-step workflow exists so the mounted operation
      retains executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_human_agent_registration_label_registrationRef
        - input_01_update_human_agent_registration_label_Idempotency_Key
        - input_01_update_human_agent_registration_label_request
      properties:
        input_01_update_human_agent_registration_label_registrationRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_update_human_agent_registration_label_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_human_agent_registration_label_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentSecurityLabelRequest
    steps:
      - stepId: 01-update-human-agent-registration-label
        description: Updates only the human-owned display label for a tenant agent
          registration.
        operationId: updateHumanAgentRegistrationLabel
        parameters:
          - name: registrationRef
            in: path
            value: $inputs.input_01_update_human_agent_registration_label_registrationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_human_agent_registration_label_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_human_agent_registration_label_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/registrations/{registrationRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateHumanAgentRegistrationLabel
    x-neotask-explicit-selection-required: false
  - workflowId: operation-revoke-human-agent-registration
    summary: "Account: Revoke an agent registration"
    description: Revokes one tenant agent registration through the canonical
      authority fence and rejects future credentials. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_human_agent_registration_registrationRef
        - input_01_revoke_human_agent_registration_Idempotency_Key
        - input_01_revoke_human_agent_registration_request
      properties:
        input_01_revoke_human_agent_registration_registrationRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_human_agent_registration_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_human_agent_registration_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
    steps:
      - stepId: 01-revoke-human-agent-registration
        description: Revokes one tenant agent registration through the canonical
          authority fence and rejects future credentials.
        operationId: revokeHumanAgentRegistration
        parameters:
          - name: registrationRef
            in: path
            value: $inputs.input_01_revoke_human_agent_registration_registrationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_human_agent_registration_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_human_agent_registration_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/registrations/{registrationRef}/revoke
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeHumanAgentRegistration
    x-neotask-explicit-selection-required: true
  - workflowId: operation-list-human-agent-runners
    summary: "Account: List agent runners"
    description: Lists tenant runners with safe state, labels, capabilities, and
      last-used timestamps without returning HMAC material. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow.
    steps:
      - stepId: 01-list-human-agent-runners
        description: Lists tenant runners with safe state, labels, capabilities, and
          last-used timestamps without returning HMAC material.
        operationId: listHumanAgentRunners
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runners
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listHumanAgentRunners
    x-neotask-explicit-selection-required: false
  - workflowId: operation-inspect-human-runner-enrollment-review
    summary: "Account: Review a runner installation"
    description: Shows the exact requested installation to a current tenant owner or
      admin. The secret-free review hash binds the enrollment request; viewing
      it does not authorize installation. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_inspect_human_runner_enrollment_review_reviewRef
      properties:
        input_01_inspect_human_runner_enrollment_review_reviewRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-inspect-human-runner-enrollment-review
        description: Shows the exact requested installation to a current tenant owner or
          admin. The secret-free review hash binds the enrollment request;
          viewing it does not authorize installation.
        operationId: inspectHumanRunnerEnrollmentReview
        parameters:
          - name: reviewRef
            in: path
            value: $inputs.input_01_inspect_human_runner_enrollment_review_reviewRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runner-enrollments/{reviewRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - inspectHumanRunnerEnrollmentReview
    x-neotask-explicit-selection-required: false
  - workflowId: operation-resolve-human-runner-enrollment-review
    summary: "Account: Decide a runner installation request"
    description: Records approval or denial for the exact displayed review hash
      under the current owner or admin session. Site rechecks current tenant,
      member and registration authority before recording a new decision.
      Approval permits the originating enrollment request to continue; it does
      not return credentials or prove installation. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_resolve_human_runner_enrollment_review_reviewRef
        - input_01_resolve_human_runner_enrollment_review_Idempotency_Key
        - input_01_resolve_human_runner_enrollment_review_request
      properties:
        input_01_resolve_human_runner_enrollment_review_reviewRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_resolve_human_runner_enrollment_review_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_resolve_human_runner_enrollment_review_request:
          $ref: ./openapi.yaml#/components/schemas/HumanRunnerEnrollmentDecisionRequest
    steps:
      - stepId: 01-resolve-human-runner-enrollment-review
        description: Records approval or denial for the exact displayed review hash
          under the current owner or admin session. Site rechecks current
          tenant, member and registration authority before recording a new
          decision. Approval permits the originating enrollment request to
          continue; it does not return credentials or prove installation.
        operationId: resolveHumanRunnerEnrollmentReview
        parameters:
          - name: reviewRef
            in: path
            value: $inputs.input_01_resolve_human_runner_enrollment_review_reviewRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_resolve_human_runner_enrollment_review_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_resolve_human_runner_enrollment_review_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runner-enrollments/{reviewRef}/decision
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - resolveHumanRunnerEnrollmentReview
    x-neotask-explicit-selection-required: false
  - workflowId: operation-inspect-human-agent-claim-move
    summary: "Account: Review moving a claimed agent into your account"
    description: "Shows which agent trial would move, what it holds and which
      account receives it. For a claimer whose WorkOS user is mapped to an
      account, only that member session can view it. Otherwise it works like an
      invite: the signed-in session sees its own account and the WorkOS-verified
      claimer as information. It names the receiving account's plan, and whether
      that plan counts Free messages. A request closes when its agent revokes
      its own registration (`cancelledBy: agent`) or stops being the
      registration it was issued for. Viewing it moves nothing. This one-step
      workflow exists so the mounted operation retains executable Arazzo
      coverage without placing it inside an unrelated multi-step workflow."
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_inspect_human_agent_claim_move_moveRef
      properties:
        input_01_inspect_human_agent_claim_move_moveRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-inspect-human-agent-claim-move
        description: "Shows which agent trial would move, what it holds and which
          account receives it. For a claimer whose WorkOS user is mapped to an
          account, only that member session can view it. Otherwise it works like
          an invite: the signed-in session sees its own account and the
          WorkOS-verified claimer as information. It names the receiving
          account's plan, and whether that plan counts Free messages. A request
          closes when its agent revokes its own registration (`cancelledBy:
          agent`) or stops being the registration it was issued for. Viewing it
          moves nothing."
        operationId: inspectHumanAgentClaimMove
        parameters:
          - name: moveRef
            in: path
            value: $inputs.input_01_inspect_human_agent_claim_move_moveRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-claim-moves/{moveRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_claim_move
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - inspectHumanAgentClaimMove
    x-neotask-explicit-selection-required: false
  - workflowId: operation-resolve-human-agent-claim-move
    summary: "Account: Confirm or cancel moving a claimed agent"
    description: Records an explicit choice for the exact displayed review hash.
      Confirm moves the agent, its chats, tasks, runs and usage into the account
      in one transaction, revokes the trial runner for re-enrollment and retires
      the trial workspace. A mapped claimer's agent acts as their own
      membership. Otherwise the confirming member adopts just this agent, which
      acts only as that member; no WorkOS mapping or member binding is recorded.
      Cancel changes nothing. Email is never used to choose the account. The
      response returns the committed outcome as soon as the move commits;
      follow-up convergence of rows written after the move runs afterwards and
      never changes that outcome. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_resolve_human_agent_claim_move_moveRef
        - input_01_resolve_human_agent_claim_move_Idempotency_Key
        - input_01_resolve_human_agent_claim_move_request
      properties:
        input_01_resolve_human_agent_claim_move_moveRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_resolve_human_agent_claim_move_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_resolve_human_agent_claim_move_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentClaimMoveDecisionRequest
    steps:
      - stepId: 01-resolve-human-agent-claim-move
        description: Records an explicit choice for the exact displayed review hash.
          Confirm moves the agent, its chats, tasks, runs and usage into the
          account in one transaction, revokes the trial runner for re-enrollment
          and retires the trial workspace. A mapped claimer's agent acts as
          their own membership. Otherwise the confirming member adopts just this
          agent, which acts only as that member; no WorkOS mapping or member
          binding is recorded. Cancel changes nothing. Email is never used to
          choose the account. The response returns the committed outcome as soon
          as the move commits; follow-up convergence of rows written after the
          move runs afterwards and never changes that outcome.
        operationId: resolveHumanAgentClaimMove
        parameters:
          - name: moveRef
            in: path
            value: $inputs.input_01_resolve_human_agent_claim_move_moveRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_resolve_human_agent_claim_move_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_resolve_human_agent_claim_move_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-claim-moves/{moveRef}/decision
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_claim_move
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - resolveHumanAgentClaimMove
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-human-agent-runner-label
    summary: "Account: Label an agent runner"
    description: Updates only the human-owned display label for a tenant runner.
      This one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_human_agent_runner_label_runnerRef
        - input_01_update_human_agent_runner_label_Idempotency_Key
        - input_01_update_human_agent_runner_label_request
      properties:
        input_01_update_human_agent_runner_label_runnerRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_update_human_agent_runner_label_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_human_agent_runner_label_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentSecurityLabelRequest
    steps:
      - stepId: 01-update-human-agent-runner-label
        description: Updates only the human-owned display label for a tenant runner.
        operationId: updateHumanAgentRunnerLabel
        parameters:
          - name: runnerRef
            in: path
            value: $inputs.input_01_update_human_agent_runner_label_runnerRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_human_agent_runner_label_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_human_agent_runner_label_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runners/{runnerRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateHumanAgentRunnerLabel
    x-neotask-explicit-selection-required: false
  - workflowId: operation-rotate-human-agent-runner
    summary: "Account: Rotate an agent runner"
    description: Rotates a tenant runner credential through the canonical encrypted
      credential owner; the new secret is never returned. This one-step workflow
      exists so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_rotate_human_agent_runner_runnerRef
        - input_01_rotate_human_agent_runner_Idempotency_Key
        - input_01_rotate_human_agent_runner_request
      properties:
        input_01_rotate_human_agent_runner_runnerRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_rotate_human_agent_runner_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_rotate_human_agent_runner_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentRunnerRotateRequest
    steps:
      - stepId: 01-rotate-human-agent-runner
        description: Rotates a tenant runner credential through the canonical encrypted
          credential owner; the new secret is never returned.
        operationId: rotateHumanAgentRunner
        parameters:
          - name: runnerRef
            in: path
            value: $inputs.input_01_rotate_human_agent_runner_runnerRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_rotate_human_agent_runner_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_rotate_human_agent_runner_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runners/{runnerRef}/rotate
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - rotateHumanAgentRunner
    x-neotask-explicit-selection-required: true
  - workflowId: operation-revoke-human-agent-runner
    summary: "Account: Revoke an agent runner"
    description: Revokes a tenant runner through the canonical dispatch convergence
      owner and removes live credential material. This one-step workflow exists
      so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_human_agent_runner_runnerRef
        - input_01_revoke_human_agent_runner_Idempotency_Key
        - input_01_revoke_human_agent_runner_request
      properties:
        input_01_revoke_human_agent_runner_runnerRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_human_agent_runner_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_human_agent_runner_request:
          $ref: ./openapi.yaml#/components/schemas/AgentRunnerRevokeRequest
    steps:
      - stepId: 01-revoke-human-agent-runner
        description: Revokes a tenant runner through the canonical dispatch convergence
          owner and removes live credential material.
        operationId: revokeHumanAgentRunner
        parameters:
          - name: runnerRef
            in: path
            value: $inputs.input_01_revoke_human_agent_runner_runnerRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_human_agent_runner_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_human_agent_runner_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-security/runners/{runnerRef}/revoke
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_account_security
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeHumanAgentRunner
    x-neotask-explicit-selection-required: true
  - workflowId: operation-cancel-human-agent-approval-settings-handoff
    summary: Cancel a requested settings change
    description: Cancels the selected pending settings handoff under the current
      owner or admin session. It does not change approval policy or grants.
      Cancellation and audit commit together; a repeated cancellation returns
      the current terminal request. This one-step workflow exists so the mounted
      operation retains executable Arazzo coverage without placing it inside an
      unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_cancel_human_agent_approval_settings_handoff_agentRef
        - input_01_cancel_human_agent_approval_settings_handoff_handoffRef
        - input_01_cancel_human_agent_approval_settings_handoff_request
      properties:
        input_01_cancel_human_agent_approval_settings_handoff_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_cancel_human_agent_approval_settings_handoff_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_cancel_human_agent_approval_settings_handoff_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
    steps:
      - stepId: 01-cancel-human-agent-approval-settings-handoff
        description: Cancels the selected pending settings handoff under the current
          owner or admin session. It does not change approval policy or grants.
          Cancellation and audit commit together; a repeated cancellation
          returns the current terminal request.
        operationId: cancelHumanAgentApprovalSettingsHandoff
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_cancel_human_agent_approval_settings_handoff_agentRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_cancel_human_agent_approval_settings_handoff_handoffRef
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_cancel_human_agent_approval_settings_handoff_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-settings/{agentRef}/handoffs/{handoffRef}/cancel
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - cancelHumanAgentApprovalSettingsHandoff
    x-neotask-explicit-selection-required: true
  - workflowId: operation-prepare-human-agent-approval-review
    summary: Prepare a runner approval review
    description: Creates a hash-only handoff for a pending runner approval under the
      current owner or admin session. Current requester, dispatch, task, profile
      and policy authority are rechecked transactionally. This operation records
      no decision and issues no execution grant. This one-step workflow exists
      so the mounted operation retains executable Arazzo coverage without
      placing it inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_prepare_human_agent_approval_review_approvalRef
        - input_01_prepare_human_agent_approval_review_request
      properties:
        input_01_prepare_human_agent_approval_review_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_prepare_human_agent_approval_review_request:
          $ref: ./openapi.yaml#/components/schemas/EmptyOperationRequest
    steps:
      - stepId: 01-prepare-human-agent-approval-review
        description: Creates a hash-only handoff for a pending runner approval under the
          current owner or admin session. Current requester, dispatch, task,
          profile and policy authority are rechecked transactionally. This
          operation records no decision and issues no execution grant.
        operationId: prepareHumanAgentApprovalReview
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_prepare_human_agent_approval_review_approvalRef
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_prepare_human_agent_approval_review_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-reviews/{approvalRef}/handoff
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - prepareHumanAgentApprovalReview
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-human-agent-approval-review
    summary: Read a human approval review
    description: Loads the complete supported request behind an opaque handoff under
      the current owner or admin session. The handoff grants no decision
      authority. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_human_agent_approval_review_approvalRef
        - input_01_get_human_agent_approval_review_handoffRef
      properties:
        input_01_get_human_agent_approval_review_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_get_human_agent_approval_review_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
    steps:
      - stepId: 01-get-human-agent-approval-review
        description: Loads the complete supported request behind an opaque handoff under
          the current owner or admin session. The handoff grants no decision
          authority.
        operationId: getHumanAgentApprovalReview
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_get_human_agent_approval_review_approvalRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_get_human_agent_approval_review_handoffRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-reviews/{approvalRef}/{handoffRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getHumanAgentApprovalReview
    x-neotask-explicit-selection-required: false
  - workflowId: operation-decide-human-agent-approval-review
    summary: Decide the reviewed approval
    description: Records one exact reviewed decision and its request-local answer in
      a transaction. Current authority, handoff, review hash and answer are
      rechecked on replay; recording a decision does not confirm execution. This
      one-step workflow exists so the mounted operation retains executable
      Arazzo coverage without placing it inside an unrelated multi-step
      workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_decide_human_agent_approval_review_approvalRef
        - input_01_decide_human_agent_approval_review_handoffRef
        - input_01_decide_human_agent_approval_review_request
      properties:
        input_01_decide_human_agent_approval_review_approvalRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_decide_human_agent_approval_review_handoffRef:
          type: string
          minLength: 32
          maxLength: 128
        input_01_decide_human_agent_approval_review_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentApprovalReviewDecisionRequest
    steps:
      - stepId: 01-decide-human-agent-approval-review
        description: Records one exact reviewed decision and its request-local answer in
          a transaction. Current authority, handoff, review hash and answer are
          rechecked on replay; recording a decision does not confirm execution.
        operationId: decideHumanAgentApprovalReview
        parameters:
          - name: approvalRef
            in: path
            value: $inputs.input_01_decide_human_agent_approval_review_approvalRef
          - name: handoffRef
            in: path
            value: $inputs.input_01_decide_human_agent_approval_review_handoffRef
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_decide_human_agent_approval_review_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-reviews/{approvalRef}/{handoffRef}/decision
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - decideHumanAgentApprovalReview
    x-neotask-explicit-selection-required: true
  - workflowId: operation-get-human-agent-approval-settings
    summary: "Approvals: Get human agent approval settings"
    description: Returns the human agent approval settings scoped to the verified
      tenant. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_human_agent_approval_settings_agentRef
      properties:
        input_01_get_human_agent_approval_settings_agentRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-human-agent-approval-settings
        description: Returns the human agent approval settings scoped to the verified
          tenant.
        operationId: getHumanAgentApprovalSettings
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_get_human_agent_approval_settings_agentRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-settings/{agentRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getHumanAgentApprovalSettings
    x-neotask-explicit-selection-required: false
  - workflowId: operation-update-human-agent-approval-settings
    summary: "Approvals: Update human agent approval settings"
    description: Updates human agent approval settings without changing tenant
      ownership. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_update_human_agent_approval_settings_agentRef
        - input_01_update_human_agent_approval_settings_Idempotency_Key
        - input_01_update_human_agent_approval_settings_request
      properties:
        input_01_update_human_agent_approval_settings_agentRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_update_human_agent_approval_settings_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_update_human_agent_approval_settings_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentApprovalSettingsUpdateRequest
    steps:
      - stepId: 01-update-human-agent-approval-settings
        description: Updates human agent approval settings without changing tenant
          ownership.
        operationId: updateHumanAgentApprovalSettings
        parameters:
          - name: agentRef
            in: path
            value: $inputs.input_01_update_human_agent_approval_settings_agentRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_update_human_agent_approval_settings_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_update_human_agent_approval_settings_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-settings/{agentRef}
        x-neotask-method: PATCH
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - updateHumanAgentApprovalSettings
    x-neotask-explicit-selection-required: false
  - workflowId: operation-list-human-agent-approval-delegations
    summary: "Approvals: List human agent approval delegations"
    description: Lists human agent approval delegations scoped to the verified
      tenant. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    steps:
      - stepId: 01-list-human-agent-approval-delegations
        description: Lists human agent approval delegations scoped to the verified tenant.
        operationId: listHumanAgentApprovalDelegations
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-delegations
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - listHumanAgentApprovalDelegations
    x-neotask-explicit-selection-required: false
  - workflowId: operation-create-human-agent-approval-delegation
    summary: "Approvals: Create human agent approval delegation"
    description: Creates human agent approval delegation and returns its stable
      reference after idempotency checks. This one-step workflow exists so the
      mounted operation retains executable Arazzo coverage without placing it
      inside an unrelated multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_create_human_agent_approval_delegation_Idempotency_Key
        - input_01_create_human_agent_approval_delegation_request
      properties:
        input_01_create_human_agent_approval_delegation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_create_human_agent_approval_delegation_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentApprovalDelegationCreateRequest
    steps:
      - stepId: 01-create-human-agent-approval-delegation
        description: Creates human agent approval delegation and returns its stable
          reference after idempotency checks.
        operationId: createHumanAgentApprovalDelegation
        parameters:
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_create_human_agent_approval_delegation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_create_human_agent_approval_delegation_request
        successCriteria:
          - condition: $statusCode == 201
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-delegations
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - createHumanAgentApprovalDelegation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-get-human-agent-approval-delegation
    summary: "Approvals: Get human agent approval delegation"
    description: Returns the human agent approval delegation scoped to the verified
      tenant. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_get_human_agent_approval_delegation_delegationRef
      properties:
        input_01_get_human_agent_approval_delegation_delegationRef:
          type: string
          minLength: 1
          maxLength: 256
    steps:
      - stepId: 01-get-human-agent-approval-delegation
        description: Returns the human agent approval delegation scoped to the verified
          tenant.
        operationId: getHumanAgentApprovalDelegation
        parameters:
          - name: delegationRef
            in: path
            value: $inputs.input_01_get_human_agent_approval_delegation_delegationRef
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-delegations/{delegationRef}
        x-neotask-method: GET
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: false
    x-neotask-operation-ids:
      - getHumanAgentApprovalDelegation
    x-neotask-explicit-selection-required: false
  - workflowId: operation-revoke-human-agent-approval-delegation
    summary: "Approvals: Revoke human agent approval delegation"
    description: Revokes human agent approval delegation and rejects subsequent
      access. This one-step workflow exists so the mounted operation retains
      executable Arazzo coverage without placing it inside an unrelated
      multi-step workflow.
    inputs:
      type: object
      additionalProperties: false
      required:
        - input_01_revoke_human_agent_approval_delegation_delegationRef
        - input_01_revoke_human_agent_approval_delegation_Idempotency_Key
        - input_01_revoke_human_agent_approval_delegation_request
      properties:
        input_01_revoke_human_agent_approval_delegation_delegationRef:
          type: string
          minLength: 1
          maxLength: 256
        input_01_revoke_human_agent_approval_delegation_Idempotency_Key:
          type: string
          minLength: 8
          maxLength: 200
        input_01_revoke_human_agent_approval_delegation_request:
          $ref: ./openapi.yaml#/components/schemas/HumanAgentApprovalDelegationRevokeRequest
    steps:
      - stepId: 01-revoke-human-agent-approval-delegation
        description: Revokes human agent approval delegation and rejects subsequent access.
        operationId: revokeHumanAgentApprovalDelegation
        parameters:
          - name: delegationRef
            in: path
            value: $inputs.input_01_revoke_human_agent_approval_delegation_delegationRef
          - name: Idempotency-Key
            in: header
            value: $inputs.input_01_revoke_human_agent_approval_delegation_Idempotency_Key
        requestBody:
          contentType: application/json
          payload: $inputs.input_01_revoke_human_agent_approval_delegation_request
        successCriteria:
          - condition: $statusCode == 200
        outputs:
          responseBody: $response.body
          statusCode: $statusCode
        x-neotask-path: /api/account/agent-approval-delegations/{delegationRef}/revoke
        x-neotask-method: POST
        x-neotask-required-scope: null
        x-neotask-required-role-policy: agent_approval_control
        x-neotask-auth-class: human_session
        x-neotask-idempotency-required: true
    x-neotask-operation-ids:
      - revokeHumanAgentApprovalDelegation
    x-neotask-explicit-selection-required: true
x-neotask-launch-state: live
x-neotask-capability-authority: https://neotask.ai/api/agent/v1/capabilities
x-neotask-authentication: https://neotask.ai/auth.md
x-neotask-coverage:
  operationCount: 188
  coveredOperationCount: 188
