Reference
Quick actions reference
A single source of truth for what each business workspace owns, which UI controls trigger it, which analytics ids track it, and how API and MCP actions must validate the same work.
Atlas ships 314 quick actions across 88 workspaces, of which 198 are live today. Each one is triggered from the product, tracked by an analytics id, and mirrored by an API route and an MCP tool that enforce the same rules.
What is a quick action?
A quick action is one unit of work you can trigger three ways (by hand, over the API, or through an AI agent) each of which runs the exact same validated operation.
From the product
Click a button, run it from the command palette, or fire a keyboard shortcut. Every control carries an analytics id so you can trace it.
Over the REST API
Call the matching route with the same required fields and bounds. See the API reference for request and response shapes.
Through an AI agent
Ask an agent in plain language. The MCP tool enforces identical validation, tenancy, and RBAC before it acts.
Maturity
- Live
- Shipping in the product, API, and MCP with parity enforced.
- Guarded
- Live but gated behind an entitlement, flag, or role.
- Configured
- Available once the workspace finishes a setup step.
- Needs proof
- Contract is defined; the runtime tool is still landing.
Parity rule
One action, three surfaces
Action catalogue
Every quick action, grouped by workspace. Each row lists the UI control, its analytics id, the mirroring API route, the MCP target, and the shared validation contract.
314 actions across 88 workspaces
Growth Hub
Module guide5 actions · 3 live, 2 guarded, 0 configured
Open standalone business modules
LiveModule cards, list cards, quick starts, and business module nav
Analytics
App API
MCP target
Validation
Growth Hub is a cross-module command center. It must route users into CRM, Contract Hub, Document Sign, or PDF Studio without owning their records.
Review business governance posture
GuardedGovernance tab
Analytics
App API
MCP target
Validation
Used to explain RBAC, delegated access, audit, and evidence posture across modules.
Search Growth Hub action catalog
LiveGrowth Hub action search, category filters, API/MCP details, validation notes, and route links
Analytics
App API
MCP target
Validation
Makes Growth Hub operable as a command center: users can search dashboard, module launcher, lists, governance, analytics, and optional handoff actions without guessing which module owns the work.
Review Growth Hub summary, evidence, and object search
LiveGrowth Hub summary cards, object search, and evidence export controls
Analytics
App API
MCP target
Validation
Closes the Growth Hub command-center readback routes that operators use to inspect summary posture, searchable CRM/PDF/signing objects, and retained evidence bundles.
Run guided rescue, signer reminder, and PDF risk actions
GuardedGrowth Hub action catalog buttons and guarded recommendation drawers
Analytics
App API
MCP target
Validation
Groups the cross-module next-best-action endpoints for stale deals, at-risk accounts, signer reminders, and PDF risk review so action docs track the live controls instead of leaving route drift hidden.
Sales CRM
Module guide6 actions · 5 live, 1 guarded, 0 configured
Create CRM account
LiveAccount name field and Create button
Analytics
App API
MCP target
Validation
Creates a native Atlas account record without requiring Salesforce or HubSpot.
Create CRM deal
LiveAccount picker, deal name, amount, expected close picker, and Create button
Analytics
App API
MCP target
Validation
Deal creation is intentionally customer-scoped. PDF, signing, and contract links stay optional.
Log customer activity
LiveAccount/deal pickers, activity note, and Log button
Analytics
App API
MCP target
Validation
Activity logs attach to CRM context only and do not create PDF/signing side effects.
Dry-run import, commit, rollback, and merge duplicates
GuardedImport and Merge tabs
Analytics
App API
MCP target
Validation
Bulk CRM changes must keep conflict review and rollback visible before destructive decisions.
Search CRM action catalog
LiveCRM action search, category filters, API/MCP details, validation notes, and route links
Analytics
App API
MCP target
Validation
Makes Sales CRM operable as a standalone workspace: users can search account, contact, deal, activity, forecast, import, merge, rollback, and optional handoff actions without knowing the page layout.
Run sales forecast v2
LiveForecast command center and Monte Carlo forecast action
Analytics
App API
MCP target
Validation
Maps the v2 sales forecast endpoint that supports the CRM forecast command center.
Contract Hub
Module guide2 actions · 1 live, 1 guarded, 0 configured
Create and manage contract packets
GuardedPacket builder, lifecycle header, obligation ledger, and approval panels
Analytics
App API
MCP target
Validation
Contract Hub can reference CRM, signing, and PDF records, but contract lifecycle is standalone.
Search Contract Hub action catalog
LiveContract action search, category filters, API/MCP details, validation notes, and route links
Analytics
App API
MCP target
Validation
Makes Contract Hub operable as a standalone lifecycle workspace: users can search packets, renewals, approvals, obligations, redlines, remediation, evidence, and optional handoffs without depending on CRM navigation.
Document Sign
Module guide3 actions · 2 live, 0 guarded, 1 configured
Prepare and route signing envelope
ConfiguredEnvelope form, recipient fields, routing controls, send/reminder buttons
Analytics
App API
MCP target
Validation
Document Sign owns signer routing and audit evidence, not PDF editing.
Search Document Sign action catalog
LiveSigning action search, category filters, API/MCP details, validation notes, and route links
Analytics
App API
MCP target
Validation
Makes Document Sign operable as a standalone signing workspace: users can search envelopes, recipients, sessions, templates, fields, lifecycle, evidence, and optional handoffs without using Sales CRM.
Complete public signing ceremony and certificate download
LivePublic signing view, decline/sign buttons, and certificate download
Analytics
App API
MCP target
Validation
Maps the public signing token route family, including ceremony reads, sign/decline decisions, and completion certificate download.
PDF Studio
Module guide11 actions · 7 live, 3 guarded, 1 configured
Create or upload standalone PDF
LivePDF name, page count, risk flag, source upload, and optional connected workflow expander
Analytics
App API
MCP target
Validation
This is the key standalone PDF boundary: no customer, deal, contract, or signing context is required.
Run PDF operation
GuardedDocument workbench operation buttons
Analytics
App API
MCP target
Validation
Covers organize, edit, annotate, OCR, extract, redact, protect, compare, convert, compress, sign, and export workflows.
Search PDF tool catalog
LivePDF tool search, category filters, API/MCP details, and route links
Analytics
App API
MCP target
Validation
Makes PDF Studio operable like a standalone PDF website: users can search for merge, split, OCR, redact, forms, stamps, compression, export, and evidence without knowing where Atlas placed the button.
Preview, comment, review, and export artifacts
LivePreview source, comments, download source/artifacts, split packages, and evidence rows
Analytics
App API
MCP target
Validation
Export remains file-first; optional signing/contract/CRM handoff is an explicit navigation decision.
Manage PDF stamp assets, templates, and annotation cleanup
GuardedStamp asset library, template editor, thumbnail actions, and bulk cleanup preview
Analytics
App API
MCP target
Validation
Covers the PDF Studio stamp-library route family: upload tickets, versions, thumbnails, archive/restore, template CRUD, and bulk annotation cleanup.
Review PDF redaction/security readiness and provider callbacks
GuardedPDF security readiness panel and sanitizer operation status
Analytics
App API
MCP target
Validation
Keeps PDF security and redaction readiness routes visible in the action registry while treating provider callback execution as a guarded integration boundary.
PDF form data API: export, import, and flatten
LiveREST API with the pdf:write scope taking a base64 PDF; the Fill and edit forms screen fills forms in the browser instead
Analytics
App API
MCP target
Validation
These routes read every form field with its type, options, and value, export the same data as an FDF file, fill a form from JSON values or an FDF file, and flatten a form so its fields become fixed content. Import and flatten answer JSON that includes the filled PDF and a report of any values that were ignored and why. Field names and values are never logged.
Summarize, question, or extract tables from a PDF
ConfiguredPDF editor Ask AI panel: summarize button, extract tables button, question field with ask button, and a streamed answer
Analytics
App API
MCP target
Validation
A person opens the Ask AI panel in the PDF editor to get a summary, an answer to a question, or the document's tables as text, each grounded only in the file and streamed as server-sent events. The routes need the model provider to be configured; without it they say that document questions are unavailable. When the person leaves, the stream stops so no further model work is spent.
Convert a file with a server conversion job
LivePDF Studio conversion tools (for example PDF to Word): file drop, use URL, convert, live progress, cancel, keep result, and download
Analytics
App API
MCP target
Validation
A person picks a file, the server issues an upload ticket for object storage, the browser uploads the file directly, and then the job starts, streams progress, and offers a time-limited download link. Reading needs the PDF Studio view permission and pdf:read, creating and starting need export and pdf:write, cancel and keep need update, and delete needs the delete permission. Results are removed 24 hours after they are created unless kept, and the routes answer 503 when object storage is not configured.
Stamp Bates numbers on a PDF
LiveBates numbering screen: file picker, prefix, suffix, start number, digits, position, font size, number preview, and stamp button
Analytics
App API
MCP target
Validation
A person stamps gapless, sequential Bates numbers across every page of a document on the server, so the run is deterministic and citable, and downloads the stamped PDF. The route refuses invalid settings and unreadable files with 422 and an oversized file with 413. The prefix and the file content are never logged.
PDF legal operations API: extract, split, compare, sign, verify
LiveREST API with the pdf:write scope taking base64 PDFs
Analytics
App API
MCP target
Validation
These routes extract page ranges as a new PDF, split one PDF into many, produce a structured text comparison of two PDFs, verify the digital signatures in a PDF, and sign or certify a PDF when the server has a signing identity. Invalid page ranges, broken files, and bad signatures are refused with 422 and a message for the person. No filename, page text, signer name, or signing reason is logged.
HR Suite - Payroll
Module guide8 actions · 8 live, 0 guarded, 0 configured
Run payroll, draft cycles, and emit payslips
LivePayroll runs page, draft/approve buttons, payslip detail drawer
Analytics
App API
MCP target
Validation
Covers payroll run lifecycle (draft, calc, approve, post) and individual payslip read/release endpoints under /v1/hr/payroll.
Manage requisitions, candidates, and offers
LiveHiring pipeline board, candidate drawers, offer composer
Analytics
App API
MCP target
Validation
Hiring controllers under /v1/hr/hiring cover requisitions, candidates, stages, interviews, and offers across the recruitment lifecycle.
Manage employee directory and profile updates
LiveEmployee directory, profile drawer, status toggles
Analytics
App API
MCP target
Validation
Directory endpoints under /v1/hr/employees cover read, search, profile updates, and lifecycle status changes for staff records.
Request, approve, and audit leave balances
LiveLeave request form, approver queue, balance summaries
Analytics
App API
MCP target
Validation
Leave endpoints under /v1/hr/leave cover request submission, approval, balance lookup, and audit-trail surfaces.
Run performance cycles and 1:1 reviews
LiveCycle calendar, review forms, feedback drawer
Analytics
App API
MCP target
Validation
Performance endpoints under /v1/hr/performance cover review cycles, peer feedback, manager comments, and calibration steps.
Submit expense reimbursements and approvals
LiveReimbursement composer, receipts uploader, approver queue
Analytics
App API
MCP target
Validation
Reimbursement endpoints under /v1/hr/reimbursements cover submission, receipt upload, approver workflow, and payout linkage.
File and resolve HR helpdesk tickets
LiveTicket composer, message thread, status tracker
Analytics
App API
MCP target
Validation
HR Helpdesk endpoints under /v1/hr/tickets cover ticket creation, replies, status updates, and admin assignment.
Administer HR policies and configuration
LiveHR admin console, policies tab, config panels
Analytics
App API
MCP target
Validation
HR admin endpoints under /v1/hr/admin cover policy CRUD, working-hour rules, leave catalog, and other tenant-wide HR config.
Projects
Module guide1 actions · 1 live, 0 guarded, 0 configured
Browse, plan, and execute project workstreams
LiveProjects list, project board, plan view, settings drawer
Analytics
App API
MCP target
Validation
Projects controllers under /v1/projects (and legacy /projects) cover project CRUD, plan/board reads, status changes, member assignment, and document linkage.
Tasks
Module guide1 actions · 1 live, 0 guarded, 0 configured
Create, schedule, and complete tasks
LiveTask list, planner, detail drawer, scheduler quick actions
Analytics
App API
MCP target
Validation
Task endpoints under /v1/tasks, /tasks/{id}, /tasks/{taskId}, and /tasks/auto-schedule cover the full task lifecycle including dependencies and planner.
CRM Core
Module guide1 actions · 1 live, 0 guarded, 0 configured
CRM core read/write API surface
LiveCRM list, deal pipeline, contact drawer, account profile
Analytics
App API
MCP target
Validation
CRM endpoints under /v1/crm cover the core accounts/deals/contacts/activities CRUD that powers Sales CRM and Growth Hub flows.
Contracts API
Module guide1 actions · 1 live, 0 guarded, 0 configured
Contract Hub native API endpoints
LiveContracts list, contract drawer, clause library, evidence panel
Analytics
App API
MCP target
Validation
Contracts endpoints under /v1/contracts cover the native Contract Hub surface: contract CRUD, clauses, parties, evidence, and lifecycle transitions.
Integrations
Module guide2 actions · 1 live, 0 guarded, 1 configured
Manage integration connectors and webhooks
LiveIntegration directory, connector cards, OAuth callbacks
Analytics
App API
MCP target
Validation
Integrations and connector endpoints under /v1/integrations and /v1/connectors cover the full third-party connector lifecycle (install, configure, sync, remove), with live MCP readback/OAuth-start coverage, admin-gated connection-targeted test/disconnect tools, and Linear, Microsoft 365 and Granola provider actions. Secret-bearing credential save remains REST-only until the MCP secret-input policy is formalized, which is why the Granola credential route has no tool.
WhatsApp delivery and reply webhook receiver
ConfiguredInbound webhook registered with WhatsApp per workspace; the platform calls it with signed delivery receipts and replies
Analytics
App API
MCP target
Validation
WhatsApp calls this route once to verify the subscription and then for every delivery receipt and inbound reply, so the workspace can mark sent messages delivered, read, or failed and record opt-in and opt-out replies. The route is public because the caller holds no Atlas credential, so the signature over the raw body is the whole of the authentication. Receipts for message ids the workspace does not know are ignored.
Identity - Me
Module guide1 actions · 1 live, 0 guarded, 0 configured
Self-service identity, profile, and preferences
LiveProfile page, preferences, identity dashboard
Analytics
App API
MCP target
Validation
Self-service endpoints under /v1/me and /profile/me cover the signed-in user's profile, preferences, sessions, and identity-affecting reads.
Tenant Admin
Module guide2 actions · 2 live, 0 guarded, 0 configured
Tenant-level admin operations
LiveAdmin console, settings panel, audit drawer
Analytics
App API
MCP target
Validation
Tenant admin endpoints under /v1/admin, /v1/account, and /v1/settings cover settings, account profile, billing-adjacent reads, and audit history.
Set how record reference numbers are formatted
LiveSettings, Reference series: per record kind editor for prefix, suffix, separator, padding, year, month, reset cadence, and next number, with live preview, save, and discard
Analytics
App API
MCP target
Validation
An administrator shapes the readable reference numbers that records receive, previews sample references before saving, and saves the series. Listing and previewing need the team view permission, while saving needs the team admin permission and an owner or administrator role. The route is not tied to any premium module, because every workspace has records that need a reference.
Meetings
Module guide1 actions · 1 live, 0 guarded, 0 configured
Schedule, join, and document meetings
LiveMeetings calendar, room drawer, transcript panel
Analytics
App API
MCP target
Validation
Meeting endpoints under /meetings/{id} cover the meeting lifecycle: details, participants, recordings, and transcripts.
Wiki
Module guide2 actions · 2 live, 0 guarded, 0 configured
Browse, edit, and version wiki pages
LiveWiki tree, page editor, version history
Analytics
App API
MCP target
Validation
Wiki endpoints under /wiki/pages cover page CRUD, hierarchy moves, version snapshots, and collaborative cursors.
Wiki page search API
LiveREST API and agent tools with a token that carries the wiki:read scope
Analytics
App API
MCP target
Validation
This route searches the workspace wiki for pages whose title or body contains the query text, ignoring case, newest updated first. It reads only the caller's workspace and never returns deleted or archived pages. It changes nothing.
Blog
Module guide1 actions · 1 live, 0 guarded, 0 configured
Author, publish, and audit blog posts
LiveBlog composer, publish queue, audit drawer
Analytics
App API
MCP target
Validation
Blog endpoints under /blog/posts cover post drafts, publishing, scheduling, and revision history for tenant-owned content.
Goals
Module guide2 actions · 2 live, 0 guarded, 0 configured
Track goals, OKRs, and key results
LiveGoals tree, key-result editor, check-in drawer
Analytics
App API
MCP target
Validation
Goals endpoints under /goals/{id} cover goal lifecycle, key-result updates, check-ins, and reporting rollups.
Goals and key results REST API
LiveREST API with a personal access token that carries the goals:read, goals:write, or goals:delete scope
Analytics
App API
MCP target
Validation
These public routes list, read, create, update, and delete objectives and key results with rolled-up progress, and return the rollup tree under a goal. Reading needs goals:read, changes need goals:write, and deleting needs goals:delete. Every create, update, and delete is recorded in the audit log. The Goals screen uses the session routes of the same service.
Marketplace
Module guide1 actions · 1 live, 0 guarded, 0 configured
Browse and install marketplace apps
LiveMarketplace directory, app drawer, install button
Analytics
App API
MCP target
Validation
Marketplace endpoints under /v1/marketplace cover app directory listing, app detail, install, and lifecycle audit hooks.
Compliance
Module guide1 actions · 0 live, 1 guarded, 0 configured
Compliance posture reads and audits
GuardedCompliance dashboard, audit drawer, evidence panel
Analytics
App API
MCP target
Validation
Compliance endpoints under /v1/compliance and /v1/privacy cover posture summaries, audit history, DSAR workflow, and evidence reads.
Webhooks
Module guide1 actions · 1 live, 0 guarded, 0 configured
Manage outbound webhooks and deliveries
LiveWebhook registry, delivery log, retry drawer
Analytics
App API
MCP target
Validation
Webhook endpoints under /v1/webhooks and /v2/webhooks cover endpoint registration, delivery log, signing key rotation, and replay actions.
Access Control
Module guide2 actions · 2 live, 0 guarded, 0 configured
Manage roles, ACLs, and access reviews
LiveAccess console, role editor, ACL inspector
Analytics
App API
MCP target
Validation
Access endpoints under /v1/access and /custom-roles cover access snapshots, module enablement, invites, member roles, grants, suite changes, provisioning, custom-role authoring, and access review reporting.
Limit workspace access to approved networks
LiveSettings, Security, IP allowlist: add entry form with address or CIDR block and label, entry list, and remove button on each
Analytics
App API
MCP target
Validation
An owner or administrator lists, adds, and removes the network addresses allowed to reach the workspace. Once at least one entry is enabled, every request from an address outside the list is refused with 403, including requests made with tokens; with no enabled entries access is open. Every change is written to the audit log.
AI Platform
Module guide3 actions · 0 live, 3 guarded, 0 configured
Manage AI providers, models, and runs
GuardedAI providers console, model registry, run inspector
Analytics
App API
MCP target
Validation
AI platform endpoints under /v1/ai and /v1/ai-providers cover provider registry, model catalog, run history, and prompt template administration.
Review AI observability providers, summaries, and traces
GuardedAI observability provider table, summary cards, and trace explorer
Analytics
App API
MCP target
Validation
Closes the AI observability route family for provider status, aggregate summaries, and trace readback.
Local intelligence API: search, recommend, capture, summarize, generate
GuardedAsk Atlas bar, natural language capture card, summarize drawer, and recommendations on the tasks, projects, and dashboard screens; REST API with the intelligence scopes
Analytics
App API
MCP target
Validation
These routes run Atlas's own models on the server to rank candidates by meaning, recommend next items from interactions, extract dates and entities from a sentence, summarize text, and generate text that can be constrained to a JSON schema. Each call is scoped to the caller's workspace, traced, and metered against its credits. They are refused when the workspace lacks the intelligence entitlement or has used up its credits.
OAuth Platform
Module guide2 actions · 2 live, 0 guarded, 0 configured
Run the OAuth 2.0 authorization server
LiveOAuth consent screens, app dashboards, scope grants
Analytics
App API
MCP target
Validation
OAuth platform endpoints under /v2/oauth cover authorization, token, refresh, revoke, introspect, and discovery for tenant-managed apps.
Review and end an app's access to your account
LiveSettings, Connected apps: assistant apps card listing each approved app with its scopes and dates, and an end access button
Analytics
App API
MCP target
Validation
A signed-in person sees the apps and AI assistants they approved through Sign in with Atlas, with the scopes granted, when they first approved, and when the app last received a token, and can end any one of them. Both routes are limited to the caller's own grants in their own workspace and need the pats:manage scope on a session. The revoke route answers with the number of tokens it revoked, which is zero for an app the caller never approved.
SCIM Directory Sync
Module guide1 actions · 1 live, 0 guarded, 0 configured
SCIM v2 user and group provisioning
LiveSCIM connector, directory sync console, audit drawer
Analytics
App API
MCP target
Validation
SCIM endpoints under /scim/v2 implement RFC 7644 user/group provisioning, group membership patches, and audit reads for enterprise IdPs.
Connectors
Module guide1 actions · 1 live, 0 guarded, 0 configured
Legacy connector administration
LiveConnector list, install drawer, status badges
Analytics
App API
MCP target
Validation
Legacy connector endpoints under /v1/connectors cover install/uninstall, status pings, config reads, and now live MCP-backed catalog/OAuth-start/event readback, connection-targeted test/disconnect, plus Linear, Microsoft 365 and Granola provider operations.
Privacy
Module guide3 actions · 2 live, 1 guarded, 0 configured
Privacy posture, consent, and DSAR workflow
GuardedPrivacy console, DSAR queue, consent drawer
Analytics
App API
MCP target
Validation
Privacy endpoints under /v1/privacy cover data-subject access requests, consent log reads, retention policy queries, and right-to-erasure workflows.
Set how long each module keeps its data
LiveSettings, Data retention: one row per module with a days field or keep forever, and a save button
Analytics
App API
MCP target
Validation
An owner or administrator sees one retention row for every module that can be purged and sets how many days its records are kept, or keeps them forever. Every change is written to the audit log and applies only to the caller's workspace. Records under an active legal hold are not purged.
Place or release a legal hold
LiveSettings, Data retention: legal hold form with name, reason, and scope, a list of holds, and a release button on each
Analytics
App API
MCP target
Validation
An owner or administrator places a legal hold on the whole workspace, one module, or one record so that retention purges skip it, and later releases it. Releasing records who released the hold and when, and every change is written to the audit log. The routes read and change only the caller's workspace.
Automations
Module guide3 actions · 3 live, 0 guarded, 0 configured
Author and run tenant automation scripts
LiveAutomation editor, run history, trigger drawer
Analytics
App API
MCP target
Validation
Automation script endpoints under /automations/scripts cover script CRUD, manual triggers, run history, and trigger schedules.
Automation rules REST API
LiveREST API with a personal access token that carries the automations:read or automations:write scope
Analytics
App API
MCP target
Validation
These public routes create, edit, enable, disable, run, and delete the workspace's audit-event automation rules, and read their run and version history, through the same service as the Settings Automations screen. Reading needs automations:read and every change needs automations:write, with the public API rate limits and Idempotency-Key replay applied. A manual run answers 202 with the run outcome, and a revert is forward only: it applies the older snapshot as a new version rather than rewriting history. Rules are scoped to the caller's workspace, and an id from another workspace answers 404.
Script automations REST API
LiveREST API with a personal access token that carries the automations:read or automations:write scope
Analytics
App API
MCP target
Validation
These public routes create, read, update, deactivate, and run script automations, and read their run history, through the same service as the Scripts screen. Reading needs automations:read and every change needs automations:write. Creating a webhook-triggered script returns its webhook secret once, the run route queues a manual run and answers 202 with the run id, and DELETE deactivates the script rather than deleting it. The list returns every script automation in the caller's workspace, while the per-script routes enforce ownership.
Reporting
Module guide1 actions · 1 live, 0 guarded, 0 configured
Report deliveries, status, and email pipelines
LiveReport scheduler, delivery log, email pipeline drawer
Analytics
App API
MCP target
Validation
Reporting endpoints under /v1/report-deliveries, /v1/status, and /v1/email cover scheduled report fan-out, status posture, and email delivery telemetry.
Agent Governance
Module guide1 actions · 0 live, 1 guarded, 0 configured
Govern agent runs, approvals, and policies
GuardedApprovals queue, policy editor, run inspector
Analytics
App API
MCP target
Validation
Agent governance endpoints under /agent-governance/approvals cover approval queue management, policy edits, and audit reads for agent decisions.
Appointments
Module guide2 actions · 2 live, 0 guarded, 0 configured
Schedule and manage appointments
LiveAppointment calendar, drawer, reschedule action
Analytics
App API
MCP target
Validation
Appointment endpoints under /appointments/{id} cover appointment booking, reschedule, cancel, and confirmation flows.
Review, reschedule, cancel, remind, and no-show appointments
LiveAppointment drawer, reschedule flow, cancel/no-show/reminder actions
Analytics
App API
MCP target
Validation
Captures the v1 appointment lifecycle route family used by the booking and scheduling surfaces.
Data Residency
Module guide1 actions · 0 live, 1 guarded, 0 configured
Manage tenant data residency and region
GuardedResidency console, region pinning, evidence drawer
Analytics
App API
MCP target
Validation
Data residency endpoints under /v1/data-residency cover tenant region pinning, residency posture, and migration evidence reads.
eSign API
Module guide1 actions · 1 live, 0 guarded, 0 configured
eSign envelope API endpoints
LiveEnvelope composer, signer drawer, evidence panel
Analytics
App API
MCP target
Validation
eSign endpoints under /v1/esign cover envelope CRUD, signer order, status updates, evidence reads, and webhook callbacks for the Document Sign module.
HR Suite - Operations
Module guide1 actions · 1 live, 0 guarded, 0 configured
HR operational sub-modules (onboarding, policies, probations, attendance, etc.)
LiveHR console sub-tabs for onboarding, policies, probations, role changes, attendance, holidays, letters, departments, locations, performance, reports, statutory, exit interviews, documents, emergency contacts, employment records, org chart
Analytics
App API
MCP target
Validation
HR operational endpoints cover onboarding workflows, policies, probations, role changes, attendance, holidays, letters, departments, locations, performance reviews, statutory reports, exit interviews, documents, emergency contacts, employment records, and org chart reads.
Platform - Auth
Module guide3 actions · 3 live, 0 guarded, 0 configured
Auth surface: login, password, 2FA, OAuth, SSO callbacks
LiveLogin, signup, password reset, OAuth + SSO callback pages
Analytics
App API
MCP target
Validation
Auth endpoints under /auth, /v1/auth, and /v1/oauth cover login, signup, password reset, OAuth providers, SSO callbacks, and session bootstrap.
Sign in with a passkey
LiveSign-in page: Sign in with a passkey button, and saved passkeys offered in the email field where the browser supports it
Analytics
App API
MCP target
Validation
These public routes sign a person in with a passkey saved on their device. A successful sign-in returns the same session, and sets the same refresh cookie, as a password sign-in, and asks for no separate two-step code. The sign-in page remembers that the person last used a passkey.
Sign in with a link sent by email
LiveSign-in page: Email me a sign-in link, resend and change email; the link page at /auth/link with continue and cancel when the link is opened in another browser, and ask for a new link when it has expired
Analytics
App API
MCP target
Validation
These public routes send a one-use sign-in link to an address and turn the opened link into a session, with the same refresh cookie a password sign-in sets. The request sets a short-lived cookie in the browser that asked, so a link opened there signs in at once and a link opened anywhere else asks the person to confirm first.
Platform - Notifications
Module guide1 actions · 1 live, 0 guarded, 0 configured
Read and manage your notifications
LiveNotification bell, preferences panel, push subscription drawer
Analytics
App API
MCP target
Validation
Notification endpoints under /notifications, /notification-preferences, /notification-prefs, /push and /v1/push cover the in-app feed, preference toggles, and push notification subscription lifecycle.
Platform - Calendar
Module guide2 actions · 2 live, 0 guarded, 0 configured
View and manage your calendar
LiveCalendar page, grid preferences toggles, availability drawer
Analytics
App API
MCP target
Validation
Calendar endpoints under /calendar, /calendar-grid-preferences, /availability, and /auto-schedule cover the unified calendar view, event CRUD, grid preferences, availability windows, and auto-schedule planner.
Calendar settings, connections, and sync REST API
LiveREST API with a personal access token that carries the calendar:read or calendar:write scope
Analytics
App API
MCP target
Validation
These public routes read and update the workspace calendar preferences, list configured providers and the caller's own connected calendars, disconnect one, read external events and tasks from those calendars, list public holidays, and push a task as an event to every connected calendar. Reading needs calendar:read and changes need calendar:write. Events, external tasks, and task sync return results only when the caller has connected a calendar, and task sync reports the outcome per provider. The calendar settings screen uses the session routes of the same service.
Platform - Search
Module guide1 actions · 1 live, 0 guarded, 0 configured
Search across everything in Atlas
LiveCommand bar, saved views, search results page
Analytics
App API
MCP target
Validation
Search endpoints under /search, /v1/search, /v1/unified-search, /v1/cross-tool-search, /frecency, /saved-views, and /task-saved-filters cover unified search, frecency ranking, saved views, and per-module filter persistence.
Platform - Onboarding
Module guide1 actions · 1 live, 0 guarded, 0 configured
New-user onboarding checklist and tenant bootstrap
LiveOnboarding wizard, checklist, tenant setup screens
Analytics
App API
MCP target
Validation
Onboarding endpoints under /onboarding cover the new-user wizard, tenant bootstrap, initial admin assignment, and checklist progression reads.
Platform - Presence + Live
Module guide1 actions · 1 live, 0 guarded, 0 configured
Realtime presence, live cursors, and sync channels
LiveAvatar stack, live cursor overlay, sync indicator
Analytics
App API
MCP target
Validation
Presence endpoints under /presence, /live, /sync, and /share cover realtime presence broadcast, live cursors, sync channel reads, and ephemeral share links.
Platform - Feedback
Module guide5 actions · 3 live, 2 guarded, 0 configured
User feedback capture, inspiration, and morning briefing
LiveFeedback widget, inspiration panel, morning briefing card
Analytics
App API
MCP target
Validation
Feedback and personalization endpoints under /v1/feedback, /inspiration, /morning-briefing, /digest, and /focus-coaching cover user feedback submission, daily inspiration, briefings, digests, and focus coaching prompts.
Answer the satisfaction survey
GuardedOnboarding page satisfaction widget: score buttons 0 to 10, optional comment, submit, skip comment, and close
Analytics
App API
MCP target
Validation
A signed-in person rates Atlas from 0 to 10 and may add a comment, and the server stores the response against their workspace and user with a computed category. The route is self-service for the caller's own workspace and is refused when the workspace lacks the required module entitlement. It does not itself enforce the 90-day survey interval; the eligibility routes report that interval.
Share the workspace referral link
LiveOnboarding page referral card: referral link, copy button, and share button with click, signup, and credit counts
Analytics
App API
MCP target
Validation
A signed-in person reads the workspace referral code with its click count, signup count, and earned credit, and copies or shares a signup link that carries it. The route only reads, or creates the code once, for the caller's own workspace. It never exposes another workspace's code or totals.
Product feedback, survey eligibility, and referral API
GuardedREST API with the growth:read or growth:write scope; the growth-status routes accept a personal access token and agent tools
Analytics
App API
MCP target
Validation
These routes record a quick positive, neutral, or negative feedback pulse, report whether the caller may answer the satisfaction survey yet, redeem another workspace's referral code, and read the referral summary and survey eligibility through the token-friendly growth-status surface. Every route is scoped to the caller's own user and workspace. A successful redemption credits the referring workspace once and is refused for self-referral or a repeat.
Open a support request
LiveSupport page form: subject, message, category, product area, priority, email, name, company, phone, optional attachment, and submit button
Analytics
App API
MCP target
Validation
Anyone, including a signed-out visitor, opens a support request from the public support page or a help entry point. The route needs no credential, stores the request, and notifies the Atlas support team by email when email is configured. Reading, answering, and updating requests are separate routes restricted to Atlas staff.
Platform - Billing
Module guide5 actions · 4 live, 0 guarded, 1 configured
Billing, plan, and rate-limit tier management
LiveBilling console, plan picker, rate-limit drawer
Analytics
App API
MCP target
Validation
Billing endpoints under /v1/billing and /v1/rate-limit-tiers cover plan subscription, invoice reads, and rate-limit tier overrides.
Apply a coupon at checkout
LiveSettings, Billing, checkout flow: coupon code field and apply button above the pay button
Analytics
App API
MCP target
Validation
During checkout a person types a coupon code and the server prices the selected plan, cycle, modules, and currency, then reports whether the coupon applies and what it takes off. The route accepts only a signed-in session from an owner, administrator, or member who can view billing. It does not redeem the coupon; it only reports validity and the discount for the quoted order.
Workspace entitlements read API
LiveRead by the app shell to show or lock modules and features; callable with the profile:read scope
Analytics
App API
MCP target
Validation
This route returns the effective entitlements of the caller's workspace: which modules and features its plan and any grants allow, and its limits. The web app uses it to hide or lock surfaces when the signed-in session does not already carry the entitlement set. It is a self-service route for the caller's own workspace and cannot read another workspace.
Payment provider webhook receiver
ConfiguredInbound webhook called by the payment provider from its own servers; no Atlas credential, authenticated by its signature
Analytics
App API
MCP target
Validation
The payment provider calls this route to report billing events for a workspace, and it is the only place where a paid plan or module is granted to a workspace. The route is public because the provider holds no Atlas credential, so the signature over the raw body is the whole of the authentication. Signatures, secrets, and payloads are never logged.
Compare plans and get a price
LivePlans page: tier, cycle, module, currency, and tax number selectors, plan recommender with team size and goals, live quote, and checkout button
Analytics
App API
MCP target
Validation
Anyone, signed in or not, reads the effective plan catalog, gets a quote for a plan, cycle, modules, add-ons, and currency, and asks for a recommended plan from team size and goals. All price arithmetic happens on the server from one catalog, so the page and checkout never disagree about a price. The catalog is the built-in default unless Atlas staff have saved an override.
Platform - Observability
Module guide1 actions · 1 live, 0 guarded, 0 configured
Health, readiness, metrics, observability endpoints
LiveStatus page, internal metrics dashboard
Analytics
App API
MCP target
Validation
Observability endpoints under /health, /ready, /metrics, /observability, /v1/health, and /.well-known cover health probes, readiness gates, Prometheus metrics, and well-known discovery documents.
Platform - Public Surfaces
Module guide2 actions · 2 live, 0 guarded, 0 configured
Public marketing, blog, and unauthenticated share surfaces
LivePublic blog, public share links, marketing pages
Analytics
App API
MCP target
Validation
Public endpoints under /public, /public-blog, and /public-shares cover marketing pages, public blog reads, and unauthenticated share token lookups for documents, dashboards, and previews.
Daily inspiration feed
LiveCalled by the browser extension popup and new tab page for the daily quote and wallpaper; shuffle=true asks for a fresh pick
Analytics
App API
MCP target
Validation
This route returns the day's inspiration bundle, such as a quote and a wallpaper, from public sources, cached for several hours unless a shuffle is requested. It is an alias of the unprefixed inspiration route kept for browser extension builds that already call the /v1 path. It holds no workspace data and needs no sign-in.
Time Tracking
Module guide3 actions · 2 live, 1 guarded, 0 configured
Time entries, workload, and focus sessions
LiveTime entry drawer, workload view, focus timer
Analytics
App API
MCP target
Validation
Time tracking endpoints under /time-entries, /workload, and /focus-sessions cover time entry CRUD, workload allocations, and focus session reads tied to the planner.
Review and decide time approvals
GuardedTime approval inbox, detail drawer, approve/reject buttons
Analytics
App API
MCP target
Validation
Covers manager-facing time approval reads and approve/reject decisions.
Time entries and timer REST API
LiveREST API with a personal access token that carries the time:read, time:write, or time:delete scope
Analytics
App API
MCP target
Validation
These public routes let a person list their time entries, log a completed entry, start and stop a timer, read the running timer, and edit or delete their own entries. Reading needs time:read, changes need time:write, and deleting needs time:delete. The duration is always computed on the server from the start and end times. The Time Tracking screen uses the session routes of the same service.
Forms Engine
Module guide2 actions · 2 live, 0 guarded, 0 configured
Build, publish, and collect forms
LiveForm builder, attribute panel, formula editor, label picker
Analytics
App API
MCP target
Validation
Forms engine endpoints under /forms, /field-policies, /custom-attributes, /formula-fields, and /labels cover form CRUD, submission, field policy management, custom attributes, formula fields, and labels across modules.
Intake forms and task approvals REST API
LiveREST API with a personal access token that carries the forms:read or forms:write scope
Analytics
App API
MCP target
Validation
These public routes list, create, edit, and delete intake forms that turn each submission into a task on a project, export up to 1,000 submissions as CSV, and request or record an approval on a task. Reading needs forms:read and every change needs forms:write. The approval routes set the task's approval state to pending, approved, or rejected and record who decided; they apply no role or state check beyond the scope. Public form schema and submission routes are not part of this surface.
Booking Engine
Module guide2 actions · 2 live, 0 guarded, 0 configured
Booking pages, meeting types, blackouts, webhooks, hosts, questions
LiveBooking page editor, meeting type drawer, host availability matrix
Analytics
App API
MCP target
Validation
Booking engine endpoints under /booking-pages, /booking-meeting-types, /booking-webhooks, /booking-blackouts, /booking-page-hosts, /booking-questions, /booking-analytics, and /scheduling-rules cover booking page CRUD, meeting types, blackout windows, webhook fan-out, host configuration, intake questions, analytics, and scheduling rules.
Review public booking meeting types and intake questions
LivePublic booking page meeting-type selector and question form
Analytics
App API
MCP target
Validation
Covers unauthenticated booking metadata reads used by public booking pages before an appointment is created.
Release Notes
Module guide2 actions · 2 live, 0 guarded, 0 configured
Release notes feed and changelog
LiveRelease notes page, changelog widget
Analytics
App API
MCP target
Validation
Release notes endpoints under /release-notes cover the public changelog, in-app release notes panel, and admin authoring surface.
Review public changelog entries and RSS feed
LiveCustomer changelog page, entry detail, and RSS subscription
Analytics
App API
MCP target
Validation
Covers the public changelog list, slug detail, and RSS feed routes added for customer-facing release notes.
Workspaces
Module guide1 actions · 1 live, 0 guarded, 0 configured
Workspaces, teams, tenants, tenant branding
LiveWorkspace switcher, team admin, tenant settings, branding panel
Analytics
App API
MCP target
Validation
Workspace endpoints under /workspaces, /v1/workspaces, /teams, /tenants, /v1/tenant, /v1/tenants, and /v1/tenant-branding cover workspace CRUD, team admin, tenant settings, and branding management.
Profile + Me
Module guide1 actions · 1 live, 0 guarded, 0 configured
Profile, me, user theme, habits, daily notes, journal
LiveProfile page, theme picker, habits tracker, daily notes panel
Analytics
App API
MCP target
Validation
Profile and personal endpoints under /profile, /me, /user-theme, /habits, /daily-notes, and /journal-reviews cover the signed-in user profile, theme preferences, habits tracker, daily notes, and journal reviews.
SSO
Module guide3 actions · 3 live, 0 guarded, 0 configured
SSO configuration and callbacks
LiveSSO admin console, IdP metadata upload
Analytics
App API
MCP target
Validation
SSO endpoints under /v1/sso cover SAML/OIDC configuration, IdP metadata upload, JIT provisioning, and SSO callback handling.
Sign in with single sign-on from your work email
LiveSign-in page: Use single sign-on button, work email field, continue, back to sign in, and the return page that finishes the sign-in
Analytics
App API
MCP target
Validation
This public route finds the workspace whose verified email domain serves a work address and returns where its SAML sign-in starts; the sign-in page then sends the person there, and the identity provider returns them to /auth/sso to finish. It is for people whose workspace signs them in through its own identity provider.
Verify your email domains for single sign-on
LiveSettings, Security, single sign-on domains card: domain field and add button, the TXT record name and value with copy buttons, verify now, and remove
Analytics
App API
MCP target
Validation
An owner or administrator claims the email domains their people sign in with and proves the workspace owns each one with a DNS record. Only a verified domain is used by single sign-on discovery, because an unproven domain would let one workspace send another company's people to its own identity provider. The workspace is always the session's own, adding and verifying are written to the audit log, and a removed domain stops matching at once.
Two-Factor Auth
Module guide2 actions · 2 live, 0 guarded, 0 configured
Two-factor authentication enrollment and challenge
LiveTwo-factor enrollment screen, recovery codes drawer
Analytics
App API
MCP target
Validation
Two-factor endpoints under /v1/two-factor cover TOTP enrollment, challenge verification, and recovery code management for end users.
Add, rename and remove your passkeys
LiveSettings, Security, Passkeys card: add a passkey, confirm with your password or an emailed code, name it, then rename or remove each passkey in the list
Analytics
App API
MCP target
Validation
These routes let a signed-in person manage their own passkeys from security settings: list them with when each was added and last used, add one after proving it is them again, rename one, and remove one. Adding a passkey adds a way into the account, which is why it needs a fresh password or emailed code rather than the age of the session. A passkey signs a person in without a separate two-step code, because it already proves possession of the device and the person's verification on it.
Sessions
Module guide1 actions · 1 live, 0 guarded, 0 configured
Active session management and revoke
LiveSessions panel in profile/security settings
Analytics
App API
MCP target
Validation
Session endpoints under /v1/sessions cover active session listing, single-session revoke, and bulk revoke flows tied to the security console.
Personal Access Tokens
Module guide1 actions · 1 live, 0 guarded, 0 configured
Personal access tokens and API key management
LiveTokens page in profile/security settings
Analytics
App API
MCP target
Validation
Token endpoints under /v1/pats and /v1/access-tokens cover personal access token creation, rotation, revoke, scope edit, and listing.
Audit + Activity
Module guide2 actions · 2 live, 0 guarded, 0 configured
Audit log, activity feed, audit events
LiveAudit log explorer, activity feed widget
Analytics
App API
MCP target
Validation
Audit endpoints under /v1/audit-log, /audit-events, and /activity-feed cover audit log search, activity feed reads, and exportable audit event streams for compliance reviews.
Stream the audit log to a security event system
LiveSettings, Security, SIEM export: destination form with format, secret token, enabled switch, and event filter; save and remove buttons; delivery log with load more
Analytics
App API
MCP target
Validation
An owner or administrator configures where the workspace audit feed is sent, in which format, and which actions are included, then reads the log of delivery attempts. Reads need the audit log view permission and the workspace:read scope; saving and removing need the audit log export permission and the workspace:manage scope, and every change is written to the audit log. The secret token is never returned, only whether one is set, and each workspace has at most one configuration.
Analytics
Module guide1 actions · 1 live, 0 guarded, 0 configured
Analytics surface and A/B tests
LiveAnalytics dashboards, A/B test console
Analytics
App API
MCP target
Validation
Analytics endpoints under /v1/analytics and /v1/email-ab-tests cover aggregate analytics queries, dashboards, and A/B test allocation/reads.
Reports
Module guide4 actions · 3 live, 1 guarded, 0 configured
Reports surface, email templates, SEO
LiveReports console, email template editor, SEO admin
Analytics
App API
MCP target
Validation
Reports and editorial endpoints under /v1/reports, /v1/email-templates, /v1/seo, and /v1/themes cover scheduled reports, email template authoring, SEO admin, and theme management.
Create, review, and revoke public dashboards
GuardedPublic dashboard sharing controls and revoke action
Analytics
App API
MCP target
Validation
Covers public dashboard listing, creation, and token revocation for shareable reporting surfaces.
Insights reporting REST API
LiveREST API with a personal access token that carries the reports:read scope
Analytics
App API
MCP target
Validation
These public routes let a token list, read, run, and export saved report definitions and dashboards, and run ad hoc aggregation queries, for business intelligence and agent callers. Every query runs scoped to the caller's workspace, and the CSV export returns a saved report's result as a file attachment. The POST routes only run queries, so they stay available in a read-only view-as session. Creating and editing reports and dashboards is not offered here.
BI dataset and report export API
LiveREST API with a personal access token that carries the reports:read or reports:write scope, returning JSON or CSV
Analytics
App API
MCP target
Validation
These routes let BI tools and scheduled extract jobs discover the reporting datasets, run an ad hoc aggregation, or pull a saved report, as JSON or as a CSV attachment. Every route needs the reports export permission; reading datasets and saved reports needs the reports:read scope, and running an ad hoc query needs reports:write. A saved report from another workspace is reported as not found.
Webhooks
Module guide1 actions · 1 live, 0 guarded, 0 configured
Webhook endpoints, deliveries, watchers
LiveWebhook endpoints console, delivery log
Analytics
App API
MCP target
Validation
Webhook endpoints under /v1/webhook-endpoints, /v1/webhook-deliveries, and /v1/watch cover webhook configuration, delivery log inspection, and watch subscriptions used by external integrators.
Integrations - Extras
Module guide1 actions · 1 live, 0 guarded, 0 configured
Integration extras: inbound email, slack, voice, AI models
LiveIntegration directory, inbound email config, slack admin, AI model picker
Analytics
App API
MCP target
Validation
Integration extras under /integrations, /inbound-email, /v1/slack, /v1/ai-models, and /v1/voice cover inbound email parsing, Slack admin, AI model selection, and voice transcription endpoints.
Task Platform Extras
Module guide4 actions · 3 live, 1 guarded, 0 configured
Task extras: templates, relations, saved filters, comments
LiveTask drawer, templates picker, relations panel
Analytics
App API
MCP target
Validation
Task platform extras under /tasks, /task-templates, /task-relations, /template-library, /templates, and /comments cover task templates, relations between tasks, the cross-module template library, and comments across resources.
Run bulk task, label, and comment mutations
GuardedBulk action bar, label picker, and comment composer
Analytics
App API
MCP target
Validation
Maps the shared bulk operation endpoints that power multi-select task, label, and comment workflows.
Review focus coaching suggestions
LiveMy Work focus coaching panel and suggestion cards
Analytics
App API
MCP target
Validation
Maps the focus coaching suggestion endpoint used by My Work and planning guidance surfaces.
Review task type catalog and task-type detail
LiveTask type settings list and type detail drawer
Analytics
App API
MCP target
Validation
Covers global and project-scoped task type catalog/list/key/id readback endpoints.
Project Platform Extras
Module guide1 actions · 1 live, 0 guarded, 0 configured
Project extras: risks, milestones, status updates, dependencies, stakeholders, initiatives, portfolios, cycles, board columns
LiveProject drawer subtabs and board configuration
Analytics
App API
MCP target
Validation
Project platform extras under /projects, /project-risks, /v1/project-risks, /project-milestones, /project-status-updates, /project-dependencies, /v1/project-dependencies, /project-stakeholders, /initiatives, /portfolios, /cycles, and /board-columns cover risks, milestones, status updates, dependencies, stakeholders, initiatives, portfolios, cycles, and board column configuration.
Goals Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
Goals catalog and goal operations
LiveGoals dashboard, goal drawer
Analytics
App API
MCP target
Validation
Goals platform endpoints under /goals cover the full goal catalog: CRUD, progress updates, alignment with cycles, and team scoping.
Meetings Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
Meetings, meeting insights, video attachments
LiveMeetings list, meeting detail, insights drawer
Analytics
App API
MCP target
Validation
Meetings endpoints under /meetings, /v1/meetings, /v1/meeting-insights, and /v1/video-attachments cover meeting CRUD, AI-powered insights, transcripts, and video attachment uploads.
Wiki Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
Wiki pages, presence, collaboration
LiveWiki editor, page tree, collaboration cursors
Analytics
App API
MCP target
Validation
Wiki platform endpoints under /v1/wiki, /v1/wiki-presence, and /v1/wiki-collab cover wiki page CRUD, realtime presence, and collaborative edit broadcast.
Blog Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
Internal blog authoring and reads
LiveBlog editor, blog list
Analytics
App API
MCP target
Validation
Blog endpoints under /blog cover internal blog post authoring, publishing, and reads across the tenant.
Automations Platform
Module guide1 actions · 0 live, 1 guarded, 0 configured
Automation scripts, triggers, runs
GuardedAutomations console, run history, script editor
Analytics
App API
MCP target
Validation
Automations platform endpoints under /automations cover script authoring, trigger configuration, run history, and operational reads for the no-code automation surface.
Custom Roles
Module guide1 actions · 1 live, 0 guarded, 0 configured
Custom roles authoring and assignment
LiveCustom roles console
Analytics
App API
MCP target
Validation
Custom roles endpoints under /custom-roles cover role definition CRUD, permission scoping, and assignment management across modules.
Undo + Trash + Quick Links
Module guide1 actions · 1 live, 0 guarded, 0 configured
Undo entries, trash recovery, quick links, shortcuts
LiveUndo toast, trash explorer, quick links menu, keyboard shortcuts dialog
Analytics
App API
MCP target
Validation
Undo and recovery endpoints under /undo-entries, /v1/trash, /quick-links, and /v1/shortcuts cover undo stack reads, trash recovery, quick links, and keyboard shortcut definitions.
Inbox + Scheduler Drift
Module guide2 actions · 2 live, 0 guarded, 0 configured
Scheduler drift feed and mute state
LiveDrift feed widget, mute drawer
Analytics
App API
MCP target
Validation
Inbox and scheduler drift endpoints under /today-scheduler-drift-feed, /scheduler-drift-mute-state, and /appointments cover the today drift feed, mute state controls, and appointment notifications shown on the planner.
Notification inbox API
LiveREST API and agent tools with a personal access token that carries the inbox:read or inbox:write scope
Analytics
App API
MCP target
Validation
These routes let a token or agent read the caller's notification inbox with filters, cursor paging, and an unread count, mark one notification read or unread, and mark everything read. Every route is scoped to the calling person, so nobody can read or change another person's notifications. Reading needs inbox:read and the three mark routes need inbox:write.
PDF Studio Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
PDF studio API surface (extras)
LivePDF studio editor, OCR drawer, convert pipeline
Analytics
App API
MCP target
Validation
PDF platform endpoints under /v1/pdf, /v1/pdf-studio, /v1/pdf-secure, /v1/pdf-convert, and /v1/pdf-ocr cover PDF tooling APIs, secure share links, conversion pipelines, and OCR job orchestration.
Docs Platform
Module guide1 actions · 1 live, 0 guarded, 0 configured
Generated docs surface: Postman, OpenAPI references
LiveDocs portal, Postman download buttons
Analytics
App API
MCP target
Validation
Docs platform endpoints under /v1/docs, /v1/postman-environment.json, and /v1/postman.json cover generated documentation portals, Postman environment exports, and OpenAPI reference artifacts.
Extension Errors
Module guide2 actions · 2 live, 0 guarded, 0 configured
Browser extension error capture
LiveExtension error console (internal)
Analytics
App API
MCP target
Validation
Extension error endpoints under /v1/extension-errors cover browser extension crash and exception ingest, replay, and internal review for extension stability monitoring.
Browser extension analytics event intake
LiveCalled by the Atlas browser extension, which posts each buffered analytics event with the signed-in person's credential
Analytics
App API
MCP target
Validation
The browser extension sends each product analytics event here, and the server records it against the caller's workspace and user and answers 204 without a body. Events are kept in a bounded in-process buffer and written as one structured log line each, not stored in the database. Malformed or oversized events are refused with a validation error.
Client Delivery
Module guide90 actions · 33 live, 56 guarded, 1 configured
Browse the engagement register and open an engagement
GuardedEngagement register: sort control, view switch, load more button, retry on a failed read, and the engagement link that opens the engagement workspace
Analytics
App API
MCP target
Validation
These routes list the engagements in the workspace page by page and return one engagement record. They require a signed-in OWNER, ADMIN or MEMBER of a workspace whose plan includes Client Delivery, view access to the client-delivery module, and the delivery:read scope for a token; a portal guest is refused. Engagements walled off by an information barrier, or marked restricted when the caller holds no access grant, are left out of the list and answer 404 on the single read, exactly as an id that never existed.
Engagement record API
GuardedREST API and agent tools with a personal access token that carries the delivery:read or delivery:write scope
Analytics
App API
MCP target
Validation
Summary returns portfolio counts by status and the number at risk, my returns up to 100 live engagements where the caller is partner, manager, QA reviewer or PMO lead, PATCH edits the engagement record, and DELETE soft deletes it. All four need a workspace whose plan includes Client Delivery and an OWNER, ADMIN or MEMBER role: reads need view access and delivery:read, PATCH needs update access and delivery:write, and DELETE needs delete access, delivery:write and the OWNER or ADMIN role. Restricting an engagement or lifting its restriction also needs the OWNER or ADMIN role, because it changes who can read the record. Engagements hidden by an information barrier or restricted access are excluded from the counts and from my, and a write to one answers 404, the same answer as an id from another workspace.
Start a new engagement from a playbook
GuardedNew engagement wizard: client, commercials, team, playbook and review steps, the playbook chooser, and the create button
Analytics
App API
MCP target
Validation
The first route creates an engagement record for a client account, audits it and adds it to search; the second copies a playbook (the workspace copy when one exists, otherwise the built-in) into the new engagement's phases, workstreams, deliverables, responsibility matrix, RAID starters, meetings, information requests, closure items and checks. Both need a workspace whose plan includes Client Delivery and an OWNER, ADMIN or MEMBER role with delivery:write; creating needs create access and applying a playbook needs admin access on the client-delivery module, because it writes across many registers with no undo. Applying refuses an engagement that already holds work, and an engagement hidden by an information barrier or restricted access answers 404.
Move an engagement through its lifecycle and set its RAG rating
GuardedEngagement workspace lifecycle panel: status move buttons with a reason, RAG rating form, archive with confirmation, and restore
Analytics
App API
MCP target
Validation
These routes move an engagement between lifecycle statuses, record a RAG rating with its reason and author, archive an engagement out of the register and search, and restore it. They need a workspace whose plan includes Client Delivery, an OWNER, ADMIN or MEMBER role, update access on the client-delivery module and the delivery:write scope. Every write is audited, closing an engagement records a separate closed event, and an engagement hidden by an information barrier or restricted access answers 404.
Check whether an engagement may close, and reopen a closed one
GuardedEngagement workspace closure tab: readiness banner with blockers and warnings, and the reopen panel with a required reason
Analytics
App API
MCP target
Validation
Readiness tells a partner whether an engagement may close today and lists each blocker and warning; reopen puts a closed engagement back into closure. Both need a workspace whose plan includes Client Delivery and an OWNER, ADMIN or MEMBER role; readiness needs view access and delivery:read, and reopen needs admin access, delivery:write and the OWNER or ADMIN role. An engagement hidden by an information barrier or restricted access answers 404 before anything is read.
Write, customise and reset engagement playbooks
GuardedPlaybook library and editor: category filter and search, new playbook form, customise, collection editors for each section, save, reset to built-in, and remove with confirmation
Analytics
App API
MCP target
Validation
These routes read the playbook library (the built-in playbooks merged with this workspace's own and customised copies), write a playbook from nothing, take an editable copy of a built-in, edit its fields and collections, reset a copy to the built-in, and remove a playbook the workspace wrote. Reads need view access and delivery:read; every write needs admin access on the client-delivery module, delivery:write and the OWNER or ADMIN role, because a playbook shapes every engagement started from it. All routes need a workspace whose plan includes Client Delivery, and engagements already started are not changed.
See open work across every engagement
GuardedDelivery home tiles and recent engagements, and the firm-wide RAID, meetings, requests, actions, approvals and exports screens with a link to each engagement
Analytics
App API
MCP target
Validation
These read-only routes gather open work across all engagements in the workspace: the portfolio counters, open RAID items, meetings, information requests, follow-up actions, change requests awaiting approval, and export jobs. They need a workspace whose plan includes Client Delivery, an OWNER, ADMIN or MEMBER role, view access on the client-delivery module and the delivery:read scope; a portal guest is refused. Rows of engagements the caller may not see are excluded in the query, so they neither appear nor count. They accept no parameters and change nothing.
Revoke a client portal invitation
GuardedEngagement workspace people tab: portal invitations panel with a revoke button on each invitation
Analytics
App API
MCP target
Validation
This route revokes a portal invitation so its token can no longer be accepted, and records an audit entry the first time. It needs a workspace whose plan includes Client Delivery, an OWNER, ADMIN or MEMBER role, update access on the client-delivery module and the delivery:write scope. A token issued by another workspace, or one for an engagement the caller may not see, answers 404 without saying which.
Configure follow-up rules and reporting officers for the firm
LiveDelivery settings: a switch, lead days field and reset button for each follow-up rule, and the reporting officers picker with a save button
Analytics
App API
MCP target
Validation
These routes read and change the firm-wide follow-up rules (which reminders run and how many days ahead) and the list of appointed money laundering reporting officers. Reads are open to an OWNER, ADMIN or MEMBER with view access on the client-delivery module and delivery:read; writes need admin access, delivery:write and the OWNER or ADMIN role, because turning off a rule or appointing an officer is an administrative decision. A portal guest is refused, and each write is recorded in the audit log.
Override follow-up rules for one engagement
LiveEngagement workspace follow-ups tab: rules toggle, a switch and reset button for each rule on this engagement
Analytics
App API
MCP target
Validation
The read returns each follow-up rule as it applies to one engagement, combining the firm setting with that engagement's overrides; the write changes those overrides. Reads need an OWNER, ADMIN or MEMBER role with view access and delivery:read; the write needs admin access, delivery:write and the OWNER or ADMIN role. An engagement the caller cannot see answers 404 before its configuration is read.
Use the firm's reporting cadence when composing a status report
LiveStatus report composer: the cadence choice, prefilled from the firm setting, and its read failure notice
Analytics
App API
MCP target
Validation
This read-only route returns how often the firm reports and on which day, so the status report composer proposes the right period. It needs an OWNER, ADMIN or MEMBER role, view access on the client-delivery module and delivery:read; a portal guest is refused. The cadence is firm-wide, and no engagement-level override exists.
Client Delivery vocabulary API
LiveREST API and agent tools with a personal access token that carries the delivery:read scope
Analytics
App API
MCP target
Validation
This read-only route returns the closed sets used by Client Delivery follow-ups, so an integration or agent tool reads them instead of keeping its own copy. It needs an OWNER, ADMIN or MEMBER role, view access on the client-delivery module and delivery:read; a portal guest is refused.
Set up a recurring meeting forum and schedule its sittings
GuardedEngagement Meetings tab: forum list with add forum, edit, stand down or reactivate, delete, preview upcoming dates, schedule a sitting, and the terms of reference editor
Analytics
App API
MCP target
Validation
These routes keep the standing forums of an engagement, such as a steering committee or a weekly status call, with their chair, secretary, quorum rule, minutes approval settings, and terms of reference. A person can preview the dates a forum's cadence produces, marked where a sitting already exists, and create one sitting from the forum with everything except the date taken from it. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, view access for reads and preview, create access to add a forum or a sitting, update access to edit or save terms of reference, and delete access to remove a forum; a token needs the delivery read or delivery write scope. An engagement behind an information barrier or restricted to named people is refused before it is read, and a guest from the client portal cannot call these routes.
Schedule an engagement meeting and record that it was held
GuardedEngagement Meetings tab: meeting register with calendar toggle, open and delete actions; meeting workspace with details form, Start, Hold, record as held afterwards, Cancel, and bind or unbind a calendar meeting
Analytics
App API
MCP target
Validation
These routes list, create, read, edit, and delete the meetings of one engagement, show them on a calendar window, and move a meeting through its life from scheduled to in progress, held, or cancelled. A meeting can be bound to a calendar meeting in the workspace so its provenance is recorded, and unbound again as a deliberate act. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view, create, update, or delete access on Client Delivery for the matching action, with the delivery read or delivery write scope on a token. Every lookup is scoped to the workspace and the engagement, so a meeting on another engagement or workspace returns 404, and an engagement behind an information barrier is refused before it is read.
Build a meeting agenda and capture outcomes, risks, decisions, and actions
GuardedMeeting workspace agenda: add item, move up or down, timebox, record outcome, mark decided, defer, remove, and the capture bar that raises a RAID item, a decision, or an action from an item; carried forward items from the previous sitting
Analytics
App API
MCP target
Validation
These routes build and run the agenda of one engagement meeting and turn what was said into records: a capture creates a real RAID item or decision on the engagement register, or an action item on the engagement follow-ups, and links it back to the agenda item. The carried forward read lists what the previous sitting of the same forum left unfinished so the chair can pick it up. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view, update, create, or delete access on Client Delivery for the matching action, with the delivery read or delivery write scope on a token. The meeting workspace records outcomes through the agenda item edit; the separate outcome route is available to API callers and applies the same freeze rule.
Record who attended a meeting and the votes they cast
GuardedMeeting workspace attendance list: add attendee, change role, mark attendance, send a delegate, remove; motion and voter fields to cast a vote
Analytics
App API
MCP target
Validation
These routes keep the attendance list of one engagement meeting, including roles, voting rights, delegates standing in for members, and the recorded attendance status that the quorum rule reads. Votes are cast against a motion by a named attendee and the tally is stored with each vote. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view, update, or delete access on Client Delivery for the matching action, with the delivery read or delivery write scope on a token. A meeting on another engagement or workspace returns 404, and an engagement behind an information barrier is refused before it is read.
Write, circulate, and approve meeting minutes
GuardedMeeting workspace minutes panel: minutes editor and Save, Import notes, Circulate, Approve, Reject, Dispute with a reason, Republish, version comparison toggle, minutes sheet and Print; Approve shortcut in the meeting register
Analytics
App API
MCP target
Validation
These routes hold the formal minutes of an engagement meeting: save a draft, import the notes of a synced Granola meeting, circulate for approval with a due time, and approve, reject, or dispute. Approval freezes the record with a snapshot of the agenda, attendance, and votes and a hash, adds an entry to the engagement timeline, and republishing opens a new version without touching the approved one; the versions and diff reads show how the record changed. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view or update access on Client Delivery, with the delivery read or delivery write scope on a token. The meeting workspace saves through the PUT route; the POST draft route is kept for API callers and saves, then circulates when circulate is true.
Raise a question or request on an engagement and see it answered
GuardedEngagement Threads tab: open and breached filters, add thread form with kind, thread list, thread detail with first response, answer, close with reason, and reopen
Analytics
App API
MCP target
Validation
These routes keep the question and request threads of one engagement, measure first response and resolution against the response target, and mark a thread as breached when the target passes. Reopening a thread increments a count, which shows questions that were closed before they were answered. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view, create, or update access on Client Delivery for the matching action, with the delivery read or delivery write scope on a token. An engagement behind an information barrier or restricted to named people is refused before it is read.
Map engagement stakeholders and log contact with them
GuardedEngagement Stakeholders tab: add stakeholder form, power and interest grid grouped by strategy, overdue contact flags, and the interactions panel with channel, subject, and sentiment
Analytics
App API
MCP target
Validation
These routes keep the stakeholder map of one engagement, with power, interest, sentiment, engagement strategy, and flags such as decision maker or signatory, and record each contact so the last and next contact dates are derived rather than typed. Logging an interaction with a sentiment also updates the stakeholder's current sentiment. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and view or update access on Client Delivery, with the delivery read or delivery write scope on a token. An engagement behind an information barrier or restricted to named people is refused before it is read.
Add a person to an engagement team
GuardedEngagement People tab, team panel: side, role, name, email, share email with client, and Add
Analytics
App API
MCP target
Validation
These routes list and add the people on one engagement, firm side, client side, and third party, with their role, workstream, allocation, and whether they are key personnel. The identity used to detect duplicates is derived on the server rather than accepted from the caller. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, view access to list and create access to add, with the delivery read or delivery write scope on a token. An engagement on another workspace, deleted, or behind an information barrier returns a refusal before any row is read.
Give a person access to a restricted engagement, or take it away
GuardedEngagement People tab, access grants panel: person, reason, expiry, workstream scope, Grant, and Revoke
Analytics
App API
MCP target
Validation
These routes list, create, and revoke record-level access grants on an engagement that is restricted to named people. Revoking a grant records it on the engagement timeline in the same transaction and then closes the person's access on every transport: their guest membership, their current session, and their open realtime connection. Callers need admin access on the Client Delivery module as well as the workspace role Owner, Admin, or Member and the Client Delivery module on the workspace plan, with the delivery read or delivery write scope on a token. An engagement behind an information barrier is refused, and every grant and revocation is written to the audit log with its reason.
Invite a client contact to the engagement portal
GuardedEngagement People tab, portal invites panel: contact picker, access role, Issue invite, copy link, and the invitation list
Analytics
App API
MCP target
Validation
These routes issue a client portal invitation for one contact on one engagement and list the invitations already issued. Issuing returns the acceptance link and reports whether the email was sent, failed, could not be sent because the contact has no address, or could not be sent because email is not configured, and the link can be copied and handed over in every case. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, update access to issue and view access to list, with the delivery write or delivery read scope on a token. Both routes first check that the caller may see the engagement, so an engagement behind an information barrier, or restricted to named people without a grant for the caller, returns the same 404 as one that does not exist, and no seat is charged. Every issue is written to the audit log.
Track access to client systems and revoke it with evidence
GuardedEngagement Ways of working tab, access provisions panel: system, access level, Add, and Revoke with evidence
Analytics
App API
MCP target
Validation
These routes record the access each team member was given to client systems on one engagement and its revocation, so closing the engagement can check that nothing is still live. Revocation stores who revoked it, when, and the evidence, and writes an audit entry. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, view access to list, create access to add, and update access to revoke, with the delivery read or delivery write scope on a token. An engagement behind an information barrier or restricted to named people is refused before it is read.
Share an engagement document with the client, or withdraw it
GuardedEngagement Requests tab, request detail: share or withdraw toggle on each attached document
Analytics
App API
MCP target
Validation
These routes decide whether an engagement document appears in the client portal by setting its audience to client or internal. Withdrawing a document removes it from the client's view but does not delete the file, and a client who already downloaded it still holds it. Callers need the workspace role Owner, Admin, or Member, the Client Delivery module on the workspace plan, and update access on Client Delivery, with the delivery write scope on a token. An engagement behind an information barrier or restricted to named people is refused before it is read.
Review the financial picture of an engagement and freeze a snapshot
GuardedEngagement Commercials tab: burn, effort and margin cards, the snapshot list, and the Take snapshot button; the Economics tab shows the same computed figures
Analytics
App API
MCP target
Validation
The summary, burn, effort, and profitability reads compute the engagement's financial picture on demand from budgets, time, expenses, and billing milestones, so the figures are never stale. Capturing a snapshot freezes that picture for a day and source so a figure quoted to a client stays quotable later, and the capture is written to the audit log. Workspace owners, admins, and members may read and capture; guests are refused with 403, and a token needs the delivery:read scope to read and delivery:write to capture. The routes sit behind the Client Delivery entitlement.
Set up rate cards and grade rates for an engagement
GuardedEngagement Commercials tab, Rate cards panel: New rate card form, per-card Add rate form (grade, bill rate, cost rate), and the Show cost rates switch
Analytics
App API
MCP target
Validation
These routes list the rate cards that apply to an engagement, including workspace-wide cards, create a card, and add or replace the bill and cost rate for a grade on a card. Workspace owners, admins, and members may read; only owners and admins may create a card or set a rate, because rates are a partner decision, and everyone else is refused with 403. Cost rates are hidden from members even when they ask for them. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Plan an engagement budget
GuardedEngagement Commercials tab, Budgets panel: New budget form, Edit form for planned cost and revenue, and Remove with confirmation
Analytics
App API
MCP target
Validation
These routes list, create, edit, and remove the budgets an engagement is measured against, at engagement, phase, workstream, or deliverable level. Workspace owners, admins, and members may read; only owners and admins may create, edit, or remove a budget, and others are refused with 403. A token needs delivery:read to read and delivery:write to change, and the routes sit behind the Client Delivery entitlement.
Record an engagement expense and take it through approval
GuardedEngagement Commercials tab, Expenses panel: status filter, New expense form, Edit form, and Submit, Approve, Reject with a reason, and Reimburse actions
Analytics
App API
MCP target
Validation
These routes record expenses against an engagement, with the foreign exchange rate stamped at entry, and move each claim through submission, approval or rejection, and reimbursement. Workspace owners, admins, and members may list, create, edit, and submit; only owners and admins may approve, reject, or reimburse, and an approver can never approve their own claim. A token needs delivery:read or delivery:write, and the routes sit behind the Client Delivery entitlement.
Track billing milestones from earned to paid
GuardedEngagement Commercials tab, Billing panel: New milestone form and per-milestone actions to mark earned, invoiced with an invoice reference, or paid, and to dispute, hold, or write off with a reason
Analytics
App API
MCP target
Validation
These routes keep the engagement's billing milestones and move each one through earned, invoiced, and paid, with dispute, hold, and write-off as recorded exceptions. The invoice reference is free text from the finance system; Atlas does not raise invoices. Every move is written to the audit log, and the first time a milestone is earned a milestone reached event is recorded. Owners, admins, and members may list, mark earned, dispute, and hold; only owners and admins may create a milestone, mark it invoiced or paid, or write it off. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Record revenue recognition events and the onerous contract provision
GuardedEngagement Revenue tab: Record event form (type, date it occurred, basis), Attach to milestone control, and the onerous provision form (raised, amount, basis)
Analytics
App API
MCP target
Validation
These routes record the events that make a fee recognisable, attach a recorded event to the billing milestone it supports, and raise or release the onerous contract provision on the engagement. Each write is recorded in the audit log, and releasing a provision clears its amount but still requires a stated basis. Owners, admins, and members may list, record, and attach events; only owners and admins may set the provision. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Track regulatory obligations and their deadlines on an engagement
GuardedEngagement Obligations tab, Regulatory panel: regime picker with Seed, custom obligation form, due soon list, and Met, Waive with a reason, and status actions
Analytics
App API
MCP target
Validation
These routes seed the obligations a set of regulatory regimes places on an engagement, record obligations the library does not carry, list them soonest deadline first, show what falls due in a window, and move each obligation's status. Every seed, record, and status change is written to the audit log. Workspace owners, admins, and members may use them; guests are refused with 403. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Record the client purchase order and draw it down
GuardedEngagement Commercials tab, Procurement panel: Start or Edit form (purchase order number, value, supplier registration, invoicing details) and the Draw down form with amount and note
Analytics
App API
MCP target
Validation
These routes read and save the client's procurement record for an engagement, with the remaining purchase order headroom computed on each response, and draw the purchase order down. The first draw that crosses the warning threshold raises a high commercial risk on the engagement RAID register, once only. Workspace owners, admins, and members may use them; guests are refused with 403. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Set approval bands and preview who must approve a value
GuardedEngagement Commercials tab, Authority panel: Add band form (subject, threshold, approver, second approver) and the Preview chain form with subject and value
Analytics
App API
MCP target
Validation
These routes list the delegation of authority bands that apply to an engagement, including workspace-wide bands, add a band, and derive the approval chain a given value would need so it can be seen before anything is raised. Workspace owners, admins, and members may list and preview; only owners and admins may add a band, and others are refused with 403. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Add a subcontractor to an engagement
GuardedEngagement People tab, Team panel: Subcontractors list and the add form with name, company, and contract status
Analytics
App API
MCP target
Validation
These routes list the subcontractors delivering on an engagement and add one, recording contract status, rates, insurance and NDA dates, and whether flow-down clauses are confirmed. Workspace owners, admins, and members may list; only owners and admins may add, and others are refused with 403. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Record the legal instruments an engagement rests on
GuardedEngagement Acceptance tab, Instruments panel: kind, status, and required controls with the Record button
Analytics
App API
MCP target
Validation
These routes list the contracts and other legal instruments recorded on an engagement and create or update one per kind, with its status, dates, signatories, and governing law. Workspace owners, admins, and members may use them; guests are refused with 403, and an engagement hidden from the caller returns 404. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Control how a deliverable is handled, released, and recalled
GuardedEngagement Working papers tab, Document handling panel: Add and Edit form, Verify redaction, Confirm insider entry, Release, and Recall with a reason
Analytics
App API
MCP target
Validation
These routes keep the handling record for each deliverable version: classification, distribution limits, redaction and metadata scrubbing, and inside information flags, and they list each record with the blockers that would stop its release. Release and recall are written to the audit log, and a recalled document keeps its release date so the record shows it went out. Owners, admins, and members may list, save, verify, release, and recall; only owners and admins may confirm an insider list entry. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Read the suspicious activity reports filed on an engagement
GuardedEngagement Screening tab: suspicious activity section with the filed reports, shown only to the appointed reporting officer
Analytics
App API
MCP target
Validation
This route returns the suspicious activity reports filed against checks on an engagement, with each check, kind, reference, and filing date. It answers every permitted reader in the same shape so the screen cannot tip anybody off: a reader who is not the appointed officer is told so and given an empty list. Workspace owners, admins, and members may call it with the delivery:read token scope; guests are refused with 403, and the route sits behind the Client Delivery entitlement.
Define the escalation ladder for an engagement
GuardedEngagement Ways of working tab: escalation ladder with the add rung form (level, description, trigger, response time)
Analytics
App API
MCP target
Validation
These routes list the engagement's escalation ladder, lowest level first, and add a rung naming who on the firm and client side it goes to and how quickly a response is due. Workspace owners, admins, and members may use them; guests are refused with 403, and an engagement hidden from the caller returns 404. The routes need the delivery:read or delivery:write token scope and sit behind the Client Delivery entitlement.
Build and edit the engagement plan
GuardedEngagement workspace Plan tab: add item form with kind picker, edit item dialog (title, dates, duration, percent complete), row move up and down, row delete, convert row to task, adopt tasks dialog, bulk select with shift by days, Gantt and card views, and the plan export button
Analytics
App API
MCP target
Validation
These routes read and write the rows of an engagement plan: list, create, edit, delete and reorder rows, adopt existing project tasks into the plan, turn a plan row into a project task, shift many rows by a number of days, and read the plan as a Gantt view or as an export. Callers need the client-delivery module entitlement, a workspace role of OWNER, ADMIN or MEMBER, and module access of view, create, update or delete to match the action; a token needs the delivery:read scope to read and delivery:write to change anything. An engagement in another workspace, or one the caller is held off by an information barrier or by restricted access without a grant, answers 404, and converting a row to a task is refused when the call carries no user.
Link plan items and reschedule the plan
GuardedEngagement workspace Plan tab: dependencies panel (from, to, type, lag, hard link, check, create, delete), critical path filter, float ceiling filter, recompute button, and the replan panel with reschedule and level preview and apply
Analytics
App API
MCP target
Validation
These routes manage the links between plan items and the schedule computed from them: list, add, edit, check and remove dependencies, read the critical path and each row's float, recompute the critical path, and propose or apply a reschedule or a resource levelling pass. Reads need module view access and the delivery:read scope, and changes need module update or delete access and the delivery:write scope, all behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. The critical path read never recomputes, a dependency that does not exist on the engagement answers 404, and an engagement the caller cannot see answers 404.
Capture plan baselines and track milestone slip
GuardedEngagement workspace Plan tab: baselines panel (open a baseline, set current with a reason, delete with confirmation), variance figures on the plan cards, and the milestone trend panel with its capture button
Analytics
App API
MCP target
Validation
These routes freeze a copy of the plan as a baseline, choose which baseline the variance figures are measured from, compare the live plan against the current baseline or a named one, and record and read the milestone trend that shows how forecast dates moved over time. Reads need module view access and the delivery:read scope; capture, set current and trend capture need update access and delivery:write, and delete needs delete access, all behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. Capturing a baseline and changing the current one each write an audit record, and an engagement the caller cannot see answers 404.
Set up phases and workstreams and decide phase gates
GuardedEngagement overview lifecycle panel: phase gates list with pass and fail buttons, gate reason field and confirm; Workstreams tab: add workstream form (key and name) and the workstream register
Analytics
App API
MCP target
Validation
These routes list and create the phases and workstreams that structure an engagement, and record a pass or fail decision on a phase gate. Reads need module view access and the delivery:read scope, creates need create access and decisions need update access with the delivery:write scope, all behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. A duplicate key is refused, a phase that does not belong to the engagement answers 404, and an engagement the caller cannot see answers 404.
Record engagement objectives and scope statements
GuardedEngagement workspace Scope tab: objectives list with the add objective form (statement, success measure, baseline and target values) and the scope register with in scope and out of scope statement forms
Analytics
App API
MCP target
Validation
These routes list and add the objectives an engagement commits to and the statements of what is in and out of its scope. Reads need module view access and the delivery:read scope, and adding needs create access and the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. An engagement in another workspace or one the caller is held off from answers 404.
Agree the engagement ways of working
GuardedEngagement workspace Ways of working tab: the ways of working form with one field per convention, the client visible switch, the agreed switch, and the save button
Analytics
App API
MCP target
Validation
These routes read the single ways of working record for an engagement and create or replace it in one write. Reading needs module view access and the delivery:read scope, and writing needs update access and the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. An engagement the caller cannot see answers 404.
Log and manage risks, assumptions, issues, dependencies and decisions
GuardedEngagement workspace RAID tab: kind facets and search, add item form, bulk add rows, manage panel per item (owner, save, status buttons, score grid, review, escalate, resolve, void, remove), review mode with bulk review, item history panel, and load more
Analytics
App API
MCP target
Validation
These routes run an engagement RAID register: list and read items, raise one or many, edit, move through working statuses, rescore, review, resolve, void, escalate and remove them, and read each item's event history. Reads need module view access and the delivery:read scope, raising needs create access, removal needs delete access and every other change needs update access with the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. Each change writes an entry in the item's event log, and an item or engagement the caller cannot see answers 404.
Convert, share, or import RAID items
GuardedEngagement workspace RAID tab: convert menu per item (to another kind, to a task, to a change request), share with client and withdraw with reason, and the import from project panel with the include closed switch
Analytics
App API
MCP target
Validation
These routes move RAID items out of the register or across its boundary: convert an item to another kind while keeping the original as superseded, turn it into a project task or a change request, disclose it to the client and withdraw it, and seed the register from the linked project risk log. Kind conversion, sharing and withdrawal need module update access, while task, change request and import need create access, all with the delivery:write scope behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. Sharing is the only path by which a RAID item reaches the client audience, and both sharing and withdrawal write an audit record and an event on the item.
Review RAID heat map, ageing, due reviews and export
GuardedEngagement workspace RAID tab: summary tiles, heat map with cells by probability and impact, insights panel with ageing by kind, review mode window for due reviews, and the engagement export menu for the RAID log
Analytics
App API
MCP target
Validation
These routes read the register as numbers and documents: the summary tiles, the probability by impact heat map, how long open items have been open, which items are past or near their review date, and the RAID log as a downloadable document. The four reads need module view access and the export needs module export access, all with the delivery:read scope behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. An unsupported format is refused with 400, and an engagement the caller cannot see answers 404.
Assign, publish and acknowledge the responsibility matrix
GuardedEngagement workspace Responsibilities tab: matrix grid with letter cells and notes, coverage add subject, party picker, remove party, decision model switch, playbook apply, validate and violations only filter, publish, acknowledge, and export
Analytics
App API
MCP target
Validation
These routes keep the engagement accountability matrix: list cells with their rule findings, assign, edit and remove cells one at a time or in bulk, list the subjects and parties the matrix can name, validate it, publish it as agreed, let each named person acknowledge their part, apply a playbook matrix, switch the decision model, and export the matrix as a document. Reads and acknowledgement need module view access and the delivery:read scope; every other change needs update access and the delivery:write scope, all behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. A cell or engagement the caller cannot see answers 404, and acknowledgement on behalf of another person is refused with 403.
Manage areas of responsibility and fill their seats
GuardedEngagement workspace Responsibilities tab: responsibility cards with new area form (key and label), rename, move up and down, remove, assign and unassign, and the fill seats button with its result
Analytics
App API
MCP target
Validation
These routes list the areas of responsibility on an engagement with who holds each, create, rename, reorder and remove areas, and fill the seats a playbook intended from the people now on the engagement. Listing needs module view access and the delivery:read scope; every change needs update access and the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. Removal is a soft delete that writes an audit record, filling seats runs only when asked and reports what it did, and an engagement the caller cannot see answers 404.
Build the hypothesis tree and run analyses
GuardedEngagement workspace Structuring tab: issue tree with add question or hypothesis, reword, move, and conclude per node; analyses panel with add, edit, start, block with reason, and complete with finding and so what
Analytics
App API
MCP target
Validation
These routes keep the problem structure of an engagement: list, add, reword, move and conclude questions and hypotheses, read them as a tree, and list, add, edit, start, block and complete the analyses that test them. Reads need module view access and the delivery:read scope, adding needs create access and other changes need update access with the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. A hypothesis, analysis or engagement the caller cannot see answers 404.
Record interviews and sources and shape the storyline
GuardedEngagement workspace Structuring tab: interviews panel with add, record consent, and complete; sources panel with cite, reliability and credibility grading, retract, and corroborates or contradicts picks; storyline panel with add page, governing thought edit, move up and down, status, and mark evidenced
Analytics
App API
MCP target
Validation
These routes hold the evidence behind an engagement: interviews with their consent and write-up, sources with their reliability grades and the sources that corroborate or contradict them, and the storyline pages the final answer is told through. Reads need module view access and the delivery:read scope, adding needs create access and other changes need update access with the delivery:write scope, behind the client-delivery module entitlement and a workspace role of OWNER, ADMIN or MEMBER. Grading and triangulating a source write an audit record, and an interview, source, section or engagement the caller cannot see answers 404.
Raise and maintain the information request list on an engagement
GuardedEngagement workspace Requests tab: outstanding, overdue, blocking, with-client and with-us summary tiles, status filters, raise request form with category and line items, raise from a playbook template, request detail panel with edit form, add line and line received toggle, attach an engagement file, and delete a draft request
Analytics
App API
MCP target
Validation
These routes raise information requests on one engagement, singly, in bulk, or by copying the information request section of a playbook, and they read the register, its chase board counts, the overdue list, each request with its lines, and the files linked to it. Workspace members with the OWNER, ADMIN, or MEMBER role can call them when the workspace holds the Client Delivery entitlement; reads need the delivery read scope and view access, writes need the delivery write scope and create, update, or delete access, and a portal guest is refused. An engagement behind an information barrier or restricted to named grants answers 404, as does a request, line, or attachment that is not on that engagement. Raising, deleting, bulk raising, and copying from a template each write an audit record.
Send, chase, and settle an information request
GuardedEngagement workspace Requests tab detail panel: send to client, remind, escalate to a level, accept, reject with a reason, mark partially received, mark not applicable, and withdraw with a reason
Analytics
App API
MCP target
Validation
These routes move one information request through its chase loop: send it to the client, remind, escalate up the engagement escalation path, and accept, reject, mark partial, mark not applicable, or withdraw what came back. Sending, reminding, and rejecting notify the client contact, escalating notifies the firm user on that level and adds an internal timeline entry, and each move except remind writes an audit record. The submit and review routes record a client submission and its review outcome on the firm side and have no control on the screen. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, the delivery write scope, and update access; a request or engagement the caller cannot see returns 404.
Track a deliverable through its stages to client sign-off
GuardedEngagement workspace Deliverables tab: deliverable register with load more and add deliverable form; deliverable detail page with advance stage buttons, acceptance blockers, acceptance criteria add, assess, and waive forms, capture version, request sign-off form with lapse period, and acceptance certificate download
Analytics
App API
MCP target
Validation
These routes keep the deliverable register for one engagement: create a deliverable with its acceptance criteria, capture numbered versions, assess or waive each criterion, request a client sign-off with a deemed acceptance date, record the signature, and move the deliverable through its review stages to acceptance. Stage changes write an audit record and a signature is stored with a timeline entry the client can see. Recording the signature itself has no control on the internal screen and is reached through the API. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, and the delivery read or write scope, and a deliverable, criterion, or sign-off not on that engagement returns 404.
Review a deliverable and clear its review notes
GuardedDeliverable detail page review panel: review rounds, record verdict form with outcome and comments, review checklist with YES, NO, and NA answers, and confirm review notes cleared
Analytics
App API
MCP target
Validation
These routes run review rounds on one deliverable: open a round for a review gate, record the reviewer verdict, keep a question checklist for the round, answer it, and confirm that the review notes are cleared, which records who confirmed and when. Opening a round and setting its checklist questions are reached through the API; the screen reads the rounds, records verdicts, answers questions, and confirms clearance. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, and the delivery read or write scope with view or update access. An engagement the caller cannot see, a deliverable on another engagement, and a review on another deliverable all return 404.
Raise, assess, and decide a change request
GuardedEngagement workspace Changes tab: change register with status filter, add change form with urgency, cumulative drift panel; change detail page with edit form, assess impact form, add approver form, approval decision form, submit, start review, withdraw, defer, implement, share with client, unshare, and delete
Analytics
App API
MCP target
Validation
These routes keep the change control register for one engagement: raise a change, assess its impact, submit it, send it to review, collect approver decisions, and withdraw, defer, or mark an approved change implemented. When the approval chain closes the decision applies its effect together with the change status, and the drift read recomputes cumulative cost, schedule, and scope change against the baseline and raises one steering review item when the workspace threshold is crossed. Sharing with the client and unsharing are the only paths that change the disclosure and each writes an audit record and an internal timeline entry. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, and the delivery read or write scope; a change or engagement the caller cannot see returns 404.
Compose, approve, and issue an engagement status report
GuardedEngagement workspace Status tab: report list with load more and open report; compose page with period start and end, RAG lights, movement note, since last report panel, refresh figures, preview pane, sections, submit, approve, reject with reason, issue, supersede, share with client, unshare, recipients with add by email, and distribute with confirmation
Analytics
App API
MCP target
Validation
These routes produce the periodic status report for one engagement: generate a draft prefilled from the previous report and current signals, edit its lights, narrative, and sections, refresh its figures, and move it through submit, approve or reject, and issue, or supersede it with a revised draft. Distribute records each unsent recipient as sent and returns the sent and skipped counts. Issuing adds a timeline entry, each status move and distribution writes an audit record, and sharing with the client is a separate, audited step. The plain create route and the delete route are reached through the API; the screen uses the draft generator. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, and the delivery read or write scope; a report or section not on that engagement returns 404.
Run client acceptance checks and decide whether to take on an engagement
GuardedEngagement workspace Acceptance tab: open acceptance file form, readiness blockers, check list with record result and waive forms, compliance terms, suspicious activity report for the reporting officer, start review, record the quality review, and decision form with conditions
Analytics
App API
MCP target
Validation
These routes hold the client acceptance file for one engagement: opening it creates the screening checks its risk tier requires, results and waivers are recorded per check, and the decision accepts, accepts with conditions, or declines, with a timeline entry for every decision. Readiness returns every blocker at once, computed from what the reader may see. Members with OWNER, ADMIN, or MEMBER can read and record results, while only OWNER and ADMIN can decide, waive, or record the quality review, and only the appointed reporting officer can file a suspicious activity report; check rows mask that filing from everyone else. Editing the file and adding a check by hand are reached through the API. Every route needs the Client Delivery entitlement and the delivery scope, and an engagement or check the caller cannot see returns 404.
Assemble, lock, and retain the working paper file
GuardedEngagement workspace Working papers tab: open file, add paper, prepare and review a paper with review method, lock blockers, clear review notes with confirmation, lock, verify integrity, legal hold and release, regulator access record, and destroy with typed confirmation
Analytics
App API
MCP target
Validation
These routes keep the working paper file for one engagement: open it with its assembly standard and retention period, add, prepare, and review papers, confirm review notes are cleared, and lock the file with an integrity seal that the verify route recomputes and records. Legal holds, regulator access, post-lock additions, and destruction are each recorded with an audit entry, and a legal hold always blocks destruction. Updating file settings is reached through the API. Members with OWNER, ADMIN, or MEMBER can read the file and add, prepare, and review papers, while only OWNER and ADMIN can perform the custody actions; every route needs the Client Delivery entitlement and the delivery scope, and an engagement or paper the caller cannot see returns 404.
Download an engagement export
GuardedEngagement workspace header export menu: artifact picker, deliverable picker for single-record exports, internal or client edition, and download button that waits for a large export to finish
Analytics
App API
MCP target
Validation
These routes list the export catalogue, render an artifact for one engagement in the requested format and edition, and run larger renders as background jobs that the requester polls and downloads once through a short-lived link. Requesting a job needs export access and writes an audit record. Listing jobs and requesting one directly are reached through the API; the screen polls the job and downloads it when the direct render is routed to a job. Callers need the OWNER, ADMIN, or MEMBER role, the Client Delivery entitlement, and the delivery read or write scope, and an engagement the caller cannot see is refused before any job is written, listed, read, or downloaded. The job list returns the requester's 25 most recent jobs on this engagement only.
Track independence, partner rotation, and non-audit fee caps on an engagement
LiveEngagement workspace Closure tab: independence declaration list with gap flags, rotation register with the add-person form (person, rule, role, first year, years served), non-audit service register form (description, rationale, pre-approval reference, fee, currency), and the fee-cap position panel with audit fee and public interest entity inputs
Analytics
App API
MCP target
Validation
These routes keep the independence record for an engagement: independence declarations, the partner rotation register for a client with its rule catalogue, and the register of non-audit services that feeds the fee-cap position. Only workspace owners, admins, and members may call them, checked both by the route guard and again in the service, so a client portal guest is refused. The Closure tab reads declarations and the rotation register and records rotation entries and non-audit services; recording a new declaration is available through the API only. A breach flagged without detail, an unknown rotation rule, and a blank non-audit description are refused. Every engagement-keyed route first checks that the caller may see the engagement, and a rotation entry naming a client account outside the workspace is refused.
Run the engagement quality review and settle differences of opinion before dating the report
LiveEngagement workspace Closure tab: quality reviewer appointment with trigger reason, unresolved matters count and save, complete review button, difference of opinion raise and resolve forms, and the report dating verdict with every refusal listed
Analytics
App API
MCP target
Validation
These routes run the engagement quality review: appoint a reviewer, record how many matters remain unresolved, complete the review, raise and resolve differences of opinion, and read every reason the report cannot be dated yet in one call. Only workspace owners, admins, and members may call them; a client portal guest is refused at the route and again in the service. The service refuses an appointment where the engagement partner appoints or reviews their own engagement, refuses completion while matters are unresolved or once the report date has passed, and returns 404 for a review or difference from another engagement or workspace. Resolved differences stay in the register as the record that they happened.
Chase actions and people with follow-ups on an engagement
LiveEngagement workspace Follow-ups tab: add follow-up form (kind, title, due date, lead time), the list of follow-ups with acknowledge, complete, pause, snooze, and cancel actions, the due and mine views, and the automatic rule toggles
Analytics
App API
MCP target
Validation
These routes create, list, edit, and act on follow-ups that chase an action or a person on an engagement, including what is due soon and what the caller personally owes. Only workspace owners, admins, and members may call them, with the client-delivery view, create, update, or delete permission for each action, and a token needs delivery:read or delivery:write. DELETE cancels the follow-up rather than removing it, so the record that a chase was called off remains. The runs route is read only, because delivery records are written by the background sender. The service refuses an engagement the caller cannot see behind an information barrier, a follow-up from another engagement, a snooze into the past, and any change to a closed follow-up. The background sender asks whether each recipient may see the engagement before it emails them, notifies them in the app, or tells them about an escalation; a recipient who may not is skipped, and the run records the skip.
Collect client feedback and handle complaints on an engagement
LiveEngagement workspace Client voice tab: request feedback form (kind, respondent, anonymous), record response form (score, verbatim), consent to quote and reference toggles, follow-up complete action, quotable verbatims list, and the complaint register with raise, acknowledge, resolve, close, and escalate actions
Analytics
App API
MCP target
Validation
These routes record what the client says: feedback requests and responses with consent to quote, the list of poor responses still owed a follow-up call, and the complaint register from raising to closing. Only workspace owners, admins, and members may call them, with the client-delivery view, create, or update permission, and a token needs delivery:read or delivery:write; there is no client portal counterpart. The quotable list leaves out the respondent label for anonymous respondents. The service checks that the engagement is visible to the caller, enforces the acknowledge, resolve, close order, and refuses changes to a closed complaint.
Staff an engagement and plan its handover to the client team
LiveEngagement workspace People tab: raise staffing request form (role, grade, allocation, key personnel, client approval), propose, confirm, record client approval, and decline actions, the weekly capacity view, and the transition panel with knowledge transfer completion and open defects
Analytics
App API
MCP target
Validation
These routes raise and progress staffing requests for an engagement, report planned capacity for a week after ramp-up, and keep the single transition plan that hands the work to the client team. Only workspace owners, admins, and members may call them, with the client-delivery view, create, or update permission, and a token needs delivery:read or delivery:write. PUT on the transition plan edits the one plan for the engagement rather than adding another. The service refuses confirmation without a proposed person or a required client approval, refuses a proposal the export control check rules out, and refuses invalid hypercare or warranty windows. Every route first checks that the caller may see the engagement.
Request, approve, and record expert network calls on an engagement
LiveEngagement workspace Expert calls tab: request form (network, expert reference, topic, justification, compliance flags), approve with chaperone, record as held, flag an incident with a reason, and the compliance review of open incidents
Analytics
App API
MCP target
Validation
These routes keep the register of expert network calls for an engagement: request a call, edit it, have somebody else approve it, record it as held, flag an incident where material non-public information came up, and record the compliance review of that incident. Callers need the client-delivery view, create, or update permission, and the service allows only workspace owners, admins, and members, so a client portal guest is refused; a token needs delivery:read or delivery:write. The service refuses self-approval, approval after the call, holding an unapproved call, a flagged call without a chaperone, direct payment, and a fifth held call with the same expert in a year.
Raise information barriers, approve wall crossings, and keep the insider list
LiveEngagement workspace Barriers tab: raise barrier form (type, code name, reason), wall crossing form with purpose, close crossing action, insider list with add form (name, function and reason) and notified and acknowledged steps
Analytics
App API
MCP target
Validation
These routes raise information barriers on an engagement, record who is let through a barrier and on whose authority, close crossings, keep the insider list with its separate notification and acknowledgement steps, and return the name a caller is entitled to see. Only workspace owners, admins, and members may call them, with the client-delivery view, create, or update permission, and a token needs delivery:read or delivery:write; a client portal guest is refused. A member excluded by an active barrier on the engagement, without an open crossing, cannot read or administer that barrier and receives the same 404 as for an engagement that does not exist. Crossings are append-only, cannot be recorded by the person crossing, and must be approved by a workspace owner or administrator other than that person. The service refuses side conflicts, crossings on an inactive barrier, unnamed insiders, and out-of-order acknowledgements.
Draft status reports, minutes, and register items with the engagement assistant
ConfiguredEngagement workspace Assistant tab: propose a status report draft, minutes from a meeting, RAID items from meetings, a deliverable pre-check, or a health explanation; pick the parts to keep and accept or decline the proposal, with provenance shown beside it
Analytics
App API
MCP target
Validation
These routes ask the configured model provider for drafts on an engagement and keep each proposal until a person decides it: status report prose, meeting minutes, proposed RAID items, a deliverable pre-check against its acceptance criteria, and an explanation of the health score. Only workspace owners, admins, and members may call them; producing a draft needs the client-delivery create permission because it spends the AI budget, and accepting or rejecting needs update, with a token carrying delivery:read or delivery:write. Accept is the only route that lets model output reach a register, and it writes only the keys named. The service refuses drafts without a configured provider or budget, and refuses a second decision on a draft that is already decided.
Harvest reusable assets from an engagement and clear them for reuse
LiveEngagement workspace Assets tab: harvest form (kind, title, description, client consent required), sanitise, record consent, and reuse actions on each asset
Analytics
App API
MCP target
Validation
These routes harvest reusable assets such as templates, models, and case studies from an engagement, mark them sanitised, record client consent, and record a reuse. Only workspace owners, admins, and members may call them, with the client-delivery view, create, or update permission, and a token needs delivery:read or delivery:write. The service refuses reuse of an asset that has not been sanitised or that needs client consent which is not on record, and refuses an asset from another engagement. Every route first checks that the caller may see the engagement.
Record the benefits an engagement delivers and take readings against them
LiveEngagement workspace Benefits tab: record benefit form (type, name, measure, unit, baseline, target, attribution, double-count note) and the take reading form (date, value, source)
Analytics
App API
MCP target
Validation
These routes keep the benefits register for an engagement: record each benefit with its baseline, target, and attribution, and take dated readings against it. Only workspace owners, admins, and members may call them, with the client-delivery view or create permission, and a token needs delivery:read or delivery:write. The service refuses an attribution outside 0 to 100 percent, a partial attribution without a note on where the rest is claimed, an unparseable reading date, and a benefit from another engagement. Every route first checks that the caller may see the engagement.
Record sanctions screening and beneficial owners for client acceptance
LiveEngagement workspace Screening tab: record screening form (subject, lists, provider, monitoring), hit disposition with rationale, second-person approval of true matches, beneficial owner form (name, control type, ownership percent, status), report discrepancy action, and the ownership assessment
Analytics
App API
MCP target
Validation
These routes record sanctions and watch-list screening runs for client acceptance, disposition each hit with a reason, take a second-person approval of true matches, and keep the beneficial owners behind the client entity with an ownership assessment per acceptance check. Only workspace owners, admins, and members may call them, with the client-delivery view, create, or update permission, and a token needs delivery:read or delivery:write. The routes record the results of a screen; they do not query a screening provider themselves. The service refuses a run with no lists named, a disposition without a rationale, self-approval of a true match, and records from another engagement.
Keep the inventory of analytical models built on an engagement and approve them for use
LiveEngagement workspace Models tab: record model form (name, type, tier), validation result with findings, approve for stated purposes, retire, and the include retired toggle
Analytics
App API
MCP target
Validation
These routes keep the inventory of analytical models built on an engagement: record and edit a model, record its validation, approve it for named purposes, retire it, and list the models still waiting on validation. Callers need the client-delivery view, create, or update permission, and the service allows only workspace owners, admins, and members; a token needs delivery:read or delivery:write. The service refuses approval with no stated purpose, approval of a retired or unvalidated model, approval of an LLM-based model without hallucination controls, and a tier 1 model whose developer validates their own work.
Record, validate, and invalidate the analytical and pricing assumptions on an engagement
LiveEngagement workspace Assumptions tab: analytical assumption form (statement, variable, basis, expiry, deliverable), Validate, Revise basis, Invalidate, pricing assumption form, and Record breach with the reality and commercial impact
Analytics
App API
MCP target
Validation
These routes keep the analytical assumptions behind the firm's models and the pricing assumptions behind its fee. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access to read and create or update access to write, through a token carrying delivery:read or delivery:write. Assumptions are never deleted: a premise is corrected through the patch, which changes only basis, disclosure, and expiry, or recorded as invalid. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Issue reliance letters and accept reliance on a specialist for an engagement
LiveEngagement workspace Reliance tab: reliance letter form (relying party, relationship, cap, aggregate cap), Issue letter, aggregate exposure figure, specialist reliance form (type, identity, evaluation), and Accept specialist
Analytics
App API
MCP target
Validation
These routes record reliance letters the firm issues to third parties, add up the exposure across issued letters, and record the firm's own reliance on outside specialists. Callers need client delivery view access to read, create access to record, and update access to issue or accept, with the delivery:read or delivery:write scope; the service admits workspace owners, admins, and members only. Caps are summed exactly in minor units before a letter is issued. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Model team ramp curves and certify the return or destruction of client data
LiveEngagement workspace Disposition tab: ramp profile form (curve type, weekly productivity, handover billable), effective allocation by week, data disposition form (dataset, client instruction, locations), and Certify destruction with method and backups scope
Analytics
App API
MCP target
Validation
These routes record how productive a team member is week by week on an engagement and what must happen to each client dataset when the work ends. The outstanding list returns every RETURN or DESTROY instruction not yet done. Callers need client delivery view, create, or update access and the delivery:read or delivery:write scope, and the service admits workspace owners, admins, and members only. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Review benchmark exhibits for competition law before they reach a deliverable
LiveEngagement workspace Structuring tab: benchmarks panel with the unreviewed count, per-benchmark review button, review note field, and Submit review
Analytics
App API
MCP target
Validation
These routes list the benchmark register for an engagement and record the competition-law review that clears a benchmark for disclosure. Reading needs client delivery view access and the delivery:read scope; recording a review needs admin access, the delivery:write scope, and the OWNER or ADMIN workspace role. A benchmark that does not belong to the engagement returns 404, and an engagement the caller cannot see returns the module 404.
Engagement benchmark register API
LiveREST API with a personal access token that carries the delivery:write scope
Analytics
App API
MCP target
Validation
These routes create, edit, attach, detach, and retire benchmark exhibits on an engagement; no screen calls them yet. Creating needs client delivery create access, editing, attaching, and detaching need update access, and removing needs delete access, each with the delivery:write scope and the OWNER, ADMIN, or MEMBER workspace role. Detaching needs no review because it can only reduce what is disclosed. A benchmark or engagement the caller cannot reach returns 404.
Record the sales handoff and accept, query, or return it to sales
LiveEngagement workspace Handoff tab: Start handoff, sold scope and commitments form, Submit for review, Request information with detail, Return to sales with reason and renegotiation flag, and Accept handoff
Analytics
App API
MCP target
Validation
These routes hold the one sales-to-delivery handoff record per engagement and move it through review. Accepting it seeds the pricing assumptions register, RAID risks from the pursuit, staffing requests from the sold team shape, and RAID assumptions from verbal commitments, which is why it happens exactly once. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view or update access, or admin access for accept, and the delivery:read or delivery:write scope. Reading an engagement with no handoff returns null, and acting on a handoff that was never recorded returns 404.
Import engagements, contacts, RAID items, plan items, or stakeholders from a spreadsheet
LiveDelivery Imports screen and the engagement Imports tab: import wizard with target choice, file input, column mapping, Create missing accounts, Dry run, Preview, and Commit
Analytics
App API
MCP target
Validation
These routes describe the import targets, read an uploaded workbook or separated text file, preview what an import would write, and commit it (or, with dryRun, stop after reporting). Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access for the targets and create access for the rest, under the delivery:read or delivery:write scope. Preview writes only an audit record. An engagement the caller cannot see returns 404, and an unreadable or oversized file is refused with a plain explanation.
Carry the stakeholders and team from a linked project into an engagement
LiveEngagement workspace Imports tab: Stakeholders and Team checkboxes, Dry run, and Carry across
Analytics
App API
MCP target
Validation
This route reads the delivery project linked to an engagement and copies its stakeholders, its team, or both onto the engagement. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery create access and the delivery:write scope. It refuses an engagement with no linked project, a linked project that no longer exists, and an engagement the caller cannot see (404).
Work through the closure checklist on an engagement
LiveEngagement workspace Closure tab: closure items panel with Seed checklist, Complete, Waive with reason and confirm, Reopen, and derived item markers
Analytics
App API
MCP target
Validation
These routes create the default closure checklist for an engagement and move its items between pending, complete, and waived. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view, create, or update access and the delivery:read or delivery:write scope. An item that is not on this engagement returns 404. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
File a lesson learned on an engagement and publish it to the firm
LiveEngagement workspace Closure tab: lessons panel with File lesson, title, category, severity, and applicability fields, Submit, and Publish
Analytics
App API
MCP target
Validation
These routes list and file lessons learned on an engagement and publish a lesson for use across the firm. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view, create, or update access and the delivery:read or delivery:write scope. Every route first checks that the caller may see the engagement, and publishing a lesson that is not on the engagement returns 404.
Record the tax position and permanent establishment watches for an engagement
LiveEngagement workspace Tax tab: tax profile form (value added tax treatment, withholding, gross-up), Save profile, permanent establishment watch form (jurisdiction, threshold, alert), and Save watch
Analytics
App API
MCP target
Validation
These routes read and replace the tax profile of an engagement and the permanent establishment watch for each jurisdiction. The watch list derives the on-site day count from the time entries recorded against the engagement and flags alerting and breached watches. Callers need client delivery view or update access and the delivery:read or delivery:write scope, and the service admits workspace owners, admins, and members only. An engagement the caller cannot see returns 404.
Track the contract obligations on an engagement and mark them met, breached, or waived
LiveEngagement workspace Obligations tab: obligation form (instrument, clause reference, text, type, due pattern, evidence required, owner role), Record, Mark met, Mark breached, Mark waived with reason, and next due date
Analytics
App API
MCP target
Validation
These routes keep the register of what the engagement contracts oblige the team to do, with an owner, a due date, and evidence. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view, create, or update access and the delivery:read or delivery:write scope. An obligation or instrument that is not on this engagement returns 404, and an engagement the caller cannot see returns the module 404.
Record the commercial terms of an engagement contract
LiveEngagement workspace Obligations tab: commercial terms panel with term type, clause reference, Record term, Remove term, and due date
Analytics
App API
MCP target
Validation
These routes list, record, and remove the commercial terms the firm has read from an engagement contract. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access to read, update access to record, and delete access to remove, under the delivery:read or delivery:write scope. An engagement the caller cannot see returns 404.
Fill in the workspace custom fields on an engagement
LiveEngagement workspace Custom fields tab: one input per field the workspace defines for engagements, and Save
Analytics
App API
MCP target
Validation
These routes read the custom field definitions and values for an engagement and save new values. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view or update access and the delivery:read or delivery:write scope. Each save is audited with the field keys it changed. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Record an approval decision on a deliverable or other engagement record
LiveDeliverable detail inside the engagement workspace: approval trail panel with the decision history, current position, and Record approval
Analytics
App API
MCP target
Validation
These routes append an approval decision to an engagement record and read back its history together with its current approval position. Recording needs client delivery create access, the delivery:write scope, and the OWNER, ADMIN, or MEMBER workspace role; reading needs view access and delivery:read. Approvals are append only: no route edits or removes one. A subject that is not on the engagement returns 404.
Read the activity timeline of an engagement
LiveEngagement workspace Timeline tab: facet filters, timeline entries, and Load more
Analytics
App API
MCP target
Validation
This route returns the engagement timeline newest first, a page at a time, with a cursor for the next page. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access and the delivery:read scope. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Read the metrics, health history, and operating model of an engagement
LiveEngagement workspace overview: metric catalogue, health history panel, operating model tabs and gates, and gate links
Analytics
App API
MCP target
Validation
These routes return the metric catalogue for one engagement (including margin, cost, and lock-up figures), its stored health readings oldest first, and the workspace shape its operating model gives it. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access and the delivery:read scope; there is no portal counterpart. An engagement in another workspace, behind an information barrier, or restricted without a grant returns the same 404 as one that does not exist.
Read the portfolio health and workload across every engagement
LiveDelivery Portfolio screen: RAG roll-up, health coverage counters, engagements by operating model, resource contention, workload, and engagement links
Analytics
App API
MCP target
Validation
This route returns the firm-wide portfolio metrics across every engagement the caller can see in the workspace, with bounded reads and a flag when a total is truncated. Workspace owners, admins, and members may call them (portal guests are refused) with client delivery view access and the delivery:read scope. An engagement is red when schedule, budget, or quality is red or health is below forty.
Client Portal
Module guide18 actions · 18 live, 0 guarded, 0 configured
Accept a client portal invitation
LiveInvitation acceptance page reached from the emailed link: sign-in prompt and retry button
Analytics
App API
MCP target
Validation
This route turns an invitation token into a portal seat: it creates a guest membership in the firm's workspace and an access grant on the one engagement, then returns the engagement and workspace ids. Any signed-in person holding the token may call it; the token is the credential. Every invalid token gets one generic answer so the route cannot be used to test which tokens exist, and a failed provisioning releases the token so the client is not locked out.
Choose an engagement and read its overview, team, milestones, status reports and commercial summary
LivePortal left sidebar with the Home, Work, Conversations, Governance, Files and People sections, the engagement switcher, the collapse and menu buttons, and the team, milestones, status reports and commercials pages with their registers and show more buttons
Analytics
App API
MCP target
Validation
These read-only routes serve the client portal: the list of engagements the signed-in person holds a seat on, and for one engagement its overview, the firm and client team, milestones, status reports shared with the client, and the contract value, approved change value and invoiced total when the firm shares them. They are for client contacts who accepted a portal invitation and now hold a guest seat; every read starts from the caller's own access grant, rows are filtered to the client audience and to the workstreams the grant covers. They refuse with a not-found answer anything the caller holds no live grant for, and expose no route for acceptance checks, internal commercials, the stakeholder map, working papers, problem structuring, lessons, the tenant directory or meeting transcripts. The RAID register is no longer denied outright: by the owner's decision of 11 October 2026 the items the firm marked client audience, client visible and not confidential are served at GET /v1/portal/engagements/{engagementId}/raid, and nothing else from the register is. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Review and sign off a deliverable in the client portal
LivePortal deliverables page and deliverable page: search, filters, open sign-off, decision buttons, comment, typed name and submit
Analytics
App API
MCP target
Validation
These routes list the deliverables shared with the client, open one by its own address, and record the client's sign-off with the typed name of the person deciding. They are for client contacts holding a live, accepted portal grant on the engagement; there is no module permission, and every call starts from the caller's own grant. Anything outside that grant answers not found, and a deliverable that is not in client review cannot be signed off. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Answer the firm's information requests in the client portal
LivePortal requests page: request and item rows, file upload, submit, and not applicable with a reason
Analytics
App API
MCP target
Validation
These routes list the firm's information requests with their items and attachments, let the client upload a file against an item through a signed upload ticket and confirm it, submit a request, or mark it not applicable with a reason. They are for client contacts holding a live, accepted portal grant on the engagement, and every call starts from that grant. Uploads need object storage to be configured for the deployment, and anything outside the grant answers not found. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Send and download documents in the client portal
LivePortal documents page: document list, send a document, show more, and download buttons on documents and attachments
Analytics
App API
MCP target
Validation
These routes list the documents shared on the engagement in both directions, let the client send a document nobody asked for through a signed upload ticket, mint a five-minute signed download link, and serve the file itself. They are for client contacts holding a live, accepted portal grant; the file route checks the signature, the expiry, the workspace, the client audience and the grant again before sending any bytes. Uploads need object storage to be configured, and any failed check answers not found without saying which check failed. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Answer a change request in the client portal
LivePortal changes page and change page: open a change, decision buttons, comment, typed name and submit
Analytics
App API
MCP target
Validation
These routes list the change requests the firm has shared with the client, open one, and record the client's answer as an approval with the typed name of the person answering. They are for client contacts holding a live, accepted portal grant on the engagement, scoped to the grant's workstreams. A change outside the grant answers not found, and a change no longer waiting for the client's answer is refused. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Read and reply to conversation threads in the client portal
LivePortal threads page: thread list, open a thread, conversation, reply box and send button
Analytics
App API
MCP target
Validation
These routes list the threads shared with the client, open one with its messages, and store the client's reply on it. They are for client contacts holding a live, accepted portal grant on the engagement, and every call starts from that grant. Threads outside the grant answer not found, and a closed thread asks the client to have their contact reopen it. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Review meetings and approve minutes in the client portal
LivePortal meetings page: meeting list, open minutes, typed name and approve button
Analytics
App API
MCP target
Validation
These routes list the engagement's meetings shared with the client and record the client's approval of a meeting's minutes with the typed name of the person approving. They are for client contacts holding a live, accepted portal grant on the engagement. Meeting transcripts have no portal route, and anything outside the grant answers not found. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Complete an action the firm assigned in the client portal
LivePortal actions page: action list, complete button with an optional note, and show more
Analytics
App API
MCP target
Validation
These routes list the follow-up actions shared with the client and mark one complete, with an optional note. They are for client contacts holding a live, accepted portal grant on the engagement. An action outside the grant answers not found, and an action that is no longer open is refused. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
Choose which portal emails to receive
LivePortal settings page: notification switches and a save button
Analytics
App API
MCP target
Validation
These routes read and change the signed-in client's own notification switches for one engagement. They are for client contacts holding a live, accepted portal grant on that engagement, and each person changes only their own preferences. An engagement outside the caller's grant answers not found. Only a signed-in browser session reaches these routes; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
See every engagement and what is waiting on you on the portfolio home
LivePortal portfolio home: figures for what is waiting on the client, a card per engagement with health, progress and next milestone, the due in the next 14 days list, and the Portfolio link in the sidebar
Analytics
App API
MCP target
Validation
This read-only route serves the portfolio home at /portal: totals of what is waiting on the client (open and overdue requests, actions due, deliverables in client review, changes awaiting a decision, minutes awaiting approval), one card per engagement with its health, percent complete, end date, next milestone and waiting counts, and a combined list of what is due in the next 14 days. It is for client contacts holding at least one accepted portal seat. Every figure is a count over rows the client could already open in a portal list; nothing is read from the firm's own health scores, margins, effort or internal due dates. A client with one engagement lands on its dashboard and a client with two or more lands here; the home is always one click away in the sidebar.
Read an engagement's dashboard and recent activity in the client portal
LivePortal engagement dashboard: waiting on you figures, progress and health, deliverables by stage, requests by age, milestones, risks, changes, threads, meetings, the latest status report, commercials when shared, due soon list, recent activity feed with load more, and print
Analytics
App API
MCP target
Validation
These read-only routes serve the engagement dashboard, the first page of an engagement in the portal: progress, overall health and its history, the next milestone with the days remaining, deliverables by stage, requests by status with their age, actions due, changes awaiting a decision with their cost and schedule effect, the latest status report summary, upcoming meetings, what is waiting on the client (the counts behind the sidebar badges), and a recent activity feed paged by time. They are for client contacts holding a live, accepted portal grant on the engagement. Nothing is read from the firm's own health scores, financial snapshots, margins, effort or internal due dates.
Chart an engagement's delivery over 30, 90 or 365 days in the client portal
LivePortal analytics page: range buttons for 30, 90 or 365 days or the whole engagement, headline figures, charts per module, and print
Analytics
App API
MCP target
Validation
This read-only route serves the engagement analytics page: deliverables accepted over time, time in client review and first-time acceptance, requests raised against submitted and their turnaround, milestones planned against actual, the cumulative cost and schedule effect of changes, health across status report periods, how quickly the firm answers client threads and how often it misses its response target, and the commercial position when the firm shares it. It is for client contacts holding a live, accepted portal grant on the engagement. The page prints cleanly and the browser's print dialog saves it as a PDF.
Find a deliverable, request, thread or document in the client portal
LivePortal top bar quick find box with its keyboard shortcut and result list
Analytics
App API
MCP target
Validation
This read-only route answers the quick find box in the portal's top bar for the open engagement. It is for client contacts holding a live, accepted portal grant on the engagement. The search text is not sent to product analytics; only the opening of a result is recorded.
Review the risks, issues and decisions the firm shared in the client portal
LivePortal risks and decisions page: figures for open, high, risks and issues, a chart by kind, search, kind and state filters, sort, and a detail panel per item
Analytics
App API
MCP target
Validation
This read-only route serves the RAID items the firm chose to show the client. The RAID register had no portal route at all until the owner's decision of 11 October 2026, which opened it for rows marked client audience, client visible and not confidential, and for nothing else; the rest of the register stays denied. It is for client contacts holding a live, accepted portal grant on the engagement.
Start a conversation with the engagement team in the client portal
LiveNew thread button on the threads page and the dashboard, and the new thread form: title, message, kind, workstream when the seat covers several, send and cancel
Analytics
App API
MCP target
Validation
This route lets a client contact open a thread with the engagement team instead of only replying to threads the firm opened. The thread is client audience and never confidential, its opening message is stored as the client's first post, it takes the firm's response target so the clock starts when the client asked, and it is addressed to the engagement manager, or else the partner, who is notified at once. It is for client contacts holding a live, accepted portal grant that may act. Only a signed-in browser session reaches this route; a personal access token or an OAuth access token is refused with 403, whatever scopes it holds.
See what changed since your last visit in the client portal
LivePortal top bar notification bell: unread count, list of recent changes, an item per change, mark all as read, and retry
Analytics
App API
MCP target
Validation
These routes serve the bell in the portal top bar: what changed on the engagement since this seat last marked it read, built from the same rows as the activity feed under the same grant, and the mark itself. Reading the bell writes nothing and notifies nobody. The page asks again every minute while the tab is in view, and marks the items read after the client has looked at the open list for a moment, or at once with Mark all as read.
Review a deliverable's versions, review rounds and sign-offs in the client portal
LiveDeliverable page review history: each issued version with its files, each client review round with its outcome and dates, and the sign-offs with their comments
Analytics
App API
MCP target
Validation
This read-only route serves the review history beside a deliverable's sign-off: every version issued to the client with its files, every client review round with its outcome and dates, and the decisions recorded by the client's own organisation with their comments. It is for client contacts holding a live, accepted portal grant on the engagement.
Incident Management
Module guide8 actions · 0 live, 7 guarded, 1 configured
Declare, update, and resolve an incident
GuardedIncidents list with row acknowledge and start review actions, Declare incident dialog with severity choice, incident workspace with stage rail, status update form, link attach field, duplicate-of picker, timeline, and report download
Analytics
App API
MCP target
Validation
These routes declare an incident (a repeated idempotency key returns the incident already declared, so a retry opens no second incident and pages nobody), read and list incidents, change status, severity, impact and resolution, acknowledge, post status updates, attach and remove links, read the timeline, download the incident report, and open a war room channel. Every route needs the Incident Management module on the workspace plan; reads need the service:read scope and the view access level, which includes guests, and writes need the service:write scope and the update access level, which excludes guests. An incident in another workspace returns 404, an illegal status change or a stale version returns 409, and a severity the workspace has not configured returns 400.
Appoint or stand down incident responders
GuardedIncident workspace responders panel: Appoint button, person picker, role choice, Cancel, and Stand down action
Analytics
App API
MCP target
Validation
Appointing gives a member a named role on an incident, and standing down releases the role while keeping who held it and when on the record rather than deleting it. The people search returns names of members of the caller's own workspace only, so the picker never downloads the whole directory. All three routes need the Incident Management module; the people search needs service:read and the view access level, and appointing or standing down needs service:write and the update access level.
Tell affected customers about an incident
GuardedStatus updates page and incident workspace customer update composer: affected customer list, Draft, Approve, and Send buttons, and the customer band
Analytics
App API
MCP target
Validation
These routes record which customer accounts or client onboardings an incident affects, then draft, edit, approve, send, or cancel the update written to them. Sending emails each targeted customer's primary contact through the shared email layer and answers with the outcome per recipient (EMAILED, NO_EMAIL, NOT_FOUND, SUPPRESSED, or FAILED) together with emailed and unreachable counts. Only customers actually handed to the email layer are stamped as notified; the update is recorded as sent, and the incident timeline and audit log name the customers who could not be reached, without their addresses. A send that can reach nobody is refused with 400 and marks nothing, so it cannot satisfy the rule that customers are told before an incident closes. Every route needs the Incident Management module; reads need service:read and the view access level, and every write, including approve and send, needs service:write and the update access level so that responders can communicate without waiting for an administrator.
Track a regulatory notification deadline
GuardedIncident workspace obligations panel with a start button per regime, and the deadlines band on the status updates page
Analytics
App API
MCP target
Validation
These routes list the notification regimes Atlas knows, start a deadline clock on an incident, list clocks on one incident or across the workspace soonest first, and restart, mark met, or waive a clock. Every route needs the Incident Management module; reads need service:read and the view access level, and starting, restarting, meeting, or waiving a clock needs service:write and the update access level. A clock or incident in another workspace returns 404, and a clock that is already settled is refused with 400.
Configure severity levels, services, and response defaults
GuardedIncident settings page: severity preset buttons, severity level editor with Save, Discard, Make default, and Retire, the response defaults form, and the service picker Create service control
Analytics
App API
MCP target
Validation
These routes read and change the workspace incident settings, the severity catalogue, and the list of services incidents and problems are filed against. Applying a preset replaces the catalogue while existing incidents keep the rank they had. Reads need the Incident Management module, service:read, and the view access level; every write needs service:write and the admin access level, because the fallback list and the severity vocabulary decide who is woken up.
Set up escalation policies and alert sources
GuardedOn-call setup panel: Create policy, Add step, escalation simulator Run button, Create alert source, and Rotate secret
Analytics
App API
MCP target
Validation
These routes build escalation ladders, ask a ladder who it would page at a chosen instant, and manage the alert sources that let an outside monitoring system raise incidents. The signing secret is returned once when a source is created or its secret rotated and is never readable again; after a rotation the previous secret keeps verifying for 24 hours. Reads and the simulation need the Incident Management module, service:read, and the view access level; every other write needs service:write and the admin access level. Deleting a source deactivates it rather than removing its history. Editing and deleting an alert source and removing a step are available through the API only.
Inbound monitoring alert endpoint
ConfiguredHTTPS POST from a monitoring system to the ingest path shown when an alert source is created, signed with that source's secret in the X-Atlas-Signature header
Analytics
App API
MCP target
Validation
This route is public, because a monitoring system has no session: it authenticates by the alert source public key in the path plus an HMAC signature over the raw body made with the source secret, and it is also covered by the global rate limiter. A firing alert declares an incident when the source has auto declare on, or records a repeat on the timeline when the incident for the same dedupe key is still open; a resolved alert records that the signal cleared and resolves the incident only when the source has auto resolve on. Unknown or acknowledged statuses are recorded and never acted on. It needs an alert source configured on the On-call page before it does anything.
Review incident response figures
GuardedService operations hub metrics section and the incidents page response band
Analytics
App API
MCP target
Validation
This route returns response figures for the workspace over a window, optionally for one service. It needs the Incident Management module, the service:read scope, and the view access level, and it reads only the caller's own workspace.
On-call
Module guide1 actions · 0 live, 1 guarded, 0 configured
Staff an on-call rotation and cover a shift
GuardedOn-call page: coverage now panel, Create schedule, rotation band, rotation editor with layer edit and remove, layer dialog with add, move, and remove member, Open override, and override removal
Analytics
App API
MCP target
Validation
These routes show who is on call now across every schedule, list schedules with their layers, preview the shift calendar with its gaps (a fortnight by default), and create schedules, layers, and overrides. They need the Incident Management module; reads need service:read and the view access level, which any member has, and every change needs service:write and the admin access level, because a rotation decides who is woken up.
Postmortems
Module guide3 actions · 0 live, 3 guarded, 0 configured
Write and publish an incident review
GuardedPostmortems list, Start review on an incident row, review editor with Add factor, Remove factor, Send for reading, Publish, Back to draft, Reopen, and report download
Analytics
App API
MCP target
Validation
These routes start a blameless review for an incident, edit its narrative, record contributing factors, move it through draft, in review, and published, and download it as a report. They need the Incident Management module; reads need service:read and the view access level, and writes need service:write and the update access level. A review or incident in another workspace returns 404.
Track follow-up actions from incident reviews
GuardedReview editor Add action control, action item Edit and Done buttons, Convert to task, and the follow-up queue on the Postmortems page
Analytics
App API
MCP target
Validation
These routes add action items to a review, update their owner, status, and due date, list the follow-up queue across every review, and file an item as a real task in a project. They need the Incident Management module; reads need service:read and the view access level, and writes need service:write and the update access level. An item or project in another workspace returns 404.
Record a recurring problem and its workaround
GuardedProblem register on the Postmortems page, the create problem dialog with service picker, and the problem detail Advance button
Analytics
App API
MCP target
Validation
These routes keep the problem register: the underlying causes that several incidents share, with their workaround, owner, service, and status. They need the Incident Management module; reads need service:read and the view access level, and writes need service:write and the update access level. A problem in another workspace returns 404.
Client Onboarding
Module guide6 actions · 0 live, 6 guarded, 0 configured
Start and follow a client onboarding
GuardedClient Onboarding page with the New onboarding dialog, plan tile Start buttons, the onboarding workspace timeline with Load older, and the account pack download
Analytics
App API
MCP target
Validation
These routes start an onboarding for a client from a plan, list and read onboardings, page through the onboarding timeline, and download the account pack as a report. They need the Client Onboarding module on the workspace plan, the onboarding:read or onboarding:write scope, and the view or create access level; guests are refused because only owners, admins, and members may read or change onboardings. An onboarding in another workspace returns 404.
Work through an onboarding checklist
GuardedOnboarding workspace checklist with task toggles and retry, phase rail stage advance, and the detail panel link list with open and remove
Analytics
App API
MCP target
Validation
These routes tick off checklist tasks, advance a stage once its required work is done, and attach or remove external links on an onboarding. They need the Client Onboarding module, the onboarding:write scope, and the update access level, and owners, admins, and members may call them. An onboarding in another workspace returns 404.
Client onboarding records API
GuardedREST API with a personal access token that carries the onboarding:write scope
Analytics
App API
MCP target
Validation
These routes edit, cancel, and archive an onboarding, add and bulk update checklist tasks, file a checklist item as a project task, link or unlink a delivery project, open the onboarding chat channel, and backfill onboardings for deals won earlier. They need the Client Onboarding module and the onboarding:write scope with the update access level, except archive, which needs the delete level, and backfill, which needs the admin level. An onboarding, task, or project in another workspace returns 404. No screen calls these routes today.
Browse the onboarding plan library
GuardedOnboarding plans page: category filters, search, Clear filters, Retry, and plan tiles
Analytics
App API
MCP target
Validation
This route lists the onboarding plans available to the workspace, both the built-in plans and the workspace's own, with their categories. It needs the Client Onboarding module, the onboarding:read scope, and the view access level.
Client onboarding template authoring API
GuardedREST API with a personal access token that carries the onboarding:read or onboarding:write scope
Analytics
App API
MCP target
Validation
These routes read one onboarding template and create, edit, duplicate, and delete the workspace's own templates. They need the Client Onboarding module; reading needs onboarding:read and the view access level, and writes need onboarding:write with the create, update, or delete access level as fitting, plus the owner or admin role. Deleting a template is a soft delete. No screen calls these routes today.
Configure when client onboarding starts automatically
GuardedClient onboarding settings page: switches for automatic start on deal won, agreement signed, and import, project creation, account lifecycle advance, owner notification, and external body mirroring
Analytics
App API
MCP target
Validation
These routes read and change the workspace client onboarding settings that decide when an onboarding starts on its own and what it creates. Reading needs the Client Onboarding module, onboarding:read, and the view access level; changing needs onboarding:write and the admin access level. The default template, default team, and project template settings are set through the API only.
Diagrams
Module guide14 actions · 2 live, 11 guarded, 1 configured
Create, open, rename, and organize diagrams in folders
GuardedDiagram Studio home: search box, sort menu, tabs, diagram cards with open, rename, favourite, and move actions, bulk visibility change, and the new folder form
Analytics
App API
MCP target
Validation
These routes list the diagram library, create a diagram, read one, save changes (each content change records a version snapshot and refreshes the thumbnail in the background), stream a small PNG thumbnail, and list or create folders. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. Workspace owners and admins see the whole library; other members see diagrams they own, diagrams shared with them, and diagrams with organization visibility. Editing requires the owner, an EDIT share, or a workspace owner or admin, a thumbnail is refused to a restricted viewer, and a diagram in another workspace or in the trash returns 404.
Move diagrams to the trash, restore them, archive them, or delete them forever
GuardedDiagram Studio Trash tab: restore, archive, and delete forever actions on each card, and the bulk move to trash action on the library
Analytics
App API
MCP target
Validation
Deleting a diagram moves it to the trash; restore brings it back, archive moves it out of both the library and the trash while keeping it, and purge permanently removes the diagram with its versions, shares, share links, comments, assets, search entries, and shape bindings. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. Workspace owners and admins see every trashed diagram in the workspace while other members see only the diagrams they own. Purge cannot be undone, and an id from another workspace returns 404.
Start a diagram from a template and manage workspace templates
GuardedDiagram Studio Templates tab: template search and filters, Use template, publish dialog, submit for review, approve and reject in the review queue, publish, unpublish, and delete
Analytics
App API
MCP target
Validation
These routes list built-in templates together with the workspace community gallery and the caller's own drafts, create a diagram from a template, and run the moderation flow in which a member submits a draft and a workspace owner or admin approves or rejects it. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. Approval and rejection notify the author, and every transition is written to the audit log. The review queue is refused to anyone who is not a workspace owner or admin.
Comment on a diagram and react to comments
GuardedDiagram editor comments sidebar: pinned comment threads, comment composer, reply, edit, resolve, delete, and emoji reactions
Analytics
App API
MCP target
Validation
These routes list the comments on a diagram (up to 500, oldest first), add a comment, edit or resolve it, delete it, and toggle emoji reactions. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. An @mention of a workspace member by email sends that member a notification that opens the comment. The author may delete their own comment, and anyone else needs edit permission on the diagram to delete it.
Send a diagram for review, save checkpoints, and restore earlier versions
GuardedDiagram editor review control (status menu and reviewer assignment) and version history panel with named checkpoints and restore
Analytics
App API
MCP target
Validation
These routes read and change the review state of a diagram, list its last 100 versions, save a named checkpoint of the current state, and restore an earlier version. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. A restore first snapshots the current state so the restore itself can be undone, and both restores and checkpoints are written to the audit log.
Share a diagram with teammates or through a public link
GuardedDiagram editor share dialog: people search with role picker and remove, visibility options, public link scope, expiry, password, embed tab, revoke, and rotate
Analytics
App API
MCP target
Validation
These routes list, grant, and revoke per-person roles on a diagram and create, list, and revoke public read-only or comment links. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. The raw link token is returned once on creation. Revoking a share link is idempotent, a link from another diagram returns 404, and every role change is written to the audit log.
Link shapes to Atlas records and style them with formatting rules
GuardedDiagram editor inspector data link section (record type, record search, field mapping, link and unlink) and the conditional formatting rules editor
Analytics
App API
MCP target
Validation
These routes bind diagram shapes to live Atlas records, resolve the current field values of those records, and store the conditional formatting rules the editor applies to them. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. Values are resolved through each record's own service, so a record the caller may not see comes back marked not visible instead of leaking its fields. A binding that does not belong to the diagram returns 404.
Export a diagram or render diagram code to an image
GuardedDiagram editor export dialog (format, scope, selection, frame, and slide deck export) and the diagram code panel (language, source, render, insert)
Analytics
App API
MCP target
Validation
Export renders a diagram to a downloadable file and records a diagram exported audit event; the /v1 render route returns an inline png or svg image of the diagram for embedding. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. Rendering diagram code returns an SVG for the canvas and returns 501 when the diagram rendering service is not configured for the deployment. All routes require view permission on the diagram.
Generate a diagram from a spreadsheet, the HR org chart, or the Atlas data model
GuardedDiagram Studio From your data actions (entity relationship diagram, org chart with department filter), the live org chart section, and the editor spreadsheet dialog
Analytics
App API
MCP target
Validation
These routes build a laid-out diagram document from tabular data, from the workspace HR hierarchy, or from the Atlas data model, and return it without saving it. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. The org chart reads people through the HR service so within-workspace access rules apply, and each node carries a binding to the employee record. The routes need only the diagrams read scope because nothing is persisted.
Set the workspace diagram brand kit
GuardedDiagram editor inspector brand kit section: brand colours, fonts, logo, apply to selection, and apply to all
Analytics
App API
MCP target
Validation
These routes read and update the brand colours, fonts, logo, theme preset, and enforcement flag that diagrams in the workspace use. The unprefixed routes require the Diagrams module on the workspace plan; the /v1 twins accept a personal access token that carries the matching diagrams scope. A workspace without a brand kit reads back an empty default, and each update is written to the audit log.
Draft, edit, and explain diagrams with the AI copilot
ConfiguredDiagram Studio AI start prompt and chips, and the editor copilot panel: prompt, send, stop, preview accept or reject, answer chips, import from code or image, and explain
Analytics
App API
MCP target
Validation
These routes report whether AI is available to the workspace, generate a diagram from a prompt, propose edits, run a multi-step agent that can ask questions, convert source code or an image into a diagram, explain a diagram in plain language, and search the workspace diagrams by meaning. They require a signed-in member with the diagrams read scope, and the generating routes need the diagrams write scope. Generate, edit, and agent stream progress as server-sent events and report failures in an error event; the generating, editing, import, and explain routes need a configured model provider, and the search route is not used by any screen.
Browse, search, and download shape packs from the shape library
LiveShape library page: search, category toggles, pack browser with download, resync, and remove, storage manager, and place into a new diagram
Analytics
App API
MCP target
Validation
These routes search the built-in shape and icon catalog together with the workspace custom shapes, list categories and packs with counts, and page through one pack so the browser can cache it for offline use. They require a signed-in member with the diagrams read scope. Results only ever include built-in shapes and shapes owned by the caller's workspace.
Diagram custom shapes and semantic shape search API
LiveREST API with a personal access token or session that carries the diagrams read, write, or delete scope
Analytics
App API
MCP target
Validation
These routes save a workspace custom shape, delete one, and rank catalog shapes by meaning with a keyword fallback. Saving needs the diagrams write scope and deleting needs the diagrams delete scope. No screen calls these routes today.
Diagram webhook catalog, share to Slack, and audit feed API
GuardedREST API with a personal access token or session that carries the diagrams read or write scope
Analytics
App API
MCP target
Validation
The webhook events route lists the diagram events an integration can subscribe to and how deliveries are signed. Share to Slack creates a public view link and posts it to the connected Slack channel, and returns the link with a reason when Slack is not connected or no channel is set. The audit route returns the diagram audit events newest first. All three require the Diagrams module on the workspace plan. No screen calls these routes today.
Whiteboards
Module guide1 actions · 1 live, 0 guarded, 0 configured
Create, open, edit, and delete whiteboards
LiveWhiteboards page: New whiteboard button, whiteboard cards with open and delete, the freeform editor with back, and retry on a failed list
Analytics
App API
MCP target
Validation
These routes list, create, open, update, and delete freeform whiteboards; any member of the workspace may co-edit a whiteboard. The unprefixed routes require inbox access (view to read, create to create, update to change or delete) and the chat read or write scope; the /v1 twins accept a personal access token with the whiteboards read, write, or delete scope. Delete is a soft delete written to the audit log, and a whiteboard from another workspace or one already deleted returns 404.
Chat
Module guide8 actions · 6 live, 2 guarded, 0 configured
Create channels, open direct messages, and manage channel membership
LiveChat channel list, New channel dialog (name, topic, private toggle, member search), New direct message dialog, Add people dialog, channel details panel, and Leave channel action
Analytics
App API
MCP target
Validation
These routes list the channels a person can see, create workspace and project channels, open one to one and group direct messages, rename or archive a channel, and manage who belongs to it. The session routes under /chat require the inbox module (view to read, create to create a channel or direct message, update for every other change) plus the chat:read or chat:write scope; the /v1 twins accept a personal access token with chat:read or chat:write and carry the public API rate limit and Idempotency-Key replay, and join and leave exist only on the session routes. A public workspace channel is browsable by any workspace member and readable without joining, while private channels and direct messages answer 404 to anyone outside them. Creating, updating, archiving, adding members, and opening a direct message each write an audit record, and leaving a channel revokes the caller's live subscription to it.
Send, edit, delete, and react to chat messages
LiveChat message composer, message timeline with Load older and gap recovery, message actions (edit, delete, reaction picker and quick reactions), thread panel with its own composer, typing indicator, and automatic read marking when a channel is open
Analytics
App API
MCP target
Validation
These routes page through a channel timeline or a thread, post and edit messages, soft delete them, add and remove emoji reactions, advance the caller's read cursor, and broadcast a typing signal to other members in real time. Session callers need the inbox module (view to read, create to send, update for edits, deletes, reactions, read state, and typing) plus chat:read or chat:write; the /v1 twins accept a personal access token with those scopes, carry the public API rate limit and Idempotency-Key replay, and do not offer reactions. Posting in a public workspace channel joins the caller automatically, while private channels and direct messages answer 404 to non members. Sends, edits that change the text, and deletes write audit records, and mentions in a message create notifications for the people named.
Pin, save, and search chat messages
LivePin and Save message actions, the channel Pins panel, the personal Saved panel, and the chat search panel
Analytics
App API
MCP target
Validation
Pins mark a message for every member of a channel, saved items are a private bookmark list for one person, and search finds messages by case insensitive text across the channels the caller belongs to. Session callers need the inbox module (view for lists and search, update to pin, unpin, save, or unsave) plus chat:read or chat:write, and the /v1 twins accept a personal access token with the same scopes under the public API rate limit and Idempotency-Key replay. Pinning and unpinning write audit records. A channel in another workspace returns 404.
Attach files to chat messages
GuardedAttach files button in the chat composer, the upload tray with progress and remove, and the image, video, audio, PDF, and file previews with download on a sent message
Analytics
App API
MCP target
Validation
These routes give the composer a short lived signed upload link (single or multipart), verify the stored file on finalize, scan it and build image previews in the background, list a channel's or a message's ready attachments, return short lived signed download links, and delete an upload. Session callers need the inbox module (view for lists and downloads, create for ticket and finalize, update to delete) plus chat:read or chat:write; the /v1 twins accept a personal access token with the same scopes under the public API rate limit and Idempotency-Key replay. The feature is guarded: it is disabled per workspace by default and needs object storage, and a ticket reserves quota atomically so concurrent uploads cannot overrun the workspace limit. Deletes write an audit record and free the stored bytes when no other attachment shares them.
Write, archive, and delete docs inside a chat channel
LiveChannel Docs panel with template grid (blank, minutes of meeting, standup, and more), New doc, the full page doc editor with title, icon, autosave status, and outline, and archive and delete actions
Analytics
App API
MCP target
Validation
Channel docs are rich text documents that live in a chat channel: these routes list the templates, list a channel's docs, create a doc from a template, read and save it with optimistic revision checks, archive or restore it, and delete it. Session callers need the inbox module (view to read, create to create a doc, update for every other change) plus chat:read or chat:write, and the /v1 twins accept a personal access token with the same scopes under the public API rate limit and Idempotency-Key replay. Read access follows the channel: a member, or anyone in the workspace for a public channel, or anyone who can read a channel the doc was shared into. Changes are broadcast to the channel in real time.
Share a chat doc to another channel and restore an earlier revision
LiveDoc Share dialog with channel targets and the shared list, and the doc Revisions panel with preview and Restore
Analytics
App API
MCP target
Validation
These routes share a channel doc into further channels so their members can read it, remove that share, list the stored revision snapshots, read one, and restore it as the current content. Session callers need the inbox module (view to read revisions, update to share, unshare, or restore) plus chat:read or chat:write, and the /v1 twins accept a personal access token with the same scopes under the public API rate limit and Idempotency-Key replay. A share and its removal are broadcast to the target channel in real time.
Chat presence API
LivePresence dots on chat avatars, filled from the online roster on load; the heartbeat route is an HTTP fallback for clients without a live socket
Analytics
App API
MCP target
Validation
The heartbeat marks the caller online in their own workspace and announces a new arrival to other members over the real time connection; the roster route returns the ids of members seen in the last 60 seconds so a freshly loaded chat screen can paint presence before any change arrives. Both are self service routes available to any signed in workspace member, with chat:write for the heartbeat and chat:read for the roster when a token is used. Presence is normally driven by the live socket, so the web app reads the roster and does not call the heartbeat.
Chat eDiscovery export API
GuardedREST API only, with a signed in session or a token that carries the chat:write scope; no screen calls it
Analytics
App API
MCP target
Validation
This route exports a workspace's chat for legal or compliance review: every channel in scope, including private channels and direct messages the caller is not a member of, with each message's author, body, sequence, and created, edited, and deleted times. It is gated by the role check in the service, not by a module permission: a workspace owner or admin, or a member whose custom role grants chat.ediscovery.export, may call it, and everyone else is refused with 403. The archive is encrypted, written to temporary object storage that expires after 24 hours, and the response returns its storage key, channel and message counts, size, expiry, and encryption algorithm. Every export writes an audit record naming the caller, the scope, and the archive.
Huddles
Module guide3 actions · 3 live, 0 guarded, 0 configured
Start, join, and run a live audio huddle
LiveHuddles page Start huddle button, live huddle list with Join, and the huddle room with Mute, Share screen, Leave, and End controls
Analytics
App API
MCP target
Validation
These routes start a huddle (the starter becomes host), list and read huddles, join and leave them, publish a participant's mute and screen share state, and end them; audio travels peer to peer between browsers while the server keeps the roster and relays signalling. Session callers need the inbox module (view to read, create to start, update for every other change) plus huddles:read or huddles:write, and the /v1 twins accept a personal access token with those scopes under the public API rate limit and Idempotency-Key replay. Access follows the anchor channel, or for an unanchored huddle, the starter and its participants. Starting and ending write audit records, and the end is recorded once even when several people end or leave at the same time.
Record your screen and manage recordings
LiveHuddle room Record and Stop controls, the recordings library, and the recording player with video, rename, and delete
Analytics
App API
MCP target
Validation
These routes create a recording and return a short lived signed upload link, confirm the upload, list and read recordings, return a playback link, rename or change visibility, and soft delete a recording with its stored file. When the deployment has no object storage the recording stays in the browser that captured it and the server keeps only its record. Callers need the inbox module (view to read, create to start an upload, update to change or delete) plus chat:read or chat:write. Creating, finalizing, and deleting write audit records, and each playback increments the view count.
Share a recording by link and comment on it
LiveRecording player Share button and time stamped comment list with comment input, Post, seek, and delete; a shared link opens the public recording player
Analytics
App API
MCP target
Validation
These routes mint a public share link for a recording, revoke it, serve the public player with a short lived playback link to anyone holding the link without signing in, and list, add, and delete time stamped comments. The signed in routes need the inbox module (view to read comments, create to comment, update to share, stop sharing, or delete a comment) plus chat:read or chat:write. The public route requires no account, reads only a recording whose visibility is LINK, and increments its view count. Sharing and stopping sharing write audit records.
Attachments
Module guide3 actions · 3 live, 0 guarded, 0 configured
Attach evidence files to an incident during its postmortem
LivePostmortem detail Evidence panel: upload button, file list with download and remove actions
Analytics
App API
MCP target
Validation
These routes upload, list, download, and remove files on a service operations incident, which the postmortem screen shows as its Evidence panel. Reading needs the attachments:read scope and view access to Incident Management; uploading, finalizing, and removing need attachments:write and update access. An upload is a two step flow: the ticket returns a signed upload address valid for 15 minutes, and finalize verifies the stored object before the file becomes ready. Uploads and downloads answer 503 when object storage is not configured, while the list still answers from the database.
Keep files on a client onboarding
LiveOnboarding workspace detail panel Files section: upload button, file list with download and remove actions
Analytics
App API
MCP target
Validation
These routes hold the files that belong to one client onboarding, such as the signed order form or the migration plan, shown in the Files section of the onboarding workspace. Reading needs the attachments:read scope and view access to Client Onboarding; uploading, finalizing, and removing need attachments:write and update access. An onboarding outside the caller's workspace answers 404, and uploads and downloads answer 503 when object storage is not configured.
Engagement files API
LiveREST API with a personal access token that carries the attachments:read, attachments:write, or attachments:delete scope
Analytics
App API
MCP target
Validation
These routes upload, list, download, and remove files on a client delivery engagement. Reading needs attachments:read and view access to Client Delivery, uploading and finalizing need attachments:write and update access, and removing needs attachments:delete and delete access. A new file is internal by default and is not shown in the client portal until someone shares it with the client. Uploads and downloads answer 503 when object storage is not configured.
Announcements
Module guide3 actions · 2 live, 1 guarded, 0 configured
Write and publish an announcement to your workspace
GuardedSettings Announcements page: announcement list, type and severity pickers, title, banner text and body fields, schedule fields, publish and unpublish toggles, and delete with confirmation
Analytics
App API
MCP target
Validation
These routes let a workspace OWNER or ADMIN create, edit, publish, unpublish, and delete announcements that appear as a banner for members of their own workspace, and read the type catalog that fills the type picker. Reading needs the announcements:read scope and writing needs announcements:write. Publishing keeps the first publish time on a republish, sends a realtime refresh to open sessions, and every change is recorded in the audit log. Deleting removes the announcement permanently.
Read and dismiss announcement banners
LiveAnnouncement banner at the top of the app: call to action link, incident link, and dismiss button
Analytics
App API
MCP target
Validation
These routes return the published announcements that target the signed-in person, with their dismissals applied, and record a dismissal so the banner stays hidden on every device. The banner reads them on every app screen and asks for scheduled announcements too, so an upcoming maintenance window can be shown before it starts. A dismissal is stored per person and never affects other members.
See status announcements on the public status page
LivePublic status page announcement callout and announcement history list, with the View all announcements link
Analytics
App API
MCP target
Validation
This public route feeds the status page with published status announcements, active ones first and then scheduled ones in start order. It needs no authentication and exposes nothing targeted at a single workspace, so an internal workspace broadcast never appears on the public page.
Dashboards
Module guide2 actions · 0 live, 2 guarded, 0 configured
Build a dashboard of report widgets
GuardedDashboards page: dashboard tabs, New dashboard dialog and templates, Add widget panel, widget cards with remove action
Analytics
App API
MCP target
Validation
These routes create, rename, and delete personal dashboards, add, edit, and remove their widgets, and render them by running every widget query against the caller's workspace data. Reading needs the dashboards:read scope and changes need dashboards:write, and every change is recorded in the audit log. A widget whose query fails renders with its error message instead of failing the whole dashboard.
Preview a report query before saving it as a widget
GuardedDashboards Add widget query builder: dataset picker, dimension and measure pickers, filters, and live preview
Analytics
App API
MCP target
Validation
These routes return the catalog of reportable datasets with their dimensions and measures, and run an unsaved aggregation query so the builder can preview a widget. Both need the dashboards:read scope, view access to Analytics, and the analytics entitlement. Every query runs scoped to the caller's workspace and saves nothing.
Habits
Module guide1 actions · 1 live, 0 guarded, 0 configured
Habits REST API
LiveREST API with a personal access token that carries the habits:read or habits:write scope
Analytics
App API
MCP target
Validation
These public routes let a person list, create, edit, archive, and check in their own habits, with streak statistics, and find the habits whose streak is at risk this period. Reading needs habits:read and changes need habits:write. DELETE archives the habit rather than deleting it, and the at-risk notify route sends an in-app notification only for habits not already notified in the last 24 hours. The Habits screen uses the session routes of the same service.
Workload
Module guide1 actions · 1 live, 0 guarded, 0 configured
Workload and capacity REST API
LiveREST API with a personal access token that carries the workload:read or workload:write scope
Analytics
App API
MCP target
Validation
These public routes compute per-person, per-day allocation against capacity, list the days where a person is over capacity with a moderate, high, or critical severity, propose leveling moves, drill into the tasks counted on one day, and manage capacity profiles. Reading needs workload:read and capacity changes need workload:write. Leveling only proposes reassignments or deferrals and changes nothing. The Workload screen uses the session routes of the same service.
Developer Platform
Module guide6 actions · 6 live, 0 guarded, 0 configured
Hosted MCP endpoint
LiveMCP client connected by URL to /mcp with a personal access token or an Atlas OAuth access token as the bearer credential
Analytics
App API
MCP target
Validation
These routes are the hosted Model Context Protocol endpoint: an AI assistant connects by URL, opens a session with an initialize request, sends tool calls with POST, listens with GET, and ends the session with DELETE. The route is not behind the session sign-in guard because it performs its own credential check, and each tool call is forwarded to the /v1 API with the caller's own credential, so scopes, workspace scoping, rate limits, and idempotency are the same as for the REST API. Only the normal tool profile is ever built on this path.
Single-file MCP server download
LiveDownload links on the MCP documentation page for atlas-mcp-server.mjs, its SHA-256 checksum, and manifest.json
Analytics
App API
MCP target
Validation
This route serves the Atlas MCP server as one file for people who run it on their own machine with Node 18.17 or later, for example behind an IP-restricted token or on an offline network. It is public and needs no credential, because the file holds no secret and is the same for everyone. It refuses every file name outside the fixed list, so no path can reach anything else on the server.
Register and manage OAuth apps for the workspace
LiveSettings, Developer: overview counts, register app form with name, redirect URIs, scopes, and client type, and per-app rotate secret and revoke buttons
Analytics
App API
MCP target
Validation
An owner or administrator registers OAuth apps that act on the workspace, rotates a confidential app's secret, and revokes an app together with every token it holds, while the overview shows counts of tokens, webhooks, and apps alongside the rate limits and scope catalog. Every route needs the developer:manage scope, which grants no access to workspace data. Registration, rotation, and revocation are written to the audit log, and a new secret is returned once and never stored in readable form.
Developer usage, rate limit, and scope catalog API
LiveREST API with a personal access token that carries the developer:manage scope
Analytics
App API
MCP target
Validation
These read-only routes report the workspace's token, webhook, and OAuth app counts, the effective request ceiling and window for each rate-limit class, and the list of scopes a credential can carry. They let a console or integration show limits without hard-coding them. They change nothing and refuse a credential without the developer:manage scope.
See the workspace API limits
LiveSettings, API access: workspace limits card with requests per minute by class, monthly API quota and usage, daily AI spend cap, and webhook retry policy
Analytics
App API
MCP target
Validation
An owner, an administrator, or an integration with workspace:read reads the limits that apply to the workspace so it can pace itself: requests a minute for each class, the monthly API call quota and how much is used, the daily AI spend cap, and how webhooks are retried. The values combine the plan defaults with any limits set for the workspace. The route reads only the caller's own workspace.
Choose which sensitive areas tokens may reach
LiveSettings, API access: token access card with one switch per sensitive area (delivery, connectors, service, chat)
Analytics
App API
MCP target
Validation
An owner or administrator decides whether personal access tokens and agent tools may reach the workspace's most sensitive areas: client delivery, connectors, service operations, and chat. The setting is session only, because it governs what tokens can do. Every change is written to the audit log.
Coverage
How this reference compares to the real surface area. The generator walks every controller in apps/api/src, the OpenAPI specification, and the MCP tool catalog, then diffs them against the curated registry above.
Generated 2026-10-11T14:22:36.760Z. Run node scripts/generate-action-docs.mjs to refresh.
>Generated registry candidates (21)
- GET/v1/client-delivery/config/portalmedium
Portal settings
apps/api/src/client-delivery/client-delivery-config.controller.ts
- PATCH/v1/client-delivery/config/portalmedium
Set portal settings
apps/api/src/client-delivery/client-delivery-config.controller.ts
- GET/v1/client-delivery/config/portal/addressingmedium
Addressing
apps/api/src/portal-addresses/portal-addressing.controller.ts
- POST/v1/client-delivery/config/portal/domainsmedium
Request domain
apps/api/src/portal-addresses/portal-addressing.controller.ts
- POST/v1/client-delivery/config/portal/domains/{domainId}/checkmedium
Check domain
apps/api/src/portal-addresses/portal-addressing.controller.ts
- POST/v1/client-delivery/config/portal/domains/{domainId}/removemedium
Remove domain
apps/api/src/portal-addresses/portal-addressing.controller.ts
- PUT/v1/client-delivery/config/portal/subdomainmedium
Set subdomain
apps/api/src/portal-addresses/portal-addressing.controller.ts
- GET/v1/client-delivery/config/portal/subdomain-availabilitymedium
Subdomain availability
apps/api/src/portal-addresses/portal-addressing.controller.ts
Comments
Module guide4 actions · 4 live, 0 guarded, 0 configured
Discuss an incident during its postmortem
LivePostmortem detail Discussion panel: comment list, comment box, and Post button
Analytics
App API
MCP target
Validation
These routes list and post comments on a service operations incident, which the postmortem screen shows as its Discussion panel. Reading needs the comments:read scope and view access to Incident Management, and posting needs comments:write and update access. Every new comment is also mirrored onto the incident timeline, and a failure to write the timeline entry does not undo the comment. Each post is recorded in the audit log.
Discuss a client onboarding with the team
LiveOnboarding workspace detail panel Discussion section: comment list, comment box, and Post button
Analytics
App API
MCP target
Validation
These routes list and post comments on one client onboarding, so questions and decisions stay on the record instead of in a chat channel. Reading needs the comments:read scope and view access to Client Onboarding, and posting needs comments:write and update access. Each post is recorded in the audit log, and a reply to a comment from another onboarding is refused with 409.
Engagement, thread, and deliverable comments API
LiveREST API with a personal access token that carries the comments:read or comments:write scope
Analytics
App API
MCP target
Validation
These routes list and post internal comments on a client delivery engagement, on one of its discussion threads, or on one of its deliverables. Reading needs the comments:read scope and view access to Client Delivery, and posting needs comments:write and update access. An engagement hidden from the caller by an information barrier or restricted access is refused. Each post is recorded in the audit log and sends the standard comment notifications.
Task, project, and goal comments REST API
LiveREST API with a personal access token that carries the comments:read or comments:write scope
Analytics
App API
MCP target
Validation
These public routes list, create, read, update, and delete comments on a task, project, or goal through one resource, using the same service as the comment threads on those screens. Reading needs the comments:read scope and writing needs comments:write, with the public API rate limits and Idempotency-Key replay applied. Deleting is a soft delete, and a comment in another workspace answers as not found.