{
  "info": {
    "name": "Vouli IQ Public API (2026-09-12)",
    "description": "Generated from the OpenAPI document (https://www.vouliiq.com/api/v1/openapi.json) — do not edit by hand. Set the {{vouli_api_key}} collection variable to an API key; a vk_test_ key reads sandbox data only. Every request sends it as \"Authorization: Bearer\".",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json",
    "version": "2026-09-12"
  },
  "auth": {
    "type": "bearer",
    "bearer": [
      {
        "key": "token",
        "value": "{{vouli_api_key}}",
        "type": "string"
      }
    ]
  },
  "variable": [
    {
      "key": "base_url",
      "value": "https://www.vouliiq.com",
      "type": "string",
      "description": "Origin the API is served from. Paths already include the version prefix."
    },
    {
      "key": "vouli_api_key",
      "value": "",
      "type": "string",
      "description": "Your API key. Prefer a vk_test_ sandbox key; keep live keys in a Postman environment, not in an exported collection."
    }
  ],
  "item": [
    {
      "name": "Meta",
      "description": "Discovery: the index and this document.",
      "item": [
        {
          "name": "Discover the resources this API version exposes.",
          "id": "index",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1"
              ]
            },
            "description": "Unauthenticated index: the current dated version, the versions still served, every resource with its required scope, and where to find the spec and the SDKs.\n\nNo authentication required.",
            "auth": {
              "type": "noauth"
            }
          },
          "response": []
        },
        {
          "name": "Fetch this OpenAPI 3.1 document.",
          "id": "openapi",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/openapi.json",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "openapi.json"
              ]
            },
            "description": "Unauthenticated. Generated from the same schemas the handlers enforce, so it cannot drift from the API.\n\nNo authentication required.",
            "auth": {
              "type": "noauth"
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "MCP",
      "description": "Model Context Protocol server: the same resources as read-only tools for AI assistants.",
      "item": [
        {
          "name": "Model Context Protocol (MCP) server: read-only tools for AI assistants.",
          "id": "mcp",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/mcp",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "mcp"
              ]
            },
            "description": "Streamable HTTP transport, JSON-RPC 2.0, one message per POST, single `application/json` responses (no SSE stream: GET and DELETE answer 405 with `Allow: POST`; no session id). Methods: `initialize`, `notifications/initialized` (202, no body), `ping`, `tools/list`, `tools/call`. Authentication, the plan gate, the per-key rate limit and the sandbox are the same as every other operation here; each tool requires its resource's scope and returns the same envelope as the matching GET, as `structuredContent` and as JSON text. Tool errors (a missing scope, a read failure) are results with `isError: true`; unknown methods are -32601, bad arguments -32602.\n\nRequired scope: any valid key",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"jsonrpc\": \"2.0\",\n  \"id\": \"example_id\",\n  \"method\": \"initialize\",\n  \"params\": {}\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "Compliance",
      "description": "",
      "item": [
        {
          "name": "Retrieve the active compliance posture.",
          "id": "compliance",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/compliance",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "compliance"
              ]
            },
            "description": "Overall posture per regime and jurisdiction. Individual obligations are a separate, paginated list at `/compliance/obligations`.\n\nRequired scope: read:compliance"
          },
          "response": []
        },
        {
          "name": "List compliance obligations, newest first.",
          "id": "obligations",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/compliance/obligations?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "compliance",
                "obligations"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "regime_id",
                  "value": "",
                  "description": "Only obligations arising from this regime.",
                  "disabled": true
                },
                {
                  "key": "status",
                  "value": "",
                  "description": "Only obligations in this status.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "Every tracked obligation with its regime, jurisdiction, priority band, owner and target date. Cursor-paginated.\n\nRequired scope: read:compliance"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Incidents",
      "description": "",
      "item": [
        {
          "name": "List AI incidents, newest first.",
          "id": "incidents",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/incidents?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "incidents"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "severity",
                  "value": "low",
                  "description": "Only incidents at this severity.",
                  "disabled": true
                },
                {
                  "key": "status",
                  "value": "open",
                  "description": "Only incidents in this lifecycle state.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "The AI Incident Command register: every declared incident with its type, severity, status, owner and notification clock. Requires the plan that includes Incident Command. Cursor-paginated.\n\nRequired scope: read:incidents"
          },
          "response": []
        },
        {
          "name": "Declare an AI incident.",
          "id": "createIncident",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/incidents",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "incidents"
              ]
            },
            "description": "Declares an incident in Incident Command, starting its timeline and notification clock. Requires an Idempotency-Key.\n\nRequired scope: write:incidents\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"affected_systems\": \"example_affected_systems\",\n  \"description\": \"example_description\",\n  \"incident_type\": \"model_failure\",\n  \"jurisdictions\": \"example_jurisdictions\",\n  \"notification_deadline\": \"2026-01-01T00:00:00.000Z\",\n  \"notification_required\": true,\n  \"owner\": \"example_owner\",\n  \"severity\": \"low\",\n  \"status\": \"open\",\n  \"title\": \"example_title\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Change an incident.",
          "id": "updateIncident",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/incidents/:id",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "incidents",
                ":id"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Changes the fields given; a status change is logged on the incident timeline. An incident id from another organisation is a 404.\n\nRequired scope: write:incidents\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"affected_systems\": \"example_affected_systems\",\n  \"description\": \"example_description\",\n  \"incident_type\": \"model_failure\",\n  \"jurisdictions\": \"example_jurisdictions\",\n  \"notification_deadline\": \"2026-01-01T00:00:00.000Z\",\n  \"notification_required\": true,\n  \"owner\": \"example_owner\",\n  \"severity\": \"low\",\n  \"status\": \"open\",\n  \"title\": \"example_title\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "KPIs",
      "description": "",
      "item": [
        {
          "name": "List KPIs (key results) with their targets and latest actuals, newest first.",
          "id": "kpis",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/kpis?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "kpis"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "code",
                  "value": "",
                  "description": "Only the key result with this code.",
                  "disabled": true
                },
                {
                  "key": "status",
                  "value": "draft",
                  "description": "Only key results in this lifecycle state.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "Every key result in the OKR & KPI Engine with its unit, direction, target and current value — the targets an external system pushes actuals to (REST: POST /kpis/checkins). Cursor-paginated.\n\nRequired scope: read:kpis"
          },
          "response": []
        },
        {
          "name": "Push KPI actuals — up to 500 data points, all or nothing.",
          "id": "recordKpiCheckins",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/kpis/checkins",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "kpis",
                "checkins"
              ]
            },
            "description": "Records actuals against key results (by id or code) from an external system — a warehouse, a BI tool, a monitoring pipeline. Every point is validated first; one bad point refuses the whole batch and nothing is written. Each key result's current value follows its LATEST period, so back-filling history never rolls it backwards. Requires an Idempotency-Key.\n\nRequired scope: write:kpis\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"checkins\": [\n    {\n      \"evidence_ref\": \"example_evidence_ref\",\n      \"key_result_code\": \"example_key_result_code\",\n      \"key_result_id\": \"00000000-0000-4000-8000-000000000000\",\n      \"note\": \"example_note\",\n      \"period_start\": \"example_period_start\",\n      \"source\": \"telemetry\",\n      \"value\": 1\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "Risks",
      "description": "",
      "item": [
        {
          "name": "List the AI risk register, newest first.",
          "id": "risks",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/risks?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "risks"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "severity",
                  "value": "CRITICAL",
                  "description": "Only risks at this inherent severity.",
                  "disabled": true
                },
                {
                  "key": "status",
                  "value": "Open",
                  "description": "Only risks in this lifecycle state.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "The org’s risk register with inherent and residual severity, owner, modelled exposure and target date. Cursor-paginated.\n\nRequired scope: read:risks"
          },
          "response": []
        },
        {
          "name": "Add a risk to the register.",
          "id": "createRisk",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/risks",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "risks"
              ]
            },
            "description": "Records a risk exactly as the Risk Radar's \"add risk\" form does (source user_added, status Open, the untreated baseline set from the severity and likelihood given). Requires an Idempotency-Key.\n\nRequired scope: write:risks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"description\": \"example_description\",\n  \"dimension\": \"example_dimension\",\n  \"likelihood\": \"RARE\",\n  \"mitigation_action\": \"example_mitigation_action\",\n  \"owner_name\": \"example_owner_name\",\n  \"severity\": \"CRITICAL\",\n  \"target_date\": \"example_target_date\",\n  \"title\": \"example_title\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Change a risk.",
          "id": "updateRisk",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/risks/:id",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "risks",
                ":id"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Changes the fields given, through the same rules as the app: lowering or clearing a severity or likelihood, or closing, accepting or mitigating a CRITICAL risk, needs a severity_change_reason and is recorded as evidence. A risk id from another organisation is a 404.\n\nRequired scope: write:risks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"likelihood\": \"RARE\",\n  \"mitigation_action\": \"example_mitigation_action\",\n  \"owner_name\": \"example_owner_name\",\n  \"residual_gap_reason\": \"example_residual_gap_reason\",\n  \"residual_severity\": \"CRITICAL\",\n  \"severity\": \"CRITICAL\",\n  \"severity_change_reason\": \"example_severity_change_reason\",\n  \"status\": \"Open\",\n  \"target_date\": \"example_target_date\",\n  \"title\": \"example_title\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "Roadmap",
      "description": "",
      "item": [
        {
          "name": "Retrieve the active transformation roadmap.",
          "id": "roadmap",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/roadmap",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "roadmap"
              ]
            },
            "description": "The active roadmap and its phases. Its milestones are a separate, paginated list at `/roadmap/milestones`.\n\nRequired scope: read:roadmap"
          },
          "response": []
        },
        {
          "name": "List milestones of the active roadmap, newest first.",
          "id": "milestones",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/roadmap/milestones?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "roadmap",
                "milestones"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "status",
                  "value": "",
                  "description": "Only milestones in this status.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "Delivery milestones under the active roadmap, with owner, RAG band and progress. Cursor-paginated.\n\nRequired scope: read:roadmap"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Scores",
      "description": "",
      "item": [
        {
          "name": "List completed assessment scores, newest first.",
          "id": "scores",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/scores?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "scores"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "The org’s assessment history — score, verdict and confidence per completed cycle — so a BI tool, GRC platform or warehouse can cite Vouli IQ as the instrument of record. Cursor-paginated.\n\nRequired scope: read:scores"
          },
          "response": []
        },
        {
          "name": "Retrieve the most recent completed SOVEREIGN scorecard.",
          "id": "scorecard",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/scorecard",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "scorecard"
              ]
            },
            "description": "The current scorecard with its completeness and evidence ratios. `data` is null before the first completed assessment.\n\nRequired scope: read:scorecard"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Signals",
      "description": "",
      "item": [
        {
          "name": "List the current signal set.",
          "id": "signals",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/signals?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "signals"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "type",
                  "value": "",
                  "description": "Only the signal of this canonical type.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "The deterministic numbers the Board Cockpit tiles render — one current row per signal type. Superseded values are not returned. Cursor-paginated.\n\nRequired scope: read:signals"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Talent",
      "description": "",
      "item": [
        {
          "name": "Retrieve the active talent readiness assessment.",
          "id": "talent",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/talent",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "talent"
              ]
            },
            "description": "Overall readiness and the recommended build / buy / borrow mix. Individual gaps are a separate, paginated list at `/talent/gaps`.\n\nRequired scope: read:talent"
          },
          "response": []
        },
        {
          "name": "List talent gaps, newest first.",
          "id": "gaps",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/talent/gaps?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "talent",
                "gaps"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "status",
                  "value": "",
                  "description": "Only gaps in this status.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "Every open capability gap with the headcount needed, priority band and recommended path. Cursor-paginated.\n\nRequired scope: read:talent"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Vendor",
      "description": "",
      "item": [
        {
          "name": "Retrieve the active AI vendor portfolio posture.",
          "id": "vendor",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/vendor",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "vendor"
              ]
            },
            "description": "Portfolio-level posture and cross-vendor risks. The vendor inventory is a separate, paginated list at `/vendor/inventory`.\n\nRequired scope: read:vendor"
          },
          "response": []
        },
        {
          "name": "List the AI vendor inventory, newest first.",
          "id": "inventory",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/vendor/inventory?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "vendor",
                "inventory"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                },
                {
                  "key": "status",
                  "value": "",
                  "description": "Only vendors in this review status.",
                  "disabled": true
                },
                {
                  "key": "updated_since",
                  "value": "",
                  "description": "Only rows created or changed at or after this instant — an ISO-8601 date (midnight UTC) or timestamp. Use it for incremental sync: store the time you started a sync and pass it next time.",
                  "disabled": true
                }
              ]
            },
            "description": "Every vendor in the AI supply chain with its risk band, intake recommendation, contract end and annual cost. Cursor-paginated.\n\nRequired scope: read:vendor"
          },
          "response": []
        },
        {
          "name": "Add a vendor to the AI vendor inventory.",
          "id": "createVendor",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/vendor/inventory",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "vendor",
                "inventory"
              ]
            },
            "description": "Adds a vendor the organisation already contracts with. vendor_key is unique in the organisation: a second create for the same key is a 409. Requires an Idempotency-Key.\n\nRequired scope: write:vendor\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ai_role\": \"example_ai_role\",\n  \"annual_cost_usd\": 0,\n  \"category\": \"example_category\",\n  \"contract_end\": \"example_contract_end\",\n  \"contract_start\": \"example_contract_start\",\n  \"initial_recommendation\": \"consolidate\",\n  \"initial_risk_band\": \"CRITICAL\",\n  \"notes\": \"example_notes\",\n  \"renewal_owner_role\": \"example_renewal_owner_role\",\n  \"status\": \"active\",\n  \"vendor_key\": \"example_vendor_key\",\n  \"vendor_name\": \"example_vendor_name\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Change a vendor’s working state.",
          "id": "updateVendor",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/vendor/inventory/:id",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "vendor",
                "inventory",
                ":id"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Changes the team-owned fields (status, contract dates, renewal owner role, annual cost, notes). A vendor id from another organisation is a 404.\n\nRequired scope: write:vendor\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"annual_cost_usd\": 0,\n  \"contract_end\": \"example_contract_end\",\n  \"contract_start\": \"example_contract_start\",\n  \"notes\": \"example_notes\",\n  \"renewal_owner_role\": \"example_renewal_owner_role\",\n  \"status\": \"active\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "Audit",
      "description": "",
      "item": [
        {
          "name": "Export the audit log, oldest first (Enterprise).",
          "id": "exportAudit",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/audit?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "audit"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "The `next_cursor` of the previous page (strictly after that event).",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Events to return, 1–1000. Defaults to 100."
                },
                {
                  "key": "format",
                  "value": "json",
                  "description": "json (the list envelope, default) or ndjson (one event per line; the next cursor is in X-Next-Cursor).",
                  "disabled": true
                },
                {
                  "key": "since",
                  "value": "",
                  "description": "Events at or after this instant (ignored when `cursor` is given — the cursor is the finer bound).",
                  "disabled": true
                },
                {
                  "key": "until",
                  "value": "",
                  "description": "Events strictly before this instant.",
                  "disabled": true
                }
              ]
            },
            "description": "The organisation's audit trail as SIEM-ready events — the same feed as Settings → SIEM export — oldest first, so a collector can poll it incrementally: keep the last `next_cursor` and pass it back. `since` and `until` bound the window. Enterprise plan only; `read:all` does not grant it. Every pull is itself audited. `limit` 1–1000 (default 100).\n\nRequired scope: read:audit"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Webhooks",
      "description": "",
      "item": [
        {
          "name": "List webhook subscriptions, newest first.",
          "id": "listWebhookSubscriptions",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/webhooks/subscriptions?limit=10",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "webhooks",
                "subscriptions"
              ],
              "query": [
                {
                  "key": "cursor",
                  "value": "",
                  "description": "Opaque cursor from a previous response’s `next_cursor`. A cursor this API did not issue is rejected with 400 `invalid_cursor`.",
                  "disabled": true
                },
                {
                  "key": "limit",
                  "value": "10",
                  "description": "Rows to return, 1–100. Defaults to 25."
                }
              ]
            },
            "description": "Every endpoint registered for this organisation, by the dashboard or by a key. The signing secret is never listed. Cursor-paginated.\n\nRequired scope: manage:webhooks"
          },
          "response": []
        },
        {
          "name": "Register a webhook endpoint.",
          "id": "createWebhookSubscription",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/webhooks/subscriptions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "webhooks",
                "subscriptions"
              ]
            },
            "description": "Registers an https endpoint and returns its signing secret ONCE. The URL must resolve to a public address (no localhost, private, link-local or metadata addresses, no http://). Requires an Idempotency-Key; a replay of the same request returns the subscription with `secret: null`.\n\nRequired scope: manage:webhooks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"active\": true,\n  \"description\": \"example_description\",\n  \"event_types\": [\n    \"example_event_types\"\n  ],\n  \"url\": \"example_url\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Pause, resume or change a webhook endpoint.",
          "id": "updateWebhookSubscription",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/webhooks/subscriptions/:id",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "webhooks",
                "subscriptions",
                ":id"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Changes the URL (re-checked), the event list, the description or `active`. A subscription id from another organisation is a 404.\n\nRequired scope: manage:webhooks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"active\": true,\n  \"description\": \"example_description\",\n  \"event_types\": [\n    \"example_event_types\"\n  ],\n  \"url\": \"example_url\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Delete a webhook endpoint.",
          "id": "deleteWebhookSubscription",
          "request": {
            "method": "DELETE",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/webhooks/subscriptions/:id",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "webhooks",
                "subscriptions",
                ":id"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Removes the endpoint and its queued deliveries. A subscription id from another organisation is a 404.\n\nRequired scope: manage:webhooks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response."
          },
          "response": []
        },
        {
          "name": "Send a signed test `ping` to one endpoint, now.",
          "id": "testWebhookSubscription",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Vouli-Version",
                "value": "2026-09-12",
                "type": "text"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}",
                "type": "text",
                "description": "A fresh GUID per send. Reuse a value to replay a retry."
              },
              {
                "key": "Content-Type",
                "value": "application/json",
                "type": "text"
              }
            ],
            "url": {
              "raw": "{{base_url}}/api/v1/webhooks/subscriptions/:id/test",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "api",
                "v1",
                "webhooks",
                "subscriptions",
                ":id",
                "test"
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "",
                  "description": "The record id. An id that is not in this organisation (including one from another organisation) is a 404."
                }
              ]
            },
            "description": "Sends one `ping` event through the real delivery path — the same SSRF checks and the same X-Vouli-Signature (HMAC-SHA256 over the exact body) as every event — and reports what the receiver answered. Works on a paused endpoint. Requires an Idempotency-Key; send an empty body or `{}`.\n\nRequired scope: manage:webhooks\n\nIdempotent: a retry with the same Idempotency-Key replays the first response.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    }
  ]
}
