Create a corrective action plan
curl --request POST \
--url https://api.example.com/remediation/caps \
--header 'Content-Type: application/json' \
--data '
{
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"owner": "<string>",
"due_date": "<string>",
"path_tier": "governed"
}
'import requests
url = "https://api.example.com/remediation/caps"
payload = {
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"owner": "<string>",
"due_date": "<string>",
"path_tier": "governed"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
target_type: '<string>',
target_id: '<string>',
title: '<string>',
problem_statement: '',
root_cause: '',
containment_action: '',
corrective_action: '',
preventive_action: '',
success_metric: '',
verification_evidence: '',
owner: '<string>',
due_date: '<string>',
path_tier: 'governed'
})
};
fetch('https://api.example.com/remediation/caps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/remediation/caps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'target_type' => '<string>',
'target_id' => '<string>',
'title' => '<string>',
'problem_statement' => '',
'root_cause' => '',
'containment_action' => '',
'corrective_action' => '',
'preventive_action' => '',
'success_metric' => '',
'verification_evidence' => '',
'owner' => '<string>',
'due_date' => '<string>',
'path_tier' => 'governed'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/remediation/caps"
payload := strings.NewReader("{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/remediation/caps")
.header("Content-Type", "application/json")
.body("{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/remediation/caps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"status": "proposed",
"version": 123,
"due_date": "<string>",
"created_at": "<string>",
"updated_at": "<string>",
"owner": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"path_tier": "governed",
"proof_window_days": 30,
"steps": {},
"proof_started_at": "<string>",
"proof_verified_at": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}Remediation
Create a corrective action plan
Requires the caps.write permission + CSRF. Idempotent adoption: if a non-terminal (not verified/rejected) CAP already exists for the same target with the same problem statement (or title, if no statement was given), that existing CAP is returned verbatim instead of creating a duplicate — no audit row is written in that case. Otherwise inserts a new CAP in proposed status with a path-tier-specific default proof window (automated = 14 days, governed = 30, expert = 60) and writes an audit_log row (tenant schema) (cap_created). Returns 201.
POST
/
remediation
/
caps
Create a corrective action plan
curl --request POST \
--url https://api.example.com/remediation/caps \
--header 'Content-Type: application/json' \
--data '
{
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"owner": "<string>",
"due_date": "<string>",
"path_tier": "governed"
}
'import requests
url = "https://api.example.com/remediation/caps"
payload = {
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"owner": "<string>",
"due_date": "<string>",
"path_tier": "governed"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
target_type: '<string>',
target_id: '<string>',
title: '<string>',
problem_statement: '',
root_cause: '',
containment_action: '',
corrective_action: '',
preventive_action: '',
success_metric: '',
verification_evidence: '',
owner: '<string>',
due_date: '<string>',
path_tier: 'governed'
})
};
fetch('https://api.example.com/remediation/caps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/remediation/caps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'target_type' => '<string>',
'target_id' => '<string>',
'title' => '<string>',
'problem_statement' => '',
'root_cause' => '',
'containment_action' => '',
'corrective_action' => '',
'preventive_action' => '',
'success_metric' => '',
'verification_evidence' => '',
'owner' => '<string>',
'due_date' => '<string>',
'path_tier' => 'governed'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/remediation/caps"
payload := strings.NewReader("{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/remediation/caps")
.header("Content-Type", "application/json")
.body("{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/remediation/caps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"target_type\": \"<string>\",\n \"target_id\": \"<string>\",\n \"title\": \"<string>\",\n \"problem_statement\": \"\",\n \"root_cause\": \"\",\n \"containment_action\": \"\",\n \"corrective_action\": \"\",\n \"preventive_action\": \"\",\n \"success_metric\": \"\",\n \"verification_evidence\": \"\",\n \"owner\": \"<string>\",\n \"due_date\": \"<string>\",\n \"path_tier\": \"governed\"\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"target_type": "<string>",
"target_id": "<string>",
"title": "<string>",
"status": "proposed",
"version": 123,
"due_date": "<string>",
"created_at": "<string>",
"updated_at": "<string>",
"owner": "<string>",
"problem_statement": "",
"root_cause": "",
"containment_action": "",
"corrective_action": "",
"preventive_action": "",
"success_metric": "",
"verification_evidence": "",
"path_tier": "governed",
"proof_window_days": 30,
"steps": {},
"proof_started_at": "<string>",
"proof_verified_at": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}Body
application/json
Available options:
automated, governed, expert Response
Successful Response
Available options:
proposed, approved, in_progress, blocked, completed, verified, rejected Available options:
automated, governed, expert