GraphQL API
The schema below is the committed contract for the Mnemose GraphQL gateway. It is auto-generated from the Pothos schema builder — do not edit manually.
To regenerate: pnpm --filter @mnemose/gateway schema:export
To verify: pnpm --filter @mnemose/gateway schema:check
"""A cloud resource that has been adopted into Pulumi management."""type AdoptedResource { adoptedAt: DateTime adoptedBy: String id: String pulumiResourceId: String pulumiStatePath: String snapshotId: String status: String tenantId: String}
"""An agent harness: provider, model, execution policy, and attached tools."""type AgentHarness { createdAt: DateTime description: String hitlTier: String id: String maxSteps: Int mode: String modelId: String name: String providerKind: String temperature: Float tenantId: String tools: [AgentHarnessTool!] updatedAt: DateTime vectorStoreRefs: [String!]}
"""A tool attached to an agent harness with a permission tier."""type AgentHarnessTool { permissionTier: String toolId: String}
"""A remote agent-kernel instance enrolled in the Mnemose platform."""type AgentKernel { capabilities: JSON certFingerprint: String enrolledAt: DateTime enrolledBy: String fleetMode: String id: String label: String lastSeenAt: DateTime permissionTier: String revokedAt: DateTime revokedReason: String status: String tags: [String!]}
"""Health status of an installed application."""type AppHealth { appId: String errors: [String!] healthy: Boolean}
"""An application available in the Mnemose App Store."""type AppStoreCard { category: String description: String featured: Boolean icon: String id: String name: String pricing: String sourcePath: String sourceRef: String sourceRepo: String vendor: String version: String}
"""Configuration required for the first-time mnemose infrastructure deploy. Uses the tenant admin's connected GCP OAuth credential as the bootstrap seed."""input BootstrapInfrastructureInput { """ Secret Manager reference (e.g. projects/{project}/secrets/{name}/versions/{version}) to the Cloud SQL database password. The raw secret value is fetched at execution time by the command handler via the Secret Manager API and never published over Pub/Sub. """ dbPasswordSecretRef: String!
"""Human-readable name for this managed project.""" displayName: String!
"""Target environment label, e.g. "production" or "staging".""" env: String!
"""The GCP project ID to deploy into.""" gcpProjectId: String!
"""Docker image tag to deploy. Defaults to "latest".""" imageTag: String
""" Secret Manager reference (e.g. projects/{project}/secrets/{name}/versions/{version}) to the LLM provider API key. The raw secret value is fetched at execution time by the command handler via the Secret Manager API and never published over Pub/Sub. """ llmApiKeySecretRef: String!
"""GCP region, e.g. "us-central1".""" region: String!
"""GCS bucket name for reports. Defaults to {project}-mnemose-reports.""" reportsBucketName: String}
"""Current status for a control-plane bootstrap target."""type BootstrapState { createdAt: DateTime error: String id: String metadata: JSON phase: String status: String targetId: String targetType: String tenantId: String updatedAt: DateTime}
"""A single message within a chat session."""type ChatMessage { content: JSON createdAt: DateTime id: String role: String sessionId: String}
"""A persisted operator chat session."""type ChatSession { createdAt: DateTime id: String status: String tenantId: String title: String updatedAt: DateTime}
"""A chat session with its full message history."""type ChatSessionWithMessages { createdAt: DateTime id: String messages: [ChatMessage!] status: String tenantId: String title: String updatedAt: DateTime}
"""A delegated customer cloud project under Mnemose management."""type CloudProject { delegatedAt: DateTime displayName: String id: String projectId: String provider: String region: String}
"""A registered cloud-provider artifact for the tenant (ADR 0012, M-4)."""type CloudProvider { appId: String
"""Whether this is the protected core cloud-provider artifact.""" core: Boolean installedAt: DateTime kind: String status: String}
"""Health status of a single core kernel declared in the deployment manifest."""type CoreKernelStatus { id: String label: String permissionTier: String platform: String role: String status: String}
input CreateAgentHarnessInput { description: String hitlTier: String maxSteps: Int mode: String modelId: String! name: String! providerKind: String! temperature: Float toolIds: [String!] vectorStoreRefs: [String!]}
input CreateSandboxInput { compute: JSON! dataSources: JSON deception: JSON grants: JSON label: String! network: JSON! owner: JSON services: JSON tools: JSON!}
scalar DateTime
"""Trigger a Pulumi `up` on an already-bootstrapped managed project using JIT credentials."""input DeployInfrastructureInput { """ID of the managed cloud project record.""" cloudProjectId: String!
"""Docker image tag to deploy.""" imageTag: String}
"""A Pulumi Automation API operation record."""type Deployment { cloudProjectId: String command: String completedAt: DateTime errorMessage: String id: String initiatedAt: DateTime initiatedBy: String pulumiOutputsJson: JSON stackName: String status: String}
input DisableAppInput { appId: String!}
"""Result of an app disable request."""type DisableAppResult { appId: String status: String success: Boolean}
"""A cloud resource discovered during a discovery scan."""type DiscoveredResource { id: String metadata: JSON projectId: String provider: String region: String resourceId: String resourceType: String}
"""A short-lived service account provisioned for cloud resource discovery."""type DiscoveryPrincipal { createdBy: String id: String principalEmail: String projectId: String provisionedAt: DateTime roles: JSON tenantId: String tombstonedAt: DateTime ttlExpiresAt: DateTime}
"""A discovery scan result for a principal."""type DiscoveryScan { completedAt: DateTime id: String principalId: String resourcesFound: Int startedAt: DateTime status: String}
input EnableAppInput { appId: String!}
"""Result of an app enable request."""type EnableAppResult { appId: String status: String success: Boolean}
input EnrollKernelInput { fleetMode: String! label: String! permissionTier: String! tags: [String!]}
"""Bootstrap token and install command returned after kernel enrollment."""type EnrollKernelResult { bootstrapToken: String installCommand: String kernelId: String}
"""Project-scoped deployment target that may optionally link to a delegated cloud project."""type Environment { archivedAt: DateTime cloudProjectId: UUID config: JSON createdAt: DateTime id: String name: String projectId: String}
"""Result of a single evaluation case"""type EvaluationCaseResult { completionTokens: Int estimatedCostUsd: Float failureReason: String latencyMs: Int model: String passed: Boolean promptTokens: Int rawResponse: String score: Float suite: String testCaseId: String testCaseName: String}
"""Evaluation run summary and detailed scorecard"""type EvaluationScorecard { accuracy: Float averageLatencyMs: Float averageScore: Float caseResults: [EvaluationCaseResult!] completedAt: String durationMs: Int f1Score: Float failedCases: Int latencyPercentiles: JSON passRate: Float passedCases: Int precision: Float recall: Float replayGroupId: String runId: String sourceSessionId: String startedAt: String suite: String suiteBreakdown: JSON target: JSON tenantId: String tokenUsage: JSON totalCases: Int}
"""Result of executing a command in a sandbox."""type ExecResult { durationMs: Int exitCode: Int redacted: [String!] stderr: String stdout: String}
"""Billing information for a GCP project."""type GcpBillingInfo { billingAccountName: String billingEnabled: Boolean}
"""Whether the current tenant admin has a live GCP OAuth credential stored."""type GcpConnectionStatus { connected: Boolean grantedAt: DateTime hasWriteScopes: Boolean scopesGranted: String}
"""A GCP project accessible to the connected Google account."""type GcpProject { createTime: String displayName: String labels: JSON lifecycleState: String projectId: String projectNumber: String}
"""Org-scoped, cross-cutting collection of members."""type Group { archivedAt: DateTime createdAt: DateTime id: String name: String orgId: String}
"""Association linking a member into a group."""type GroupMembership { addedAt: DateTime addedBy: String groupId: String id: String memberId: String memberKind: String orgId: String removedAt: DateTime}
"""A harness artifact: an agent/model configuration preset stored in the marketplace."""type HarnessArtifact { """Kebab-case harness identifier (spec.id).""" harnessId: String
"""Marketplace artifact row id.""" id: String installedAt: DateTime spec: JSON status: String tenantId: String updatedAt: DateTime version: String}
"""A tenant-scoped honeypot / deception alert emitted by a sandbox."""type HoneypotAlert { alertType: String createdAt: DateTime id: String payload: JSON regressionLayer: Int sandboxId: String severity: String status: String tenantId: String updatedAt: DateTime}
"""A request for a time-bounded IAM role escalation reviewed by the Mnemose agent."""type IamEscalationRequest { decidedAt: DateTime decidedBy: String decisionReason: String expiresAt: DateTime id: String reason: String requestedAt: DateTime requestedBy: String status: String targetRole: String ttlSeconds: Int}
"""A role binding granting a principal access within a tenant."""type IamRoleBinding { expiresAt: DateTime grantedAt: DateTime grantedBy: String id: String isActive: Boolean principalId: String principalType: String revokedAt: DateTime revokedBy: String role: String scope: JSON ttlSeconds: Int}
input InstallAppInput { appId: String! config: JSON! source: InstallAppSourceInput! version: String!}
"""Result of an app installation request."""type InstallAppResult { appId: String status: String success: Boolean}
input InstallAppSourceInput { path: String! ref: String! repo: String!}
"""An application installed in the current tenant."""type InstalledApp { appId: String disabledAt: DateTime enabledAt: DateTime id: String installedAt: DateTime status: String version: String}
"""A pending user invite."""type Invite { acceptedAt: DateTime createdAt: DateTime email: String expiresAt: DateTime id: String invitedBy: String isPending: Boolean revokedAt: DateTime role: String}
"""Result of inviteUser — includes the one-time raw invite code."""type InviteCreated { invite: Invite rawCode: String}
scalar JSON
"""A single MCP tool invocation dispatched to a remote kernel."""type KernelInvocation { args: JSON completedAt: DateTime correlationId: String createdAt: DateTime durationMs: Int error: String issuedBy: String kernelId: String result: JSON sessionId: String status: String tool: String}
type KernelInvocationEvent { correlationId: String durationMs: Int error: String kernelId: String result: JSON status: String tool: String}
type KernelInvocationResult { correlationId: String}
type KernelMetricsEvent { collectedAt: String cpuPercent: Float diskTotalBytes: Float diskUsedBytes: Float kernelId: String loadAvg1m: Float memoryTotalBytes: Float memoryUsedBytes: Float processCount: Int uptimeSeconds: Float}
"""A time-bounded, tier-scoped session granting access above read-only on a kernel."""type KernelSession { decidedAt: DateTime decidedBy: String decisionReason: String expiresAt: DateTime id: String kernelId: String reason: String requestedAt: DateTime requestedBy: String status: String tier: String ttlSeconds: Int}
type KernelStatusEvent { kernelId: String status: String timestamp: String}
"""A single message in a chat history for direct model testing."""input LlmChatMessageInput { content: String! role: String!}
"""Result of a direct provider-pinned chat test probe against a model."""type LlmChatResult { completionTokens: Int content: String errorMessage: String latencyMs: Int model: String ok: Boolean promptTokens: Int providerKind: String requestPayload: String responsePayload: String}
"""Result of a direct minimal-cost vendor probe (max_tokens: 1, prompt: 'ping') against a model."""type LlmModelTestResult { errorMessage: String latencyMs: Int model: String ok: Boolean providerKind: String requestPayload: String responsePayload: String}
"""A per-persona LLM provider/model override for a tenant."""type LlmPersonaOverride { id: String model: String personaId: String providerConfigId: String}
"""A tenant-scoped LLM provider configuration. Credential material is never returned; only whether a credential reference is set."""type LlmProviderConfig { """Derived auth mode: "oauth", "cloud", or "token".""" authMode: String! baseUrl: String createdAt: DateTime
"""Operator-facing nickname.""" displayName: String
"""Whether an OAuth client-credentials descriptor is set.""" hasOAuth: Boolean
"""Whether an API-key secret reference is configured.""" hasSecret: Boolean id: String isDefault: Boolean model: String
"""Model entries attached to this provider kind.""" models: [LlmProviderModel!] providerKind: String updatedAt: DateTime}
"""Static metadata describing one supported LLM provider kind."""type LlmProviderKindMetadata { authModes: [String!] defaultBaseUrl: String discoverable: Boolean kind: String}
"""A discovered or manually added model for one provider kind."""type LlmProviderModel { capabilities: JSON contextWindow: Int createdAt: DateTime displayName: String enabled: Boolean id: String modelId: String params: JSON source: String updatedAt: DateTime}
"""Per-provider health, latency, and error counters from ModelRouter."""type LlmProviderStatus { averageLatencyMs: Float errorCount: Int healthy: Boolean lastError: String lastLatencyMs: Float lastUpdatedAt: String providerKind: String requestCount: Int}
"""A tenant-scoped LLM routing policy."""type LlmRoute { """Ordered candidate provider and model pairs for this route.""" candidates: [LlmRouteCandidate!] capture: String createdAt: DateTime enabled: Boolean id: String matchKind: String matchValue: String name: String strategy: String updatedAt: DateTime}
"""A candidate provider and model pair in an LLM route fallback chain."""type LlmRouteCandidate { modelId: String providerKind: String}
"""Input for a candidate provider and model pair in an LLM route."""input LlmRouteCandidateInput { modelId: String! providerKind: String!}
"""Input for creating or updating an LLM route."""input LlmRouteInput { candidates: [LlmRouteCandidateInput!]! capture: String! enabled: Boolean! matchKind: String! matchValue: String! name: String! strategy: String!}
"""A single model-call spend and token usage record."""type ModelCall { cachedTokens: Int completionTokens: Int costUsd: Float id: ID latencyMs: Int model: String payloadKey: String promptTokens: Int provider: String recordedAt: DateTime routeId: String sessionId: String status: String tenant: String usageSource: String}
"""A single model-call record with its full R2 payload (when present)."""type ModelCallDetail { cachedTokens: Int completionTokens: Int costUsd: Float id: ID latencyMs: Int model: String
"""Full captured payload JSON, null when absent or unreadable.""" payload: String payloadKey: String promptTokens: Int provider: String recordedAt: DateTime routeId: String sessionId: String status: String tenant: String usageSource: String}
"""Paginated list of model call records."""type ModelCallPage { items: [ModelCall!] limit: Int offset: Int total: Int}
"""Mnemose GraphQL mutation root"""type Mutation { """Add a member to a group (platform_admin only).""" addGroupMember(groupId: String!, memberId: String!, memberKind: String!): GroupMembership
"""Add one model entry to a configured provider kind.""" addLlmProviderModel(model: JSON!, providerKind: String!): LlmProviderModel addSeoDomain(notes: String, url: String!): JSON addSeoKeyword(domainId: ID!, keyword: String!, locale: String, projectId: ID, searchEngine: String): JSON
""" Adopt a discovered resource into Pulumi management via `pulumi import` (tenant_admin). """ adoptResource(pulumiConfig: JSON, snapshotId: String!): AdoptedResource
"""Append a message to a chat session.""" appendChatMessage(content: JSON!, role: String!, sessionId: String!): ChatMessage approveIamEscalation(escalationId: String!, reason: String!): Boolean approveKernelSession(reason: String, sessionId: String!): Boolean
"""Archive an environment (tenant_admin).""" archiveEnvironment(id: String!): Environment bindSandboxService(binding: JSON!, id: String!): Boolean
"""Queue a delegated project bootstrap flow and seed a pending state row.""" bootstrapCloudProject(agentServiceAccountEmail: String!, displayName: String!, projectId: String!, provider: String!, region: String!): BootstrapState
""" Initiate a first-time mnemose infrastructure deployment into a connected GCP project. Uses the tenant admin's stored OAuth credential as the bootstrap seed, creates IAM artifacts (service accounts, WIF pool), and runs `pulumi up`. On success, JIT credentials take over for all subsequent operations. """ bootstrapInfrastructure(input: BootstrapInfrastructureInput!): Deployment
""" Queue the control-plane organization bootstrap flow and seed a pending state row. """ bootstrapOrganization(agentServiceAccountId: String!, allowedAudiences: [String!], hostProjectId: String!, issuerUri: String!, organizationId: String!, region: String!, workloadIdentityPoolId: String!, workloadIdentityProviderId: String!): BootstrapState
"""Enqueue a report generation job. Returns the correlation ID.""" buildReport( """xlsx | csv | pdf""" format: String!
"""ISO 8601 date-time""" periodEnd: String!
"""ISO 8601 date-time""" periodStart: String!
"""Optional list of email recipients""" recipientEmails: [String!]
"""iam-activity | resource-inventory | cost-summary | security-posture""" reportType: String! ): String
""" Execute a direct provider-pinned chat test probe with message history against a configured provider model; records token spend. """ chatLlmProviderModel(maxTokens: Int, messages: [LlmChatMessageInput!]!, modelId: String!, providerKind: String!): LlmChatResult createAgentHarness(input: CreateAgentHarnessInput!): AgentHarness
"""Create a new chat session.""" createChatSession(title: String): ChatSession
"""Create a new environment in a project (tenant_admin).""" createEnvironment(cloudProjectId: String, config: JSON, name: String!, projectId: String!): Environment
"""Create an ephemeral sandbox for command execution.""" createExecSandbox(environmentId: String!, projectId: String!, spec: SandboxSpecInput!): SandboxExec
"""Create a group in an org (platform_admin only).""" createGroup(name: String!, orgId: String!): Group
""" Create a harness artifact from a structured spec. Validates against HarnessSpecSchema and persists directly. """ createHarness(input: JSON!): HarnessArtifact
"""Create a new LLM routing policy for the current tenant.""" createLlmRoute(input: LlmRouteInput!): LlmRoute
"""Create a new org (platform_admin only).""" createOrg(name: String!): Org
"""Create a project in a workspace (tenant_admin).""" createProject(name: String!, workspaceId: String!): Project
"""Create a new project-agent binding (tenant_admin).""" createProjectAgent(agentId: String!, agentName: String!, autonomyLevel: String, permissions: JSON, projectId: String!): ProjectAgent createSandbox(input: CreateSandboxInput!): Sandbox createSeoProject(cadence: String, geoCountry: String!, geoLocale: String, geoLocation: String, name: String!): JSON
"""Create a new tenant (platform_admin only).""" createTenant(name: String!, primaryCloudProvider: String! = "gcp", tier: String! = "starter"): Tenant
"""Provision a new KMS key for the current tenant.""" createTenantKey(algorithm: String = "GOOGLE_SYMMETRIC_ENCRYPTION", displayName: String!, purpose: String! = "encrypt_decrypt", rotationPeriodDays: Int): TenantKmsKey
"""Create a workspace in the current tenant (tenant_admin).""" createWorkspace(name: String!): Workspace delegateCloudProject(displayName: String!, projectId: String!, provider: String!, region: String!, serviceAccountEmail: String!, wifPoolId: String!): CloudProject deleteAgentHarness(id: String!): Boolean
"""Delete a chat session and its messages.""" deleteChatSession(id: String!): Boolean
""" Delete a harness artifact row for the acting tenant. Returns false when not found. """ deleteHarness(id: String!): Boolean
"""Delete the current tenant's configuration for one provider kind.""" deleteLlmProviderConfig(providerKind: String!): Boolean
"""Delete an LLM routing policy for the current tenant.""" deleteLlmRoute(id: String!): Boolean
""" Delete a retention policy; falls back to the tenant default / global retention. """ deleteRetentionPolicy(class: String!, scope: RetentionScope!): Boolean
"""Delete a tenant tool permission policy rule by pattern.""" deleteToolPermission(toolPattern: String!): Boolean denyIamEscalation(escalationId: String!, reason: String!): Boolean denyKernelSession(reason: String, sessionId: String!): Boolean
""" Trigger a `pulumi up` on an already-bootstrapped managed project. Uses JIT credentials minted from the project's WIF configuration. """ deployInfrastructure(input: DeployInfrastructureInput!): Deployment
"""Destroy an ephemeral sandbox.""" destroyExecSandbox(sandboxId: String!): Boolean destroySandbox(id: String!, reason: String): Boolean destroyTenantKeyVersion(id: String!, version: String!): Boolean
"""Disable an installed app without uninstalling it.""" disableApp(input: DisableAppInput!): DisableAppResult
"""Trigger a discovery scan using a provisioned principal (operator+).""" discoverResources(principalId: String!): DiscoveryScan
"""Enable a previously installed but disabled app.""" enableApp(input: EnableAppInput!): EnableAppResult enrollKernel(input: EnrollKernelInput!): EnrollKernelResult
"""Execute a command in an ephemeral sandbox.""" execInSandbox(command: String!, env: JSON, sandboxId: String!, stdin: String): ExecResult
"""Grant a role binding scoped to a project.""" grantProjectRoleBinding(principalId: String!, principalType: String!, projectId: String!, role: String!, ttlSeconds: Int): IamRoleBinding grantRoleBinding(principalId: String!, principalType: String!, role: String!, scope: JSON, ttlSeconds: Int): IamRoleBinding grantSandboxFacet(grant: JSON!, id: String!): Boolean
""" Import a harness artifact from a raw JSON document (string or object). Same validation layer as createHarness. """ importHarness(json: JSON!): HarnessArtifact
"""Request installation of an app from the App Store.""" installApp(input: InstallAppInput!): InstallAppResult
"""Invite a user by email to the current tenant.""" inviteUser(email: String!, role: String!, ttlDays: Int = 7): InviteCreated
""" Dispatch a tool call to a connected agent-kernel. Read-only tools require no session. Returns a correlationId to track the result via the onKernelInvocation subscription. """ invokeKernelTool(args: JSON, kernelId: UUID!, tool: String!): KernelInvocationResult
""" Orphan an adopted resource, removing it from Pulumi management without destroying the cloud resource (tenant_admin). """ orphanResource(reason: String!, snapshotId: String!): AdoptedResource
""" Run a non-destructive `pulumi preview` and return the structured change diff in pulumiOutputsJson once complete. """ previewInfrastructure(input: PreviewInfrastructureInput!): Deployment
""" Provision a short-lived discovery principal for cloud resource enumeration (tenant_admin). """ provisionDiscoveryPrincipal(principalEmail: String!, projectId: String, roles: [String!]!, tenantId: String!, ttlMinutes: Int!): DiscoveryPrincipal
""" Idempotently upserts all core kernels declared in the CoreManifest. Safe to call repeatedly. """ provisionPlatformCore: Boolean
"""Enqueue a resource provisioning job. Returns the correlation ID.""" provisionResource( cloudProjectId: String! reason: String!
"""JSON-serialised ResourceProvisionSpec""" specJson: String! ): String
""" Run `pulumi refresh` to detect infrastructure drift: reconcile Pulumi state against live GCP resources and update the state file. """ refreshInfrastructure(input: RefreshInfrastructureInput!): Deployment
""" Register the platform's own Cloudflare account as a managed cloud project. Called by the installer after a successful deploy. Idempotent. """ registerSelf(projectId: String!, region: String!, serviceAccountEmail: String!, tenantId: String): RegisterSelfResult
"""Dynamically register or update a tool definition.""" registerTool(input: RegisterToolInput!): ToolEntry
""" Enqueue a security finding remediation job. Returns the correlation ID. """ remediateFinding(action: String!, agentReasoning: String!, cloudProjectId: String!, findingId: String!, requiresHumanConfirmation: Boolean = false): String
"""Remove a member from a group (platform_admin only).""" removeGroupMember(groupId: String!, memberId: String!, memberKind: String!): Boolean
"""Remove one model entry from a configured provider kind.""" removeLlmProviderModel(modelId: String!, providerKind: String!): Boolean
"""Remove a project-agent binding (tenant_admin).""" removeProjectAgent(id: String!): Boolean removeSeoKeyword(keywordId: ID!): Boolean
""" Derive evaluation cases from a chat session transcript and run them against a model or harness target """ replaySession(input: ReplaySessionInput!): EvaluationScorecard requestIamEscalation(input: RequestIamEscalationInput!): IamEscalationRequest requestKernelSession(input: RequestKernelSessionInput!): KernelSession
""" Revoke (tombstone) a discovery principal before its TTL expires (tenant_admin). """ revokeDiscoveryPrincipal(id: String!, reason: String!): DiscoveryPrincipal revokeInvite(id: String!): Boolean revokeKernel(kernelId: String!, reason: String): Boolean
"""Revoke a project-scoped role binding.""" revokeProjectRoleBinding(id: String!): IamRoleBinding revokeRoleBinding(id: String!): IamRoleBinding revokeSandboxFacet(id: String!, personaId: String!): Boolean rotateTenantKey(id: String!): TenantKmsKey
"""Trigger benchmark evaluation on a model, agent, or harness target""" runEvaluation(input: RunEvaluationInput!): EvaluationScorecard
""" Set a per-persona provider override. The provider kind must already be configured for the tenant. """ setLlmPersonaOverride(model: String, personaId: String!, providerKind: String!): LlmPersonaOverride
""" Create or replace the current tenant's configuration for one provider kind. Omitted credential references and model are carried forward from the stored row so edits without re-keying preserve credentials. """ setLlmProviderConfig(baseUrl: String, cloudCredentialRef: JSON, displayName: String, extra: JSON, isDefault: Boolean, model: String, oauth: JSON, providerKind: String!, secretRef: String): LlmProviderConfig
""" Store an API-key secret value in Secret Manager under the given reference. The value is write-only and never returned. """ setLlmProviderSecret(secretRef: String!, value: String!): Boolean
"""Create or update a tenant tool permission policy rule.""" setToolPermission(input: SetToolPermissionInput!): ToolPermissionRule suspendTenant(id: String!): Tenant suspendUser(id: String!): User
""" Fetch vendor models for a configured provider kind and atomically replace the tenant's discovered model catalog. """ syncLlmProviderModels(providerKind: String!): [LlmProviderModel!] syncResourceInventory(cloudProjectId: String!): Boolean
""" Execute a direct minimal-cost vendor probe (max_tokens: 1, prompt: 'ping') against a configured provider model. """ testLlmProviderModel(modelId: String!, providerKind: String!): LlmModelTestResult unbindSandboxService(id: String!, name: String!): Boolean
"""Request uninstallation of an installed app.""" uninstallApp(input: UninstallAppInput!): UninstallAppResult unsuspendTenant(id: String!): Tenant unsuspendUser(id: String!): User updateAgentHarness(id: String!, input: UpdateAgentHarnessInput!): Boolean
""" Update an installed app's per-tenant configuration (and optionally bump its version). """ updateAppConfig(input: UpdateAppConfigInput!): UpdateAppConfigResult
"""Update a chat session's title.""" updateChatSessionTitle(id: String!, title: String!): ChatSession
"""Update an existing environment (tenant_admin).""" updateEnvironment(cloudProjectId: String, config: JSON, id: String!, name: String): Environment updateKeyRotationPolicy(id: String!, rotationPeriodDays: Int!): TenantKmsKey
"""Patch display name, enabled flag, or params on one model.""" updateLlmProviderModel(modelId: String!, patch: JSON!, providerKind: String!): LlmProviderModel
"""Update an existing LLM routing policy for the current tenant.""" updateLlmRoute(id: String!, input: LlmRouteInput!): LlmRoute
"""Update an existing project-agent binding (tenant_admin).""" updateProjectAgent(autonomyLevel: String, id: String!, permissions: JSON): ProjectAgent updateSandboxDataSources(dataSources: JSON!, id: String!): Boolean updateSandboxDeceptionPolicy(deception: JSON!, id: String!): Boolean updateSandboxNetworkPolicy(id: String!, network: JSON!): Boolean updateTenantTier(id: String!, tier: String!): Tenant updateUserRole(id: String!, role: String!): User
""" Create or update a retention policy. Omit durationDays (or pass null) to retain forever. """ upsertRetentionPolicy(class: String!, durationDays: Int, scope: RetentionScope!): RetentionPolicy verifySeoDomain(domainId: ID!, method: String): JSON}
"""Top-level ownership root that owns tenants and groups."""type Org { createdAt: DateTime id: String name: String suspendedAt: DateTime}
"""Result of evaluating tool permissions for an actor."""type PermissionEvaluationResult { allowed: Boolean matchedPattern: String policy: String reason: String requiresApproval: Boolean}
"""Health of the platform core — declarative manifest vs. enrolled kernels."""type PlatformCoreHealth { healthy: Boolean kernels: [CoreKernelStatus!]}
"""Run a non-destructive `pulumi preview` and return the structured diff."""input PreviewInfrastructureInput { cloudProjectId: String!}
"""Workspace-scoped organizational container."""type Project { archivedAt: DateTime createdAt: DateTime id: String name: String tenantId: String workspaceId: String}
"""Per-project agent configuration binding with autonomy level and permissions."""type ProjectAgent { agentId: String agentName: String autonomyLevel: String createdAt: DateTime id: String permissions: JSON projectId: String updatedAt: DateTime}
"""A tracked resource provisioning job."""type ProvisionJob { cloudProjectId: String createdAt: DateTime error: String id: String issuedBy: String reason: String resourceId: String resourceType: String status: String updatedAt: DateTime}
"""Live provisioning status from the Sandbox Durable Object."""type ProvisionStatus { mode: String provisionError: String remoteSandboxId: String state: String}
"""Mnemose GraphQL query root"""type Query { """Get a single adopted resource by ID.""" adoptedResource(id: String!): AdoptedResource
"""List adopted resources for a project in the current tenant.""" adoptedResources(projectId: String!): [AdoptedResource!]
"""Fetch a single agent harness by id for the acting tenant.""" agentHarness(id: String!): AgentHarness
"""List agent harnesses for the acting tenant, newest first.""" agentHarnesses: [AgentHarness!]
"""Get a single installed app by ID.""" app(id: String!): InstalledApp
"""Get health status for an installed app.""" appHealth(id: String!): AppHealth
"""List all apps available in the Mnemose App Store catalog.""" availableApps: [AppStoreCard!]
""" List registered cloud-provider artifacts for the current tenant with install status (ADR 0012, M-4). """ availableCloudProviders: [CloudProvider!]
"""All LLM provider kinds the platform supports.""" availableLlmProviderKinds: [String!]
""" List visible bootstrap state rows for the current operator tenant, including control-plane rows with no tenant. """ bootstrapStates(targetType: String): [BootstrapState!]
"""Get a single chat session with its messages.""" chatSession(id: String!): ChatSessionWithMessages
"""List chat sessions for the authenticated tenant.""" chatSessions: [ChatSession!] cloudProjects: [CloudProject!]
"""Deployment profile of this Mnemose instance: 'solo' or 'prod'.""" deploymentProfile: String
"""List all deployment operations for this tenant.""" deployments(cloudProjectId: String): [Deployment!]
"""Get a single environment by ID.""" environment(id: String!): Environment
"""List environments for a project in the current tenant.""" environments(projectId: String!): [Environment!]
"""Evaluate if a specific tool can be executed by the current actor.""" evaluateToolPermission(riskScore: Int, toolName: String!): PermissionEvaluationResult
"""Get detailed scorecard for a specific evaluation run ID""" evaluationRun(id: String!): EvaluationScorecard
"""List historical evaluation runs and scorecards for the acting tenant""" evaluationRuns: [EvaluationScorecard!]
"""Get a single ephemeral sandbox by ID.""" execSandbox(id: String!): SandboxExec
"""List active ephemeral sandboxes.""" execSandboxes(projectId: String!): [SandboxExec!]
"""Billing status for a specific GCP project.""" gcpBillingInfo(projectId: String!): GcpBillingInfo
""" Returns whether the current tenant admin has a connected GCP account and what scopes were granted. """ gcpConnectionStatus: GcpConnectionStatus
"""List all GCP projects accessible to the connected Google account.""" gcpProjects: [GcpProject!]
"""Fetch a single harness artifact by its kebab-case id.""" getHarness(id: String!): HarnessArtifact
"""List tool permission rules for the active tenant.""" getToolPermissions: [ToolPermissionRule!]
"""List active members of a group (platform_admin only).""" groupMembers(groupId: String!): [GroupMembership!]
"""List groups in an org (platform_admin only).""" groups(orgId: String!): [Group!] honeypotAlerts(limit: Int, sandboxId: String, severity: String, status: String): [HoneypotAlert!] iamEscalation(id: String!): IamEscalationRequest iamEscalations: [IamEscalationRequest!]
"""List active IAM role bindings in the current tenant.""" iamRoleBindings(principalId: String, principalType: String): [IamRoleBinding!]
"""List all apps installed in the current tenant.""" installedApps: [InstalledApp!]
"""List pending invites in the current tenant.""" invites: [Invite!] kernel(id: String!): AgentKernel kernelInvocations(kernelId: String!, limit: Int): [KernelInvocation!] kernelSessions(kernelId: String, status: String): [KernelSession!] kernels(status: String): [AgentKernel!]
"""List harness artifacts for the acting tenant, newest installed first.""" listHarnesses: [HarnessArtifact!]
"""List all indexed tools, optionally filtered by source or category.""" listTools(category: String, source: String): [ToolEntry!]
"""List the current tenant's per-persona LLM overrides.""" llmPersonaOverrides: [LlmPersonaOverride!]
"""List the current tenant's configured LLM providers.""" llmProviderConfigs: [LlmProviderConfig!]
"""Static per-kind defaults (base URL, auth modes, discoverability).""" llmProviderKindMetadata: [LlmProviderKindMetadata!]
""" Per-provider health, latency, and error counters from ModelRouter telemetry. """ llmProviderStatus: [LlmProviderStatus!]
"""List the current tenant's LLM routing policies ordered by name.""" llmRoutes: [LlmRoute!]
"""Single model-call drill-down with full payload, tenant-scoped.""" modelCall(id: ID!): ModelCallDetail
"""Paginated tenant model-call records, newest first.""" modelCalls(limit: Int, offset: Int): ModelCallPage
"""List all tenants the current user has access to.""" myTenants: [TenantMembership!] org(id: String!): Org
"""List all orgs (platform_admin only).""" orgs: [Org!]
"""Health of the platform core kernels as declared in the CoreManifest.""" platformCore: PlatformCoreHealth project(id: String!): Project
"""Get a single project agent by ID.""" projectAgent(id: String!): ProjectAgent
"""List project agents for a project in the current tenant.""" projectAgents(projectId: String!): [ProjectAgent!]
"""List active role bindings scoped to a project.""" projectRoleBindings(projectId: String!): [IamRoleBinding!]
"""List projects in the current tenant, optionally by workspace.""" projects(workspaceId: String): [Project!] provisionJobs(cloudProjectId: String!): [ProvisionJob!] provisionStatus(id: String!): ProvisionStatus remediationJobs(cloudProjectId: String!): [RemediationJob!]
"""List all report jobs for this tenant.""" reports: [Report!] resources(cloudProjectId: String!, resourceType: String): [ResourceSnapshot!]
"""Tenant-scoped retention policies, optionally filtered by scope.""" retentionPolicies(scope: RetentionScope): [RetentionPolicy!] sandbox(id: String!): Sandbox sandboxes(status: String): [Sandbox!]
"""Semantic and keyword search for tools by natural language query.""" searchTools(category: String, limit: Int, query: String!, source: String): SearchResponse seoCompetitors(limit: Int): [JSON!] seoDomains: [JSON!] seoKeywords(domainId: ID): [JSON!] seoProjects: [JSON!] seoRankings(keywordId: ID, limit: Int): [JSON!] tenant(id: String!): Tenant tenantKey(id: String!): TenantKmsKey
"""List KMS keys for the current tenant.""" tenantKeys: [TenantKmsKey!]
"""List all tenants (platform_admin only).""" tenants: [Tenant!] user(id: String!): User
"""List users in the current tenant.""" users: [User!] workspace(id: String!): Workspace
"""List workspaces in the current tenant.""" workspaces: [Workspace!]}
"""Run `pulumi refresh` to reconcile Pulumi state against the live GCP resources (drift detection)."""input RefreshInfrastructureInput { cloudProjectId: String!}
"""Result of registering the platform's own infrastructure as a managed cloud project."""type RegisterSelfResult { cloudProjectId: String credentialsValidated: Boolean tenantId: String}
input RegisterToolInput { category: String description: String! inputSchema: JSON name: String! outputSchema: JSON source: String! sourceLocation: String! tags: [String!] version: String}
"""A tracked security finding remediation job."""type RemediationJob { action: String agentReasoning: String cloudProjectId: String createdAt: DateTime error: String findingId: String id: String issuedBy: String requiresHuman: Boolean status: String updatedAt: DateTime}
input ReplaySessionInput { maxCases: Int replayGroupId: String sourceChatSessionId: String! targetId: String! targetType: String!}
"""A generated report job."""type Report { createdAt: DateTime error: String fileSizeBytes: Int format: String id: String issuedBy: String periodEnd: DateTime periodStart: DateTime reportType: String signedDownloadUrl: String status: String updatedAt: DateTime}
input RequestIamEscalationInput { reason: String! scopeKind: String! scopeProjectId: String targetRole: String! ttlSeconds: Int!}
input RequestKernelSessionInput { kernelId: String! reason: String! tier: String! ttlSeconds: Int!}
"""Point-in-time snapshot of a cloud resource captured by the inventory sync."""type ResourceSnapshot { displayName: String firstSeenAt: DateTime id: String labels: JSON region: String resourceId: String resourceType: String state: String syncedAt: DateTime}
"""A tenant-managed retention window for a scope/class pair. durationDays null = infinite."""type RetentionPolicy { class: String durationDays: Int id: ID scope: String tenantId: String updatedAt: DateTime}
enum RetentionScope { metrics payloads}
input RunEvaluationInput { suites: [String!] targetId: String! targetType: String!}
"""An isolated compute environment with configurable policies and bindings."""type Sandbox { compute: JSON createdAt: DateTime createdBy: String dataSources: JSON deception: JSON destroyedAt: DateTime grants: JSON id: String label: String network: JSON owner: JSON provisionError: String services: JSON status: String suspendedAt: DateTime tenantId: String tools: JSON}
"""An ephemeral sandbox created via the execution layer."""type SandboxExec { command: String createdAt: DateTime environmentId: String id: String image: String projectId: String status: String ttl: Int}
input SandboxSpecInput { command: [String!]! env: JSON image: String! network: JSON resources: JSON ttl: Int}
"""Response from a semantic tool search."""type SearchResponse { tools: [ToolEntry!] total: Int}
input SetToolPermissionInput { allowedRoles: [String!] autoApprovalThreshold: Int autoApprove: Boolean = false deniedRoles: [String!] policy: String! reason: String toolPattern: String!}
"""Mnemose GraphQL subscription root"""type Subscription { """ Subscribe to real-time status updates for a specific deployment operation. """ deploymentStatus(deploymentId: String!): Deployment
"""Subscribe to environment creation events for the current tenant.""" environmentCreated(tenantId: String!): Environment
"""Subscribe to IAM role binding changes (revoke).""" onIamBindingChanged: IamRoleBinding
""" Subscribe to invocation lifecycle events (dispatched/completed/failed) for a kernel. """ onKernelInvocation(kernelId: UUID!): KernelInvocationEvent
""" Subscribe to periodic metrics snapshots for a kernel (published every ~30 s while connected). """ onKernelMetrics(kernelId: UUID!): KernelMetricsEvent
""" Subscribe to kernel status changes (online/offline/revoked). Pass kernelId to filter to a single kernel. """ onKernelStatusChanged(kernelId: UUID): KernelStatusEvent
""" Subscribe to tenant status changes (suspend/unsuspend). Platform admin only. """ onTenantChanged: Tenant
"""Subscribe to user status/role changes (suspend/unsuspend/updateRole).""" onUserChanged: User}
"""A Mnemose platform tenant."""type Tenant { createdAt: DateTime id: String isActive: Boolean name: String primaryCloudProvider: String suspendedAt: DateTime tier: String}
"""A tenant-scoped encryption key managed in GCP Cloud KMS."""type TenantKmsKey { algorithm: String createdAt: DateTime destroyedAt: DateTime displayName: String id: String keyName: String keyRingName: String primaryVersion: String purpose: String rotatedAt: DateTime rotationPeriodDays: Int state: String}
"""A tenant the current user has access to, with their role."""type TenantMembership { role: String tenant: Tenant}
"""A single indexed tool entry in the registry."""type ToolEntry { category: String description: String id: String indexedAt: DateTime inputSchema: JSON name: String outputSchema: JSON source: String sourceLocation: String tags: [String!] version: String}
"""A tenant-scoped tool permission policy rule."""type ToolPermissionRule { allowedRoles: [String!] autoApprovalThreshold: Int autoApprove: Boolean deniedRoles: [String!] id: String policy: String reason: String tenantId: String toolPattern: String}
scalar UUID
input UninstallAppInput { appId: String! purgeData: Boolean! = false}
"""Result of an app uninstallation request."""type UninstallAppResult { appId: String status: String success: Boolean}
input UpdateAgentHarnessInput { description: String hitlTier: String maxSteps: Int mode: String modelId: String name: String providerKind: String temperature: Float toolIds: [String!] vectorStoreRefs: [String!]}
input UpdateAppConfigInput { appId: String! config: JSON! version: String}
"""Result of an app config update request."""type UpdateAppConfigResult { appId: String status: String success: Boolean}
"""A Mnemose platform user."""type User { activatedAt: DateTime createdAt: DateTime displayName: String email: String id: String invitedAt: DateTime invitedBy: String isActive: Boolean role: String suspendedAt: DateTime tenantId: String}
"""Tenant-scoped container for projects."""type Workspace { archivedAt: DateTime createdAt: DateTime id: String name: String tenantId: String}