Skip to content

GraphQL API

The schema below is the committed contract for the Mnemose GraphQL gateway. It is auto-generated from the Pothos schema builder — do not edit manually.

To regenerate: pnpm --filter @mnemose/gateway schema:export To verify: pnpm --filter @mnemose/gateway schema:check

"""A cloud resource that has been adopted into Pulumi management."""
type AdoptedResource {
adoptedAt: DateTime
adoptedBy: String
id: String
pulumiResourceId: String
pulumiStatePath: String
snapshotId: String
status: String
tenantId: String
}
"""
An agent harness: provider, model, execution policy, and attached tools.
"""
type AgentHarness {
createdAt: DateTime
description: String
hitlTier: String
id: String
maxSteps: Int
mode: String
modelId: String
name: String
providerKind: String
temperature: Float
tenantId: String
tools: [AgentHarnessTool!]
updatedAt: DateTime
vectorStoreRefs: [String!]
}
"""A tool attached to an agent harness with a permission tier."""
type AgentHarnessTool {
permissionTier: String
toolId: String
}
"""A remote agent-kernel instance enrolled in the Mnemose platform."""
type AgentKernel {
capabilities: JSON
certFingerprint: String
enrolledAt: DateTime
enrolledBy: String
fleetMode: String
id: String
label: String
lastSeenAt: DateTime
permissionTier: String
revokedAt: DateTime
revokedReason: String
status: String
tags: [String!]
}
"""Health status of an installed application."""
type AppHealth {
appId: String
errors: [String!]
healthy: Boolean
}
"""An application available in the Mnemose App Store."""
type AppStoreCard {
category: String
description: String
featured: Boolean
icon: String
id: String
name: String
pricing: String
sourcePath: String
sourceRef: String
sourceRepo: String
vendor: String
version: String
}
"""
Configuration required for the first-time mnemose infrastructure deploy. Uses the tenant admin's connected GCP OAuth credential as the bootstrap seed.
"""
input BootstrapInfrastructureInput {
"""
Secret Manager reference (e.g. projects/{project}/secrets/{name}/versions/{version}) to the Cloud SQL database password. The raw secret value is fetched at execution time by the command handler via the Secret Manager API and never published over Pub/Sub.
"""
dbPasswordSecretRef: String!
"""Human-readable name for this managed project."""
displayName: String!
"""Target environment label, e.g. "production" or "staging"."""
env: String!
"""The GCP project ID to deploy into."""
gcpProjectId: String!
"""Docker image tag to deploy. Defaults to "latest"."""
imageTag: String
"""
Secret Manager reference (e.g. projects/{project}/secrets/{name}/versions/{version}) to the LLM provider API key. The raw secret value is fetched at execution time by the command handler via the Secret Manager API and never published over Pub/Sub.
"""
llmApiKeySecretRef: String!
"""GCP region, e.g. "us-central1"."""
region: String!
"""GCS bucket name for reports. Defaults to {project}-mnemose-reports."""
reportsBucketName: String
}
"""Current status for a control-plane bootstrap target."""
type BootstrapState {
createdAt: DateTime
error: String
id: String
metadata: JSON
phase: String
status: String
targetId: String
targetType: String
tenantId: String
updatedAt: DateTime
}
"""A single message within a chat session."""
type ChatMessage {
content: JSON
createdAt: DateTime
id: String
role: String
sessionId: String
}
"""A persisted operator chat session."""
type ChatSession {
createdAt: DateTime
id: String
status: String
tenantId: String
title: String
updatedAt: DateTime
}
"""A chat session with its full message history."""
type ChatSessionWithMessages {
createdAt: DateTime
id: String
messages: [ChatMessage!]
status: String
tenantId: String
title: String
updatedAt: DateTime
}
"""A delegated customer cloud project under Mnemose management."""
type CloudProject {
delegatedAt: DateTime
displayName: String
id: String
projectId: String
provider: String
region: String
}
"""A registered cloud-provider artifact for the tenant (ADR 0012, M-4)."""
type CloudProvider {
appId: String
"""Whether this is the protected core cloud-provider artifact."""
core: Boolean
installedAt: DateTime
kind: String
status: String
}
"""
Health status of a single core kernel declared in the deployment manifest.
"""
type CoreKernelStatus {
id: String
label: String
permissionTier: String
platform: String
role: String
status: String
}
input CreateAgentHarnessInput {
description: String
hitlTier: String
maxSteps: Int
mode: String
modelId: String!
name: String!
providerKind: String!
temperature: Float
toolIds: [String!]
vectorStoreRefs: [String!]
}
input CreateSandboxInput {
compute: JSON!
dataSources: JSON
deception: JSON
grants: JSON
label: String!
network: JSON!
owner: JSON
services: JSON
tools: JSON!
}
scalar DateTime
"""
Trigger a Pulumi `up` on an already-bootstrapped managed project using JIT credentials.
"""
input DeployInfrastructureInput {
"""ID of the managed cloud project record."""
cloudProjectId: String!
"""Docker image tag to deploy."""
imageTag: String
}
"""A Pulumi Automation API operation record."""
type Deployment {
cloudProjectId: String
command: String
completedAt: DateTime
errorMessage: String
id: String
initiatedAt: DateTime
initiatedBy: String
pulumiOutputsJson: JSON
stackName: String
status: String
}
input DisableAppInput {
appId: String!
}
"""Result of an app disable request."""
type DisableAppResult {
appId: String
status: String
success: Boolean
}
"""A cloud resource discovered during a discovery scan."""
type DiscoveredResource {
id: String
metadata: JSON
projectId: String
provider: String
region: String
resourceId: String
resourceType: String
}
"""
A short-lived service account provisioned for cloud resource discovery.
"""
type DiscoveryPrincipal {
createdBy: String
id: String
principalEmail: String
projectId: String
provisionedAt: DateTime
roles: JSON
tenantId: String
tombstonedAt: DateTime
ttlExpiresAt: DateTime
}
"""A discovery scan result for a principal."""
type DiscoveryScan {
completedAt: DateTime
id: String
principalId: String
resourcesFound: Int
startedAt: DateTime
status: String
}
input EnableAppInput {
appId: String!
}
"""Result of an app enable request."""
type EnableAppResult {
appId: String
status: String
success: Boolean
}
input EnrollKernelInput {
fleetMode: String!
label: String!
permissionTier: String!
tags: [String!]
}
"""Bootstrap token and install command returned after kernel enrollment."""
type EnrollKernelResult {
bootstrapToken: String
installCommand: String
kernelId: String
}
"""
Project-scoped deployment target that may optionally link to a delegated cloud project.
"""
type Environment {
archivedAt: DateTime
cloudProjectId: UUID
config: JSON
createdAt: DateTime
id: String
name: String
projectId: String
}
"""Result of a single evaluation case"""
type EvaluationCaseResult {
completionTokens: Int
estimatedCostUsd: Float
failureReason: String
latencyMs: Int
model: String
passed: Boolean
promptTokens: Int
rawResponse: String
score: Float
suite: String
testCaseId: String
testCaseName: String
}
"""Evaluation run summary and detailed scorecard"""
type EvaluationScorecard {
accuracy: Float
averageLatencyMs: Float
averageScore: Float
caseResults: [EvaluationCaseResult!]
completedAt: String
durationMs: Int
f1Score: Float
failedCases: Int
latencyPercentiles: JSON
passRate: Float
passedCases: Int
precision: Float
recall: Float
replayGroupId: String
runId: String
sourceSessionId: String
startedAt: String
suite: String
suiteBreakdown: JSON
target: JSON
tenantId: String
tokenUsage: JSON
totalCases: Int
}
"""Result of executing a command in a sandbox."""
type ExecResult {
durationMs: Int
exitCode: Int
redacted: [String!]
stderr: String
stdout: String
}
"""Billing information for a GCP project."""
type GcpBillingInfo {
billingAccountName: String
billingEnabled: Boolean
}
"""
Whether the current tenant admin has a live GCP OAuth credential stored.
"""
type GcpConnectionStatus {
connected: Boolean
grantedAt: DateTime
hasWriteScopes: Boolean
scopesGranted: String
}
"""A GCP project accessible to the connected Google account."""
type GcpProject {
createTime: String
displayName: String
labels: JSON
lifecycleState: String
projectId: String
projectNumber: String
}
"""Org-scoped, cross-cutting collection of members."""
type Group {
archivedAt: DateTime
createdAt: DateTime
id: String
name: String
orgId: String
}
"""Association linking a member into a group."""
type GroupMembership {
addedAt: DateTime
addedBy: String
groupId: String
id: String
memberId: String
memberKind: String
orgId: String
removedAt: DateTime
}
"""
A harness artifact: an agent/model configuration preset stored in the marketplace.
"""
type HarnessArtifact {
"""Kebab-case harness identifier (spec.id)."""
harnessId: String
"""Marketplace artifact row id."""
id: String
installedAt: DateTime
spec: JSON
status: String
tenantId: String
updatedAt: DateTime
version: String
}
"""A tenant-scoped honeypot / deception alert emitted by a sandbox."""
type HoneypotAlert {
alertType: String
createdAt: DateTime
id: String
payload: JSON
regressionLayer: Int
sandboxId: String
severity: String
status: String
tenantId: String
updatedAt: DateTime
}
"""
A request for a time-bounded IAM role escalation reviewed by the Mnemose agent.
"""
type IamEscalationRequest {
decidedAt: DateTime
decidedBy: String
decisionReason: String
expiresAt: DateTime
id: String
reason: String
requestedAt: DateTime
requestedBy: String
status: String
targetRole: String
ttlSeconds: Int
}
"""A role binding granting a principal access within a tenant."""
type IamRoleBinding {
expiresAt: DateTime
grantedAt: DateTime
grantedBy: String
id: String
isActive: Boolean
principalId: String
principalType: String
revokedAt: DateTime
revokedBy: String
role: String
scope: JSON
ttlSeconds: Int
}
input InstallAppInput {
appId: String!
config: JSON!
source: InstallAppSourceInput!
version: String!
}
"""Result of an app installation request."""
type InstallAppResult {
appId: String
status: String
success: Boolean
}
input InstallAppSourceInput {
path: String!
ref: String!
repo: String!
}
"""An application installed in the current tenant."""
type InstalledApp {
appId: String
disabledAt: DateTime
enabledAt: DateTime
id: String
installedAt: DateTime
status: String
version: String
}
"""A pending user invite."""
type Invite {
acceptedAt: DateTime
createdAt: DateTime
email: String
expiresAt: DateTime
id: String
invitedBy: String
isPending: Boolean
revokedAt: DateTime
role: String
}
"""Result of inviteUser — includes the one-time raw invite code."""
type InviteCreated {
invite: Invite
rawCode: String
}
scalar JSON
"""A single MCP tool invocation dispatched to a remote kernel."""
type KernelInvocation {
args: JSON
completedAt: DateTime
correlationId: String
createdAt: DateTime
durationMs: Int
error: String
issuedBy: String
kernelId: String
result: JSON
sessionId: String
status: String
tool: String
}
type KernelInvocationEvent {
correlationId: String
durationMs: Int
error: String
kernelId: String
result: JSON
status: String
tool: String
}
type KernelInvocationResult {
correlationId: String
}
type KernelMetricsEvent {
collectedAt: String
cpuPercent: Float
diskTotalBytes: Float
diskUsedBytes: Float
kernelId: String
loadAvg1m: Float
memoryTotalBytes: Float
memoryUsedBytes: Float
processCount: Int
uptimeSeconds: Float
}
"""
A time-bounded, tier-scoped session granting access above read-only on a kernel.
"""
type KernelSession {
decidedAt: DateTime
decidedBy: String
decisionReason: String
expiresAt: DateTime
id: String
kernelId: String
reason: String
requestedAt: DateTime
requestedBy: String
status: String
tier: String
ttlSeconds: Int
}
type KernelStatusEvent {
kernelId: String
status: String
timestamp: String
}
"""A single message in a chat history for direct model testing."""
input LlmChatMessageInput {
content: String!
role: String!
}
"""Result of a direct provider-pinned chat test probe against a model."""
type LlmChatResult {
completionTokens: Int
content: String
errorMessage: String
latencyMs: Int
model: String
ok: Boolean
promptTokens: Int
providerKind: String
requestPayload: String
responsePayload: String
}
"""
Result of a direct minimal-cost vendor probe (max_tokens: 1, prompt: 'ping') against a model.
"""
type LlmModelTestResult {
errorMessage: String
latencyMs: Int
model: String
ok: Boolean
providerKind: String
requestPayload: String
responsePayload: String
}
"""A per-persona LLM provider/model override for a tenant."""
type LlmPersonaOverride {
id: String
model: String
personaId: String
providerConfigId: String
}
"""
A tenant-scoped LLM provider configuration. Credential material is never returned; only whether a credential reference is set.
"""
type LlmProviderConfig {
"""Derived auth mode: "oauth", "cloud", or "token"."""
authMode: String!
baseUrl: String
createdAt: DateTime
"""Operator-facing nickname."""
displayName: String
"""Whether an OAuth client-credentials descriptor is set."""
hasOAuth: Boolean
"""Whether an API-key secret reference is configured."""
hasSecret: Boolean
id: String
isDefault: Boolean
model: String
"""Model entries attached to this provider kind."""
models: [LlmProviderModel!]
providerKind: String
updatedAt: DateTime
}
"""Static metadata describing one supported LLM provider kind."""
type LlmProviderKindMetadata {
authModes: [String!]
defaultBaseUrl: String
discoverable: Boolean
kind: String
}
"""A discovered or manually added model for one provider kind."""
type LlmProviderModel {
capabilities: JSON
contextWindow: Int
createdAt: DateTime
displayName: String
enabled: Boolean
id: String
modelId: String
params: JSON
source: String
updatedAt: DateTime
}
"""Per-provider health, latency, and error counters from ModelRouter."""
type LlmProviderStatus {
averageLatencyMs: Float
errorCount: Int
healthy: Boolean
lastError: String
lastLatencyMs: Float
lastUpdatedAt: String
providerKind: String
requestCount: Int
}
"""A tenant-scoped LLM routing policy."""
type LlmRoute {
"""Ordered candidate provider and model pairs for this route."""
candidates: [LlmRouteCandidate!]
capture: String
createdAt: DateTime
enabled: Boolean
id: String
matchKind: String
matchValue: String
name: String
strategy: String
updatedAt: DateTime
}
"""A candidate provider and model pair in an LLM route fallback chain."""
type LlmRouteCandidate {
modelId: String
providerKind: String
}
"""Input for a candidate provider and model pair in an LLM route."""
input LlmRouteCandidateInput {
modelId: String!
providerKind: String!
}
"""Input for creating or updating an LLM route."""
input LlmRouteInput {
candidates: [LlmRouteCandidateInput!]!
capture: String!
enabled: Boolean!
matchKind: String!
matchValue: String!
name: String!
strategy: String!
}
"""A single model-call spend and token usage record."""
type ModelCall {
cachedTokens: Int
completionTokens: Int
costUsd: Float
id: ID
latencyMs: Int
model: String
payloadKey: String
promptTokens: Int
provider: String
recordedAt: DateTime
routeId: String
sessionId: String
status: String
tenant: String
usageSource: String
}
"""A single model-call record with its full R2 payload (when present)."""
type ModelCallDetail {
cachedTokens: Int
completionTokens: Int
costUsd: Float
id: ID
latencyMs: Int
model: String
"""Full captured payload JSON, null when absent or unreadable."""
payload: String
payloadKey: String
promptTokens: Int
provider: String
recordedAt: DateTime
routeId: String
sessionId: String
status: String
tenant: String
usageSource: String
}
"""Paginated list of model call records."""
type ModelCallPage {
items: [ModelCall!]
limit: Int
offset: Int
total: Int
}
"""Mnemose GraphQL mutation root"""
type Mutation {
"""Add a member to a group (platform_admin only)."""
addGroupMember(groupId: String!, memberId: String!, memberKind: String!): GroupMembership
"""Add one model entry to a configured provider kind."""
addLlmProviderModel(model: JSON!, providerKind: String!): LlmProviderModel
addSeoDomain(notes: String, url: String!): JSON
addSeoKeyword(domainId: ID!, keyword: String!, locale: String, projectId: ID, searchEngine: String): JSON
"""
Adopt a discovered resource into Pulumi management via `pulumi import` (tenant_admin).
"""
adoptResource(pulumiConfig: JSON, snapshotId: String!): AdoptedResource
"""Append a message to a chat session."""
appendChatMessage(content: JSON!, role: String!, sessionId: String!): ChatMessage
approveIamEscalation(escalationId: String!, reason: String!): Boolean
approveKernelSession(reason: String, sessionId: String!): Boolean
"""Archive an environment (tenant_admin)."""
archiveEnvironment(id: String!): Environment
bindSandboxService(binding: JSON!, id: String!): Boolean
"""Queue a delegated project bootstrap flow and seed a pending state row."""
bootstrapCloudProject(agentServiceAccountEmail: String!, displayName: String!, projectId: String!, provider: String!, region: String!): BootstrapState
"""
Initiate a first-time mnemose infrastructure deployment into a connected GCP project. Uses the tenant admin's stored OAuth credential as the bootstrap seed, creates IAM artifacts (service accounts, WIF pool), and runs `pulumi up`. On success, JIT credentials take over for all subsequent operations.
"""
bootstrapInfrastructure(input: BootstrapInfrastructureInput!): Deployment
"""
Queue the control-plane organization bootstrap flow and seed a pending state row.
"""
bootstrapOrganization(agentServiceAccountId: String!, allowedAudiences: [String!], hostProjectId: String!, issuerUri: String!, organizationId: String!, region: String!, workloadIdentityPoolId: String!, workloadIdentityProviderId: String!): BootstrapState
"""Enqueue a report generation job. Returns the correlation ID."""
buildReport(
"""xlsx | csv | pdf"""
format: String!
"""ISO 8601 date-time"""
periodEnd: String!
"""ISO 8601 date-time"""
periodStart: String!
"""Optional list of email recipients"""
recipientEmails: [String!]
"""iam-activity | resource-inventory | cost-summary | security-posture"""
reportType: String!
): String
"""
Execute a direct provider-pinned chat test probe with message history against a configured provider model; records token spend.
"""
chatLlmProviderModel(maxTokens: Int, messages: [LlmChatMessageInput!]!, modelId: String!, providerKind: String!): LlmChatResult
createAgentHarness(input: CreateAgentHarnessInput!): AgentHarness
"""Create a new chat session."""
createChatSession(title: String): ChatSession
"""Create a new environment in a project (tenant_admin)."""
createEnvironment(cloudProjectId: String, config: JSON, name: String!, projectId: String!): Environment
"""Create an ephemeral sandbox for command execution."""
createExecSandbox(environmentId: String!, projectId: String!, spec: SandboxSpecInput!): SandboxExec
"""Create a group in an org (platform_admin only)."""
createGroup(name: String!, orgId: String!): Group
"""
Create a harness artifact from a structured spec. Validates against HarnessSpecSchema and persists directly.
"""
createHarness(input: JSON!): HarnessArtifact
"""Create a new LLM routing policy for the current tenant."""
createLlmRoute(input: LlmRouteInput!): LlmRoute
"""Create a new org (platform_admin only)."""
createOrg(name: String!): Org
"""Create a project in a workspace (tenant_admin)."""
createProject(name: String!, workspaceId: String!): Project
"""Create a new project-agent binding (tenant_admin)."""
createProjectAgent(agentId: String!, agentName: String!, autonomyLevel: String, permissions: JSON, projectId: String!): ProjectAgent
createSandbox(input: CreateSandboxInput!): Sandbox
createSeoProject(cadence: String, geoCountry: String!, geoLocale: String, geoLocation: String, name: String!): JSON
"""Create a new tenant (platform_admin only)."""
createTenant(name: String!, primaryCloudProvider: String! = "gcp", tier: String! = "starter"): Tenant
"""Provision a new KMS key for the current tenant."""
createTenantKey(algorithm: String = "GOOGLE_SYMMETRIC_ENCRYPTION", displayName: String!, purpose: String! = "encrypt_decrypt", rotationPeriodDays: Int): TenantKmsKey
"""Create a workspace in the current tenant (tenant_admin)."""
createWorkspace(name: String!): Workspace
delegateCloudProject(displayName: String!, projectId: String!, provider: String!, region: String!, serviceAccountEmail: String!, wifPoolId: String!): CloudProject
deleteAgentHarness(id: String!): Boolean
"""Delete a chat session and its messages."""
deleteChatSession(id: String!): Boolean
"""
Delete a harness artifact row for the acting tenant. Returns false when not found.
"""
deleteHarness(id: String!): Boolean
"""Delete the current tenant's configuration for one provider kind."""
deleteLlmProviderConfig(providerKind: String!): Boolean
"""Delete an LLM routing policy for the current tenant."""
deleteLlmRoute(id: String!): Boolean
"""
Delete a retention policy; falls back to the tenant default / global retention.
"""
deleteRetentionPolicy(class: String!, scope: RetentionScope!): Boolean
"""Delete a tenant tool permission policy rule by pattern."""
deleteToolPermission(toolPattern: String!): Boolean
denyIamEscalation(escalationId: String!, reason: String!): Boolean
denyKernelSession(reason: String, sessionId: String!): Boolean
"""
Trigger a `pulumi up` on an already-bootstrapped managed project. Uses JIT credentials minted from the project's WIF configuration.
"""
deployInfrastructure(input: DeployInfrastructureInput!): Deployment
"""Destroy an ephemeral sandbox."""
destroyExecSandbox(sandboxId: String!): Boolean
destroySandbox(id: String!, reason: String): Boolean
destroyTenantKeyVersion(id: String!, version: String!): Boolean
"""Disable an installed app without uninstalling it."""
disableApp(input: DisableAppInput!): DisableAppResult
"""Trigger a discovery scan using a provisioned principal (operator+)."""
discoverResources(principalId: String!): DiscoveryScan
"""Enable a previously installed but disabled app."""
enableApp(input: EnableAppInput!): EnableAppResult
enrollKernel(input: EnrollKernelInput!): EnrollKernelResult
"""Execute a command in an ephemeral sandbox."""
execInSandbox(command: String!, env: JSON, sandboxId: String!, stdin: String): ExecResult
"""Grant a role binding scoped to a project."""
grantProjectRoleBinding(principalId: String!, principalType: String!, projectId: String!, role: String!, ttlSeconds: Int): IamRoleBinding
grantRoleBinding(principalId: String!, principalType: String!, role: String!, scope: JSON, ttlSeconds: Int): IamRoleBinding
grantSandboxFacet(grant: JSON!, id: String!): Boolean
"""
Import a harness artifact from a raw JSON document (string or object). Same validation layer as createHarness.
"""
importHarness(json: JSON!): HarnessArtifact
"""Request installation of an app from the App Store."""
installApp(input: InstallAppInput!): InstallAppResult
"""Invite a user by email to the current tenant."""
inviteUser(email: String!, role: String!, ttlDays: Int = 7): InviteCreated
"""
Dispatch a tool call to a connected agent-kernel. Read-only tools require no session. Returns a correlationId to track the result via the onKernelInvocation subscription.
"""
invokeKernelTool(args: JSON, kernelId: UUID!, tool: String!): KernelInvocationResult
"""
Orphan an adopted resource, removing it from Pulumi management without destroying the cloud resource (tenant_admin).
"""
orphanResource(reason: String!, snapshotId: String!): AdoptedResource
"""
Run a non-destructive `pulumi preview` and return the structured change diff in pulumiOutputsJson once complete.
"""
previewInfrastructure(input: PreviewInfrastructureInput!): Deployment
"""
Provision a short-lived discovery principal for cloud resource enumeration (tenant_admin).
"""
provisionDiscoveryPrincipal(principalEmail: String!, projectId: String, roles: [String!]!, tenantId: String!, ttlMinutes: Int!): DiscoveryPrincipal
"""
Idempotently upserts all core kernels declared in the CoreManifest. Safe to call repeatedly.
"""
provisionPlatformCore: Boolean
"""Enqueue a resource provisioning job. Returns the correlation ID."""
provisionResource(
cloudProjectId: String!
reason: String!
"""JSON-serialised ResourceProvisionSpec"""
specJson: String!
): String
"""
Run `pulumi refresh` to detect infrastructure drift: reconcile Pulumi state against live GCP resources and update the state file.
"""
refreshInfrastructure(input: RefreshInfrastructureInput!): Deployment
"""
Register the platform's own Cloudflare account as a managed cloud project. Called by the installer after a successful deploy. Idempotent.
"""
registerSelf(projectId: String!, region: String!, serviceAccountEmail: String!, tenantId: String): RegisterSelfResult
"""Dynamically register or update a tool definition."""
registerTool(input: RegisterToolInput!): ToolEntry
"""
Enqueue a security finding remediation job. Returns the correlation ID.
"""
remediateFinding(action: String!, agentReasoning: String!, cloudProjectId: String!, findingId: String!, requiresHumanConfirmation: Boolean = false): String
"""Remove a member from a group (platform_admin only)."""
removeGroupMember(groupId: String!, memberId: String!, memberKind: String!): Boolean
"""Remove one model entry from a configured provider kind."""
removeLlmProviderModel(modelId: String!, providerKind: String!): Boolean
"""Remove a project-agent binding (tenant_admin)."""
removeProjectAgent(id: String!): Boolean
removeSeoKeyword(keywordId: ID!): Boolean
"""
Derive evaluation cases from a chat session transcript and run them against a model or harness target
"""
replaySession(input: ReplaySessionInput!): EvaluationScorecard
requestIamEscalation(input: RequestIamEscalationInput!): IamEscalationRequest
requestKernelSession(input: RequestKernelSessionInput!): KernelSession
"""
Revoke (tombstone) a discovery principal before its TTL expires (tenant_admin).
"""
revokeDiscoveryPrincipal(id: String!, reason: String!): DiscoveryPrincipal
revokeInvite(id: String!): Boolean
revokeKernel(kernelId: String!, reason: String): Boolean
"""Revoke a project-scoped role binding."""
revokeProjectRoleBinding(id: String!): IamRoleBinding
revokeRoleBinding(id: String!): IamRoleBinding
revokeSandboxFacet(id: String!, personaId: String!): Boolean
rotateTenantKey(id: String!): TenantKmsKey
"""Trigger benchmark evaluation on a model, agent, or harness target"""
runEvaluation(input: RunEvaluationInput!): EvaluationScorecard
"""
Set a per-persona provider override. The provider kind must already be configured for the tenant.
"""
setLlmPersonaOverride(model: String, personaId: String!, providerKind: String!): LlmPersonaOverride
"""
Create or replace the current tenant's configuration for one provider kind. Omitted credential references and model are carried forward from the stored row so edits without re-keying preserve credentials.
"""
setLlmProviderConfig(baseUrl: String, cloudCredentialRef: JSON, displayName: String, extra: JSON, isDefault: Boolean, model: String, oauth: JSON, providerKind: String!, secretRef: String): LlmProviderConfig
"""
Store an API-key secret value in Secret Manager under the given reference. The value is write-only and never returned.
"""
setLlmProviderSecret(secretRef: String!, value: String!): Boolean
"""Create or update a tenant tool permission policy rule."""
setToolPermission(input: SetToolPermissionInput!): ToolPermissionRule
suspendTenant(id: String!): Tenant
suspendUser(id: String!): User
"""
Fetch vendor models for a configured provider kind and atomically replace the tenant's discovered model catalog.
"""
syncLlmProviderModels(providerKind: String!): [LlmProviderModel!]
syncResourceInventory(cloudProjectId: String!): Boolean
"""
Execute a direct minimal-cost vendor probe (max_tokens: 1, prompt: 'ping') against a configured provider model.
"""
testLlmProviderModel(modelId: String!, providerKind: String!): LlmModelTestResult
unbindSandboxService(id: String!, name: String!): Boolean
"""Request uninstallation of an installed app."""
uninstallApp(input: UninstallAppInput!): UninstallAppResult
unsuspendTenant(id: String!): Tenant
unsuspendUser(id: String!): User
updateAgentHarness(id: String!, input: UpdateAgentHarnessInput!): Boolean
"""
Update an installed app's per-tenant configuration (and optionally bump its version).
"""
updateAppConfig(input: UpdateAppConfigInput!): UpdateAppConfigResult
"""Update a chat session's title."""
updateChatSessionTitle(id: String!, title: String!): ChatSession
"""Update an existing environment (tenant_admin)."""
updateEnvironment(cloudProjectId: String, config: JSON, id: String!, name: String): Environment
updateKeyRotationPolicy(id: String!, rotationPeriodDays: Int!): TenantKmsKey
"""Patch display name, enabled flag, or params on one model."""
updateLlmProviderModel(modelId: String!, patch: JSON!, providerKind: String!): LlmProviderModel
"""Update an existing LLM routing policy for the current tenant."""
updateLlmRoute(id: String!, input: LlmRouteInput!): LlmRoute
"""Update an existing project-agent binding (tenant_admin)."""
updateProjectAgent(autonomyLevel: String, id: String!, permissions: JSON): ProjectAgent
updateSandboxDataSources(dataSources: JSON!, id: String!): Boolean
updateSandboxDeceptionPolicy(deception: JSON!, id: String!): Boolean
updateSandboxNetworkPolicy(id: String!, network: JSON!): Boolean
updateTenantTier(id: String!, tier: String!): Tenant
updateUserRole(id: String!, role: String!): User
"""
Create or update a retention policy. Omit durationDays (or pass null) to retain forever.
"""
upsertRetentionPolicy(class: String!, durationDays: Int, scope: RetentionScope!): RetentionPolicy
verifySeoDomain(domainId: ID!, method: String): JSON
}
"""Top-level ownership root that owns tenants and groups."""
type Org {
createdAt: DateTime
id: String
name: String
suspendedAt: DateTime
}
"""Result of evaluating tool permissions for an actor."""
type PermissionEvaluationResult {
allowed: Boolean
matchedPattern: String
policy: String
reason: String
requiresApproval: Boolean
}
"""
Health of the platform core — declarative manifest vs. enrolled kernels.
"""
type PlatformCoreHealth {
healthy: Boolean
kernels: [CoreKernelStatus!]
}
"""Run a non-destructive `pulumi preview` and return the structured diff."""
input PreviewInfrastructureInput {
cloudProjectId: String!
}
"""Workspace-scoped organizational container."""
type Project {
archivedAt: DateTime
createdAt: DateTime
id: String
name: String
tenantId: String
workspaceId: String
}
"""
Per-project agent configuration binding with autonomy level and permissions.
"""
type ProjectAgent {
agentId: String
agentName: String
autonomyLevel: String
createdAt: DateTime
id: String
permissions: JSON
projectId: String
updatedAt: DateTime
}
"""A tracked resource provisioning job."""
type ProvisionJob {
cloudProjectId: String
createdAt: DateTime
error: String
id: String
issuedBy: String
reason: String
resourceId: String
resourceType: String
status: String
updatedAt: DateTime
}
"""Live provisioning status from the Sandbox Durable Object."""
type ProvisionStatus {
mode: String
provisionError: String
remoteSandboxId: String
state: String
}
"""Mnemose GraphQL query root"""
type Query {
"""Get a single adopted resource by ID."""
adoptedResource(id: String!): AdoptedResource
"""List adopted resources for a project in the current tenant."""
adoptedResources(projectId: String!): [AdoptedResource!]
"""Fetch a single agent harness by id for the acting tenant."""
agentHarness(id: String!): AgentHarness
"""List agent harnesses for the acting tenant, newest first."""
agentHarnesses: [AgentHarness!]
"""Get a single installed app by ID."""
app(id: String!): InstalledApp
"""Get health status for an installed app."""
appHealth(id: String!): AppHealth
"""List all apps available in the Mnemose App Store catalog."""
availableApps: [AppStoreCard!]
"""
List registered cloud-provider artifacts for the current tenant with install status (ADR 0012, M-4).
"""
availableCloudProviders: [CloudProvider!]
"""All LLM provider kinds the platform supports."""
availableLlmProviderKinds: [String!]
"""
List visible bootstrap state rows for the current operator tenant, including control-plane rows with no tenant.
"""
bootstrapStates(targetType: String): [BootstrapState!]
"""Get a single chat session with its messages."""
chatSession(id: String!): ChatSessionWithMessages
"""List chat sessions for the authenticated tenant."""
chatSessions: [ChatSession!]
cloudProjects: [CloudProject!]
"""Deployment profile of this Mnemose instance: 'solo' or 'prod'."""
deploymentProfile: String
"""List all deployment operations for this tenant."""
deployments(cloudProjectId: String): [Deployment!]
"""Get a single environment by ID."""
environment(id: String!): Environment
"""List environments for a project in the current tenant."""
environments(projectId: String!): [Environment!]
"""Evaluate if a specific tool can be executed by the current actor."""
evaluateToolPermission(riskScore: Int, toolName: String!): PermissionEvaluationResult
"""Get detailed scorecard for a specific evaluation run ID"""
evaluationRun(id: String!): EvaluationScorecard
"""List historical evaluation runs and scorecards for the acting tenant"""
evaluationRuns: [EvaluationScorecard!]
"""Get a single ephemeral sandbox by ID."""
execSandbox(id: String!): SandboxExec
"""List active ephemeral sandboxes."""
execSandboxes(projectId: String!): [SandboxExec!]
"""Billing status for a specific GCP project."""
gcpBillingInfo(projectId: String!): GcpBillingInfo
"""
Returns whether the current tenant admin has a connected GCP account and what scopes were granted.
"""
gcpConnectionStatus: GcpConnectionStatus
"""List all GCP projects accessible to the connected Google account."""
gcpProjects: [GcpProject!]
"""Fetch a single harness artifact by its kebab-case id."""
getHarness(id: String!): HarnessArtifact
"""List tool permission rules for the active tenant."""
getToolPermissions: [ToolPermissionRule!]
"""List active members of a group (platform_admin only)."""
groupMembers(groupId: String!): [GroupMembership!]
"""List groups in an org (platform_admin only)."""
groups(orgId: String!): [Group!]
honeypotAlerts(limit: Int, sandboxId: String, severity: String, status: String): [HoneypotAlert!]
iamEscalation(id: String!): IamEscalationRequest
iamEscalations: [IamEscalationRequest!]
"""List active IAM role bindings in the current tenant."""
iamRoleBindings(principalId: String, principalType: String): [IamRoleBinding!]
"""List all apps installed in the current tenant."""
installedApps: [InstalledApp!]
"""List pending invites in the current tenant."""
invites: [Invite!]
kernel(id: String!): AgentKernel
kernelInvocations(kernelId: String!, limit: Int): [KernelInvocation!]
kernelSessions(kernelId: String, status: String): [KernelSession!]
kernels(status: String): [AgentKernel!]
"""List harness artifacts for the acting tenant, newest installed first."""
listHarnesses: [HarnessArtifact!]
"""List all indexed tools, optionally filtered by source or category."""
listTools(category: String, source: String): [ToolEntry!]
"""List the current tenant's per-persona LLM overrides."""
llmPersonaOverrides: [LlmPersonaOverride!]
"""List the current tenant's configured LLM providers."""
llmProviderConfigs: [LlmProviderConfig!]
"""Static per-kind defaults (base URL, auth modes, discoverability)."""
llmProviderKindMetadata: [LlmProviderKindMetadata!]
"""
Per-provider health, latency, and error counters from ModelRouter telemetry.
"""
llmProviderStatus: [LlmProviderStatus!]
"""List the current tenant's LLM routing policies ordered by name."""
llmRoutes: [LlmRoute!]
"""Single model-call drill-down with full payload, tenant-scoped."""
modelCall(id: ID!): ModelCallDetail
"""Paginated tenant model-call records, newest first."""
modelCalls(limit: Int, offset: Int): ModelCallPage
"""List all tenants the current user has access to."""
myTenants: [TenantMembership!]
org(id: String!): Org
"""List all orgs (platform_admin only)."""
orgs: [Org!]
"""Health of the platform core kernels as declared in the CoreManifest."""
platformCore: PlatformCoreHealth
project(id: String!): Project
"""Get a single project agent by ID."""
projectAgent(id: String!): ProjectAgent
"""List project agents for a project in the current tenant."""
projectAgents(projectId: String!): [ProjectAgent!]
"""List active role bindings scoped to a project."""
projectRoleBindings(projectId: String!): [IamRoleBinding!]
"""List projects in the current tenant, optionally by workspace."""
projects(workspaceId: String): [Project!]
provisionJobs(cloudProjectId: String!): [ProvisionJob!]
provisionStatus(id: String!): ProvisionStatus
remediationJobs(cloudProjectId: String!): [RemediationJob!]
"""List all report jobs for this tenant."""
reports: [Report!]
resources(cloudProjectId: String!, resourceType: String): [ResourceSnapshot!]
"""Tenant-scoped retention policies, optionally filtered by scope."""
retentionPolicies(scope: RetentionScope): [RetentionPolicy!]
sandbox(id: String!): Sandbox
sandboxes(status: String): [Sandbox!]
"""Semantic and keyword search for tools by natural language query."""
searchTools(category: String, limit: Int, query: String!, source: String): SearchResponse
seoCompetitors(limit: Int): [JSON!]
seoDomains: [JSON!]
seoKeywords(domainId: ID): [JSON!]
seoProjects: [JSON!]
seoRankings(keywordId: ID, limit: Int): [JSON!]
tenant(id: String!): Tenant
tenantKey(id: String!): TenantKmsKey
"""List KMS keys for the current tenant."""
tenantKeys: [TenantKmsKey!]
"""List all tenants (platform_admin only)."""
tenants: [Tenant!]
user(id: String!): User
"""List users in the current tenant."""
users: [User!]
workspace(id: String!): Workspace
"""List workspaces in the current tenant."""
workspaces: [Workspace!]
}
"""
Run `pulumi refresh` to reconcile Pulumi state against the live GCP resources (drift detection).
"""
input RefreshInfrastructureInput {
cloudProjectId: String!
}
"""
Result of registering the platform's own infrastructure as a managed cloud project.
"""
type RegisterSelfResult {
cloudProjectId: String
credentialsValidated: Boolean
tenantId: String
}
input RegisterToolInput {
category: String
description: String!
inputSchema: JSON
name: String!
outputSchema: JSON
source: String!
sourceLocation: String!
tags: [String!]
version: String
}
"""A tracked security finding remediation job."""
type RemediationJob {
action: String
agentReasoning: String
cloudProjectId: String
createdAt: DateTime
error: String
findingId: String
id: String
issuedBy: String
requiresHuman: Boolean
status: String
updatedAt: DateTime
}
input ReplaySessionInput {
maxCases: Int
replayGroupId: String
sourceChatSessionId: String!
targetId: String!
targetType: String!
}
"""A generated report job."""
type Report {
createdAt: DateTime
error: String
fileSizeBytes: Int
format: String
id: String
issuedBy: String
periodEnd: DateTime
periodStart: DateTime
reportType: String
signedDownloadUrl: String
status: String
updatedAt: DateTime
}
input RequestIamEscalationInput {
reason: String!
scopeKind: String!
scopeProjectId: String
targetRole: String!
ttlSeconds: Int!
}
input RequestKernelSessionInput {
kernelId: String!
reason: String!
tier: String!
ttlSeconds: Int!
}
"""
Point-in-time snapshot of a cloud resource captured by the inventory sync.
"""
type ResourceSnapshot {
displayName: String
firstSeenAt: DateTime
id: String
labels: JSON
region: String
resourceId: String
resourceType: String
state: String
syncedAt: DateTime
}
"""
A tenant-managed retention window for a scope/class pair. durationDays null = infinite.
"""
type RetentionPolicy {
class: String
durationDays: Int
id: ID
scope: String
tenantId: String
updatedAt: DateTime
}
enum RetentionScope {
metrics
payloads
}
input RunEvaluationInput {
suites: [String!]
targetId: String!
targetType: String!
}
"""
An isolated compute environment with configurable policies and bindings.
"""
type Sandbox {
compute: JSON
createdAt: DateTime
createdBy: String
dataSources: JSON
deception: JSON
destroyedAt: DateTime
grants: JSON
id: String
label: String
network: JSON
owner: JSON
provisionError: String
services: JSON
status: String
suspendedAt: DateTime
tenantId: String
tools: JSON
}
"""An ephemeral sandbox created via the execution layer."""
type SandboxExec {
command: String
createdAt: DateTime
environmentId: String
id: String
image: String
projectId: String
status: String
ttl: Int
}
input SandboxSpecInput {
command: [String!]!
env: JSON
image: String!
network: JSON
resources: JSON
ttl: Int
}
"""Response from a semantic tool search."""
type SearchResponse {
tools: [ToolEntry!]
total: Int
}
input SetToolPermissionInput {
allowedRoles: [String!]
autoApprovalThreshold: Int
autoApprove: Boolean = false
deniedRoles: [String!]
policy: String!
reason: String
toolPattern: String!
}
"""Mnemose GraphQL subscription root"""
type Subscription {
"""
Subscribe to real-time status updates for a specific deployment operation.
"""
deploymentStatus(deploymentId: String!): Deployment
"""Subscribe to environment creation events for the current tenant."""
environmentCreated(tenantId: String!): Environment
"""Subscribe to IAM role binding changes (revoke)."""
onIamBindingChanged: IamRoleBinding
"""
Subscribe to invocation lifecycle events (dispatched/completed/failed) for a kernel.
"""
onKernelInvocation(kernelId: UUID!): KernelInvocationEvent
"""
Subscribe to periodic metrics snapshots for a kernel (published every ~30 s while connected).
"""
onKernelMetrics(kernelId: UUID!): KernelMetricsEvent
"""
Subscribe to kernel status changes (online/offline/revoked). Pass kernelId to filter to a single kernel.
"""
onKernelStatusChanged(kernelId: UUID): KernelStatusEvent
"""
Subscribe to tenant status changes (suspend/unsuspend). Platform admin only.
"""
onTenantChanged: Tenant
"""Subscribe to user status/role changes (suspend/unsuspend/updateRole)."""
onUserChanged: User
}
"""A Mnemose platform tenant."""
type Tenant {
createdAt: DateTime
id: String
isActive: Boolean
name: String
primaryCloudProvider: String
suspendedAt: DateTime
tier: String
}
"""A tenant-scoped encryption key managed in GCP Cloud KMS."""
type TenantKmsKey {
algorithm: String
createdAt: DateTime
destroyedAt: DateTime
displayName: String
id: String
keyName: String
keyRingName: String
primaryVersion: String
purpose: String
rotatedAt: DateTime
rotationPeriodDays: Int
state: String
}
"""A tenant the current user has access to, with their role."""
type TenantMembership {
role: String
tenant: Tenant
}
"""A single indexed tool entry in the registry."""
type ToolEntry {
category: String
description: String
id: String
indexedAt: DateTime
inputSchema: JSON
name: String
outputSchema: JSON
source: String
sourceLocation: String
tags: [String!]
version: String
}
"""A tenant-scoped tool permission policy rule."""
type ToolPermissionRule {
allowedRoles: [String!]
autoApprovalThreshold: Int
autoApprove: Boolean
deniedRoles: [String!]
id: String
policy: String
reason: String
tenantId: String
toolPattern: String
}
scalar UUID
input UninstallAppInput {
appId: String!
purgeData: Boolean! = false
}
"""Result of an app uninstallation request."""
type UninstallAppResult {
appId: String
status: String
success: Boolean
}
input UpdateAgentHarnessInput {
description: String
hitlTier: String
maxSteps: Int
mode: String
modelId: String
name: String
providerKind: String
temperature: Float
toolIds: [String!]
vectorStoreRefs: [String!]
}
input UpdateAppConfigInput {
appId: String!
config: JSON!
version: String
}
"""Result of an app config update request."""
type UpdateAppConfigResult {
appId: String
status: String
success: Boolean
}
"""A Mnemose platform user."""
type User {
activatedAt: DateTime
createdAt: DateTime
displayName: String
email: String
id: String
invitedAt: DateTime
invitedBy: String
isActive: Boolean
role: String
suspendedAt: DateTime
tenantId: String
}
"""Tenant-scoped container for projects."""
type Workspace {
archivedAt: DateTime
createdAt: DateTime
id: String
name: String
tenantId: String
}