{
  "openapi": "3.1.0",
  "info": {
    "title": "mandate-control-plane",
    "summary": "Administrative deployment and documentation publisher for the shared mandate.core vocabulary. All four deployments compile those shared library types; core is not a remote control-plane runtime dependency. See docs/architecture/ownership.md.",
    "description": "The HTTP surface of `mandate-control-plane`, one of the components of `mandate` v1.\n\nEvery path here is one semantic command, so the method is always POST and the path is the command's wire name under its domain's: a command is not a resource, and this document does not invent one. A status code is the outcome the specification declares — 202 for a branch that was taken, 422 for a refusal the input decides, 502 for a refusal decided outside the request — and the `outcome` property of every response body names the branch. Events emitted by a branch are published to consumers through the event transport; they are not returned here.",
    "version": "v1",
    "x-ess-provenance": {
      "system": "mandate",
      "specification_version": "v1",
      "source_digest": "2f11d2daffc2d75bb4ca8c0485aedc56fb2a712cdaed6347fc48b8ba2b1f7ca6",
      "contract_digest": "slice-sha256/2:24f8b7ca816042022e388db8c5cf68284342a9907ab949a26ab7a1be1af618cc"
    }
  },
  "tags": [
    {
      "name": "delegation"
    },
    {
      "name": "directory"
    },
    {
      "name": "federation"
    },
    {
      "name": "identity",
      "description": "Principal, session and independent principal/organization/federation generation ownership. UNMAPPED-EPOCH: each generation record declares one non-negative Integer generation, the recorded stand-in for the addendum's u64; monotonic increment, denial at the maximum and per-dimension snapshot values are absent until supported. EpochSnapshotRef is an immutable record handle, not a generation number. Refresh and exchange cannot be implemented without closing this blocker."
    },
    {
      "name": "tenancy"
    },
    {
      "name": "workload"
    }
  ],
  "paths": {
    "/delegation/commands/CompleteExecution": {
      "post": {
        "operationId": "mandate.delegation.CompleteExecution",
        "summary": "CompleteExecution",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.CompleteExecution` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.CompleteExecution.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.CompleteExecution.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.CompleteExecution.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.CompleteExecution.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/delegation/commands/ConsumeApproval": {
      "post": {
        "operationId": "mandate.delegation.ConsumeApproval",
        "summary": "ConsumeApproval",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.ConsumeApproval` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.ConsumeApproval.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.ConsumeApproval.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.ConsumeApproval.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.ConsumeApproval.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/delegation/commands/CreateDelegation": {
      "post": {
        "operationId": "mandate.delegation.CreateDelegation",
        "summary": "CreateDelegation",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.CreateDelegation` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.CreateDelegation.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.CreateDelegation.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.CreateDelegation.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/delegation/commands/RetireAgent": {
      "post": {
        "operationId": "mandate.delegation.RetireAgent",
        "summary": "RetireAgent",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.RetireAgent` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.RetireAgent.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RetireAgent.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RetireAgent.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RetireAgent.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/delegation/commands/RevokeDelegation": {
      "post": {
        "operationId": "mandate.delegation.RevokeDelegation",
        "summary": "RevokeDelegation",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.RevokeDelegation` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.RevokeDelegation.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RevokeDelegation.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RevokeDelegation.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.RevokeDelegation.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/delegation/commands/SupersedeAgentCapabilityCeiling": {
      "post": {
        "operationId": "mandate.delegation.SupersedeAgentCapabilityCeiling",
        "summary": "SupersedeAgentCapabilityCeiling",
        "tags": [
          "delegation"
        ],
        "requestBody": {
          "description": "The input `mandate.delegation.SupersedeAgentCapabilityCeiling` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.delegation.SupersedeAgentCapabilityCeiling.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.SupersedeAgentCapabilityCeiling.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.SupersedeAgentCapabilityCeiling.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.delegation.SupersedeAgentCapabilityCeiling.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/CompleteSyncJob": {
      "post": {
        "operationId": "mandate.directory.CompleteSyncJob",
        "summary": "CompleteSyncJob",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.CompleteSyncJob` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.CompleteSyncJob.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.CompleteSyncJob.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.CompleteSyncJob.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.CompleteSyncJob.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/CreateDirectoryGroupTeamMapping": {
      "post": {
        "operationId": "mandate.directory.CreateDirectoryGroupTeamMapping",
        "summary": "CreateDirectoryGroupTeamMapping",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.CreateDirectoryGroupTeamMapping` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.CreateDirectoryGroupTeamMapping.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.CreateDirectoryGroupTeamMapping.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.CreateDirectoryGroupTeamMapping.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/FailSyncJob": {
      "post": {
        "operationId": "mandate.directory.FailSyncJob",
        "summary": "FailSyncJob",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.FailSyncJob` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.FailSyncJob.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.FailSyncJob.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.FailSyncJob.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.FailSyncJob.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/RemoveDirectoryGroupMembership": {
      "post": {
        "operationId": "mandate.directory.RemoveDirectoryGroupMembership",
        "summary": "RemoveDirectoryGroupMembership",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.RemoveDirectoryGroupMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupMembership.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupMembership.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/RemoveDirectoryGroupTeamMapping": {
      "post": {
        "operationId": "mandate.directory.RemoveDirectoryGroupTeamMapping",
        "summary": "RemoveDirectoryGroupTeamMapping",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.RemoveDirectoryGroupTeamMapping` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupTeamMapping.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupTeamMapping.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupTeamMapping.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveDirectoryGroupTeamMapping.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/RemoveMembershipContribution": {
      "post": {
        "operationId": "mandate.directory.RemoveMembershipContribution",
        "summary": "RemoveMembershipContribution",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.RemoveMembershipContribution` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.RemoveMembershipContribution.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveMembershipContribution.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveMembershipContribution.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RemoveMembershipContribution.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/RetireDirectoryGroup": {
      "post": {
        "operationId": "mandate.directory.RetireDirectoryGroup",
        "summary": "RetireDirectoryGroup",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.RetireDirectoryGroup` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.RetireDirectoryGroup.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RetireDirectoryGroup.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RetireDirectoryGroup.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.RetireDirectoryGroup.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/directory/commands/SyncDirectoryMembership": {
      "post": {
        "operationId": "mandate.directory.SyncDirectoryMembership",
        "summary": "SyncDirectoryMembership",
        "tags": [
          "directory"
        ],
        "requestBody": {
          "description": "The input `mandate.directory.SyncDirectoryMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.directory.SyncDirectoryMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.SyncDirectoryMembership.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.directory.SyncDirectoryMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/AuthenticateFederation": {
      "post": {
        "operationId": "mandate.federation.AuthenticateFederation",
        "summary": "AuthenticateFederation",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.AuthenticateFederation` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.AuthenticateFederation.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.AuthenticateFederation.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.AuthenticateFederation.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/AuthorizePublicClient": {
      "post": {
        "operationId": "mandate.federation.AuthorizePublicClient",
        "summary": "AuthorizePublicClient",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.AuthorizePublicClient` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.AuthorizePublicClient.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.AuthorizePublicClient.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.AuthorizePublicClient.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/DisableFederationConnection": {
      "post": {
        "operationId": "mandate.federation.DisableFederationConnection",
        "summary": "DisableFederationConnection",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.DisableFederationConnection` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.DisableFederationConnection.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableFederationConnection.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableFederationConnection.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableFederationConnection.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/DisableOAuthClient": {
      "post": {
        "operationId": "mandate.federation.DisableOAuthClient",
        "summary": "DisableOAuthClient",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.DisableOAuthClient` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.DisableOAuthClient.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableOAuthClient.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableOAuthClient.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.DisableOAuthClient.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/LinkExternalPrincipal": {
      "post": {
        "operationId": "mandate.federation.LinkExternalPrincipal",
        "summary": "LinkExternalPrincipal",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.LinkExternalPrincipal` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.LinkExternalPrincipal.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.LinkExternalPrincipal.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.LinkExternalPrincipal.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/ProvisionExternalPrincipal": {
      "post": {
        "operationId": "mandate.federation.ProvisionExternalPrincipal",
        "summary": "ProvisionExternalPrincipal",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.ProvisionExternalPrincipal` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.ProvisionExternalPrincipal.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.ProvisionExternalPrincipal.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.ProvisionExternalPrincipal.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/RegisterFederationConnection": {
      "post": {
        "operationId": "mandate.federation.RegisterFederationConnection",
        "summary": "RegisterFederationConnection",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.RegisterFederationConnection` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.RegisterFederationConnection.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.RegisterFederationConnection.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.RegisterFederationConnection.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/RegisterOAuthClient": {
      "post": {
        "operationId": "mandate.federation.RegisterOAuthClient",
        "summary": "RegisterOAuthClient",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.RegisterOAuthClient` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.RegisterOAuthClient.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.RegisterOAuthClient.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.RegisterOAuthClient.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/federation/commands/UnlinkExternalPrincipal": {
      "post": {
        "operationId": "mandate.federation.UnlinkExternalPrincipal",
        "summary": "UnlinkExternalPrincipal",
        "tags": [
          "federation"
        ],
        "requestBody": {
          "description": "The input `mandate.federation.UnlinkExternalPrincipal` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.federation.UnlinkExternalPrincipal.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.UnlinkExternalPrincipal.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.UnlinkExternalPrincipal.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.federation.UnlinkExternalPrincipal.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/identity/commands/DisablePrincipal": {
      "post": {
        "operationId": "mandate.identity.DisablePrincipal",
        "summary": "DisablePrincipal",
        "tags": [
          "identity"
        ],
        "requestBody": {
          "description": "The input `mandate.identity.DisablePrincipal` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.identity.DisablePrincipal.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.DisablePrincipal.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.DisablePrincipal.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.DisablePrincipal.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/identity/commands/IncrementSecurityEpoch": {
      "post": {
        "operationId": "mandate.identity.IncrementSecurityEpoch",
        "summary": "IncrementSecurityEpoch",
        "tags": [
          "identity"
        ],
        "requestBody": {
          "description": "The input `mandate.identity.IncrementSecurityEpoch` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.identity.IncrementSecurityEpoch.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.IncrementSecurityEpoch.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.IncrementSecurityEpoch.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/identity/commands/RefreshSession": {
      "post": {
        "operationId": "mandate.identity.RefreshSession",
        "summary": "RefreshSession",
        "tags": [
          "identity"
        ],
        "requestBody": {
          "description": "The input `mandate.identity.RefreshSession` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.identity.RefreshSession.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RefreshSession.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RefreshSession.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/identity/commands/RevokeRefreshCredential": {
      "post": {
        "operationId": "mandate.identity.RevokeRefreshCredential",
        "summary": "RevokeRefreshCredential",
        "tags": [
          "identity"
        ],
        "requestBody": {
          "description": "The input `mandate.identity.RevokeRefreshCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.identity.RevokeRefreshCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeRefreshCredential.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeRefreshCredential.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeRefreshCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/identity/commands/RevokeSession": {
      "post": {
        "operationId": "mandate.identity.RevokeSession",
        "summary": "RevokeSession",
        "tags": [
          "identity"
        ],
        "requestBody": {
          "description": "The input `mandate.identity.RevokeSession` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.identity.RevokeSession.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeSession.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeSession.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.identity.RevokeSession.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/AddOrganizationMembership": {
      "post": {
        "operationId": "mandate.tenancy.AddOrganizationMembership",
        "summary": "AddOrganizationMembership",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.AddOrganizationMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.AddOrganizationMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.AddOrganizationMembership.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.AddOrganizationMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/AddTeamMembership": {
      "post": {
        "operationId": "mandate.tenancy.AddTeamMembership",
        "summary": "AddTeamMembership",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.AddTeamMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.AddTeamMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.AddTeamMembership.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.AddTeamMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/CloseOrganization": {
      "post": {
        "operationId": "mandate.tenancy.CloseOrganization",
        "summary": "CloseOrganization",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.CloseOrganization` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.CloseOrganization.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CloseOrganization.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CloseOrganization.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CloseOrganization.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/CreateOrganization": {
      "post": {
        "operationId": "mandate.tenancy.CreateOrganization",
        "summary": "CreateOrganization",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.CreateOrganization` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.CreateOrganization.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateOrganization.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateOrganization.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/CreateSpace": {
      "post": {
        "operationId": "mandate.tenancy.CreateSpace",
        "summary": "CreateSpace",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.CreateSpace` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.CreateSpace.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateSpace.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateSpace.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/CreateTeam": {
      "post": {
        "operationId": "mandate.tenancy.CreateTeam",
        "summary": "CreateTeam",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.CreateTeam` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.CreateTeam.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateTeam.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.CreateTeam.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/RemoveOrganizationMembership": {
      "post": {
        "operationId": "mandate.tenancy.RemoveOrganizationMembership",
        "summary": "RemoveOrganizationMembership",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.RemoveOrganizationMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.RemoveOrganizationMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveOrganizationMembership.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveOrganizationMembership.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveOrganizationMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/RemoveTeamMembership": {
      "post": {
        "operationId": "mandate.tenancy.RemoveTeamMembership",
        "summary": "RemoveTeamMembership",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.RemoveTeamMembership` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.RemoveTeamMembership.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveTeamMembership.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveTeamMembership.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RemoveTeamMembership.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/RetireSpace": {
      "post": {
        "operationId": "mandate.tenancy.RetireSpace",
        "summary": "RetireSpace",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.RetireSpace` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.RetireSpace.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireSpace.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireSpace.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireSpace.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/tenancy/commands/RetireTeam": {
      "post": {
        "operationId": "mandate.tenancy.RetireTeam",
        "summary": "RetireTeam",
        "tags": [
          "tenancy"
        ],
        "requestBody": {
          "description": "The input `mandate.tenancy.RetireTeam` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.tenancy.RetireTeam.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireTeam.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireTeam.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.tenancy.RetireTeam.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/workload/commands/RevokeWorkloadIdentity": {
      "post": {
        "operationId": "mandate.workload.RevokeWorkloadIdentity",
        "summary": "RevokeWorkloadIdentity",
        "tags": [
          "workload"
        ],
        "requestBody": {
          "description": "The input `mandate.workload.RevokeWorkloadIdentity` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.workload.RevokeWorkloadIdentity.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.workload.RevokeWorkloadIdentity.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.workload.RevokeWorkloadIdentity.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.workload.RevokeWorkloadIdentity.denied.Response"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "mandate.core.Action": {
        "title": "Action",
        "x-ess-name": "mandate.core.Action",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.AgentCapabilityCeilingId": {
        "title": "AgentCapabilityCeilingId",
        "x-ess-name": "mandate.core.AgentCapabilityCeilingId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ApprovalId": {
        "title": "ApprovalId",
        "x-ess-name": "mandate.core.ApprovalId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.Audience": {
        "title": "Audience",
        "x-ess-name": "mandate.core.Audience",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.AuthorityScope": {
        "title": "AuthorityScope",
        "x-ess-name": "mandate.core.AuthorityScope",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "actions": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.Action"
            }
          },
          "resources": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.ResourceRef"
            }
          },
          "space": {
            "$ref": "#/components/schemas/mandate.core.SpaceId"
          }
        },
        "required": [
          "actions",
          "resources"
        ],
        "additionalProperties": false
      },
      "mandate.core.ClientId": {
        "title": "ClientId",
        "x-ess-name": "mandate.core.ClientId",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.CorrelationId": {
        "title": "CorrelationId",
        "x-ess-name": "mandate.core.CorrelationId",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.CredentialId": {
        "title": "CredentialId",
        "x-ess-name": "mandate.core.CredentialId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.CredentialProof": {
        "title": "CredentialProof",
        "x-ess-name": "mandate.core.CredentialProof",
        "x-ess-kind": "newtype",
        "type": "string",
        "pattern": "^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$",
        "contentEncoding": "base64"
      },
      "mandate.core.DelegationId": {
        "title": "DelegationId",
        "x-ess-name": "mandate.core.DelegationId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.DenialReason": {
        "title": "DenialReason",
        "x-ess-name": "mandate.core.DenialReason",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "Denied",
          "ApprovalRequired",
          "InvalidCredential",
          "TenantMismatch",
          "AudienceMismatch",
          "Unavailable",
          "StaleEpoch"
        ]
      },
      "mandate.core.DirectoryGroupId": {
        "title": "DirectoryGroupId",
        "x-ess-name": "mandate.core.DirectoryGroupId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.DirectoryGroupMembershipId": {
        "title": "DirectoryGroupMembershipId",
        "x-ess-name": "mandate.core.DirectoryGroupMembershipId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.DirectoryGroupTeamMappingId": {
        "title": "DirectoryGroupTeamMappingId",
        "x-ess-name": "mandate.core.DirectoryGroupTeamMappingId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ExecutionId": {
        "title": "ExecutionId",
        "x-ess-name": "mandate.core.ExecutionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ExternalLinkMethod": {
        "title": "ExternalLinkMethod",
        "x-ess-name": "mandate.core.ExternalLinkMethod",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "Administrator",
          "AuthenticatedConfirmation",
          "VerifiedMigration",
          "ConfiguredFederation",
          "SecuritySupport"
        ]
      },
      "mandate.core.ExternalPrincipalId": {
        "title": "ExternalPrincipalId",
        "x-ess-name": "mandate.core.ExternalPrincipalId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ExternalSubject": {
        "title": "ExternalSubject",
        "x-ess-name": "mandate.core.ExternalSubject",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.FederationConnectionId": {
        "title": "FederationConnectionId",
        "x-ess-name": "mandate.core.FederationConnectionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.Issuer": {
        "title": "Issuer",
        "x-ess-name": "mandate.core.Issuer",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.MembershipContributionId": {
        "title": "MembershipContributionId",
        "x-ess-name": "mandate.core.MembershipContributionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.OAuthClientId": {
        "title": "OAuthClientId",
        "x-ess-name": "mandate.core.OAuthClientId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.OrganizationId": {
        "title": "OrganizationId",
        "x-ess-name": "mandate.core.OrganizationId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.OrganizationMembershipId": {
        "title": "OrganizationMembershipId",
        "x-ess-name": "mandate.core.OrganizationMembershipId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.PkceChallenge": {
        "title": "PkceChallenge",
        "x-ess-name": "mandate.core.PkceChallenge",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.PkceMethod": {
        "title": "PkceMethod",
        "x-ess-name": "mandate.core.PkceMethod",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "S256"
        ]
      },
      "mandate.core.PrincipalId": {
        "title": "PrincipalId",
        "x-ess-name": "mandate.core.PrincipalId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.RedirectUri": {
        "title": "RedirectUri",
        "x-ess-name": "mandate.core.RedirectUri",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.RefreshCredentialId": {
        "title": "RefreshCredentialId",
        "x-ess-name": "mandate.core.RefreshCredentialId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ResourceId": {
        "title": "ResourceId",
        "x-ess-name": "mandate.core.ResourceId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ResourceRef": {
        "title": "ResourceRef",
        "x-ess-name": "mandate.core.ResourceRef",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "resource_type": {
            "$ref": "#/components/schemas/mandate.core.ResourceType"
          },
          "resource_id": {
            "$ref": "#/components/schemas/mandate.core.ResourceId"
          }
        },
        "required": [
          "resource_type",
          "resource_id"
        ],
        "additionalProperties": false
      },
      "mandate.core.ResourceServerId": {
        "title": "ResourceServerId",
        "x-ess-name": "mandate.core.ResourceServerId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ResourceType": {
        "title": "ResourceType",
        "x-ess-name": "mandate.core.ResourceType",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.SecurityEpochTarget": {
        "title": "SecurityEpochTarget",
        "x-ess-name": "mandate.core.SecurityEpochTarget",
        "x-ess-kind": "union",
        "oneOf": [
          {
            "title": "federation",
            "type": "object",
            "properties": {
              "kind": {
                "type": "string",
                "const": "federation"
              },
              "value": {
                "$ref": "#/components/schemas/mandate.core.FederationConnectionId"
              }
            },
            "required": [
              "kind",
              "value"
            ],
            "additionalProperties": false
          },
          {
            "title": "organization",
            "type": "object",
            "properties": {
              "kind": {
                "type": "string",
                "const": "organization"
              },
              "value": {
                "$ref": "#/components/schemas/mandate.core.OrganizationId"
              }
            },
            "required": [
              "kind",
              "value"
            ],
            "additionalProperties": false
          },
          {
            "title": "principal",
            "type": "object",
            "properties": {
              "kind": {
                "type": "string",
                "const": "principal"
              },
              "value": {
                "$ref": "#/components/schemas/mandate.core.PrincipalId"
              }
            },
            "required": [
              "kind",
              "value"
            ],
            "additionalProperties": false
          }
        ],
        "x-ess-union-tag": "kind"
      },
      "mandate.core.SessionId": {
        "title": "SessionId",
        "x-ess-name": "mandate.core.SessionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.SpaceId": {
        "title": "SpaceId",
        "x-ess-name": "mandate.core.SpaceId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.SyncJobId": {
        "title": "SyncJobId",
        "x-ess-name": "mandate.core.SyncJobId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.TeamId": {
        "title": "TeamId",
        "x-ess-name": "mandate.core.TeamId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.TeamMembershipId": {
        "title": "TeamMembershipId",
        "x-ess-name": "mandate.core.TeamMembershipId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.TenantResolutionRule": {
        "title": "TenantResolutionRule",
        "x-ess-name": "mandate.core.TenantResolutionRule",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "configured_organization": {
            "$ref": "#/components/schemas/mandate.core.OrganizationId"
          },
          "verified_claim_name": {
            "type": "string"
          },
          "verified_claim_value": {
            "type": "string"
          }
        },
        "required": [
          "configured_organization"
        ],
        "additionalProperties": false
      },
      "mandate.core.VerifiedContext": {
        "title": "VerifiedContext",
        "x-ess-name": "mandate.core.VerifiedContext",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "subject": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "actor": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "organization": {
            "$ref": "#/components/schemas/mandate.core.OrganizationId"
          },
          "audience": {
            "$ref": "#/components/schemas/mandate.core.Audience"
          },
          "credential": {
            "$ref": "#/components/schemas/mandate.core.CredentialId"
          },
          "delegation": {
            "$ref": "#/components/schemas/mandate.core.DelegationId"
          },
          "execution": {
            "$ref": "#/components/schemas/mandate.core.ExecutionId"
          },
          "correlation": {
            "$ref": "#/components/schemas/mandate.core.CorrelationId"
          }
        },
        "required": [
          "subject",
          "organization",
          "audience",
          "credential",
          "correlation"
        ],
        "additionalProperties": false
      },
      "mandate.core.WorkloadIdentityId": {
        "title": "WorkloadIdentityId",
        "x-ess-name": "mandate.core.WorkloadIdentityId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.delegation.CompleteExecution.Input": {
        "title": "CompleteExecution input",
        "x-ess-name": "mandate.delegation.CompleteExecution",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.ExecutionId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.CompleteExecution.accepted.Response": {
        "additionalProperties": false,
        "description": "The recorded end of one agent invocation. No further tool call is admitted under the execution; the record, its delegation binding and its policy version are preserved. An execution past expires_at is ineligible without any recorded move. Taken when no other outcome's condition matched. A `mandate.delegation.Execution` has moved to `Completed`, along `complete`. The instance is the one `id` names. Emits `ExecutionCompleted`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.CompleteExecution.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller is not the agent runtime that holds this execution, the execution is outside the verified organization, or completion cannot durably stop further tool calls bound to it..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.CompleteExecution.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.ConsumeApproval.Input": {
        "title": "ConsumeApproval input",
        "x-ess-name": "mandate.delegation.ConsumeApproval",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.ApprovalId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.ConsumeApproval.accepted.Response": {
        "additionalProperties": false,
        "description": "One approval satisfies exactly one decision. Consumption commits with the decision that used it; a consumed approval never satisfies a second check and is never reinstated. Taken when no other outcome's condition matched. A `mandate.delegation.Approval` has moved to `Consumed`, along `consume`. The instance is the one `id` names. Emits `ApprovalConsumed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.ConsumeApproval.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller does not hold the decision context the approval answers, the approval is outside the verified organization, its subject/actor/action/resource or expiry does not match the check being satisfied, or one-use consumption cannot commit atomically with that decision..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.ConsumeApproval.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.CreateDelegation.Input": {
        "title": "CreateDelegation input",
        "x-ess-name": "mandate.delegation.CreateDelegation",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "delegate": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          },
          "audience": {
            "$ref": "#/components/schemas/mandate.core.Audience"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          },
          "not_before": {
            "type": "string",
            "format": "date-time"
          },
          "execution_binding": {
            "$ref": "#/components/schemas/mandate.core.ExecutionId"
          }
        },
        "required": [
          "context",
          "delegate",
          "scope",
          "audience",
          "expires_at"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.CreateDelegation.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.delegation.Delegation` now exists, in `Active`. Its identity is published as `id` on `mandate.delegation.DelegationCreated`. Emits `DelegationCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.CreateDelegation.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks delegation authority, subject/delegate/tenant/space/registered audience or execution binding fails, requested scope/expiry exceeds source/delegation/policy limits or agent ceilings, or a transitive/approval-required grant would be created..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.delegation.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.RetireAgent.Input": {
        "title": "RetireAgent input",
        "x-ess-name": "mandate.delegation.RetireAgent",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.RetireAgent.accepted.Response": {
        "additionalProperties": false,
        "description": "The installation is withdrawn, not deleted. A retired agent starts no execution and is admitted by no exchange; its executions, delegations and audit history are preserved, and disabling the agent's principal remains a separate identity command. Taken when no other outcome's condition matched. A `mandate.delegation.Agent` has moved to `Retired`, along `retire`. The instance is the one `id` names. Emits `AgentRetired`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.RetireAgent.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks agent-administration authority, the agent is outside the verified organization, or retirement cannot stop new executions and exchanges under its ceiling..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.RetireAgent.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.RevokeDelegation.Input": {
        "title": "RevokeDelegation input",
        "x-ess-name": "mandate.delegation.RevokeDelegation",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.DelegationId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.RevokeDelegation.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.delegation.Delegation` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `DelegationRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.RevokeDelegation.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks delegation-revocation authority, delegation is outside the verified organization, or durable revocation and affected exchange invalidation fail..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.RevokeDelegation.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.SupersedeAgentCapabilityCeiling.Input": {
        "title": "SupersedeAgentCapabilityCeiling input",
        "x-ess-name": "mandate.delegation.SupersedeAgentCapabilityCeiling",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.AgentCapabilityCeilingId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.delegation.SupersedeAgentCapabilityCeiling.accepted.Response": {
        "additionalProperties": false,
        "description": "A ceiling is never edited. The replacement is a new ceiling record and this one stops being current, which is what keeps exactly one current ceiling per (agent, organization-or-platform); every applicable platform and tenant ceiling still intersects. Taken when no other outcome's condition matched. A `mandate.delegation.AgentCapabilityCeiling` has moved to `Superseded`, along `supersede`. The instance is the one `id` names. Emits `AgentCapabilityCeilingSuperseded`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.delegation.SupersedeAgentCapabilityCeiling.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks ceiling-administration authority, the ceiling is outside the verified organization or platform scope, no later ceiling covers the same agent and scope, or supersession cannot take effect before the next exchange is evaluated..",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.delegation.SupersedeAgentCapabilityCeiling.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.delegation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.delegation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.CompleteSyncJob.Input": {
        "title": "CompleteSyncJob input",
        "x-ess-name": "mandate.directory.CompleteSyncJob",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SyncJobId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.CompleteSyncJob.accepted.Response": {
        "additionalProperties": false,
        "description": "One synchronization run is recorded as having applied every membership change it resolved. The queue that delivered the job stays behind its port; this records the outcome, not the transport. Taken when no other outcome's condition matched. A `mandate.directory.SyncJob` has moved to `Completed`, along `complete`. The instance is the one `id` names. Emits `SyncJobCompleted`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.CompleteSyncJob.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller is not the trusted synchronization worker, the job is outside the verified organization, or the membership changes the run applied cannot be recorded durably with its completion..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.CompleteSyncJob.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.CreateDirectoryGroupTeamMapping.Input": {
        "title": "CreateDirectoryGroupTeamMapping input",
        "x-ess-name": "mandate.directory.CreateDirectoryGroupTeamMapping",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "group_id": {
            "$ref": "#/components/schemas/mandate.core.DirectoryGroupId"
          },
          "team_id": {
            "$ref": "#/components/schemas/mandate.core.TeamId"
          }
        },
        "required": [
          "context",
          "group_id",
          "team_id"
        ],
        "additionalProperties": false
      },
      "mandate.directory.CreateDirectoryGroupTeamMapping.accepted.Response": {
        "additionalProperties": false,
        "description": "One mapping row, and the mapping-derived contribution rows the reconciliation wrote named by identity alone. Each contribution's own fields are on its MembershipContributionRecorded; nothing here is read positionally. Taken when no other outcome's condition matched. A `mandate.directory.DirectoryGroupTeamMapping` now exists, in `Active`. Its identity is published as `mapping_id` on `mandate.directory.DirectoryGroupTeamMappingCreated`. Emits `DirectoryGroupTeamMappingCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.CreateDirectoryGroupTeamMapping.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks mapping authority, group/team is unknown, the group is retired, the team is retired, either target is outside the verified organization, or provenance-preserving contribution reconciliation fails..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.directory.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.directory.FailSyncJob.Input": {
        "title": "FailSyncJob input",
        "x-ess-name": "mandate.directory.FailSyncJob",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SyncJobId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.FailSyncJob.accepted.Response": {
        "additionalProperties": false,
        "description": "A run that did not apply its full result is recorded as failed, so stale directory state is visible rather than silent. Redelivery is a new job record; a failed job is never retried in place. Taken when no other outcome's condition matched. A `mandate.directory.SyncJob` has moved to `Failed`, along `fail`. The instance is the one `id` names. Emits `SyncJobFailed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.FailSyncJob.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller is not the trusted synchronization worker, the job is outside the verified organization, or the partial run cannot be recorded without implying a completed synchronization..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.FailSyncJob.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupMembership.Input": {
        "title": "RemoveDirectoryGroupMembership input",
        "x-ess-name": "mandate.directory.RemoveDirectoryGroupMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.DirectoryGroupMembershipId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.RemoveDirectoryGroupMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.directory.DirectoryGroupMembership` has moved to `Removed`, along `remove`. The instance is the one `id` names. Emits `DirectoryGroupMembershipRemoved`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks trusted provisioning authority, group/member organization mismatches, or derived contribution removal cannot preserve unrelated memberships..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupMembership.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupTeamMapping.Input": {
        "title": "RemoveDirectoryGroupTeamMapping input",
        "x-ess-name": "mandate.directory.RemoveDirectoryGroupTeamMapping",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.DirectoryGroupTeamMappingId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.RemoveDirectoryGroupTeamMapping.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.directory.DirectoryGroupTeamMapping` has moved to `Removed`, along `remove`. The instance is the one `id` names. Emits `DirectoryGroupTeamMappingRemoved`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupTeamMapping.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks mapping authority, mapping is outside the verified organization, or retraction would remove the team, manual membership or another mapping contribution..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveDirectoryGroupTeamMapping.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveMembershipContribution.Input": {
        "title": "RemoveMembershipContribution input",
        "x-ess-name": "mandate.directory.RemoveMembershipContribution",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.MembershipContributionId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.RemoveMembershipContribution.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.directory.MembershipContribution` has moved to `Removed`, along `remove`. The instance is the one `id` names. Emits `MembershipContributionRemoved`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveMembershipContribution.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks mapping authority, contribution is outside the verified organization, or removal cannot preserve every other valid manual/mapping contribution..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RemoveMembershipContribution.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RetireDirectoryGroup.Input": {
        "title": "RetireDirectoryGroup input",
        "x-ess-name": "mandate.directory.RetireDirectoryGroup",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.DirectoryGroupId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.directory.RetireDirectoryGroup.accepted.Response": {
        "additionalProperties": false,
        "description": "The group the customer directory no longer publishes stops contributing authority and is kept as a record. Its memberships and team mappings are retracted by their own commands, which is what preserves every other manual or mapping contribution. Taken when no other outcome's condition matched. A `mandate.directory.DirectoryGroup` has moved to `Retired`, along `retire`. The instance is the one `id` names. Emits `DirectoryGroupRetired`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.RetireDirectoryGroup.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller is not an admitted provisioning source, the group is outside the verified organization, or retirement cannot preserve the team, manual memberships and the contributions another mapping still supports..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.RetireDirectoryGroup.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.directory.SyncDirectoryMembership.Input": {
        "title": "SyncDirectoryMembership input",
        "x-ess-name": "mandate.directory.SyncDirectoryMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "group_id": {
            "$ref": "#/components/schemas/mandate.core.DirectoryGroupId"
          },
          "members": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.PrincipalId"
            }
          }
        },
        "required": [
          "context",
          "group_id",
          "members"
        ],
        "additionalProperties": false
      },
      "mandate.directory.SyncDirectoryMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "The membership rows this run wrote, named by identity alone and nothing else. They are the additions the run resolved, never the group's full membership, and each row's own fields are on its own DirectoryGroupMembershipRecorded. A membership this run no longer resolves is removed only by RemoveDirectoryGroupMembership, whose DirectoryGroupMembershipRemoved names the row; absence from this list removes nothing. Taken when no other outcome's condition matched. Emits `DirectoryGroupMembershipChanged`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.directory.SyncDirectoryMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller is not an admitted provisioning source, the group is retired, group/member organization mismatches, or synchronization would grant authority without an explicit valid team mapping..",
        "properties": {
          "error": {
            "const": "mandate.directory.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.directory.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.AuthenticateFederation.Input": {
        "title": "AuthenticateFederation input",
        "x-ess-name": "mandate.federation.AuthenticateFederation",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "connection_id": {
            "$ref": "#/components/schemas/mandate.core.FederationConnectionId"
          },
          "proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          }
        },
        "required": [
          "connection_id",
          "proof"
        ],
        "additionalProperties": false
      },
      "mandate.federation.AuthenticateFederation.accepted.Response": {
        "additionalProperties": false,
        "description": "A validated federated login mints the session, which is step 9 of the resolution order in docs/architecture/federated-login.md. FederationAuthenticated carries the whole mandate.identity.Session record — the new session identity, the principal, the resolved organization, the connection, the epoch snapshot the session is bound to and its expiry — so the identity fold materializes the session from this event alone and reads no command input or response. The audience and the correlation are carried beside the record. The principal, the organization, the epoch snapshot handle and the expiry are the ones this command resolved and returned, so the fold reads each from the response rather than from a value the implementation invented; the snapshot's own contents are recorded by the adapter through EpochSnapshotRecorded. Taken when no other outcome's condition matched. A `mandate.identity.Session` now exists, in `Active`. Its identity is published as `session_id` on `mandate.federation.FederationAuthenticated`. Emits `FederationAuthenticated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.AuthenticateFederation.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Connection is disabled/untrusted, proof signature/issuer/audience/expiry is invalid, tenant resolution has zero or multiple matches, principal linking is absent/conflicting, or any email-domain/unverified-input fallback would be required..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.AuthorizePublicClient.Input": {
        "title": "AuthorizePublicClient input",
        "x-ess-name": "mandate.federation.AuthorizePublicClient",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "client_id": {
            "$ref": "#/components/schemas/mandate.core.OAuthClientId"
          },
          "redirect_uri": {
            "$ref": "#/components/schemas/mandate.core.RedirectUri"
          },
          "challenge": {
            "$ref": "#/components/schemas/mandate.core.PkceChallenge"
          },
          "method": {
            "$ref": "#/components/schemas/mandate.core.PkceMethod"
          },
          "state": {
            "type": "string"
          },
          "nonce": {
            "type": "string"
          },
          "session_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "requested_scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          }
        },
        "required": [
          "client_id",
          "redirect_uri",
          "challenge",
          "method",
          "state",
          "nonce",
          "session_proof",
          "target",
          "requested_scope"
        ],
        "additionalProperties": false
      },
      "mandate.federation.AuthorizePublicClient.accepted.Response": {
        "additionalProperties": false,
        "description": "The control plane orchestrates the verified session and client checks and calls the STS IssueAuthorizationCode port; the STS creates the mandate.credential.AuthorizationCode record and returns its identity, which this event names. This outcome creates nothing — code_id is the code STS minted, not one minted here — and the transient code is returned to the public-client adapter and to nothing else. Taken when no other outcome's condition matched. Emits `AuthorizationCodeIssued`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.AuthorizePublicClient.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Session proof is invalid/stale, client is not a registered public client, the client is disabled, exact redirect URI or state/applicable nonce binding fails, S256 challenge is absent/invalid, target is unregistered/outside tenant, or STS code issuance/narrowing is refused..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.federation.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.federation.DisableFederationConnection.Input": {
        "title": "DisableFederationConnection input",
        "x-ess-name": "mandate.federation.DisableFederationConnection",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.FederationConnectionId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.federation.DisableFederationConnection.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.federation.FederationConnection` has moved to `Disabled`, along `disable`. The instance is the one `id` names. Emits `FederationConnectionDisabled`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.DisableFederationConnection.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks federation-administration authority, connection is outside the verified organization, or emergency trust shutdown and affected generation invalidation cannot commit..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.DisableFederationConnection.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.DisableOAuthClient.Input": {
        "title": "DisableOAuthClient input",
        "x-ess-name": "mandate.federation.DisableOAuthClient",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.OAuthClientId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.federation.DisableOAuthClient.accepted.Response": {
        "additionalProperties": false,
        "description": "A registered public client whose redirect surface is no longer trusted stops being admitted. The registration record is kept. No new authorization code is issued to it, and an outstanding code is refused at redemption, where RedeemAuthorizationCode re-reads the client the code is bound to; no declared move invalidates an outstanding code. Taken when no other outcome's condition matched. A `mandate.federation.OAuthClient` has moved to `Disabled`, along `disable`. The instance is the one `id` names. Emits `OAuthClientDisabled`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.DisableOAuthClient.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks client-administration authority, the client is outside the verified organization, or disablement cannot stop the issuance of new authorization codes to it..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.DisableOAuthClient.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.LinkExternalPrincipal.Input": {
        "title": "LinkExternalPrincipal input",
        "x-ess-name": "mandate.federation.LinkExternalPrincipal",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "connection_id": {
            "$ref": "#/components/schemas/mandate.core.FederationConnectionId"
          },
          "external_subject": {
            "$ref": "#/components/schemas/mandate.core.ExternalSubject"
          },
          "principal_id": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "method": {
            "$ref": "#/components/schemas/mandate.core.ExternalLinkMethod"
          }
        },
        "required": [
          "context",
          "connection_id",
          "external_subject",
          "principal_id",
          "method"
        ],
        "additionalProperties": false
      },
      "mandate.federation.LinkExternalPrincipal.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.federation.ExternalPrincipal` now exists, in `Linked`. Its identity is published as `external_principal_id` on `mandate.federation.ExternalPrincipalLinked`. Emits `ExternalPrincipalLinked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.LinkExternalPrincipal.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller/method lacks linking authority, proof/connection trust is invalid, organization or target principal mismatches, composite (organization, configured issuer, subject) key conflicts, or durable audited linking fails. Email equality never authorizes linking..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.ProvisionExternalPrincipal.Input": {
        "title": "ProvisionExternalPrincipal input",
        "x-ess-name": "mandate.federation.ProvisionExternalPrincipal",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "connection_id": {
            "$ref": "#/components/schemas/mandate.core.FederationConnectionId"
          },
          "proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          }
        },
        "required": [
          "connection_id",
          "proof"
        ],
        "additionalProperties": false
      },
      "mandate.federation.ProvisionExternalPrincipal.accepted.Response": {
        "additionalProperties": false,
        "description": "Just-in-time provisioning on first login. The outcome creates exactly one record, the mandate.federation.ExternalPrincipal linking the principal with ExternalLinkMethod::ConfiguredFederation. The event also names the mandate.identity.Principal of kind User the provisioning produced, and no outcome in this contract declares that Principal's creation. Both identities, the external subject and the display name are bound from the response rather than left to the implementation; the display name is the validated subject until a connection admits a display-name claim, which no connection declares yet (story:federation-linking). The composite key is (organization, connection issuer, external subject), with the issuer read from the validated connection and the subject from the validated proof, never from the caller. No session is minted here; the adapter calls AuthenticateFederation again. Taken when no other outcome's condition matched. A `mandate.federation.ExternalPrincipal` now exists, in `Linked`. Its identity is published as `external_principal_id` on `mandate.federation.ExternalPrincipalProvisioned`. Emits `ExternalPrincipalProvisioned`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.ProvisionExternalPrincipal.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Connection is disabled/untrusted, proof signature/issuer/audience/expiry is invalid, tenant resolution has zero or multiple matches, principal linking is conflicting, connection does not admit provisioning, the composite (organization, configured issuer, subject) key already exists, or any email-domain/unverified-input fallback would be required..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.RegisterFederationConnection.Input": {
        "title": "RegisterFederationConnection input",
        "x-ess-name": "mandate.federation.RegisterFederationConnection",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "issuer": {
            "$ref": "#/components/schemas/mandate.core.Issuer"
          },
          "client_id": {
            "$ref": "#/components/schemas/mandate.core.ClientId"
          },
          "tenant_resolution": {
            "$ref": "#/components/schemas/mandate.core.TenantResolutionRule"
          },
          "jit_provisioning": {
            "type": "boolean"
          }
        },
        "required": [
          "context",
          "issuer",
          "client_id",
          "tenant_resolution",
          "jit_provisioning"
        ],
        "additionalProperties": false
      },
      "mandate.federation.RegisterFederationConnection.accepted.Response": {
        "additionalProperties": false,
        "description": "The connection is created with its provisioning setting decided here and never changed afterwards. A connection whose issuer or provisioning admission must change is disabled and registered again; there is no update command. Taken when no other outcome's condition matched. A `mandate.federation.FederationConnection` now exists, in `Enabled`. Its identity is published as `connection_id` on `mandate.federation.FederationConnectionCreated`. Emits `FederationConnectionCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.RegisterFederationConnection.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks federation-administration authority, issuer/client/trust, tenant-resolution or just-in-time provisioning configuration is unadmitted, or organization binding is invalid..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.RegisterOAuthClient.Input": {
        "title": "RegisterOAuthClient input",
        "x-ess-name": "mandate.federation.RegisterOAuthClient",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "public": {
            "type": "boolean"
          },
          "redirect_uris": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.RedirectUri"
            }
          },
          "pkce_method": {
            "$ref": "#/components/schemas/mandate.core.PkceMethod"
          }
        },
        "required": [
          "context",
          "public",
          "redirect_uris",
          "pkce_method"
        ],
        "additionalProperties": false
      },
      "mandate.federation.RegisterOAuthClient.accepted.Response": {
        "additionalProperties": false,
        "description": "The client is bound to the organization the verified context carries; the command takes no organization input, so no caller selects the tenant a client is registered into. OAuthClientRegistered carries the whole mandate.federation.OAuthClient record — the client identity, its organization, whether it is a public client, its exact redirect set and its PKCE method — so the federation fold materializes the client from this event alone and reads no command input or response. The identity and the organization are the ones this outcome decided and returned, read from the response rather than from a value the implementation invented. An empty redirect set is admitted and is not a denial — the client it registers is inert, because AuthorizePublicClient matches the presented redirect against the registered set exactly and an empty set matches nothing, so every authorization request to that client is refused. mandate.core.PkceMethod admits S256 and nothing else, so no registration can name another method and none is refused for naming one. A registration whose redirect surface or PKCE method must change is disabled and registered again; there is no update command. Taken when no other outcome's condition matched. A `mandate.federation.OAuthClient` now exists, in `Recorded`. Its identity is published as `id` on `mandate.federation.OAuthClientRegistered`. Emits `OAuthClientRegistered`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.RegisterOAuthClient.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks client-administration authority, a redirect URI is unadmitted, or organization binding is invalid..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.UnlinkExternalPrincipal.Input": {
        "title": "UnlinkExternalPrincipal input",
        "x-ess-name": "mandate.federation.UnlinkExternalPrincipal",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.ExternalPrincipalId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.federation.UnlinkExternalPrincipal.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.federation.ExternalPrincipal` has moved to `Unlinked`, along `unlink`. The instance is the one `id` names. Emits `ExternalPrincipalUnlinked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.federation.UnlinkExternalPrincipal.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks explicit link-administration authority, link is outside the verified organization, or unlinking and its required invalidation/audit cannot commit..",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.federation.UnlinkExternalPrincipal.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.federation.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.federation.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.identity.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.identity.DisablePrincipal.Input": {
        "title": "DisablePrincipal input",
        "x-ess-name": "mandate.identity.DisablePrincipal",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.identity.DisablePrincipal.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.identity.Principal` has moved to `Disabled`, along `disable`. The instance is the one `id` names. Emits `PrincipalDisabled`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.identity.DisablePrincipal.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks principal-administration authority, principal does not exist, or disablement cannot atomically trigger the required session/credential invalidation..",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.DisablePrincipal.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.IncrementSecurityEpoch.Input": {
        "title": "IncrementSecurityEpoch input",
        "x-ess-name": "mandate.identity.IncrementSecurityEpoch",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.SecurityEpochTarget"
          }
        },
        "required": [
          "context",
          "target"
        ],
        "additionalProperties": false
      },
      "mandate.identity.IncrementSecurityEpoch.accepted.Response": {
        "additionalProperties": false,
        "description": "UNMAPPED-EPOCH: this event declares the required increment outcome; no numeric mutation is executed or approximated. The adapter must atomically increment the one selected generation, deny unsigned overflow and preserve isolation of unrelated organizations/connections. Taken when no other outcome's condition matched. Emits `SecurityEpochIncremented`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.identity.IncrementSecurityEpoch.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks authority for the explicitly selected principal/organization/federation target, tenant containment fails, the exact unsigned generation is at its maximum, or atomic increment cannot commit..",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.RefreshSession.Input": {
        "title": "RefreshSession input",
        "x-ess-name": "mandate.identity.RefreshSession",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "refresh_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          }
        },
        "required": [
          "refresh_proof"
        ],
        "additionalProperties": false
      },
      "mandate.identity.RefreshSession.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. Emits `SessionRefreshed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.identity.RefreshSession.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Refresh verifier is absent/incorrect, record is expired/revoked, principal/session is disabled, any applicable principal/organization/federation epoch mismatches, or session binding fails..",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeRefreshCredential.Input": {
        "title": "RevokeRefreshCredential input",
        "x-ess-name": "mandate.identity.RevokeRefreshCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.RefreshCredentialId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.identity.RevokeRefreshCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.identity.RefreshCredential` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `RefreshCredentialRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeRefreshCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks authority over the resolved refresh credential, tenant/session binding mismatches, or durable revocation fails..",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeRefreshCredential.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeSession.Input": {
        "title": "RevokeSession input",
        "x-ess-name": "mandate.identity.RevokeSession",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SessionId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.identity.RevokeSession.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.identity.Session` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `SessionRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeSession.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks authority over this session, session is outside the verified organization, or revocation cannot be durably observed under the applicable profile..",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.identity.RevokeSession.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.identity.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.identity.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.AddOrganizationMembership.Input": {
        "title": "AddOrganizationMembership input",
        "x-ess-name": "mandate.tenancy.AddOrganizationMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "organization_id": {
            "$ref": "#/components/schemas/mandate.core.OrganizationId"
          },
          "principal_id": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          }
        },
        "required": [
          "context",
          "organization_id",
          "principal_id"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.AddOrganizationMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "The one membership path, and the only command that names an organization other than the caller's. organization_id must equal the organization in the caller's verified context; it may differ only for a caller holding platform organization-administration authority, which is how the organization CreateOrganization returns is first populated and how it acquires the administrator whose own context every later write inside it resolves from. A directory provisioning source calls this command as an admitted caller; membership carries no authority by itself, which stays with grants and relationships. Taken when no other outcome's condition matched. A `mandate.tenancy.OrganizationMembership` now exists, in `Active`. Its identity is published as `membership_id` on `mandate.tenancy.OrganizationMembershipAdded`. Emits `OrganizationMembershipAdded`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.AddOrganizationMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks membership-administration authority, organization_id differs from the verified organization and the caller lacks platform organization-administration authority, the named organization is closed, the principal is unresolved or disabled, the principal is already a member of that organization, or membership and its dependent authorization cannot commit consistently..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.AddTeamMembership.Input": {
        "title": "AddTeamMembership input",
        "x-ess-name": "mandate.tenancy.AddTeamMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "team_id": {
            "$ref": "#/components/schemas/mandate.core.TeamId"
          },
          "principal_id": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          }
        },
        "required": [
          "context",
          "team_id",
          "principal_id"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.AddTeamMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "The manual path, and the only command that records a team membership. It records one membership and the one manual MembershipContribution that says where the membership came from, and returns both identities. A mapping-derived contribution against the same membership is mandate.directory's own record, written by that domain's commands when a group mapping is created or synchronized, so a retracted mapping never removes a membership a manual decision still holds up. Taken when no other outcome's condition matched. A `mandate.tenancy.TeamMembership` now exists, in `Recorded`. Its identity is published as `team_membership_id` on `mandate.tenancy.TeamMembershipAdded`. Emits `TeamMembershipAdded`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.AddTeamMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks team-administration authority, team or principal is unresolved or outside the verified organization, the team is retired, the principal is disabled, the principal is not a member of that organization, the principal is already a member of that team, or the membership and the manual contribution recording its provenance cannot be recorded together..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.CloseOrganization.Input": {
        "title": "CloseOrganization input",
        "x-ess-name": "mandate.tenancy.CloseOrganization",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.OrganizationId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.CloseOrganization.accepted.Response": {
        "additionalProperties": false,
        "description": "The tenant stops admitting authority and nothing it owns is destroyed. Memberships, grants, delegations and audit history are preserved; sessions and credentials inside it stop being eligible through the organization generation, which IncrementSecurityEpoch advances. Taken when no other outcome's condition matched. A `mandate.tenancy.Organization` has moved to `Closed`, along `close`. The instance is the one `id` names. Emits `OrganizationClosed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.CloseOrganization.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks platform organization-administration authority, the organization is unresolved, the sessions, credentials and delegations inside it cannot be invalidated with the closure, or closure would require destroying membership or audit history..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.CloseOrganization.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateOrganization.Input": {
        "title": "CreateOrganization input",
        "x-ess-name": "mandate.tenancy.CreateOrganization",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "display_name": {
            "type": "string"
          }
        },
        "required": [
          "context",
          "display_name"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.CreateOrganization.accepted.Response": {
        "additionalProperties": false,
        "description": "The isolation root every other tenant-owned record resolves to. It is created empty, and no membership, team, space or grant exists inside it until that record's own command writes one. AddOrganizationMembership is the one command that can name this organization rather than the caller's own, so the first membership inside it is written by a caller holding platform organization-administration authority; every later write resolves the organization from that member's verified context. Taken when no other outcome's condition matched. A `mandate.tenancy.Organization` now exists, in `Recorded`. Its identity is published as `organization_id` on `mandate.tenancy.OrganizationCreated`. Emits `OrganizationCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateOrganization.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks platform organization-administration authority, the requested display name is not admitted, or the isolation root cannot be created without implying membership, grants or authority inside it..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateSpace.Input": {
        "title": "CreateSpace input",
        "x-ess-name": "mandate.tenancy.CreateSpace",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "display_name": {
            "type": "string"
          }
        },
        "required": [
          "context",
          "display_name"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.CreateSpace.accepted.Response": {
        "additionalProperties": false,
        "description": "A security boundary below the organization, with no environment semantics implied by its name. Creating it grants nothing inside it. Taken when no other outcome's condition matched. A `mandate.tenancy.Space` now exists, in `Recorded`. Its identity is published as `space_id` on `mandate.tenancy.SpaceCreated`. Emits `SpaceCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateSpace.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks space-administration authority, the display name is not admitted in the verified organization, or the space cannot be created without implying a grant or a resource inside it..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateTeam.Input": {
        "title": "CreateTeam input",
        "x-ess-name": "mandate.tenancy.CreateTeam",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "display_name": {
            "type": "string"
          }
        },
        "required": [
          "context",
          "display_name"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.CreateTeam.accepted.Response": {
        "additionalProperties": false,
        "description": "A team is created by an organization administrator and never by directory synchronization. A customer directory group populates directory state, and whether that group maps to this team is a separate explicit decision. Taken when no other outcome's condition matched. A `mandate.tenancy.Team` now exists, in `Recorded`. Its identity is published as `team_id` on `mandate.tenancy.TeamCreated`. Emits `TeamCreated`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.CreateTeam.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks team-administration authority, the display name is not admitted in the verified organization, or the team cannot be created without implying a grant or a directory mapping..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.tenancy.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.RemoveOrganizationMembership.Input": {
        "title": "RemoveOrganizationMembership input",
        "x-ess-name": "mandate.tenancy.RemoveOrganizationMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.OrganizationMembershipId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.RemoveOrganizationMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.tenancy.OrganizationMembership` has moved to `Removed`, along `remove`. The instance is the one `id` names. Emits `OrganizationMembershipRemoved`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.RemoveOrganizationMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks membership-administration authority, membership is outside the verified organization, or membership and dependent authorization invalidation cannot commit consistently..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RemoveOrganizationMembership.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RemoveTeamMembership.Input": {
        "title": "RemoveTeamMembership input",
        "x-ess-name": "mandate.tenancy.RemoveTeamMembership",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.TeamMembershipId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.RemoveTeamMembership.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken only once no contribution supports the membership any longer — neither the manual one recorded with it nor any mandate.directory mapping contribution — which is what stops a retracted mapping from removing a membership a manual decision still holds up. The record and its history are kept. Taken when no other outcome's condition matched. A `mandate.tenancy.TeamMembership` has moved to `Removed`, along `remove`. The instance is the one `id` names. Emits `TeamMembershipRemoved`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.RemoveTeamMembership.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks team-administration authority, the membership is outside the verified organization, a mandate.directory mapping contribution still supports it, or dependent authorization invalidation cannot commit consistently..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RemoveTeamMembership.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireSpace.Input": {
        "title": "RetireSpace input",
        "x-ess-name": "mandate.tenancy.RetireSpace",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SpaceId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.RetireSpace.accepted.Response": {
        "additionalProperties": false,
        "description": "The boundary stops admitting new authority and keeps every resource bound to it. Resources inside are deregistered by their own command; nothing is destroyed by retiring the space around them. Taken when no other outcome's condition matched. A `mandate.tenancy.Space` has moved to `Retired`, along `retire`. The instance is the one `id` names. Emits `SpaceRetired`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireSpace.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks space-administration authority, the space is outside the verified organization, or retirement cannot refuse new authority inside it while preserving the resources and grants already bound to it..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireSpace.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireTeam.Input": {
        "title": "RetireTeam input",
        "x-ess-name": "mandate.tenancy.RetireTeam",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.TeamId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.tenancy.RetireTeam.accepted.Response": {
        "additionalProperties": false,
        "description": "The explicit request a mapping retraction never makes on its own. The team stops resolving as an authorization subject; its memberships and their provenance are preserved, and the grants that target it are revoked by their own command. Taken when no other outcome's condition matched. A `mandate.tenancy.Team` has moved to `Retired`, along `retire`. The instance is the one `id` names. Emits `TeamRetired`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireTeam.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks team-administration authority, the team is outside the verified organization, a directory mapping still contributes to it, or retirement cannot revoke the grants that target it while preserving membership provenance..",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.tenancy.RetireTeam.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.tenancy.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.tenancy.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.workload.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.workload.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.workload.RevokeWorkloadIdentity.Input": {
        "title": "RevokeWorkloadIdentity input",
        "x-ess-name": "mandate.workload.RevokeWorkloadIdentity",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.WorkloadIdentityId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.workload.RevokeWorkloadIdentity.accepted.Response": {
        "additionalProperties": false,
        "description": "The binding stops being admitted. A workload credential presented under this trust domain and subject is refused from that point, and the record is kept so past exchanges stay attributable. Taken when no other outcome's condition matched. A `mandate.workload.WorkloadIdentity` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `WorkloadIdentityRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.workload.RevokeWorkloadIdentity.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks workload-identity administration authority, the identity is outside the verified organization, or revocation cannot durably stop the exchange of workload credentials presented under the binding..",
        "properties": {
          "error": {
            "const": "mandate.workload.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.workload.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.workload.RevokeWorkloadIdentity.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.workload.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.workload.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      }
    }
  },
  "x-ess-entities": {
    "mandate.core.Action": {
      "title": "Action",
      "x-ess-name": "mandate.core.Action",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.ActionPattern": {
      "title": "ActionPattern",
      "x-ess-name": "mandate.core.ActionPattern",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.AgentCapabilityCeilingId": {
      "title": "AgentCapabilityCeilingId",
      "x-ess-name": "mandate.core.AgentCapabilityCeilingId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ApprovalId": {
      "title": "ApprovalId",
      "x-ess-name": "mandate.core.ApprovalId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.Audience": {
      "title": "Audience",
      "x-ess-name": "mandate.core.Audience",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.AuthorityScope": {
      "title": "AuthorityScope",
      "x-ess-name": "mandate.core.AuthorityScope",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "actions": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.Action"
          }
        },
        "resources": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.ResourceRef"
          }
        },
        "space": {
          "$ref": "#/x-ess-entities/mandate.core.SpaceId"
        }
      },
      "required": [
        "actions",
        "resources"
      ],
      "additionalProperties": false
    },
    "mandate.core.ClientId": {
      "title": "ClientId",
      "x-ess-name": "mandate.core.ClientId",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.CorrelationId": {
      "title": "CorrelationId",
      "x-ess-name": "mandate.core.CorrelationId",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.CredentialVerifier": {
      "title": "CredentialVerifier",
      "x-ess-name": "mandate.core.CredentialVerifier",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.DelegationId": {
      "title": "DelegationId",
      "x-ess-name": "mandate.core.DelegationId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.DirectoryGroupId": {
      "title": "DirectoryGroupId",
      "x-ess-name": "mandate.core.DirectoryGroupId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.DirectoryGroupMembershipId": {
      "title": "DirectoryGroupMembershipId",
      "x-ess-name": "mandate.core.DirectoryGroupMembershipId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.DirectoryGroupTeamMappingId": {
      "title": "DirectoryGroupTeamMappingId",
      "x-ess-name": "mandate.core.DirectoryGroupTeamMappingId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.EpochSnapshotRef": {
      "title": "EpochSnapshotRef",
      "x-ess-name": "mandate.core.EpochSnapshotRef",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ExecutionId": {
      "title": "ExecutionId",
      "x-ess-name": "mandate.core.ExecutionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ExternalLinkMethod": {
      "title": "ExternalLinkMethod",
      "x-ess-name": "mandate.core.ExternalLinkMethod",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Administrator",
        "AuthenticatedConfirmation",
        "VerifiedMigration",
        "ConfiguredFederation",
        "SecuritySupport"
      ]
    },
    "mandate.core.ExternalPrincipalId": {
      "title": "ExternalPrincipalId",
      "x-ess-name": "mandate.core.ExternalPrincipalId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ExternalSubject": {
      "title": "ExternalSubject",
      "x-ess-name": "mandate.core.ExternalSubject",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.FederationConnectionId": {
      "title": "FederationConnectionId",
      "x-ess-name": "mandate.core.FederationConnectionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.Issuer": {
      "title": "Issuer",
      "x-ess-name": "mandate.core.Issuer",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.MembershipContributionId": {
      "title": "MembershipContributionId",
      "x-ess-name": "mandate.core.MembershipContributionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.MembershipSource": {
      "title": "MembershipSource",
      "x-ess-name": "mandate.core.MembershipSource",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Manual",
        "DirectoryMapping"
      ]
    },
    "mandate.core.OAuthClientId": {
      "title": "OAuthClientId",
      "x-ess-name": "mandate.core.OAuthClientId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.OrganizationId": {
      "title": "OrganizationId",
      "x-ess-name": "mandate.core.OrganizationId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.OrganizationMembershipId": {
      "title": "OrganizationMembershipId",
      "x-ess-name": "mandate.core.OrganizationMembershipId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.PkceMethod": {
      "title": "PkceMethod",
      "x-ess-name": "mandate.core.PkceMethod",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "S256"
      ]
    },
    "mandate.core.PolicyVersion": {
      "title": "PolicyVersion",
      "x-ess-name": "mandate.core.PolicyVersion",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.PrincipalId": {
      "title": "PrincipalId",
      "x-ess-name": "mandate.core.PrincipalId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.PrincipalKind": {
      "title": "PrincipalKind",
      "x-ess-name": "mandate.core.PrincipalKind",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "User",
        "Service",
        "Agent",
        "ServiceAccount"
      ]
    },
    "mandate.core.RedirectUri": {
      "title": "RedirectUri",
      "x-ess-name": "mandate.core.RedirectUri",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.RefreshCredentialId": {
      "title": "RefreshCredentialId",
      "x-ess-name": "mandate.core.RefreshCredentialId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ResourceId": {
      "title": "ResourceId",
      "x-ess-name": "mandate.core.ResourceId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ResourceRef": {
      "title": "ResourceRef",
      "x-ess-name": "mandate.core.ResourceRef",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "resource_type": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceType"
        },
        "resource_id": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceId"
        }
      },
      "required": [
        "resource_type",
        "resource_id"
      ],
      "additionalProperties": false
    },
    "mandate.core.ResourceType": {
      "title": "ResourceType",
      "x-ess-name": "mandate.core.ResourceType",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.SessionId": {
      "title": "SessionId",
      "x-ess-name": "mandate.core.SessionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.SpaceId": {
      "title": "SpaceId",
      "x-ess-name": "mandate.core.SpaceId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.SyncJobId": {
      "title": "SyncJobId",
      "x-ess-name": "mandate.core.SyncJobId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.TeamId": {
      "title": "TeamId",
      "x-ess-name": "mandate.core.TeamId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.TeamMembershipId": {
      "title": "TeamMembershipId",
      "x-ess-name": "mandate.core.TeamMembershipId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.TenantResolutionRule": {
      "title": "TenantResolutionRule",
      "x-ess-name": "mandate.core.TenantResolutionRule",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "configured_organization": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId"
        },
        "verified_claim_name": {
          "type": "string"
        },
        "verified_claim_value": {
          "type": "string"
        }
      },
      "required": [
        "configured_organization"
      ],
      "additionalProperties": false
    },
    "mandate.core.TrustDomain": {
      "title": "TrustDomain",
      "x-ess-name": "mandate.core.TrustDomain",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.WorkloadIdentityId": {
      "title": "WorkloadIdentityId",
      "x-ess-name": "mandate.core.WorkloadIdentityId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.delegation.Agent": {
      "title": "Agent",
      "x-ess-name": "mandate.delegation.Agent",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.delegation.Agent",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "agent_type": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.delegation.Agent.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "agent_type",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.delegation.Agent.State": {
      "title": "State",
      "x-ess-name": "mandate.delegation.Agent.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Retired"
      ]
    },
    "mandate.delegation.AgentCapabilityCeiling": {
      "title": "AgentCapabilityCeiling",
      "x-ess-name": "mandate.delegation.AgentCapabilityCeiling",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.AgentCapabilityCeilingId"
        },
        "agent_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "agent_record",
            "kind": "references",
            "source": "mandate.delegation.AgentCapabilityCeiling",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "agent_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.delegation.AgentCapabilityCeiling",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "allowed_actions": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.ActionPattern"
          }
        },
        "denied_actions": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.ActionPattern"
          }
        },
        "scope": {
          "$ref": "#/x-ess-entities/mandate.core.AuthorityScope"
        },
        "max_delegation_ttl": {
          "type": "string",
          "format": "duration"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.delegation.AgentCapabilityCeiling.State"
        }
      },
      "required": [
        "id",
        "agent_id",
        "allowed_actions",
        "denied_actions",
        "scope",
        "max_delegation_ttl",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.delegation.AgentCapabilityCeiling.State": {
      "title": "State",
      "x-ess-name": "mandate.delegation.AgentCapabilityCeiling.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Superseded"
      ]
    },
    "mandate.delegation.Approval": {
      "title": "Approval",
      "x-ess-name": "mandate.delegation.Approval",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.ApprovalId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.delegation.Approval",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "subject": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "subject_record",
            "kind": "references",
            "source": "mandate.delegation.Approval",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "subject",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "actor": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "actor_record",
            "kind": "references",
            "source": "mandate.delegation.Approval",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "actor",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "action": {
          "$ref": "#/x-ess-entities/mandate.core.Action"
        },
        "resource": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceRef"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "approver": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "approver_record",
            "kind": "references",
            "source": "mandate.delegation.Approval",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "approver",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.delegation.Approval.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "subject",
        "action",
        "resource",
        "expires_at",
        "approver",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.delegation.Approval.State": {
      "title": "State",
      "x-ess-name": "mandate.delegation.Approval.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Consumed",
        "Recorded"
      ]
    },
    "mandate.delegation.Delegation": {
      "title": "Delegation",
      "x-ess-name": "mandate.delegation.Delegation",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.DelegationId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.delegation.Delegation",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "delegator": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "delegator_record",
            "kind": "references",
            "source": "mandate.delegation.Delegation",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "delegator",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "delegate": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "delegate_record",
            "kind": "references",
            "source": "mandate.delegation.Delegation",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "delegate",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "scope": {
          "$ref": "#/x-ess-entities/mandate.core.AuthorityScope"
        },
        "audience": {
          "$ref": "#/x-ess-entities/mandate.core.Audience"
        },
        "not_before": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "execution_binding": {
          "$ref": "#/x-ess-entities/mandate.core.ExecutionId",
          "x-ess-relation": {
            "name": "execution_binding_record",
            "kind": "references",
            "source": "mandate.delegation.Delegation",
            "target": "mandate.delegation.Execution",
            "cardinality": "one",
            "via": "execution_binding",
            "$ref": "#/x-ess-entities/mandate.delegation.Execution"
          }
        },
        "transitive": {
          "type": "boolean"
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.delegation.Delegation.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "delegator",
        "delegate",
        "scope",
        "audience",
        "expires_at",
        "transitive",
        "created_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.delegation.Delegation.State": {
      "title": "State",
      "x-ess-name": "mandate.delegation.Delegation.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Revoked"
      ]
    },
    "mandate.delegation.Execution": {
      "title": "Execution",
      "x-ess-name": "mandate.delegation.Execution",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.ExecutionId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.delegation.Execution",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "agent_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "agent_id_record",
            "kind": "references",
            "source": "mandate.delegation.Execution",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "agent_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "subject": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "subject_record",
            "kind": "references",
            "source": "mandate.delegation.Execution",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "subject",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "delegation_id": {
          "$ref": "#/x-ess-entities/mandate.core.DelegationId",
          "x-ess-relation": {
            "name": "delegation_id_record",
            "kind": "references",
            "source": "mandate.delegation.Execution",
            "target": "mandate.delegation.Delegation",
            "cardinality": "one",
            "via": "delegation_id",
            "$ref": "#/x-ess-entities/mandate.delegation.Delegation"
          }
        },
        "initiating_session": {
          "$ref": "#/x-ess-entities/mandate.core.SessionId",
          "x-ess-relation": {
            "name": "initiating_session_record",
            "kind": "references",
            "source": "mandate.delegation.Execution",
            "target": "mandate.identity.Session",
            "cardinality": "one",
            "via": "initiating_session",
            "$ref": "#/x-ess-entities/mandate.identity.Session"
          }
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "policy_version": {
          "$ref": "#/x-ess-entities/mandate.core.PolicyVersion"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.delegation.Execution.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "agent_id",
        "created_at",
        "expires_at",
        "policy_version",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.delegation.Execution.State": {
      "title": "State",
      "x-ess-name": "mandate.delegation.Execution.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Completed",
        "Recorded"
      ]
    },
    "mandate.directory.DirectoryGroup": {
      "title": "DirectoryGroup",
      "x-ess-name": "mandate.directory.DirectoryGroup",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroup",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "display_name": {
          "type": "string"
        },
        "source": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroup.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "display_name",
        "source",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.directory.DirectoryGroup.State": {
      "title": "State",
      "x-ess-name": "mandate.directory.DirectoryGroup.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Retired"
      ]
    },
    "mandate.directory.DirectoryGroupMembership": {
      "title": "DirectoryGroupMembership",
      "x-ess-name": "mandate.directory.DirectoryGroupMembership",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupMembershipId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupMembership",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "group_id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupId",
          "x-ess-relation": {
            "name": "group_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupMembership",
            "target": "mandate.directory.DirectoryGroup",
            "cardinality": "one",
            "via": "group_id",
            "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroup"
          }
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupMembership",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroupMembership.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "group_id",
        "principal_id",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.directory.DirectoryGroupMembership.State": {
      "title": "State",
      "x-ess-name": "mandate.directory.DirectoryGroupMembership.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Removed"
      ]
    },
    "mandate.directory.DirectoryGroupTeamMapping": {
      "title": "DirectoryGroupTeamMapping",
      "x-ess-name": "mandate.directory.DirectoryGroupTeamMapping",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupTeamMappingId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupTeamMapping",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "group_id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupId",
          "x-ess-relation": {
            "name": "group_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupTeamMapping",
            "target": "mandate.directory.DirectoryGroup",
            "cardinality": "one",
            "via": "group_id",
            "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroup"
          }
        },
        "team_id": {
          "$ref": "#/x-ess-entities/mandate.core.TeamId",
          "x-ess-relation": {
            "name": "team_id_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupTeamMapping",
            "target": "mandate.tenancy.Team",
            "cardinality": "one",
            "via": "team_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Team"
          }
        },
        "created_by": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "created_by_record",
            "kind": "references",
            "source": "mandate.directory.DirectoryGroupTeamMapping",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "created_by",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroupTeamMapping.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "group_id",
        "team_id",
        "created_by",
        "created_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.directory.DirectoryGroupTeamMapping.State": {
      "title": "State",
      "x-ess-name": "mandate.directory.DirectoryGroupTeamMapping.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Removed"
      ]
    },
    "mandate.directory.MembershipContribution": {
      "title": "MembershipContribution",
      "x-ess-name": "mandate.directory.MembershipContribution",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.MembershipContributionId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.directory.MembershipContribution",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "team_membership_id": {
          "$ref": "#/x-ess-entities/mandate.core.TeamMembershipId",
          "x-ess-relation": {
            "name": "team_membership_id_record",
            "kind": "references",
            "source": "mandate.directory.MembershipContribution",
            "target": "mandate.tenancy.TeamMembership",
            "cardinality": "one",
            "via": "team_membership_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.TeamMembership"
          }
        },
        "source": {
          "$ref": "#/x-ess-entities/mandate.core.MembershipSource"
        },
        "mapping_id": {
          "$ref": "#/x-ess-entities/mandate.core.DirectoryGroupTeamMappingId",
          "x-ess-relation": {
            "name": "mapping_id_record",
            "kind": "references",
            "source": "mandate.directory.MembershipContribution",
            "target": "mandate.directory.DirectoryGroupTeamMapping",
            "cardinality": "one",
            "via": "mapping_id",
            "$ref": "#/x-ess-entities/mandate.directory.DirectoryGroupTeamMapping"
          }
        },
        "created_by": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "created_by_record",
            "kind": "references",
            "source": "mandate.directory.MembershipContribution",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "created_by",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.directory.MembershipContribution.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "team_membership_id",
        "source",
        "created_by",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.directory.MembershipContribution.State": {
      "title": "State",
      "x-ess-name": "mandate.directory.MembershipContribution.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Removed"
      ]
    },
    "mandate.directory.SyncJob": {
      "title": "SyncJob",
      "x-ess-name": "mandate.directory.SyncJob",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.SyncJobId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.directory.SyncJob",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "connection_id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId",
          "x-ess-relation": {
            "name": "connection_id_record",
            "kind": "references",
            "source": "mandate.directory.SyncJob",
            "target": "mandate.federation.FederationConnection",
            "cardinality": "one",
            "via": "connection_id",
            "$ref": "#/x-ess-entities/mandate.federation.FederationConnection"
          }
        },
        "correlation": {
          "$ref": "#/x-ess-entities/mandate.core.CorrelationId"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.directory.SyncJob.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "connection_id",
        "correlation",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.directory.SyncJob.State": {
      "title": "State",
      "x-ess-name": "mandate.directory.SyncJob.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Completed",
        "Failed",
        "Recorded"
      ]
    },
    "mandate.federation.ExternalPrincipal": {
      "title": "ExternalPrincipal",
      "x-ess-name": "mandate.federation.ExternalPrincipal",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.ExternalPrincipalId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.federation.ExternalPrincipal",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "subject": {
          "$ref": "#/x-ess-entities/mandate.core.ExternalSubject"
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.federation.ExternalPrincipal",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "connection_id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId",
          "x-ess-relation": {
            "name": "connection_id_record",
            "kind": "references",
            "source": "mandate.federation.ExternalPrincipal",
            "target": "mandate.federation.FederationConnection",
            "cardinality": "one",
            "via": "connection_id",
            "$ref": "#/x-ess-entities/mandate.federation.FederationConnection"
          }
        },
        "link_method": {
          "$ref": "#/x-ess-entities/mandate.core.ExternalLinkMethod"
        },
        "linked_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.federation.ExternalPrincipal.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "subject",
        "principal_id",
        "connection_id",
        "link_method",
        "linked_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.federation.ExternalPrincipal.State": {
      "title": "State",
      "x-ess-name": "mandate.federation.ExternalPrincipal.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Linked",
        "Unlinked"
      ]
    },
    "mandate.federation.FederationConnection": {
      "title": "FederationConnection",
      "x-ess-name": "mandate.federation.FederationConnection",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.federation.FederationConnection",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "issuer": {
          "$ref": "#/x-ess-entities/mandate.core.Issuer"
        },
        "client_id": {
          "$ref": "#/x-ess-entities/mandate.core.ClientId"
        },
        "tenant_resolution": {
          "$ref": "#/x-ess-entities/mandate.core.TenantResolutionRule"
        },
        "jit_provisioning": {
          "type": "boolean"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.federation.FederationConnection.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "issuer",
        "client_id",
        "tenant_resolution",
        "jit_provisioning",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.federation.FederationConnection.State": {
      "title": "State",
      "x-ess-name": "mandate.federation.FederationConnection.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Disabled",
        "Enabled"
      ]
    },
    "mandate.federation.OAuthClient": {
      "title": "OAuthClient",
      "x-ess-name": "mandate.federation.OAuthClient",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.OAuthClientId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.federation.OAuthClient",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "public": {
          "type": "boolean"
        },
        "redirect_uris": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.RedirectUri"
          }
        },
        "pkce_method": {
          "$ref": "#/x-ess-entities/mandate.core.PkceMethod"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.federation.OAuthClient.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "public",
        "redirect_uris",
        "pkce_method",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.federation.OAuthClient.State": {
      "title": "State",
      "x-ess-name": "mandate.federation.OAuthClient.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Disabled",
        "Recorded"
      ]
    },
    "mandate.identity.FederationSecurityEpoch": {
      "title": "FederationSecurityEpoch",
      "x-ess-name": "mandate.identity.FederationSecurityEpoch",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId"
        },
        "generation": {
          "type": "integer"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.FederationSecurityEpoch.State"
        }
      },
      "required": [
        "id",
        "generation",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.FederationSecurityEpoch.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.FederationSecurityEpoch.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded"
      ]
    },
    "mandate.identity.OrganizationSecurityEpoch": {
      "title": "OrganizationSecurityEpoch",
      "x-ess-name": "mandate.identity.OrganizationSecurityEpoch",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId"
        },
        "generation": {
          "type": "integer"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.OrganizationSecurityEpoch.State"
        }
      },
      "required": [
        "id",
        "generation",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.OrganizationSecurityEpoch.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.OrganizationSecurityEpoch.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded"
      ]
    },
    "mandate.identity.Principal": {
      "title": "Principal",
      "x-ess-name": "mandate.identity.Principal",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId"
        },
        "kind": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalKind"
        },
        "display_name": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.Principal.State"
        }
      },
      "required": [
        "id",
        "kind",
        "display_name",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.Principal.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.Principal.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Disabled"
      ]
    },
    "mandate.identity.PrincipalSecurityEpoch": {
      "title": "PrincipalSecurityEpoch",
      "x-ess-name": "mandate.identity.PrincipalSecurityEpoch",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId"
        },
        "generation": {
          "type": "integer"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.PrincipalSecurityEpoch.State"
        }
      },
      "required": [
        "id",
        "generation",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.PrincipalSecurityEpoch.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.PrincipalSecurityEpoch.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded"
      ]
    },
    "mandate.identity.RefreshCredential": {
      "title": "RefreshCredential",
      "x-ess-name": "mandate.identity.RefreshCredential",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.RefreshCredentialId"
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.identity.RefreshCredential",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.identity.RefreshCredential",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "session_id": {
          "$ref": "#/x-ess-entities/mandate.core.SessionId",
          "x-ess-relation": {
            "name": "session_id_record",
            "kind": "references",
            "source": "mandate.identity.RefreshCredential",
            "target": "mandate.identity.Session",
            "cardinality": "one",
            "via": "session_id",
            "$ref": "#/x-ess-entities/mandate.identity.Session"
          }
        },
        "verifier": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialVerifier"
        },
        "epochs": {
          "$ref": "#/x-ess-entities/mandate.core.EpochSnapshotRef",
          "x-ess-relation": {
            "name": "epoch_snapshot_record",
            "kind": "references",
            "source": "mandate.identity.RefreshCredential",
            "target": "mandate.identity.SecurityEpochSnapshot",
            "cardinality": "one",
            "via": "epochs",
            "$ref": "#/x-ess-entities/mandate.identity.SecurityEpochSnapshot"
          }
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.RefreshCredential.State"
        }
      },
      "required": [
        "id",
        "principal_id",
        "organization_id",
        "session_id",
        "verifier",
        "epochs",
        "expires_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.RefreshCredential.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.RefreshCredential.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Revoked"
      ]
    },
    "mandate.identity.SecurityEpochSnapshot": {
      "title": "SecurityEpochSnapshot",
      "x-ess-name": "mandate.identity.SecurityEpochSnapshot",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.EpochSnapshotRef"
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_record",
            "kind": "references",
            "source": "mandate.identity.SecurityEpochSnapshot",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.identity.SecurityEpochSnapshot",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "connection_id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId",
          "x-ess-relation": {
            "name": "connection_id_record",
            "kind": "references",
            "source": "mandate.identity.SecurityEpochSnapshot",
            "target": "mandate.federation.FederationConnection",
            "cardinality": "one",
            "via": "connection_id",
            "$ref": "#/x-ess-entities/mandate.federation.FederationConnection"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.SecurityEpochSnapshot.State"
        }
      },
      "required": [
        "id",
        "principal_id",
        "organization_id",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.SecurityEpochSnapshot.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.SecurityEpochSnapshot.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded"
      ]
    },
    "mandate.identity.Session": {
      "title": "Session",
      "x-ess-name": "mandate.identity.Session",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.SessionId"
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.identity.Session",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.identity.Session",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "connection_id": {
          "$ref": "#/x-ess-entities/mandate.core.FederationConnectionId",
          "x-ess-relation": {
            "name": "connection_id_record",
            "kind": "references",
            "source": "mandate.identity.Session",
            "target": "mandate.federation.FederationConnection",
            "cardinality": "one",
            "via": "connection_id",
            "$ref": "#/x-ess-entities/mandate.federation.FederationConnection"
          }
        },
        "epochs": {
          "$ref": "#/x-ess-entities/mandate.core.EpochSnapshotRef",
          "x-ess-relation": {
            "name": "epoch_snapshot_record",
            "kind": "references",
            "source": "mandate.identity.Session",
            "target": "mandate.identity.SecurityEpochSnapshot",
            "cardinality": "one",
            "via": "epochs",
            "$ref": "#/x-ess-entities/mandate.identity.SecurityEpochSnapshot"
          }
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.identity.Session.State"
        }
      },
      "required": [
        "id",
        "principal_id",
        "organization_id",
        "epochs",
        "expires_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.identity.Session.State": {
      "title": "State",
      "x-ess-name": "mandate.identity.Session.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Revoked"
      ]
    },
    "mandate.tenancy.Organization": {
      "title": "Organization",
      "x-ess-name": "mandate.tenancy.Organization",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId"
        },
        "display_name": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.tenancy.Organization.State"
        }
      },
      "required": [
        "id",
        "display_name",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.tenancy.Organization.State": {
      "title": "State",
      "x-ess-name": "mandate.tenancy.Organization.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Closed",
        "Recorded"
      ]
    },
    "mandate.tenancy.OrganizationMembership": {
      "title": "OrganizationMembership",
      "x-ess-name": "mandate.tenancy.OrganizationMembership",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationMembershipId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.tenancy.OrganizationMembership",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.tenancy.OrganizationMembership",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.tenancy.OrganizationMembership.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "principal_id",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.tenancy.OrganizationMembership.State": {
      "title": "State",
      "x-ess-name": "mandate.tenancy.OrganizationMembership.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Removed"
      ]
    },
    "mandate.tenancy.Space": {
      "title": "Space",
      "x-ess-name": "mandate.tenancy.Space",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.SpaceId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.tenancy.Space",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "display_name": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.tenancy.Space.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "display_name",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.tenancy.Space.State": {
      "title": "State",
      "x-ess-name": "mandate.tenancy.Space.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Retired"
      ]
    },
    "mandate.tenancy.Team": {
      "title": "Team",
      "x-ess-name": "mandate.tenancy.Team",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.TeamId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.tenancy.Team",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "display_name": {
          "type": "string"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.tenancy.Team.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "display_name",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.tenancy.Team.State": {
      "title": "State",
      "x-ess-name": "mandate.tenancy.Team.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Retired"
      ]
    },
    "mandate.tenancy.TeamMembership": {
      "title": "TeamMembership",
      "x-ess-name": "mandate.tenancy.TeamMembership",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.TeamMembershipId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.tenancy.TeamMembership",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "team_id": {
          "$ref": "#/x-ess-entities/mandate.core.TeamId",
          "x-ess-relation": {
            "name": "team_id_record",
            "kind": "references",
            "source": "mandate.tenancy.TeamMembership",
            "target": "mandate.tenancy.Team",
            "cardinality": "one",
            "via": "team_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Team"
          }
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.tenancy.TeamMembership",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.tenancy.TeamMembership.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "team_id",
        "principal_id",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.tenancy.TeamMembership.State": {
      "title": "State",
      "x-ess-name": "mandate.tenancy.TeamMembership.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Removed"
      ]
    },
    "mandate.workload.WorkloadIdentity": {
      "title": "WorkloadIdentity",
      "x-ess-name": "mandate.workload.WorkloadIdentity",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.WorkloadIdentityId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.workload.WorkloadIdentity",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "principal_id": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId",
          "x-ess-relation": {
            "name": "principal_id_record",
            "kind": "references",
            "source": "mandate.workload.WorkloadIdentity",
            "target": "mandate.identity.Principal",
            "cardinality": "one",
            "via": "principal_id",
            "$ref": "#/x-ess-entities/mandate.identity.Principal"
          }
        },
        "trust_domain": {
          "$ref": "#/x-ess-entities/mandate.core.TrustDomain"
        },
        "external_subject": {
          "$ref": "#/x-ess-entities/mandate.core.ExternalSubject"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.workload.WorkloadIdentity.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "principal_id",
        "trust_domain",
        "external_subject",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.workload.WorkloadIdentity.State": {
      "title": "State",
      "x-ess-name": "mandate.workload.WorkloadIdentity.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Revoked"
      ]
    }
  }
}
