> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List the decision audit

> Cursor-paginated audit of every permission decision ever taken on this host — by a human or by policy, including denials during unattended work. Every decision is recorded and reviewable afterwards.



## OpenAPI

````yaml /en/openapi/v3-current/narya.yaml get /v1/permissions/decisions
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    runs on your machine and serves this API over a Unix socket in your Narya
    home. Narya creates the socket owner-only, and file permissions are the
    whole authorization. There is no password, no token and no TLS. The terminal
    client and the one-shot command that Lerian ships drive this API, and a
    client you write drives the same one.


    Results never arrive on the response of the request that caused them.
    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title, message, and fields on 422. Codes are NRY-
    followed by four digits. A paged list answers items, limit and a nextCursor
    when more remains. Cursors are opaque.
servers: []
security: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
paths:
  /v1/permissions/decisions:
    get:
      tags:
        - permissions
      summary: List the decision audit
      description: >-
        Cursor-paginated audit of every permission decision ever taken on this
        host — by a human or by policy, including denials during unattended
        work. Every decision is recorded and reviewable afterwards.
      operationId: listPermissionDecisions
      parameters:
        - $ref: '#/components/parameters/CursorParam'
        - $ref: '#/components/parameters/LimitParam'
        - name: sessionId
          in: query
          required: false
          description: Filter to decisions taken in one session.
          schema:
            type: string
            format: uuid
        - name: decision
          in: query
          required: false
          description: >-
            Filter to one outcome. `deny` is the audit's own question — what was
            refused, and why — and `expired` is the finding when somebody asks
            why an action did not happen and the answer is that nobody answered.
          schema:
            type: string
            enum:
              - allow
              - deny
              - expired
        - name: since
          in: query
          required: false
          description: >-
            Only decisions whose `requestedAt` is at or after this instant. It
            is the half of "what was denied last week and why" that the
            `decision` filter alone cannot answer: without it an operator pages
            backwards from now until `requestedAt` drops out of the window they
            care about, which is a paging exercise rather than one call. Served
            off the same index as the cursor.
          schema:
            type: string
            format: date-time
        - name: until
          in: query
          required: false
          description: >-
            Only decisions whose `requestedAt` is at or before this instant.
            Combines with `since` to bound a window from both ends; either may
            be given alone. A window whose `until` precedes its `since` is a
            malformed request rather than an empty page, because an empty page
            reads as "nothing was denied".
          schema:
            type: string
            format: date-time
      responses:
        '200':
          description: One page of decision records.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PermissionDecisionPage'
        '400':
          $ref: '#/components/responses/BadRequest'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    CursorParam:
      name: cursor
      in: query
      required: false
      description: >-
        Opaque pagination cursor from a previous page's nextCursor or
        prevCursor.
      schema:
        type: string
        maxLength: 1024
    LimitParam:
      name: limit
      in: query
      required: false
      description: Maximum items per page.
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 25
  schemas:
    PermissionDecisionPage:
      type: object
      description: One page of the decision audit.
      required:
        - items
        - limit
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/PermissionDecisionRecord'
        limit:
          type: integer
          minimum: 1
        nextCursor:
          type: string
        prevCursor:
          type: string
      examples:
        - items:
            - id: 3f1e5d7c-2b4a-4c6e-8d0f-9a1b3c5d7e9f
              permissionId: 7e5d3c1b-9a8f-4e6d-b2c4-0f1a3b5c7d9e
              decision: deny
              decidedBy: user
              requestedAt: '2026-08-08T12:20:58.000Z'
              decidedAt: '2026-08-08T12:21:00.000Z'
          limit: 25
    PermissionDecisionRecord:
      type: object
      description: >-
        One entry of the decision audit. There is exactly one decision per ask,
        so the decision's id IS the ask's id: id and permissionId carry the same
        identifier.


        WHAT IS RECORDED, stated here because it is narrower than "every
        decision" and deliberately so: every ASK and its answer, whoever
        answered it, and every DENY — including the ones taken without asking
        anybody, which is the shape almost every denial has in unattended work.
        A rule-derived ALLOW on a free action is NOT a row. Recording every
        permitted read would write thousands of rows per session and bury the
        two questions this audit exists to answer — what was denied and why, and
        what did I approve.


        AND A DECISION IS NOT A RECORD OF EXECUTION. It says what was decided,
        not what ran: a call interrupted in the same instant its decision was
        released can leave an `allow` here for something that never happened.
        Read it as the trail of judgements, and the transcript for what
        followed.
      required:
        - id
        - permissionId
        - decision
        - requestedAt
      properties:
        id:
          type: string
          format: uuid
        permissionId:
          type: string
          format: uuid
        sessionId:
          type: string
          format: uuid
        action:
          type: string
          maxLength: 128
        resource:
          type: string
          maxLength: 4096
        decision:
          type: string
          enum:
            - allow
            - deny
            - expired
          description: >-
            `expired` is an ask nobody answered before the call it was blocking
            ended. It carries no decider and no decidedAt, because "nobody
            answered" is itself the finding when somebody asks why an action did
            not happen.
        decidedBy:
          type: string
          enum:
            - user
            - policy
            - hook
          description: >-
            Who decided — a human, the policy deciding without asking (which
            includes a rule that landed after the ask was raised and covered
            it), or the configured executable at the permission-ask decision
            point. Absent on an expired entry.
        reason:
          type: string
          maxLength: 4096
          description: >-
            Why, in the decider's own words: a person's message on a
            deny-with-message, the rule a policy refusal names, or the hook that
            decided — a hook denial that does not say which hook is an audit
            trail ending in a shrug. Absent when the outcome speaks for itself.
        remember:
          type: string
          enum:
            - none
            - session
            - project
            - global
        requestedAt:
          type: string
          format: date-time
          description: >-
            When the decision was raised. It is what the audit is ordered and
            paged by, so a page boundary is stable while new decisions land.
        decidedAt:
          type: string
          format: date-time
          description: Absent on an expired entry, which nobody decided.
      examples:
        - id: 3f1e5d7c-2b4a-4c6e-8d0f-9a1b3c5d7e9f
          permissionId: 7e5d3c1b-9a8f-4e6d-b2c4-0f1a3b5c7d9e
          sessionId: 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d
          action: shell
          resource: git push origin main
          decision: deny
          decidedBy: user
          reason: do not push to main, open a PR branch instead
          remember: none
          requestedAt: '2026-08-08T12:20:58.000Z'
          decidedAt: '2026-08-08T12:21:00.000Z'
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension. fields appears only on 422 validation errors,
        mapping each offending property to its problem.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems. Present on 422 only.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.
  responses:
    BadRequest:
      description: Malformed request — invalid parameter, cursor, or JSON body.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'

````