List the questions waiting on a person
The questions the agent has asked and nobody has answered yet — the recovery road for a client that was not attached when question-asked went out.
It is the road listPermissions already is for the other kind of ask, and it exists for the same reason: a question is durable state on the host and the event announcing it is long past by the time a client attaches, which reads the transcript and then subscribes after the position that read returned. A question is not a transcript entry, so a client with no retained event cursor has nothing else to reconstruct it from.
ONLY PENDING QUESTIONS, and there is no status filter. An answered question is retired by tool-call-finished for the call it was blocking, and the decision audit never carries a question, so the only thing there is to list is what somebody still has to answer.
Authorizations
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Query Parameters
Opaque pagination cursor from a previous page's nextCursor or prevCursor.
1024Maximum items per page.
1 <= x <= 100Filter to the questions standing on one conversation, which is what a client attaching to a session asks for.

