> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Get one exclusion operation's audit trail

> Returns ONE exclusion operation's append-only transition trail, oldest first.

The trail is keyed by the operation's own request_ref rather than by contract number, because the trail belongs to the OPERATION: a contract excluded more than once has more than one trail, and keying by contract would need a resolution step free to answer with the wrong one.

The tenant is derived from the validated identity: an operation that does not exist and an operation belonging to another tenant are the SAME answer, 404, so this read cannot be used to probe another tenant's book.

evidence is handed back as the JSON document the writer stored, byte for byte, and its shape varies by event_type. It is deliberately not re-encoded: a trail exists to hold proof, and a server that rewrites proof cannot settle the argument the trail was kept for.

The trail is not paginated. It is capped at 200 entries and the cut is STATED through truncated rather than swallowed, because a silent cut reads as a complete history. A quarantined operation's trail is served like any other: it is exactly the evidence an operator has about a row nothing will converge.



## OpenAPI

````yaml /en/openapi/v3-current/consignado.yaml get /v1/consignado/exclusion-operations/{request_ref}/audit
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian Consignado — Dataprev. The API covers tenant
    credentials and rail configuration, worker margin, loan auctions and bids,
    contract registration and lifecycle, disbursement confirmation, portability,
    refinancing, renegotiation, FGTS guarantees, reconciliation, funds,
    assignments, usage, throughput, and event subscriptions. Secret material is
    written to the tenant secret store and is never returned by any operation.
  license:
    name: Lerian Studio General License
  title: Lerian Consignado API
  version: v1.0.0
servers:
  - url: https://br-consignado-gw.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Per-tenant Dataprev credential custody and public rail configuration
      (upload, status, rotation, revoke, requester code, and worker portal base
      URL)
    name: Credentials
  - description: >-
      Tenant-scoped consignado gateway usage: priced billable-unit aggregation
      per competência
    name: Consignado Usage
  - description: >-
      Per-tenant streaming-hub subscription control-plane (list, create, get,
      rotate, revoke, and test delivery)
    name: Subscriptions
  - description: >-
      Dataprev payroll-rail surface: FGTS balance and authorization reads, the
      FGTS guarantee execution, contract suspension, reactivation and term
      changes, the rail's own contract documents, and the on-demand reads of
      leilão solicitações, escriturações, repasses and employment terminations
    name: Consignado Rail
  - description: >-
      Synchronous rail command surface: the operations a bancarizador without
      the lender drives over HTTP. Each shares its command implementation with
      the equivalent lender event trigger.
    name: Consignado Rail Commands
  - description: >-
      Gateway-owned disbursement confirmation: a client bank recording money it
      has ALREADY paid to a worker. It crosses no government boundary and
      proxies no Dataprev operation.
    name: Consignado Disbursement
  - description: >-
      Per-tenant self-service outbound Dataprev rail throughput: read and set
      this tenant's own requests-per-second, including a deliberate pause at
      zero
    name: Consignado Throughput
paths:
  /v1/consignado/exclusion-operations/{request_ref}/audit:
    get:
      tags:
        - Consignado Exclusion Operations
      summary: Get one exclusion operation's audit trail
      description: >-
        Returns ONE exclusion operation's append-only transition trail, oldest
        first.


        The trail is keyed by the operation's own request_ref rather than by
        contract number, because the trail belongs to the OPERATION: a contract
        excluded more than once has more than one trail, and keying by contract
        would need a resolution step free to answer with the wrong one.


        The tenant is derived from the validated identity: an operation that
        does not exist and an operation belonging to another tenant are the SAME
        answer, 404, so this read cannot be used to probe another tenant's book.


        evidence is handed back as the JSON document the writer stored, byte for
        byte, and its shape varies by event_type. It is deliberately not
        re-encoded: a trail exists to hold proof, and a server that rewrites
        proof cannot settle the argument the trail was kept for.


        The trail is not paginated. It is capped at 200 entries and the cut is
        STATED through truncated rather than swallowed, because a silent cut
        reads as a complete history. A quarantined operation's trail is served
        like any other: it is exactly the evidence an operator has about a row
        nothing will converge.
      operationId: getConsignadoExclusionOperationAudit
      parameters:
        - description: >-
            The exclusion operation's own reference, exactly as the list
            returned it.
          in: path
          name: request_ref
          required: true
          schema:
            description: >-
              The exclusion operation's own reference, exactly as the list
              returned it.
            maxLength: 128
            minLength: 1
            pattern: ^[A-Za-z0-9._-]{1,128}$
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExclusionAuditTrail'
          description: OK
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Not Found
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
      security:
        - BearerAuth: []
components:
  schemas:
    ExclusionAuditTrail:
      additionalProperties: false
      properties:
        entries:
          items:
            $ref: '#/components/schemas/ExclusionAuditEntry'
          type: array
        truncated:
          description: >-
            True when the trail reached the entry ceiling and older transitions
            were not returned.
          type: boolean
      required:
        - entries
        - truncated
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ExclusionAuditEntry:
      additionalProperties: false
      properties:
        event_type:
          type: string
        evidence:
          description: >-
            The evidence document exactly as it was written. Its shape varies by
            event_type.
        from_status:
          type:
            - string
            - 'null'
        occurred_at:
          format: date-time
          type: string
        to_status:
          enum:
            - claimed
            - invoking
            - confirmed
            - rejected
            - outcome_unknown
          type: string
      required:
        - from_status
        - to_status
        - event_type
        - occurred_at
        - evidence
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````