> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List the tenant's exclusion operations

> Walks the tenant's own exclusion operation book, oldest claim first.

Exclusion is the product's IRREVERSIBLE operation: once the registry removes the payroll deduction there is no undo, so this queue is the surface an operator watches. The situation that matters most is outcome_unknown: the command was sent and the registry has not yet been observed answering it, which the exclusion recovery loop is still driving.

It answers from a LOCAL table and never reaches the Dataprev rail, so it cannot answer 501 and it is served even on a deployment where exclusion itself is switched off. That deployment simply has an empty book. Distinguishing "the queue is clear" from "the command was never composed" is what GET /v1/consignado/capabilities is for: read the exclusao family there, not the status of this response.

The tenant is derived from the validated identity and is never read from the request. There is no tenant parameter on this operation.

Paging is keyset over the operation's own claim instant and reference, the pair the table holds immutable, so a row's position never moves and a page can neither skip nor repeat. Send the previous page's page.next_after as after. has_more is true exactly when another page exists, and next_after is null exactly when it is false. The cursor never expires; a cursor this service did not mint is refused with 422 rather than silently restarting the scan from the top.

status may be repeated to narrow the page to several situations at once (status=claimed&status=invoking). Omitting it means ALL five situations, never none.

A quarantined row, a legacy operation whose authority could not be hydrated and which no worker converges, is present and MARKED, never filtered out. Hiding it would make an exclusion that happened indistinguishable from one that never did.



## OpenAPI

````yaml /en/openapi/v3-current/consignado.yaml get /v1/consignado/exclusion-operations
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian Consignado — Dataprev. The API covers tenant
    credentials and rail configuration, worker margin, loan auctions and bids,
    contract registration and lifecycle, disbursement confirmation, portability,
    refinancing, renegotiation, FGTS guarantees, reconciliation, funds,
    assignments, usage, throughput, and event subscriptions. Secret material is
    written to the tenant secret store and is never returned by any operation.
  license:
    name: Lerian Studio General License
  title: Lerian Consignado API
  version: v1.0.0
servers:
  - url: https://br-consignado-gw.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Per-tenant Dataprev credential custody and public rail configuration
      (upload, status, rotation, revoke, requester code, and worker portal base
      URL)
    name: Credentials
  - description: >-
      Tenant-scoped consignado gateway usage: priced billable-unit aggregation
      per competência
    name: Consignado Usage
  - description: >-
      Per-tenant streaming-hub subscription control-plane (list, create, get,
      rotate, revoke, and test delivery)
    name: Subscriptions
  - description: >-
      Dataprev payroll-rail surface: FGTS balance and authorization reads, the
      FGTS guarantee execution, contract suspension, reactivation and term
      changes, the rail's own contract documents, and the on-demand reads of
      leilão solicitações, escriturações, repasses and employment terminations
    name: Consignado Rail
  - description: >-
      Synchronous rail command surface: the operations a bancarizador without
      the lender drives over HTTP. Each shares its command implementation with
      the equivalent lender event trigger.
    name: Consignado Rail Commands
  - description: >-
      Gateway-owned disbursement confirmation: a client bank recording money it
      has ALREADY paid to a worker. It crosses no government boundary and
      proxies no Dataprev operation.
    name: Consignado Disbursement
  - description: >-
      Per-tenant self-service outbound Dataprev rail throughput: read and set
      this tenant's own requests-per-second, including a deliberate pause at
      zero
    name: Consignado Throughput
paths:
  /v1/consignado/exclusion-operations:
    get:
      tags:
        - Consignado Exclusion Operations
      summary: List the tenant's exclusion operations
      description: >-
        Walks the tenant's own exclusion operation book, oldest claim first.


        Exclusion is the product's IRREVERSIBLE operation: once the registry
        removes the payroll deduction there is no undo, so this queue is the
        surface an operator watches. The situation that matters most is
        outcome_unknown: the command was sent and the registry has not yet been
        observed answering it, which the exclusion recovery loop is still
        driving.


        It answers from a LOCAL table and never reaches the Dataprev rail, so it
        cannot answer 501 and it is served even on a deployment where exclusion
        itself is switched off. That deployment simply has an empty book.
        Distinguishing "the queue is clear" from "the command was never
        composed" is what GET /v1/consignado/capabilities is for: read the
        exclusao family there, not the status of this response.


        The tenant is derived from the validated identity and is never read from
        the request. There is no tenant parameter on this operation.


        Paging is keyset over the operation's own claim instant and reference,
        the pair the table holds immutable, so a row's position never moves and
        a page can neither skip nor repeat. Send the previous page's
        page.next_after as after. has_more is true exactly when another page
        exists, and next_after is null exactly when it is false. The cursor
        never expires; a cursor this service did not mint is refused with 422
        rather than silently restarting the scan from the top.


        status may be repeated to narrow the page to several situations at once
        (status=claimed&status=invoking). Omitting it means ALL five situations,
        never none.


        A quarantined row, a legacy operation whose authority could not be
        hydrated and which no worker converges, is present and MARKED, never
        filtered out. Hiding it would make an exclusion that happened
        indistinguishable from one that never did.
      operationId: listConsignadoExclusionOperations
      parameters:
        - description: >-
            Narrows the page to the named situations. Repeat the parameter for
            several. Omitted means all five.
          explode: true
          in: query
          name: status
          schema:
            description: >-
              Narrows the page to the named situations. Repeat the parameter for
              several. Omitted means all five.
            items:
              enum:
                - claimed
                - invoking
                - confirmed
                - rejected
                - outcome_unknown
              type: string
            type: array
        - description: >-
            The previous page's page.next_after. Omitted starts at the oldest
            claim. A cursor this service did not mint is refused, never
            restarted from the top.
          explode: false
          in: query
          name: after
          schema:
            description: >-
              The previous page's page.next_after. Omitted starts at the oldest
              claim. A cursor this service did not mint is refused, never
              restarted from the top.
            type: string
        - description: >-
            Maximum number of operations to return. Omitted means the ceiling of
            200.
          explode: false
          in: query
          name: limit
          schema:
            description: >-
              Maximum number of operations to return. Omitted means the ceiling
              of 200.
            format: int64
            maximum: 200
            minimum: 1
            type: integer
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExclusionOperationsPage'
          description: OK
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
      security:
        - BearerAuth: []
components:
  schemas:
    ExclusionOperationsPage:
      additionalProperties: false
      properties:
        items:
          items:
            $ref: '#/components/schemas/ExclusionOperationItem'
          type: array
        page:
          $ref: '#/components/schemas/KeysetPageMetadata'
      required:
        - items
        - page
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ExclusionOperationItem:
      additionalProperties: false
      properties:
        claimed_at:
          format: date-time
          type: string
        evidence_source:
          description: >-
            The proof that terminated the operation. Null while the operation is
            not terminal.
          enum:
            - exclude_response
            - provider_status
            - operator_evidence
            - m005_observation
            - null
          type:
            - string
            - 'null'
        numero_contrato:
          type: string
        outcome_at:
          format: date-time
          type:
            - string
            - 'null'
        provider_message:
          type:
            - string
            - 'null'
        provider_reference:
          type:
            - string
            - 'null'
        quarantined:
          description: >-
            True when the row is a legacy operation whose M003 authority could
            not be hydrated. Such a row is read-only and no worker converges it.
          type: boolean
        reason_code:
          type:
            - string
            - 'null'
        request_ref:
          type: string
        status:
          description: The situation the operation is durably parked in.
          enum:
            - claimed
            - invoking
            - confirmed
            - rejected
            - outcome_unknown
          type: string
        status_check_attempts:
          format: int64
          type: integer
        status_check_next_at:
          format: date-time
          type:
            - string
            - 'null'
      required:
        - request_ref
        - numero_contrato
        - status
        - provider_reference
        - reason_code
        - provider_message
        - evidence_source
        - outcome_at
        - claimed_at
        - status_check_attempts
        - status_check_next_at
        - quarantined
      type: object
    KeysetPageMetadata:
      additionalProperties: false
      properties:
        after:
          description: >-
            The cursor this page resumed from, echoed back. Null when the read
            started at the beginning.
          examples:
            - >-
              eyJ2IjoxLCJyIjoiYm9hcmQiLCJ0IjoiMjAyNi0wOC0xNFQwOToxMjozM1oiLCJrIjpbImMwMDEyIl19
          type:
            - string
            - 'null'
        has_more:
          description: Whether at least one further page exists.
          examples:
            - true
          type: boolean
        next_after:
          description: >-
            The cursor for the page after this one. Null exactly when has_more
            is false.
          examples:
            - >-
              eyJ2IjoxLCJyIjoiYm9hcmQiLCJ0IjoiMjAyNi0wOC0xNFQwOTowNzo1MVoiLCJrIjpbImMwMDM3Il19
          type:
            - string
            - 'null'
      required:
        - after
        - next_after
        - has_more
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````