> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Record a reviewer action intent on a Praxis Shield incident

> Appends an INTENT-ONLY reviewer action to the incident (recorded for audit but never executed by the institution panel — `metadata.intentOnly` is forced true). Mounted under the admin gate (isAdmin) and RAP-scoped via the `institutions.edit` entitlement (super bypasses): the caller must manage at least one of the incident's institutions.




## OpenAPI

````yaml /mdx/api-reference/admin/admin-api.json post /api/admin/security/threats/{incidentId}/actions
openapi: 3.0.0
info:
  title: Pria Admin API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Admin Memory
    description: Admin inspection and editing of user/instance memory parameters.
  - name: Admin Usage Limits
    description: Per-user usage-vs-cap reporting and account-wide at-limit counts.
paths:
  /api/admin/security/threats/{incidentId}/actions:
    post:
      tags:
        - Admin
        - Security
      summary: Record a reviewer action intent on a Praxis Shield incident
      description: >
        Appends an INTENT-ONLY reviewer action to the incident (recorded for
        audit but never executed by the institution panel —
        `metadata.intentOnly` is forced true). Mounted under the admin gate
        (isAdmin) and RAP-scoped via the `institutions.edit` entitlement (super
        bypasses): the caller must manage at least one of the incident's
        institutions.
      parameters:
        - in: path
          name: incidentId
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - action
              properties:
                action:
                  type: string
                  description: Action identifier (trimmed; required non-empty)
                metadata:
                  type: object
                  description: Optional structured metadata (intentOnly forced true)
      responses:
        '200':
          description: The updated incident
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  incident:
                    $ref: '#/components/schemas/ThreatIncidentFull'
        '400':
          description: Invalid incidentId or missing action
        '403':
          description: Not authorized for any of the incident institutions
        '404':
          description: Incident not found
        '500':
          description: Server error
      security:
        - apiKeyAuth: []
components:
  schemas:
    ThreatIncidentFull:
      type: object
      description: >
        Full incident document INCLUDING `evidence` and `llmAssessments`, plus
        resolved `institutions`/user name fields. Evidence and LLM-assessment
        text is attacker-influenced and MUST be rendered INERT by the client.
      properties:
        _id:
          type: string
        status:
          type: string
          enum:
            - open
            - reviewing
            - resolved
            - false_positive
            - escalated
        severity:
          type: integer
          minimum: 0
          maximum: 4
        categories:
          type: array
          items:
            type: string
        title:
          type: string
        summary:
          type: string
        user:
          type: string
        userEmail:
          type: string
        userFname:
          type: string
        userLname:
          type: string
        institutionIds:
          type: array
          items:
            type: string
        institutions:
          type: array
          items:
            type: object
            properties:
              _id:
                type: string
              name:
                type: string
        evidence:
          type: array
          description: >-
            Evidence subdocuments (history references + extracted signals).
            Inert.
          items:
            type: object
        llmAssessments:
          type: array
          description: Per-run LLM assessment records (rationale text). Inert.
          items:
            type: object
        reviewerNotes:
          type: array
          items:
            type: object
            properties:
              author:
                type: string
              note:
                type: string
              createdAt:
                type: string
                format: date-time
        reviewerActions:
          type: array
          items:
            type: object
            properties:
              author:
                type: string
              action:
                type: string
              metadata:
                type: object
              createdAt:
                type: string
                format: date-time
        firstSeenAt:
          type: string
          format: date-time
        lastSeenAt:
          type: string
          format: date-time
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-access-token
      description: JWT token passed in x-access-token header

````