Retry pending source preservation acknowledgments from the actual retained hold/release instructions
/bank-records/controls/{control}/repairDedicated records:bank staff authority and step-up within five minutes required; customers, services, API keys and third parties refuse. Source retention mappings, release, retention events, disposition and dispose_versions (removal of an unheld inventory source's retained row versions superseded through a nonfuture time, carried to the source by the repair route and worker only while no hub hold covers that source) need independent approval. Holds take effect immediately for existing/future archived facts and stay pending at each source until actual acknowledgment. An attachment the source or hub verification refuses for good, or that staff declare unretrievable after exhausted transport fetches, is recorded as a capture failure rather than blocking the ingest. Ingestion uses dedicated service connections and retained exact source snapshots/pages; users cannot upload or assert source contents. Discovery freezes complete membership and hashes with the requesting staff subject/purpose; every read is audited before release. Full external referenced documents remain outside explicit metadata projection coverage.
Path parameters
controlstringRequiredHeaders
Idempotency-KeystringOptionalSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
afterintegerRequiredpurposestringRequiredReturns
200 OK
actorstringRequiredcreated_atstring · date-timeRequireddecided_atstring · date-time or nullOptionaldecided_bystringOptionalidstringRequiredpreservationarray of objectsRequired6 child attributes
decisionstringRequiredlast_attempt_atstring · date-time or nullOptionalreceiptobject or nullOptional5 child attributes
enforcementstringRequiredrecorded_atstring · date-timeRequiredrequestobjectRequired8 child attributes
command_idstringRequireddecisionstringRequiredevidence_sha256stringRequiredmatter_idstringRequiredon_behalf_ofstringRequiredpurposestringRequiredsourcestringRequiredversionintegerRequiredrequest_sha256stringRequiredservicestringRequiredstatusstringRequiredtargetobjectRequired2 child attributes
servicestringRequiredsourcestringRequiredversionintegerRequiredrequestobjectRequired13 child attributes
bank_widebooleanRequiredcategorystringOptionalevent_atstring · date-time or nullOptionalevidence_refstringRequiredevidence_sha256stringRequiredexpected_versionintegerOptionalhold_idstringOptionalExample hold_2tVh8nqLxq4GbDe0K1F6S9zRcWm
kindstringRequiredmatter_refstringRequiredreasonstringRequiredrecord_idstringOptionaltargetobjectRequired2 child attributes
servicestringRequiredsourcestringRequiredthroughstring · date-time or nullOptionalThrough bounds a dispose_versions control: the source removes its retained row versions superseded on or before this time, once the control is independently approved and no archive hold covers the source.
statusstringRequiredversionintegerRequiredversion_dispositionobject or nullOptionalVersionDisposition is the source's receipt for an approved dispose_versions control; until it is recorded the approved control is still to be propagated.
5 child attributes
deletedintegerRequiredrecorded_atstring · date-timeRequiredrequestobjectRequiredVersionDispositionRequest is the hub's independently approved instruction to remove an inventory source's retained row versions superseded on or before Through. It applies only to a source under no acknowledged preservation; the archive keeps what it captured.
7 child attributes
command_idstringRequiredevidence_sha256stringRequiredmatter_idstringRequiredon_behalf_ofstringRequiredpurposestringRequiredsourcestringRequiredthroughstring · date-timeRequiredrequest_sha256stringRequiredservicestringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503