Import Compliance Framework
import_compliance_frameworkImport custom compliance frameworks when built-in options don't cover a customer's regulatory, contractual, or internal program; after import, select it on threat models like built-in frameworks.
Instructions
Import a custom compliance framework. Requires PRO tier.
Use this when your customer's program (regulatory, contractual, or internal) is not covered by Mipiti's built-in frameworks. After import, the framework is selectable on threat models exactly like a built-in.
Fields: name (required), version, description,
requirements (required, non-empty), level_definitions.
Each requirement takes id and description (required), level
(integer, default 1), the optional grouping chapter_id /
chapter_name / section_id / section_name / title,
scope (component, the default, or system: covered if ANY
model satisfies it) and level_specific_text (per-level text).
level_definitions and level_specific_text are keyed by the
level as a string integer ("1", "2"): the key is the ordinal the
level <= target_level filter compares, so a non-integer key is
refused (400). Labels ("Baseline", "SL3") go in each value's name.
A level value is {"name", "description", "source"}, where source
is authoritative (paraphrased from the published standard) or
mipiti_convention (tiers you defined).
Example::
{
"name": "ACME Tiered",
"level_definitions": {
"1": {"name": "Baseline", "description": "Minimum.",
"source": "mipiti_convention"}
},
"requirements": [
{"id": "ACME-PWD", "description": "Passwords meet policy",
"level": 1, "level_specific_text": {"1": "Min 8 characters."}}
]
}Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| framework_json | Yes | The framework body as a JSON string. | |
| server_version | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||