Strengthen Controls
strengthen_controlsStrengthens a threat model's controls by addressing objectives whose mitigation groups leave them uncovered. Estimates credit cost, then starts a background run upon confirmation.
Instructions
Strengthen a model's controls: work on the objectives whose mitigation
groups the background judge found do not cover them (the uncovered
and undecided of get_control_generation_status's diagnosis).
Mutating only with confirm_estimate=True; consumes credits then.
not_judged objectives have nothing to strengthen from: judge them
first with judge_objectives.
Call with
confirm_estimate=False(the default): nothing starts or is charged; the answer carriesdiagnosis,scope,estimate(credits,per_objective,basis) and themodel_version/set_revisionthe model stands at. Show the user the estimate.Once they agree, call with
confirm_estimate=Trueand those two values (their review of the model as it stood). A background run starts (started: true); pollget_control_generation_status. It holds the model like any build: pausable, resumable, discardable.
A gap only the environment can close (hosting, a third party) is never
answered with a control: an accepted assumption stating it is bound
into the group; otherwise an assumption proposal waits in the
review queue (get_review_queue / decide_proposal) and the objective
counts as awaiting_assumption. A rejected one is not proposed again.
Refusals come back as data, {started: false, http_status, code}:
409 review_stale (the model or its controls changed since the
estimate: confirm again with the values returned), 409
generation_active (a build holds the model), 402 (the balance cannot
cover the estimate).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| co_ids | No | Optional comma-separated objective IDs, of those diagnosed uncovered or undecided; omit for all. | |
| model_id | Yes | ID of the threat model. | |
| set_revision | No | With ``confirm_estimate=True``: the estimate's value. | |
| model_version | No | With ``confirm_estimate=True``: the estimate's value. | |
| server_version | Yes | ||
| confirm_estimate | No | False (default) estimates; True starts the run. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||