Connect your systems: the context endpoint

Give GaaS one HTTPS address of your own. When your agent proposes an action, GaaS asks that address for the facts its policies check (is the channel encrypted, is there an active security incident, has the customer consented, what is this agent's spending limit) and decides with them. You answer from your own systems, in one small JSON shape.

Why it matters

Policies decide on facts. When GaaS has no source for a fact, it treats the gap as risk: the context is reported as missing, confidence drops, and a policy that needs the fact to allow an action does not allow it. For example, pol_t1_001 blocks sending payment-card data unless environmental.channel_encryption is true. Your endpoint is how GaaS learns facts only you know.


How it works

WhenDuring every decision for your organization, in live, shadow and test mode, for the categories you chose that matter to the action (below). One request per decision.
What GaaS sendsA signed POST describing the action: agent, action type and verb, target, sensitivity, estimated impact and the context your agent declared. Never the action's free-text summary or content.
What you answerThe facts you know, per category. Every fact is optional; leave out what you don't know.
Time limitOne attempt, within your endpoint's time limit: 1.5 seconds by default, 200 ms to 3 seconds. No retries, and redirects are not followed.
If it failsThe decision still happens. The categories it should have answered count as missing context, which is risk, and the audit record says why (below).

Which categories GaaS asks for

You choose which of the six categories your endpoint answers. For each action GaaS asks only for those that matter to it:

CategoryAsked when
environmentalAlways
entity_stateThe action is transact, access, modify or control
regulatoryThe target is regulated, or the agent declared regulatory domains
organizationalThe action has financial exposure, or the agent is not certified
identityThe action is access, modify or control
securityThe target is not public, or the action has financial exposure

GaaS keeps its own history, behaviour and session-trust context; those categories are not asked for.


Set it up

In the dashboard: Settings → Connected systems. Only an organization admin who signed in with two-factor can change it. Enter the address, choose the categories, and give the secret your endpoint expects, if any (sent as Authorization: Bearer … or in a header you name). GaaS then shows you a signing secret, once: store it, because your endpoint uses it to check that requests come from GaaS. Press Test connection; when every category answers correctly you can switch the endpoint on. Changing the address, categories, secret or time limit switches it off until you test again.

The same with the API (admin key to change, operator or admin key to read):

EndpointWhat it does
GET /v1/context-endpointYour settings. Secrets appear only as their last four characters.
PUT /v1/context-endpointCreate or replace: url, categories, auth_type (none, bearer, header), auth_header_name, auth_secret (write-only; omit to keep), timeout_ms, enabled. The first save returns the signing_secret, once.
POST /v1/context-endpoint/testSends a signed test request ("test": true, "mode": "test") and reports each category. At most 6 a minute.
POST /v1/context-endpoint/rotate-signing-secretA new signing secret, returned once, used from the next request.
DELETE /v1/context-endpointRemove it. Decisions go on without it at once.
Try it in shadow mode first. Send your agent's intents with ?mode=shadow: GaaS calls your endpoint and records what it would decide, without enforcing anything. Compare the verdicts and the audit records before you rely on it in live.

The request

HeaderValue
Content-Typeapplication/json
X-GaaS-Request-IdUnique per request, also in the body as request_id
X-GaaS-TimestampUnix seconds when GaaS signed the request
X-GaaS-Signaturev1= + hex HMAC-SHA256 of <timestamp>.<raw body> with your signing secret
Authorization or your headerThe secret you saved, if any
{
  "contract_version": "1",
  "request_id": "ctxreq_5f0c2a9e41d7b3a8c6e2f190",
  "sent_at": "2026-09-29T15:04:05.123456Z",
  "mode": "live",
  "test": false,
  "categories": [
    "environmental",
    "regulatory"
  ],
  "intent": {
    "id": "8c1e1a4e-3f7a-4d8e-9f10-2b7c5d6e7f80",
    "agent": {
      "id": "billing-agent",
      "name": "Billing agent",
      "framework": "langchain"
    },
    "action": {
      "type": "communicate",
      "verb": "send_email",
      "target": {
        "type": "person",
        "identifier": "cust_42",
        "sensitivity": "confidential",
        "jurisdiction": "US-CA"
      },
      "estimated_impact": {
        "reversible": true,
        "financial_exposure_usd": 0,
        "audience_size": 1,
        "data_categories": [
          "PCI"
        ],
        "regulatory_domains": [
          "PCI-DSS"
        ]
      }
    },
    "context_provided": {
      "session_id": "sess_19",
      "user_state": null,
      "environment": {
        "channel": "email"
      }
    }
  }
}

Full schema: context-endpoint-request.v1.json.

Verify the signature

Check every request before you answer it. Reject a timestamp more than five minutes from your clock, so a recorded request cannot be replayed. Python, standard library only:

import hashlib, hmac, time

def verify(secret: str, headers: dict, body: bytes) -> bool:
    """True only if GaaS signed this exact body within the last five minutes."""
    lower = {k.lower(): v for k, v in headers.items()}
    timestamp = lower.get("x-gaas-timestamp", "")
    signature = lower.get("x-gaas-signature", "")
    if not timestamp.isdigit() or abs(time.time() - int(timestamp)) > 300:
        return False
    expected = "v1=" + hmac.new(secret.encode(), timestamp.encode() + b"." + body, hashlib.sha256).hexdigest()
    return hmac.compare_digest(expected, signature)

The response

Answer 200 with Content-Type: application/json:

{
  "contract_version": "1",
  "facts": {
    "environmental": {
      "channel_encryption": true,
      "tls_version": "1.3",
      "protocol": "https"
    },
    "regulatory": {
      "applicable_frameworks": {
        "PCI-DSS": {
          "level": 1
        }
      },
      "cardholder_data_environment": false
    }
  },
  "as_of": {
    "environmental": "2026-09-29T15:04:00Z",
    "regulatory": "2026-09-29T00:00:00Z"
  }
}

Full schema: context-endpoint-response.v1.json.

The facts GaaS's policies read

This is every fact a built-in policy checks. Supply the ones you can; a policy that does not get the fact it needs treats it as missing.

CategoryFactTypeMeaning
environmentalchannel_encryptionbooleanThe channel the action uses is encrypted end to end.
environmentaltls_versionstring or numberTLS version of that channel, e.g. "1.3".
environmentalprotocolstringTransport protocol, e.g. "https", "sftp", "ftp".
environmentalnetwork_segmentstringNetwork segment the target sits in, e.g. "cde", "internal", "public".
environmentalglobal_privacy_controlbooleanThe consumer sent a Global Privacy Control signal.
environmentalcommunication_channelstringChannel for an outbound communication: "voice", "sms", "email", ….
environmentalcommunication_methodstringHow it is placed, e.g. "autodialer", "prerecorded", "ai_voice", "manual".
environmentalrecipient_local_hourintegerRecipient's local hour, 0–23.
environmentalrecipient_statestringRecipient's US state, two letters, e.g. "FL".
environmentalai_voice_detectedbooleanThe call uses an AI-generated voice.
environmentalai_voice_disclosureboolean or stringThe call discloses that the voice is AI-generated.
environmentalboundary_crossing_approvedbooleanData leaving the FedRAMP authorization boundary is approved.
environmentalencryption_standardstringEncryption module standard, e.g. "fips_140_3".
environmentaltransport_securitystringTransport security for CUI, e.g. "tls_1_3", "fips_validated".
entity_stateaccount_balance_usdnumberCurrent balance of the account the action touches, in USD.
entity_stateaccount_statusstringStatus of that account, e.g. "active", "frozen", "closed".
regulatoryapplicable_frameworksobjectFrameworks that apply, keyed by domain, e.g. {"PCI-DSS": {...}}.
regulatorygdpr_consentobjectThe data subject's GDPR consent record.
status: "active" | "withdrawn" | …
regulatoryhipaa_access_purposestringHIPAA purpose of the access: "treatment", "payment", "operations", "research", ….
regulatorypatient_authorizationbooleanA documented patient authorization covers this use.
regulatoryminimum_necessary_overridestring or booleanDocumented reason to override minimum necessary (e.g. emergency care).
regulatorypatient_access_requestobjectA patient's right-of-access request being answered.
response_deadline_days: number, extension_granted: boolean, elapsed_days: number, denial: boolean, denial_reason: string
regulatorycardholder_data_environmentbooleanThe target is inside the cardholder data environment.
regulatoryccpa_opt_outobjectThe consumer's CCPA sale/share opt-out.
status: "opted_out" | …
regulatoryconsumer_agenumberThe consumer's age in years.
regulatoryccpa_minor_opt_inobjectOpt-in for a consumer under 16.
status: "active" | …, consent_source: "parent_guardian" | "self"
regulatorygpc_override_consentobjectConsent that overrides a Global Privacy Control signal.
status: "active" | …
regulatoryferpa_record_typestringKind of education record, e.g. "grades", "directory_information".
regulatoryferpa_consentobjectWritten consent to disclose the education record.
status: "active" | …
regulatoryferpa_disclosure_purposestringFERPA exception relied on, e.g. "school_official", "judicial_order".
regulatoryferpa_directory_opt_outbooleanThe student opted out of directory-information disclosure.
regulatorysox_scopeobjectThe action is in SOX scope.
action: "approve" | "certify" | …, initiated_by: string, reporting_period: string, control_override: boolean
regulatorytcpaobjectTCPA context, when kept together.
communication_channel: string, tcpa_consent: object (as tcpa_consent)
regulatorytcpa_consentobjectThe recipient's TCPA consent record.
status: "active" | "revoked" | …, consent_type: "prior_express_written" | "prior_express" | "oral" | …, consent_form_valid: boolean, pewc_elements: object, revocation_requested_at: ISO 8601 string, revocation_processed_at: ISO 8601 string
regulatorydnc_registry_statusstringNational Do Not Call status of the number, e.g. "listed", "not_listed".
regulatoryestablished_business_relationshipobjectAn established business relationship with the recipient.
status: string, last_transaction_date: ISO 8601 date, last_inquiry_date: ISO 8601 date
regulatorydnc_last_scrub_datestringWhen the list was last scrubbed against the DNC registry (ISO 8601 date).
regulatoryinternal_dnc_listedbooleanThe number is on your own do-not-call list.
regulatoryrevocation_sla_exceededbooleanA consent revocation was not processed within its deadline.
regulatoryrevocation_business_days_elapsednumberBusiness days since the revocation request.
regulatoryai_voice_detectedbooleanThe call uses an AI-generated voice.
regulatoryai_voice_disclosureboolean or stringThe call discloses that the voice is AI-generated.
regulatoryrecipient_statestringRecipient's US state, two letters.
organizationaldelegation_limit_usdnumberThe most this agent may commit on its own, in USD.
organizationalgdpr_legal_basisstringGDPR Article 6 basis, e.g. "contract", "legitimate_interest".
organizationallegitimate_interest_assessmentstring or boolean or objectA documented legitimate-interest assessment.
organizationalphi_access_scopestring or arrayThe documented scope of PHI this agent may access.
organizationalbulk_access_justificationstringWhy bulk access to PHI is needed.
organizationalssl_certificate_validbooleanThe target's TLS certificate is valid.
organizationalcertificate_expiry_daysnumberDays until that certificate expires.
organizationalpci_network_segmentationstring"compliant" or "non_compliant".
organizationallegitimate_educational_interestbooleanThe requester has a legitimate educational interest.
organizationalferpa_annual_notice_issuedbooleanThe annual FERPA directory-information notice was issued.
organizationalsox_audit_trailobjectAudit trail for SOX-relevant actions.
status: "active" | …
organizationalsox_management_certificationobjectManagement certification.
period: string, status: "certified" | …
organizationalsox_override_authorizationobjectAuthorization for a SOX control override.
status: "approved" | …
organizationalrisk_management_systemstring or booleanAn AI risk-management system is in place (EU AI Act Art. 9).
organizationalrisk_framework_refstringReference to that risk framework.
organizationaltraining_data_lineagestring or boolean or objectTraining-data lineage is documented (Art. 10).
organizationaldata_sheetstring or objectA data sheet for the model's data (Art. 10).
organizationalexplainability_enabledbooleanThe agent's decisions can be explained (Art. 13).
organizationalexplanation_methodstringHow they are explained.
organizationalasset_inventory_refstringReference to the asset inventory entry (NIST CSF ID.AM).
organizationalsystem_asset_idstringThe system's asset ID.
organizationalincident_response_plan_refstringReference to the incident response plan.
organizationalincident_report_refstringReference to the incident report (NIST 800-53 IR-6).
organizationalato_statusstringFedRAMP Authority to Operate: "authorized", "in_process", "not_started".
organizationalsupply_chain_assessment_refstringReference to the supply-chain risk assessment.
organizationalcui_handling_procedures_refstringReference to CUI handling procedures (CMMC).
organizationalconfiguration_baseline_refstringReference to the configuration baseline.
organizationalchange_management_ticketstringChange ticket covering this change.
organizationalmonitoring_enabledbooleanContinuous monitoring is enabled for the system.
organizationaltelemetry_endpointstringWhere the system's telemetry goes.
identityauthenticated_agent_idstringThe agent identity your identity provider authenticated.
identityaccount_statusstringStatus of the agent's account, e.g. "active", "provisioned", "suspended".
identitylast_account_review_daysnumberDays since the agent's access was last reviewed.
identityassigned_permissionsarrayPermissions assigned to the agent.
identitydelegation_limit_usdnumberThe agent's delegation limit, in USD.
identityrecovery_authorizationbooleanThe agent is authorized to run recovery actions.
identityclearance_statusstringClearance for CUI, e.g. "cleared", "uncleared".
identityclearance_verifiedbooleanThe clearance was verified.
securityprivilege_escalation_alertbooleanYour security tooling raised a privilege-escalation alert for this agent.
securityprompt_injection_detectedbooleanA prompt injection was detected in this agent's inputs.
securityactive_security_incidentbooleanAn active security incident affects the target or agent.
securitysiem_refstringWhere this system's events go in your SIEM.

Reserved. GaaS sets these itself; a value from your endpoint is dropped and flagged reserved_key_ignored:


In the audit record

Every decision's audit record shows your endpoint as one source per category, customer_endpoint_<category>, in stage_2_enrichment.sources_queried, with its status and latency. A category that failed is also in sources_failed, and missing_context gives the reason, for example Source customer_endpoint_environmental returned status timed_out (timeout).

ReasonMeaning
timeoutNo answer within the time limit
http_error, redirectA status other than 200 (redirects are not followed)
invalid_response, contract_version_mismatch, too_largeThe answer is not this contract's JSON, or is over 256 KB
category_missing, invalid_fact:<key>, invalid_key, too_deep:<key>, too_many_keysThat category was absent or broke a rule above
connect_error, ssrf_blockedGaaS could not connect, or the address resolved to a private or internal network
circuit_openFive calls in a row failed, so GaaS pauses calls for 30 seconds
concurrency_limitedToo many calls to your endpoint were already in flight
secret_unavailableGaaS could not open the saved secrets; the call was not made

Security