# Oleria Identity Security - [Oleria Identity Security](https://docs.oleria.ai/introduction/overview.md): The AI-native identity intelligence layer for speed, scale, and security. - [Oleria AI](https://docs.oleria.ai/posture/oleria-ai.md): Ask questions about your identity security posture in natural language and get immediate, context-specific answers from Oleria AI. - [Oleria MCP](https://docs.oleria.ai/introduction/oleria-mcp.md): Connect Claude, ChatGPT, or any MCP-compatible AI client to your Oleria workspace, and ask questions about your identity and access data without leaving that client. - [Adaptive Security](https://docs.oleria.ai/posture/oleria-adaptive-security-overview.md): Understand how Oleria gives you centralized visibility and control over identity and access across all your SaaS and IAM systems. - [Risk Monitoring](https://docs.oleria.ai/posture/risk-monitoring-overview.md): Track identity and access risks across your connected applications in real time, with SLA visibility, detailed context per risk, and remediation actions. - [Access Graph](https://docs.oleria.ai/posture/access-graph-overview.md): Visualize who has access to what across your entire environment, trace how that access was granted, and identify and remediate over-privileged accounts. - [Read the Access Graph](https://docs.oleria.ai/posture/explore-access-graph.md): Understand the nodes, edges, node details, activity overlay, and Entitlement Graph that make up the Access Graph. - [Navigate and search the Access Graph](https://docs.oleria.ai/posture/navigate-access-graph.md): Search the Access Graph to find a starting point, then trace access paths from an account to its resources or from a resource back to every account that can reach it. - [Activity Analysis](https://docs.oleria.ai/posture/activity-analysis-overview.md): Monitor account activity across your integrated applications to detect suspicious behavior, investigate incidents, and respond faster. - [Activity dashboard](https://docs.oleria.ai/posture/activity-dashboard.md) - [Activity details](https://docs.oleria.ai/posture/activity-details.md) - [Access Inventory](https://docs.oleria.ai/posture/access-inventory-overview.md): Consolidate identity data from all your connected platforms into a single, searchable view of who has access to what. - [Using Access Inventory](https://docs.oleria.ai/posture/learn-access-inventory.md) - [Overview](https://docs.oleria.ai/posture/workflows-overview.md): Automate recurring identity and access actions with configurable triggers, conditions, and approval steps, built from a template or from scratch. - [Workflow templates](https://docs.oleria.ai/posture/workflow-templates.md): A library of ready-made workflow templates for common identity and access automation. - [Disable dormant accounts](https://docs.oleria.ai/posture/disable-dormant-accounts-workflow.md): Automatically find accounts inactive beyond a set threshold and disable them, with a required manager approval step first. - [Security insights email](https://docs.oleria.ai/posture/security-insights-email-workflow.md): Deliver a recurring summary of security and activity insights to stakeholders on a schedule. - [Enforce MFA compliance](https://docs.oleria.ai/posture/enforce-mfa-compliance-workflow.md): Detect users missing multi-factor authentication (MFA) on configured apps, escalate to their manager, and notify. - [Manage stale SharePoint sites](https://docs.oleria.ai/posture/manage-stale-sharepoint-sites-workflow.md): Identify SharePoint sites with low activity, route them to site owners for approval, and act on the outcome. - [NHI ownership assignment](https://docs.oleria.ai/posture/nhi-ownership-assignment-workflow.md): Continuously discover unowned non-human identities (NHIs), assign an owner, and optionally route the assignment to a reviewer before applying it. - [Detect and report Shadow IT](https://docs.oleria.ai/posture/detect-report-shadow-it-workflow.md): Identify newly detected shadow IT applications and create incident tickets in your connected ITSM tool automatically. - [Access Requests](https://docs.oleria.ai/governance/access-requests.md): Let employees request access to applications and groups, route each request through an approval chain, and grant access automatically once it's approved. - [Access Reviews](https://docs.oleria.ai/governance/access-review.md) - [Employee access insights](https://docs.oleria.ai/governance/employee-access-insights.md): Export the access review insights and recommendations Oleria computes for every employee and application, without launching an access review campaign. - [Account Hygiene](https://docs.oleria.ai/governance/account-hygiene-overview.md): Identify dormant, over-privileged, and misconfigured accounts across your connected applications to reduce your attack surface and maintain compliance. - [Password age](https://docs.oleria.ai/governance/last-password-change-insights.md) - [AI Agent Gateway](https://docs.oleria.ai/governance/ai-agent-gateway-overview.md): Let AI agents work in your SaaS applications without ever holding a credential - with your own permissions, your company's policy, and a full audit trail applied to every call. - [Administrator setup](https://docs.oleria.ai/governance/ai-agent-gateway-admin-setup.md): Choose which applications AI agents can reach, decide what happens when an agent attempts a risky operation, and add custom rules in Rego. - [User setup](https://docs.oleria.ai/governance/ai-agent-gateway-user-setup.md): Authorize the applications you want your AI agent to reach, from the Governance App, with no credential ever leaving Oleria. - [Connect and use your AI agent](https://docs.oleria.ai/governance/ai-agent-gateway-connect-agents.md): Add the Oleria AI Agent Gateway to your AI agent, sign in once, and work across your applications with policy applied and every call recorded. - [Application Hygiene](https://docs.oleria.ai/governance/application-hygiene-overview.md): Discover shadow IT applications - the unsanctioned apps your users access outside your approved software catalog - and assess their risk before they become a vulnerability. - [Dormancy thresholds](https://docs.oleria.ai/governance/account-dormant-days.md) - [Joiner](https://docs.oleria.ai/governance/employee-lifecycle-joiner.md): Automate employee onboarding by provisioning accounts and access when a new hire is detected in your HR system, or by manually entering employees to onboard on demand. - [Mover](https://docs.oleria.ai/governance/employee-lifecycle-mover.md): Automate access changes when employees change roles - grant new-role access and revoke previous-role access using Access Bundles, automatically or on demand. - [Leaver](https://docs.oleria.ai/governance/employee-lifecycle-leaver.md): Automate employee offboarding by revoking access when a departure is detected in your HR system, or by manually entering employees to offboard on demand. - [Access Bundles](https://docs.oleria.ai/governance/access-bundles-and-adaptive-recommendations.md): Define the access each employee population should have, and let Oleria keep it current based on what peers actually hold and use. - [Access Bundle Presets](https://docs.oleria.ai/governance/access-bundle-presets.md): Bulk-create Access Bundles from your organization's employee attributes - Oleria generates candidate bundles from your real workforce data and you choose which to create. - [External access](https://docs.oleria.ai/governance/external-access.md) - [Group Hygiene](https://docs.oleria.ai/governance/group-hygiene-overview.md): Identify inactive group members and unused groups across your connected applications to reduce your attack surface and access management overhead. - [Remediations](https://docs.oleria.ai/governance/remediations-overview.md): Take direct action on identity risks from within Oleria - disable dormant accounts, revoke external access, and remove group members with minimal manual effort. - [View remediation actions](https://docs.oleria.ai/governance/view-remediation-actions.md): Track every remediation action submitted in Oleria, view action status, and roll back changes within 7 days using Audit Logs. - [Disable dormant accounts](https://docs.oleria.ai/governance/disable-dormant-accounts.md): Disable dormant user accounts across Google Workspace, Entra ID, Okta, PingOne, Salesforce, and ServiceNow directly from Oleria to reduce your attack surface. - [Revoke external user access](https://docs.oleria.ai/governance/revoke-external-users-access-permissions.md): Remove unwanted external user access to your organization's assets directly from Oleria, with support for Microsoft SharePoint. - [Remove an account from a group](https://docs.oleria.ai/governance/remove-account-from-group.md) - [User management](https://docs.oleria.ai/administration/user-management-overview.md): Manage who has access to your Oleria workspace - add users, assign roles, and control permissions across your team. - [Default user roles](https://docs.oleria.ai/administration/default-user-roles.md) - [Manage users](https://docs.oleria.ai/administration/manage-users.md) - [Update a user's role](https://docs.oleria.ai/administration/update-a-users-role.md) - [Remove a user](https://docs.oleria.ai/administration/remove-a-user.md) - [SCIM user provisioning](https://docs.oleria.ai/administration/scim-user-provisioning.md): Provision and deprovision Oleria workspace users and groups automatically from your identity provider using the SCIM 2.0 API. - [Governance App SCIM provisioning](https://docs.oleria.ai/administration/scim-governance-provisioning.md): Provision and deprovision governance app users automatically from your identity provider using Oleria's governance SCIM 2.0 endpoint. - [User attributes](https://docs.oleria.ai/administration/user-attributes.md): Reference for the user attributes shown in Oleria's User Management page, including identity, status, and onboarding fields. - [User profile settings](https://docs.oleria.ai/administration/user-profile-settings.md) - [Business rules](https://docs.oleria.ai/administration/workspace-settings-business-rules.md) - [Authentication methods](https://docs.oleria.ai/administration/authentication-methods.md) - [SSO configuration](https://docs.oleria.ai/administration/sso-configuration.md): Let workspace users sign in with your identity provider using SAML single sign-on or social login, and provision governance reviewers automatically. - [Email notifications](https://docs.oleria.ai/administration/email-notifications.md) - [Ticketing](https://docs.oleria.ai/workspace/ticketing-overview.md): Create and manage tickets in Jira or ServiceNow directly from risks and posture insights in Oleria. - [Audit log](https://docs.oleria.ai/governance/audit-log-overview.md): Track every change made in your Oleria workspace - user actions, integration changes, and remediations - for incident investigation and compliance. - [Support](https://docs.oleria.ai/support/overview.md) - [Help](https://docs.oleria.ai/support/help.md) - [Integrations overview](https://docs.oleria.ai/integrations/overview.md): Connect your identity providers, HR systems, cloud infrastructure, and SaaS apps to Oleria so it can build a continuously updated map of access across your environment. - [Integration Studio](https://docs.oleria.ai/integrations/integration-studio.md): Connect any app that has a documented API. An AI research agent reads the API, drafts a connector manifest, and hands it to you to review and connect. - [Active Directory](https://docs.oleria.ai/integrations/active-directory.md) - [Airtable](https://docs.oleria.ai/integrations/airtable.md): Connect your Airtable Enterprise account to Oleria to continuously discover and map who has access to your workspaces, bases, and enterprise groups. - [Atlassian Cloud](https://docs.oleria.ai/integrations/atlassian-cloud.md): Connect your Atlassian Cloud organization to Oleria to continuously discover and map who has access across your organization. - [AWS IAM and S3](https://docs.oleria.ai/integrations/aws-iam-and-s3.md) - [Azure](https://docs.oleria.ai/integrations/azure.md) - [BambooHR](https://docs.oleria.ai/integrations/bamboohr.md): Connect BambooHR to Oleria to bring employees, departments, and manager relationships into your identity and access graph as the authoritative worker record. - [Coupa](https://docs.oleria.ai/integrations/coupa.md) - [Cursor](https://docs.oleria.ai/integrations/cursor.md): Connect your Cursor Enterprise team to Oleria to continuously discover team members, billing groups, roles, and audit activity in your AI code editor. - [File-Based Integration](https://docs.oleria.ai/integrations/custom-application.md) - [DocuSign](https://docs.oleria.ai/integrations/docusign.md) - [Google Cloud Platform](https://docs.oleria.ai/integrations/gcp.md) - [GitHub](https://docs.oleria.ai/integrations/github.md) - [Google Admin and Drive Integration](https://docs.oleria.ai/integrations/google-workspace.md) - [GreytHR](https://docs.oleria.ai/integrations/greythr.md): Connect GreytHR to Oleria to bring employee and department data into your identity security platform. - [Microsoft Entra ID and M365 SharePoint](https://docs.oleria.ai/integrations/microsoft-entra-id.md) - [Okta](https://docs.oleria.ai/integrations/okta.md) - [Oracle HCM Integration](https://docs.oleria.ai/integrations/oracle-hcm.md) - [PagerDuty](https://docs.oleria.ai/integrations/pagerduty.md): Connect your PagerDuty account to Oleria to continuously discover and map who has access across your teams, services, and escalation policies. - [Ping Directory](https://docs.oleria.ai/integrations/ping-directory.md) - [PingOne](https://docs.oleria.ai/integrations/pingone.md) - [Sage Intacct Integration](https://docs.oleria.ai/integrations/sage-intacct.md) - [Salesforce](https://docs.oleria.ai/integrations/salesforce.md) - [SAP Fieldglass](https://docs.oleria.ai/integrations/sap-fieldglass.md) - [SAP SuccessFactors](https://docs.oleria.ai/integrations/sap-success-factors.md): Connect SAP SuccessFactors to Oleria to bring employee and organizational data into your identity security posture. - [SCIM-Based Integration](https://docs.oleria.ai/integrations/scim.md) - [ServiceNow](https://docs.oleria.ai/integrations/servicenow.md) - [Slack](https://docs.oleria.ai/integrations/slack.md): Connect your Slack workspace or Enterprise Grid organization to Oleria to continuously discover and map who has access across your channels, user groups, files, and workspaces. - [Snowflake](https://docs.oleria.ai/integrations/snowflake.md) - [Vanta](https://docs.oleria.ai/integrations/vanta.md) - [Workday](https://docs.oleria.ai/integrations/workday.md) - [Jira](https://docs.oleria.ai/workspace/jira-ticketing.md): Connect Jira to Oleria to create tickets directly from risks and posture findings, automatically populated with risk details and routed to your assignment group. - [ServiceNow](https://docs.oleria.ai/workspace/servicenow-ticketing.md): Connect ServiceNow to Oleria to create incident tickets directly from risks and posture findings using automated OAuth JWT setup. - [ServiceNow (Manual Setup)](https://docs.oleria.ai/workspace/servicenow-ticketing-manual.md): Manually configure ServiceNow to create incident tickets directly from Oleria risks and posture findings using OAuth JWT authentication. - [Slack](https://docs.oleria.ai/workspace/slack-messaging.md): Connect Slack to Oleria to receive security alerts and notifications directly in your Slack channels. - [Microsoft Teams](https://docs.oleria.ai/workspace/teams-messaging.md): Connect Microsoft Teams to Oleria to receive security alerts and notifications directly in your Teams channels. - [API Overview](https://docs.oleria.ai/developer-docs/api-reference/overview.md) - [Generate an API Token](https://docs.oleria.ai/developer-docs/api-reference/generate-token.md) - [List](https://docs.oleria.ai/api-reference/access-assignments/list.md): Returns a page of access assignments. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria… - [Get](https://docs.oleria.ai/api-reference/access-assignments/get.md): Returns an access assignment by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/account-roles/list.md): Returns a page of account roles. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/r… - [Get](https://docs.oleria.ai/api-reference/account-roles/get.md): Returns an account role by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/accounts/list.md): Returns a page of accounts. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/read`… - [Get](https://docs.oleria.ai/api-reference/accounts/get.md): Returns an account by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Create](https://docs.oleria.ai/api-reference/accounts/create.md): Creates an account in the application named by `applicationInstanceId`. This is the one write that carries a body: there is no existing account to address, so the new account's details have to be supplied. The change is applied in the source system asynchronously: this returns a job, and the job rep… - [Activate](https://docs.oleria.ai/api-reference/accounts/activate.md): Activates the account in the application it belongs to, so its owner can sign in. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io/w… - [Disable](https://docs.oleria.ai/api-reference/accounts/disable.md): Disables the account in the application it belongs to, preventing sign-in while keeping the account and its assignments in place. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requ… - [Enable](https://docs.oleria.ai/api-reference/accounts/enable.md): Re-enables an account that was disabled, restoring the access it had. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io/write` scope. - [Revoke active sessions](https://docs.oleria.ai/api-reference/accounts/revoke-active-sessions.md): Invalidates the account's session tokens, signing it out everywhere. Disabling an account does not by itself end sessions already in progress, so this is the change that takes effect immediately. The change is applied in the source system asynchronously: this returns a job, and the job reports the o… - [Remove access to shared resources](https://docs.oleria.ai/api-reference/accounts/remove-access-to-shared-resources.md): Removes the access this account holds to resources shared with it. Intended for accounts outside your organization that have been granted access to internal resources. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether th… - [Delete](https://docs.oleria.ai/api-reference/accounts/delete.md): Permanently deletes the account in the application it belongs to. This cannot be undone. Disable the account instead if you may need to restore its access. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target cou… - [List](https://docs.oleria.ai/api-reference/activities/list.md): Returns a page of activities. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Defaults to the most recent 30 days when `from`/`to` ar… - [Get](https://docs.oleria.ai/api-reference/activities/get.md): Returns an activity by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/assigned-applications/list.md): Returns a page of assigned applications. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.ole… - [Get](https://docs.oleria.ai/api-reference/assigned-applications/get.md): Returns an assigned application by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Grant an account access](https://docs.oleria.ai/api-reference/assigned-applications/grant-an-account-access.md): Entitles the account to the application, granting it access. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io/write` scope. - [Remove an account's access](https://docs.oleria.ai/api-reference/assigned-applications/remove-an-accounts-access.md): Removes the account's entitlement to the application. Access the account holds through a group is unaffected; remove it from the group to revoke that. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be… - [Grant a group access](https://docs.oleria.ai/api-reference/assigned-applications/grant-a-group-access.md): Entitles the group to the application, granting access to every one of its members. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io… - [Remove a group's access](https://docs.oleria.ai/api-reference/assigned-applications/remove-a-groups-access.md): Removes the group's entitlement to the application, and with it the access every member held through that group. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https:/… - [List](https://docs.oleria.ai/api-reference/authenticator-enrollments/list.md): Returns a page of authenticator enrollments. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}… - [Get](https://docs.oleria.ai/api-reference/authenticator-enrollments/get.md): Returns an authenticator enrollment by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/authenticators/list.md): Returns a page of authenticators. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/… - [Get](https://docs.oleria.ai/api-reference/authenticators/get.md): Returns an authenticator by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/department-assignments/list.md): Returns a page of department assignments. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.ol… - [Get](https://docs.oleria.ai/api-reference/department-assignments/get.md): Returns a department assignment by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/department-hierarchy/list.md): Returns a page of department hierarchy edges. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment… - [Get](https://docs.oleria.ai/api-reference/department-hierarchy/get.md): Returns a department hierarchy edge by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/departments/list.md): Returns a page of departments. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/rea… - [Get](https://docs.oleria.ai/api-reference/departments/get.md): Returns a department by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/employees/list.md): Returns a page of employees. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/read`… - [Get](https://docs.oleria.ai/api-reference/employees/get.md): Returns an employee by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/enrollment-links/list.md): Returns a page of enrollment links. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.i… - [Get](https://docs.oleria.ai/api-reference/enrollment-links/get.md): Returns an enrollment link by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/impersonation-grants/list.md): Returns a page of impersonation grants. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oler… - [Get](https://docs.oleria.ai/api-reference/impersonation-grants/get.md): Returns an impersonation grant by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/integrated-applications/list.md): Returns a page of integrated applications. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.o… - [Get](https://docs.oleria.ai/api-reference/integrated-applications/get.md): Returns an integrated application by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/managed-via-relationships/list.md): Returns a page of managed-via relationships. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}… - [Get](https://docs.oleria.ai/api-reference/managed-via-relationships/get.md): Returns a managed-via relationship by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/memberships/list.md): Returns a page of memberships. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/rea… - [Get](https://docs.oleria.ai/api-reference/memberships/get.md): Returns a membership by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/non-human-identities/list.md): Returns a page of non-human identities. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Scoped to non-human identities (service princ… - [Get](https://docs.oleria.ai/api-reference/non-human-identities/get.md): Returns a non-human identity by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Disable](https://docs.oleria.ai/api-reference/non-human-identities/disable.md): Disables the service principal, machine account, or token, so anything using its credentials stops being able to authenticate. Check the identity's impersonation blast-radius first: disabling one that other accounts depend on will break them. The change is applied in the source system asynchronously… - [List](https://docs.oleria.ai/api-reference/object-extensions/list.md): Returns a page of object extensions. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.… - [Get](https://docs.oleria.ai/api-reference/object-extensions/get.md): Returns an object extension by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/person-employee-links/list.md): Returns a page of person-employee links. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.ole… - [Get](https://docs.oleria.ai/api-reference/person-employee-links/get.md): Returns a person-employee link by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/persons/list.md): Returns a page of persons. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/read` s… - [Get](https://docs.oleria.ai/api-reference/persons/get.md): Returns a person by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/reporting-lines/list.md): Returns a page of reporting lines. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io… - [Get](https://docs.oleria.ai/api-reference/reporting-lines/get.md): Returns a reporting line by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/resource-classes/list.md): Returns a page of resource classes. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.i… - [Get](https://docs.oleria.ai/api-reference/resource-classes/get.md): Returns a resource class by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/resource-hierarchy/list.md): Returns a page of resource hierarchy edges. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.… - [Get](https://docs.oleria.ai/api-reference/resource-hierarchy/get.md): Returns a resource hierarchy edge by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List](https://docs.oleria.ai/api-reference/resource-instances/list.md): Returns a page of resource instances. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria… - [Get](https://docs.oleria.ai/api-reference/resource-instances/get.md): Returns a resource instance by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Revoke anonymous access](https://docs.oleria.ai/api-reference/resource-instances/revoke-anonymous-access.md): Removes public or link-based access to this resource, so it can only be reached by named accounts. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environ… - [Revoke external sharing](https://docs.oleria.ai/api-reference/resource-instances/revoke-external-sharing.md): Revokes access held by people outside your organization to this resource. Every external share found on it is removed, so one request can produce many results. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target… - [Remove an account's permissions](https://docs.oleria.ai/api-reference/resource-instances/remove-an-accounts-permissions.md): Removes the permissions the account holds on this resource. Every permission record found for that account on that resource is removed. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all… - [List](https://docs.oleria.ai/api-reference/roles/list.md): Returns a page of roles. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/read` sco… - [Get](https://docs.oleria.ai/api-reference/roles/get.md): Returns a role by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Assign to an account](https://docs.oleria.ai/api-reference/roles/assign-to-an-account.md): Assigns the role to the account, granting the permissions the role carries. Already holding the role is not an error. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `ht… - [Remove from an account](https://docs.oleria.ai/api-reference/roles/remove-from-an-account.md): Removes the role from the account, and with it the permissions the role granted. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io/wr… - [List](https://docs.oleria.ai/api-reference/user-groups/list.md): Returns a page of user groups. Pass `pageToken` from the previous response's `nextPageToken` to fetch the next page. A page can be empty while the results are still being prepared. Keep requesting pages until the response has no `nextPageToken`. Requires the `https://devx.{environment}.oleria.io/rea… - [Get](https://docs.oleria.ai/api-reference/user-groups/get.md): Returns a user group by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Create](https://docs.oleria.ai/api-reference/user-groups/create.md): Creates a group in the application named by `applicationInstanceId`. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the `https://devx.{environment}.oleria.io/write` scope. - [Add an account](https://docs.oleria.ai/api-reference/user-groups/add-an-account.md): Makes the account a member of the group, granting it whatever access the group carries. Already being a member is not an error. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requir… - [Remove an account](https://docs.oleria.ai/api-reference/user-groups/remove-an-account.md): Removes the account's membership of the group, and with it the access the group granted. The account itself is unchanged. The change is applied in the source system asynchronously: this returns a job, and the job reports the outcome, including whether the target could be changed at all. Requires the… - [List](https://docs.oleria.ai/api-reference/action-jobs/list.md): Returns a page of the jobs this tenant has started, most recently started first. Each job is one submitted change and the outcome of applying it. Requires the `https://devx.{environment}.oleria.io/read` scope. - [Get](https://docs.oleria.ai/api-reference/action-jobs/get.md): Returns one job: its status, how many targets it affected, whether Oleria's own data reflects the change yet, and whether it can still be reverted. Poll this after a write until the status is terminal. Requires the `https://devx.{environment}.oleria.io/read` scope. - [List results](https://docs.oleria.ai/api-reference/action-jobs/list-results.md): Returns a page of the job's results, one per target the change was applied to. A job that partly succeeded reports which targets failed and why here: a partial outcome is data to read, not a failed request. One submitted target can produce many results: some changes expand server-side into every rec… - [Revert](https://docs.oleria.ai/api-reference/action-jobs/revert.md): Undoes the change this job applied, where the application it was applied to supports undoing it. Check `revert.available` on the job first: whether a change can be undone depends on that application and on how long ago the change was made. Reverting creates a **new** job, returned here, which report… - [Validate](https://docs.oleria.ai/api-reference/query/validate.md): Parses the SQL query and evaluates it against configured validation rules. Returns `200` if the query passes all rules. Returns `422` with violation details if the query is denied. Does not execute the query. - [Execute](https://docs.oleria.ai/api-reference/query/execute.md): Validates and executes the SQL query. If the query completes within the server-side sync threshold, the response is `200` with inline rows. If not, the response is `202` with a job_id for polling. Clients must always handle both `200` and `202`. Both responses carry a `job_id`; pass it to `GET /v1/q… - [Get a job](https://docs.oleria.ai/api-reference/query/get-a-job.md): Returns the current status of a query job. The job_id from either the `200` or `202` execute response resolves here. When the job is completed, the response includes download references for the result; while it is still running, only the status is returned. - [List](https://docs.oleria.ai/api-reference/saved-query/list.md): Returns a paginated list of saved queries. Supports case-insensitive `contains` filtering, single-field sorting, and cursor pagination. All filter params combine with AND. - [Create](https://docs.oleria.ai/api-reference/saved-query/create.md): Persists a SQL query with authorship and replay metadata. The name must be unique within the tenant (case-insensitive); a conflict returns `409`. - [Get](https://docs.oleria.ai/api-reference/saved-query/get.md): Returns a saved query by its id: the stored SQL, the semantic model it targets, and the authorship and version metadata recorded when it was last written. The `version` in the response is what a subsequent update sends as `expected_version`. - [Delete](https://docs.oleria.ai/api-reference/saved-query/delete.md): Deletes a saved query by its id. Idempotent: the response is `204` whether or not the id existed, so a retried delete is not an error. - [Update](https://docs.oleria.ai/api-reference/saved-query/update.md): Partial update with optimistic concurrency. The caller sends the `expected_version` it last read; a mismatch returns `409` VERSION_CONFLICT. On success `version` is incremented and `last_modified_by` / `last_modified_at` are set. - [List models](https://docs.oleria.ai/api-reference/schema/list-models.md): Returns a list of all semantic models available to the caller. Use this endpoint to discover model names before querying specific model details. - [Get a model](https://docs.oleria.ai/api-reference/schema/get-a-model.md): Returns the full OSI semantic model definition for the given model name, including all datasets, fields, relationships, and metrics. This is the primary endpoint AI agents and BI platforms use to discover the data landscape before generating queries. - [Working with Downloads](https://docs.oleria.ai/developer-docs/api-reference/working-with-downloads.md): The asynchronous request lifecycle, filter and sort grammar, and the full catalog of data contexts available in the Downloads API. - [Create a download request](https://docs.oleria.ai/api-reference/downloads/create-a-download-request.md): Create an asynchronous export for a single resource type. The resource type is chosen by the `context` field — see the `context` field below (`DownloadContext`) for the full list of values and what each one exports. Returns a request `id`; poll `GET /v1/downloads/{id}` until the status is `completed… - [Get a download request](https://docs.oleria.ai/api-reference/downloads/get-a-download-request.md): Poll the status of a download request by id. While processing, `status` is `accepted`. When `status` is `completed`, the response includes a presigned `url` to the CSV result. On failure, `status` is `failed` and `error` is populated. - [What's new](https://docs.oleria.ai/release-notes.md): New features, integrations, and improvements to the Oleria platform. ## OpenAPI Specs - [downloads-openapi-schema-1.0.0](/developer-docs/api-reference/downloads-openapi-schema-1.0.0.yaml) - [oleria-public-api-1.0.0](/developer-docs/api-reference/oleria-public-api-1.0.0.yaml) - [trustfusion-openapi-schema-1.0.0](/developer-docs/api-reference/trustfusion-openapi-schema-1.0.0.yaml)