Solo personal de NotificadoPermiso: admin:orgs:readHerramienta MCP: abuseOverview
Staff only. Sending-abuse controls: every org's suspensions (active first; automatic = paused by complaint-watch pending review), org-specific sender limits (recipients per rolling hour/day), the per-plan defaults, and — with orgId — that org's active suspension, history, effective limit and usage in the last hour and 24 h. Org names and counts only.
Parámetros de abuseOverview
Nombre
Dónde
Tipo
Obligatorio
orgId
Consulta
string (uuid)
No
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: affiliate:adminHerramienta MCP: adminPayoutBatches
Staff only (affiliate:admin). The affiliate payout batches, newest month first: period (YYYY-MM), status (draft → approved → executing → done), who built and who approved it, total net, and per payout the affiliate code, gross, withholding, ReteICA and net in COP minor units (centavos), status (draft, approved, sent, paid, failed, canceled), the transfer reference once paid, whether it awaits a manual bank transfer, and its DSNO number. No personal data.
Parámetros de adminPayoutBatches
Nombre
Dónde
Tipo
Obligatorio
limit
Consulta
integer 1–60
No
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: affiliate:adminHerramienta MCP: adminWithholdingRates
Staff only (affiliate:admin). The affiliate retención rate rows, newest first: concept, regime (non_declarant, declarant, art383, legal_entity), rateBps (null = the art. 383 ET table), reteIcaBps, validFrom/validTo (UTC), the norm cited, needsAccountantReview (true blocks every affiliate payout on that regime) and who reviewed it. No personal data.
Parámetros de adminWithholdingRates
Nombre
Dónde
Tipo
Obligatorio
limit
Consulta
integer 1–200
No
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:kpi:readHerramienta MCP: billingKpis
Staff only. Billing figures, no personal data, for payments created in [from, to): per payment method and status the count and the gross, net (after discount), discount and IVA sums in COP minor units (centavos); totals of payments ever approved; refunds recorded in the window; and the DIAN invoices and credit notes queued (pending manual issue) or rejected right now.
Parámetros de billingKpis
Nombre
Dónde
Tipo
Obligatorio
from
Consulta
string (date-time)
Sí
to
Consulta
string (date-time)
Sí
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:config:readHerramienta MCP: catalogSnapshot
Staff only. The sales catalog and provider configuration, read-only, no personal data: active credit packs (sends, price in COP minor units, validity days), plans with the prices in force per interval, coupons that still validate (with redeemed and reserved counts), and env flags — name, set, the non-secret value of each provider selector and what the app built from it (effective, or the X_* error code refusing it). Secrets are never listed; ADMIN_ALLOWED_IPS only says whether it is set.
Parámetros de catalogSnapshot
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:orgs:readHerramienta MCP: deliverability
Staff only. Email deliverability for events recorded in [from, to), no personal data: per America/Bogota day and per recipient domain (domains with fewer than 3 distinct addresses are grouped as "(other)") the sends, deliveries, hard and soft bounces, complaints and deferrals with rates in percent; the customer orgs with the most bounces (org id, name and counts only); and the SES account standing (production access, sending enabled, 24 h quota and usage). Window at most 92 days.
Parámetros de deliverability
Nombre
Dónde
Tipo
Obligatorio
from
Consulta
string (date-time)
Sí
to
Consulta
string (date-time)
Sí
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: evidenceHealth
Staff only. Evidence system health, no personal data: the last 14 daily anchors (Bogotá days; missing days listed; which timestamp authorities stamped each Merkle root), per-authority stamped/missed anchors plus tokens issued and stamp failures over the window, the last nightly evidence-chain verification verdict (ok, events checked, first broken seq), the latest NTP clock sample per host against the 100 ms threshold, and the mail transport account status (productionAccess false = SES sandbox: only verified recipients receive mail; 24 h quota and sent; errorCode when the provider could not be asked).
Parámetros de evidenceHealth
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:kpi:readHerramienta MCP: funnelReport
Staff only. The growth funnel for orgs that signed up in [from, to) (at most 190 days), no personal data: one row per signup week (Monday, America/Bogota) with counts of orgs that signed up, submitted KYC, were KYC-approved, started the trial, created a first case, sent a first notification, had a first delivery and paid; each stage's conversion from the previous one in percent; and trial-to-paid within 30 days in percent.
Parámetros de funnelReport
Nombre
Dónde
Tipo
Obligatorio
from
Consulta
string (date-time)
Sí
to
Consulta
string (date-time)
Sí
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: jobQueues
Staff only. The background job queues, no personal data: per queue ready, delayed, running, suspended and dead counts plus oldestReadyMs; the last 50 dead letters (jobId, name, attempts, errorCode — never the input); every scheduled task with cron, time zone and nextRunAt (UTC); missing lists what this process cannot report (no driver, no introspection). Requeue a dead letter with requeueJob({ jobId }).
Parámetros de jobQueues
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:kpi:readHerramienta MCP: kpiSnapshot
Staff only. One America/Bogota month's launch KPIs (month as YYYY-MM), no personal data: signups; KYC submissions and the percent approved; trials started, the percent that sent a first notification (activation) and the percent that paid within 30 days (trial-to-paid); MRR in COP minor units (centavos, annual prices counted monthly) and live subscriptions at the month end; churn (subscriptions live at the month start that ended in it, percent); net revenue before IVA of payments approved in the month, the subscription part and its share. Revenue by payment method: billingKpis.
Parámetros de kpiSnapshot
Nombre
Dónde
Tipo
Obligatorio
month
Consulta
string 7–7
Sí
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: opsAlerts
Staff only. The conditions operations must act on, most severe first: tsa_failures (timestamp authority failures in 24 h), anchor_missed (no daily Merkle anchor for the last due Bogotá day), clock_offset (NTP offset past 100 ms), chain_verify_failed and staff_audit_chain_broken (a nightly hash-chain verification failed), ses_sending_paused, ses_sandbox, ses_quota_high, bounce_rate_high (> 5 %) and complaint_rate_high (> 0.1 %) over 24 h. Each row: code, severity (info | warn | critical), since (UTC), href (console page), value (the figure). No personal data.
Parámetros de opsAlerts
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: opsOverview
Staff only. Operations counts, no personal data: lawyers pending KYC, four-eyes approvals pending, notifications and recipients created in the last 24 h by outcome (sent, failed, delivered, bounced, complained), and the job backlog.
Parámetros de opsOverview
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:payments:readHerramienta MCP: orphanApprovals
Staff only (admin:payments:read). Approvals the gateway reported for payments already closed without money (declined, voided, error) and not yet revived — the customer was charged and holds nothing. Per row: payment id, org id, reference, current status, the gateway event key (`transaction.updated:<txId>:APPROVED`), the gross in COP minor units (centavos) and when the approval was refused. Refund or void each at the gateway, or wait for the reconcile to revive it.
Parámetros de orphanApprovals
Nombre
Dónde
Tipo
Obligatorio
limit
Consulta
integer 1–500
No
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: affiliate:adminHerramienta MCP: previewPayoutBatch
Staff only (affiliate:admin). Read-only preview of the affiliate payout batch for a closed month (period YYYY-MM): per affiliate whose payable balance reaches the $100,000 minimum, the code, gross, withholding (retención), ReteICA and net in COP minor units, the tax regime, and `held` — the reasons it would roll over instead (kyc_not_approved, terms_missing, payout_destination_missing, iva_responsible_invoice_required, payout_in_flight, below_minimum, refund_heavy, velocity, rate_missing, rate_unreviewed, art383_table_missing). Also the payable count, totals, and the regimes whose rate awaits accountant sign-off (which blocks building the batch). Writes nothing.
Parámetros de previewPayoutBatch
Nombre
Dónde
Tipo
Obligatorio
period
Consulta
string 7–7
Sí
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: providerHealth
Staff only. Liveness of every configured provider, no personal data: each timestamp authority, the PDF signer, the mail transport, the evidence and uploads storage disks, the payment gateway, the e-invoice provider and captcha — each { kind, id, ok, latencyMs, checkedAt, detail } where detail.code names why a provider is down. Probes are read-only (nothing is stamped, signed, sent or charged) and the answer is cached for 60 s.
Parámetros de providerHealth
Nombre
Dónde
Tipo
Obligatorio
_first
Consulta
integer 1–10000page size; present, the response is the page envelope rather than the bare rows (1 to 10000)
No
_after
Consulta
stringthe endCursor a previous page answered; needs _first
Solo personal de NotificadoPermiso: admin:approvals:readHerramienta MCP: listApprovals
Staff only. Four-eyes approval requests (credit grants/adjustments above 100 credits). Default: pending, oldest first; pass status for history (newest first). Every call is audited. A second staff member decides each with decideApproval in the console.
Solo personal de NotificadoPermiso: admin:coupons:writeHerramienta MCP: adminArchiveCoupon
Staff only (admin:coupons:write). Archives a coupon by id (from adminListCoupons): new previews and checkouts refuse it; redemptions already made keep it. Idempotent. Recorded in the audit trail.
Solo personal de NotificadoPermiso: admin:customer-data:readHerramienta MCP: viewAsOrg
Staff only. A read-only snapshot of what one customer org's panel shows: the org, spendable credit balance and next expiry, KYC banner state, the 5 most recent notifications and cases. Read as a viewer of that org (no session, no writes possible). Needs a purpose (5+ characters). Every call is audited.
Solo personal de NotificadoPermiso: admin:audit:exportHerramienta MCP: exportAudit
Staff only (superadmin, compliance). The staff-access audit trail for Bogotá days from..to (YYYY-MM-DD, both inclusive) as a CSV file: base64 bytes, filename and SHA-256. Oldest first; columns seq, at_utc, at_bogota, actor, action, outcome, subject, purpose, diff, prev_hash, hash. Optional filters actorId, subjectOrgId, subjectType/subjectId, outcome. At most 10000 rows — past that X_ADMIN_AUDIT_EXPORT_TOO_LARGE: split the range. This export is itself audited.
Solo personal de NotificadoPermiso: admin:audit:readHerramienta MCP: listAudit
Staff only (superadmin, compliance). The staff-access audit trail: every staff read of customer data and every refusal on a staff surface, newest first. Filter by actorId, subjectOrgId, subjectType/subjectId, outcome (allowed|denied|failed), from/to (UTC). Page with cursor. This read is itself audited.
Solo personal de NotificadoPermiso: admin:coupons:writeHerramienta MCP: adminCreateCoupon
Staff only (admin:coupons:write). Creates a coupon: code (3–40 of A-Z 0-9 _ -, stored upper-case, never reused — X_PROMO_COUPON_CODE_TAKEN otherwise), kind percent (percentBps 1..10000) or fixed (amountOff in COP minor units, whole pesos), appliesTo pack | subscription | any, duration once | cycles (with cycles) | forever, optional firstPurchaseOnly, maxRedemptions across orgs, UTC validFrom/validTo and a campaign tag. The discount comes off the net before IVA. Recorded in the audit trail.
Parámetros de adminCreateCoupon
Nombre
Dónde
Tipo
Obligatorio
Idempotency-Key
Consulta
string ≤ 255Replays the first response for a repeated key.
No
amountOff
Cuerpo
objectinteger minor units plus an ISO 4217 currency code
Solo personal de NotificadoPermiso: admin:orgs:readHerramienta MCP: viewCustomer360
Staff only. The customer 360 of one org: members (email, role, second factor), lawyer KYC (cédula masked), credit balance and the last 20 ledger rows, notifications by status, subscription and plan, payments and DIAN invoices in summary, recipients sent in the last 30 days with bounce and complaint rates, active suspension and sender limit with usage, deadline (term) counts, affiliate attribution, and the newest staff support notes. Needs a purpose (5+ characters). Every call is audited.
Solo personal de NotificadoPermiso: admin:payments:readHerramienta MCP: adminDownloadGatewayEvent
Staff only (admin:payments:read). Returns the stored body of one payment gateway delivery (eventId from adminPaymentDetail) as base64 bytes with its SHA-256, size, verified flag and received-at. Read-only. Every call is recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:dsr:readHerramienta MCP: listDsrQueue
Staff only (admin:dsr:read). The habeas-data (Ley 1581) request queue: open requests first, ordered by legal due date (dueAt, UTC; the extended date when the single extension was taken), with late=true when the due day in America/Bogota has passed. Each row: reference, kind (consulta | reclamo | actualizacion | supresion), whether the titular is a notification recipient or an account holder, identity and contact, message, outcome and response once answered, and the outcomes the respond form allows with and without evidence in scope. Evidence is never deleted: a supresión on evidence is answered with the retention basis. Every call is recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:evidence:exportHerramienta MCP: adminExportEvidenceZip
Staff only. The offline-verifiable evidence zip of any org's notification, as base64 bytes with filename and SHA-256 (verified against the stored digest in this call); newest version unless version is given. Needs a purpose (5+ characters). Recorded on the staff trail, in the firm's audit log and as an evidence.viewed event. X_EVIDENCE_ZIP_NOT_READY while the zip is being built (it is queued) — ask again shortly.
Solo personal de NotificadoPermiso: admin:incident:writeHerramienta MCP: postIncidentUpdate
Staff only (admin:incident:write). Posts a PUBLIC update (Spanish message, optional English messageEn) on an open incident of notificado.co/estado: status investigating | identified | monitoring, and optionally a new impact. Updates are never edited; to close the incident call resolveIncident. Recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:incident:writeHerramienta MCP: createIncident
Staff only (admin:incident:write). Opens an incident on the public status page notificado.co/estado with its first public update (status investigating). impact: maintenance | degraded | partial_outage | major_outage. title and message are Spanish and PUBLIC — no customer names or data; titleEn/messageEn are optional English courtesy lines. startedAt (UTC) defaults to now; only a maintenance may start in the future. Recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:incident:writeHerramienta MCP: resolveIncident
Staff only (admin:incident:write). Resolves an open incident on notificado.co/estado with a closing PUBLIC update (Spanish message, optional English messageEn). A resolved incident cannot be reopened; a recurrence is a new incident (createIncident). Recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:jobs:writeHerramienta MCP: requeueJob
Staff only (ops, superadmin). Requeue one finished job — dead, cancelled or done — by jobId (from jobQueues), optionally fromStep. A running or waiting job is refused. Through MCP the call waits for your human to confirm it in /admin/mcp. Audited.
Solo personal de NotificadoPermiso: kyc:reviewHerramienta MCP: listKycQueue
Staff only. The lawyers waiting for KYC review across every firm, oldest first: name, cédula, tarjeta profesional, SIRNA email, the firm name, and the uploaded certificado de vigencia (id, SHA-256, type). Every call is audited. Decide each with approveKyc or rejectKyc.
Solo personal de NotificadoPermiso: kyc:reviewHerramienta MCP: approveKyc
Staff only. Approve a pending lawyer KYC after checking the certificado de vigencia against the CSJ: records the decision with its reason, grants the firm its one-time trial credits and mails the lawyer. Pass orgId and profileId exactly as listKycQueue returned them.
Solo personal de NotificadoPermiso: kyc:reviewHerramienta MCP: rejectKyc
Staff only. Reject a pending lawyer KYC (for example an expired or unreadable certificado de vigencia). The reason is mailed to the lawyer verbatim, so write it for them. Pass orgId and profileId exactly as listKycQueue returned them.
Solo personal de NotificadoPermiso: admin:coupons:readHerramienta MCP: adminListCoupons
Staff only (admin:coupons:read). Lists coupons newest first: code, percent (basis points) or fixed amount (COP minor units), what it applies to (pack | subscription | any), duration (once | cycles | forever), first-purchase-only, max redemptions, UTC validity window, campaign tag, archived instant, and live redemption counts (reserved by open checkouts, committed by approved payments). Archived coupons only with includeArchived: true; filter by campaign.
Solo personal de NotificadoPermiso: admin:payments:readHerramienta MCP: adminListPayments
Staff only (admin:payments:read). Lists payments across every customer org, newest first: org, gateway reference, status, method, gross in COP minor units (centavos), created/approved instants and the DIAN invoice status. Filter by status, orgId, a createdAt window (from inclusive, to exclusive) and q (reference prefix, Wompi transaction id, payment id prefix or part of the org name); page with cursor. Every call is recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:invoicing:issueHerramienta MCP: requestManualInvoiceUpload
Staff only (admin:invoicing:issue). Step 1 of recording an invoice issued by hand in DIAN software: returns a signed PUT url for its PDF (application/pdf, at most 5 MB). PUT the bytes there, then call recordManualInvoice with the returned key as pdfKey.
Solo personal de NotificadoPermiso: admin:invoicing:issueHerramienta MCP: pendingManualInvoices
Staff only (admin:invoicing:issue). The queued DIAN invoices and credit notes (document: invoice | credit_note; a credit note names the invoice it corrects) waiting to be issued by hand (EINVOICE_PROVIDER=manual), oldest first, each with buyer, lines, amounts in COP minor units (centavos), form of payment and our reference. Issue each in the DIAN software, then record it with recordManualInvoice. Every call is recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:invoicing:issueHerramienta MCP: recordManualInvoice
Staff only (admin:invoicing:issue). Records a DIAN invoice or credit note issued by hand in external DIAN software for a queued document (see pendingManualInvoices): its DIAN number, CUFE/CUDE (96 hex chars), issue time, and the PDF uploaded via requestManualInvoiceUpload (pdfKey). Marks it issued exactly once; the customer can then download it.
Solo personal de NotificadoPermiso: admin:customer-data:readHerramienta MCP: searchNotifications
Staff only. Finds notifications of any customer org by 23-digit radicado, recipient email (or part of it), SES MessageId, notification or recipient id, or constancia verify code; newest first, with org, case radicado, status, sentAt, recipient count and each live recipient (recipientId, email, status; the matched one first). At least 3 characters. Every call is audited with its term.
Solo personal de NotificadoPermiso: admin:orgs:readHerramienta MCP: searchOrgs
Staff only. Finds customer orgs by part of the name, a member email, an org id prefix (4+ hex chars) or a 23-digit radicado; newest first, with member count, KYC state and credit balance. At least 3 characters. Every call is audited with its term.
Solo personal de NotificadoPermiso: admin:orgs:readHerramienta MCP: viewOrg
Staff only. One customer org: members (email, role, MFA), lawyer KYC status (cédula masked), credit balance with the last 20 ledger rows, notification counts by status, pending approvals. Every call is audited.
Solo personal de NotificadoPermiso: admin:payments:readHerramienta MCP: adminPaymentDetail
Staff only (admin:payments:read). One payment by paymentId, in any org: amounts (COP minor units), status history markers, the gateway events about it (verified or not, applied or with the apply error, SHA-256 and size of the stored raw body), the credit ledger rows it produced, its DIAN invoice and credit notes, refunds and refund approval requests, and the amount still refundable. Every call is recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:customer-data:readHerramienta MCP: viewRawEvent
Staff only. The raw provider payload behind one evidence event (SES/SNS JSON, inbound reply notification, transport receipt), base64, exactly as stored, with its SHA-256 recomputed now and compared with the digest the hash-chained event committed to (match). Needs a purpose (5+ characters). Read-only; every call is audited.
Solo personal de NotificadoPermiso: admin:customer-data:readHerramienta MCP: viewRecipientTimeline
Staff only. One recipient of a notification as the evidence shows it: recipient and notification (org, case radicado, frozen .eml SHA-256), address provenance and sworn statement, attachment SHA-256s, every evidence event in chain order (UTC and Bogotá time, seq, hash, prevHash, indicio flag for opens, hasRaw) and the constancia versions. Read-only. Every call is audited.
Solo personal de NotificadoPermiso: admin:payments:readHerramienta MCP: adminReconcilePayment
Staff only (admin:payments:read). Enqueues a reconciliation of one payment now: the server asks the payment gateway for its transaction and applies the answer (idempotent — an approved payment stays approved; missing credits or invoice are repaired). Returns the status before it runs; read adminPaymentDetail again after a few seconds. Recorded in the staff audit trail.
Solo personal de NotificadoPermiso: admin:evidence:reissueHerramienta MCP: adminReissueConstancia
Staff only. Queue the next version of a notification's constancia (signed PDF built from every evidence event so far); earlier versions are never overwritten and keep verifying as superseded. Needs a reason (5+ characters). Fails X_CONSTANCIA_NOT_FOUND before the first constancia exists. Audited, and recorded in the firm's own audit log.
Solo personal de NotificadoPermiso: admin:payments:refundHerramienta MCP: adminRequestRefund
Staff only (admin:payments:refund). Files a four-eyes refund request for one approved payment: gross in COP minor units (at most the refundable amount adminPaymentDetail reports), a reason, and refundReason customer|chargeback|error. A DIFFERENT staff member must approve it (decideApproval); approval then records the refund, takes back unused credits and queues the DIAN credit note. It does NOT move money: staff return it in the Wompi dashboard. Returns the approval request.
Solo personal de NotificadoPermiso: admin:system:readHerramienta MCP: checkStorageLock
Staff only. Reads the S3 Object Lock actually applied to one evidence object (one HEAD, never the content): mode COMPLIANCE | GOVERNANCE | NONE (or n/a on a local dev disk), retainUntil (UTC), legalHold. Omit key to check the newest stored timestamp token. In production alert is true, with alertReason, when the object is deletable. Audited.
Solo personal de NotificadoPermiso: admin:support:writeHerramienta MCP: addSupportNote
Staff only (superadmin, ops, support, compliance). Append a support note to one customer org: what happened and what was agreed (up to 4000 characters). Notes are staff-only, insert-only (never edited or deleted — write a new note to correct one) and shown on the org 360. Through MCP the call waits for your human to confirm it in /admin/mcp. Audited.