---
title: "Protect Route"
method: POST
path: "/api/v1/nova/discovery/onboarding-plans/{agent_id}/protection"
tags: ["nova"]
---

# Protect Route

`POST /api/v1/nova/discovery/onboarding-plans/{agent_id}/protection`

## Path parameters

- `agent_id` string, uuid, required

## Headers

- `Authorization` string, nullable
- `X-Request-ID` string, nullable

## Request body

- ProtectionApproval
  - `revision` string, required
  - `provider_id` string, uuid, required

## Response `200`

Successful Response

- ProtectionResult
  - `preview` ProtectionPreview, required
    - `agent_id` string, uuid, required
    - `name` string, required
    - `entry_file` string, required
    - `entry_line` integer, nullable, required
    - `findings` JobFindingRead[], required
      - `id` string, uuid, required
      - `type` string, required
      - `severity` string, required
      - `file` string, required
      - `line` integer, nullable, required
      - `excerpt` string, nullable, required
    - `assessment` OnboardingPlanRead, required
      - `agent_id` string, uuid, required
      - `repository_id` string, uuid, required
      - `scan_job_id` string, uuid, nullable, required
      - `head_sha` string, nullable, required
      - `recorded_by` string, required
      - `recorded_by_ref` string, nullable, required
      - `observed` object, required
      - `plan` AgentOnboardingPlan, required — The whole plan, as the model records it.
        - `summary` string, required
        - `intent` string, required
        - `tools_observed` ObservedTool[]
          - `name` string, required
          - `source` string, required — The evidence line or finding id this comes from.
          - `risk` 'none' | 'elevated' | 'dangerous'
        - `scope_instructions` string, required — Instructions for a scope guardrail: permitted activities and boundaries.
        - `policies` PlannedPolicy[]
          - `template` string, required — Policy template id.
          - `parameter_values` object
          - `reason` string, required
          - `finding_ids` string[]
        - `guardrails` PlannedGuardrails
          - `daily_token_budget` integer, nullable
          - `per_request_cost_cap_usd` number, nullable
          - `output_token_cap` integer, nullable
        - `agent` PlannedAgent, required — The governed agent the plan reuses or creates.
          - `action` 'reuse' | 'create', required
          - `agent_id` string, uuid, nullable
          - `name` string, nullable
          - `provider_id` string, uuid, nullable
        - `coverage` PlannedCoverage, required
          - `scan_truncated` boolean
          - `confidence` 'low' | 'medium' | 'high', required
          - `open_questions` string[]
      - `status` string, required
      - `planner_plan` AgentOnboardingPlan, required — The whole plan, as the model records it.
        - `summary` string, required
        - `intent` string, required
        - `tools_observed` ObservedTool[]
          - `name` string, required
          - `source` string, required — The evidence line or finding id this comes from.
          - `risk` 'none' | 'elevated' | 'dangerous'
        - `scope_instructions` string, required — Instructions for a scope guardrail: permitted activities and boundaries.
        - `policies` PlannedPolicy[]
          - `template` string, required — Policy template id.
          - `parameter_values` object
          - `reason` string, required
          - `finding_ids` string[]
        - `guardrails` PlannedGuardrails
          - `daily_token_budget` integer, nullable
          - `per_request_cost_cap_usd` number, nullable
          - `output_token_cap` integer, nullable
        - `agent` PlannedAgent, required — The governed agent the plan reuses or creates.
          - `action` 'reuse' | 'create', required
          - `agent_id` string, uuid, nullable
          - `name` string, nullable
          - `provider_id` string, uuid, nullable
        - `coverage` PlannedCoverage, required
          - `scan_truncated` boolean
          - `confidence` 'low' | 'medium' | 'high', required
          - `open_questions` string[]
      - `planner_head_sha` string, nullable, required
      - `applied_resources` object, nullable, required
      - `apply_complete` boolean, required
      - `applied_at` string, date-time, nullable, required
      - `changed_since_onboarded` boolean, required
      - `created_at` string, date-time, required
      - `updated_at` string, date-time, required
    - `providers` ProtectionProvider[], required
      - `id` string, uuid, required
      - `name` string, required
      - `provider` string, required
      - `model` string, nullable, required
    - `provider_id` string, uuid, nullable, required
    - `policies` ProtectionPolicy[], required
      - `template` string, required
      - `title` string, required
      - `stage` string, required
      - `parameter_values` object, required
      - `reason` string, required
      - `finding_ids` string[], required
    - `revision` string, required
    - `blockers` string[], required
    - `limitations` string[], required
    - `governed_agent_id` string, uuid, nullable, required
    - `agent_url` string, nullable, required
    - `configured` boolean, required
    - `configured_at` string, date-time, nullable, required
  - `access_key` string, nullable

## Other responses

- `422` — Validation Error

## Changes

- **2026-09-27** `b20a3bdd6219` — 4 breaking, 4 info
  - removed the required property `preview/assessment/plan/proxy` from the response with the `200` status
  - removed the required property `preview/assessment/planner_plan/anyOf[subschema #1: AgentOnboardingPlan]/proxy` from the response with the `200` status
  - removed the required property `preview/proxy_id` from the response with the `200` status
  - removed the required property `preview/proxy_url` from the response with the `200` status
  - …4 more
- **2026-09-22** `66575c8854c1` — 4 warning, 2 info
  - removed the optional property `preview/assessment/plan/capabilities` from the response with the `200` status
  - removed the optional property `preview/assessment/plan/guardrails/rate_limit_rpm` from the response with the `200` status
  - removed the optional property `preview/assessment/planner_plan/anyOf[subschema #1: AgentOnboardingPlan]/capabilities` from the response with the `200` status
  - removed the optional property `preview/assessment/planner_plan/anyOf[subschema #1: AgentOnboardingPlan]/guardrails/rate_limit_rpm` from the response with the `200` status
  - …2 more
- **2026-09-11** `3bf37c9d2784` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/xenovia/apis/controlplane/changes/api/v1/nova/discovery/onboarding-plans/:agent_id/protection/post.md)

---

[API](https://skmtc.dev/xenovia/apis/controlplane.md) · [All operations](https://skmtc.dev/xenovia/apis/controlplane/llms.txt) · [OpenAPI document](https://skmtc.dev/xenovia/apis/controlplane/revisions/b20a3bdd6219?raw)
