Resolve an open anomaly with a resolution type and investigator notes.
| Resolution | Description | Effect |
|---|---|---|
false_positive | Anomaly was not a genuine threat | Auto-response reversed (agent restored) |
mitigated | Anomaly was genuine and has been addressed | Auto-response remains; agent may be restored manually |
accepted_risk | Anomaly is genuine but accepted per policy | Auto-response reversed; risk documented |
agent_revoked | Anomaly led to permanent agent revocation | Agent remains revoked |
anomalies:resolve scope. Alternatively, pass a Bearer JWT token
in the Authorization header.maip-anom:ULID). Must be in open status.false_positive, mitigated,
accepted_risk, agent_revoked.resolved.API key for machine-to-machine authentication
Anomaly identifier
Anomaly resolved
low, medium, high, critical open, investigating, resolved, dismissed