> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the full remediation context of several compliance alerts

> Return, for MULTIPLE compliance alerts in one call, the same payload as `getComplianceAlertDetails` — the alert, its MDM control with the configuration in clear, the device on both sides and the `enforcement` facets — as `items`, in the order of `alertIds` (up to 25 per call, from `getComplianceAlerts` or `searchComplianceAlerts`). Prefer this over calling `getComplianceAlertDetails` once per alert. An id that matches no alert of your company is listed in `notFoundAlertIds` instead of failing the call: the check no longer applies to that device, and asking again returns the same answer. Each alert weighs 3 to 8 KB, more when its control carries a large profile or script.

<span className="badge-read">Key: Read</span><span className="badge-company">Scope: Company</span>


## OpenAPI

````yaml https://api.getprimo.com/openapi.json post /compliance/alerts/details
openapi: 3.1.1
info:
  title: Public API - BETA
  description: Read docs on https://docs.getprimo.com/
  version: '1.0'
  contact: {}
servers:
  - url: https://api.getprimo.com
security:
  - apikey: []
tags: []
paths:
  /compliance/alerts/details:
    post:
      tags:
        - Compliance
      summary: Get the full remediation context of several compliance alerts
      description: >-
        Return, for MULTIPLE compliance alerts in one call, the same payload as
        `getComplianceAlertDetails` — the alert, its MDM control with the
        configuration in clear, the device on both sides and the `enforcement`
        facets — as `items`, in the order of `alertIds` (up to 25 per call, from
        `getComplianceAlerts` or `searchComplianceAlerts`). Prefer this over
        calling `getComplianceAlertDetails` once per alert. An id that matches
        no alert of your company is listed in `notFoundAlertIds` instead of
        failing the call: the check no longer applies to that device, and asking
        again returns the same answer. Each alert weighs 3 to 8 KB, more when
        its control carries a large profile or script.
      operationId: getComplianceAlertsDetails
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GetComplianceAlertsDetailsBody'
      responses:
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetComplianceAlertsDetails_Output'
components:
  schemas:
    GetComplianceAlertsDetailsBody:
      type: object
      properties:
        alertIds:
          description: >-
            Identifiers of the compliance alerts, as returned by
            getComplianceAlerts or searchComplianceAlerts. Up to 25 per call.
          minItems: 1
          maxItems: 25
          type: array
          items:
            type: string
            pattern: ^[a-f\d]{24}$
      required:
        - alertIds
    GetComplianceAlertsDetails_Output:
      type: object
      properties:
        items:
          type: array
          description: The details of every alert found, in the order of `alertIds`.
          items:
            type: object
            properties:
              alert:
                type: object
                properties:
                  id:
                    type: string
                  deviceId:
                    type: string
                  deviceName:
                    anyOf:
                      - type: string
                      - type: 'null'
                  devicePlatform:
                    anyOf:
                      - type: string
                        enum:
                          - ANDROID
                          - IOS
                          - IPADOS
                          - MACOS
                          - WINDOWS
                          - LINUX
                          - CHROME_OS
                          - UNKNOWN
                      - type: 'null'
                  owner:
                    description: Employee the alerting device is assigned to.
                    anyOf:
                      - type: object
                        properties:
                          id:
                            type: string
                          firstName:
                            type: string
                          lastName:
                            type: string
                        required:
                          - id
                          - firstName
                          - lastName
                        additionalProperties: false
                      - type: 'null'
                  complianceRuleId:
                    type: string
                  ruleType:
                    description: Type of the compliance rule behind the alert.
                    anyOf:
                      - type: string
                      - type: 'null'
                  mdmControlId:
                    anyOf:
                      - type: string
                      - type: 'null'
                  status:
                    type: string
                    enum:
                      - ACTIVE
                      - NOT_PROTECTED
                      - OFFLINE_7_DAYS
                      - PENDING
                      - PROTECTED
                      - FAILED
                      - NOT_ENCRYPTED
                      - MISSING_RECOVERY_KEY
                      - ENCRYPTED
                      - ACTION_REQUIRED
                      - GRACE_PERIOD
                      - UP_TO_DATE
                      - NOT_UP_TO_DATE
                      - ENFORCED
                      - ERROR
                      - CREATION_PENDING
                      - DEMOTION_PENDING
                      - CREATED
                      - CREATION_FAILED
                      - SUCCESS
                      - UNSUPPORTED
                      - INSTALLED
                      - MDM_ON
                      - MDM_OFF
                      - MDM_ON_IN_ANOTHER_MDM
                      - READY_ZTD
                      - MISSING_AGENT
                      - ONLINE
                      - OFFLINE
                      - ENABLED
                      - DISABLED
                      - MISSING_BYPASS_CODE
                      - MEETS_REQUIREMENTS
                      - BELOW_MINIMUM_VERSION
                      - UNSUPPORTED_OS_EDITION
                  additionalStatus:
                    description: >-
                      Narrows `status` when several situations share it. Null
                      when `status` already says everything — a compliant
                      device, or a status only one situation can produce — and
                      on rows computed before this field existed.
                      PROFILE_DELIVERY_PENDING: The MDM profile is queued for
                      delivery; the device has not acknowledged it yet.
                      PROFILE_VERIFYING: The MDM profile was installed and the
                      MDM is verifying it applied. PROFILE_NOT_ON_DEVICE: The
                      MDM has no record of this profile on the device; it was
                      never scoped to it. A resend needs a prior delivery, so
                      refresh the device and re-check the control targeting
                      instead. PROFILE_DELIVERY_FAILED: The device rejected the
                      MDM profile. `detail` carries the MDM error.
                      CONTROL_MISSING_PROFILE: The control has no profile to
                      deploy; this is a Primo configuration issue, not a device
                      issue. POLICY_NOT_EVALUATED: The device has not reported a
                      result for the compliance check yet. POLICY_NOT_ON_DEVICE:
                      The compliance check is not attached to this device in the
                      MDM. POLICY_FAILED: The compliance check attached to the
                      control fails on the device. CONTROL_MISSING_POLICY: The
                      control has no compliance check attached; this is a Primo
                      configuration issue. RECOVERY_OS_STATUS_UNKNOWN: Primo has
                      not computed the recovery OS state of this device yet.
                      RECOVERY_OS_PROTECTION_PENDING: The recovery OS password
                      command was sent and awaits the device.
                      RECOVERY_OS_PROTECTION_FAILED: The device rejected the
                      recovery OS password command. RECOVERY_OS_NOT_PROTECTED:
                      Recovery OS has no password set.
                      RECOVERY_OS_STATUS_UNRECOGNIZED: The device reports a
                      recovery OS state Primo does not know. `detail` carries
                      the raw value. SENTINEL_ONE_AGENT_NOT_INSTALLED: The
                      SentinelOne agent is not installed on the device.
                      SENTINEL_ONE_AGENT_INSTALLED_NOT_REGISTERED: The
                      SentinelOne agent is installed but the device is not
                      registered in the SentinelOne console.
                      MALWAREBYTES_AGENT_NOT_INSTALLED: The Malwarebytes agent
                      is not in the device software inventory and no install ran
                      in the last 24 hours. MALWAREBYTES_INSTALL_IN_PROGRESS:
                      The Malwarebytes install script ran in the last 24 hours;
                      wait for the next inventory sync. `detail` carries the run
                      date. MALWAREBYTES_ENDPOINT_NOT_FOUND: The Malwarebytes
                      agent is installed but the device has no endpoint in the
                      Malwarebytes console; the agent is not registered to the
                      company account. MALWAREBYTES_REGISTRATION_IN_PROGRESS:
                      The Malwarebytes registration script ran in the last hour;
                      wait for the console to sync. `detail` carries the run
                      date. MALWAREBYTES_ENDPOINT_UNPROTECTED: The device exists
                      in the Malwarebytes console but is not protected. `detail`
                      carries the console protection status.
                      MALWAREBYTES_AGENT_NEVER_REPORTED: The Malwarebytes
                      console has no activity date for this device.
                      MALWAREBYTES_AGENT_INACTIVE: The Malwarebytes agent last
                      reported more than 7 days ago. `detail` carries the last
                      activity date. RUSTDESK_INSTALL_NOT_STARTED: No RustDesk
                      installation was recorded for this device yet.
                      RUSTDESK_INSTALL_IN_PROGRESS: The RustDesk installation is
                      in progress. RUSTDESK_INSTALL_FAILED: The RustDesk
                      installation failed on the device.
                      ADMIN_ACCOUNT_CREATION_QUEUED: The managed admin account
                      creation is queued: no creation command has been
                      dispatched to this device yet.
                      ADMIN_ACCOUNT_CREATION_IN_PROGRESS: The managed admin
                      account creation was dispatched and awaits the device.
                      ADMIN_ACCOUNT_PRE_EXISTING: An account with the policy
                      username already exists on the device and was not created
                      by Primo. `detail` carries the username.
                      NO_MANAGED_ADMIN_TO_ROTATE: No Primo-managed admin account
                      exists on the device, nothing to rotate.
                      PASSWORD_ROTATION_UP_TO_DATE: The managed admin password
                      was rotated within the configured frequency.
                      DEVICE_NAME_SUGGESTION_NOT_GENERATED: Primo has not
                      generated the expected name for this device yet. `detail`
                      carries the last failed attempt, if any.
                      DEVICE_NAME_ALREADY_USED: Primo gave up naming this
                      device: the name its rule produces is held by another
                      device of the company. `detail` carries the name and the
                      id of that device — retire it or rename it, then
                      regenerate the name. DEVICE_NAME_SUGGESTION_FAILED: Primo
                      gave up naming this device after repeated invalid AI
                      outputs. `detail` carries the failure type; regenerate the
                      name once the rule is fixed. DEVICE_RENAME_NOT_DISPATCHED:
                      The device name differs from the convention and no rename
                      command is in flight. `detail` carries expected vs actual.
                      DEVICE_RENAME_COMMAND_IN_PROGRESS: A rename command was
                      sent and awaits the device. `detail` carries expected vs
                      actual. DEVICE_OFFLINE_LESS_THAN_7_DAYS: The device has
                      not checked in for less than 7 days. `detail` carries the
                      last check-in. DEVICE_LAST_SEEN_UNKNOWN: The MDM reports
                      no valid last check-in date for this device.
                    anyOf:
                      - type: string
                        enum:
                          - MALWAREBYTES_AGENT_NOT_INSTALLED
                          - MALWAREBYTES_INSTALL_IN_PROGRESS
                          - MALWAREBYTES_ENDPOINT_NOT_FOUND
                          - MALWAREBYTES_REGISTRATION_IN_PROGRESS
                          - MALWAREBYTES_ENDPOINT_UNPROTECTED
                          - MALWAREBYTES_AGENT_NEVER_REPORTED
                          - MALWAREBYTES_AGENT_INACTIVE
                          - RECOVERY_OS_STATUS_UNKNOWN
                          - RECOVERY_OS_PROTECTION_PENDING
                          - RECOVERY_OS_PROTECTION_FAILED
                          - RECOVERY_OS_NOT_PROTECTED
                          - RECOVERY_OS_STATUS_UNRECOGNIZED
                          - PROFILE_DELIVERY_PENDING
                          - PROFILE_VERIFYING
                          - PROFILE_NOT_ON_DEVICE
                          - PROFILE_DELIVERY_FAILED
                          - CONTROL_MISSING_PROFILE
                          - POLICY_NOT_EVALUATED
                          - POLICY_NOT_ON_DEVICE
                          - POLICY_FAILED
                          - CONTROL_MISSING_POLICY
                          - ADMIN_ACCOUNT_CREATION_QUEUED
                          - ADMIN_ACCOUNT_CREATION_IN_PROGRESS
                          - ADMIN_ACCOUNT_PRE_EXISTING
                          - NO_MANAGED_ADMIN_TO_ROTATE
                          - PASSWORD_ROTATION_UP_TO_DATE
                          - DEVICE_NAME_SUGGESTION_NOT_GENERATED
                          - DEVICE_NAME_ALREADY_USED
                          - DEVICE_NAME_SUGGESTION_FAILED
                          - DEVICE_RENAME_NOT_DISPATCHED
                          - DEVICE_RENAME_COMMAND_IN_PROGRESS
                          - SENTINEL_ONE_AGENT_NOT_INSTALLED
                          - SENTINEL_ONE_AGENT_INSTALLED_NOT_REGISTERED
                          - RUSTDESK_INSTALL_NOT_STARTED
                          - RUSTDESK_INSTALL_IN_PROGRESS
                          - RUSTDESK_INSTALL_FAILED
                          - DEVICE_OFFLINE_LESS_THAN_7_DAYS
                          - DEVICE_LAST_SEEN_UNKNOWN
                      - type: 'null'
                  detail:
                    description: >-
                      Raw evidence behind `additionalStatus` when one exists (an
                      MDM error, an upstream protection status, a date, a name).
                      Human readable, not stable.
                    anyOf:
                      - type: string
                      - type: 'null'
                  hasAlert:
                    type: boolean
                  createdAt:
                    type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                  updatedAt:
                    description: When the compliance of the device was last checked.
                    type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                  statusSince:
                    description: >-
                      When the device was first observed carrying the current
                      status. Resets on every status change, including between
                      two non-compliant statuses. Null until the device syncs
                      for the first time.
                    anyOf:
                      - type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      - type: 'null'
                required:
                  - id
                  - deviceId
                  - deviceName
                  - devicePlatform
                  - owner
                  - complianceRuleId
                  - ruleType
                  - mdmControlId
                  - status
                  - additionalStatus
                  - detail
                  - hasAlert
                  - createdAt
                  - updatedAt
                  - statusSince
                additionalProperties: false
              mdmControl:
                description: >-
                  The MDM control behind the alert — null for built-in checks
                  (enrollment, online, iCloud lock, Primo requirement).
                anyOf:
                  - type: object
                    properties:
                      id:
                        type: string
                      name:
                        type: string
                      category:
                        type: string
                      type:
                        type: string
                      identifier:
                        type: string
                      enabled:
                        type: boolean
                      profileFleetId:
                        description: >-
                          MDM identifier of the profile this control deploys —
                          matches an entry of device.fleet.profiles.
                        anyOf:
                          - type: string
                          - type: 'null'
                      configurationPayload:
                        description: >-
                          The Primo configuration the control enforces on the
                          device, secret values included.
                        anyOf:
                          - type: object
                            propertyNames:
                              type: string
                            additionalProperties: {}
                          - type: 'null'
                    required:
                      - id
                      - name
                      - category
                      - type
                      - identifier
                      - enabled
                      - profileFleetId
                      - configurationPayload
                    additionalProperties: false
                  - type: 'null'
              device:
                type: object
                properties:
                  fleet:
                    description: >-
                      Live MDM state of the device — null when the device is no
                      longer enrolled, or when your company has no MDM instance
                      to read it from.
                    anyOf:
                      - type: object
                        properties:
                          fleetHostId:
                            description: >-
                              MDM identifier of the host — the join key for MDM
                              operations.
                            type: number
                          uuid:
                            type: string
                          displayName:
                            type: string
                          hardwareSerial:
                            description: >-
                              Can be an empty string — never use it as a join
                              key.
                            type: string
                          status:
                            description: Liveness — caps any device-side remediation.
                            type: string
                            enum:
                              - online
                              - offline
                              - missing
                              - new
                          seenTime:
                            description: When the device last checked in.
                            type: string
                          detailUpdatedAt:
                            description: How fresh the inventory below is.
                            anyOf:
                              - type: string
                              - type: 'null'
                          refetchRequested:
                            description: >-
                              True when a refresh of this host is already
                              queued.
                            type: boolean
                          uptime:
                            description: Nanoseconds since boot.
                            anyOf:
                              - type: number
                              - type: 'null'
                          lastRestartedAt:
                            anyOf:
                              - type: string
                              - type: 'null'
                          orbitVersion:
                            description: null means the device does not run the MDM agent.
                            anyOf:
                              - type: string
                              - type: 'null'
                          platform:
                            description: >-
                              Raw MDM platform: darwin | windows | ubuntu |
                              debian | fedora…
                            type: string
                          osVersion:
                            type: string
                          build:
                            anyOf:
                              - type: string
                              - type: 'null'
                          codeName:
                            description: OS code name; the edition string on Windows.
                            anyOf:
                              - type: string
                              - type: 'null'
                          gigsDiskSpaceAvailable:
                            description: Absolute free space in GB.
                            anyOf:
                              - type: number
                              - type: 'null'
                          mdm:
                            type: object
                            properties:
                              enrollmentStatus:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              name:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              serverUrl:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              connectedToFleet:
                                type: boolean
                              depProfileError:
                                type: boolean
                              deviceStatus:
                                description: unlocked | locked | wiped
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              pendingAction:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastEnrolledAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastMdmEnrolledAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastMdmCheckedInAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                            required:
                              - enrollmentStatus
                              - name
                              - serverUrl
                              - connectedToFleet
                              - depProfileError
                              - deviceStatus
                              - pendingAction
                              - lastEnrolledAt
                              - lastMdmEnrolledAt
                              - lastMdmCheckedInAt
                            additionalProperties: false
                          encryption:
                            type: object
                            properties:
                              diskEncryptionEnabled:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                              encryptionKeyAvailable:
                                description: >-
                                  Whether a recovery key is escrowed. The key
                                  itself is never returned.
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                              osSettingsStatus:
                                description: >-
                                  verified | verifying | pending |
                                  action_required | failed
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              osSettingsDetail:
                                description: >-
                                  The root cause when encryption is not
                                  verified.
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              appleActionRequired:
                                description: >-
                                  What FileVault is waiting for on a Mac.
                                  `log_out` and `rotate_key`: the end user logs
                                  out and back in. `turn_on_encryption`: the key
                                  is set to be escrowed but FileVault is not
                                  enforced and the disk is not encrypted, so no
                                  prompt reaches the end user; it is an admin
                                  setting to change.
                                anyOf:
                                  - type: string
                                    enum:
                                      - rotate_key
                                      - log_out
                                      - turn_on_encryption
                                  - type: 'null'
                            required:
                              - diskEncryptionEnabled
                              - encryptionKeyAvailable
                              - osSettingsStatus
                              - osSettingsDetail
                              - appleActionRequired
                            additionalProperties: false
                          profiles:
                            description: >-
                              All configuration profiles and their delivery
                              status.
                            type: array
                            items:
                              type: object
                              properties:
                                profileUuid:
                                  description: >-
                                    MDM identifier of the profile. Not a valid
                                    UUID despite the name — pass verbatim.
                                  type: string
                                name:
                                  type: string
                                status:
                                  description: >-
                                    MDM delivery status of the profile on the
                                    device.
                                  anyOf:
                                    - type: string
                                      enum:
                                        - verified
                                        - verifying
                                        - pending
                                        - failed
                                    - type: 'null'
                                operationType:
                                  anyOf:
                                    - type: string
                                      enum:
                                        - install
                                        - remove
                                    - type: 'null'
                                detail:
                                  description: >-
                                    Delivery error detail reported by MDM when
                                    the profile failed.
                                  type: string
                                scope:
                                  anyOf:
                                    - type: string
                                    - type: 'null'
                              required:
                                - profileUuid
                                - name
                                - status
                                - operationType
                                - detail
                                - scope
                              additionalProperties: false
                          labelNames:
                            description: MDM label names the device belongs to.
                            type: array
                            items:
                              type: string
                          idpUsername:
                            description: >-
                              Identity-provider account the MDM associates with
                              the device.
                            anyOf:
                              - type: string
                              - type: 'null'
                          idpFullName:
                            anyOf:
                              - type: string
                              - type: 'null'
                          bootstrapPackageStatus:
                            anyOf:
                              - type: string
                              - type: 'null'
                          bootstrapPackageDetail:
                            anyOf:
                              - type: string
                              - type: 'null'
                        required:
                          - fleetHostId
                          - uuid
                          - displayName
                          - hardwareSerial
                          - status
                          - seenTime
                          - detailUpdatedAt
                          - refetchRequested
                          - uptime
                          - lastRestartedAt
                          - orbitVersion
                          - platform
                          - osVersion
                          - build
                          - codeName
                          - gigsDiskSpaceAvailable
                          - mdm
                          - encryption
                          - profiles
                          - labelNames
                          - idpUsername
                          - idpFullName
                          - bootstrapPackageStatus
                          - bootstrapPackageDetail
                        additionalProperties: false
                      - type: 'null'
                  primo:
                    description: Device state Primo tracks itself, outside of MDM.
                    type: object
                    properties:
                      scriptsEnabled:
                        description: >-
                          Whether MDM scripts can run on the device — null when
                          unknown. Primo-verified, not the unreliable
                          agent-reported flag: no script remediation when false.
                        anyOf:
                          - type: boolean
                          - type: 'null'
                      naming:
                        description: >-
                          Expected versus actual device naming — the gap is what
                          a deviceNaming alert reports.
                        anyOf:
                          - type: object
                            properties:
                              name:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              computerName:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              hostname:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              computerNameSuggestion:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              hostnameSuggestion:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              mdmCommandInProgress:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                              lastMDMCommandRunAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              aiSuggestionFailure:
                                description: >-
                                  Why Primo could not generate the expected name
                                  — null when it never failed. After 3 attempts
                                  it stops trying; on NAME_COLLISION,
                                  conflictingDeviceId is the device holding
                                  attemptedName.
                                anyOf:
                                  - type: object
                                    properties:
                                      attempts:
                                        type: number
                                      lastAttemptAt:
                                        type: string
                                      failureType:
                                        anyOf:
                                          - type: string
                                            enum:
                                              - EMPTY_OUTPUT
                                              - NAME_COLLISION
                                              - SCHEMA_PARSE_ERROR
                                          - type: 'null'
                                      attemptedName:
                                        anyOf:
                                          - type: string
                                          - type: 'null'
                                      conflictingDeviceId:
                                        anyOf:
                                          - type: string
                                          - type: 'null'
                                    required:
                                      - attempts
                                      - lastAttemptAt
                                      - failureType
                                      - attemptedName
                                      - conflictingDeviceId
                                    additionalProperties: false
                                  - type: 'null'
                            required:
                              - name
                              - computerName
                              - hostname
                              - computerNameSuggestion
                              - hostnameSuggestion
                              - mdmCommandInProgress
                              - lastMDMCommandRunAt
                              - aiSuggestionFailure
                            additionalProperties: false
                          - type: 'null'
                      malwarebytes:
                        anyOf:
                          - type: object
                            properties:
                              protectionStatus:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              hasAgentInstalled:
                                type: boolean
                              hasAlerts:
                                type: boolean
                              lastActive:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastScriptRunAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                            required:
                              - protectionStatus
                              - hasAgentInstalled
                              - hasAlerts
                              - lastActive
                              - lastScriptRunAt
                            additionalProperties: false
                          - type: 'null'
                      sentinelOne:
                        anyOf:
                          - type: object
                            properties:
                              installed:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                              registeredAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastActiveDate:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              scanFinishedAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              uninstalledAt:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              infected:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                            required:
                              - installed
                              - registeredAt
                              - lastActiveDate
                              - scanFinishedAt
                              - uninstalledAt
                              - infected
                            additionalProperties: false
                          - type: 'null'
                      encryption:
                        anyOf:
                          - type: object
                            properties:
                              encrypted:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                              recoveryKeyRemotelyAvailable:
                                anyOf:
                                  - type: boolean
                                  - type: 'null'
                            required:
                              - encrypted
                              - recoveryKeyRemotelyAvailable
                            additionalProperties: false
                          - type: 'null'
                      recoveryOsStatus:
                        anyOf:
                          - type: string
                          - type: 'null'
                      localUsers:
                        description: >-
                          Local accounts on the device, with their creation
                          status and password-rotation state.
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                            username:
                              type: string
                            rights:
                              type: string
                            accountType:
                              type: string
                            creationStatus:
                              anyOf:
                                - type: string
                                - type: 'null'
                            creationSource:
                              type: string
                            groupName:
                              anyOf:
                                - type: string
                                - type: 'null'
                            passwordChangePending:
                              anyOf:
                                - type: boolean
                                - type: 'null'
                            passwordChangedAt:
                              anyOf:
                                - type: string
                                - type: 'null'
                            createdAt:
                              type: string
                          required:
                            - id
                            - username
                            - rights
                            - accountType
                            - creationStatus
                            - creationSource
                            - groupName
                            - passwordChangePending
                            - passwordChangedAt
                            - createdAt
                          additionalProperties: false
                    required:
                      - scriptsEnabled
                      - naming
                      - malwarebytes
                      - sentinelOne
                      - encryption
                      - recoveryOsStatus
                      - localUsers
                    additionalProperties: false
                required:
                  - fleet
                  - primo
                additionalProperties: false
              enforcement:
                type: object
                description: >-
                  How this control is enforced on this device. A key is present
                  only when the control carries that artifact, and a control can
                  carry several. All keys absent means the enforcement happens
                  outside MDM — read `device.primo`.
                properties:
                  profile:
                    type: object
                    properties:
                      fleetId:
                        type: string
                      resendable:
                        description: >-
                          Whether resendDeviceProfile would be accepted for this
                          profile right now — false for a declaration (which has
                          no per-device redelivery) and while a delivery is
                          already in flight (pending / verifying).
                        type: boolean
                      delivery:
                        description: >-
                          Delivery state of the profile enforcing this control
                          on this device — null when the profile never reached
                          the device.
                        anyOf:
                          - type: object
                            properties:
                              profileUuid:
                                description: >-
                                  MDM identifier of the profile. Not a valid
                                  UUID despite the name — pass verbatim.
                                type: string
                              name:
                                type: string
                              status:
                                description: >-
                                  MDM delivery status of the profile on the
                                  device.
                                anyOf:
                                  - type: string
                                    enum:
                                      - verified
                                      - verifying
                                      - pending
                                      - failed
                                  - type: 'null'
                              operationType:
                                anyOf:
                                  - type: string
                                    enum:
                                      - install
                                      - remove
                                  - type: 'null'
                              detail:
                                description: >-
                                  Delivery error detail reported by MDM when the
                                  profile failed.
                                type: string
                              scope:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                            required:
                              - profileUuid
                              - name
                              - status
                              - operationType
                              - detail
                              - scope
                            additionalProperties: false
                          - type: 'null'
                      content:
                        description: >-
                          The rendered configuration profile deployed to the
                          device.
                        anyOf:
                          - type: string
                          - type: 'null'
                    required:
                      - fleetId
                      - resendable
                      - delivery
                      - content
                    additionalProperties: false
                  script:
                    type: object
                    properties:
                      scriptId:
                        anyOf:
                          - type: number
                          - type: 'null'
                      source:
                        description: The enforcement script deployed to the device.
                        anyOf:
                          - type: string
                          - type: 'null'
                      lastExecution:
                        anyOf:
                          - type: object
                            properties:
                              status:
                                type: string
                                enum:
                                  - ran
                                  - pending
                                  - error
                              executedAt:
                                type: string
                              exitCode:
                                anyOf:
                                  - type: number
                                  - type: 'null'
                              output:
                                description: Tail of the script output (truncated).
                                anyOf:
                                  - type: string
                                  - type: 'null'
                            required:
                              - status
                              - executedAt
                              - exitCode
                              - output
                            additionalProperties: false
                          - type: 'null'
                      policies:
                        description: Compliance checks attached to this control.
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: number
                            name:
                              type: string
                            query:
                              description: The osquery check evaluated on the device.
                              type: string
                            resolution:
                              anyOf:
                                - type: string
                                - type: 'null'
                            response:
                              description: >-
                                Latest device response for the check — empty or
                                null when not yet evaluated.
                              anyOf:
                                - type: string
                                  enum:
                                    - pass
                                    - fail
                                    - ''
                                - type: 'null'
                          required:
                            - id
                            - name
                            - query
                            - resolution
                            - response
                          additionalProperties: false
                    required:
                      - scriptId
                      - source
                      - lastExecution
                      - policies
                    additionalProperties: false
                  software:
                    type: object
                    properties:
                      appId:
                        description: >-
                          The software this control installs — inspect it with
                          getDeviceSoftware.
                        type: string
                      install:
                        description: >-
                          Install state of that software on this device — null
                          when no install record exists.
                        anyOf:
                          - type: object
                            properties:
                              softwareId:
                                type: string
                              softwareName:
                                type: string
                              status:
                                type: string
                                enum:
                                  - installed
                                  - failed
                                  - in_progress
                                  - not_installed
                              installedVersion:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              availableVersion:
                                anyOf:
                                  - type: string
                                  - type: 'null'
                              lastInstalledAt:
                                anyOf:
                                  - type: string
                                    format: date-time
                                    pattern: >-
                                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                                  - type: 'null'
                            required:
                              - softwareId
                              - softwareName
                              - status
                              - installedVersion
                              - availableVersion
                              - lastInstalledAt
                            additionalProperties: false
                          - type: 'null'
                    required:
                      - appId
                      - install
                    additionalProperties: false
                  command:
                    type: object
                    properties:
                      id:
                        type: string
                      command:
                        type: string
                      status:
                        type: string
                      type:
                        anyOf:
                          - type: string
                          - type: 'null'
                      source:
                        type: string
                      initiator:
                        type: string
                      remoteId:
                        anyOf:
                          - type: string
                          - type: 'null'
                      payload:
                        description: >-
                          What was sent to the device — the script itself for
                          script commands.
                      result:
                        description: What the device answered.
                      uuid:
                        anyOf:
                          - type: string
                          - type: 'null'
                      createdAt:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      updatedAt:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                    required:
                      - id
                      - command
                      - status
                      - type
                      - source
                      - initiator
                      - remoteId
                      - payload
                      - result
                      - uuid
                      - createdAt
                      - updatedAt
                    additionalProperties: false
                additionalProperties: false
            required:
              - alert
              - mdmControl
              - device
              - enforcement
            additionalProperties: false
        notFoundAlertIds:
          type: array
          description: >-
            The requested ids that match no compliance alert of your company:
            the check no longer applies to that device. Asking again returns
            them here again.
          items:
            type: string
      required:
        - items
        - notFoundAlertIds
      additionalProperties: false
  securitySchemes:
    apikey:
      scheme: bearer
      bearerFormat: API key
      type: http
      description: >-
        Use your Primo API key in the Authorization header as `Bearer
        <API_KEY>`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.