Exceptions API

Exceptions are time-bound, tenant-scoped, auditable objects that change policy outcomes in StellaOps without mutating upstream evidence. Use them for waivers, compensating controls, and scoped suppressions in a way that is fully replayable offline.

Audience: integrators and operators automating exception governance. This document is the entry point for exception contracts; the concrete request/response shapes live in the gateway and Console schemas listed under API Surfaces.

Core Concepts

API Surfaces

Security & Headers

Common requirements across endpoints:

Scopes vary by deployment, but typically follow:

Offline / Air-Gap