OptionalconnectorsOptionalpayloadOptionalpriorityOptionalrequestedOptionalrequestedTrusted requester kind paired with requestedBy.
OptionalresumeRuntime resume ordinal of that suspension, observed from
RunSummary.resumeCount by the same bridge — undefined for a first
suspension, 1,2,… on re-suspensions. Pairs with suspendedAt as the
collision-free grant-binding tie-breaker.
OptionalresumedEpoch-ms resumedAt of that suspension, observed from RunSummary.resumedAt by the same bridge. INFORMATIONAL only — not the grant tie-breaker.
OptionalrunOpt in to a run-scoped standing grant (mints on every leg). Create-time only — see ApprovalRecord.runScoped. Never settable over HTTP.
OptionalslaSeconds from creation to the SLA deadline; overrides the service default.
OptionalstepOptionalsummaryOptionalsuspendedEpoch-ms suspendedAt of the suspension this approval binds to, observed from RunSummary.suspendedAt by the creating bridge (core clock, so grant minting is clock-free: mint requires record.suspendedAt to EXACTLY match the resumed leg's suspension). A capability-bearing record without it is inert.
OptionaltoolMastra tool-call identity captured from a durable-agent suspension. Trusted creation only; never accepted over HTTP.
Trusted requester provenance. New writes must provide it together with
requestedByKind; the HTTP create route derives both from authentication.