miosa_audit_count_by_host | Count egress audit events grouped by destination host for a given resource and time window. Useful for building allowlists or detecting anomalous traffic patterns. |
miosa_audit_get | Fetch a single audit event by its ID. |
miosa_audit_query | Query the egress audit log. Returns events with host, action (allowed/denied), timestamp, and resource attribution. Supports filtering by resource, host, action, and time range. |
miosa_network_allow | Add an allow rule to the egress allowlist for a specific host. Optionally restrict by HTTP methods and path glob. Rules apply to the tenant policy or a specific resource policy. |
miosa_network_deny | Add an explicit deny rule to the egress allowlist for a specific host. Deny rules take precedence over allow rules. Use to block known-bad destinations even in observe mode. |
miosa_network_list_policies | List all egress policies in the tenant, with their mode and default effect. |
miosa_network_list_rules | List allowlist rules for a specific policy. Returns host, methods, path_glob, and effect for each rule. |
miosa_network_lockdown | Switch egress policy to enforce mode - all traffic not explicitly allowed will be blocked. Use miosa_network_allow to whitelist destinations before calling this. |
miosa_network_observe | Switch egress policy to audit-only (observe) mode - traffic is logged but not blocked. Use this to build an allowlist before enforcing with miosa_network_lockdown. |
miosa_network_suggestions | Return AI-generated allowlist suggestions derived from recently observed egress traffic. Use these as input to miosa_network_allow to build a policy before switching to enforce mode. |
miosa_oauth_providers_list | List OAuth providers configured and visible to the calling tenant. Use provider slugs from this list as input to miosa_secrets_connect_oauth. |
miosa_secrets_connect_oauth | Start an OAuth 2.0 connect flow for the given provider. Returns authorize_url (which the user must open in a browser) and a poll_url to check completion status. Call miosa_audit_query or GET the poll_url until status=completed. |
miosa_secrets_delete | Delete a secret and remove all associated bindings. Resources that were injecting this secret will no longer receive it. |
miosa_secrets_list | List secrets visible to the calling tenant. Returns metadata only (name, type, scope, id) - plaintext values are never returned. Filter by scope, workspace, or owner identity. |
miosa_secrets_rotate | Rotate a secret’s value in-place. All existing bindings continue to reference the same secret_id and pick up the new value automatically. |
miosa_secrets_set | Create a secret and optionally bind it to a resource so it is injected as an environment variable. Provide expose_as_env + resource_id + resource_type to auto-bind. |