> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Sanction Service

> Mark a discovered service as sanctioned (allowed, no longer shadow).

Sanctioning is the decision that this is not shadow AI, so it also takes the
service out of whatever the shadow-AI posture was doing to it:

* a ``block`` rule is cleared, so approving a tool is a real way back from
  banning it rather than a status change the agent never hears about;
* the "protect unapproved AI" floor stops applying, because the setting says
  *unapproved* and this one now is. Written as an explicit ``observe`` rule,
  since the floor would otherwise re-protect it on the next merge.

An admin who wants an approved tool inspected can still protect it by hand;
that is a decision about this service, not a side effect of a posture aimed
at the ones nobody vetted.

Both of those follow from the status alone, so the rule is written by
``_apply_decision`` rather than here. The version that reasoned about it
inline treated them as alternatives and never did the second after the
first.



## OpenAPI

````yaml /api-reference/openapi.json post /api/runtime-security/discovery/{service_uuid}/sanction
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/discovery/{service_uuid}/sanction:
    post:
      tags:
        - runtime-security-discovery
      summary: Sanction Service
      description: >-
        Mark a discovered service as sanctioned (allowed, no longer shadow).


        Sanctioning is the decision that this is not shadow AI, so it also takes
        the

        service out of whatever the shadow-AI posture was doing to it:


        * a ``block`` rule is cleared, so approving a tool is a real way back
        from
          banning it rather than a status change the agent never hears about;
        * the "protect unapproved AI" floor stops applying, because the setting
        says
          *unapproved* and this one now is. Written as an explicit ``observe`` rule,
          since the floor would otherwise re-protect it on the next merge.

        An admin who wants an approved tool inspected can still protect it by
        hand;

        that is a decision about this service, not a side effect of a posture
        aimed

        at the ones nobody vetted.


        Both of those follow from the status alone, so the rule is written by

        ``_apply_decision`` rather than here. The version that reasoned about it

        inline treated them as alternatives and never did the second after the

        first.
      operationId: >-
        sanction_service_api_runtime_security_discovery__service_uuid__sanction_post
      parameters:
        - name: service_uuid
          in: path
          required: true
          schema:
            type: string
            title: Service Uuid
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````