opted_out=true triggers an immediate
purge of every existing card about the user across every agent in the current
workspace, and of their operator model — it does not wait for the next
routine sweep.
The operator model is a separate surface with its own endpoints below: one
short profile per (user, workspace) holding the role, ownership and standing
constraints that person has stated. It records only what they said, never what
the system inferred. The endpoints let a person read it and drop a single wrong
entry without turning the whole feature off.
List My Peer Cards
200 OK
Peer Card Fields
Purge My Peer Cards
200 OK
Get Peer Consent
200 OK
Set Peer Consent
opted_out=true triggers an immediate
purge of all existing peer cards about the user in this workspace, alongside
the consent change and an audit row.
Auth: Any authenticated user (own data only)
Request Body:
200 OK
purged reflects the number of peer cards removed by the opt-out and
purged_models the operator model (0 or 1). Both are 0 when opting back in.
Get My Operator Model
- key: value bullet split into a field. A read is
recorded in the peer-card audit log with action='read'.
Auth: Any authenticated user (own data only)
Response: 200 OK
exists: false with an empty facts array means nothing has been recorded
about this person in this workspace yet. content and facts are omitted when
the server has no memory storage path configured.
Forget One Field
{key} is a field name from the
facts array above; matching is case-insensitive.
Removing the last remaining field removes the model entirely (an empty model is
not a model), which the response reports as exists: false.
Auth: Any authenticated user (own data only)
Response: 200 OK
Purge My Operator Model
PUT /users/me/peer-consent
with opted_out: true to stop recording altogether.
Auth: Any authenticated user (own data only)
Response: 200 OK