> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply a change the assistant proposed.

> Only the member the change was put on screen for may apply it, and only while they hold the permission the change itself needs. The change is carried out as it was shown and refused once the record has moved past it.



## OpenAPI

````yaml /openapi-public.json post /agent/proposals/{id}/apply
openapi: 3.1.1
info:
  title: Klef API
  description: Klef's multi-tenant HRIS sync platform API.
  version: v1
servers:
  - url: https://{workspace}.klef.ai/api
    variables:
      workspace:
        default: acme
        description: Your workspace's subdomain.
security: []
tags:
  - name: Users
  - name: Connections
  - name: Adoption
  - name: Policy resources
  - name: Audit
  - name: Catalog
  - name: Sync
  - name: Search
  - name: SyncPlans
  - name: Agent
  - name: Auth
  - name: Workspaces
  - name: Billing
  - name: Invitations
  - name: FirstSignIns
  - name: Connection accounts
  - name: Policies
  - name: Secrets
  - name: Lookup tables
  - name: Scripts
  - name: Segments
  - name: ApiKeys
  - name: Members
  - name: Workers
  - name: Inbox
  - name: Notifications
paths:
  /agent/proposals/{id}/apply:
    post:
      tags:
        - Agent
      summary: Apply a change the assistant proposed.
      description: >-
        Only the member the change was put on screen for may apply it, and only
        while they hold the permission the change itself needs. The change is
        carried out as it was shown and refused once the record has moved past
        it.
      operationId: ApplyAgentProposal
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponseOfApplyAgentProposalResponse'
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '404':
          description: Not Found
        '409':
          description: Conflict
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
      security:
        - cookieAuth: []
        - apiKeyAuth: []
components:
  schemas:
    ApiResponseOfApplyAgentProposalResponse:
      required:
        - result
        - errors
      type: object
      properties:
        result:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/ApplyAgentProposalResponse'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ApiError'
      description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
    ApplyAgentProposalResponse:
      required:
        - message
      type: object
      properties:
        message:
          type: string
      description: What the change came to, in the words the assistant would have used.
    ApiError:
      required:
        - errorCode
        - errorMessage
      type: object
      properties:
        errorCode:
          $ref: '#/components/schemas/ApiErrorCode'
        errorMessage:
          type: string
        target:
          type:
            - 'null'
            - string
      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
    ApiErrorCode:
      enum:
        - validation_error
        - unauthorized
        - forbidden
        - not_found
        - internal_error
        - error
        - precondition_required
        - precondition_failed
        - invalid_if_match
        - worker_not_found
        - worker_version_not_found
        - connection_not_found
        - policy_not_found
        - policy_revision_not_found
        - lookup_table_not_found
        - script_not_found
        - segment_not_found
        - workspace_secret_not_found
        - member_not_found
        - invitation_not_found
        - user_not_found
        - workspace_not_found
        - api_key_not_found
        - inbox_item_not_found
        - sync_plan_not_found
        - connection_account_not_found
        - managed_account_not_found
        - adoption_run_not_found
        - sync_plan_not_ready
        - sync_plan_stale
        - sync_plan_already_applying
        - subdomain_taken
        - invalid_subdomain
        - invalid_invite
        - last_owner_protected
        - owner_protected
        - already_member
        - already_invited
        - role_not_assignable
        - invalid_email
        - email_required
        - email_mismatch
        - invitation_gone
        - invalid_connector_credentials
        - wrong_connector_type
        - connection_not_syncable
        - connector_o_auth_not_configured
        - connector_authorization_failed
        - salesforce_manage_users_required
        - box_admin_required
        - linear_admin_required
        - dropbox_admin_required
        - invalid_match_rule
        - adoption_run_composed
        - adoption_run_empty
        - adoption_selection_refused
        - invalid_policy
        - policy_does_not_compile
        - policy_secret_missing
        - policy_lookup_table_missing
        - policy_script_missing
        - policy_segment_missing
        - policy_edit_target_missing
        - policy_secret_disclosure_forbidden
        - notification_send_failed
        - invalid_workspace_secret
        - workspace_secret_referenced
        - workspace_secret_name_conflict
        - invalid_lookup_table
        - lookup_table_referenced
        - lookup_table_name_conflict
        - invalid_script
        - script_name_conflict
        - script_referenced
        - invalid_segment
        - segment_name_conflict
        - segment_referenced
        - segment_worker_missing
        - api_key_scope_not_granted
        - api_key_limit_reached
        - subscription_required
        - already_subscribed
        - no_billing_customer
        - workspace_pending_deletion
        - workspace_deletion_confirmation_mismatch
        - workspace_deletion_already_scheduled
        - workspace_deletion_not_scheduled
        - workspace_export_expired
        - workspace_export_not_found
        - agent_conversation_not_found
        - agent_proposal_not_found
        - agent_proposal_outdated
        - agent_proposal_expired
        - agent_proposal_already_applied
        - agent_proposal_rejected
        - notification_kind_unsupported
        - first_sign_in_not_found
        - first_sign_in_gone
        - first_sign_in_not_a_recipient
        - first_sign_in_recipient_unknown
        - first_sign_in_locked
        - first_sign_in_code_refused
        - first_sign_in_proof_invalid
        - password_reset_unsupported
        - invalid_password_rules
        - avatar_not_owned
        - unsupported_image_type
        - image_too_large
      description: The central catalog of every error returned by the API.
  securitySchemes:
    cookieAuth:
      type: apiKey
      description: >-
        Cookie-based session. Obtain by completing the `/auth/login/{provider}`
        OAuth flow; the `/auth/callback` response sets the `klef.session` cookie
        that subsequent requests send automatically.
      name: klef.session
      in: cookie
    apiKeyAuth:
      type: http
      description: >-
        An API key from **Settings > API keys**, sent as `Authorization: Bearer
        klef_sk_…`. A key works only on its own workspace's subdomain, and only
        with the permissions its scopes grant.
      scheme: bearer
      bearerFormat: klef_sk_…

````