Skip to main content
The Notes API lets you attach simple text records to a top-level Field Model V1 entity (such as an event, exposure, quote, submission, person, organization, or policy). A note is just a body of text scoped to its parent entity. Key Concepts:
  • Parent entity: Every note belongs to a parent entity, identified by entityType (a lowercase kebab-case wire slug — one of event, exposure, quote, submission, person, organization, policy) and entityId. The entityType is supplied as a query parameter on every endpoint. PascalCase like Event is rejected with a 400.
  • Body: The note body is a free-text string and must not be empty. It is the only field you can update.
  • Listing: List returns a parent entity’s notes newest first. Select the parent with the entityType and entityId query parameters, and pass search to filter to notes whose body contains a substring (case-insensitive).
  • Audit fields: Responses include createdAt/createdBy and updatedAt/updatedBy, plus a resolved createdByName for display.
  • Soft delete: DELETE soft deletes the note; it no longer appears in list or get responses.

API Endpoints

The five Notes endpoints are listed in the left navigation:
  • List Notes (GET /notes) - Paginated list of a parent entity’s notes, newest first
  • Create Note (POST /notes) - Create a note on a parent entity
  • Get Note (GET /notes/{noteId}) - Retrieve a note by ID
  • Update Note (PATCH /notes/{noteId}, PUT alias) - Update the note body
  • Delete Note (DELETE /notes/{noteId}) - Soft delete a note

Permissions


Privileged notes

Every note carries a privileged flag. A privileged note is restricted commentary — the coverage-counsel call, the fraud referral — and the note.view-privileged permission is the single gate on it: reading one, marking a note privileged, un-marking it, editing it, and deleting it all require that permission on top of the ordinary per-action one. Without it a privileged note is simply absent: it never appears in a list or the totalCount, and GET, PATCH, and DELETE by its ID all answer 404. Sending privileged on a create or update — true or false — is itself the privileged act, so a caller without the permission is refused with 403 rather than silently ignored. Generated documents and AI note summaries are built from ordinary notes only, so a privileged note never leaks through them.

Filtering (List Notes)


Pagination

The list endpoint uses 1-based pagination: page=1 is the first page. Use pageSize to control the number of records per page (default 50).