---
id: action-item-create
title: "Create an action item"
description: "Create a new action item. The item is created in `open` status."
sidebar_label: "Create an action item"
hide_title: true
hide_table_of_contents: true
api: eJztW3tv2zgS/yoD/tNdQHacV7c1UOCyaReX2+0DTbq7d3EQ09JIYiuRWpJy4hr+7ochJVmyndhpdgvsXYvCdWWSMxzO88fRnEVoQi0KK5RkQ3aqkVsEDhJvgIf0FITFvA8XKbpvIAyEblQEQsJYFSjHYCy3pemP5Ej+OIMIY15mNgCboh+sNM0zaCHWKnfPeWlTlFaEbqnSoH5iYIJcowarPqH0NMcVsevJbAyxwCyilZTMZpAqqTRGECsNIc8y1AZuhE0hwgwT7pjXIkmtge9oDN7yvMgwAJ6gtCCkxUS7YcZxo7T4jBFYVW3Q7ZdowQRTnsWgYlA2Re24Nd/3R5IFTBXoFzmL2JB5mV3TzKFfhQXM8sSw4SU78QI9s5izq4AZDEst7IwNL+fM7/yktCkbXl4trgKm8Y8Sjf1RRTM2nLv/Co0RG1pdYsBCJS1KSz/xoshIjkLJvY+GDnLOTJhizumbnRXIhkxNPmJoWdBa6JJJTVuwwmZIHBWadmMFGppIPy7nG6uFTFiwojF0Rm/evwGbcgvqRhqwqTAd3WEBq0RPbOiES/HZMftif8jDUJXSvjgYSp6jKXiILw6HrQ29OGKLmsOtzJyASZW2ATSPpwhurlMSp3Z3MfahSDSPECbcIIicJ0iaEItbOP31Ve9gcPC0t39w6LjpEN3OU4SWiwwjaP1AukTsCGNK7MN5WRRKWwOvuf4UqRvZ5Y2EHJZak9q2+Eu5AQ6hFmRFGUzLTKLmE5EJO+sTo2RbidKzaxHtdpL1BDh72YcPBgGFU/hxa6UxqPYDk5XJOACpLEyUTbuM80m4f3AYYXx0/LTDEM16IEs05U9hqra7XltgpPMLsgChvE2u84ayzMloMnXDApZjJMqcBSwVScoCVh8D2VF3F++qNSHDKWZ9eOndoyH9Gvtlxl0Om7VIZI3/201emHORkTQqLxeRk40F6lrlKofch7MYCq2mIsKoctXOiUJeGgsTXPGJPLRdV+gsnjzhHdI1IZcSdc/xQTuZ8qxsG7Es8wnqzZswVuQuMExQYiwsEdRoVDYVMvEuhkw4oBhErJdSWIo7QtKcGQhrGs3p8Hc8GJAFl3gdkXPeINJY6ZxbNmQ0oGdFjmssvnVfeAYR8igT0ruXDfz14ez8LTx7OtiHZrWuuJxjGRz3BvsXg8HQ/f0PCSvjE8zMJv/No0h48u867rq7j1U3xX7GWc+dABRcaOOjZsaNEXHlajuMzZlRpQ6dNippuaCjpCMlVZ/S4xW3uAgYj2MMSVdJEjS5zRfXms/WJPm+Hgn1ZDo9Lz/vGl/zWzge+FhMHLovm+RSbJDGLgZTMws0dMV9LeMQCZRC1APXpCndNfNZjxeiZ1BPRYjO56DOeSbkp12CCY0jc7QtKl0CqbWFGe7t8aLoyzLLioxb0ul+qPK91o7M3pcEs4kWGLcjWZf4ay4knLw7g2Z/y+jNTqojrg/d/agxRo1yF2V5dWtRk9kt54DGzPkJJ5LG6khpDh6uNA854IqDDSe8li884oArKptPWE6jvhTG9hM13aNgtudTjb3HZixbDvnNry8BpdWzKqsSppt7dA79fb0H9zRHyyNuNyamXS5+yvBWTDKEeooj5oNahFHZ6DFwGUEsMou0mxUnFk7RJT8rhxKwKjqxIbNaTD3LoZKxSLaz9pK2pHkGmcgp0DjGluEGTgqKqzwDKkJk0goOSKlpjDpwTGuk5UdSGJAKMiUT1OCZKKmwSVFjH84sVTyRFlOU5Bx5vbpPZU0dAuvnZiRRJkJSWonofhq3ypIxHR1lI9W0htmTd2e+ounaRM5vr6Nqw9cRn7XNyJVQG0L4a34r8jIHH+EpdtNE4D7vhpBTHuEloV0dWel7XNpSd5X9OYXrDg+uYPgiJij63slFh+phW4NPq4M99eqxcH/IcZlCSeOldDDYp382pK9VrbxSd3xx9dY9nF3z+lKKP8pO8UMZfseob//9+Ydnz08mp9GrmFzGbhn6SWlVL0Gyfdrlh/e/9GItUEZZlbB3aJS+xupRDdNzNUzPql4sbnvhFLse6+9XfBIzbujXqSuJXNtD/1U1pId27quHCAKiGCuvC60SjcaQnqKMhEwas3X8e0tr/TpF3aSfDppwTrI9wvvI+uePLn8g+8mUwWi91mrvsgKluhpAvH6dOu/Ois6ESuMODuyUZ2Hpsxs3xR1bREWYz+MphNT76FA7GLgi51HV/71l/I6V3KttVRyu26ivzx5a9NYg453F7641KtVDiUTsyuyuEyLS7RTblcNw9rJBdyzmTwx5Jgr5hFDQ6DHcpChBqomKZt5tCds9wMOj4yUz0TW3m8SwQ6H6GxGyLZvwS+b09YYbyHmEu9aoz3oHg4v9o+HhQV2jNvztcky/pcqRu4OdIXAvveURyi2n+JFL/Ef1Xypu2F9Q2H95AV97u+tSWpFt5Wc9ySQE2s2Fm1SEaaNQLhvclLSQbi2WTnQXrdlM9abWGkeO9KRecxO9/1mk4hvS8H+ENHxDCP7+CMFutf+icc4PKCbfrBSRDdbkEugJotzskwffYIVvsMJusAIpSk6p0HYg9LQaSLVAC/V8p4qqXqCbb+TRA6DPnWsET3qtRAhzu39wuIQP/OXRw9b0c7YneS3wZPfFLd7a1YqYehJSVWZUoNSllLvvqm+LJd5aMIUW0vbbl3FfnJC7BgsCJ5zSWJ4Xm7LJo97gqUu1KZvsD1xG2dYcvyWfyZSRsNeZSrZrzQkNBatdfh0Dz7KqRKZn0oiqE8KhqdRnURa0jxUlu0+j1i7jhUwyukckuplKqpCgMVSainvg6wxQ5t8mDw7gXYV0HoeCrfCzqsqH4eFx/PyHw150fDjpHeHTQY8f//Csd4DP4gnfjyaTyb5T8dDuquFVUeOrQlfm3KQKCtSkMnR70XQmbNd+P243upXYHD5GeXxDsUumQWZcaKQEYZfzbbJ7cAZ5a4FPVGlbmwnAlGEKRFjjVKjSqxc1F1UHX9lZ7YXJa5m1/J56hmrsJmBWtTmmtI4bX2Fy0cTFxnhzTo5cckrEboSM1E2/sqXK/h5bWVcivke6bZs+8BXiuk074/xFJf4i4mu6mS5LAfN29wjiv3Bja+t9MP22SJxkXbeUR9yPfv99HWQ/zQS5d9Tap0Mek4eodDirkFOeCcoFitIGkAtDTgkKrnmOFrVxsEwpW70OPAzR+F62974FC9waXqCOjiEbBg6RiF3qasGkvMDhSI7HY8LwR3I+kgAjJ74RG8KI/dqs8YqWGLHAj/AL0pjLOYxYjsbwpJrjACLXjpHyKSX7vnMLKvc3gyfODjzE8GTEYHE1kgvHhUu5dr5lUBLfxq4P7X6bP7dcRlxHK+Lur7SVeeM+VREphxvqgFS3s/U+s9bo7enXPy8u3tXOI1QRwnfYT/oBHA0G9LFPH4f0cfR9R+WOPK7YJXKH53zNw1RI7FEKxanA8LulyV01nnBCEJyOkOX4nW5d/px61DY1g3ky6+DAjzyC90sytSC3l2lLD1159ZaHdsTWrwiq7VToYFbFJ7d7j61EjU0tjYhc6iLYpjx3WdOdauSWq8Rq1vXmLuBluaEVm2vO6BEAwD3Cb+nFVrv1FlvdJV5593a8yb2do54SKrri3oSMnDVTEiV9q4zP09BjIsKr6p/SJPo1rVljodFQKVldEJgCQ8L9HMxTC2LTjcFOln0C+d227dOkqt4Wn12VjzXdmItstYh026KGlGs/6Bo7WrYzjhJAWuZcLnl6gG84q1iASlEaRf/LvMSJhFLibeG7tTxfKnSIflTroJdHv9Jvj+qkirCYQhlnVJwandleC0Ggpgw3zbhAVOqsAzGKNYiRLVpN1Oekyl4D263UzeZpIdf2QcPIRN0gFlRffqrTmn/9duGSEDKR98sO7FfLbNTdTH/JVfIys9n1Tvi+282d73BXLgK7l3lrLbl3d8e2L02X95ndu7q7btaaK8PjwaB9SbP59qR9p/BAbH8ztL/Ma9o4ew2zrwLlHTj2QSD3eiKxilFfdWHoyxpRXutP2sTCjmjuGna5FYy96sKuuzdNtcHNDYje88FmkM3hYELGiuaRxXtG9/uD/oCtFgDufQnfnK2Mzblc4vDN+yodgGBVAPNlGPz2gsvDX3CpLIcK/L0i48JdUDnvPK/c+GX7tRfKCFJy8sNLNp+Tl/qgs8WCHv9Roqa3Xa7IHWhBoc697BKwFHlEenU5Z59w5iAud2K9C58CVt5jPYmhrNPPOAlDLOy9Y69acejd2/ML8v7V2zW5Sx+Y5tTyQZ9D5t7tccKjAe7ZnGVcJqULq8yvuaiwzlaoWQktHfcjZy0O53M/4oK0YbFgQbUVpx3MpYX/BdMrhK8=
sidebar_class_name: "post api-method"
info_path: docs/api/action-items
custom_edit_url: null
---

import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import ParamsDetails from "@theme/ParamsDetails";
import RequestSchema from "@theme/RequestSchema";
import StatusCodes from "@theme/StatusCodes";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";
import Heading from "@theme/Heading";

<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Create an action item"}
>
</Heading>

<MethodEndpoint
  method={"post"}
  path={"/action_item"}
  context={"endpoint"}
>
  
</MethodEndpoint>



Create a new action item. The item is created in `open` status.

By default, the creator is set from the authenticated user's bearer token. The `created_by` field is only honored for callers with delegation rights (for example, agent integrations authorized to create items on behalf of other users).


<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={undefined}
>
  
</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["nrn","title"],"properties":{"nrn":{"type":"string","description":"The NRN that owns this action item.","example":"organization=1:account=2:namespace=3:application=4"},"title":{"type":"string","description":"A short, descriptive title for the action item.","example":"Upgrade base image to fix CVE-2026-1234"},"description":{"type":"string","description":"A detailed description of the issue. Supports Markdown.","example":"The current base image has a critical vulnerability."},"category_id":{"type":"string","description":"The category ID. Use either `category_id` or `category_slug`, not both.","example":"abc123def456"},"category_slug":{"type":"string","description":"The category slug. Use either `category_id` or `category_slug`, not both.","example":"security-vulnerabilities"},"priority":{"type":"string","enum":["low","medium","high","critical"],"description":"Priority level. Defaults to `medium`.","example":"critical"},"created_by":{"type":"string","description":"The email or agent identifier of the creator. If provided, the caller must be authorized to act on behalf of that user.","example":"security-scanner-agent"},"value":{"type":"number","description":"The estimated benefit of resolving this item, in the unit defined by its category.","example":500},"due_date":{"type":"string","format":"date-time","description":"Optional deadline for resolving this item. ISO 8601 date-time.","example":"2026-05-01T00:00:00Z"},"labels":{"type":"object","additionalProperties":{"type":"string"},"description":"Key-value pairs for classification.","example":{"source":"container-scan","cve":"CVE-2026-1234"}},"affected_resources":{"type":"array","description":"Resources affected by this issue. Max 50 items.","items":{"type":"object","properties":{"type":{"type":"string","description":"The resource type.","example":"application"},"name":{"type":"string","description":"The resource name.","example":"my-api-service"},"permalink":{"type":"string","description":"A link to the resource.","example":"https://app.nullplatform.com/applications/4"},"description":{"type":"string","description":"A brief description.","example":"Main API service"}},"title":"AffectedResource"}},"references":{"type":"array","description":"External references related to this item. Max 20 items.","items":{"type":"object","properties":{"name":{"type":"string","description":"The reference name.","example":"CVE-2026-1234"},"permalink":{"type":"string","description":"A link to the reference.","example":"https://nvd.nist.gov/vuln/detail/CVE-2026-1234"},"description":{"type":"string","description":"A brief description.","example":"NVD entry for this vulnerability"}},"title":"Reference"}},"metadata":{"type":"object","description":"Flexible metadata for agent deduplication and filtering.","example":{"cve_id":"CVE-2026-1234","scanner":"trivy"}},"config":{"type":"object","description":"Deferral limits for a category. Approval gating for resolve, defer, and reject\nis no longer configured here. It is driven by approval actions in the approvals\nengine. See the `action_item` entity in the Approval API.\n","properties":{"max_deferral_days":{"type":"integer","description":"Maximum number of days an item can be deferred into the future.","example":90},"max_deferral_count":{"type":"integer","description":"Maximum number of times an item can be deferred.","example":3}},"title":"CategoryConfig"}}}}}}}
>
  
</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"201":{"description":"The created action item.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","description":"The unique action item ID.","example":"xYz789AbCdEf"},"slug":{"type":"string","description":"Auto-generated URL-friendly slug.","example":"upgrade-base-image-to-fix-cve-2026-1234"},"nrn":{"type":"string","description":"The NRN that owns this action item.","example":"organization=1:account=2:namespace=3:application=4"},"title":{"type":"string","description":"The title.","example":"Upgrade base image to fix CVE-2026-1234"},"description":{"type":"string","description":"The description. Supports Markdown.","example":"The current base image has a critical vulnerability."},"status":{"type":"string","enum":["open","in_progress","pending_deferral","deferred","pending_verification","resolved","pending_rejection","rejected","closed"],"description":"The current status.","example":"open"},"priority":{"type":"string","enum":["low","medium","high","critical"],"description":"Priority level.","example":"critical"},"score":{"type":"integer","description":"Calculated score based on value and priority.","example":2000},"category_id":{"type":"string","description":"The category ID.","example":"abc123def456"},"value":{"type":"number","description":"Estimated benefit of resolving the item.","example":500},"created_by":{"type":"string","description":"The creator email or agent identifier.","example":"security-scanner-agent"},"assignee_id":{"type":"integer","description":"The nullplatform user ID of the item's owner, or `null` when nobody owns it.","example":2345},"assigned_at":{"type":"string","format":"date-time","description":"When the current assignment was made. ISO 8601 date-time.","example":"2026-08-20T14:32:00Z"},"assigned_by":{"type":"string","description":"Who made the current assignment: a user email or an agent identifier.","example":"jane@example.com"},"due_date":{"type":"string","format":"date-time","description":"Optional deadline. ISO 8601 date-time.","example":"2026-05-01T00:00:00Z"},"deferred_until":{"type":"string","format":"date","description":"Date until which the item is deferred.","example":null},"resolved_at":{"type":"string","format":"date","description":"Date when the item was resolved.","example":null},"labels":{"type":"object","additionalProperties":{"type":"string"},"description":"Key-value pairs for classification.","example":{"source":"container-scan","cve":"CVE-2026-1234"}},"affected_resources":{"type":"array","items":{"type":"object","properties":{"type":{"type":"string","description":"The resource type.","example":"application"},"name":{"type":"string","description":"The resource name.","example":"my-api-service"},"permalink":{"type":"string","description":"A link to the resource.","example":"https://app.nullplatform.com/applications/4"},"description":{"type":"string","description":"A brief description.","example":"Main API service"}},"title":"AffectedResource"}},"references":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string","description":"The reference name.","example":"CVE-2026-1234"},"permalink":{"type":"string","description":"A link to the reference.","example":"https://nvd.nist.gov/vuln/detail/CVE-2026-1234"},"description":{"type":"string","description":"A brief description.","example":"NVD entry for this vulnerability"}},"title":"Reference"}},"metadata":{"type":"object","description":"Flexible metadata.","example":{"cve_id":"CVE-2026-1234"}},"deferral_count":{"type":"integer","description":"Number of times this item has been deferred.","example":0},"config":{"type":"object","description":"Deferral limits for a category. Approval gating for resolve, defer, and reject\nis no longer configured here. It is driven by approval actions in the approvals\nengine. See the `action_item` entity in the Approval API.\n","properties":{"max_deferral_days":{"type":"integer","description":"Maximum number of days an item can be deferred into the future.","example":90},"max_deferral_count":{"type":"integer","description":"Maximum number of times an item can be deferred.","example":3}},"title":"CategoryConfig"},"comments":{"type":"array","description":"Comments on this item. Populated on read.","items":{"type":"object","properties":{"id":{"type":"string","description":"The comment ID.","example":"cmt123AbCdEf"},"author":{"type":"string","description":"The comment author.","example":"jane@example.com"},"content":{"type":"string","description":"The comment text.","example":"This should be prioritized for the next sprint."},"created_at":{"type":"string","format":"date-time","description":"Creation timestamp.","example":"2026-04-06T14:30:00.000Z"}},"title":"Comment"}},"audit_logs":{"type":"array","description":"Audit trail of all status transitions and field updates on this item.","items":{"type":"object","description":"A single audit log entry recording a status transition or field update on an action item.","properties":{"id":{"type":"string","description":"The unique audit log entry ID.","example":"3c35f973-d53b-4e60-a578-2e8fba1dbbb1"},"actor":{"type":"string","description":"The email of the user who performed the action.","example":"jane@example.com"},"action":{"type":"string","description":"The action that was performed.","example":"deferred"},"details":{"type":"object","description":"Additional context about the action, such as previous and new status or the deferral reason.","example":{"from":"open","to":"deferred","reason":"Waiting for the next maintenance window."}},"timestamp":{"type":"string","format":"date-time","description":"When the action was performed.","example":"2026-04-06T12:00:00.000Z"}},"title":"AuditLog"}},"created_at":{"type":"string","format":"date-time","description":"Creation timestamp.","example":"2026-04-06T12:00:00.000Z"},"updated_at":{"type":"string","format":"date-time","description":"Last update timestamp.","example":"2026-04-06T12:00:00.000Z"}},"title":"ActionItem"}}}},"4XX":{"description":"Client error responses due to invalid input, missing parameters, or unauthorized access.\n\nRequest validation errors use a different shape:\n```json\n{\n  \"type\": \"ValidationError\",\n  \"errors\": [{ \"message\": \"body must have required property 'defer_until'\" }]\n}\n```\n","content":{"application/json":{"schema":{"oneOf":[{"type":"object","description":"Standard error response.","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"Machine-readable error code.","example":"bad_request"},"error":{"type":"string","description":"Short description of the error type.","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}},{"type":"object","description":"Request validation error response.","required":["type","errors"],"properties":{"type":{"type":"string","example":"ValidationError"},"errors":{"type":"array","items":{"type":"object","properties":{"message":{"type":"string","example":"body must have required property 'until'"}}}}}}]}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error.","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type.","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred on the server."}}}}}}}}
>
  
</StatusCodes>


      