/** * SIEM pricing/applicability lens — "what would this look like on ?" * * The demo pipeline (and any single customer env) has ONE actual destination, * but prospects evaluate against THEIR stack. The lens lets a cost-bearing * tool price the SAME real volumes at a different destination's list rates * and gate actions by that destination's rules, without pretending the * pipeline destination changed. * * Honesty contract (enforced by callers via this resolution): * - Volumes/patterns are never lensed — they are real measurements. * - A lensed run ALWAYS prices at the lens destination's list price * (the env-configured analyzerCost belongs to the ACTUAL destination * and must not leak into another SIEM's story). An explicit caller * rate arg still wins — that is the caller asserting their own rate * for the lens. * - Applicability gating (compact/tier_down/...) follows the lens. * - The envelope stamps both sides (siem_actual / siem_lens) so a * receipt reader can verify the story matches the math. */ import type { SiemId } from './pricing.js'; /** The destinations a lens may target = the destinations we can price. */ export declare const SIEM_LENS_IDS: SiemId[]; export interface SiemLensResolution { /** Canonical actual destination of the connected pipeline (null if unknown). */ actual: SiemId | null; /** Destination in effect for pricing + applicability. */ effective: SiemId | null; /** True iff a lens was requested and differs from the actual destination. */ lensed: boolean; /** Where `effective` came from. */ basis: 'requested' | 'detected' | 'none'; /** Display name of the effective destination (null when effective is null). */ display: string | null; /** * One-line, render-ready provenance note when lensed; callers surface it * near any dollar figure. Null when not lensed. */ disclosure: string | null; } /** Normalize an arbitrary analyzer/SIEM string to a priceable SiemId, else null. */ export declare function toSiemId(raw: string | undefined | null): SiemId | null; /** * Resolve the effective destination for a tool run. * * A lens is "in effect" when the EFFECTIVE destination differs from the env's * ACTUAL destination. The effective destination is derived from EITHER the * explicit `siem_lens` arg OR a passed-through `destination`, in that order. * This single-derivation rule closes the class of bug where one transport * (destination) carries the what-if but the lens flag is computed from another * (siem_lens) and silently reads false. * * @param requested the tool's `siem_lens` arg (validated upstream by the * Zod enum, but tolerated loosely here for direct callers) * @param envAnalyzer the resolved env's analyzer (env.analyzer), raw form * @param destination optional resolved destination (e.g. cost_options' * effectiveDestination). Used only as a fallback source of * the effective destination when `requested` is absent. A * destination equal to the actual env destination yields * lensed:false (it is NOT a what-if). */ export declare function resolveSiemLens(requested: string | undefined | null, envAnalyzer: string | undefined | null, destination?: string | undefined | null): SiemLensResolution; /** * source_disclosure fragment every lens-aware tool spreads into its envelope. * Stamped even when not lensed (so readers can rely on the field's presence * wherever the arg is supported). */ export declare function lensDisclosure(res: SiemLensResolution): { siem_actual?: string; siem_lens?: string; siem_lens_basis: 'requested' | 'detected' | 'none'; }; /** Zod-enum-ready list for tool schemas. */ export declare const SIEM_LENS_ENUM: [SiemId, ...SiemId[]];