/** * log10x_cost_options — the outcome-first action menu. * * Called after the user picks option 1 ("Show me what cutting costs would * look like") from log10x_start. Returns a structured menu of the six * enforcement modes, led by the keep-everything levers (compact / offload / * tier_down), then the lossy opt-ins (sample / drop), then observe_only, * each gated by the customer's detected capabilities. * * At Receiver tier: 6 modes. * At Reporter-only or Dev tier: 2-item collapsed menu (observe_only + * install_receiver placeholder) with prose explaining that the full * 6-mode menu requires the Receiver in-path. * * Three compliance levers (same shape as log10x_start): * must_render_verbatim — pre-rendered markdown the agent surfaces as-is. * must_ask_user — numbered question the agent MUST ask before routing. * forbidden_next_actions — tools the agent MUST NOT call until the user picks. */ import { z } from 'zod'; import { type StructuredOutput } from '../lib/output-types.js'; import type { CapabilitySummary, MustAskUser } from './log10x-start.js'; export declare const costOptionsSchema: { target_percent: z.ZodOptional; service: z.ZodOptional; pattern_hash: z.ZodOptional; destination: z.ZodOptional>; siem_lens: z.ZodOptional>; monthly_volume_gb: z.ZodOptional; }; export type CostOptionId = 'drop' | 'sample' | 'compact' | 'tier_down' | 'offload' | 'observe_only' | 'install_receiver'; export interface CostOptionItem { id: CostOptionId; /** Short label rendered to user (one sentence). */ label: string; /** One-line mechanism description. */ description: string; /** Which infrastructure layer enforces the action. */ who_enforces: 'engine' | 'SIEM' | 'forwarder' | 'customer'; /** True when the customer's env supports this mode without further setup. */ applicable: boolean; /** When applicable=false, explains what's missing. */ gated_reason?: string; /** What events survive (land in stack / overflow bucket / nowhere). */ what_survives: string; /** Tool + args to call when user picks this mode. */ routes_to: { tool: string; args: Record; }; } export interface CostOptionsEnvelope { modes: CostOptionItem[]; siem_detected: string | null; capability_summary: CapabilitySummary; must_render_verbatim: string; must_ask_user: MustAskUser; forbidden_next_actions: string[]; } declare function siemSupportsCompact(siem: string | null): boolean; export type CustomerTier = 'dev' | 'reporter' | 'receiver' | 'retriever'; declare function buildCapabilities(args: { gatewayOk: boolean; reporterTier: 'edge' | 'cloud' | null; receiverInPath: boolean; receiverUncertain: boolean; retrieverOk: boolean; siemDetected: string | null; }): CapabilitySummary & { _tier: CustomerTier; }; declare function buildModes(caps: CapabilitySummary & { _tier?: CustomerTier; }, siemDetected: string | null, args: { target_percent?: number; service?: string; pattern_hash?: string; destination?: string; monthly_volume_gb?: number; siem_lens?: string; }): CostOptionItem[]; declare function renderVerbatim(modes: CostOptionItem[], effectiveDestination: string | null, siemDetected: string | null, tier?: CustomerTier): string; declare function buildCostOptionsForbidden(): string[]; export declare function executeCostOptions(args: { target_percent?: number; service?: string; pattern_hash?: string; destination?: 'splunk' | 'datadog' | 'elasticsearch' | 'clickhouse' | 'cloudwatch' | 'azure-monitor' | 'gcp-logging' | 'sumo' | 'coralogix' | 'elastic-serverless'; siem_lens?: 'splunk' | 'datadog' | 'elasticsearch' | 'clickhouse' | 'cloudwatch' | 'azure-monitor' | 'gcp-logging' | 'sumo' | 'coralogix' | 'elastic-serverless'; monthly_volume_gb?: number; }): Promise; /** Export internals so tests can call helpers directly. */ export declare const _internals: { buildCapabilities: typeof buildCapabilities; buildModes: typeof buildModes; renderVerbatim: typeof renderVerbatim; buildCostOptionsForbidden: typeof buildCostOptionsForbidden; siemSupportsCompact: typeof siemSupportsCompact; }; export {};