{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "$id": "https://thuban.dev/schemas/action-event.schema.json",
  "title": "Thuban Shield Action Event",
  "description": "Standard structured event emitted for every action Shield observes. This is the foundational data contract consumed by Forge, Blackbox, Intelligence, and the behavioural sequence engine.",
  "type": "object",
  "required": ["event_id", "timestamp", "agent", "task", "action", "context", "decision"],
  "additionalProperties": false,
  "properties": {
    "event_id": {
      "type": "string",
      "description": "Unique identifier for this event (UUID v4).",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "timestamp": {
      "type": "string",
      "description": "ISO 8601 timestamp of when the action was observed.",
      "format": "date-time",
      "pattern": "^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}(\\.\\d+)?(Z|[+-]\\d{2}:\\d{2})$"
    },
    "agent": {
      "type": "object",
      "required": ["name", "session_id", "parent_process"],
      "additionalProperties": false,
      "properties": {
        "name": {
          "type": "string",
          "description": "Name/identifier of the agent performing the action."
        },
        "session_id": {
          "type": "string",
          "description": "Identifier for the agent's current session."
        },
        "parent_process": {
          "type": "string",
          "description": "Name or identifier of the parent process that spawned the agent."
        }
      }
    },
    "task": {
      "type": "object",
      "required": ["declared_intent"],
      "additionalProperties": false,
      "properties": {
        "declared_intent": {
          "type": "string",
          "description": "The task or intent the agent declared before acting."
        }
      }
    },
    "action": {
      "type": "object",
      "required": ["type", "target", "process", "arguments"],
      "additionalProperties": false,
      "properties": {
        "type": {
          "type": "string",
          "description": "The category of action being performed.",
          "enum": [
            "file_write",
            "file_delete",
            "file_read",
            "execute_command",
            "credential_access",
            "network_connect",
            "package_install",
            "git_operation",
            "policy_change"
          ]
        },
        "target": {
          "type": "string",
          "description": "The primary subject of the action (file path, host, package name, etc.)."
        },
        "process": {
          "type": "string",
          "description": "The process/executable performing the action."
        },
        "arguments": {
          "type": "array",
          "description": "Arguments associated with the action.",
          "items": { "type": "string" }
        }
      }
    },
    "context": {
      "type": "object",
      "required": ["inside_workspace", "protected_target", "credential_related", "action_index"],
      "additionalProperties": false,
      "properties": {
        "inside_workspace": {
          "type": "boolean",
          "description": "Whether the action target is inside the project workspace root."
        },
        "protected_target": {
          "type": "boolean",
          "description": "Whether the action target matches a Shield-protected file/pattern."
        },
        "credential_related": {
          "type": "boolean",
          "description": "Whether the action involves credential-shaped data."
        },
        "action_index": {
          "type": "integer",
          "description": "Sequential index of this action within the current session (0-based or 1-based, monotonically increasing).",
          "minimum": 0
        }
      }
    },
    "decision": {
      "type": "object",
      "required": ["risk", "result", "policy_ids", "reasoning"],
      "additionalProperties": false,
      "properties": {
        "risk": {
          "type": "string",
          "description": "Risk level assigned to this action.",
          "enum": ["low", "medium", "high", "critical"]
        },
        "result": {
          "type": "string",
          "description": "The outcome Shield applied to this action.",
          "enum": ["allowed", "warned", "blocked", "isolated"]
        },
        "policy_ids": {
          "type": "array",
          "description": "Identifiers of the policies/rules that informed this decision.",
          "items": { "type": "string" }
        },
        "reasoning": {
          "type": "string",
          "description": "Human-readable explanation of why this decision was made."
        }
      }
    }
  }
}
