Katana control plane POST /ingest {source, events:[raw vendor payloads]} GET /status what is running, and what is not live GET /cases every case this instance has seen GET /cases/:id one case, in full POST /cases {caseId, title, events:[...]} GET /approvals requests awaiting named humans POST /approvals/:caseId/token {subject, surface} -> a signed token POST /approvals/:caseId/approve {token} or {message} GET /containments active containments and their expiry POST /reconcile one reconciliation pass POST /killswitch {engaged, reason} GET /audit/:recordId a signed case record, verified on read GET /ui the console, in a browser Nothing here is authenticated. See the note in services/runtime/server.ts.