Compliance Documents Overview
The Compliance Documents API gives the document-review agent everything it needs to review one application in a single read: the application’s requirement slots, the document types each slot accepts with their definitions, and the documents uploaded with their status, extracted fields and review result.
Status: Defined, not yet published. The route below is specified for the CORA integration and is not delivered yet. Authenticate with the x-api-key header, as for every other route.
Key Concepts
The bundle
One read returns Application → Requirements → Document Types → Documents → Extracted fields → Review result. It lists every requirement of the application, including slots with no upload yet (empty documents). Definitions (fields, mappings, rules) are the versions pinned for the application when it was signed; a document type with no approved definition has definitionVersion: null and empty fields, mappings and rules.
Requirement status
Fortress derives each requirement’s status from the statuses of its documents: AWAITING_UPLOAD, UPLOADED, IN_REVIEW, WAITING_FOR_APPLICANT, WAITING_FOR_COMPLIANCE or VALIDATED. A REJECTED document stays in the bundle as history only and never counts, so a requirement without the non-rejected documents it needs is AWAITING_UPLOAD. It is never written by the agent. The agent writes document statuses through POST /documents/{documentId}/results, and Fortress recomputes the requirement status after each write.
Trimming the response
excludeleaves out parts of the bundle (comma-separated paths). Excluded properties are absent, never returned empty: an empty array means “no definition”.hideDocumentTypesOnValidatedRequirement=truereturnsVALIDATEDrequirements without theirdocumentTypes, so the reader sees only what still needs work.
When to read it
On application.signed and on every requirement.upload_received and requirement.upload_removed.

