Get Application Bundle
Everything CORA needs to review one application, in one place: Application -> Requirements -> Document Types -> Documents -> Extracted fields -> Review result.
- Requirement slots done?
requirements[] - Document types accepted per slot?
requirements[].documentTypes[] - A document’s status, extracted fields or review result?
requirements[].documentTypes[].documents[] - A rule or mapping for a document type?
requirements[].documentTypes[].rules[]/mappings[]
Lists every requirement of the application, including slots with no upload yet (empty documents).
The bundle is the end goal for CORA’s reads: it replaces the requirement manifest, and CORA does not
need separate calls for requirements or review criteria. Definitions (fields, mappings, rules) are the versions pinned for
this application. A document type with no approved definition has definitionVersion: null and empty
fields, mappings and rules. Requirement status is derived by Fortress from document statuses.
How CORA uses requirement status:
- Can CORA start on applicant X? No requirement of applicant X is AWAITING_UPLOAD.
- Is there work to pick up? A requirement is UPLOADED (process its NOT_YET_REVIEWED documents).
- Is the application done? Every requirement is VALIDATED.
CORA reads the bundle on application.signed and on every requirement.upload_received / requirement.upload_removed. Documents are never replaced: a rejected document stays as history only (it never counts toward the requirement) and the applicant uploads a new one, or compliance approves it manually.
This route is defined for the CORA integration and is not delivered yet. Fortress does not serve it until it moves to Available. Authenticate with the x-api-key header.
Authentication
Path parameters
The application (unit of work).
Query parameters
Parts of the bundle to leave out, as paths. Comma-separated; any combination. Excluded properties are omitted, not returned empty (an empty array means "no definition").
- requirements.documentTypes: omits each requirement's documentTypes, and with them its documents. Returns requirement-level data only (id, type, applicant, status), e.g. for the "all uploaded?" check.
- requirements.documentTypes.fields / .mappings / .rules: omits that part of each definition. documentTypeId and definitionVersion are always returned, so CORA can cache definitions by documentTypeId + definitionVersion and read only statuses and documents.
- requirements.documentTypes.documents.extractedFields / .reviewResult: omits that part of each document. Document status and reasonCodes are always returned. Excluding requirements.documentTypes makes every other value redundant. The caller chooses what to exclude for each read; anything it excludes is simply not returned (for example, rules that compare across documents need the other documents' extractedFields).
When true, requirements whose status is VALIDATED are returned without documentTypes (and so without their documents). Requirements in any other status are returned in full, subject to exclude. Useful once part of the application is validated: CORA reads only what still needs work. Redundant with exclude=requirements.documentTypes, which already omits documentTypes everywhere.

