Post Document Results
The only write route for documents. Every status CORA writes goes through it, with or without data. Fortress recomputes the requirement status after each call (see RequirementStatus).
One run, in order:
- Pickup: status EXTRACTING and reviewResult.runId (opens the run). No data yet.
- Extraction (“Save the extracted data in Fortress”): extractedFields and reviewResult.quality, with status EVALUATING_RULES. If a quality check fails (wrong item, unreadable, incomplete), this call carries the outcome status and reasonCodes instead, and the run ends here.
- Evaluated rules: reviewResult.checks and computed, with the outcome status (VALIDATED_BY_CORA, REJECTED, WAITING_FOR_APPLICANT or WAITING_FOR_COMPLIANCE) and reasonCodes.
Clarification: CORA writes WAITING_FOR_APPLICANT while it waits for the applicant’s clarification, then WAITING_FOR_COMPLIANCE when the clarification is ready for compliance. The applicant’s reply stays in the message thread (POST /v1/messages, message.received), where compliance reads it.
REJECTED: CORA failed the document and it needs a new upload (unreadable, wrong document, a rule failed). CORA writes REJECTED with the reasonCodes. A rejected document stays in the bundle as history only and never counts toward the requirement, so the requirement derives AWAITING_UPLOAD. CORA waits for the applicant’s new upload (requirement.upload_received) and reviews the new document. Staff can set REJECTED too; statusSetBy says who.
Outcomes without data (e.g. WAITING_FOR_COMPLIANCE with NO_DEFINITION or SYS_FORTRESS_API) send only status and reasonCodes. reviewResult is optional, except that it is required whenever extractedFields is sent: a body with extractedFields and no reviewResult returns 400.
Fortress can refuse a write with 409 (see below). CORA must handle it: stop, re-read the bundle and continue from the state Fortress returns.
Calls with the same reviewResult.runId merge into one result: properties not sent are left unchanged; extractedFields and checks items replace earlier items with the same canonicalName or checkId. A new runId starts a new result. The bundle returns the latest run, in the same shape (requirements[].documentTypes[].documents[]).
This route is defined for the CORA integration and is not delivered yet. Fortress does not serve it until it moves to Available. Authenticate with the x-api-key header.
Authentication
Path parameters
Request
The document statuses CORA may write (a subset of BundleDocumentStatus). NOT_YET_REVIEWED and APPROVED are Fortress only; writing them returns 403.
Required when extractedFields is sent; Fortress returns 400 otherwise. Omit for outcomes without data.

