{"schema_version":"1.0.0","differentiation_note":"Each workflow's observed_p95_ms is derived from mcp_query_log over the rolling 30-day window — observed, not committed. /agents.json is a planning surface; /workflows.json is the verbose HowTo counterpart and is authoritative for step semantics, expected_response shapes, and intent fields.","generated_at":"2026-10-06T13:05:28.063Z","workflows":[{"id":"check-obligations","name":"Check current obligations for a Norwegian company","tool_names":["get_company_obligations"],"estimated_steps":1,"observed_p95_ms":304,"requires_auth":true,"idempotent":true,"failure_branch_examples":["If 404, surface verbatim; do not retry. The org number is not in Brønnøysundregistrene.","If 5xx from upstream registry, retry once with exponential backoff (max 1s). If still failing, surface the structured error envelope to the operator."],"details_url":"/workflows.json#/workflows/check-obligations"},{"id":"validate-filing","name":"Validate a Norwegian government filing before submission","tool_names":["get_company_obligations","validate_action"],"estimated_steps":2,"observed_p95_ms":408,"requires_auth":true,"idempotent":true,"failure_branch_examples":["If get_company_obligations returns 404, do not proceed to validate_action; surface the org-not-found error verbatim.","If validate_action returns VALIDATION_FAILED, surface the per-field details to the operator and pause; do not auto-correct or re-attempt with mutated payload.","If validate_action returns SCOPE_INSUFFICIENT, the API key lacks the required scope; surface the missing scope name and halt — do not retry."],"details_url":"/workflows.json#/workflows/validate-filing"},{"id":"execute-with-approval","name":"Execute a Norwegian government filing with human approval gating (sandbox only)","tool_names":["get_company_obligations","validate_action","submit_vat_return"],"estimated_steps":3,"observed_p95_ms":701,"requires_auth":true,"idempotent":false,"failure_branch_examples":["The approval token is minted out-of-band by a human operator via POST /api/v1/sandbox/auth/approval-token — the sandbox-scoped mint, not the production /api/v1/auth/approval-token endpoint; submit_vat_return only accepts the sandbox-approval-* token shape. The agent never calls this itself. If the operator's mint attempt returns AUTH_INVALID_KEY or AUTH_KEY_MISSING_SCOPE, surface the structured error and halt; never auto-mint a new key or retry with a different scope.","submit_vat_return is sandbox-only — it never reaches a real government system. If it is interrupted after the approval token is spent (network drop, client crash), do NOT retry with the same Idempotency-Key — the token is single-use and the server has already recorded the attempt. Surface the partial-execution receipt and let the operator decide whether to re-request approval.","If validate_action returns warnings (not errors), surface them to the operator before requesting an approval token. The approval gate exists so a human reviews validate_action's verdict."],"details_url":"/workflows.json#/workflows/execute-with-approval"}]}