> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ctrl-hub.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List expiring competency records

> List the competency records that expire, across every member of an
organisation. One row per record: qualification awards, training, induction
and assessment records, and skills-register, scheme and category
registrations.

Only a person's latest record for each definition is listed, so an expired
record that has since been renewed does not appear. Exemption records and
records with no expiry are never listed, but they still count as the latest
record: a renewal with no expiry, or a later exemption, hides an older
expiring record. Deactivated members are left out.

A qualification award is listed only when one of the person's job roles
requires it, which is how the holder detail page shows awards. The other
record types are listed whether or not a role requires them.

The `organisation` filter is **required**. A caller reading a bridged
organisation sees only the people assigned to the roles shared with them, and
only the records those roles require.

Send `format=csv` for the export instead of a page. The export ignores
pagination and covers the whole filtered set, up to 10 000 rows.

Served by a hand-written handler rather than a generated one, because the
resource is computed rather than stored and the operation negotiates CSV.




## OpenAPI

````yaml /api-reference/openapi.yaml get /v3/competency-expiring-records
openapi: 3.1.0
info:
  contact:
    email: support@ctrl-hub.com
    name: Ctrl Hub
    url: https://www.ctrl-hub.com
  description: >
    Ctrl Hub is the all-in-one platform for high-risk industries like utilities,
    construction, infrastructure, and renewables. We help teams manage
    everything from risk assessments and HAVS exposure to vehicle and equipment
    checks, with a guaranteed minimum of 200% ROI.
  license:
    name: MIT License
    url: https://opensource.org/licenses/MIT
  summary: An API for managing your compliance and risk posture
  termsOfService: https://www.ctrl-hub.com/terms-conditions
  title: Ctrl Hub
  version: 1.0.0
servers:
  - description: Production
    url: https://api.ctrl-hub.com
  - description: Staging
    url: https://api.ctrl-hub.dev
  - description: Development
    url: https://api.ctrl-hub.run
security: []
tags:
  - description: |
      Actions are follow-ups assigned to users and teams, produced manually or
      by domain producers such as the data-capture workflow runner.
    name: Actions
  - description: |
      Audit events are the events that are logged by the system.
    name: Audit Events
  - description: |
      View the platform's health and availability.
    name: Status
  - description: >
      User-owned dashboards composed of cards on a fixed-slot bento layout.
      Cards come from a per-domain registry; the API stores their config as
      opaque JSON.
    name: Dashboards
  - description: >
      Copies of a mobile device's local database, sent by the operative on
      request so that people

      in their organisation can recover work that never reached the server. Kept
      for 30 days, and

      visible to people granted `device-backups:view` in the organisation each
      is filed against.
    name: Device Backups
  - description: >
      A record of documents the platform generated and handed over, retained as
      evidence of what

      was issued. `subject_type` says what kind of records an export covers, and
      it is what decides

      how the request is authorised: there is no export permission of its own,
      so if you can see the

      records you can export them.
    name: Exports
  - description: >
      Scheduled delivery of a saved query's results, as a CSV attachment or a
      summary email. Every run is retained with the file it sent, so what a
      recipient received stays retrievable. A report runs as the person who
      created it, under their own access.
    name: Reports
  - description: |
      Manage appointments for work to be carried out with your customers
    name: Customer Appointments
  - description: |
      Manage interactions you have with your customers
    name: Customer Interactions
  - description: |
      Manage accounts for your customers
    name: Customer Accounts and Contacts
  - description: |
      Qualifications are the skills and knowledge that an organisation requires.
    name: Qualifications
  - description: |
      Workflows allow you to automate your processes.
    name: Workflows
  - description: |
      Manage documents
    name: Documents
  - description: |
      Manage documents
    name: Folders
  - description: |
      Manage documents
    name: Document Reviews
  - description: |
      Manage feature configurations for an organisation.
    name: Feature Configurations
  - description: |
      Equipment are the physical assets that an organisation manages.
    name: Equipment
  - description: |
      The central cost register: time-versioned rate codes for material, labour,
      contractor and miscellaneous spend, used to cost work against the job
      hierarchy.
    name: Costs
  - description: >
      Locations are places an organisation manages, optionally classified by a
      location type.
    name: Locations
  - description: >
      Bulk loads of locations from an uploaded CSV. An import matches rows on
      the organisation's own

      `reference`, so re-importing a corrected file updates what is already
      there rather than

      doubling the population, and the import record is the audit trail for the
      whole load: the bulk

      write path deliberately emits no per-row events.
    name: Location Imports
  - description: |
      Manage your forms and their schemas
    name: Forms, Schemas and Categories
  - description: |
      Create and view form submissions
    name: Submissions
  - description: |
      View the roles available in the system.
    name: IAM Roles
  - description: >
      IAM role groups can be assigned to principals to manage authorisation
      centrally.
    name: IAM Role Groups
  - description: |
      Manage service accounts which can access the API programmatically.
    name: Service Accounts
  - description: |
      Manage bridges between organisations.
    name: Bridges
  - description: |
      Manage settings for an organisation.
    name: Settings
  - description: |
      Manage teams within an organisation.
    name: Teams
  - description: |
      Manage job roles within an organisation.
    name: Job Roles
  - description: |
      Manage users and accounts.
    name: Users
  - description: |
      Invite and manage invitations to organisations.
    name: Invitations
  - description: >
      IAM grants are the asignment of roles or permissions to principals to
      manage resource access.
    name: IAM Grants
  - description: |
      View the permissions available in the system.
    name: IAM Permissions
  - description: |
      SSO providers are the identity providers for an organisation.
    name: SSO Providers
  - description: |
      Whoami returns information about the currently authenticated principal.
    name: Whoami
  - description: |
      Your personal inbox. A notification is the thing you receive: an envelope
      that carries what happened to one or more channels. Email is one of those
      channels, the inbox is another, and this is where the ones delivered to
      your inbox are listed, read, saved and archived.
    name: Notifications
  - description: |
      Manage your images
    name: Images
  - description: >
      AI agent personas that synthesise data into role-specific intelligent
      briefings.
    name: Agents
  - description: |
      Briefings generated by AI agents, including reasoning traces.
    name: Briefings
  - description: >
      Organisations are the center point for most resources in the platform.
      Most other endpoints are subresources of an organisation.
    name: Organisations
  - description: |
      Permits managements, integrated with street manager.
    name: Permits
  - description: |
      Projects manage your work and governance.
    name: Projects
  - description: >
      Import templates allow users to save and reuse their CSV importer
      configuration as named templates.
    name: Import Templates
  - description: |
      Properties are the physical locations.
    name: Properties
  - description: |
      Search across schemes, work orders, and operations.
    name: Search
  - description: |
      Provides the API specification in JSON and YAML formats
    name: Specifications
  - description: |
      Streets are the physical roads.
    name: Streets
  - description: |
      Integration with street manager
    name: Street Manager
  - description: |
      Vehicles are the physical vehicles that an organisation manages.
    name: Vehicles
  - description: >
      Scheme contracts (also known as regions) group schemes allocated from the
      network to a contractor.
    name: Scheme Contracts
  - description: >
      Scheme shares allow you to share your schemes with other organisations
      across bridges.
    name: Scheme Shares
  - description: |
      Schemes are large programmes of work
    name: Schemes
  - description: >
      Site attendances record who was on site and when, whether or not they hold
      an account.

      There is no daily register resource: a day's register and who is currently
      on site are

      both queries over the attendances themselves.
    name: Site Attendances
  - description: |
      Work orders the component parts of a scheme.
    name: Work Orders
  - description: |
      Operations are the work to be carried out within work orders.
    name: Operations
externalDocs:
  description: More documentation and resources
  url: https://docs.ctrl-hub.com
paths:
  /v3/competency-expiring-records:
    get:
      tags:
        - Competency
      description: >
        List the competency records that expire, across every member of an

        organisation. One row per record: qualification awards, training,
        induction

        and assessment records, and skills-register, scheme and category

        registrations.


        Only a person's latest record for each definition is listed, so an
        expired

        record that has since been renewed does not appear. Exemption records
        and

        records with no expiry are never listed, but they still count as the
        latest

        record: a renewal with no expiry, or a later exemption, hides an older

        expiring record. Deactivated members are left out.


        A qualification award is listed only when one of the person's job roles

        requires it, which is how the holder detail page shows awards. The other

        record types are listed whether or not a role requires them.


        The `organisation` filter is **required**. A caller reading a bridged

        organisation sees only the people assigned to the roles shared with
        them, and

        only the records those roles require.


        Send `format=csv` for the export instead of a page. The export ignores

        pagination and covers the whole filtered set, up to 10 000 rows.


        Served by a hand-written handler rather than a generated one, because
        the

        resource is computed rather than stored and the operation negotiates
        CSV.
      operationId: ListCompetencyExpiringRecords
      parameters:
        - $ref: '#/components/parameters/competency_expiring_records_filter'
        - $ref: '#/components/parameters/competency_expiring_records_sort'
        - $ref: '#/components/parameters/competency_expiring_records_include'
        - $ref: '#/components/parameters/limit'
        - $ref: '#/components/parameters/offset'
        - $ref: '#/components/parameters/page'
        - $ref: '#/components/parameters/competency_expiring_records_format'
      responses:
        '200':
          $ref: '#/components/responses/ListCompetencyExpiringRecords'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorised'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - Session: []
        - OAuth2: []
        - Cookie: []
components:
  parameters:
    competency_expiring_records_filter:
      name: filter
      in: query
      description: >
        Filters the records listed.


        - `eq(organisation,xxx)`: **Required.** The organisation whose members'
        records are listed.

        - `ge(expires_at,xxx)` and `le(expires_at,xxx)`: the expiry window.
        Without `ge`, records that have already expired are included.

        - `in(type,[xxx,yyy])`: the record types. One of `qualification`,
        `training`, `induction`, `assessment`, `registration`,
        `scheme_registration` or `category_registration`.

        - `in(job_role,[xxx,yyy])`: records required by at least one of these
        job roles.

        - `in(risk,[xxx,yyy])`: the risk bands. One of `critical`, `high`,
        `medium`, `low` or `none`. `critical` means expired.

        - `contains(name,xxx)`: the person's name or email. Every word must
        match.


        A filter term this endpoint does not recognise, or one given more than
        once, is rejected with a 400 rather than ignored. `expires_at` takes one
        `ge` and one `le`.


        For more information on using named filters, see [the
        docs](https://docs.ctrl-hub.com/api-reference/features#filtering)
      required: true
      schema:
        type: string
        minLength: 1
    competency_expiring_records_sort:
      in: query
      name: sort
      description: >
        The field to order the records by. One field only.


        Defaults to `expires_at`, the soonest expiry first. `risk` orders by
        severity,

        from `critical` down to `none`, and soonest expiry first within a band.
      required: false
      style: form
      explode: false
      schema:
        type: array
        maxItems: 1
        items:
          type: string
          enum:
            - expires_at
            - '-expires_at'
            - risk
            - '-risk'
    competency_expiring_records_include:
      name: include
      in: query
      description: A comma separated list of related resources to include.
      required: false
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
          enum:
            - user
    limit:
      name: limit
      in: query
      description: Limit the number of resources returned by the API
      required: false
      schema:
        type: integer
        format: int64
        minimum: 1
        default: 100
    offset:
      name: offset
      in: query
      description: Offset the resources returned by the API
      required: false
      schema:
        type: integer
        format: int64
        minimum: 0
        default: 0
    page:
      name: page
      in: query
      description: >
        JSON:API pagination, as `page[limit]` and `page[offset]`. The same as
        the top-level `limit` and `offset` parameters; when both forms are sent,
        `page[...]` wins.
      required: false
      style: deepObject
      explode: true
      schema:
        type: object
        additionalProperties: false
        properties:
          limit:
            type: integer
            format: int64
            minimum: 1
            description: >-
              Limit the number of resources returned by the API. Defaults to the
              operation's `limit` default.
          offset:
            type: integer
            format: int64
            minimum: 0
            description: Offset the resources returned by the API. Defaults to 0.
    competency_expiring_records_format:
      name: format
      in: query
      description: >
        Asks for the CSV export rather than a page of records. The export exists
        as a

        plain URL so a browser download can use it without setting a header.
      required: false
      schema:
        type: string
        enum:
          - csv
  responses:
    ListCompetencyExpiringRecords:
      description: >
        A page of expiring competency records, or the whole filtered set as CSV
        when

        `format=csv` was asked for.
      headers:
        X-Expiring-Records-Truncated:
          description: >
            Present and `true` on the CSV export when the filtered set was
            larger than

            the export's 10 000 row limit, so the file holds only the first 10
            000

            rows in the requested order.
          schema:
            type: string
        Content-Type:
          $ref: '#/components/headers/content-type'
        Content-Length:
          $ref: '#/components/headers/content-length'
        X-Request-ID:
          $ref: '#/components/headers/x-request-id'
      content:
        application/vnd.api+json:
          schema:
            allOf:
              - type: object
                required:
                  - data
                properties:
                  data:
                    title: A list of expiring competency records
                    type: array
                    items:
                      $ref: '#/components/schemas/CompetencyExpiringRecord'
                  included:
                    $ref: '#/components/schemas/CompetencyExpiringRecordIncludes'
              - $ref: '#/components/schemas/DocumentMeta'
              - $ref: '#/components/schemas/JSONAPI'
        text/csv:
          schema:
            type: string
            description: |
              The records as comma-separated values, one row per record, in the
              requested order. Pagination does not apply.
    BadRequest:
      description: >
        There was an error with the request - this could be due to an invalid
        body, query parameters,

        or headers that were sent to the API.
      headers:
        Content-Type:
          $ref: '#/components/headers/content-type'
        Content-Length:
          $ref: '#/components/headers/content-length'
        X-Request-ID:
          $ref: '#/components/headers/x-request-id'
      content:
        application/vnd.api+json:
          schema:
            type: object
            properties:
              errors:
                type: array
                items:
                  $ref: '#/components/schemas/Error'
          example:
            id: 98ca4a78-b66f-4234-9719-aaf832ee6669
            status: '400'
            title: A validation error was encountered
            source:
              parameter: include
            meta:
              resource: wrong_value
    Unauthorised:
      description: Authentication failed
      headers:
        Content-Type:
          $ref: '#/components/headers/content-type'
        Content-Length:
          $ref: '#/components/headers/content-length'
        X-Request-ID:
          $ref: '#/components/headers/x-request-id'
      content:
        application/vnd.api+json:
          schema:
            type: object
            properties:
              errors:
                type: array
                items:
                  $ref: '#/components/schemas/Error'
          example:
            id: 05fc9c8d-73b9-4697-9337-57f7a567a48f
            status: '401'
            title: You are not authorised to access this resource
            detail: In order to access this resource, you need the 'admin' role.
            code: AUTH.001
    InternalServerError:
      description: There was a problem handling the request on the server side
      headers:
        Content-Type:
          $ref: '#/components/headers/content-type'
        Content-Length:
          $ref: '#/components/headers/content-length'
        X-Request-ID:
          $ref: '#/components/headers/x-request-id'
      content:
        application/vnd.api+json:
          schema:
            type: object
            properties:
              errors:
                type: array
                items:
                  $ref: '#/components/schemas/Error'
          example:
            id: fe9d9a69-f0a7-4fdc-bb2c-176027f316c5
            status: '500'
            title: Internal Server Error
            detail: An unexpected error occurred on the server.
  headers:
    content-type:
      description: The content type of the response
      schema:
        type: string
      example: application/vnd.api+json
    content-length:
      description: The length of the response body in bytes
      schema:
        type: integer
        format: int32
      example: 1234
    x-request-id:
      description: >-
        An ID that can be provided when reporting bugs to help identify the
        issue
      schema:
        type: string
      example: 8470f56af4cf25e22be08e72c70dbbdc
  schemas:
    CompetencyExpiringRecord:
      type: object
      description: >
        A competency record that expires, belonging to a member of an
        organisation.

        The resource id is the record's own id.
      required:
        - id
        - type
        - attributes
        - relationships
      properties:
        id:
          type: string
          format: uuid
          description: >-
            The id of the underlying record, such as the qualification award or
            the training completion.
        type:
          type: string
          const: competency-expiring-records
        attributes:
          $ref: '#/components/schemas/CompetencyExpiringRecordAttributes'
        relationships:
          $ref: '#/components/schemas/CompetencyExpiringRecordRelationships'
    CompetencyExpiringRecordIncludes:
      type: array
      description: >-
        Related resources that can be included when an expiring competency
        record is returned
      items:
        discriminator:
          propertyName: type
          mapping:
            users: '#/components/schemas/User'
        oneOf:
          - $ref: '#/components/schemas/User'
    DocumentMeta:
      type: object
      description: Document level meta about the resources on the server in list endpoints.
      required:
        - meta
      properties:
        meta:
          type: object
          required:
            - pagination
          properties:
            features:
              $ref: '#/components/schemas/Features'
            pagination:
              $ref: '#/components/schemas/Pagination'
    JSONAPI:
      type: object
      description: JSON API response object
      required:
        - jsonapi
      properties:
        jsonapi:
          type: object
          required:
            - version
          properties:
            version:
              type: string
              description: The version of the JSON API specification
              examples:
                - '1.0'
    Error:
      type: object
      description: An error response
      properties:
        id:
          description: >-
            A unique identifier for this particular occurrence of the problem.
            If you encounter this, please provide us with the error ID and we
            can investigate it on our side.
          type: string
          format: uuid
          examples:
            - 05fc9c8d-73b9-4697-9337-57f7a567a48f
        status:
          description: >-
            The status code for the error. This might not match the HTTP status
            code if there are more that one errors to return with different
            status codes.
          type: string
          examples:
            - '401'
            - '500'
        title:
          description: A human readable title for the error.
          type: string
          examples:
            - You are not authorised to access this resource
        detail:
          description: >-
            Where there is more detail that we can provide outside of the title,
            we will provide it here.
          type: string
          examples:
            - In order to access this resource, you need the 'admin' role.
        code:
          description: >-
            A unique code for the error that may help us to diagnose the issue.
            Not all errors have codes, so this is usually empty.

            `CH.003.080` (403) means the organisation in `meta.organisation_id`
            requires two-factor authentication and the caller's session does not
            satisfy it. The caller must set up or use a second factor, or sign
            in through their organisation's SAML single sign-on. Other OIDC
            sign-ins do not count.
          type: string
          examples:
            - AUTH.001
            - CH.003.080
        source:
          description: A JSON object containing additional information about the error.
          type: object
          properties:
            pointer:
              description: >-
                A JSON Pointer to the value in the request that caused the
                error.
              type: string
              examples:
                - /data/attributes/email
            parameter:
              description: >-
                A string indicating which query parameter in the request caused
                the error.
              type: string
              examples:
                - include
        meta:
          description: >-
            A JSON object containing additional information about the error.

            When a parameter caused the error, there will be a `resource`
            property with the name of the resource that caused the error.

            When `code` is `CH.003.080`, `organisation_id` names the
            organisation that requires two-factor authentication, which the
            caller's session does not satisfy.
          type: object
          properties:
            resource:
              type: string
              description: >-
                The resource a parameter error relates to, such as an
                unsupported include.
            organisation_id:
              type: string
              format: uuid
              examples:
                - c000c344-8847-47da-a091-32e75902d3b1
          additionalProperties: true
      required:
        - id
        - status
        - title
    CompetencyExpiringRecordAttributes:
      type: object
      description: Attributes for an expiring competency record.
      required:
        - record_type
        - definition
        - expires_at
        - risk_status
        - required_by
      properties:
        record_type:
          type: string
          description: The kind of record.
          enum:
            - qualification
            - training
            - induction
            - assessment
            - registration
            - scheme_registration
            - category_registration
        definition:
          type: object
          description: >
            What the record is for: the qualification, training standard or
            item,

            induction, assessment definition, skills register, scheme or
            category.
          required:
            - id
            - name
          properties:
            id:
              type: string
              format: uuid
            name:
              type: string
        expires_at:
          type: string
          format: date-time
          description: When the record expires.
        risk_status:
          type: string
          description: >
            The risk band now, from the definition's risk durations. `critical`
            means

            the record has expired.
          enum:
            - none
            - low
            - medium
            - high
            - critical
        required_by:
          type: array
          description: |
            The person's job roles whose requirement specification names this
            record's definition. Empty when no assigned role requires it.
          items:
            type: object
            required:
              - id
              - name
            properties:
              id:
                type: string
                format: uuid
              name:
                type: string
    CompetencyExpiringRecordRelationships:
      type: object
      description: Relationships for an expiring competency record
      required:
        - user
      properties:
        user:
          type: object
          required:
            - data
          properties:
            data:
              $ref: '#/components/schemas/UserRelationship'
    User:
      type: object
      description: A user
      required:
        - id
        - type
        - attributes
      properties:
        id:
          type: string
          format: uuid
          description: The unique identifier of the user.
          examples:
            - 123e4567-e89b-12d3-a456-426614174000
        type:
          type: string
          const: users
        attributes:
          $ref: '#/components/schemas/UserAttributes'
        meta:
          $ref: '#/components/schemas/UserMeta'
        relationships:
          $ref: '#/components/schemas/UserRelationships'
    Features:
      type: object
      description: Represents feature configurations of the API
      properties:
        include:
          type: object
          properties:
            options:
              type: array
              items:
                type: string
                examples:
                  - related.resource
    Pagination:
      type: object
      description: Represents pagination details for API responses
      required:
        - counts
        - current_page
        - offsets
        - requested
      properties:
        counts:
          type: object
          required:
            - pages
            - resources
          properties:
            pages:
              type: integer
              examples:
                - 1
            resources:
              type: integer
              examples:
                - 1
        current_page:
          type: integer
          examples:
            - 1
        offsets:
          type: object
          required:
            - next
            - previous
          properties:
            next:
              type:
                - integer
                - 'null'
              examples:
                - null
            previous:
              type:
                - integer
                - 'null'
              examples:
                - null
        requested:
          type: object
          required:
            - limit
            - offset
          properties:
            limit:
              type: integer
              examples:
                - 10
            offset:
              type: integer
              examples:
                - 0
    UserRelationship:
      type: object
      description: Represents a relationship to a user
      required:
        - id
        - type
      properties:
        id:
          type: string
          format: uuid
          description: The unique identifier of the user
        type:
          type: string
          const: users
    UserAttributes:
      type: object
      description: Attributes for a user
      required:
        - email
        - profile
      properties:
        email:
          type: string
          format: email
          description: The email address of the user.
          examples:
            - john.doe@example.com
        status:
          type: string
          enum:
            - active
            - inactive
            - pending
            - unknown
          description: >
            The membership status of this user in the organisation in the
            request URL.

            Only populated on org-scoped member endpoints; absent on global user

            endpoints.
          examples:
            - active
        password_set_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >
            When the user last set a password. Null if they never have, or if it
            is

            unknown because the user was created before this was tracked. Set by
            the

            server; it cannot be written through the API.
          examples:
            - '2026-09-25T10:15:00.000Z'
        mfa_enabled_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >
            When the user set up two-factor authentication with an authenticator
            app

            (TOTP). Null when they have none, including after they turn it off.

            Recovery codes on their own do not count. Set by the server from the

            identity provider; it cannot be written through the API.
          examples:
            - '2026-10-06T09:30:00.000Z'
        identities:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
                format: uuid
                description: The unique identifier for the identity.
                examples:
                  - 39ce13b8-1116-416a-ad5f-3c5edfd44f53
              platform:
                type: string
                description: The platform of the identity.
                examples:
                  - multi_tenant
              meta:
                type:
                  - object
                  - 'null'
                additionalProperties: true
                description: Additional metadata for the identity.
        profile:
          type: object
          required:
            - work
            - personal
            - contact
            - address
            - settings
          properties:
            work:
              type: object
              required:
                - occupation
                - cscs
                - eusr
                - start_date
              properties:
                occupation:
                  type: string
                  description: The occupation of the user.
                  examples:
                    - Site Manager
                cscs:
                  type: string
                  description: The CSCS card number of the user.
                  examples:
                    - CSC123456
                eusr:
                  type: string
                  description: The EUSR card number of the user.
                  examples:
                    - EUR789123
                start_date:
                  type: string
                  format: date
                  description: The start date of the user's employment.
                  examples:
                    - '2020-03-01T00:00:00.000Z'
            personal:
              type: object
              required:
                - first_name
                - last_name
                - dob
                - username
              properties:
                first_name:
                  type: string
                  description: The first name of the user.
                  examples:
                    - John
                last_name:
                  type: string
                  description: The last name of the user.
                  examples:
                    - Doe
                dob:
                  type: string
                  format: date
                  description: The date of birth of the user.
                  examples:
                    - '1985-06-15T00:00:00.000Z'
                username:
                  type: string
                  description: The username of the user.
                  examples:
                    - johndoe
            contact:
              type: object
              required:
                - mobile
                - landline
              properties:
                mobile:
                  type: string
                  description: The mobile number of the user.
                  examples:
                    - +44 7700 900123
                landline:
                  type: string
                  description: The landline of the user.
                  examples:
                    - +44 20 7946 0958
            address:
              type: object
              required:
                - name
                - number
                - street
                - area
                - town
                - county
                - postcode
                - country_code
                - what3words
              properties:
                name:
                  type: string
                  description: Building or location name
                  examples:
                    - Tech Tower
                number:
                  type: string
                  description: The house number of the user's address.
                  default: ''
                  examples:
                    - '42'
                street:
                  type: string
                  description: The street of the user's address.
                  examples:
                    - High Street
                area:
                  type: string
                  description: The area of the user's address.
                  examples:
                    - Westminster
                town:
                  type: string
                  description: The town of the user's address.
                  examples:
                    - London
                county:
                  type: string
                  description: The county of the user's address.
                  examples:
                    - Greater London
                postcode:
                  type: string
                  description: The postcode of the user's address.
                  examples:
                    - SW1A 1AA
                country_code:
                  type: string
                  description: The country code of the user's address.
                  examples:
                    - GB
                what3words:
                  type: string
                  description: The what3words location of the user's address.
                  examples:
                    - filled.count.soap
            settings:
              type: object
              required:
                - preferred_language
                - timezone
              properties:
                preferred_language:
                  type: string
                  description: The preferred language of the user.
                  default: en-GB
                  examples:
                    - en-GB
                timezone:
                  type: string
                  description: The timezone of the user.
                  examples:
                    - Europe/London
    UserMeta:
      type: object
      description: Metadata for a user
      properties:
        managed_type:
          type: string
          enum:
            - none
            - scim
            - organisation
            - unknown
          description: How this user is managed.
        withheld_organisations:
          type: array
          description: >
            Returned on `/v3/whoami` only. The organisations whose access is
            withheld

            from this session, because each requires two-factor authentication
            and the

            session does not satisfy it. This includes organisations the caller
            works in

            through a grant without being a member, such as a contractor in the
            owner's

            organisation. Absent when there are none. Requests to those
            organisations'

            routes answer 403 with code `CH.003.080`.
          items:
            type: string
            format: uuid
          examples:
            - - c000c344-8847-47da-a091-32e75902d3b1
    UserRelationships:
      type: object
      description: Relationships for a user
      properties:
        organisations:
          type: object
          required:
            - data
          properties:
            data:
              type: array
              items:
                $ref: '#/components/schemas/OrganisationRelationship'
        teams:
          type: object
          required:
            - data
          properties:
            data:
              type: array
              items:
                $ref: '#/components/schemas/TeamRelationship'
        managing_organisation:
          type: object
          required:
            - data
          properties:
            data:
              $ref: '#/components/schemas/OrganisationRelationship'
    OrganisationRelationship:
      type: object
      description: Represents a relationship to an organisation
      required:
        - id
        - type
      properties:
        id:
          type: string
          format: uuid
          description: The unique identifier of the organisation
        type:
          type: string
          const: organisations
    TeamRelationship:
      type: object
      description: Represents a relationship to a team
      required:
        - id
        - type
      properties:
        id:
          type: string
          format: uuid
          description: The unique identifier of the team
        type:
          type: string
          const: teams
  securitySchemes:
    Session:
      description: |
        Session token for authentication.
      in: header
      name: X-Session-Token
      type: apiKey
    OAuth2:
      description: |
        OAuth2 token for authentication.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: https://auth.ctrl-hub.com/oauth2/token
      type: oauth2
    Cookie:
      description: |
        Cookie token for authentication.
      in: cookie
      name: ctrl_hub_session
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.