Start a triage run for a finding
Start a Neo triage run for one finding of your team. This is the one route that starts triage for every source: HackerOne reports, GitHub security advisories, Security Inbox (Gmail) threads and custom API source findings, each addressed by its opaque finding id. Neo builds the triage prompt (custom free-form task text is not accepted) and queues the task on the same durable task-start path as normal tasks. Each run is appended to the finding’s history and pins the finding revision it triages. Only one run per finding can be active: a second request while one is queued or running returns 409 run_in_flight. Built-in sources must still be connected. Custom source findings are triaged from the record Neo stored at synchronization; Neo does not call the source and never sends its credential to the task. Requires Neo AI access and available credits; viewers cannot start runs.
Authorizations
JWT authentication token
Path Parameters
Finding id
Body
Optional model to use for triage. An invalid value rejects the request before a run is claimed.
Response
The run was claimed and its task queued
One triage run of a finding. Runs are append-only.
The finding revision this run triages.
Model requested for the run. Empty means the default.
queued, running, completed, failed, cancelled Stable failure code when status is failed, such as enqueue_failed.
Neo task id of this run once dispatched.
Current Neo task status, when the run has a task.
pending, active, completed, error, aborted, suspended Neo suggested severity. Only set when triage_status is valid.
none, low, medium, high, critical, unknown Neo disposition. Null until the run records a decision.
valid, need_more_info, duplicate, informative, not_applicable, spam, unknown 
