Creates the first ComplianceEntity for a subject. If a current record already exists, returns 409 ResourceConflict; use the explicit /advance action to create a successor. A subject-less Individual is Person-owned and callers must omit X-Wingspan-Account. Business and subject-bearing records are Account-owned. A headerless Person session may create one under its authorized principal Account, and the response identifies that Account in ownerId/accountId. Item requests resolve the returned globally unique ComplianceEntity id only across the request's already-authorized Person and principal Account lanes. List requests never merge lanes: use filter[ownerType][eq]=OwnerAccount for the principal Account chain or OwnerPerson for the Person chain. X-Wingspan-Account remains required to select any other accessible Account. An unauthorized owner lane returns 403. Idempotent via Idempotency-Key.
Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||