API REFERENCE
Beta
Set a Finding’s Review Note
Sets reviewNote to the given value — this replaces the finding’s current note outright, it does not append to a list. The prior note, if any, is not lost: it remains visible as a NOTE_CHANGED entry on the finding’s audit trail — see Get a Finding’s History.
Requires that you currently have permission to update this finding’s review note — see Finding.editStates.note on List a Workflow’s Findings, published on every finding so you can tell in advance whether this call would succeed.
Sample
url="https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/note"
curl -X POST "${url}" \
-H "Authorization: Bearer your_access_token_here" \
-H "Content-Type: application/json" \
-d '{
"reviewNote": "Confirmed with borrower via phone on 8/7; income supported by attached paystub."
}'
Header Properties
| Property | Value | Required? |
|---|---|---|
| Authorization | Bearer your token | true |
| Content-Type | application/json | true |
Path Parameters
| Property | Description | Type |
|---|---|---|
| workflowId | The opaque handle identifying the workflow. | string |
| findingId | The opaque finding identifier (fndg_…). | string |
workflowId is accepted with or without its wfpop_ prefix — a bare GUID resolves. findingId and attachmentId are not interchangeable this way: either must carry its exact prefix, or the request 404s as if that finding or attachment did not exist. There is no bare form of either that has ever been valid.
Request Body Properties
| Property | Description | Type | Required |
|---|---|---|---|
| reviewNote | The finding’s new current review note. Required: a request with this field missing or blank is a 400, not a no-op. Must be 110 UTF-8 bytes or fewer — bytes, not characters, so a note containing accents, em dashes, or emoji can be rejected well under 110 typed characters. | string | yes |
The 110-byte limit is measured in UTF-8 bytes of the note text, not characters. ' fits in 1 byte; ' (a curly quote) takes 3; most emoji take 4. If you’re near the limit, encode the string as UTF-8 and check its byte length before sending, rather than counting characters.
Responses
200
The finding, re-projected — byte-identical in shape to a GET of the same finding, reflecting the note just recorded. See List a Workflow’s Findings for the full Finding field table.
{
"workflowId": "wfpop_0000000000002082611",
"finding": {
"findingId": "fndg_0000000000006051384",
"code": "HP.ST",
"displayName": "High-priority stated income mismatch",
"category": ["Income"],
"severity": "HIGH",
"alertState": "Alert",
"userMessage": ["Stated income does not match the verified source document."],
"userSuggestion": ["Confirm the applicant's income against the attached document before proceeding."],
"reviewStatus": "PENDING",
"reviewNote": "Confirmed with borrower via phone on 8/7; income supported by attached paystub.",
"updatedAt": "2026-08-07T15:01:42Z",
"hasAttachments": true,
"hasHistory": true,
"links": {
"self": { "href": "https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384" },
"history": { "href": "https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/history" },
"attachments": { "href": "https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/attachments" }
},
"editStates": {
"note": {
"href": "https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/note",
"method": "POST"
},
"resolve": {
"href": "https://api.pointservices.com/riskinsight-services-ws/resources/v1/findings/workflows/wfpop_0000000000002082611/findings/fndg_0000000000006051384/resolve",
"method": "POST"
}
}
}
}
Note that resolve now appears in editStates — it only publishes once a note exists, since Mark a Finding Reviewed requires one.
400
reviewNote missing, blank, or over 110 UTF-8 bytes; or the body is malformed.
| Property | Description | Type |
|---|---|---|
| message | A human-readable explanation of what was rejected. Not a stable code — write your handling against the status code and the operation you called, not this text. | string |
{
"message": "reviewNote must be 110 UTF-8 bytes or fewer"
}
403
You may not read this workflow, or may read it but currently lack permission to update this finding’s review note.
Zero-length body, no Content-Type. Do not attempt to parse a body from this response — there is none. Branch on the status code alone.
This surface uses a bodyless 403 for every authorization failure, which is different from a problem+json 404 on the same operation. Do not assume every non-2xx on this API carries JSON — check the status first.
A 403 is also produced at the edge, before this service is reached, when a request value resembles SQL injection or cross-site scripting, and separately from the per-address rate limit (429). Both of those are also bodyless and carry no Content-Type.
404
Unknown workflowId or unknown findingId.
An RFC 9457 problem document, served as application/problem+json.
| Property | Description | Type |
|---|---|---|
| type | An absolute URI identifying the problem type. https://pointservices.com/problems/not-found is the only type this surface emits. This is the stable value to match on. | string |
| title | A short summary, written for a person. | string |
| status | The HTTP status code, repeated in the body. | number |
| detail | An explanation of this occurrence, written for your logs — never a stable code. | string |
| instance | A URI identifying this occurrence, written as urn:pps:request:<id>. Quote it when you raise a support ticket. | string |
{
"type": "https://pointservices.com/problems/not-found",
"title": "No such resource",
"status": 404,
"detail": "No finding fndg_0000000000006051384 is available to this request.",
"instance": "urn:pps:request:8d3a1f56-6c94-4e20-b7f8-0a5e9c2d4b73"
}
Branch on type, never on the text of detail.