Threats
The threat board and operator designation.
/api/threats
The current live threats (one per hostile object), each with its rolled-up alert timeline and kill-chain stage. Carries the authored
/api/threats/designate
This is an ROE-relevant act, not a UI toggle. Our doctrine says kinematics
/api/threats/designations
The calls currently in force (audit read).