Scripts, Policies and Checks currently have no public API endpoints at all. This blocks any programmatic audit of what policies/scripts exist across the org, version-controlling scripts externally (git-backed source of truth), or building tooling that reasons about which checks/remediations are configured where. Tickets, Assets, Clients and Contacts are fully exposed - Scripts/Policies/Checks are the remaining major gap for anyone trying to manage Gorelo as code.