Skip to main content

Evaluation & States

Evaluations are how Compliance Engine turns policies into concrete findings. Evaluations can be scheduled or run on demand and are designed to handle large environments while respecting platform and provider limits.

This section explains how evaluations run, how scope is applied, and how states are updated over time.

At a high level:

  1. An evaluation job selects the policies to run (single policy or a pack).
  2. For each policy, Compliance Engine queries in‑scope CMDB objects.
  3. The policy code evaluates each object and writes or updates output objects.
  4. Status and timestamps are updated according to the state model and lifecycle.

Evaluation Cadence

Choose evaluation schedules, balance freshness with platform limits, and plan policy run frequency.

Scoping & Targeting

Define which CMDB objects each policy evaluates by account, environment, tags, ownership, and other attributes.

State Model

Understand how Compliance Engine tracks per-asset policy states, timestamps, history, and reporting behavior.