Skip to main content

Schema

This page summarizes the key fields you can expect on Compliance Engine output objects (policy violations and benchmark checks).

Exact field names vary by object type and Cloudaware configuration, but most output objects include:

  • Policy reference – a lookup to the policy that produced the finding.
  • Status – current compliance status (Compliant, Incompliant, Inapplicable, Closed/Out of Scope).
  • Severity and category – used to prioritize and group findings.
  • Timestamps – created date, last status change, start/end timestamps for key statuses (for example, incompliant start/end), and close date when out of scope.
  • Evidence fields – details that explain why the asset failed or passed (for example, configuration values, missing tags, benchmark section identifiers).
  • Target reference – a lookup or identifier for the CMDB object being evaluated (for example, account, instance, bucket, subscription).
  • Ownership fields – application, team, service, or other ownership context derived from CMDB.
  • Links – deep links back to the policy, the asset, and any related tickets or external systems.

These fields are available for:

  • Reports and dashboards built within Cloudaware.
  • Exports to external systems (ITSM, SIEM, data warehouses).
  • Automation and workflows that react to new or updated findings.

See Finding/Output Schema for more details.