Skip to main content

Finding/Output Schema

This guide provides a more formal view of common fields on Compliance Engine output objects (policy violations and benchmark checks). Actual field names may differ in your tenant.

Identity and Relationships

  • Id – unique identifier of the finding.
  • Policy – lookup to the policy that produced the finding.
  • Target object – lookup or reference to the CMDB object evaluated.
  • Framework/pack – optional fields linking to benchmark packs or frameworks (CIS, PCI, HIPAA, and so on).

Status and Severity

  • Status – current compliance status (Compliant, Incompliant, Inapplicable, Closed/Out of Scope).
  • Severity – risk level assigned to the control (for example, Critical, High, Medium, Low).
  • Category – grouping for dashboards (for example, Security, Reliability, Cost).

Timestamps

  • Created date – when the finding was first created.
  • Last status change – most recent time the status changed.
  • Incompliant start/end – timestamps for the incompliant period.
  • Compliant start/end – timestamps for the compliant period.
  • Inapplicable start/end – timestamps for the inapplicable period.
  • Close date – when the finding was closed due to scope loss.

Evidence and Context

  • Evidence fields – control‑specific fields that explain why the asset passed or failed (for example, configuration flags, missing tags, benchmark section identifiers).
  • Ownership fields – application, service, team, or cost center.
  • Location fields – account, subscription, project, region.
  • Policy link – URL or reference back to the policy editor.
  • Target link – link to the asset view in Cloudaware.
  • Ticket links – references to related ITSM tickets where applicable.

These fields together support both operational workflows and audit‑grade reporting.