Finding/Output Schema
This guide provides a more formal view of common fields on Compliance Engine output objects (policy violations and benchmark checks). Actual field names may differ in your tenant.
Identity and Relationships
- Id – unique identifier of the finding.
- Policy – lookup to the policy that produced the finding.
- Target object – lookup or reference to the CMDB object evaluated.
- Framework/pack – optional fields linking to benchmark packs or frameworks (CIS, PCI, HIPAA, and so on).
Status and Severity
- Status – current compliance status (Compliant, Incompliant, Inapplicable, Closed/Out of Scope).
- Severity – risk level assigned to the control (for example, Critical, High, Medium, Low).
- Category – grouping for dashboards (for example, Security, Reliability, Cost).
Timestamps
- Created date – when the finding was first created.
- Last status change – most recent time the status changed.
- Incompliant start/end – timestamps for the incompliant period.
- Compliant start/end – timestamps for the compliant period.
- Inapplicable start/end – timestamps for the inapplicable period.
- Close date – when the finding was closed due to scope loss.
Evidence and Context
- Evidence fields – control‑specific fields that explain why the asset passed or failed (for example, configuration flags, missing tags, benchmark section identifiers).
- Ownership fields – application, service, team, or cost center.
- Location fields – account, subscription, project, region.
Links
- Policy link – URL or reference back to the policy editor.
- Target link – link to the asset view in Cloudaware.
- Ticket links – references to related ITSM tickets where applicable.
These fields together support both operational workflows and audit‑grade reporting.