---
title: ApplicationInstall type | Wartiva GraphQL API
description: One installed copy of an application on one Endpoint. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/application-install.html
updated: 2026-10-07
---

Applications and updates · GraphQL type

# `ApplicationInstall` type

One installed copy of an application on one [Endpoint](https://wartiva.com/api-docs/types/endpoint.html). The install path is part of its identity, so a product installed in two locations on the same computer yields two ApplicationInstall objects. The agent reads the registry uninstall keys on Windows, application bundles in the system and per-user Applications folders on macOS, and the dpkg or RPM package database plus snap packages on Linux. Where the platform reports them, each install carries its version, install and access dates, installer-reported and measured size, code-signature verification result, and the CPE and CVE matches in `vulnerabilities`. The abstract product identity lives on [Application](https://wartiva.com/api-docs/types/application.html); the per-user, per-install configuration lives on [ApplicationInstallUserSettings](https://wartiva.com/api-docs/types/application-install-user-settings.html).

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | Unique identifier for this graph object. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier for the owning organization. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A human-readable label for this object; the install path. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | When this ApplicationInstall was last observed on the endpoint. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `endpoint` - [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) | The [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) this Application is installed on. |
| `endpointsSeenOn` - [`EndpointConnection!`](https://wartiva.com/api-docs/types/endpoint-connection.html) | Historical sightings of this ApplicationInstall on [Endpoint](https://wartiva.com/api-docs/types/endpoint.html)s. Each edge records when the install was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. `timeRange` - [`DateTimeRangeInput`](https://wartiva.com/api-docs/types/date-time-range-input.html) Restrict edges to a date/time range. `includeSeen` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) Include the per-edge seen series in the response. |
| `application` - [`Application`](https://wartiva.com/api-docs/types/application.html) | The [Application](https://wartiva.com/api-docs/types/application.html) software identity this install installs. |
| `userSettings` - [`ApplicationInstallUserSettingsConnection!`](https://wartiva.com/api-docs/types/application-install-user-settings-connection.html) | All [ApplicationInstallUserSettings](https://wartiva.com/api-docs/types/application-install-user-settings.html) records that configure this install. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `installDate` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Date the application was installed, if available. |
| `lastAccessedDate` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Date the application was last accessed. |
| `lastModifiedDate` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Date the application was last modified. |
| `size` - [`Int64!`](https://wartiva.com/api-docs/types/int64.html) | The installer-reported size of the application in bytes. |
| `diskUsage` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The measured disk-usage of the install directory in bytes, as last computed by the paced background disk-usage walk. Null if the walk hasn't completed yet for this install. |
| `path` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Filesystem path of the install root. |
| `version` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Version of the installed application, if available. |
| `versionMajor` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | Major version number. |
| `versionMinor` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | Minor version number. |
| `versionPatch` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | Patch version number. |
| `permissions` - [`String`](https://wartiva.com/api-docs/types/string.html) | File permissions of the install root formatted as a Unix mode string (e.g. "-rwxr-xr-x"). |
| `signature` - [`ApplicationSignature`](https://wartiva.com/api-docs/types/application-signature.html) | Code-signing state of this install as verified on the endpoint. Null when the endpoint has not reported a signature verification result for this install. See [ApplicationSignature](https://wartiva.com/api-docs/types/application-signature.html). |
| `iconUrl` - [`String`](https://wartiva.com/api-docs/types/string.html) | A short-lived presigned URL that downloads the PNG icon most recently reported by this particular installation, directly from object storage (no proxy through the API). The icon is stored per install and always reflects the last icon processed for this install path — it is independent of the canonical icon elected across all installs on [Application](https://wartiva.com/api-docs/types/application.html). The URL is an unauthenticated, time-limited bearer link: anyone holding it can fetch the icon until it expires, so treat it as a credential and do not persist or share it. Null when this install has never reported an icon. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |
| `vulnerabilities` - [`PlatformVulnerabilities`](https://wartiva.com/api-docs/types/platform-vulnerabilities.html) | CPE identifiers determined for this installed application and the CVEs they match in the vulnerability catalog. Null when the install could not be identified precisely enough to match vulnerabilities accurately. See [PlatformVulnerabilities](https://wartiva.com/api-docs/types/platform-vulnerabilities.html). |

## Returned by

- [`applicationInstall`](https://wartiva.com/api-docs/queries/application-install.html) query: Retrieves an ApplicationInstall by its graph object id: one installed copy of an application on one endpoint, with its version, size, code…

## Used by

- [`Application`](https://wartiva.com/api-docs/types/application.html) type: A software product as an identity shared across an organization, independent of any one computer.
- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`ApplicationInstallConnection`](https://wartiva.com/api-docs/types/application-install-connection.html) type: Collection payload for ApplicationInstall edges with total count.
- [`ApplicationInstallEdge`](https://wartiva.com/api-docs/types/application-install-edge.html) type: Edge payload for an ApplicationInstall with optional seen data.
- [`ApplicationInstallPayload`](https://wartiva.com/api-docs/types/application-install-payload.html) type: Payload wrapper for a single ApplicationInstall result.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

## Related types

- [`Application`](https://wartiva.com/api-docs/types/application.html) A software product as an identity shared across an organization, independent of any one computer.
- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

## Example

### Example

```json
{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "endpointsSeenOn": EndpointConnection,
  "application": Application,
  "userSettings": ApplicationInstallUserSettingsConnection,
  "installDate": "2021-10-07T18:23:25.829Z",
  "lastAccessedDate": "2021-10-07T18:23:25.829Z",
  "lastModifiedDate": "2021-10-07T18:23:25.829Z",
  "size": "-8589934592",
  "diskUsage": "-8589934592",
  "path": "abc123",
  "version": "abc123",
  "versionMajor": 987,
  "versionMinor": 987,
  "versionPatch": 987,
  "permissions": "xyz789",
  "signature": ApplicationSignature,
  "iconUrl": "abc123",
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary,
  "vulnerabilities": PlatformVulnerabilities
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
