Policies and findings · GraphQL type

Finding type

The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service. The policy service keeps one finding per rule and object (or, for a rule that raises several per object, one per key, such as one per CVE): it opens the finding on the first FAIL, marks it RESOLVED when a later evaluation passes, and reopens the same finding if the rule fails again, recording each transition and the object state behind it in statusChanges. Each finding is paired with an Issue that carries the triage workflow. Reach findings through the findings field every GraphObject exposes, through policyFindingsList, by id with finding, or as the FINDING object type in graphSearch.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
name - String! Human-readable name for the finding: the generating Rule's discoveryName, refreshed each time the rule is evaluated against the object.
foundOnObject - GraphObject The graph object this finding was found on, in its current state — the object the Rule was evaluated against (for example an endpoint, device, or network service). Null when that object no longer exists: findings are purged asynchronously after their object is deleted or aged out by data retention, so a finding can briefly outlive the object it was found on. For the state that produced the finding, use Finding.foundOnSnapshot.
foundOnSnapshot - GraphObject The graph object this finding was found on, as it appeared when the Rule was last evaluated — the stored snapshot referenced by the finding's most recent status change. A snapshot is invisible to listings, searches, and relationship traversals, so its relationship fields resolve empty; see GraphObjectSnapshotInfo for the state's observation time and the id of the live object it was taken from. Null once the object it was taken from is deleted — snapshots are readable only while that object exists.
severity - Severity! Severity of the finding, as determined by the Rule. For a VULNERABILITY rule it's the severity of the most severe CVE the finding covers (its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon), or the rule's severity when no covered CVE has one.
remediationInstructions - RemediationInstructions! How to remediate the finding, split into GUI and CLI Go templates. See RemediationInstructions.
currentConfiguration - String! The object's observed configuration for the fields this finding checks, as a compact JSON text string (e.g. {"siriVoiceTriggerEnabled":true}). Captured from the rule's function result each time the finding is evaluated, so it reflects the value that triggered (or last re-evaluated) the finding. Empty for findings created before this field existed.
expectedConfiguration - String! The required configuration for the fields this finding checks, as a compact JSON text string (e.g. {"siriVoiceTriggerEnabled":false}) — the compliant value to compare against Finding.currentConfiguration. Empty for findings created before this field existed.
type - RuleType! The type of the rule that generated this finding, which decides what metadata it carries.
typeMetadata - FindingTypeMetadata Metadata recorded from the evaluation that generated this finding, specific to the generating rule's type. Null when that evaluation produced none. See FindingTypeMetadata.
status - FindingStatus! The current FindingStatus of this finding: OPEN while the rule still evaluates FAIL against the object, RESOLVED once the failure no longer applies. Derived from the most recent entry in statusChanges; consult that field for the full transition history.
statusChanges - FindingStatusChangesPayload! Status change history, most recent first. The first element is the current status.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

rule - Rule The rule that generated this finding.
findings - FindingsPayload! Policy findings for this object. Always empty for Finding.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object. Always empty for Finding.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues. Always empty for Finding.

Returned by

  • finding query: Retrieves a Finding by its graph object id: the record of a policy rule evaluating FAIL against one graph object, with its status history and the…

Used by

  • Issue type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • FindingPayload type: Payload wrapper for a single Finding result.
  • FindingsListPayload type: Result of the policyFindingsList query.
  • FindingsPayload type: Paginated findings response for the findings field on GraphObject.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • Rule type: A policy rule evaluated against graph objects.
  • RuleInput input: Input variant of Rule carrying its writable fields.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "name": "abc123",
  "foundOnObject": GraphObject,
  "foundOnSnapshot": GraphObject,
  "severity": "INFORMATIONAL",
  "remediationInstructions": RemediationInstructions,
  "currentConfiguration": "abc123",
  "expectedConfiguration": "xyz789",
  "type": "CONFIGURATION",
  "typeMetadata": FindingTypeMetadataConfiguration,
  "status": "OPEN",
  "statusChanges": FindingStatusChangesPayload,
  "rule": Rule,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}