---
title: Finding type | Wartiva GraphQL API
description: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
url: https://wartiva.com/api-docs/types/finding.html
updated: 2026-10-07
---

Policies and findings · GraphQL type

# `Finding` type

The record of a policy [Rule](https://wartiva.com/api-docs/types/rule.html) evaluating FAIL against one graph object, such as an [Endpoint](https://wartiva.com/api-docs/types/endpoint.html), [Device](https://wartiva.com/api-docs/types/device.html), or network service. The policy service keeps one finding per rule and object (or, for a rule that raises several per object, one per key, such as one per CVE): it opens the finding on the first FAIL, marks it RESOLVED when a later evaluation passes, and reopens the same finding if the rule fails again, recording each transition and the object state behind it in `statusChanges`. Each finding is paired with an [Issue](https://wartiva.com/api-docs/types/issue.html) that carries the triage workflow. Reach findings through the `findings` field every [GraphObject](https://wartiva.com/api-docs/types/graph-object.html) exposes, through [policyFindingsList](https://wartiva.com/api-docs/queries/policy-findings-list.html), by id with [finding](https://wartiva.com/api-docs/queries/finding.html), or as the FINDING object type in [graphSearch](https://wartiva.com/api-docs/queries/graph-search.html).

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | Unique identifier for this graph object. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier for the owning organization. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | When this graph object was seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `name` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Human-readable name for the finding: the generating [Rule](https://wartiva.com/api-docs/types/rule.html)'s `discoveryName`, refreshed each time the rule is evaluated against the object. |
| `foundOnObject` - [`GraphObject`](https://wartiva.com/api-docs/types/graph-object.html) | The graph object this finding was found on, in its current state — the object the Rule was evaluated against (for example an endpoint, device, or network service). Null when that object no longer exists: findings are purged asynchronously after their object is deleted or aged out by data retention, so a finding can briefly outlive the object it was found on. For the state that produced the finding, use [Finding](https://wartiva.com/api-docs/types/finding.html).foundOnSnapshot. |
| `foundOnSnapshot` - [`GraphObject`](https://wartiva.com/api-docs/types/graph-object.html) | The graph object this finding was found on, as it appeared when the Rule was last evaluated — the stored snapshot referenced by the finding's most recent status change. A snapshot is invisible to listings, searches, and relationship traversals, so its relationship fields resolve empty; see [GraphObjectSnapshotInfo](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) for the state's observation time and the id of the live object it was taken from. Null once the object it was taken from is deleted — snapshots are readable only while that object exists. |
| `severity` - [`Severity!`](https://wartiva.com/api-docs/types/severity.html) | Severity of the finding, as determined by the Rule. For a VULNERABILITY rule it's the severity of the most severe CVE the finding covers (its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon), or the rule's severity when no covered CVE has one. |
| `remediationInstructions` - [`RemediationInstructions!`](https://wartiva.com/api-docs/types/remediation-instructions.html) | How to remediate the finding, split into GUI and CLI Go templates. See [RemediationInstructions](https://wartiva.com/api-docs/types/remediation-instructions.html). |
| `currentConfiguration` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The object's observed configuration for the fields this finding checks, as a compact JSON text string (e.g. `{"siriVoiceTriggerEnabled":true}`). Captured from the rule's function result each time the finding is evaluated, so it reflects the value that triggered (or last re-evaluated) the finding. Empty for findings created before this field existed. |
| `expectedConfiguration` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The required configuration for the fields this finding checks, as a compact JSON text string (e.g. `{"siriVoiceTriggerEnabled":false}`) — the compliant value to compare against [Finding](https://wartiva.com/api-docs/types/finding.html).currentConfiguration. Empty for findings created before this field existed. |
| `type` - [`RuleType!`](https://wartiva.com/api-docs/types/rule-type.html) | The type of the rule that generated this finding, which decides what metadata it carries. |
| `typeMetadata` - [`FindingTypeMetadata`](https://wartiva.com/api-docs/types/finding-type-metadata.html) | Metadata recorded from the evaluation that generated this finding, specific to the generating rule's type. Null when that evaluation produced none. See [FindingTypeMetadata](https://wartiva.com/api-docs/types/finding-type-metadata.html). |
| `status` - [`FindingStatus!`](https://wartiva.com/api-docs/types/finding-status.html) | The current [FindingStatus](https://wartiva.com/api-docs/types/finding-status.html) of this finding: OPEN while the rule still evaluates FAIL against the object, RESOLVED once the failure no longer applies. Derived from the most recent entry in statusChanges; consult that field for the full transition history. |
| `statusChanges` - [`FindingStatusChangesPayload!`](https://wartiva.com/api-docs/types/finding-status-changes-payload.html) | Status change history, most recent first. The first element is the current status. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `rule` - [`Rule`](https://wartiva.com/api-docs/types/rule.html) | The rule that generated this finding. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. Always empty for Finding. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. Always empty for Finding. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues. Always empty for Finding. |

## Returned by

- [`finding`](https://wartiva.com/api-docs/queries/finding.html) query: Retrieves a Finding by its graph object id: the record of a policy rule evaluating FAIL against one graph object, with its status history and the…

## Used by

- [`Issue`](https://wartiva.com/api-docs/types/issue.html) type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
- [`FindingPayload`](https://wartiva.com/api-docs/types/finding-payload.html) type: Payload wrapper for a single Finding result.
- [`FindingsListPayload`](https://wartiva.com/api-docs/types/findings-list-payload.html) type: Result of the policyFindingsList query.
- [`FindingsPayload`](https://wartiva.com/api-docs/types/findings-payload.html) type: Paginated findings response for the findings field on GraphObject.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`Rule`](https://wartiva.com/api-docs/types/rule.html) type: A policy rule evaluated against graph objects.
- [`RuleInput`](https://wartiva.com/api-docs/types/rule-input.html) input: Input variant of Rule carrying its writable fields.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "name": "abc123",
  "foundOnObject": GraphObject,
  "foundOnSnapshot": GraphObject,
  "severity": "INFORMATIONAL",
  "remediationInstructions": RemediationInstructions,
  "currentConfiguration": "abc123",
  "expectedConfiguration": "xyz789",
  "type": "CONFIGURATION",
  "typeMetadata": FindingTypeMetadataConfiguration,
  "status": "OPEN",
  "statusChanges": FindingStatusChangesPayload,
  "rule": Rule,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
