Policies and findings · GraphQL type

Issue type

The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision. The policy service opens an issue alongside the Finding when a Rule evaluates FAIL against an object, keeping one issue per rule and object (or one per key, such as one per CVE, for a rule that raises several). It marks an OPEN or IN_PROGRESS issue RESOLVED when a later evaluation passes and reopens it if the rule fails again. An IGNORED issue stays ignored until its ignored.expires time passes. Users move an issue between OPEN, IN_PROGRESS, and IGNORED and record notes with issueUpdate. Reach issues through the issues and issuesSummary fields every GraphObject exposes, by id with issue, or as the ISSUE object type in graphSearch.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
name - String! Name of the issue: the generating Rule's discoveryName, refreshed each time the rule fails against the object and when a passing evaluation resolves the issue.
foundOnObject - GraphObject The graph object this issue was found on, in its current state — the object the policy violation applies to (for example an endpoint, device, or network service). Null when that object no longer exists: issues are purged asynchronously after their object is deleted or aged out by data retention, so an issue can briefly outlive the object it was found on.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! When the issue was first created.
updatedAt - Time! When the issue was last updated.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
status - IssueStatus! The current status of the issue. Equal to the status of the most recent IssueStatusChange in the statusChanges history.
statusChanges - IssueStatusChangesPayload! Status change history, most recent first. The first element is the current status.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

severity - Severity! Severity inherited from the rule at the time the issue was opened or re-opened. For a VULNERABILITY rule it's the severity of the most severe CVE the issue covers (its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon), or the rule's severity when no covered CVE has one, and it follows that CVE's severity while the issue stays open.
notes - String! User-authored notes for this issue, set through issueUpdate. Empty when none have been recorded.
type - RuleType! The type of the rule that generated this issue, which decides what metadata it carries.
typeMetadata - IssueTypeMetadata Metadata recorded from the evaluation that generated this issue, specific to the generating rule's type. Null when that evaluation produced none. See IssueTypeMetadata.
rule - Rule The Rule that generated this issue. Null when that rule is no longer present.
findings - FindingsPayload! The Finding objects that reference this issue. An issue aggregates the findings that evidence it; a finding may contribute to many issues.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object. Always empty for Issue.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues. Always empty for Issue.

Returned by

  • issue query: Retrieves an Issue by its graph object id: the triage record for a policy violation on one graph object, which users move between OPEN, IN_PROGRESS,…

Used by

  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • IssuePayload type: Payload wrapper for a single Issue result.
  • IssuesPayload type: Paginated issues response for the issues field on GraphObject.
  • IssuesUpdateInput input: Input for the issueUpdate mutation.
  • IssuesUpdatePayload type: Result of the issueUpdate mutation.
  • Rule type: A policy rule evaluated against graph objects.
  • RuleInput input: Input variant of Rule carrying its writable fields.

Related types

  • Finding The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "name": "abc123",
  "foundOnObject": GraphObject,
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "status": "OPEN",
  "statusChanges": IssueStatusChangesPayload,
  "severity": "INFORMATIONAL",
  "notes": "xyz789",
  "type": "CONFIGURATION",
  "typeMetadata": IssueTypeMetadataConfiguration,
  "rule": Rule,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}