Policies and findings · GraphQL type

RemediationInstructions type

Remediation guidance split by surface (GUI vs CLI). The gui field is Markdown-formatted human guidance; the cli field is copy-pasteable / directly-executable shell commands.

Fields

Field Name Description
gui - String GUI remediation steps, formatted as Markdown. Point-and-click navigation that ends in the concrete action (e.g. "Open System Settings > General > Sharing and turn Screen Sharing off").
cli - String

CLI remediation steps: one shell command per line, ready to copy-paste or be executed directly by an operator or automation. Commands only — no explanatory prose (not "run X to ..."), no commands that reboot or halt the machine, and no destructive commands (e.g. rm -rf /).

Authored as a Go text/template for the one OS the rule applies to; this field returns the commands with their substitutions resolved from the evaluated object. Any substitution that cannot be resolved renders empty. The unresolved template is returned when it can't be rendered, including when a value from the object can't be placed safely under that OS's shell quoting. See cliTemplate for the always-raw form.

cliTemplate - String The raw cli remediation template, with its Go text/template substitutions left unresolved.
requiresReboot - Boolean Whether the machine must be rebooted after the CLI commands are applied for the remediation to take effect. The CLI commands themselves must never reboot the machine; set this flag instead so the caller can schedule the reboot.

Used by

  • Finding type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • RemediationInstructionsInput input: Input variant of RemediationInstructions.
  • Rule type: A policy rule evaluated against graph objects.

Example

Example

{
  "gui": "xyz789",
  "cli": "xyz789",
  "cliTemplate": "xyz789",
  "requiresReboot": false
}