---
title: RuleBodyFile type | Wartiva GraphQL API
description: The body of a FILE rule. Wartiva GraphQL API reference with arguments, fields, and examples. Browse related operations and types.
url: https://wartiva.com/api-docs/types/rule-body-file.html
updated: 2026-10-07
---

Policies and findings · GraphQL type

# `RuleBodyFile` type

The body of a FILE rule. It checks only what your path sensors already collect: make sure a sensor covers the glob, and collects contents when the rule checks them.

A rule makes one kind of check. An existence check applies to [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) and raises one finding per endpoint; an endpoint no path sensor has collected on isn't judged. The contents, permissions, and ownership checks apply to [EndpointPath](https://wartiva.com/api-docs/types/endpoint-path.html), the files one path sensor collected on an endpoint, and raise one finding per failing file, keyed by the file's path. A file a check can't judge, such as one whose contents weren't collected, keeps its current findings until the check can. A file its sensor reports deleted counts as removed from the endpoint. Windows collects no file owners or meaningful permission bits, so a Windows glob can check only existence or contents.

## Fields

| Field Name | Description |
|---|---|
| `pathGlob` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The paths checked, as an absolute glob such as /etc/ssh/sshd_config or /etc/cron.d/*. Each * stays within one directory. A Windows glob (starting with a drive letter or \) matches case-insensitively and accepts either slash. |
| `pathSensorId` - [`PathSensorId`](https://wartiva.com/api-docs/types/path-sensor-id.html) | When set, only paths this path sensor collected are checked. |
| `existence` - [`RuleFileExistence`](https://wartiva.com/api-docs/types/rule-file-existence.html) | Requires matching paths to be present or absent on each endpoint. See [RuleFileExistence](https://wartiva.com/api-docs/types/rule-file-existence.html). |
| `contents` - [`RuleFileContents`](https://wartiva.com/api-docs/types/rule-file-contents.html) | The content check each matching file must pass. See [RuleFileContents](https://wartiva.com/api-docs/types/rule-file-contents.html). |
| `permissions` - [`RuleFilePermissions`](https://wartiva.com/api-docs/types/rule-file-permissions.html) | The permission check each matching file must pass. See [RuleFilePermissions](https://wartiva.com/api-docs/types/rule-file-permissions.html). |
| `ownership` - [`RuleFileOwnership`](https://wartiva.com/api-docs/types/rule-file-ownership.html) | The ownership check each matching file must pass. See [RuleFileOwnership](https://wartiva.com/api-docs/types/rule-file-ownership.html). |

## Used by

- [`RuleBody`](https://wartiva.com/api-docs/types/rule-body.html) union: A polymorphic body for a rule type.
- [`RuleBodyFileInput`](https://wartiva.com/api-docs/types/rule-body-file-input.html) input: Input variant of RuleBodyFile.
- [`RuleType`](https://wartiva.com/api-docs/types/rule-type.html) enum: Describes how a rule gathers the input its function evaluates.

## Example

### Example

```json
{
  "pathGlob": "xyz789",
  "pathSensorId": PathSensorId,
  "existence": "MUST_EXIST",
  "contents": RuleFileContents,
  "permissions": RuleFilePermissions,
  "ownership": RuleFileOwnership
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
