---
title: RuleType enum | Wartiva GraphQL API
description: Describes how a rule gathers the input its function evaluates. The type determines which body the rule carries — see RuleBody.
url: https://wartiva.com/api-docs/types/rule-type.html
updated: 2026-10-07
---

Policies and findings · GraphQL enum

# `RuleType` enum

Describes how a rule gathers the input its function evaluates. The type determines which body the rule carries — see [RuleBody](https://wartiva.com/api-docs/types/rule-body.html).

## Values

| Enum Value | Description |
|---|---|
| `CONFIGURATION` | The rule checks an object's attributes against a required state. Evaluated whenever that object changes, so it carries no schedule. Its body is [RuleBodyConfiguration](https://wartiva.com/api-docs/types/rule-body-configuration.html). |
| `FILE` | The rule checks the files your path sensors collect: that they exist or don't on each [Endpoint](https://wartiva.com/api-docs/types/endpoint.html), or that each matching file a sensor collected, listed on its [EndpointPath](https://wartiva.com/api-docs/types/endpoint-path.html), meets the rule's content, permission, and ownership expectations, one finding per failing file. Runs on the rule's [Schedule](https://wartiva.com/api-docs/types/schedule.html). Its body is [RuleBodyFile](https://wartiva.com/api-docs/types/rule-body-file.html). |
| `PROPRIETARY` | The rule runs a check that ships with the platform rather than one authored as rule content, so it carries no query or function of its own. Runs on the rule's [Schedule](https://wartiva.com/api-docs/types/schedule.html). Its body is [RuleBodyProprietary](https://wartiva.com/api-docs/types/rule-body-proprietary.html). |
| `SEARCH` | The rule flags every object its graph search finds, and clears the finding once an object no longer matches. Runs on the rule's [Schedule](https://wartiva.com/api-docs/types/schedule.html). Its body is [RuleBodySearch](https://wartiva.com/api-docs/types/rule-body-search.html). |
| `THRESHOLD` | The rule counts, for each object it applies to, the related objects its count path reaches, and flags every object whose count falls below its minimum or above its maximum. Runs on the rule's [Schedule](https://wartiva.com/api-docs/types/schedule.html). Its body is [RuleBodyThreshold](https://wartiva.com/api-docs/types/rule-body-threshold.html). |
| `VULNERABILITY` | The rule matches the CPEs on the objects it applies to against known CVEs, raising a finding and issue for each vulnerability it identifies, or one per object listing them all. Runs on the rule's [Schedule](https://wartiva.com/api-docs/types/schedule.html). Its body is [RuleBodyVulnerability](https://wartiva.com/api-docs/types/rule-body-vulnerability.html). |

## Used by

- [`Finding`](https://wartiva.com/api-docs/types/finding.html) type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
- [`Issue`](https://wartiva.com/api-docs/types/issue.html) type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
- [`Rule`](https://wartiva.com/api-docs/types/rule.html) type: A policy rule evaluated against graph objects.
- [`RuleInput`](https://wartiva.com/api-docs/types/rule-input.html) input: Input variant of Rule carrying its writable fields.

## Related types

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointPath`](https://wartiva.com/api-docs/types/endpoint-path.html) The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…

## Example

### Example

```json
"CONFIGURATION"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
