Policies and findings · GraphQL type

Rule type

A policy rule evaluated against graph objects. Its function returns PASS or FAIL; a FAIL generates one or more Finding objects.

Fields

Field Name Description
id - ID!

Unique identifier for this rule. Submit it as the id of a RuleInput to policyRulesEdit, or to policyRulesRemove.

Note: unlike every other type implementing GraphObject, this is the rule's own identifier rather than its graph object identifier, because the policy mutations address rules by it.

orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! The time this rule was created at.
updatedAt - Time! The time this rule was last modified.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
group - String! The group this rule belongs to.
source - RuleSource! Where this rule came from: provided by Wartiva, or created or modified by the organization.
applyTo - GraphObjectType! Defines what object type this rule applies to.
applyToOptions - [RuleApplyToOption!]! Optional key/operator/value constraints that further scope which objects this rule applies to. Empty when the rule applies to every object of its applyTo type. CONFIGURATION rules accept any option their applyTo type can resolve; FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules accept only a single OS option with the EQUALS operator.
osNeutral - Boolean! True when the rule's check and remediation hold on every OS, such as a full disk or an outdated agent. An OS-neutral rule carries no OS option and its CLI remediation fills in no values from the evaluated object.
name - String! The name of the rule.
discoveryName - String! The name given to the Finding (and paired Issue) objects this rule generates.
description - String! The description of the rule.
notes - String! Free-text notes about the rule. Blank when there are none.
enabled - Boolean! Is the rule enabled.
severity - Severity! The severity of the Finding objects, and the paired Issue, generated by the rule.
type - RuleType! The type of rule, which decides how the rule gathers the input its function evaluates.
body - RuleBody

The body for this rule's type, including the function that implements the rule logic. See RuleBody.

Null when the rule carries no body for a type this deployment recognizes. Nullable so that one such rule returns an empty field rather than emptying the list it appears in.

schedule - Schedule! When this rule is evaluated. NONE when the rule is evaluated as its objects change, which is how every rule of a change-driven type such as CONFIGURATION runs — those types accept no other schedule. FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules run on their schedule and need a CRONTAB one; they reject NONE. See Schedule.
mockOptions - [MockDataOption!] Options used to generate mock data for testing the rule.
lastMockDataInput - String! JSON-encoded test cases for the rule's function: an array of {name, input, expect} where expect is "PASS" or "FAIL". Empty when no test cases are stored.
remediationInstructions - RemediationInstructions! How to remediate findings from this rule. See RemediationInstructions.
securityFrameworks - [SecurityFrameworkReference!] The security frameworks this rule helps satisfy, each with the products it is assessed under and the sections within them it is filed under. See SecurityFrameworkReference.
risks - [SecurityRisk!] List of applicable security risks this rule is related to.
tactics - [SecurityTactic!] List of applicable security tactics this rule is related to.
createdBy - User The user that created this rule, if any.
findings - FindingsPayload! Findings generated by this rule.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Issue objects generated by this rule.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Used by

  • Finding type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Issue type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RulesListPayload type: Result of the policyRulesList query.

Related types

  • Finding The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Issue The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "group": "xyz789",
  "source": "VENDOR",
  "applyTo": "ACCOUNT_POLICY",
  "applyToOptions": [RuleApplyToOption],
  "osNeutral": false,
  "name": "xyz789",
  "discoveryName": "xyz789",
  "description": "abc123",
  "notes": "xyz789",
  "enabled": true,
  "severity": "INFORMATIONAL",
  "type": "CONFIGURATION",
  "body": RuleBodyConfiguration,
  "schedule": Schedule,
  "mockOptions": [MockDataOption],
  "lastMockDataInput": "xyz789",
  "remediationInstructions": RemediationInstructions,
  "securityFrameworks": [SecurityFrameworkReference],
  "risks": ["VULNERABILITY"],
  "tactics": ["RECONNAISSANCE"],
  "createdBy": User,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}