---
title: Rule type | Wartiva GraphQL API
description: A policy rule evaluated against graph objects. Its function returns PASS or FAIL; a FAIL generates one or more Finding objects.
url: https://wartiva.com/api-docs/types/rule.html
updated: 2026-10-07
---

Policies and findings · GraphQL type

# `Rule` type

A policy rule evaluated against graph objects. Its function returns PASS or FAIL; a FAIL generates one or more [Finding](https://wartiva.com/api-docs/types/finding.html) objects.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | Unique identifier for this rule. Submit it as the `id` of a [RuleInput](https://wartiva.com/api-docs/types/rule-input.html) to [policyRulesEdit](https://wartiva.com/api-docs/mutations/policy-rules-edit.html), or to [policyRulesRemove](https://wartiva.com/api-docs/mutations/policy-rules-remove.html). Note: unlike every other type implementing [GraphObject](https://wartiva.com/api-docs/types/graph-object.html), this is the rule's own identifier rather than its graph object identifier, because the policy mutations address rules by it. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier for the owning organization. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | When this graph object was seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this rule was created at. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this rule was last modified. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `group` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The group this rule belongs to. |
| `source` - [`RuleSource!`](https://wartiva.com/api-docs/types/rule-source.html) | Where this rule came from: provided by Wartiva, or created or modified by the organization. |
| `applyTo` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | Defines what object type this rule applies to. |
| `applyToOptions` - [`[RuleApplyToOption!]!`](https://wartiva.com/api-docs/types/rule-apply-to-option.html) | Optional key/operator/value constraints that further scope which objects this rule applies to. Empty when the rule applies to every object of its applyTo type. CONFIGURATION rules accept any option their applyTo type can resolve; FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules accept only a single OS option with the EQUALS operator. |
| `osNeutral` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True when the rule's check and remediation hold on every OS, such as a full disk or an outdated agent. An OS-neutral rule carries no OS option and its CLI remediation fills in no values from the evaluated object. |
| `name` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The name of the rule. |
| `discoveryName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The name given to the [Finding](https://wartiva.com/api-docs/types/finding.html) (and paired [Issue](https://wartiva.com/api-docs/types/issue.html)) objects this rule generates. |
| `description` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The description of the rule. |
| `notes` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Free-text notes about the rule. Blank when there are none. |
| `enabled` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | Is the rule enabled. |
| `severity` - [`Severity!`](https://wartiva.com/api-docs/types/severity.html) | The severity of the [Finding](https://wartiva.com/api-docs/types/finding.html) objects, and the paired [Issue](https://wartiva.com/api-docs/types/issue.html), generated by the rule. |
| `type` - [`RuleType!`](https://wartiva.com/api-docs/types/rule-type.html) | The type of rule, which decides how the rule gathers the input its function evaluates. |
| `body` - [`RuleBody`](https://wartiva.com/api-docs/types/rule-body.html) | The body for this rule's type, including the function that implements the rule logic. See [RuleBody](https://wartiva.com/api-docs/types/rule-body.html). Null when the rule carries no body for a type this deployment recognizes. Nullable so that one such rule returns an empty field rather than emptying the list it appears in. |
| `schedule` - [`Schedule!`](https://wartiva.com/api-docs/types/schedule.html) | When this rule is evaluated. NONE when the rule is evaluated as its objects change, which is how every rule of a change-driven type such as CONFIGURATION runs — those types accept no other schedule. FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules run on their schedule and need a CRONTAB one; they reject NONE. See [Schedule](https://wartiva.com/api-docs/types/schedule.html). |
| `mockOptions` - [`[MockDataOption!]`](https://wartiva.com/api-docs/types/mock-data-option.html) | Options used to generate mock data for testing the rule. |
| `lastMockDataInput` - [`String!`](https://wartiva.com/api-docs/types/string.html) | JSON-encoded test cases for the rule's function: an array of {name, input, expect} where expect is "PASS" or "FAIL". Empty when no test cases are stored. |
| `remediationInstructions` - [`RemediationInstructions!`](https://wartiva.com/api-docs/types/remediation-instructions.html) | How to remediate findings from this rule. See [RemediationInstructions](https://wartiva.com/api-docs/types/remediation-instructions.html). |
| `securityFrameworks` - [`[SecurityFrameworkReference!]`](https://wartiva.com/api-docs/types/security-framework-reference.html) | The security frameworks this rule helps satisfy, each with the products it is assessed under and the sections within them it is filed under. See [SecurityFrameworkReference](https://wartiva.com/api-docs/types/security-framework-reference.html). |
| `risks` - [`[SecurityRisk!]`](https://wartiva.com/api-docs/types/security-risk.html) | List of applicable security risks this rule is related to. |
| `tactics` - [`[SecurityTactic!]`](https://wartiva.com/api-docs/types/security-tactic.html) | List of applicable security tactics this rule is related to. |
| `createdBy` - [`User`](https://wartiva.com/api-docs/types/user.html) | The user that created this rule, if any. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Findings generated by this rule. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | [Issue](https://wartiva.com/api-docs/types/issue.html) objects generated by this rule. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Used by

- [`Finding`](https://wartiva.com/api-docs/types/finding.html) type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
- [`Issue`](https://wartiva.com/api-docs/types/issue.html) type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`RulesListPayload`](https://wartiva.com/api-docs/types/rules-list-payload.html) type: Result of the policyRulesList query.

## Related types

- [`Finding`](https://wartiva.com/api-docs/types/finding.html) The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
- [`Issue`](https://wartiva.com/api-docs/types/issue.html) The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "group": "xyz789",
  "source": "VENDOR",
  "applyTo": "ACCOUNT_POLICY",
  "applyToOptions": [RuleApplyToOption],
  "osNeutral": false,
  "name": "xyz789",
  "discoveryName": "xyz789",
  "description": "abc123",
  "notes": "xyz789",
  "enabled": true,
  "severity": "INFORMATIONAL",
  "type": "CONFIGURATION",
  "body": RuleBodyConfiguration,
  "schedule": Schedule,
  "mockOptions": [MockDataOption],
  "lastMockDataInput": "xyz789",
  "remediationInstructions": RemediationInstructions,
  "securityFrameworks": [SecurityFrameworkReference],
  "risks": ["VULNERABILITY"],
  "tactics": ["RECONNAISSANCE"],
  "createdBy": User,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
