Skip to content

Relationships

Schema relationships
graph LR
    PostureFindings -->|"account"| Accounts

Properties

idstring
required·

Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.

accountstring

The account, subscription or project this object belongs to.

References: Accounts → id
associated_standardsstring[]

Every benchmark this finding maps to, as provider standard identifiers.

collected_atstring · date-time

When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.

control_idstring

The provider's own control identifier, unmodified — e.g. 'S3.8', 'IAM.1'. Never renamed, prefixed, or normalized.

created_atstring · date-time

When the provider created the finding record. Dependable on all three providers, unlike first_observed_at.

descriptionstring

The provider's own description of the control or finding.

finding_idstring

The provider's own finding identifier, verbatim.

first_observed_atstring · date-time

When the problem was first detected. On AWS, FirstObservedAt resets on every compliance status transition, so CreatedAt is substituted instead — flagged in unreadable_fields.

last_observed_atstring · date-time

When the finding was most recently seen.

native_typestring

The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.

providerstring

Which cloud this object was read from.

Possible values:
awsazuregcp
provider_idstring

The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.

record_statestring

Whether the finding is active or archived. On AWS, not_applicable findings auto-archive after three days, so archived findings are included here too — filtering to active only would drop them.

Possible values:
activearchived
regionstring

Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.

remediation_textstring

The provider's own remediation guidance for this finding.

remediation_urlstring

Link to the provider's remediation documentation.

remote_dataRecord<string, any>

Raw data returned from the remote API call.

resource_idstring

The provider's own identifier for the resource evaluated — an ARN or resource id.

resource_typestring

The provider's own type string for the evaluated resource.

severitystring

Severity as the provider labelled it. On AWS, a passing finding is always 'INFORMATIONAL' — this reflects the outcome, not the control's real risk level.

standard_idstring

The benchmark this evaluation came from, as the provider emits it (e.g. a standards ARN or subscription id). Never normalized.

standard_versionstring

The benchmark version, e.g. '3.0.0'. On AWS this is parsed from the standard ARN, not returned directly; parsing failures are noted in unreadable_fields.

statusstring

Outcome of the evaluation. not_applicable (skipped) is never reported as passed; unknown (could not check) is never reported as passed either. On AWS, NOT_AVAILABLE maps to not_applicable only when the reason is CONFIG_RETURNS_NOT_APPLICABLE — otherwise it maps to unknown, flagged in unreadable_fields.

Possible values:
passedfailedwarningnot_applicableunknown
status_reason_codesstring[]

The provider's own reason codes behind the status, verbatim.

suppressedboolean

Whether the finding is suppressed in the provider console. Derived from workflow_status.

tagsobject

Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.

titlestring

The provider's own title for the control or finding.

unreadable_fieldsobject[]

Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.

detailstring

Explanation of the reason, where one adds anything.

fieldstring

The property on this resource that could not be read.

reasonstring

Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.

Possible values:
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
updated_atstring

When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.

workflow_statusstring

The triage state set in the provider console. On AWS this is Workflow.Status — not the deprecated WorkflowState field, whose enum values differ.

Possible values:
newnotifiedin_progressresolvedsuppressedunknown