PostureFindings Object
Relationships
graph LR
PostureFindings -->|"account"| Accounts
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
Every benchmark this finding maps to, as provider standard identifiers.
When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.
The provider's own control identifier, unmodified — e.g. 'S3.8', 'IAM.1'. Never renamed, prefixed, or normalized.
When the provider created the finding record. Dependable on all three providers, unlike first_observed_at.
The provider's own description of the control or finding.
The provider's own finding identifier, verbatim.
When the problem was first detected. On AWS, FirstObservedAt resets on every compliance status transition, so CreatedAt is substituted instead — flagged in unreadable_fields.
When the finding was most recently seen.
The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.
Whether the finding is active or archived. On AWS, not_applicable findings auto-archive after three days, so archived findings are included here too — filtering to active only would drop them.
activearchived
Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.
The provider's own remediation guidance for this finding.
Link to the provider's remediation documentation.
Raw data returned from the remote API call.
The provider's own identifier for the resource evaluated — an ARN or resource id.
The provider's own type string for the evaluated resource.
Severity as the provider labelled it. On AWS, a passing finding is always 'INFORMATIONAL' — this reflects the outcome, not the control's real risk level.
The benchmark this evaluation came from, as the provider emits it (e.g. a standards ARN or subscription id). Never normalized.
The benchmark version, e.g. '3.0.0'. On AWS this is parsed from the standard ARN, not returned directly; parsing failures are noted in unreadable_fields.
Outcome of the evaluation. not_applicable (skipped) is never reported as passed; unknown (could not check) is never reported as passed either. On AWS, NOT_AVAILABLE maps to not_applicable only when the reason is CONFIG_RETURNS_NOT_APPLICABLE — otherwise it maps to unknown, flagged in unreadable_fields.
passedfailedwarningnot_applicableunknown
The provider's own reason codes behind the status, verbatim.
Whether the finding is suppressed in the provider console. Derived from workflow_status.
Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
The provider's own title for the control or finding.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Explanation of the reason, where one adds anything.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
The triage state set in the provider console. On AWS this is Workflow.Status — not the deprecated WorkflowState field, whose enum values differ.
newnotifiedin_progressresolvedsuppressedunknown