# PostureFindings Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/posturefindings/

Schema for the `PostureFindings` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`finding_id`** _(string)_
  The provider's own finding identifier, verbatim.
- **`standard_id`** _(string)_
  The benchmark this evaluation came from, as the provider emits it (e.g. a standards ARN or subscription id). Never normalized.
- **`standard_version`** _(string)_
  The benchmark version, e.g. '3.0.0'. On AWS this is parsed from the standard ARN, not returned directly; parsing failures are noted in unreadable_fields.
- **`control_id`** _(string)_
  The provider's own control identifier, unmodified — e.g. 'S3.8', 'IAM.1'. Never renamed, prefixed, or normalized.
- **`status`** _(string)_
  Outcome of the evaluation. not_applicable (skipped) is never reported as passed; unknown (could not check) is never reported as passed either. On AWS, NOT_AVAILABLE maps to not_applicable only when the reason is CONFIG_RETURNS_NOT_APPLICABLE — otherwise it maps to unknown, flagged in unreadable_fields.
  Allowed: `passed`, `failed`, `warning`, `not_applicable`, `unknown`
- **`status_reason_codes`** _(array<string>)_
  The provider's own reason codes behind the status, verbatim.
- **`severity`** _(string)_
  Severity as the provider labelled it. On AWS, a passing finding is always 'INFORMATIONAL' — this reflects the outcome, not the control's real risk level.
- **`resource_id`** _(string)_
  The provider's own identifier for the resource evaluated — an ARN or resource id.
- **`resource_type`** _(string)_
  The provider's own type string for the evaluated resource.
- **`first_observed_at`** _(string)_
  When the problem was first detected. On AWS, FirstObservedAt resets on every compliance status transition, so CreatedAt is substituted instead — flagged in unreadable_fields.
- **`last_observed_at`** _(string)_
  When the finding was most recently seen.
- **`created_at`** _(string)_
  When the provider created the finding record. Dependable on all three providers, unlike first_observed_at.
- **`title`** _(string)_
  The provider's own title for the control or finding.
- **`description`** _(string)_
  The provider's own description of the control or finding.
- **`remediation_text`** _(string)_
  The provider's own remediation guidance for this finding.
- **`remediation_url`** _(string)_
  Link to the provider's remediation documentation.
- **`workflow_status`** _(string)_
  The triage state set in the provider console. On AWS this is Workflow.Status — not the deprecated WorkflowState field, whose enum values differ.
  Allowed: `new`, `notified`, `in_progress`, `resolved`, `suppressed`, `unknown`
- **`suppressed`** _(boolean)_
  Whether the finding is suppressed in the provider console. Derived from workflow_status.
- **`record_state`** _(string)_
  Whether the finding is active or archived. On AWS, not_applicable findings auto-archive after three days, so archived findings are included here too — filtering to active only would drop them.
  Allowed: `active`, `archived`
- **`associated_standards`** _(array<string>)_
  Every benchmark this finding maps to, as provider standard identifiers.

## Methods

- [GET /unified/cloud-infrastructure/posture_findings](/docs/api-reference/unified-cloud-infrastructure-api/posturefindings/list) — List Posture findings
