Skip to content
Proud to collaborate with Microsoft for Startups

Audit ​

WorkflowTypeDescription
audit.audit-run.archiveAtomicArchive an audit scan run using the soft-delete lifecycle.
audit.audit-run.deleteAtomicSoft-delete an audit scan run.
audit.audit-run.getAtomicGet one audit scan run for an organization.
audit.audit-run.listAtomicList audit scan runs for an organization.
audit.evidence.recordAtomicAtomic adapter for audit.evidence.record; required by parent workflow specs: identity.access.review-and-revoke, identity.org.invite-and-provision-role, identity.user.offboard-and-transfer-ownership, policy.service-account.create-least-privilege.
audit.export-evidence-packDagCollect workflow run history, resource evidence, and policy decisions into a downloadable audit evidence package.
audit.finding.archiveAtomicArchive an audit finding using the soft-delete lifecycle.
audit.finding.deleteAtomicSoft-delete an audit finding.
audit.finding.getAtomicGet one audit finding for an organization.
audit.finding.listAtomicList audit findings for an organization.
audit.software-delivery-slo.scanAtomicEvaluate active software deliveries and reconcile deduplicated, auto-clearing findings without accepting caller-forged scan evidence.
audit.software-delivery-slo.scan-and-syncDagRun the software-delivery SLO scan, list findings for the audit run, and fan out ticket.sync.software-delivery-slo-finding for each row.
audit.workflow-health.scanAtomicAudit an organization's workflow-execution health (failed / stuck / deprecated-type runs) and emit trackable findings.
audit.workflow-run.aggregateAtomicAggregate workflow-run counts per workflow_type for an organization, optionally scoped to a domain prefix group and a time window.
audit.workflow-run.get-historyAtomicFull transition log for one workflow run, after verifying it belongs to the caller's organization.
audit.workflow-run.queryAtomicList workflow runs for an organization, filterable by workflow-type prefixes, state, terminal status, actor, and time range.