Skip to content
Proud to collaborate with Microsoft for Startups

audit.software-delivery-slo.scan ​

Evaluate active software deliveries and reconcile deduplicated, auto-clearing findings without accepting caller-forged scan evidence.

Evaluate active software deliveries against the versioned Tickets SLO contract.

The workflow invokes the published evaluator directly against the organization-scoped app session, then upserts deduplicated Audit findings. Partial scans may create/update findings but cannot auto-resolve unseen ones.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-audit
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization whose active software deliveries are evaluated
limitintegerNo—Bounded active-delivery scan size (default/max 100)
triggerstringNo—manual
workflow_run_idstringNo—Engine-stamped parent DAG run id when invoked as a Step target

Output Schema ​

FieldTypeRequiredDefaultDescription
audit_run_uuiduuidNo——
statusstringNo——
contract_versionstringNo——
evaluated_atstringNo——
new_findingsintegerNo——
updated_findingsintegerNo——
resolved_findingsintegerNo——
total_findingsintegerNo——
scanned_deliveriesintegerNo——
returned_deliveriesintegerNo——
alert_signalsintegerNo——
eligible_signalsintegerNo——
good_signalsintegerNo——
breached_signalsintegerNo——
unavailable_signalsintegerNo——
terminal_successesintegerNo——
terminal_failuresintegerNo——
slifloatNo——
burnfloatNo——
scan_limitintegerNo——
matched_at_leastintegerNo——
last_evaluated_atstringNo——
budget_contract_versionstringNo——
auto_clear_performedbooleanNo——
scan_completebooleanNo——
truncatedbooleanNo——
by_severityjsonNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepjsonNo——
failed_layerjsonNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—scan—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingscancompleted—
* (any state)failfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
scannedSUCCESSSoftware-delivery SLO scan completedaudit_run_uuid, total_findings
failedFAILUREAudit workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "audit.software-delivery-slo.scan",
  "initial_data": {
    "organization_uuid": "value"
  }
}