Skip to content
Proud to collaborate with Microsoft for Startups

control.policy.evaluate_matrix ​

Evaluate a list of items against reusable policy rules and summarize compliance

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-control
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
itemsjsonYes—List of row objects to evaluate, such as services, packages, images, or controls.
rulesjsonYes—List of rule objects with id, field, op, and optional value. Operators match control.predicate.compare.
modestringNo—Per-item rule mode: all (default), any, or none.
identity_fieldsjsonNo—Fields used to build stable row identities, for example service or package.
name_fieldsjsonNo—Fields used to choose display labels for summary_text.
strict_rulesbooleanNo—Fail invalid rule definitions instead of reporting affected rows as unknown.

Output Schema ​

FieldTypeRequiredDefaultDescription
itemsjsonNo—Input item list echoed from input.
rulesjsonNo—Input rule list echoed from input.
modestringNo—Per-item rule mode used for evaluation.
identity_fieldsjsonNo—Identity fields used for matching and labels.
name_fieldsjsonNo—Name fields used for display labels.
strict_rulesbooleanNo—Whether invalid rules were fatal.
checked_countintegerNo—Number of items evaluated.
rule_countintegerNo—Number of rules evaluated per item.
compliant_countintegerNo—Number of items with compliant status.
noncompliant_countintegerNo—Number of items with noncompliant status.
unknown_countintegerNo—Number of items with unknown status.
checked_itemslistNo—Per-item policy evaluation records.
compliant_itemslistNo—Items whose rules evaluated compliant.
noncompliant_itemslistNo—Items whose rules evaluated noncompliant.
unknown_itemslistNo—Items whose rule status could not be fully determined.
summary_textstringNo—Bounded deterministic prose summary.
statusstringNo—Aggregate status: compliant, noncompliant, or unknown.
resultjsonNo—Typed envelope using schema control.policy.evaluate_matrix.v1.
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "control.policy.evaluate_matrix",
  "initial_data": {
    "items": "value",
    "rules": "value"
  }
}