Compliance Audit Reports

Policies API v1 endpoints for generating and downloading compliance audit reports.

Generate compliance audit reports across standards and targets, then list, download, and delete the generated report artifacts.

All paths are relative to /policies/api/v1. See Policies API v1 for authentication and conventions.

Endpoints

OperationMethodPath
List compliance report artifactsGET/compliance/reports/artifacts
Generate a compliance audit reportPOST/compliance/reports/generate
Get a compliance report artifactGET/compliance/reports/artifacts/{id}
Delete a compliance report artifactDELETE/compliance/reports/artifacts/{id}
Download a compliance report artifactGET/compliance/reports/artifacts/{id}/download
Generate a scheduled report nowPOST/compliance/reports/schedules/{scheduleId}/generate-now

Reference

List compliance report artifacts

GET /policies/api/v1/compliance/reports/artifacts

Lists stored compliance report artifacts, newest first. Filters match both single-scope and composed audit reports.

Roles: admin, platform, security, devops

Query parameters

NameTypeRequiredDefaultDescription
targetIdstringNo—Filter by target UUID
standardstringNo—Filter by standard key
scheduleIdstringNo—Filter by originating schedule
sourcestringNo—Filter by source: policy_hub | compliance_standard | audit
limitintegerNo100Page size; <=0 uses default, max 500
offsetintegerNo0Items to skip (>=0)

Response 200 (application/json)

Array of artifact summaries (no total count)

FieldTypeDescription
idstring (uuid)Artifact ID
scheduleRefstringSchedule that produced it, if any
sourcestringpolicy_hub | compliance_standard | audit
targetIdstring (uuid)Single-scope artifacts only
targetTypestring—
targetNamestring—
standardstringSingle-scope artifacts only
generatedAtstring (date-time)—
triggerTypestringscheduled | on_demand
scorenumber—
levelstringgreen | yellow | red | unknown
passControlsinteger—
failControlsinteger—
totalControlsinteger—
standardsstring[]Composed audit reports
targetIdsstring[]Composed audit reports
periodFromstring (date-time)Composed audit reports
periodTostring (date-time)Composed audit reports

Errors

  • 400 — INVALID_OFFSET or INVALID_FILTER (bad targetId)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Generate a compliance audit report

POST /policies/api/v1/compliance/reports/generate

Generates a composed audit report covering several standards and targets over a time period and stores it as an artifact. The period defaults to the last 30 days.

Roles: admin, security

Request body (application/json)

FieldTypeRequiredDescription
standardsstring[]YesStandard keys (must be known)
targetIdsstring[]YesTarget UUIDs
fromstring (date-time)NoPeriod start; must be given together with to
tostring (date-time)NoPeriod end; after from
periodDaysintegerNoRolling window when from/to absent; default 30, max 10000

Response 200 (application/json)

{artifactId, generatedAt, score, level, sectionsWithData, sectionsWithoutData}

FieldTypeDescription
artifactIdstring (uuid)—
generatedAtstring (date-time)—
scorenumber—
levelstring—
sectionsWithDataintegerStandard x target sections with scan data
sectionsWithoutDataintegerSections with no data

Errors

  • 400 — Invalid options, e.g. unknown standard, bad target UUID, from/to mismatch, scope too large (INVALID_REPORT_CONFIG)
  • 500 — GENERATE_FAILED
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Example

{"standards":["soc2","cis-eks"],"targetIds":["3f1c..."],"from":"2026-09-01T00:00:00Z","to":"2026-10-01T00:00:00Z"}

Get a compliance report artifact

GET /policies/api/v1/compliance/reports/artifacts/{id}

Returns an artifact’s metadata plus the full report content: an nctl-format snapshot for single-scope artifacts, or the composed audit report for multi-standard reports.

Roles: admin, platform, security, devops

Path parameters

NameTypeDescription
idstringArtifact ID (UUID)

Response 200 (application/json)

Artifact summary fields + contentSha256 + report

FieldTypeDescription
idstring (uuid)Artifact ID
scheduleRefstringSchedule that produced it, if any
sourcestringpolicy_hub | compliance_standard | audit
targetIdstring (uuid)Single-scope artifacts only
targetTypestring—
targetNamestring—
standardstringSingle-scope artifacts only
generatedAtstring (date-time)—
triggerTypestringscheduled | on_demand
scorenumber—
levelstringgreen | yellow | red | unknown
passControlsinteger—
failControlsinteger—
totalControlsinteger—
standardsstring[]Composed audit reports
targetIdsstring[]Composed audit reports
periodFromstring (date-time)Composed audit reports
periodTostring (date-time)Composed audit reports
contentSha256stringHash of stored report content
reportobjectSnapshot or composed audit report

Errors

  • 404 — Artifact not found or id malformed (ARTIFACT_NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Delete a compliance report artifact

DELETE /policies/api/v1/compliance/reports/artifacts/{id}

Permanently deletes a stored report artifact.

Roles: admin, security

Path parameters

NameTypeDescription
idstringArtifact ID (UUID)

Response 204

No content

Errors

  • 404 — Artifact not found or id malformed (ARTIFACT_NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Download a compliance report artifact

GET /policies/api/v1/compliance/reports/artifacts/{id}/download

Downloads an artifact as a JSON, CSV, or PDF attachment. PDF is available only for composed audit reports and is cached after the first render.

Roles: admin, platform, security, devops

Path parameters

NameTypeDescription
idstringArtifact ID (UUID)

Query parameters

NameTypeRequiredDefaultDescription
formatstringNojsonjson | csv | pdf

Response 200 (application/json | text/csv | application/pdf)

File attachment (compliance-report-<scope>-<id>.<ext>)

Errors

  • 400 — Unsupported format (UNSUPPORTED_FORMAT)
  • 404 — Artifact not found (ARTIFACT_NOT_FOUND) or PDF requested for a non-audit artifact (PDF_NOT_AVAILABLE)
  • 500 — PDF rendering failed (PDF_RENDER_FAILED)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Generate a scheduled report now

POST /policies/api/v1/compliance/reports/schedules/{scheduleId}/generate-now

Immediately generates a report artifact using a compliance report schedule’s saved configuration (compliance history, compliance standard history, or audit report types). The run is recorded as on-demand but attributed to the schedule.

Roles: admin, security

Path parameters

NameTypeDescription
scheduleIdstringReport schedule ID

Response 200 (application/json)

{artifactId, generatedAt, score}

FieldTypeDescription
artifactIdstring (uuid)—
generatedAtstring (date-time)—
scorenumber—

Errors

  • 400 — Schedule is not a compliance report schedule (NOT_A_COMPLIANCE_HISTORY_SCHEDULE) or its config is invalid (INVALID_REPORT_CONFIG)
  • 404 — Schedule not found (SCHEDULE_NOT_FOUND)
  • 409 — Report already exists for the period (DUPLICATE_PERIOD)
  • 500 — GENERATE_FAILED
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles