organizations

Generates an audit scope report for the given standard. The report includes the following: * The technical attributes and constraints that Audit Manager uses to verify your compliance with a framework. * A list of Google Cloud services and resources that are within the scope of the framework.

post/v1/{+scope}/auditScopeReports:generate

Request

  • Base URL: https://auditmanager.googleapis.com
  • URL: https://auditmanager.googleapis.com/v1/{+scope}/auditScopeReports:generate
  • Auth: one of:
    • OAuth 2 (implicit, authorization URL https://accounts.google.com/o/oauth2/auth, scopes: https://www.googleapis.com/auth/cloud-auditmanager) and OAuth 2 (authorization code, authorization URL https://accounts.google.com/o/oauth2/auth, token URL https://accounts.google.com/o/oauth2/token, scopes: https://www.googleapis.com/auth/cloud-auditmanager)
    • OAuth 2 (implicit, authorization URL https://accounts.google.com/o/oauth2/auth, scopes: https://www.googleapis.com/auth/cloud-platform) and OAuth 2 (authorization code, authorization URL https://accounts.google.com/o/oauth2/auth, token URL https://accounts.google.com/o/oauth2/token, scopes: https://www.googleapis.com/auth/cloud-platform)

Path parameters

scopestring required

Required. Project or folder that the audit scope report is generated for, in one of the following formats: * projects/{project}/locations/{location} * folders/{folder}/locations/{location} * organizations/{organization}/locations/{location}

Request body

validateOnlyboolean

Optional. If true, only validates the request and does not generate the audit scope report. This executes standard request validation (such as schema, framework existence, scope, and IAM checks) and skips the apply phase. Use this field for the following purposes: * Infrastructure as Code (IaC): Allow tools like Terraform to run dry-run mutations (e.g., terraform plan) without creating real resources or incurring costs. * User Interface Validation: Enable real-time form and permission validation in custom UIs before submitting requests. * CI/CD & Automation: Test your scripts, permissions, and parameters safely without consuming resource quotas.

complianceFrameworkstring

Required. Framework (set of controls) that the audit scope report is generated against. For example, NIST_800_53.

complianceStandardstring

Optional. Deprecated. The standard (industry or regulatory requirements) that the audit scope report is run against. Use the compliance_framework field instead.

reportFormat'AUDIT_SCOPE_REPORT_FORMAT_UNSPECIFIED' | 'AUDIT_SCOPE_REPORT_FORMAT_ODF'

Required. Format for the audit scope report.

Response

Successful response

Changes

No recorded changes to this operation across all 1 revision of this API.