compliance

Read every runtime compliance control's current state (machine feed, bearer token)

Read-only feed for the compliance team's Risk & Controls Registry. Authenticated by a bearer token dedicated to this route, never by a session. Returns one entry per runtime compliance control with its on/off state and the time, operator and note of its latest change, and one entry per allowlisted engineering setting (today aml_rules_enabled, the AML rule engine's switch) with its effective value and source. Answers 503 when the deployment has no token configured, and 401 control_state_feed_token_invalid for a missing, malformed or wrong token.

get/compliance/control_states

Response

OK

environmentstring required

The deployment environment the state was read from, for example prod.

read_atstring date-time required

When this response was read from the control registry, RFC 3339 UTC.

Changes

Changed in 2 of the 43 revisions of this API.2