---
title: "Read every runtime compliance control's current state (machine feed, bearer token)"
method: GET
path: "/compliance/control_states"
tags: ["compliance"]
---

# Read every runtime compliance control's current state (machine feed, bearer token)

`GET /compliance/control_states`

Read-only feed for the compliance team's Risk & Controls Registry. Authenticated by a bearer token dedicated to this route, never by a session. Returns one entry per runtime compliance control with its on/off state and the time, operator and note of its latest change, and one entry per allowlisted engineering setting (today aml_rules_enabled, the AML rule engine's switch) with its effective value and source. Answers 503 when the deployment has no token configured, and 401 control_state_feed_token_invalid for a missing, malformed or wrong token.

## Response `200`

OK

- ControlfeedListControlStatesOutput
  - `controls` ControlfeedControlStateView[], nullable, required — One entry per runtime compliance control this build knows, sorted by key. The set is closed and small, so the list is not paginated.
    - `changed_at` string, date-time, nullable, required — When the latest change was recorded, RFC 3339 UTC, or null if the control has never been changed.
    - `changed_by` string, nullable, required — Who made the latest change, as recorded on it (an operator id or the operator named on an admin change), or null if the control has never been changed.
    - `enabled` boolean, required — Whether the control is on. A control that has never been changed is off.
    - `key` string, required — The control key, for example sdn_screening.
    - `note` string, nullable, required — The justification recorded with the latest change, or null if the control has never been changed.
  - `engineering_settings` ControlfeedEngineeringSettingView[], nullable, required — One entry per engineering setting a registry row depends on, from a fixed allowlist in this build: today only aml_rules_enabled, the AML rule engine's switch. Each carries its effective value and the precedence level it came from.
    - `enabled` boolean, required — Whether the setting is on in the process that answered, after the Engineering Controls precedence: an operator row, else the deployment's environment value, else the code default. aml_rules_enabled on means the AML rule engine runs its sweep.
    - `key` string, required — The engineering setting key, for example aml_rules_enabled.
    - `source` 'live_database' | 'environment' | 'code_default', required
  - `environment` string, required — The deployment environment the state was read from, for example prod.
  - `read_at` string, date-time, required — When this response was read from the control registry, RFC 3339 UTC.

## Other responses

- `401` — Unauthorized
- `503` — Service Unavailable
- `default` — Error response.

## Changes

- **2026-09-24** `c1348532239f` — 1 info
  - added the required property `engineering_settings` to the response with the `200` status
- **2026-09-23** `9d861107c815` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/stablesea/apis/stable-sea-backend/changes/compliance/control_states/get.md)

---

[API](https://skmtc.dev/stablesea/apis/stable-sea-backend.md) · [All operations](https://skmtc.dev/stablesea/apis/stable-sea-backend/llms.txt) · [OpenAPI document](https://skmtc.dev/stablesea/apis/stable-sea-backend/revisions/823fcbbd2f80?raw)
