Compliance Coverage
The materialized coverage read model for one adopted framework version, in one call (ADR-0015): each applicable requirement with its serving control, weakest-wins status, contributing resource bindings, evidence count, any risk acceptance, and per-row staleness. Reads projections, never recomputes.
ADR-0023: aws_account_id selects that account’s rollup rows in the same
shape. Without it, unrestricted callers get the tenant-level rollup;
account-restricted callers get their single account’s rollup, or the named
400 when they reach several, the tenant aggregate is never served to them.
Parameters
Section titled “ Parameters ”Query Parameters
Section titled “Query Parameters ”Cookie Parameters
Section titled “Cookie Parameters ”Responses
Section titled “ Responses ”Successful Response
object
One control-category filter for this framework’s matrix (A63). Served rather than derived client-side so the label, the order, and the count come from the catalog the coverage rows were built from.
object
object
object
One thing that must be satisfied for a requirement, the strict roll-up made legible.
kind is control (something the platform deploys, evaluates, or inherits)
or attestation (the one document covering what no control reaches).
state is the per-contributor vocabulary (satisfied / inherited / attested /
partial / unsatisfied / unreachable), distinct from the requirement’s
rollup_status.
object
object
object
Validation Error