ControlsList controls

List controls

Returns controls for the authenticated tenant. Default items include identifiers, domain, grouping, scope, computed compliance status, and owners. When frameworkIds is set, status and percentage are computed in that framework set. Request extra columns with fields (comma-separated). List responses are a JSON array in data. There is no cursor pagination on this endpoint. Requires scope control:read or control:write.

curl -X GET "https://api.scrut.io/v1/controls?status=compliant%2Cnon_compliant&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&assigneeEmails=alex%40example.com%2Calex%40example.com&domains=Logical%20and%20Physical%20Access%20Controls&functionGroupings=protect%2Cdetect&controlScope=in_scope&fields=mappedFrameworkIds%2CoutOfScopeReason%2CmarkedOutOfScopeBy" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": [
    {
      "controlId": "8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b",
      "controlCode": "CC6.1",
      "controlName": "Logical access",
      "controlDomain": "Logical and Physical Access Controls",
      "functionGrouping": "govern",
      "controlScope": "out_of_scope",
      "status": "non_compliant",
      "controlCompliancePercentage": 40,
      "assignees": [
        {
          "name": "Alex Rivera",
          "email": "alex@example.com",
          "isPrimary": true
        }
      ],
      "entities": [
        {
          "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
          "entityName": "Organization Wide"
        }
      ],
      "mappedFrameworkIds": [
        "14c4c45d-6c31-4097-a02a-ad9cfd04850e"
      ],
      "outOfScopeReason": "This control does not apply to the selected entity.",
      "markedOutOfScopeBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "addedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "addedOn": 1704067200000,
      "lastModifiedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "modifiedOn": 1704067200000
    }
  ],
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
GET
/v1/controls
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
query
statusstring

Filter by computed control compliance status. Pass a comma-separated list (no spaces required). Allowed values: non_compliant, compliant, not_applicable.

query
frameworkIdsstring

Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).

query
entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

query
assigneeEmailsstring

Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).

query
domainsstring

Filter by control domain name. Match is case-insensitive. Pass a comma-separated list (no spaces required).

query
functionGroupingsstring

Filter by NIST-style function grouping. Pass a comma-separated list (no spaces required). Allowed values: govern, identify, protect, detect, respond, recover.

query
controlScopestring

Filter by control scope. Pass a comma-separated list (no spaces required). Allowed values: out_of_scope, in_scope.

query
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, outOfScopeReason, markedOutOfScopeBy, addedBy, addedOn, lastModifiedBy, modifiedOn.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Query Parameters

statusstring

Filter by computed control compliance status. Pass a comma-separated list (no spaces required). Allowed values: non_compliant, compliant, not_applicable.

Example:
compliant,non_compliant
frameworkIdsstring

Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).

Example:
14c4c45d-6c31-4097-a02a-ad9cfd04850e,3a10a604-b942-43e5-8294-d418a0448ee5
entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

Example:
8fa88e7b-eb16-4999-854a-2f407958740a
assigneeEmailsstring

Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).

Example:
alex@example.com,alex@example.com
domainsstring

Filter by control domain name. Match is case-insensitive. Pass a comma-separated list (no spaces required).

Example:
Logical and Physical Access Controls
functionGroupingsstring

Filter by NIST-style function grouping. Pass a comma-separated list (no spaces required). Allowed values: govern, identify, protect, detect, respond, recover.

Example:
protect,detect
controlScopestring

Filter by control scope. Pass a comma-separated list (no spaces required). Allowed values: out_of_scope, in_scope.

Example:
in_scope
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, outOfScopeReason, markedOutOfScopeBy, addedBy, addedOn, lastModifiedBy, modifiedOn.

Example:
mappedFrameworkIds,outOfScopeReason,markedOutOfScopeBy

Responses

dataarray
Required
metaobject
Required