ControlsGet a control

Get a control

Returns one control including description, mapped frameworks, requirements, and authorship metadata. Optional expansions via fields: complianceOverview, mappedArtifacts, mappedRisks. mappedArtifacts includes policy, evidence, and automated tests only. File download URLs are never returned. Requires scope control:read or control:write.

curl -X GET "https://api.scrut.io/v1/controls/2aa1b21e-4705-47cd-b1a7-e74ed4808bc9?fields=complianceOverview%2CmappedArtifacts%2CmappedRisks" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": {
    "controlId": "2aa1b21e-4705-47cd-b1a7-e74ed4808bc9",
    "controlCode": "DCH-14.2",
    "controlName": "Transfer Authorizations",
    "controlDescription": "Authorize and record transfers of sensitive data before they leave the environment.",
    "controlDomain": "Data Classification and Handling",
    "functionGrouping": "govern",
    "controlScope": "out_of_scope",
    "controlCompliancePercentage": 40,
    "status": "non_compliant",
    "assignees": [
      {
        "name": "Alex Rivera",
        "email": "alex@example.com",
        "isPrimary": true
      }
    ],
    "entities": [
      {
        "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
        "entityName": "Organization Wide"
      }
    ],
    "mappedFrameworks": [
      {
        "frameworkId": "14c4c45d-6c31-4097-a02a-ad9cfd04850e",
        "frameworkName": "SOC 2"
      }
    ],
    "controlQuestions": "Are transfer authorizations reviewed before data leaves the environment?",
    "outOfScopeReason": "This control does not apply to the selected entity.",
    "addedBy": {
      "name": "Alex Rivera",
      "email": "alex@example.com"
    },
    "addedOn": 1704067200000,
    "lastModifiedBy": {
      "name": "Alex Rivera",
      "email": "alex@example.com"
    },
    "modifiedOn": 1704067200000,
    "mappedRequirements": [
      {
        "frameworkName": "SOC 2",
        "requirementCode": "CC6.1",
        "requirementName": "Logical Access Security"
      }
    ],
    "complianceOverview": [
      {
        "frameworkName": "SOC 2",
        "entities": [
          {
            "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
            "entityName": "Organization Wide"
          }
        ],
        "controlStatus": "non_compliant",
        "artifactCompliancePercentage": 40
      }
    ],
    "mappedArtifacts": [
      {
        "name": "Information Security Policy",
        "artifactType": "policy",
        "artifactStatus": "not_uploaded",
        "entities": [
          {
            "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
            "entityName": "Organization Wide"
          }
        ],
        "frameworks": [
          "SOC 2"
        ],
        "isRelevant": true,
        "justification": "This control does not apply to the selected entity."
      }
    ],
    "mappedRisks": [
      {
        "riskId": "c3d4e5f6-a7b8-4901-8c2d-3e4f5a6b7c8d",
        "riskName": "Unauthorized access to production systems"
      }
    ]
  },
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
GET
/v1/controls/{controlId}
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
path
controlIdstring
Required

Control identifier returned by list and get endpoints.

query
fieldsstring

Optional expansions. Default get response already includes core metadata; use this to add complianceOverview, mappedArtifacts, or mappedRisks. Pass a comma-separated list (no spaces required). Allowed values: complianceOverview, mappedArtifacts, mappedRisks.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Path Parameters

controlIdstring
Required

Control identifier returned by list and get endpoints.

Example:
2aa1b21e-4705-47cd-b1a7-e74ed4808bc9

Query Parameters

fieldsstring

Optional expansions. Default get response already includes core metadata; use this to add complianceOverview, mappedArtifacts, or mappedRisks. Pass a comma-separated list (no spaces required). Allowed values: complianceOverview, mappedArtifacts, mappedRisks.

Example:
complianceOverview,mappedArtifacts,mappedRisks

Responses

dataobject
Required
metaobject
Required