EvidenceList evidence

List evidence

Returns evidence records for the authenticated tenant. Default items include identifiers, status, owners, entities, gap status, and gap count. Mapped framework names are not included on list; request mappedFrameworkIds via fields, or use get-by-id. Request extra columns with fields (comma-separated). List responses are a JSON array in data. There is no cursor pagination on this endpoint. Requires scope evidence:read or evidence:write.

curl -X GET "https://api.scrut.io/v1/evidence?status=uploaded%2Cneeds_review&frameworkIds=14c4c45d-6c31-4097-a02a-ad9cfd04850e%2C3a10a604-b942-43e5-8294-d418a0448ee5&controlIds=2aa1b21e-4705-47cd-b1a7-e74ed4808bc9%2C8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b&entityIds=8fa88e7b-eb16-4999-854a-2f407958740a&isRelevant=true&assigneeEmails=alex%40example.com%2Calex%40example.com&approverEmails=sam%40example.com&departments=Security%2CEngineering&nextReviewAtFrom=1735689600000&nextReviewAtTo=1767225600000&fields=mappedFrameworkIds%2CmappedControlIds%2CnotRelevantReason" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": [
    {
      "evidenceId": "92af7e7f-b18e-495b-bf92-61c23ebd34a7",
      "evidenceName": "Identity Verification Procedure and Records",
      "status": "not_uploaded",
      "department": "Security",
      "assignees": [
        {
          "name": "Alex Rivera",
          "email": "alex@example.com",
          "isPrimary": true
        }
      ],
      "approvers": [
        {
          "name": "Alex Rivera",
          "email": "alex@example.com"
        }
      ],
      "isRelevant": true,
      "nextReviewDate": 1704067200000,
      "entities": [
        {
          "entityId": "8fa88e7b-eb16-4999-854a-2f407958740a",
          "entityName": "Organization Wide"
        }
      ],
      "gapStatus": "no_gaps",
      "gapCount": 2,
      "mappedFrameworkIds": [
        "14c4c45d-6c31-4097-a02a-ad9cfd04850e"
      ],
      "mappedControlIds": [
        "2aa1b21e-4705-47cd-b1a7-e74ed4808bc9"
      ],
      "notRelevantReason": "Covered by the parent information security policy.",
      "recurrence": "annually",
      "effortEstimate": "low",
      "source": "Scrut",
      "evidenceCollectionMethod": "manual",
      "ticketsCount": 1,
      "addedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "addedOn": 1704067200000,
      "lastModifiedBy": {
        "name": "Alex Rivera",
        "email": "alex@example.com"
      },
      "modifiedOn": 1704067200000
    }
  ],
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
GET
/v1/evidence
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
query
statusstring

Filter by public evidence status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, uploaded, needs_attention, draft, needs_review, pending_approval, needs_revision.

query
frameworkIdsstring

Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).

query
controlIdsstring

Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).

query
entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

query
isRelevantboolean

Filter by relevance. Accepts true/false or 1/0.

query
assigneeEmailsstring

Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).

query
approverEmailsstring

Filter by approver email addresses. Pass a comma-separated list (no spaces required).

query
departmentsstring

Filter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).

query
nextReviewAtFrominteger

Inclusive lower bound for next review date, as Unix epoch milliseconds.

Format: int64 • Min: 0
query
nextReviewAtTointeger

Inclusive upper bound for next review date, as Unix epoch milliseconds.

Format: int64 • Min: 0
query
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, mappedControlIds, notRelevantReason, recurrence, effortEstimate, source, evidenceCollectionMethod, ticketsCount, addedBy, addedOn, lastModifiedBy, modifiedOn.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Query Parameters

statusstring

Filter by public evidence status. Pass a comma-separated list (no spaces required). Allowed values: not_uploaded, uploaded, needs_attention, draft, needs_review, pending_approval, needs_revision.

Example:
uploaded,needs_review
frameworkIdsstring

Filter to resources mapped to these framework IDs. Pass a comma-separated list (no spaces required).

Example:
14c4c45d-6c31-4097-a02a-ad9cfd04850e,3a10a604-b942-43e5-8294-d418a0448ee5
controlIdsstring

Filter to resources mapped to these control IDs. Pass a comma-separated list (no spaces required).

Example:
2aa1b21e-4705-47cd-b1a7-e74ed4808bc9,8d7c6b5a-4e3f-4210-9a8b-7c6d5e4f3a2b
entityIdsstring

Filter to resources linked to these entity (product) IDs. Pass a comma-separated list (no spaces required).

Example:
8fa88e7b-eb16-4999-854a-2f407958740a
isRelevantboolean

Filter by relevance. Accepts true/false or 1/0.

Example:
true
assigneeEmailsstring

Filter by assignee email addresses. Matches any assignees[].email. URL-encode + in plus-addressed emails as %2B. Pass a comma-separated list (no spaces required).

Example:
alex@example.com,alex@example.com
approverEmailsstring

Filter by approver email addresses. Pass a comma-separated list (no spaces required).

Example:
sam@example.com
departmentsstring

Filter by department names. Use No Department for unassigned items. Pass a comma-separated list (no spaces required).

Example:
Security,Engineering
nextReviewAtFrominteger

Inclusive lower bound for next review date, as Unix epoch milliseconds.

Example:
1735689600000
nextReviewAtTointeger

Inclusive upper bound for next review date, as Unix epoch milliseconds.

Example:
1767225600000
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: mappedFrameworkIds, mappedControlIds, notRelevantReason, recurrence, effortEstimate, source, evidenceCollectionMethod, ticketsCount, addedBy, addedOn, lastModifiedBy, modifiedOn.

Example:
mappedFrameworkIds,mappedControlIds,notRelevantReason

Responses

dataarray
Required
metaobject
Required