Updated on 2026-07-22 GMT+08:00

Obtaining Findings Generated for an Access Preview

Function

This API is used to obtain the findings generated for an access preview.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

AccessAnalyzer:analyzer:listPreviewFindings

List

analyzer *

g:ResourceTag/<tag-key>

-

-

URI

POST /v5/analyzers/{analyzer_id}/access-previews/{access_preview_id}/findings

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

analyzer_id

Yes

String

Definition:

Unique identifier of an analyzer.

You can call the ListAnalyzers API to obtain the analyzer ID. The response parameters of this API return an analyzer list. The id field of each analyzer object is the analyzer ID.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

access_preview_id

Yes

String

Definition:

Unique identifier of an access preview.

You can call the ListAccessPreviews API to retrieve all access previews created for a specified analyzer. The response of this API contains an access preview list. Each access preview summary object in the list contains a unique access_preview_id field, which is the preview access analysis ID.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

filters

No

Array of FindingFilter objects

Definition:

A filter to match the returned findings.

Constraints:

N/A

Range:

Array length: 1 to 20.

Default Value:

N/A

limit

No

Integer

Definition:

Maximum number of results on a page.

Constraints:

N/A

Range:

The value ranges from 1 to 200.

Default Value:

100

marker

No

String

Definition:

Page marker.

Constraints:

N/A

Range:

The value contains 4 to 400 characters. Only letters, digits, and special characters (+/=-_) are allowed.

Default Value:

N/A

Table 3 FindingFilter

Parameter

Mandatory

Type

Description

criterion

Yes

Criterion object

Definition:

Criteria in the filter.

Constraints:

Only one operator is allowed.

Range:

N/A

Default Value:

N/A

key

Yes

String

Definition:

Filter key.

Constraints:

N/A

Range:

  • resource: resource URN.

  • resource_type: resource type.

  • resource_owner_account: resource owner account.

  • is_public: public access permission.

  • id: finding ID

  • status: finding type

  • principal_type: principal type.

  • principal_identifier: principal identifier

  • change_type: finding status change

  • existing_finding_id: ID of an existing finding

  • existing_finding_status: status of an existing finding

  • condition.g:PrincipalUrn: principal URN

  • condition.g:PrincipalId: principal ID

  • condition.g:PrincipalAccount: principal account

  • condition.g:PrincipalOrgId: principal organization ID

  • condition.g:PrincipalOrgPath: principal organization path

  • condition.g:PrincipalOrgManagementAccountId: principal organization management account ID

  • condition.g:SourceIp: source IP address

  • condition.g:SourceVpc: source VPC

  • condition.g: SourceVpce: source VPC endpoint

  • finding_type: finding type

Default Value:

N/A

Table 4 Criterion

Parameter

Mandatory

Type

Description

contains

No

Array of strings

Definition:

Matching the "contains" operator in the filter.

Constraints:

N/A

Range:

Array length: 1 to 20.

Default Value:

N/A

eq

No

Array of strings

Definition:

Matching the "eq" operator in the filter.

Constraints:

N/A

Range:

Array length: 1 to 20.

Default Value:

N/A

exists

No

Boolean

Definition:

Matching the "exists" operator in the filter

Constraints:

N/A

Range:

N/A

Default Value:

N/A

neq

No

Array of strings

Definition:

Matching the "neq" operator in the filter.

Constraints:

N/A

Range:

Array length: 1 to 20.

Default Value:

N/A

Response Parameters

Status code: 200

Table 5 Response body parameters

Parameter

Type

Description

findings

Array of PreviewFinding objects

Definition:

List of findings generated by an access preview.

Range:

N/A

page_info

PageInfo object

Definition:

Page information.

Range:

N/A

Table 6 PreviewFinding

Parameter

Type

Description

action

Array of strings

Definition:

Action that can be used by external principals.

Range:

N/A

change_type

String

Definition:

Finding change.

Range:

  • unchanged: no change

  • new: new content

  • changed: content updated

condition

Array of FindingCondition objects

Definition:

Condition that generates findings in the policy statement.

Range:

N/A

created_at

String

Definition:

Time when the findings were generated for an access preview. The UTC+0 time zone is used. The format is yyyy-MM-ddTHH:mm:ss.SSSZ, for example, 2023-09-07T07:51:10.502Z.

Range:

N/A

existing_finding_id

String

Definition:

Unique identifier of a finding.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

existing_finding_status

String

Definition:

Finding status.

Range:

  • active

  • archived

  • resolved

id

String

Definition:

Unique identifier of a finding.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

is_public

Boolean

Definition:

Whether the policy that generates findings allows public access to resources.

Range:

N/A

principal

FindingPrincipal object

Definition:

External principal that accesses resources in the trusted zone.

Range:

N/A

resource

String

Definition:

Unique identifier of a resource.

Range:

N/A

resource_owner_account

String

Definition:

ID of the account that owns resources.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

resource_type

String

Definition:

Type of a resource.

Range:

  • iam:agency: IAM agency

  • iam:user: IAM user

  • kms:cmk: DEW key

  • obs:bucket: OBS bucket

  • swr:repo: SWR image repository

  • cbr:backup: CBR backup

  • ims:image: IMS image

sources

Array of strings

Definition:

Source of findings.

Range:

  • bucket_acl: bucket ACL

  • bucket_policy: bucket policy

status

String

Definition:

Status after the change.

Range:

  • active

  • archived

  • resolved

Table 7 FindingCondition

Parameter

Type

Description

key

String

Definition:

Identifier or name of the condition key.

Range:

N/A

value

String

Definition:

Value of the condition key.

Range:

N/A

Table 8 FindingPrincipal

Parameter

Type

Description

identifier

String

Definition:

Identifier of an external principal.

Range:

N/A

type

String

Definition:

Type of an external principal.

Range:

  • all_principal: all external principals

  • account: account

  • all_user_in_account: all users under an account

  • all_agency_in_account: all agencies under an account

  • all_identity_provider_in_account: all identity providers under an account

  • specific_user: specific user

  • specific_agency: specific agency

  • specific_group: specific user group

  • specific_identity_provider: specific identity provider

Table 9 PageInfo

Parameter

Type

Description

current_count

Integer

Definition:

Number of items on the current page.

Range:

N/A

next_marker

String

Definition:

If present, it indicates that the available output is more than the output contained in the current response. Use this value in the marker request parameter in a subsequent call to the operation to get the next part of the output. You should repeat this operation until the next_marker response returns null.

Range:

Only letters, digits, plus signs (+), slashes (/), equal signs (=), underscores (_), and hyphens (-) are allowed.

Example Requests

Obtaining findings generated for an access preview

POST https://{hostname}/v5/analyzers/{analyzer_id}/access-previews/{access_preview_id}/findings

{
  "filters" : [ {
    "criterion" : {
      "eq" : [ "iam:agency" ]
    },
    "key" : "resource_type"
  } ]
}

Example Responses

Status code: 200

OK

{
  "findings" : [ {
    "action" : [ "sts::setSourceIdentity", "sts::tagSession", "sts:agencies:assume" ],
    "change_type" : "new",
    "condition" : [ {
      "key" : "g:PrincipalOrgId",
      "value" : "org_id"
    } ],
    "created_at" : "2023-09-07T07:26:23.440Z",
    "existing_finding_status" : null,
    "existing_finding_id" : null,
    "is_public" : false,
    "id" : "{finding_id}",
    "principal" : {
      "identifier" : "{domain_id}",
      "type" : "account"
    },
    "resource" : "iam::{domain_id}:agency:{agency_name}",
    "resource_owner_account" : "{domain_id}",
    "resource_type" : "iam:agency",
    "status" : "active"
  } ],
  "page_info" : {
    "current_count" : 1,
    "next_marker" : null
  }
}

Status Codes

Status Code

Description

200

OK

Error Codes

See Error Codes.