Skip to main content
The compliance report turns the denials your governance packs and custom policy bundles produce into audit-ready evidence. Every time a policy gate blocks an action, the Rego rule that fired records the framework control IDs it satisfies onto the audit event. The report aggregates those denials over a window — grouped by control, by framework, and by gate — alongside which packs the account has enabled and the full catalog of available controls.

Pull a report

GET /admin/accounts/<account_id>/compliance with an ISO-8601 start and end:

Reading the report

What a denial count means

A denial count is a real enforcement event — a moment when a policy gate blocked an action your agent attempted inside the sandbox, not an advisory finding. Each blocked action is attributed to the framework control IDs carried in the firing Rego rule’s metadata, so a single denial can count toward several controls at once (e.g. one blocked command satisfying both OWASP-LLM06 and NIST-SI-4).
A denial is positive evidence that a control fired. The absence of denials is not evidence that nothing occurred: the net.egress and content.scan gates observe every process in the sandbox, but cmd.exec sees commands issued through the Declaw API, not those a running process spawns for itself. See Where each gate runs. Report denial counts as controls demonstrably enforced, not as a complete census of sandbox activity.
Use denials_by_framework as your top-line evidence per framework, and denials_by_control to show exactly which controls have live enforcement signal over the period.

The four enforcement gates

denials_by_gate reports each denial’s audit category and event:
Only these four denial events are counted toward compliance evidence. Completed (allowed) actions and non-policy audit events are excluded — the report is strictly the record of what policy blocked in the window.

Interpreting it as evidence

The report is designed to be attached directly to a compliance package per framework:
  • Coverage comes from catalog (enforced_controls per pack) plus enabled_packs (what’s actually switched on for the account).
  • Effectiveness comes from denials_by_control / denials_by_framework (controls that fired, and how often) over your stated window.
Pair the two: the catalog shows the controls you can enforce, and the denial counts show the controls that did fire — giving an auditor both the configured surface and the operational evidence for the period. The same data renders in the console under Admin → Compliance, with the framework and control breakdowns shown as charts over a selectable window.
  • Governance Packs — the curated, framework-aligned bundles whose control metadata produces this evidence.