{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://acdl.cloudinit.dev/schemas/policy_check_result.schema.json", "title": "ACDL PolicyCheckResult", "description": "Normalized policy check result — the contract between policy engines and the confidence signal. Engine-specific adapters (checkov_adapter.py, future kyverno_adapter) translate native engine output to this shape. The confidence signal consumes a list of these as its policy input; it is engine-agnostic. The severity enum drives the severity->penalty mapping (critical hard-override, high -0.2, medium -0.05, low -0.01, info 0.0).", "$comment": "Canonical PolicyCheckResult (ARCHITECTURE.md §12.6). The confidence signal (platform/confidence_signal.py) consumes a list of these as its policy input; it is engine-agnostic. Adapters translate native output to this shape; the signal never reads engine-specific evidence.", "type": "object", "required": ["contractId", "evaluatedAt", "engine", "ruleId", "severity", "result", "message", "resourceRef"], "properties": { "contractId": { "type": "string", "format": "uuid", "description": "The contract this check was evaluated against." }, "evaluatedAt": { "type": "string", "format": "date-time", "description": "ISO-8601 timestamp of evaluation." }, "engine": { "type": "string", "enum": ["checkov", "kyverno", "opa"], "description": "Policy engine that produced this result." }, "ruleId": { "type": "string", "description": "Rule identifier (e.g. CKV_AWS_24, KYVERNO_NO_PRIVILEGED, ACDL_TAG_NAMING)." }, "severity": { "type": "string", "enum": ["critical", "high", "medium", "low", "info"], "description": "Severity drives the confidence signal's penalty mapping (ARCHITECTURE.md §8)." }, "result": { "type": "string", "enum": ["pass", "fail", "skipped", "error"], "description": "Check outcome." }, "message": { "type": "string", "description": "Human-readable result message." }, "evidence": { "type": "object", "additionalProperties": true, "description": "Engine-specific payload (file_path, resource, code_block, etc.). Opaque to the confidence signal; present for audit/debug." }, "resourceRef": { "type": "string", "description": "IR-typed resource identifier (the resource this check evaluated)." } } }