Prepare a scoped token
Create a token with both permissions:
For a user key, its owner must retain those permissions. Store the token in the
ALIGNR_API_KEY environment variable through your secret manager or shell environment; keep the token out of source files and report output.
Fetch all pages and preserve the grid
Save the following asassessment_summary.py and run it with Python 3. It uses the standard library and prints a complete result only after all requests succeed.
assessment, including per-control evaluation time, effective parameters, required predicates and coverage detail. retrievedAt is when the script assembled the export, not when the environment was observed or evaluated.
The requests are sequential, not a transaction across the whole workspace. Client records and assessments can change during collection; for a dated review deliverable, use the app’s saved report workflow.
Read the outcome honestly
For a fictional client with two passing rows, one failing row and one
no_data row, the counts should retain all three categories. Do not turn “three assessed rows” into “four passing rows”, or call an empty items list a clean bill of health.
Check each row’s evaluatedAt and source/coverage details. A successful HTTP response says the request succeeded; it does not establish freshness or complete client coverage. Keep status interpretation alongside any dashboard built from the export.
Handle a failed request
- 401: check whether the token expired, was revoked or belongs to a deactivated owner.
- 403: check both assigned scopes and the user’s current permissions. A missing permission is not an empty result set.
- 404: verify the client ID and workspace; it may have changed or no longer be accessible.
- 429 or a transient network/server error: use bounded backoff and any retry guidance in the response. This example stops so a failed client cannot silently disappear from a partial “complete” report.
Explain one result with MCP
An assistant can useget_organization_compliance with compliance:read, then explain_control_status with compliance:explain. A user key also needs the backing detection.read permission. These colon-delimited MCP scopes are separate from the REST scopes above.
For example: “For this Organization ID, explain the administrator MFA control. Show the evidence gaps and evaluation time; do not change anything.” Give the assistant the exact client ID and prefer the control UUID where names could be ambiguous. Read its cited context before drawing a conclusion.
Checkpoint: the summary includes every retrieved client, keeps gaps and exclusions distinct, retains the grid’s timestamps, and does not claim the script performed a fresh assessment.