How to use this reference
This catalogue covers 88 registered predicates in the application vocabulary. Availability depends on your connected sources and deployment. Check client-specific coverage and actual observations before using a predicate in a control. Use the docs search to find a technical identifier, or the page contents to jump to a topic category. Expand an entry to see its readable label, the exact technical identifier, its meaning and an interpretation limit. Multiple values means several values can legitimately coexist for a subject; it does not change a control operator into an automatic check of every member. Boolean values distinguish true, false and missing evidence. Counts, state strings, dates and relationships must be interpreted in their source context. These descriptions are not a replacement for inspecting the observed value.Identity and access
Directory role
Directory role
has_roleA role held by the subject, such as Global Administrator.Interpretation: One person can hold several roles. Match the exact observed role name.Multiple values: several values can legitimately coexist for one subject.Account enabled
Account enabled
account_enabledWhether the directory reports the account enabled.Interpretation: Enabled does not prove the person can successfully sign in or that access is appropriate.Last interactive sign-in
Last interactive sign-in
last_sign_inWhen the identity source reports the last interactive sign-in.Interpretation: A fresh collection can report an old sign-in. Do not substitute a different vendor authentication event.Last non-interactive sign-in
Last non-interactive sign-in
last_non_interactive_sign_inWhen the source reports the last non-interactive sign-in.Interpretation: Background activity is different from a person actively signing in.User type
User type
user_typeThe type of directory user reported by the source.Interpretation: Use actual source values when distinguishing members and guests.Directory synchronised
Directory synchronised
directory_syncedWhether the account is reported as synchronised from another directory.Interpretation: This describes its directory origin, not the health of the whole synchronisation service.MFA registered
MFA registered
mfa_registeredWhether the user has registered multi-factor authentication.Interpretation: Registration does not establish enforcement on every sign-in.Password reset registered
Password reset registered
sspr_registeredWhether self-service password reset registration is reported.Interpretation: Registration does not prove every recovery path is configured safely.Group membership
Group membership
member_ofA group the subject belongs to.Interpretation: Membership can have several values. Review which group is actually relevant.Multiple values: several values can legitimately coexist for one subject.Registered MFA method
Registered MFA method
mfa_methodA second-factor method associated with the subject.Interpretation: Several methods can coexist; a strong method does not erase a weaker one.Multiple values: several values can legitimately coexist for one subject.MFA bypass enabled
MFA bypass enabled
mfa_bypass_enabledWhether the MFA source reports bypass enabled for the user.Interpretation: A bypass setting is a separate observation from having registered a factor.Licensing
Licence or entitlement
Licence or entitlement
has_licenceA licence associated with the subject.Interpretation: The subject may be a user or a company. Assignment and purchased entitlement are different contexts.Multiple values: several values can legitimately coexist for one subject.Purchased seats
Purchased seats
licence_seats_purchasedThe reported number of purchased or entitled seats for a product.Interpretation: Compare like-for-like products and subjects; it is not a count of active users.Assigned seats
Assigned seats
licence_seats_assignedThe reported number of seats assigned for a product.Interpretation: Assigned seats do not prove active usage or contractual entitlement.Next licence renewal
Next licence renewal
licence_renewal_dateThe reported next renewal date for a product commitment.Interpretation: A date, not an assurance that cancellation or quantity changes remain possible.Conditional Access
Policy scope
Policy scope
ca_policy_scopeThe normalised scope reported for a Conditional Access policy.Interpretation: Inspect the policy context; a scope label is not proof that every relevant sign-in is protected.Policy state
Policy state
ca_policy_stateWhether and how a Conditional Access policy is enabled, as reported by the source.Interpretation: Report-only and enforced behaviour differ. Compare actual state values.Policy grant requirements
Policy grant requirements
ca_policy_grant_controlsThe grant controls configured on a Conditional Access policy.Interpretation: A policy can contain several controls. Their presence alone does not prove effective coverage.Multiple values: several values can legitimately coexist for one subject.Policy last changed
Policy last changed
ca_policy_modified_atWhen the source reports the policy was modified.Interpretation: A timestamp establishes timing, not authorisation or the safety of the change.Policy changed by
Policy changed by
ca_policy_last_modified_byThe reported actor associated with the policy modification.Interpretation: An actor identity is not itself approval evidence.Policy scope reduced
Policy scope reduced
policy_scope_narrowedAn observation that the policy scope narrowed.Interpretation: Review the affected scope and approved change context before deciding whether the change is wrong.Mailboxes and directory domains
Mailbox type
Mailbox type
mailbox_typeThe type of mailbox reported by the source.Interpretation: Use it to distinguish mailbox kinds, not to infer security configuration.Mailbox time zone
Mailbox time zone
mailbox_timezoneThe time zone configured for the mailbox.Interpretation: This is a mailbox setting; Alignr evidence timestamps remain UTC.Automatic reply setting
Automatic reply setting
mailbox_auto_replyThe automatic-reply setting reported for the mailbox.Interpretation: Interpret the source value; it does not prove a message was delivered.Verified directory domain
Verified directory domain
verified_domainA domain verified in the source tenant.Interpretation: Domain ownership verification does not establish mail protection or DNS policy correctness.Multiple values: several values can legitimately coexist for one subject.Default directory domain
Default directory domain
default_domainThe default domain reported by the directory.Interpretation: A default designation is different from the complete set of verified domains.Domain authentication type
Domain authentication type
domain_auth_typeThe authentication type reported for the directory domain.Interpretation: Review its actual source value and policy context before drawing an access conclusion.Endpoint management and patching
Device management
Device management
device_managed_byThe reported management relationship for an endpoint.Interpretation: RMM management is different from MDM enrolment and EDR protection.Last management check-in
Last management check-in
device_last_checkinWhen the device last reported to the management source.Interpretation: Compare the event time with your reporting expectation, and check when it was collected.Device online
Device online
device_onlineWhether the source reports the device online.Interpretation: Online does not imply patched, encrypted or free of threats.Operating system
Operating system
os_platformThe reported operating-system platform.Interpretation: Match actual normalised values; a platform name alone does not prove a supported version.Patch state
Patch state
patch_statusThe patching state reported by the management source.Interpretation: State vocabularies and source coverage matter; do not assume every vendor means the same thing.Pending patch count
Pending patch count
patches_pendingThe source-reported number of pending patches.Interpretation: A zero count is meaningful within the reporting source’s scope, not proof of a complete vulnerability scan.Antivirus product
Antivirus product
antivirus_productThe antivirus product reported on the endpoint.Interpretation: Product presence does not establish protection health or recent updates.Management agent health
Management agent health
agent_healthThe reported health of the endpoint management agent.Interpretation: This is distinct from the health of an EDR agent.Endpoint detection and threats
EDR installed
EDR installed
edr_agent_installedWhether the source reports endpoint detection and response agent installation.Interpretation: Check health and check-in evidence separately.EDR health
EDR health
edr_agent_healthThe EDR source’s reported agent-health state.Interpretation: Read the actual state and source; installed, healthy and recently seen are separate questions.Last EDR check-in
Last EDR check-in
edr_last_checkinWhen the EDR agent last reported activity.Interpretation: Use the event timestamp as well as evidence freshness.EDR version
EDR version
edr_agent_versionThe reported EDR agent version.Interpretation: A version string needs a supported-version expectation before it can establish alignment.EDR policy group
EDR policy group
edr_policy_groupThe policy group reported for the EDR agent.Interpretation: Group membership does not prove the effective policy settings are correct.Reported threat
Reported threat
threat_detectedAn individual threat observation, such as its classification.Interpretation: Multiple threats can exist. Review the source record before interpreting severity or current status.Multiple values: several values can legitimately coexist for one subject.Open threat count
Open threat count
threat_open_countThe source’s per-device count of open threats.Interpretation: A vendor rollup can differ from counting individual fact rows; do not silently equate them.Vulnerabilities
Reported vulnerability
Reported vulnerability
vulnerability_detectedAn individual vulnerability observation associated with the subject.Interpretation: There may be several findings; check the identifier and source context.Multiple values: several values can legitimately coexist for one subject.Highest vulnerability severity
Highest vulnerability severity
vulnerability_max_severityThe highest reported severity band for the subject.Interpretation: A severity band is not a count, and does not describe every finding.Open vulnerability count
Open vulnerability count
vulnerability_open_countThe source-reported count of open vulnerabilities.Interpretation: Scanner scope and counting methods differ; avoid adding unlike rollups together.Missing patch
Missing patch
missing_patchAn individual patch reported missing from the subject.Interpretation: Several patches can be missing. This differs from the total pending-patch count.Multiple values: several values can legitimately coexist for one subject.Networks and firewalls
Network device role
Network device role
network_device_roleA role the device performs, such as switching or wireless access.Interpretation: One appliance can have several roles.Multiple values: several values can legitimately coexist for one subject.Hardware model
Hardware model
network_device_modelThe reported network-device model.Interpretation: Model identity does not establish firmware support or configuration safety.Firmware version
Firmware version
network_device_firmwareThe reported network-device firmware version.Interpretation: Compare with the relevant expectation for that device and source.Management address
Management address
network_device_ipThe reported network-device IP address.Interpretation: An address is not evidence that the device is publicly reachable.Upstream connection
Upstream connection
network_device_uplinkThe reported upstream connection for a network device.Interpretation: Use it as topology evidence, not a complete network diagram.Firmware update available
Firmware update available
firmware_update_availableWhether the source reports an available firmware update.Interpretation: Availability is distinct from approval, urgency and safe scheduling.VPN tunnel membership
VPN tunnel membership
vpn_tunnelA reported VPN tunnel or topology relationship.Interpretation: Several tunnels can exist. Membership alone does not prove current tunnel health.Multiple values: several values can legitimately coexist for one subject.Network segment type
Network segment type
network_segment_typeThe reported type of a network segment, such as a VLAN or routed network.Interpretation: The presence of a VLAN does not prove isolation between networks.Firewall rule count
Firewall rule count
firewall_policy_countThe reported number of firewall policies.Interpretation: A count cannot prove which traffic is allowed or whether the rulebase is safe.Firewall rule fingerprint
Firewall rule fingerprint
firewall_l3_rules_fingerprintA versioned fingerprint of supported Layer 3 rule configuration.Interpretation: A changed fingerprint shows configuration identity changed; it does not establish approval or safety.Remote access
Accessible resource
Accessible resource
remote_access_resourceA remote-access resource associated with a group.Interpretation: A group can reach several resources. Combine with relevant membership evidence when reviewing access.Multiple values: several values can legitimately coexist for one subject.Resource destination
Resource destination
remote_access_addressThe address reported for a remote-access resource.Interpretation: A destination is distinct from the users and groups entitled to reach it.MDM and policy baselines
MDM enrolment
MDM enrolment
mdm_enrolled_byThe management product in which the device is enrolled.Interpretation: Co-management can produce several valid enrolments; enrolment alone is not compliance.Multiple values: several values can legitimately coexist for one subject.MDM compliance state
MDM compliance state
device_compliance_stateThe device-compliance result reported by the MDM source.Interpretation: This reflects that source’s policy evaluation, not every Alignr control.Device encryption
Device encryption
device_encryption_enabledWhether the management source reports encryption enabled.Interpretation: This does not prove recovery-key availability or successful recovery.Baseline state
Baseline state
policy_baseline_stateThe reported state of a managed policy baseline.Interpretation: Normalised states include enforced, not_applied, drifted and error. Unknown source states must not be guessed.Mail protection and external DNS
Mail protection provider
Mail protection provider
mail_protected_byA mail security gateway reported for the domain.Interpretation: Several providers can coexist during migration; provider presence is not proof of every protection.Multiple values: several values can legitimately coexist for one subject.Mail protection feature
Mail protection feature
mail_protection_featureA reported protection feature for the mail domain.Interpretation: Several features can coexist. Check the feature and source rather than assuming full mail security.Multiple values: several values can legitimately coexist for one subject.SPF record present
SPF record present
external_spf_presentWhether the bounded DNS check observed an SPF record for the approved target.Interpretation: Presence is not a full SPF correctness or deliverability assessment.DMARC enforcement policy
DMARC enforcement policy
external_dmarc_enforcedWhether the DNS check reports an enforcing DMARC policy for the approved target.Interpretation: A policy observation does not establish message alignment or delivery outcomes.Mail routing records present
Mail routing records present
external_mx_presentWhether MX records were observed for the approved domain.Interpretation: MX presence does not prove that a mailbox exists or mail will be accepted.Name server count
Name server count
external_nameserver_countThe number of name servers reported by the DNS check.Interpretation: A count does not prove independent hosting or resilience.Configuration monitoring
Monitored system
Monitored system
monitored_systemA system reported by the configuration-monitoring source.Interpretation: Being listed does not establish successful or recent inspection.Inspection state
Inspection state
inspection_statusThe reported state of a configuration inspection.Interpretation: Read the actual source state alongside the inspection time.Last inspection
Last inspection
inspection_last_run_atWhen the source reports its last inspection run.Interpretation: A recent run timestamp is different from a successful result.Tickets, contracts and credential signals
Leaver ticket
Leaver ticket
leaver_ticketA ticket associated with an offboarding process.Interpretation: A ticket’s existence does not establish that all access has been removed.Leaver ticket state
Leaver ticket state
leaver_ticket_statusThe reported state of an offboarding ticket.Interpretation: A closed ticket is workflow evidence, not proof that directory access is disabled.Ticket closure time
Ticket closure time
ticket_closed_atWhen the source reports a ticket was closed.Interpretation: Use it for timing; verify the technical outcome separately.Secret-in-ticket signal
Secret-in-ticket signal
ticket_contains_secretAn observation that ticket content contains a secret.Interpretation: The signal is not an instruction to publish or retrieve the secret itself.Secret reuse count
Secret reuse count
secret_reuse_countA reported count associated with reuse of a credential.Interpretation: Interpret within the producer’s scope. The count does not reveal the credential value.Change ticket reference
Change ticket reference
change_ticket_refA change-ticket reference associated with the subject.Interpretation: Several references may exist. A reference alone is not evidence of approval.Multiple values: several values can legitimately coexist for one subject.Ticket state
Ticket state
ticket_statusThe status reported for a general ticket.Interpretation: Use the actual workflow state; similarly named statuses can have different meanings across sources.Contract type
Contract type
contract_typeThe contract classification reported by the PSA source.Interpretation: A type label does not establish the full terms or technical requirements.Backup
Backup protection provider
Backup protection provider
backup_protected_byA product reporting backup protection for the subject.Interpretation: Product presence does not prove a successful backup or a tested restore.Multiple values: several values can legitimately coexist for one subject.Last successful backup
Last successful backup
backup_last_successful_atWhen the source reports the last successful backup.Interpretation: Review the relevant job/workload and required recovery-point expectation.Backup job state
Backup job state
backup_job_stateThe source-reported result or state of a backup job.Interpretation: Review the exact normalised state and timing, not the label alone.Protected workload
Protected workload
backup_protected_workloadA workload associated with a backup job.Interpretation: A job can protect several workloads; membership is distinct from successful recovery.Multiple values: several values can legitimately coexist for one subject.Derived records and certificates
Document asset reference
Document asset reference
document_references_assetAn asset referenced by a retained evidence document.Interpretation: This describes an evidence relationship; it does not make documentation a separate product library.Multiple values: several values can legitimately coexist for one subject.Referenced asset last seen
Referenced asset last seen
referenced_asset_last_seenWhen a referenced asset was last observed.Interpretation: Check its producer and observation time before interpreting it as current inventory.Referenced asset retired
Referenced asset retired
referenced_asset_decommissionedAn observation that a referenced asset is decommissioned.Interpretation: A missing observation does not prove that the asset is still active.Certificate expiry
Certificate expiry
certificate_expires_onThe expiry date or time reported for a certificate.Interpretation: Expiry evidence needs its producer and target context; not every integration collects certificates.Certificate issuer
Certificate issuer
certificate_issuerThe issuer reported for a certificate.Interpretation: The issuer name alone does not prove trust, validity or correct deployment.