Skip to main content
Use this reference when choosing evidence for a control or reading a technical result. Start with Understanding predicates if these names are unfamiliar.

How to use this reference

This catalogue covers 88 registered predicates in the application vocabulary. Availability depends on your connected sources and deployment. Check client-specific coverage and actual observations before using a predicate in a control. Use the docs search to find a technical identifier, or the page contents to jump to a topic category. Expand an entry to see its readable label, the exact technical identifier, its meaning and an interpretation limit. Multiple values means several values can legitimately coexist for a subject; it does not change a control operator into an automatic check of every member. Boolean values distinguish true, false and missing evidence. Counts, state strings, dates and relationships must be interpreted in their source context. These descriptions are not a replacement for inspecting the observed value.

Identity and access

has_roleA role held by the subject, such as Global Administrator.Interpretation: One person can hold several roles. Match the exact observed role name.Multiple values: several values can legitimately coexist for one subject.
account_enabledWhether the directory reports the account enabled.Interpretation: Enabled does not prove the person can successfully sign in or that access is appropriate.
last_sign_inWhen the identity source reports the last interactive sign-in.Interpretation: A fresh collection can report an old sign-in. Do not substitute a different vendor authentication event.
last_non_interactive_sign_inWhen the source reports the last non-interactive sign-in.Interpretation: Background activity is different from a person actively signing in.
user_typeThe type of directory user reported by the source.Interpretation: Use actual source values when distinguishing members and guests.
directory_syncedWhether the account is reported as synchronised from another directory.Interpretation: This describes its directory origin, not the health of the whole synchronisation service.
mfa_registeredWhether the user has registered multi-factor authentication.Interpretation: Registration does not establish enforcement on every sign-in.
sspr_registeredWhether self-service password reset registration is reported.Interpretation: Registration does not prove every recovery path is configured safely.
member_ofA group the subject belongs to.Interpretation: Membership can have several values. Review which group is actually relevant.Multiple values: several values can legitimately coexist for one subject.
mfa_methodA second-factor method associated with the subject.Interpretation: Several methods can coexist; a strong method does not erase a weaker one.Multiple values: several values can legitimately coexist for one subject.
mfa_bypass_enabledWhether the MFA source reports bypass enabled for the user.Interpretation: A bypass setting is a separate observation from having registered a factor.

Licensing

has_licenceA licence associated with the subject.Interpretation: The subject may be a user or a company. Assignment and purchased entitlement are different contexts.Multiple values: several values can legitimately coexist for one subject.
licence_seats_purchasedThe reported number of purchased or entitled seats for a product.Interpretation: Compare like-for-like products and subjects; it is not a count of active users.
licence_seats_assignedThe reported number of seats assigned for a product.Interpretation: Assigned seats do not prove active usage or contractual entitlement.
licence_renewal_dateThe reported next renewal date for a product commitment.Interpretation: A date, not an assurance that cancellation or quantity changes remain possible.

Conditional Access

ca_policy_scopeThe normalised scope reported for a Conditional Access policy.Interpretation: Inspect the policy context; a scope label is not proof that every relevant sign-in is protected.
ca_policy_stateWhether and how a Conditional Access policy is enabled, as reported by the source.Interpretation: Report-only and enforced behaviour differ. Compare actual state values.
ca_policy_grant_controlsThe grant controls configured on a Conditional Access policy.Interpretation: A policy can contain several controls. Their presence alone does not prove effective coverage.Multiple values: several values can legitimately coexist for one subject.
ca_policy_modified_atWhen the source reports the policy was modified.Interpretation: A timestamp establishes timing, not authorisation or the safety of the change.
ca_policy_last_modified_byThe reported actor associated with the policy modification.Interpretation: An actor identity is not itself approval evidence.
policy_scope_narrowedAn observation that the policy scope narrowed.Interpretation: Review the affected scope and approved change context before deciding whether the change is wrong.

Mailboxes and directory domains

mailbox_typeThe type of mailbox reported by the source.Interpretation: Use it to distinguish mailbox kinds, not to infer security configuration.
mailbox_timezoneThe time zone configured for the mailbox.Interpretation: This is a mailbox setting; Alignr evidence timestamps remain UTC.
mailbox_auto_replyThe automatic-reply setting reported for the mailbox.Interpretation: Interpret the source value; it does not prove a message was delivered.
verified_domainA domain verified in the source tenant.Interpretation: Domain ownership verification does not establish mail protection or DNS policy correctness.Multiple values: several values can legitimately coexist for one subject.
default_domainThe default domain reported by the directory.Interpretation: A default designation is different from the complete set of verified domains.
domain_auth_typeThe authentication type reported for the directory domain.Interpretation: Review its actual source value and policy context before drawing an access conclusion.

Endpoint management and patching

device_managed_byThe reported management relationship for an endpoint.Interpretation: RMM management is different from MDM enrolment and EDR protection.
device_last_checkinWhen the device last reported to the management source.Interpretation: Compare the event time with your reporting expectation, and check when it was collected.
device_onlineWhether the source reports the device online.Interpretation: Online does not imply patched, encrypted or free of threats.
os_platformThe reported operating-system platform.Interpretation: Match actual normalised values; a platform name alone does not prove a supported version.
patch_statusThe patching state reported by the management source.Interpretation: State vocabularies and source coverage matter; do not assume every vendor means the same thing.
patches_pendingThe source-reported number of pending patches.Interpretation: A zero count is meaningful within the reporting source’s scope, not proof of a complete vulnerability scan.
antivirus_productThe antivirus product reported on the endpoint.Interpretation: Product presence does not establish protection health or recent updates.
agent_healthThe reported health of the endpoint management agent.Interpretation: This is distinct from the health of an EDR agent.

Endpoint detection and threats

edr_agent_installedWhether the source reports endpoint detection and response agent installation.Interpretation: Check health and check-in evidence separately.
edr_agent_healthThe EDR source’s reported agent-health state.Interpretation: Read the actual state and source; installed, healthy and recently seen are separate questions.
edr_last_checkinWhen the EDR agent last reported activity.Interpretation: Use the event timestamp as well as evidence freshness.
edr_agent_versionThe reported EDR agent version.Interpretation: A version string needs a supported-version expectation before it can establish alignment.
edr_policy_groupThe policy group reported for the EDR agent.Interpretation: Group membership does not prove the effective policy settings are correct.
threat_detectedAn individual threat observation, such as its classification.Interpretation: Multiple threats can exist. Review the source record before interpreting severity or current status.Multiple values: several values can legitimately coexist for one subject.
threat_open_countThe source’s per-device count of open threats.Interpretation: A vendor rollup can differ from counting individual fact rows; do not silently equate them.

Vulnerabilities

vulnerability_detectedAn individual vulnerability observation associated with the subject.Interpretation: There may be several findings; check the identifier and source context.Multiple values: several values can legitimately coexist for one subject.
vulnerability_max_severityThe highest reported severity band for the subject.Interpretation: A severity band is not a count, and does not describe every finding.
vulnerability_open_countThe source-reported count of open vulnerabilities.Interpretation: Scanner scope and counting methods differ; avoid adding unlike rollups together.
missing_patchAn individual patch reported missing from the subject.Interpretation: Several patches can be missing. This differs from the total pending-patch count.Multiple values: several values can legitimately coexist for one subject.

Networks and firewalls

network_device_roleA role the device performs, such as switching or wireless access.Interpretation: One appliance can have several roles.Multiple values: several values can legitimately coexist for one subject.
network_device_modelThe reported network-device model.Interpretation: Model identity does not establish firmware support or configuration safety.
network_device_firmwareThe reported network-device firmware version.Interpretation: Compare with the relevant expectation for that device and source.
network_device_ipThe reported network-device IP address.Interpretation: An address is not evidence that the device is publicly reachable.
network_device_uplinkThe reported upstream connection for a network device.Interpretation: Use it as topology evidence, not a complete network diagram.
firmware_update_availableWhether the source reports an available firmware update.Interpretation: Availability is distinct from approval, urgency and safe scheduling.
vpn_tunnelA reported VPN tunnel or topology relationship.Interpretation: Several tunnels can exist. Membership alone does not prove current tunnel health.Multiple values: several values can legitimately coexist for one subject.
network_segment_typeThe reported type of a network segment, such as a VLAN or routed network.Interpretation: The presence of a VLAN does not prove isolation between networks.
firewall_policy_countThe reported number of firewall policies.Interpretation: A count cannot prove which traffic is allowed or whether the rulebase is safe.
firewall_l3_rules_fingerprintA versioned fingerprint of supported Layer 3 rule configuration.Interpretation: A changed fingerprint shows configuration identity changed; it does not establish approval or safety.

Remote access

remote_access_resourceA remote-access resource associated with a group.Interpretation: A group can reach several resources. Combine with relevant membership evidence when reviewing access.Multiple values: several values can legitimately coexist for one subject.
remote_access_addressThe address reported for a remote-access resource.Interpretation: A destination is distinct from the users and groups entitled to reach it.

MDM and policy baselines

mdm_enrolled_byThe management product in which the device is enrolled.Interpretation: Co-management can produce several valid enrolments; enrolment alone is not compliance.Multiple values: several values can legitimately coexist for one subject.
device_compliance_stateThe device-compliance result reported by the MDM source.Interpretation: This reflects that source’s policy evaluation, not every Alignr control.
device_encryption_enabledWhether the management source reports encryption enabled.Interpretation: This does not prove recovery-key availability or successful recovery.
policy_baseline_stateThe reported state of a managed policy baseline.Interpretation: Normalised states include enforced, not_applied, drifted and error. Unknown source states must not be guessed.

Mail protection and external DNS

mail_protected_byA mail security gateway reported for the domain.Interpretation: Several providers can coexist during migration; provider presence is not proof of every protection.Multiple values: several values can legitimately coexist for one subject.
mail_protection_featureA reported protection feature for the mail domain.Interpretation: Several features can coexist. Check the feature and source rather than assuming full mail security.Multiple values: several values can legitimately coexist for one subject.
external_spf_presentWhether the bounded DNS check observed an SPF record for the approved target.Interpretation: Presence is not a full SPF correctness or deliverability assessment.
external_dmarc_enforcedWhether the DNS check reports an enforcing DMARC policy for the approved target.Interpretation: A policy observation does not establish message alignment or delivery outcomes.
external_mx_presentWhether MX records were observed for the approved domain.Interpretation: MX presence does not prove that a mailbox exists or mail will be accepted.
external_nameserver_countThe number of name servers reported by the DNS check.Interpretation: A count does not prove independent hosting or resilience.

Configuration monitoring

monitored_systemA system reported by the configuration-monitoring source.Interpretation: Being listed does not establish successful or recent inspection.
inspection_statusThe reported state of a configuration inspection.Interpretation: Read the actual source state alongside the inspection time.
inspection_last_run_atWhen the source reports its last inspection run.Interpretation: A recent run timestamp is different from a successful result.

Tickets, contracts and credential signals

leaver_ticketA ticket associated with an offboarding process.Interpretation: A ticket’s existence does not establish that all access has been removed.
leaver_ticket_statusThe reported state of an offboarding ticket.Interpretation: A closed ticket is workflow evidence, not proof that directory access is disabled.
ticket_closed_atWhen the source reports a ticket was closed.Interpretation: Use it for timing; verify the technical outcome separately.
ticket_contains_secretAn observation that ticket content contains a secret.Interpretation: The signal is not an instruction to publish or retrieve the secret itself.
secret_reuse_countA reported count associated with reuse of a credential.Interpretation: Interpret within the producer’s scope. The count does not reveal the credential value.
change_ticket_refA change-ticket reference associated with the subject.Interpretation: Several references may exist. A reference alone is not evidence of approval.Multiple values: several values can legitimately coexist for one subject.
ticket_statusThe status reported for a general ticket.Interpretation: Use the actual workflow state; similarly named statuses can have different meanings across sources.
contract_typeThe contract classification reported by the PSA source.Interpretation: A type label does not establish the full terms or technical requirements.

Backup

backup_protected_byA product reporting backup protection for the subject.Interpretation: Product presence does not prove a successful backup or a tested restore.Multiple values: several values can legitimately coexist for one subject.
backup_last_successful_atWhen the source reports the last successful backup.Interpretation: Review the relevant job/workload and required recovery-point expectation.
backup_job_stateThe source-reported result or state of a backup job.Interpretation: Review the exact normalised state and timing, not the label alone.
backup_protected_workloadA workload associated with a backup job.Interpretation: A job can protect several workloads; membership is distinct from successful recovery.Multiple values: several values can legitimately coexist for one subject.

Derived records and certificates

document_references_assetAn asset referenced by a retained evidence document.Interpretation: This describes an evidence relationship; it does not make documentation a separate product library.Multiple values: several values can legitimately coexist for one subject.
referenced_asset_last_seenWhen a referenced asset was last observed.Interpretation: Check its producer and observation time before interpreting it as current inventory.
referenced_asset_decommissionedAn observation that a referenced asset is decommissioned.Interpretation: A missing observation does not prove that the asset is still active.
certificate_expires_onThe expiry date or time reported for a certificate.Interpretation: Expiry evidence needs its producer and target context; not every integration collects certificates.
certificate_issuerThe issuer reported for a certificate.Interpretation: The issuer name alone does not prove trust, validity or correct deployment.

Choosing the right observation

Write the question you need to answer, identify its subject, then choose the predicate that directly addresses it. Confirm your source supplies that predicate and inspect an actual value before choosing an operator. For example, “is a backup product present?”, “did a backup succeed recently?” and “can we restore this system?” are three different questions. The first two have separate observations; neither replaces a restore test. Build a control condition or troubleshoot missing evidence.