REST Resource: projects.locations.instances.remediationPlans.remediationActions

Resource: RemediationAction

Represents a SecOps single remediation action, part of a Remediation Plan.

JSON representation
{
  "name": string,
  "integrationId": string,
  "integrationInstance": string,
  "displayName": string,
  "type": enum (ActionOriginType),
  "creator": enum (ActionInstanceCreator),
  "actionReasoning": string,
  "parameters": {
    object
  },
  "targetEntities": [
    {
      object
    }
  ],
  "actionGeneration": {
    object
  },
  "additionalData": {
    object
  },
  "metadata": {
    object
  },
  "createTime": string,
  "updateTime": string
}
Fields
name

string

Identifier. Resource name of the remediation plan action.

integrationId

string

Optional. Integration identifier (name, e.g. "GoogleCloudIAM").

integrationInstance

string

Optional. Integration instance (e.g. "prod-tenant-1").

displayName

string

Optional. Name of the action (e.g. "Disable Service Account").

type

enum (ActionOriginType)

Optional. Origin type of the action.

creator

enum (ActionInstanceCreator)

Optional. Source of who added this action to the plan.

actionReasoning

string

Optional. Reasoning explaining why this specific action was proposed.

parameters

object (Struct format)

Optional. Action parameters. Struct enables JSON dynamic storage.

targetEntities[]

object (Struct format)

Optional. Target entities for this action.

actionGeneration

object (Struct format)

Optional. Field to store json with python code and action definition for dynamic scripts.

additionalData

object (Struct format)

Optional. Additional unstructured data.

metadata

object (Struct format)

Optional. Metadata for the action.

createTime

string (Timestamp format)

Output only. Creation time.

Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30".

updateTime

string (Timestamp format)

Output only. Modification time.

Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30".

ActionOriginType

The origin type of the actions whether existing or generated code.

Enums
ACTION_ORIGIN_TYPE_UNSPECIFIED Unspecified type.
ACTION_ORIGIN_TYPE_GENERATED Action was dynamically generated (drafted) by the LLM.
ACTION_ORIGIN_TYPE_EXISTING Action pre-existed in the integrations repository (Partner/Community).

ActionInstanceCreator

The creator of the action instance whether the user or the AI agent.

Enums
ACTION_INSTANCE_CREATOR_UNSPECIFIED Unspecified user type.
ACTION_INSTANCE_CREATOR_USER Manually attached by the user (SOC analyst).
ACTION_INSTANCE_CREATOR_AI Automatically attached by the Remediation Agent (AI).

Methods

create

Creates a manual Remediation Action under a plan.

get

Retrieves an individual Remediation Action.

list

Lists Remediation Actions under a plan.