Resource: RemediationAction
Represents a SecOps single remediation action, part of a Remediation Plan.
| JSON representation |
|---|
{ "name": string, "integrationId": string, "integrationInstance": string, "displayName": string, "type": enum ( |
| Fields | |
|---|---|
name |
Identifier. Resource name of the remediation plan action. |
integrationId |
Optional. Integration identifier (name, e.g. "GoogleCloudIAM"). |
integrationInstance |
Optional. Integration instance (e.g. "prod-tenant-1"). |
displayName |
Optional. Name of the action (e.g. "Disable Service Account"). |
type |
Optional. Origin type of the action. |
creator |
Optional. Source of who added this action to the plan. |
actionReasoning |
Optional. Reasoning explaining why this specific action was proposed. |
parameters |
Optional. Action parameters. Struct enables JSON dynamic storage. |
targetEntities[] |
Optional. Target entities for this action. |
actionGeneration |
Optional. Field to store json with python code and action definition for dynamic scripts. |
additionalData |
Optional. Additional unstructured data. |
metadata |
Optional. Metadata for the action. |
createTime |
Output only. Creation time. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
updateTime |
Output only. Modification time. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
ActionOriginType
The origin type of the actions whether existing or generated code.
| Enums | |
|---|---|
ACTION_ORIGIN_TYPE_UNSPECIFIED |
Unspecified type. |
ACTION_ORIGIN_TYPE_GENERATED |
Action was dynamically generated (drafted) by the LLM. |
ACTION_ORIGIN_TYPE_EXISTING |
Action pre-existed in the integrations repository (Partner/Community). |
ActionInstanceCreator
The creator of the action instance whether the user or the AI agent.
| Enums | |
|---|---|
ACTION_INSTANCE_CREATOR_UNSPECIFIED |
Unspecified user type. |
ACTION_INSTANCE_CREATOR_USER |
Manually attached by the user (SOC analyst). |
ACTION_INSTANCE_CREATOR_AI |
Automatically attached by the Remediation Agent (AI). |
Methods |
|
|---|---|
|
Creates a manual Remediation Action under a plan. |
|
Retrieves an individual Remediation Action. |
|
Lists Remediation Actions under a plan. |