Get Risk View
get_risk_viewRetrieve a prioritized risk view ranking live control objectives by risk tier, control coverage, and open findings for a threat model or tag scope, so teams can triage what needs attention.
Instructions
Prioritized Risk View — one row per live Control Objective — at a chosen scope. Read-only; no side effects.
scope selects the aggregation boundary and how scope_id is interpreted:
"model"— a single threat model (scope_id= model id). One row per live CO with derived risk tier, asset impact, attacker likelihood, control coverage counts (coverage_ratio), and open-finding count (open_findings). Tombstoned COs are excluded; pair withget_threat_modelif historical context is needed. Use to triage which COs need attention on one model — a single call ranks the work, no per-CO fan-out."tag"— every member model of a tag (scope_id= tag id). The same row shape withmodel_idandmodel_titleadded per row, so rows can be grouped by source model without an extra lookup, and delegation-aware (delegation_mitigated/delegating_controls): a CO mitigated via a verified cross-model delegation reads as covered, consistent with each model's own assessment. Use for a product, portfolio or audit-scope posture rollup.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| scope | Yes | aggregation boundary — "model" or "tag". | |
| scope_id | Yes | id of the model or tag selected by ``scope``. | |
| server_version | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||