> For the complete documentation index, see [llms.txt](https://docs.ox.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ox.security/api-documentation/api-reference/api--response-center/types/objects/incident-evidence-item.md).

# incidentEvidenceItem

### Examples

```graphql
type IncidentEvidenceItem {
  id: String!
  incidentId: String!
  category: EvidenceCategory!
  state: EvidenceState!
  severity: IncidentSeverity
  title: String!
  resourceName: String!
  resourceDetail: String
  pipelineOutcome: PipelineOutcome
  targetBranch: String
  appName: String
  appType: String
  hitIndicatorValues: [String!]!
  isRunning: Boolean
  runtimeStatus: String
  cloudRunState: CloudRunState
  isUsed: Boolean
  isInternetExposed: Boolean
  dependencyType: EvidenceDependencyType
  pinState: String
  stateReason: String
  externalUrl: String
  asOf: DateTime!
  developerEmail: String
  commandRanAt: DateTime
  devEnvironmentOutcome: DevEnvironmentOutcome
  resourceOwner: String
  issueId: String
  sbomAppId: String
  sbomLibrary: String
  isFixAvailable: Boolean
  hasTicket: Boolean
  commentCount: Int
  latestCommentText: String
  latestCommentAuthorName: String
  latestCommentAt: DateTime
  isGptAvailable: Boolean
  isExcluded: Boolean
  hasJiraTicket: Boolean
  hasNonJiraTicket: Boolean
  hasSeverityOverride: Boolean
  originalIssueSeverity: IncidentSeverity
  hasOwnerOverride: Boolean
  originalOwnerName: String
  originalOwnerEmail: String
  currentOwnerName: String
  currentOwnerEmail: String
  hasMessages: Boolean
  isFixApplied: Boolean
  isExcludedByAlert: Boolean
  isFalsePositive: Boolean
  isCanceledFalsePositive: Boolean
  hasFalsePositiveDetails: Boolean
  falsePositiveComment: String
  cancelFalsePositiveComment: String
}
```

### Fields

| Field                                                                                                                                         | Description                                                                                             | Supported fields |
| --------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- | ---------------- |
| id `String!`                                                                                                                                  |                                                                                                         |                  |
| incidentId `String!`                                                                                                                          |                                                                                                         |                  |
| category [`EvidenceCategory!`](/api-documentation/api-reference/api--response-center/types/enums/evidence-category.md)                        |                                                                                                         |                  |
| state [`EvidenceState!`](/api-documentation/api-reference/api--response-center/types/enums/evidence-state.md)                                 |                                                                                                         |                  |
| severity [`IncidentSeverity`](/api-documentation/api-reference/api--response-center/types/enums/incident-severity.md)                         |                                                                                                         |                  |
| title `String!`                                                                                                                               |                                                                                                         |                  |
| resourceName `String!`                                                                                                                        |                                                                                                         |                  |
| resourceDetail `String`                                                                                                                       |                                                                                                         |                  |
| pipelineOutcome [`PipelineOutcome`](/api-documentation/api-reference/api--response-center/types/enums/pipeline-outcome.md)                    |                                                                                                         |                  |
| targetBranch `String`                                                                                                                         |                                                                                                         |                  |
| appName `String`                                                                                                                              |                                                                                                         |                  |
| appType `String`                                                                                                                              |                                                                                                         |                  |
| hitIndicatorValues `[String!]!`                                                                                                               |                                                                                                         |                  |
| isRunning `Boolean`                                                                                                                           |                                                                                                         |                  |
| runtimeStatus `String`                                                                                                                        |                                                                                                         |                  |
| cloudRunState [`CloudRunState`](/api-documentation/api-reference/api--response-center/types/enums/cloud-run-state.md)                         |                                                                                                         |                  |
| isUsed `Boolean`                                                                                                                              |                                                                                                         |                  |
| isInternetExposed `Boolean`                                                                                                                   |                                                                                                         |                  |
| dependencyType [`EvidenceDependencyType`](/api-documentation/api-reference/api--response-center/types/enums/evidence-dependency-type.md)      |                                                                                                         |                  |
| pinState `String`                                                                                                                             |                                                                                                         |                  |
| stateReason `String`                                                                                                                          |                                                                                                         |                  |
| externalUrl `String`                                                                                                                          |                                                                                                         |                  |
| asOf `DateTime!`                                                                                                                              |                                                                                                         |                  |
| developerEmail `String`                                                                                                                       |                                                                                                         |                  |
| commandRanAt `DateTime`                                                                                                                       | DevEnvironment rows — when the install command actually ran.                                            |                  |
| devEnvironmentOutcome [`DevEnvironmentOutcome`](/api-documentation/api-reference/api--response-center/types/enums/dev-environment-outcome.md) | DevEnvironment rows — the ox-ai-agent governance verdict for the install: Blocked, Flagged, or Allowed. |                  |
| resourceOwner `String`                                                                                                                        |                                                                                                         |                  |
| issueId `String`                                                                                                                              |                                                                                                         |                  |
| sbomAppId `String`                                                                                                                            |                                                                                                         |                  |
| sbomLibrary `String`                                                                                                                          |                                                                                                         |                  |
| isFixAvailable `Boolean`                                                                                                                      |                                                                                                         |                  |
| hasTicket `Boolean`                                                                                                                           |                                                                                                         |                  |
| commentCount `Int`                                                                                                                            |                                                                                                         |                  |
| latestCommentText `String`                                                                                                                    | Newest comment body, truncated — drives the Actions-column comment tooltip preview.                     |                  |
| latestCommentAuthorName `String`                                                                                                              |                                                                                                         |                  |
| latestCommentAt `DateTime`                                                                                                                    |                                                                                                         |                  |
| isGptAvailable `Boolean`                                                                                                                      |                                                                                                         |                  |
| isExcluded `Boolean`                                                                                                                          |                                                                                                         |                  |
| hasJiraTicket `Boolean`                                                                                                                       |                                                                                                         |                  |
| hasNonJiraTicket `Boolean`                                                                                                                    |                                                                                                         |                  |
| hasSeverityOverride `Boolean`                                                                                                                 |                                                                                                         |                  |
| originalIssueSeverity [`IncidentSeverity`](/api-documentation/api-reference/api--response-center/types/enums/incident-severity.md)            |                                                                                                         |                  |
| hasOwnerOverride `Boolean`                                                                                                                    |                                                                                                         |                  |
| originalOwnerName `String`                                                                                                                    |                                                                                                         |                  |
| originalOwnerEmail `String`                                                                                                                   |                                                                                                         |                  |
| currentOwnerName `String`                                                                                                                     |                                                                                                         |                  |
| currentOwnerEmail `String`                                                                                                                    |                                                                                                         |                  |
| hasMessages `Boolean`                                                                                                                         |                                                                                                         |                  |
| isFixApplied `Boolean`                                                                                                                        |                                                                                                         |                  |
| isExcludedByAlert `Boolean`                                                                                                                   |                                                                                                         |                  |
| isFalsePositive `Boolean`                                                                                                                     |                                                                                                         |                  |
| isCanceledFalsePositive `Boolean`                                                                                                             |                                                                                                         |                  |
| hasFalsePositiveDetails `Boolean`                                                                                                             |                                                                                                         |                  |
| falsePositiveComment `String`                                                                                                                 |                                                                                                         |                  |
| cancelFalsePositiveComment `String`                                                                                                           |                                                                                                         |                  |

### References

#### Fields with this object:

* [{} IncidentEvidenceGroup.items](/api-documentation/api-reference/api--response-center/types/objects/incident-evidence-group.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ox.security/api-documentation/api-reference/api--response-center/types/objects/incident-evidence-item.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
