{"id":"bac24241-2bda-4201-ab6f-6d0d0a61e4ef","task":"Query and triage findings from Google Cloud Security Command Center via the REST API","domain":"cloud.google.com","steps":["Enable Security Command Center on the organization and grant the caller a role such as securitycenter.findingsViewer.","Call findings.list scoped to a source (or \"-\" for all sources) with a filter expression, e.g. state=\"ACTIVE\" AND severity=\"HIGH\", paginating with pageSize/pageToken.","Use filter operators like contains() for array fields, such as matching specific finding categories or resource labels.","Mute or update a finding's state via the API to suppress an accepted-risk finding without deleting the underlying record.","For historical investigation, query findings as of a specific past timestamp to see the finding state at that point in time."],"gotchas":["The location path segment must be set correctly (global, or a specific region such as eu/sa/us if data residency is enabled) — using the wrong location returns no results even if findings exist.","Finding retention duration depends on the Security Command Center tier, so older findings may not be queryable via list without exporting them first."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/bac24241-2bda-4201-ab6f-6d0d0a61e4ef"}