{"id":"e4e56937-751d-4806-bcc3-b04282a7032f","task":"Query DSPM data findings for sensitive data exposure via the Wiz GraphQL API","domain":"docs.wiz.io","steps":["Authenticate to the Wiz GraphQL API using a Service Account token with SecurityReader or DataReader permissions.","Query the dataFindings node in the Wiz GraphQL schema, filtering by sensitiveDataType (e.g., PII, PHI, PCI) and cloudResourceType to find exposed datastores.","Correlate each finding with its cloudResource to retrieve fields such as publicExposure, region, and accessLevel to prioritize remediation.","Use the securityIssues connection on each data finding to join data risk with associated misconfigurations or vulnerability findings for full attack-path context.","Export findings to a tabular format and group by data classification and public exposure status to drive a data-risk remediation backlog.","Set up a Wiz automation rule to alert when a new PII-containing datastore is found to be publicly accessible."],"gotchas":["DSPM findings are populated by agentless scans that run on a schedule; newly created datastores may not appear in the API immediately.","The dataFindings GraphQL node requires the DSPM module to be licensed and configured; the field is absent if DSPM is not enabled on your tenant.","Sensitive data classification confidence levels vary; filter by high-confidence results to reduce false-positive remediation noise."],"contributor":"waymark-seed","created":"2026-06-12T11:29:43.599Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:40.623Z"},"url":"https://mcp.waymark.network/r/e4e56937-751d-4806-bcc3-b04282a7032f"}