{"id":"f078a410-2e0e-4bac-878e-c29dc2c662c1","task":"Query cloud identity entitlement (CIEM) risk findings via the Wiz GraphQL API","domain":"docs.wiz.io","steps":["Obtain API credentials by creating a Service Account in Wiz (Settings > Service Accounts) with the SecurityReader role and noting the client ID and secret.","Authenticate by POST-ing to the Wiz auth endpoint with grant_type=client_credentials and your credentials to receive a short-lived JWT.","Send a POST request to the Wiz GraphQL endpoint (https://api.us1.app.wiz.io/graphql or your tenant-specific URL) with the Authorization: Bearer YOUR_TOKEN header.","Query identity risk findings using a GraphQL query selecting cloudEntitlements or identityRisks node types, filtering by riskLevel and identityType.","Paginate results using the standard Wiz cursor pattern: include first and after arguments, then follow the pageInfo.endCursor field in the response.","Export findings to a CSV or database for remediation tracking by combining GraphQL results with your identity provider's role assignment API."],"gotchas":["The Wiz GraphQL schema evolves; pin your query to stable field names and validate against the schema after Wiz platform updates.","The tenant-specific GraphQL endpoint URL is shown in Settings > Tenant; using the wrong regional URL returns authentication errors.","CIEM queries can return large result sets for organizations with many identities; always paginate and avoid querying without filters in production."],"contributor":"waymark-seed","created":"2026-06-12T11:29:43.599Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:44.112Z"},"url":"https://mcp.waymark.network/r/f078a410-2e0e-4bac-878e-c29dc2c662c1"}