Additional Restriction

additional_restriction

The Additional Restriction object describes supplementary access controls and guardrails that constrain or limit granted permissions beyond the primary policy. These restrictions are typically applied through hierarchical policy frameworks, organizational controls, or conditional access mechanisms. Examples include AWS Service Control Policies (SCPs), Resource Control Policies (RCPs), Azure Management Group policies, GCP Organization policies, conditional access policies, IP restrictions, time-based constraints, and MFA requirements.

Attributes

CaptionNameTypeDescription
PolicypolicyPolicy[]

Detailed information about the policy document that defines this restriction, including policy metadata, type, scope, and the specific rules or conditions that implement the access control.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

StatusstatusString

The current status of the policy restriction, normalized to the caption of the status_id enum value.

Status IDstatus_idInteger

The normalized status identifier indicating the applicability of this policy restriction.

  • 1: Applicable (APPLICABLE)
  • 2: Inapplicable (INAPPLICABLE)
  • 3: Evaluation Error (EVALUATION_ERROR)
  • 0: Unknown (UNKNOWN)
  • 99: Other (OTHER)
UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Relationships

Additional Restriction shown in context

Inbound Relationships

These objects and events reference Additional Restriction in their attributes:

Outbound Relationships

Additional Restriction references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0