> ## Documentation Index
> Fetch the complete documentation index at: https://docs.chainloop.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# List a policy evaluation's violations

> Returns one policy evaluation's violation messages, paginated, in the order the policy reported them. GetEvaluationsForWorkflow reports only violation_count and has_violations, because a single evaluation can carry hundreds of thousands of violations. Evaluations stored before violations had their own rows are served from the legacy inline column, where every violation reports suppressed=false.



## OpenAPI

````yaml https://api.app.chainloop.dev/openapi.yaml get /v1/compliance/policy-evaluations/{policy_evaluation_id}/violations
openapi: 3.0.1
info:
  contact:
    email: support@chainloop.dev
    name: Chainloop Support
    url: https://chainloop.dev
  termsOfService: https://chainloop.dev/terms
  title: Chainloop Platform API
  version: '1.0'
servers:
  - url: https://api.app.chainloop.dev/
security:
  - bearerToken: []
tags:
  - description: AI-powered agent operations
    name: AgentsService
  - name: ArtifactService
  - name: AssessmentService
  - description: Service for polling the status of asynchronous operations
    name: AsyncOperationsService
  - name: AttestationsService
  - name: PolicyService
  - name: ComplianceService
  - name: ComponentService
  - name: EnvironmentsService
  - name: EvidenceService
  - name: FindingService
  - name: LinearService
  - name: LogicalEnvironmentsService
  - name: ProductsService
  - name: ProjectsService
  - name: UserService
  - name: WorkflowTemplateService
externalDocs:
  description: Chainloop Official Documentation
  url: https://docs.chainloop.dev
paths:
  /v1/compliance/policy-evaluations/{policy_evaluation_id}/violations:
    get:
      tags:
        - ComplianceService
      summary: List a policy evaluation's violations
      description: >-
        Returns one policy evaluation's violation messages, paginated, in the
        order the policy reported them. GetEvaluationsForWorkflow reports only
        violation_count and has_violations, because a single evaluation can
        carry hundreds of thousands of violations. Evaluations stored before
        violations had their own rows are served from the legacy inline column,
        where every violation reports suppressed=false.
      operationId: ComplianceService_ListPolicyEvaluationViolations
      parameters:
        - description: The evaluation whose violations to list
          in: path
          name: policy_evaluation_id
          required: true
          schema:
            type: string
        - description: >-
            The (zero-based) offset of the first item returned in the
            collection.
          in: query
          name: pagination.page
          schema:
            format: int32
            type: integer
        - description: >-
            The maximum number of entries to return. If the value exceeds the
            maximum, then the maximum value will be used.
          in: query
          name: pagination.page_size
          schema:
            format: int32
            type: integer
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1ListPolicyEvaluationViolationsResponse'
          description: A successful response.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1BadRequestResponse'
          description: Bad Request - The request was invalid or cannot be served.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1UnauthorizedResponse'
          description: Unauthorized - Authentication is required.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1PermissionDeniedResponse'
          description: Forbidden - You do not have permission to access this resource.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1InternalServerErrorResponse'
          description: Internal Server Error - An unexpected error occurred on the server.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
          description: An unexpected error response.
components:
  schemas:
    v1ListPolicyEvaluationViolationsResponse:
      example:
        pagination:
          total_count: 1
          page: 4
          total_pages: 1
          page_size: 7
        violations:
          - suppressed: true
            message: message
            ordinal: 0
          - suppressed: true
            message: message
            ordinal: 0
        material_name: material_name
      properties:
        violations:
          items:
            $ref: '#/components/schemas/v1PolicyViolation'
          title: The evaluation's violations, in the order the policy reported them
          type: array
        pagination:
          $ref: '#/components/schemas/v1OffsetPaginationResponse'
        material_name:
          title: >-
            The evaluation's material, which is the subject every violation here
            is about
          type: string
      type: object
    v1BadRequestResponse:
      description: Response for bad request
      example:
        code: 0
        details:
          - details
          - details
        message: message
      properties:
        code:
          default: 3
          description: >-
            The error code indicating the type of error. It's fixed to 3, which
            is the code for INVALID_ARGUMENT.
          format: int32
          type: integer
        message:
          description: A human-readable message providing more details about the error.
          type: string
        details:
          description: Additional details about the error.
          items:
            type: string
          type: array
      required:
        - code
        - message
      title: BadRequestResponse
      type: object
    v1UnauthorizedResponse:
      description: Response for unauthorized access
      example:
        code: 6
        details:
          - details
          - details
        message: message
      properties:
        code:
          default: 16
          description: >-
            The error code indicating the type of error. It's fixed to 16, which
            is the code for UNAUTHENTICATED.
          format: int32
          type: integer
        message:
          description: A human-readable message providing more details about the error.
          type: string
        details:
          description: Additional details about the error.
          items:
            type: string
          type: array
      required:
        - code
        - message
      title: UnauthorizedResponse
      type: object
    v1PermissionDeniedResponse:
      description: Response for permission denied
      example:
        code: 1
        details:
          - details
          - details
        message: message
      properties:
        code:
          default: 7
          description: >-
            The error code indicating the type of error. It's fixed to 7, which
            is the code for PERMISSION_DENIED.
          format: int32
          type: integer
        message:
          description: A human-readable message providing more details about the error.
          type: string
        details:
          description: Additional details about the error.
          items:
            type: string
          type: array
      required:
        - code
        - message
      title: PermissionDeniedResponse
      type: object
    v1InternalServerErrorResponse:
      description: Response for internal server error
      example:
        code: 5
        details:
          - details
          - details
        message: message
      properties:
        code:
          default: 13
          description: >-
            The error code indicating the type of error. It's fixed to 13, which
            is the code for INTERNAL_ERROR.
          format: int32
          type: integer
        message:
          description: A human-readable message providing more details about the error.
          type: string
        details:
          description: Additional details about the error.
          items:
            type: string
          type: array
      required:
        - code
        - message
      title: InternalServerErrorResponse
      type: object
    rpcStatus:
      example:
        code: 5
        details:
          - '@type': '@type'
          - '@type': '@type'
        message: message
      properties:
        code:
          format: int32
          type: integer
        message:
          type: string
        details:
          items:
            $ref: '#/components/schemas/protobufAny'
          type: array
      type: object
    v1PolicyViolation:
      example:
        suppressed: true
        message: message
        ordinal: 0
      properties:
        ordinal:
          description: >-
            The violation's position in the evaluation, as the policy reported
            it. Zero-based.
          format: int32
          type: integer
        message:
          title: The violation message
          type: string
        suppressed:
          description: >-
            Whether the violation was kept out of the gate at ingest, by the
            assessments current at

            that time or by the policy's own suppression flag. Always false for
            an evaluation stored

            before violations had their own rows: its messages never included
            the suppressed ones.
          type: boolean
      title: PolicyViolation is one violation reported by a policy evaluation
      type: object
    v1OffsetPaginationResponse:
      example:
        total_count: 1
        page: 4
        total_pages: 1
        page_size: 7
      properties:
        page:
          format: int32
          title: The current page number
          type: integer
        page_size:
          format: int32
          title: The number of results per page
          type: integer
        total_count:
          format: int32
          title: The total number of results
          type: integer
        total_pages:
          format: int32
          title: The total number of pages
          type: integer
      title: OffsetPaginationResponse is used to return the pagination information
      type: object
    protobufAny:
      additionalProperties:
        type: object
      example:
        '@type': '@type'
      properties:
        '@type':
          type: string
      type: object
  securitySchemes:
    bearerToken:
      description: Bearer token for authentication
      type: http
      scheme: bearer
      bearerFormat: JWT

````