.yml files are required.

Benchmarks: every run's pass rate, compliance, and trend over time.
Where it lives
Go to Command Center → Benchmarks:Creating a scenario
Click New Scenario (or open an existing one to edit) to get a form organized into sections:
A scenario has a status -
draft, published, or disabled. Only a disabled scenario is refused when you try to run it. Titles must be unique within the organization.
Every section holding structured data (steps, validation rules) has a Form / JSON toggle: edit through fields, or drop into raw JSON for anything the form doesn’t expose.
Setup and restore steps
Target Setup and Target Restore are both lists of plain-shell steps, grouped by host. Each step is either:- A command - a shell command, run as written (for example
sudo systemctl stop nginx). - A write - a file path, its full content, and an optional Write with sudo checkbox. A write replaces the file’s complete content; it does not append or patch.
${secret:name}; the value is exported as an environment variable and never inlined into the step itself.
Running a scenario
From a scenario’s page:- Run Now opens a dialog to pick one or more scenarios and optional overrides (main/secondary engine, gateway), then starts a benchmark and takes you to its run page.
- Break and Restore run just the Target Setup or Target Restore steps on their own, with live per-step status and output - useful for testing the steps themselves without waiting on a full graded run.
queued, running, completed, failed, cancelled) and a Stop that cancels the whole run.
Reviewing a run
A scenario’s run page shows the pass/fail result for each validation rule, the compliance score, and - when the scenario declares restore steps - whether the host was left clean. The scenario’s own page keeps its full run history, and the Benchmarks dashboard charts every run’s pass rate and compliance over time.If a run is interrupted
A benchmark’s status answers whether it ran, not how its scenarios scored. If something interrupts a run partway through, the scenario caught mid-run resolves to a cleanfailed (or cancelled, if you had already hit Stop) instead of hanging, and the rest of the scenarios in the benchmark keep running and report their own verdicts as usual.
