Skip to main content
Validation rules determine whether a scenario passed. They are evaluated after the agent finishes executing.

Command Center scenarios

Scenarios stored in Command Center use a flat validation array. The engine always checks that the job completed, even when the array is empty.
The available validators are: Every rule needs a human-readable label. required defaults to true; an optional rule still contributes to the compliance score but does not fail the run. pattern_match can inspect these targets: Setup and restoration are also plain shell. Give each step a name so reports describe the action rather than displaying the command as its label:
A write step creates or replaces the complete file. It does not append or patch existing content.

CLI runner scenarios

The classic file-based runner declares validation in the grouped validation object of scenario.json.

Structure

Rules are organized into three scopes based on what they check: For tasks rules, each rule is checked against every task. A rule passes if it matches on at least one task.

Rule Structure

Every rule shares a common set of fields:

Validators

pattern_match

Checks whether a regex pattern matches in a specific field of the job or task data.
where targets:

job_resolution_status

Checks the job’s final resolution status.
pattern fixes one status. statuses accepts any of several, so a read-only scenario the agent ends as either success or partial does not fail on the difference:
Allowed values: success, agentic_failure, hard_failure, partial, no_action.

ticket_status

Checks the status of the ServiceNow ticket. Only applicable with --from gateway.

task_count

Verifies that the number of tasks created under the job falls within a range.

ansible

Runs an Ansible playbook and treats its exit code as pass/fail. The most reliable way to assert actual machine state.
A non-zero exit code fails the resolution gate and marks the scenario as failed. See Playbooks for how to write validate.yml.

Scoring Model

Compliance score: percentage of all non-Ansible rules that passed (required + optional combined). Informational. Two gates determine the actual pass/fail result: Compliance gate: passes when every required non-Ansible rule passes. Resolution gate: if a validate.yml Ansible rule exists, passes when the playbook exits 0. If no validate.yml rule is defined, it passes when the compliance gate passes and the compliance score is at least 80%. A scenario passes only when both gates pass.