---
title: "Get asset policy suggestions"
method: GET
path: "/v1/asset/policy/suggestion"
---

# Get asset policy suggestions

`GET /v1/asset/policy/suggestion`

Get suggested asset policies based on user data patterns. Analyzes asset data to suggest policies for bad data detection and important asset highlighting.

## Query parameters

- `enumeration_id` string
- `limit` integer
- `threshold` number

## Response `200`

OK

- AssetPolicySuggestionsResponse
  - `suggestions` AssetPolicySuggestion[], required — List of suggested policies based on user asset patterns
    - `id` string, required — Unique identifier for this suggestion (deterministic based on pattern)
    - `category` string, required — Category of the suggestion (e.g., ip_concentration, repeated_title)
    - `title` string, required — Human-readable title for the suggestion
    - `reason` string, required — Detailed explanation of why this suggestion is made
    - `severity` string, required — Severity level of the suggestion
    - `suggested_policy` object, required
      - `name` string, required — Suggested name for the policy
      - `policy_type` 'alert' | 'delete' | 'set_label' | 'remove_label', required — Type of action to perform when policy matches assets
      - `policies` AssetFilters, required
        - `is_tech` boolean — Return records that have technologies
        - `is_favicon` boolean — Return the records that have favicon
        - `is_new` boolean — Filter by new content
        - `labels` string — Filter by comma separated labels, e.g-> labels=p1,p2
        - `host` string — Filter by comma separated hosts, e.g-> host=p1,p2
        - `port` string — Filter by comma separated ports, e.g-> port=p1,p2
        - `status_code` string — Filter by comma separated status codes, e.g-> status_code=p1,p2
        - `content_length` string — Filter by comma separated content lengths, e.g-> content_length=p1,p2
        - `title` string — Filter by comma separated titles, e.g-> title=p1,p2
        - `domain` string[] — Filter by comma separated domain names, e.g-> domain=domain1.com,domain2.com
        - `cname` string — Filter by comma separated cnames, e.g-> cname=p1,p2
        - `technologies` string — Filter by comma separated technologies, e.g-> technologies=p1,p2
        - `ip` string — Filter by comma separated ips, e.g-> ip=p1,p2
        - `is_screenshot` boolean — Return the records with screenshots
        - `time` 'last_day' | 'last_week' | 'last_month' | 'last_3_months' | 'last_6_months' | 'last_12_months' | 'all_time'
        - `start_date` string, date — Filter by start date
        - `end_date` string, date — Filter by end date
        - `custom_filter` string — Filter by custom filter. Double encode the query string.
        - `search` string — Search on the content name
        - `enumeration_ids` string[] — Filter by enumeration ids
        - `only_dns` boolean — Query only dns FQDN records
        - `only_ip` boolean — Query only dns IP records
        - `not_seen_for_days` integer — Return assets that haven't been seen in the last N days. An asset is only included if a scan that covers it has run during that period without rediscovering it, so assets that simply haven't been rescanned recently are not matched.
      - `labels` string[] — Labels to apply (for set_label/remove_label types)
    - `affected_count` integer, required — Number of assets affected by this pattern
    - `affected_percentage` number, float — Percentage of total assets affected
    - `sample_assets` object[] — Sample assets matching this pattern
  - `total` integer, required — Total number of suggestions
  - `message` string

## Other responses

- `400` — Example response
- `401` — Example response
- `404` — Example response
- `500` — Example response
- `default` — Example response

---

[API](https://skmtc.net/projectdiscovery/apis/pdcp-api.md) · [All operations](https://skmtc.net/projectdiscovery/apis/pdcp-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/projectdiscovery/pdcp-api/versions/220f0adf9efd/schema)
