Called by an agent, collector or connector with its own key: post one scan document
Itam
Called by an agent, collector or connector with its own key: post one scan document
(schema itam.scan/1) as that source, with an HMAC-SHA256 signature over the exact text. Resending a
document with the same document_id returns the first answer and records nothing. Attributes the
organisation does not keep are dropped and only their names are returned; devices a collector
reports outside every range it is authorised to scan are dropped entirely and only counted.
Matching against the asset register happens shortly afterwards, not in this call.
The document: {"schema": "itam.scan/1", "document_id": uuid, "kind": "FULL" | "PARTIAL" |
"SWEEP", "collected_at": time, "agent_version": text, "run": {"schedule_id", "attempted",
"responded", "auth_failed"}, "devices": [{"observed_at": time, "method": "AGENT" | "SNMP" | "SSH" |
"WMI" | "WINRM" | "ICMP" | "API" | "MDM", "attributes": {...}, "software": [{"title", "publisher",
"version", "installed_on"}]}]}. A FULL document's software list is everything installed, so
anything it leaves out is recorded as removed.

