Compliance rules
The Compliance category currently holds one rule. It carries a 1.0 multiplier in scoring.
LOG-03 — Run History Retention (Low)
What it checks. Nothing is broken, strictly speaking. The rule fires for every flow that has run history, as a reminder to verify retention settings. A flow with no runs at all is not flagged; there is nothing to retain. The platform default keeps run history for 28 days. The finding records the environment name and how many runs the scan saw, so you can judge how much history the flow produces and how quickly the 28-day window would fill.
Why it matters. Twenty-eight days is often shorter than audit and forensic needs. If you investigate an incident two months after it happened, the run evidence is already gone.
What to do. Extend run history retention to meet your compliance requirements (90 days is a common target) and forward audit logs to a central SIEM, so evidence survives independently of the platform.
Treat LOG-03 as a checklist item rather than a defect. It fires once per flow with run history, so a large scan will produce many of these findings; review them in aggregate instead of one by one. Its Low severity contributes 1 base point to the risk score, so it will not move a flow’s action level on its own, and its confidence value (0.6) marks it as advisory. If the reminder is noise for your tenant, drop it to Informational with a severity override or disable the Compliance category toggle.
In 1.2.0. This rule cannot fire — the scan does not collect run history, so no flow has runs to evaluate. See Known limitations in 1.2.0.
A note on scope
LOG-03 is about run history inside the Power Platform. It does not cover the audit reports PowerToolBox writes to disk; those are yours to archive or delete under your own retention policy. See Report formats for where reports land and what they contain.
Last updated: July 27, 2026