Workflow States
Every risk assessment moves through specific states. Here’s what each state means:Draft
Draft
Work in progress. You can save incomplete information and return later.
Initiated
Initiated
Submitted and waiting for review. The checker will verify or decline it.
Verified
Verified
Approved by checker. Asset owners can now add their action plans.
Declined
Declined
Rejected by checker. Review the feedback and make corrections before resubmitting.
Plan Proposed
Plan Proposed
All asset owners have submitted their action plans. Waiting for maker approval.
Plan Accepted
Plan Accepted
Action plans approved. Asset owners can begin remediation work.
Plan Rejected
Plan Rejected
Action plans need improvement. Asset owners must revise and resubmit.
Closure Proposed
Closure Proposed
Work is complete. Asset owner has requested closure.
Closed
Closed
Risk is fully resolved and closed.
Step 1: Create Risk Assessment
Option A: Save as Draft
Use this when you don’t have all the information yet.Option B: Submit Directly
Use this when you have all the required information ready.Required fields: Risk name, description, at least one asset, impact ratings, control effectiveness, and at least one finding.
Step 2: Submit Draft (If Saved as Draft)
When your draft is complete and ready for review:Step 3: Checker Review
This step only happens if your organization has checker approval enabled. If disabled, skip to Step 4.
Option A: Checker Approves
Option B: Checker Declines
Step 4: Update Declined Risk
If your risk was declined, here’s how to fix it:Step 5: Asset Owners Add Action Plans
Once the risk is verified (or initiated if no checker approval), asset owners create their plans.Create Action Plan
Describe specific steps to address the risk. Example: Install security patches, enable MFA, update policies.
Step 6: Maker Reviews Plans
Option A: Accept Plans
Option B: Reject Plans
Step 7: Asset Owners Revise Plans (If Rejected)
Step 8: Implement Remediation
Step 9: Propose Closure
When remediation work is complete:Step 10: Close Risk
Closed risks remain in the system for audit and compliance purposes.
Quick Reference
Who Does What
Risk Maker:- Creates and submits risks
- Updates declined risks
- Accepts or rejects action plans
- Closes risks
- Reviews submitted risks
- Verifies or declines with feedback
- Creates action plans for assigned findings
- Implements remediation
- Proposes closure when work is complete
Common Scenarios
- With Checker Approval
- Without Checker Approval
- Quick Submit
Flow: Draft → Initiated → Verified → Plan Proposed → Plan Accepted → Closure Proposed → ClosedTotal steps: 7-10 depending on revisions
Notifications
You’ll receive email and in-app notifications at key steps: Risk Makers get notified when:- Risk is verified or declined
- All action plans are proposed
- Closure is proposed
- New risk awaits review
- Declined risk is resubmitted
- New finding is assigned
- Action plan is rejected
Tips for Success
For Risk Makers
Use drafts for complex assessments. Address all feedback before resubmitting. Review plans carefully before accepting.
For Risk Checkers
Review within 24-48 hours. Provide specific feedback. Be consistent in your criteria.
For Asset Owners
Create specific, measurable plans. Set realistic dates. Document your work thoroughly.
For Everyone
Use comments to collaborate. Attach evidence. Keep information current.
Troubleshooting
Cannot submit draft
Cannot submit draft
Problem: Submit button is disabledSolution: Complete all required fields. Look for red validation errors on the form.
Risk stuck in Initiated
Risk stuck in Initiated
Problem: Waiting too long for checkerSolution: Contact the checker directly or escalate to admin if urgent.
Cannot edit risk
Cannot edit risk
Problem: Update button not availableSolution: Only Draft and Declined risks can be edited. Other states are locked.
Action plan will not submit
Action plan will not submit
Problem: Submit button disabledSolution: Both action plan text and target date are required.
Configuration
Admins can enable or disable checker approval in Entity Configuration. This setting only affects new risks, not existing ones.