Working on findings
Assign, comment on, resolve, accept or dispute findings, and track them to closure.
Open any finding to work on it. Analysts, admins and owners can make changes; viewers can read.
Statuses
| Status | Use it when… |
|---|---|
| Open | New and not yet looked at. |
| Acknowledged | You've seen it and agree it needs work. |
| In progress | Someone is fixing it. |
| Resolved | You believe it's fixed. Then request verification. |
| Reopened | It came back, or verification showed it isn't fixed. |
| Accepted risk | You have decided to live with it, for a documented reason. |
| False positive | It doesn't apply to you. Say why in a comment. |
Every status change is recorded with who made it and when.
Assigning
Use Assign to give a finding to a member of your organization. Your team gets an email notification.
Comments
Use comments for context: the ticket number in your own system, why a risk was accepted, or evidence that a finding is a false positive. Comments are part of the finding's history.
Accepting a risk
Accept risk records a deliberate decision not to fix something, with your reason. Accepted risks stay visible, and you can reopen them at any time. Use this rather than ignoring a finding, so auditors see a decision rather than a gap.
When a finding gets worse
If a later run sees the same problem at a higher severity, your team is emailed. Monitoring runs never create duplicates of a finding you already have; they update it.