Skip to content

Findings & the Risk Ledger

A finding is a single result — one entity (a device or a user) that failed one check on the latest pass. Findings are grouped into per-company cards on an audit's Findings tab, each showing how many entities were scanned and how many are compliant.

Finding Lifecycle

Every finding carries a status:

StatusMeaning
NewJust detected on the latest pass.
In progressOpen and being worked, often by a runbook. May show its age (for example, "open 8d").
Needs attentionHas persisted across passes and requires a human to act. This is the only red state.
ResolvedCleared — fixed, or closed by a runbook.
AcknowledgedThe client was notified and chose not to act. The risk is accepted and kept on record.

Use the filter chips to focus the list: Open (everything unresolved), Resolved, Acknowledged, Suppressed, or Everything.

Working a Finding

Click a finding to open its evidence timeline — a slide-over showing everything that happened to it, from detection through each pass, escalation, runbook run, ticket, and resolution. If a ticket was created, a link to it appears here.

From the finding you can:

Acknowledge Risk

When a client is notified and chooses not to act, acknowledge the risk. This transfers responsibility to them, stops nudges, and keeps the finding on record. You'll capture:

  • Who accepted the risk (required)
  • How it was communicated — Email on file, Verbal, or Attached doc
  • An optional note
  • The date accepted (required)

Suppress a Finding

Suppress a finding to stop it appearing in the list while keeping it counted under its company. You'll choose:

  • A reason — Device being decommissioned, Vendor-managed (out of scope), Known false positive, or Client-approved exception.
  • Re-check after — Never, 30, 90, or 180 days.

You can unsuppress a finding at any time to bring it back into the active list.

The Acknowledged Risk Ledger

Every acknowledged risk is recorded in the Acknowledged risk ledger, reachable from the Acknowledged risks tile on the Audits overview. The ledger shows everything you flagged, when you flagged it, and the client's sign-off declining to act — organized per company.

Use Export for QBR to produce a client-facing record of the accepted risks on file — useful evidence for quarterly business reviews that the issues were surfaced and the client chose the risk.

Next Steps