Skip to content

Configuring Responses

A response is what happens when a finding opens. Responses are set per company on an audit's Response tab, so you can automate action for the clients that want it and simply track findings for the ones that don't.

Every company starts at Do nothing — findings are still reported and tracked, but no runbook or ticket fires until you set a response here.

The Response Table

The Response tab lists each company in scope with these columns:

ColumnWhat it controls
CompanyThe client the response applies to.
When a finding opensThe action: Do nothing, Runbook, or Ticket.
Runbook / ticketWhich runbook runs (when applicable).
GranularityWhether action is taken per finding or once per company.

When a Finding Opens

Choose one of three actions:

  • Do nothing -- Report only. Findings are still tracked; no action is taken.
  • Runbook -- Run a runbook to work the finding. Pick a published runbook from the dropdown, or click New to create one. You can also check Also open a ticket to do both.
  • Ticket -- Create a ticket for the finding.

Only published runbooks can be selected. If you create a new runbook from here, it opens in the runbook editor as a draft — publish it before it can run.

Granularity

Decide how much action a company's findings generate:

  • Per finding -- One ticket (or runbook run) for each finding.
  • Per company -- One ticket per company per audit, grouping that company's findings together.

Each row shows whether it's using the audit default or an override.

Bulk-Editing Responses

To set the same response across many clients at once, select their rows. A bar appears where you can choose the action, runbook, and ticket option, then apply it to every selected company in one step.

Applying to Existing Findings

Responses fire on the pass that detects a finding. If you set or change a response after findings are already open, use Apply to open findings on that row to apply the new response to the findings that are already open — otherwise it only affects findings detected on future passes.

At a Glance

The Findings tab shows a response summary banner for the audit (for example, "Response · Run runbook") with an Edit link back to this tab. Until you configure one, it reads "No response configured — findings are report-only."

Next Steps