Findings Triage & Risk Quick View
Triage findings and review risk scoring from the web Reviewer Dashboard or the mobile GRC tabs.
Findings Triage & Risk Quick View
Findings record gaps surfaced during a review. Risks live in the Risk Register and are scored using inherent and residual ratings. Both are reviewable on the web and on mobile.
Findings — list & filters
Open Findings on mobile (/grc/findings) or the Reviewer Dashboard on web. Filters available on mobile:
- •Severity — Critical, High, Medium, Low, Info
- •Status — Open, Acknowledged, Resolved, Accepted Risk
- •Search — text search across title and description
Each row shows:
- •Title
- •Severity badge
- •Status badge
- •Date created
- •Linked assessment and question
Triaging a finding
Open a finding to see its full description and the originating response. From the detail view you can:
- •Change severity via chip selector (Critical → Info) — mobile and web
- •Change status via chip selector (Open → Acknowledged → Resolved or Accepted Risk) — mobile and web
The mobile finding detail pane only exposes severity and status edits; longer-form reviewer notes are managed from the web finding detail. Status transitions are logged to the activity log and trigger finding.status_changed and finding.resolved webhook events where applicable.
Risk Register & quick view
Open Risks on mobile (/grc/risks) or the Risk Register on web. Filters:
- •Severity (Inherent) — Critical, High, Medium, Low
- •Treatment —
mitigate,accept,avoid,transfer - •Search
List rows show: title, category, type, owner, identified date.
Risk quick view fields
Tap a risk to open the score card. It surfaces:
- •Inherent score — value, severity label, and the formula
Impact × Likelihood(each 1–5) — read-only in the mobile quick view - •Residual score — value, severity label, and the same formula applied after treatment — read-only in the mobile quick view
- •Treatment type — chip selector for
mitigate,accept,avoid,transfer(editable) - •Status — chip selector for Active, Closed, Archived (editable)
The mobile quick view edits treatment and status only; impact, likelihood, and severity ratings are managed from the full Risk editor on web. Saving a treatment or status change persists immediately and refreshes the score card.
Tips
- •Set a severity before changing status — the dashboard groups by severity, so consistent grading keeps the queue meaningful.
- •Use Accepted Risk sparingly; it removes the finding from the open queue but is preserved for the auditor trail.
- •For risks, always record the treatment type even when accepting, so the residual score reflects reality.
