Skip to main content

Risks & controls

Status: Available (Shipped) · Owner: Proof / Trust & Review · maturity: Feature status Open /proof/risks-and-controls in the product. The workspace answers: what could go wrong, what addresses it, which safeguards are mapped, and what remains unestablished. This is a collaborative RACM over risks, controls, safeguard bindings, walkthrough notes, assignments, evidence requests/submissions, conclusions, findings, risk acceptance, and reviewed-scope export. It is separate from the control-assurance implementation surface at /proof/controls, which owns receipt-backed prevention claims for tool/schema controls.

What the matrix shows

Authority boundaries

  • Review, conclude, and close paths require the control’s designated reviewer (or an explicit combined-role setting). Submitters cannot self-approve by default.
  • Risk acceptance requires the recorded risk owner.
  • Staging≠production mismatches come from artifact provenance, not free-text claim scope.
  • Superseded submissions stay readable but are not current acceptance material.

Evidence and export

  1. Request evidence for a control criterion.
  2. Submit artifacts against that request (request-scoped replace).
  3. Review with loaded artifacts and provenance.
  4. Record design/implementation/operation conclusions bound to configuration revisions.
  5. Export a reviewed-scope snapshot (JSON and XLSX) that freezes limitations and evidence IDs.
Guest portals and optional connector collectors remain optional product paths; do not treat an empty guest invite as a closed control.