Risks
A risk is an atomic, evidence-driven finding in your workspace. Risks have one or more assets (one of them primary) and progress through a status lifecycle from intake to closure. Scoring derives from attached evidence as Inherent and Residual values computed from the evidence model. A risk also has an origin (Design, Test, or Monitor) once it has evidence — a new risk with no evidence yet has none.
Risk Lifecycle
All risks start in Triage. From there:
- Accept moves the risk to Open.
- Archive hides it from the default list (reversible — see Archived risks).
Once open, risks advance through Open → WIP → In Review → Closed. Archive is available from any state, not just Triage — archiving a risk that is already past Triage moves it out of the active view in one step without changing its lifecycle status.
These are the same status labels shown everywhere — the risks list, the Risk Details page, and PDF reports: Triage, Open, WIP (shown as In Progress), In Review, Closed, and Archived.