🎉 VSEC Test v4.0.1 is now live! Release Notes ↗
Risk Details

Risk Details

Open a risk’s detail page from the risks list: click a row to open its preview drawer and choose Open details, or right-click the row → Open risk details. Risk Details is organized into four tabs: the Risk tab (status, scoring, and the evidence model), the Related tab (auto-derived related risks), the Context tab (AI curation and suggested actions), and the Activity log.

Layout

A Return to Risk Manager link at the top of the page steps back to the list. The header shows the risk’s origin, status, and priority as chips (plus an Archived chip when applicable) above the heading, with the action buttons on the right. The four tabs — Risk, Related, Context, and Activity — are always present.

Header Actions

  • Add context — opens the Add context dialog to add a note, attach files, or request context from someone outside your workspace.
  • Accept — shown only while the risk is in Triage (and not archived); moves it to Open.
  • Edit — opens the Edit risk dialog to change the Heading, Priority, or Status (Triage, Open, WIP, In Review, or Closed). Save persists; Cancel abandons the changes.
  • Archive / Restore — hide the risk from the default list, or bring an archived risk back.

Risk Tab

The Risk tab holds the score headline, the Model health card, the Details card (status, assets, ownership), the Threat Library, Controls, and Evidence cards, a Related glance strip, and Comments.

Status

All risks start in Triage regardless of type. From Triage, Accept (header button) moves the risk to Open; Archive hides it from the default list (it is not deleted).

Once open, risks advance through OpenWIPIn ReviewClosed. Change the status from the Edit risk dialog’s Status dropdown — or from the list’s right-click context menu (Change status).

Archive is available from any state, not just Triage — archiving a risk that is already Open or beyond moves it out of the active view in one step without changing its lifecycle status. When archiving from the list’s context menu you may optionally enter a Reason (optional); it is saved as a comment on the risk and logged in the Activity tab. The Archive dialog on the Risk Details page has no reason field.

Archived risks

If a risk is archived, a warning Archived chip appears in the Risk Details header and a Restore button replaces Archive. To find archived risks, enable Include archived risks on the list, open the risk, then Restore — from Risk Details or from the list’s right-click context menu (Restore risk).

Deleting a risk

Archived risks may be permanently deleted if your role includes the deleteRMRisks permission. The Delete permanently option appears in the right-click context menu on the risks list — only when the risk is archived. This is intentionally high-friction: archive first (reversible), then delete (irreversible).

Deleting a risk removes it and all associated data — comments, asset links, revisions, stages, controls, custom field values, keywords, attachments, attack paths, damage scenarios, and any CSI links.

Assets

A risk is linked to one or more Assets, each shown as a chip — the primary asset (chosen at creation) is highlighted and cannot be detached; any additional linked assets show in a secondary color.

Click Manage assets on the Details card to attach or detach assets from this page. The picker supports the same list/tree views, type/property filters, and primary-asset badge as attaching assets from the Risk Manager table’s right-click menu. A risk must always keep at least one asset — if you uncheck every asset, or a detach would leave none, that removal is rejected and the rest of your changes are still applied.

Manage assets is disabled while a save is in progress or while the risk is archived (restore it first).

Ownership and treatment

The Details card shows the risk’s Priority (Unassigned, Low, Medium, High, Critical) and Treatment (how your team plans to handle the risk: Avoid, Reduce, Share, or Retain):

  • Priority and Status are changed via the Edit dialog, or from the list’s right-click context menu.
  • The assignee is set from the list’s right-click context menu (Assign to…).
  • Treatment is read-only here — it is set by applying an AI suggested action on the Context tab.

Scoring

Risk scores are derived automatically from attached evidence. Two values are displayed:

  • Inherent — the baseline score before controls are applied, derived from the evidence’s CVSS/impact and attack-feasibility inputs.
  • Residual — the score after applying the Control Library entries linked to this risk.

Both values are on a 1–5 scale. A risk that is missing required evidence inputs shows as unscored until the model is complete.

Model Health

The Model health card shows whether the risk has all the inputs needed to produce a score:

IndicatorMeaning
LikelihoodAt least one evidence item that drives the likelihood dial
ImpactAt least one evidence item that drives the impact dial
ControlsAt least one control applied (affects the residual score)
ComputableAll required inputs are present; a score can be derived

When inputs are missing the card lists what is needed (e.g., needs likelihood evidence). It also shows the evidence count, the last scored date, and the last evidence date so you can spot stale scores at a glance.

Evidence

The Evidence card lists the source-tagged observations that feed the score. Add evidence opens an inline form; each item can also be edited or deleted. Fields:

FieldDescription
SourceDesign, Test, Monitor, or Manual
SummaryNarrative description of the finding
CVSS score0–10; drives the dials when the risk has no Threat Library linkage
Weakness stateClause-8 state — Event, Weakness, Vulnerability, or Not Applicable. A rationale is required when marking evidence Not Applicable (ISO/SAE 21434 §8.5)
Reference (CVE / report id)An external identifier

Adding, editing, or removing evidence re-scores the risk immediately.

Threat Library links

The Threat Library card attaches and detaches library entities:

  • Threat scenarios — the scenario being analyzed.
  • Attack paths — drive Likelihood: the easiest linked path (lowest attack potential across its steps) sets the attack feasibility.
  • Damage scenarios — drive Impact: the worst impact category across linked scenarios sets the impact rating.

Controls

The Controls card applies Control Library entries to the risk. Linked controls reduce the residual score, and the risk re-scores live as controls are applied or removed.

Comments

The Comments section accepts text comments and is visible at the bottom of the Risk tab. To attach files to a risk, use the Context tab — uploaded documents become part of the risk’s context.

Related Tab

The Related tab shows risks that are automatically linked to this one based on the asset graph and threat-library relationships. Relatedness is derived on demand — no manual linking is required — and is read-only.

A risk appears in the Related list when it shares one or more of:

  • The same asset, or a parent / child asset in the asset hierarchy.
  • A Threat Library entity: threat scenario, attack path, damage scenario, or control.
  • A CVE or evidence reference.

Each related risk shows the reason(s) for the relationship as chips (e.g., Same asset, Same control, Shared CVE). Click a related risk to navigate to its detail page.

A compact glance strip on the Risk tab shows the related count and top reason chips. Click Explore in the strip to jump directly to the Related tab.

Context Tab

The Context tab maintains a living AI-curated understanding of the risk, proposes field updates for human review, and surfaces Suggested actions — structured one-click state transitions. See Risk Context for the full workflow.

Activity

Per-risk change log. An entry is created whenever a field is edited, status changes (accepted, archived, restored), or a file is attached. Comments do not create Activity entries (an archive Reason is logged as part of its archive entry).

Filtering

The filter bar above the log lets you narrow history by any combination of:

FilterDescription
From / ToShow only entries within a date range. Preset chips (Last 7 days, Last 30 days) are available for common ranges.
UserShow only entries by a specific user (or System for automated actions). Options are derived from the users present in the currently loaded entries.
ActionShow only entries of a specific action type. Options are derived from the action types present in the currently loaded entries.

From / To re-query the server for the selected range; User and Action filter the loaded entries client-side. All filters can be combined. Click Clear to reset all filters at once.

If the filtered result is empty, the log displays “No activity matches your filter.”

If your workspace supports revision comparison, open an entry to compare it side by side with the previous version.

Last updated on