Risks & controls
Status: Available (Shipped) · Owner: Proof / Trust & Review · maturity: Feature status Open/proof/risks-and-controls in the product. The workspace answers: what
could go wrong, what addresses it, which safeguards are mapped, and what
remains unestablished.
This is a collaborative RACM over risks, controls, safeguard bindings,
walkthrough notes, assignments, evidence requests/submissions, conclusions,
findings, risk acceptance, and reviewed-scope export. It is separate from the
control-assurance implementation surface at /proof/controls, which owns
receipt-backed prevention claims for tool/schema controls.
What the matrix shows
Authority boundaries
- Review, conclude, and close paths require the control’s designated reviewer (or an explicit combined-role setting). Submitters cannot self-approve by default.
- Risk acceptance requires the recorded risk owner.
- Staging≠production mismatches come from artifact provenance, not free-text claim scope.
- Superseded submissions stay readable but are not current acceptance material.
Evidence and export
- Request evidence for a control criterion.
- Submit artifacts against that request (request-scoped replace).
- Review with loaded artifacts and provenance.
- Record design/implementation/operation conclusions bound to configuration revisions.
- Export a reviewed-scope snapshot (JSON and XLSX) that freezes limitations and evidence IDs.