Welcome to RiskVault

RiskVault is where your organization keeps track of uncertain events that could affect its objectives. A risk does not simply sit in a list: it moves through a controlled process so the right people can review it, decide what to do, and keep an auditable record.

Risk management in one minute

The usual journey looks like this:

  1. Someone creates a risk and saves it as a draft.
  2. They submit it for review. A reviewer is assigned automatically or by a manager.
  3. A reviewer assesses its likelihood and impact, then validates it, returns it for more information, or rejects it. A risk owner is named once the risk has been submitted.
  4. A validated risk is treated or formally accepted within tolerance.
  5. The organization monitors and reassesses it over time.
  6. When work is complete, the risk is closed and eventually archived.

Your organization can customize parts of this workflow, so names and required fields may differ slightly. See Workflow lifecycle for the full explanation.

The navigation menu can include:

  • Dashboard — personal work, portfolio indicators, heatmap, status totals, and optional SLA information.
  • My Work Items — drafts, assigned actions, approvals, and authorized operational queues.
  • Risk Register — search, filter, review, and manage risks.
  • Reports — build, save, schedule, and export reports.
  • Risk Surveys — collect information and turn responses into draft risks.
  • Assets — browse the asset catalogue and link assets to risks.
  • Workflow Rules — configure automation when you have administration access.
  • Administration — manage access, configuration, imports, integrations, monitoring, SLAs, and workflow design.

The ? icon in the top bar opens this documentation in a new tab.

Image needed: Main RiskVault layout with the navigation menu, notification bell, account menu, and help icon labeled.

Search or jump anywhere

Press Ctrl+K on Windows or ⌘K on a Mac—or select the search box in the top bar—to open one search-and-navigation window. From there you can find:

  • Risks by RR number or title.
  • People by name or email. People results appear only for Risk Analysts, managers, and administrators. The briefcase icon shows risks assigned to that person; administrators can also open the person's admin profile.
  • Assets by asset code or name, when the asset inventory is enabled and you have access to it.
  • Go to destinations across the application, including the Administration and Configuration Hub pages available to you. Common synonyms work too—for example, searching for “sso” finds External Login Providers, and “kms” finds Encryption Settings. To find one specific setting rather than a page, use the search box on the Configuration Hub instead (see Find a setting fast).

Only results you are allowed to open are shown. Use the arrow keys to move through the list and Enter to open the highlighted result, or select a result with the mouse. If you can create risks and your search does not find a match, RiskVault offers to create a risk with your search text already entered as its title.

Select the eye icon beside a risk result to open a quick summary panel without leaving your current page or blocking the rest of it. The same quick view is available from the Risk Register's Kanban board (eye icon) and from My Work Items' All work list (select the risk's ID). It always includes a link to the full risk record.

Find your way back

Pages that sit inside Administration, Compliance, Reports, Assets, or an individual risk show a breadcrumb trail near the top. Earlier parts of the trail are links, so you can move back a level without reopening the main menu. The final part shows the page you are currently viewing.

Risk or issue?

  • A risk is an uncertain future event or condition that could affect an objective.
  • An issue is something that has already happened and needs a response or remediation.

Why screens differ between users

RiskVault combines four checks:

  1. Your signed-in identity.
  2. Your general roles, policies, and claims.
  3. Your access to the specific risk or asset.
  4. What the current workflow state allows.

A broad permission does not necessarily give access to every risk. Likewise, access to one risk does not grant the same access across the register.

Who can see a risk

Out of the box, anyone who can sign in can open a submitted risk. The exceptions are:

  • A draft is visible only to the person who created it.
  • A confidential risk needs the permission to view confidential risks.
  • A risk restricted to a department is visible to people in that department, people given access to that department, and people allowed to view all risks.

Whoever is named on a risk — the owner, action owner, reviewer, or an approver — can always open it, and so can anyone given access to that one risk. The creator of a risk can keep reading it after submitting it, unless it's confidential. See Who can see a risk for the details.

When RiskVault says you can't do something

If RiskVault blocks an action, it shows an Access Denied page with a link back into the application. You are usually signed in correctly but lack the permission, or the risk-specific access, that the action needs. Check My Account > My Claims, or ask an administrator.

A good first-day tour

  1. Open My Account and confirm your name, time zone, and theme.
  2. Review My Claims so you know which capabilities are available.
  3. Open Dashboard and inspect My Actions.
  4. Open My Work Items and review each queue.
  5. Open the Risk Register, try a search, and remove the filter.
  6. Open a risk you can view and explore its Details page and history.