Troubleshooting¶
Start with the exact page, record reference, action, time, and error message. These details help an administrator distinguish missing access from missing data or configuration.
I cannot see a menu item¶
- Open My Account > My Claims.
- Confirm the expected capability is present.
- Ask whether the optional feature is enabled.
- Sign out and back in if access changed recently.
Access Denied or HTTP 403¶
- Confirm the general claim required by the action.
- Confirm access to the specific risk or asset.
- For workflow actions, confirm required assignment or approval responsibility.
- Remember that asset View, Manage, Request, and Classify Sensitivity are separate capabilities.
RiskVault asks me to accept the Terms of Use and Privacy Policy¶
Your organization has published a new version, so everyone is asked to accept it once. Open the linked documents, then select Accept & Continue; you won't be asked again until the next revision. If an integration or API call started failing at the same time with a “terms acceptance required” message, sign in through the browser once and accept to clear it.
If you're sure you already accepted the current version, or you see the page on every visit, tell an administrator; the required version may have been changed by mistake.
A workflow action is missing or fails¶
Check the current state, your claim, the selected reviewer or approver, and the prerequisite message. Select a greyed-out button to see a checklist of what's missing, with links to each field. Save the section containing the required fields before retrying.
If Validate, Reject, or Request More Info is missing only on a risk you created, your organization probably blocks creators from reviewing their own risks (see Reviewer assignment and self-review). A different reviewer needs to make that decision.
A workflow action says the risk changed since I loaded it¶
Workflow actions carry the version of the risk you were looking at, so an action from a stale page is refused instead of overwriting someone else's change. Reload the risk, confirm its state and fields are what you expect, and take the action again.
My edit was rejected as a conflict¶
Another user saved after you opened the record. Reload, review the newer values, and reapply the change.
No quick-edit pencil appears¶
You need both Edit access to the risk and permission to edit that field in the current state. Scores, tolerance approvals, control links, and linked assets always use the full Edit page.
I'm told to give a reason for changing an assignment¶
Once work is under way, changing who is assigned to a risk needs a short reason, which is kept with the change. Use the pencil beside the name in the Resources card; its dialog has the Reason box. If you don't see that card, ask an administrator whether resource reassignment is enabled. See Change who is assigned to a risk.
A bulk assignment tells me to run Preview first¶
Bulk assignment records each risk's version during Preview and uses it to make sure nothing changed before Execute writes anything. Select Preview, check the result, then execute. If you changed the selection or filters after previewing, preview again.
I can't pick someone as the risk owner¶
The person must already be able to do the treatment work, and their account must be active. The message names what they're missing. If you manage users, you can assign them the Risk Owner Policy from the message; otherwise, ask an administrator or choose someone else. See Who can be a risk owner.
I cannot delete a risk¶
A submitted risk must have reached Closed, Rejected, or Archived, completed general retention, and have no active legal hold. The error identifies the blocking reason. Your own drafts are the exception: only an active legal hold blocks deleting them (see Deleting your own drafts).
A report export is blocked¶
The row estimate may exceed the configured maximum or time budget. Narrow filters and retry, or use queued background export when available.
An attachment will not upload¶
Confirm file size and extension rules, your Edit access to the risk (or, on the Create page, your permission to create risks), and the risk's state. Ask an administrator whether storage or scanning is reporting an error.
Jira linking is missing or fails¶
- Jira must be configured by an administrator.
- Linking normally begins at Validated and freezes at Closed, Archived, or Rejected.
- A second auto-created ticket is not allowed; re-link the existing one.
- Existing-ticket keys and URLs must use the configured Jira host.
I cannot link a control¶
- Confirm the Compliance Catalog feature is active.
- Confirm Edit access and a workflow state where Control Links is editable.
- A Not yet adopted result must be adopted by a control steward first.
Survey conversion did not create a risk¶
Review the conversion preview. The response may already be converted, may exactly match an existing title, or may fail draft validation.
Risk import will not continue¶
- Use CSV, TXT, or XLSX no larger than 10 MB and with no more than 1,000 data rows.
- Map Title correctly.
- Read dry-run row messages.
- Validate again after changing mappings or Strict/Lenient mode.
- Re-upload if the staged file expired.
An imported risk is missing a region, business unit, or rating¶
- Check the dry-run warnings for that row before you imported — an unmatched or ambiguous reference value, or a Rating column that did not match the calculated band, is reported there rather than silently dropped.
- Look for Unresolved values under the dry-run results and choose the correct match from the dropdown, then validate again. This is the fastest fix and applies to every row that used the same value.
- Alternatively, confirm the source value matches an active Region, Business Unit, Impact Area, Risk Factor, or ISO Domain name exactly (case and surrounding spaces are ignored, but not other differences), and re-upload.
- Ratings always come from Likelihood and Impact through your configured risk matrix; a mapped Rating column is a check against that value, not a replacement for it.
Notification links use the wrong address¶
Ask an administrator to correct Configuration Hub > Organization Settings > Base URL and restart the application (see Restart a service). The Base URL must be a complete HTTP(S) address with no query string or fragment.
My AI assistant asked me to sign in again¶
This is expected right after an administrator restarts the web application, for example to rotate a security certificate. A restart breaks MCP connections that were already open. Reconnect the tool the usual way; nothing about your account or access has changed. If it keeps happening outside a known restart, or colleagues' browser sessions are affected at the same time, tell an administrator.
MCP does not connect or return data¶
See Connect an MCP client and Common errors. Confirm the registered client, URL, scopes, consent, account access, data classification, and organization-wide exclusions.