View and edit a risk

The Details page is the authoritative read view. The Edit page provides the full workflow-aware form.

Understand the Details page

Depending on access and workflow state, Details can show ownership, rating, assessment, controls, assets, treatment, residual risk, monitoring, files, relationships, comments, permissions, and complete activity history.

Image needed: Risk Details page with state, owner, rating, phase cards, comments, history, and action menu labeled.

Make a quick edit

For a small correction, hover over a field. A pencil appears only when you can edit both the risk and that field in its current state.

  1. Select the pencil.
  2. Change the value.
  3. Save according to the field type:
  4. Text saves with Enter or when you click elsewhere.
  5. Long text saves with Ctrl+Enter or Cmd+Enter, or when you click elsewhere.
  6. Dropdowns and user pickers save when you choose a value.
  7. Press Escape before saving to cancel.

Tags use instant saving: each addition or removal is saved separately.

Scores, tolerance approval fields, control links, and linked assets stay in the full Edit page because they require additional validation or multi-value controls. When resource reassignment is enabled, the Tolerance Approver is changed from the Resources card instead, and the pencil beside the risk owner, reviewer, or action owner opens the reassignment dialog described below rather than an inline picker.

If someone else changed the risk while you were looking at it, your quick edit is rejected and the page reloads to show the latest version.

Read the Key Dates panel

The Key Dates panel keeps the risk's dates apart:

  • Target Date — the date your team is aiming for. This is the only one you edit here.
  • Deadline — the automatic SLA deadline for the step the risk is on now.
  • Treatment Due — the date set for the treatment work, once treatment starts.

Change who is assigned to a risk

Note

This is available only when an administrator has enabled resource reassignment. Until then, change the owner, reviewer, and action owner with the Details pencil or the matching field on the Edit page.

A risk has five people fields, and at some point one of them usually needs to change: someone leaves, work is handed over, or the wrong name was picked. Sending the risk backwards through its workflow to fix that would lose its history, so RiskVault treats reassignment as its own action.

When the feature is on, the Details and Edit pages show a Resources card listing the risk owner, reviewer, action owner, treatment approver, and tolerance approver. A pencil appears only beside the ones you can change on this risk right now.

  1. Select the pencil beside the person to replace.
  2. Review who holds the slot today and the risk's current state.
  3. Choose the replacement in the picker.
  4. Enter a Reason if one is required.
  5. Save. The page reloads with the new name.

Image needed: Resources card with its five people fields and the reassignment dialog open, showing the current holder, replacement picker, and Reason box.

What the dialog will and won't let you do:

  • The workflow doesn't move. The risk's state, its SLA deadline, and every other assignment stay as they were. Only the one name changes.
  • A reason is required once work has started. While a risk is still in its setup window — a new risk's owner, or a reviewer who hasn't started reviewing — no reason is needed. After that, it is required and kept with the change.
  • You replace; you don't clear. There's no “unassign.” To hand work off from someone who has left, name their replacement.
  • Recorded decisions are final. An approver who has already approved can't be swapped out afterwards, because that name is the record of who approved. Approvers can be replaced while their decision is still pending.
  • Closed, Archived, and Rejected risks are locked, as they are everywhere else.

The dialog may warn you about two things before you save:

  • The person can't do the work yet. Each slot is checked against the abilities it needs (see Who can be a risk owner). If you manage users, you're offered a one-click policy fix; otherwise the message names what's missing so you can pass it on.
  • The person can't open this risk. Being named reviewer or approver comes with access to the risk; being named action owner does not. If the replacement couldn't see the risk, you're warned, and if you can manage this risk's permissions, you're offered a button to grant them view access.

The person taking over, the person handed off from, and anyone watching the risk are all notified just after the change is saved. Someone who can no longer open the risk gets a plain notice without its details.

Below the card on the Details page, Resource assignment history lists the last twenty changes: what changed, when, who made the change, and the reason. The list is append-only, so it remains a dependable record of why a handover happened.

Use the full Edit page

  1. Select Edit from Details or the Risk Register.
  2. Open the workflow phase and sub-tab containing the information to change.
  3. Edit only the fields that are unlocked.
  4. Use the section save control, or Save all changes.
  5. Confirm that no validation errors remain before running a workflow action.

Ctrl+S or Cmd+S saves all registered editable sections. Merely changing tabs does not save data.

Completed phases are normally summarized. A previous phase marked (view) has no editable fields for you, though a different previous phase can remain partly editable if workflow rules allow a correction. Field editing depends on both the workflow state and your claims, so you may be able to run a workflow action without being able to edit the current fields.

Once a risk has moved past intake, a Summary tab appears first with a short read-only overview. If your organization uses AI assistance and you have it turned on, the Summary also includes a brief recap of the risk's story so far, refreshed each time the risk enters a new phase.

To keep a tab you use often within reach, select the pin next to its name. You can pin up to three tabs; they stay in the tab strip for that risk as it moves through its phases. Select the pin again to unpin.

A rejected risk also has a Rejection Details tab with the reason it was rejected, and a Clone Risk action to start a new draft from it.

This tab remains available across workflow phases because it contains risk-wide metadata:

  • file attachments;
  • Jira linkage;
  • related-risk links;
  • custom tags.

On an existing risk, these cards save independently and immediately. During initial creation, staged content is saved with the new risk.

Resolve a save conflict

Risk and asset edits use version checks. If someone else saved first, RiskVault rejects your stale update instead of silently overwriting theirs.

  1. Copy any lengthy unsaved text somewhere safe.
  2. Reload the record.
  3. Review the newer values and history.
  4. Reapply only the changes that are still appropriate.
  5. Save again.

If you have legal-hold management access, the Details overflow menu includes Assign Legal Hold.

  1. Open the risk's Details page.
  2. Open the overflow menu and select Assign Legal Hold.
  3. Choose an active legal-hold policy.
  4. Keep the policy's default duration, override the number of days, or leave it indefinite as permitted.
  5. Enter the reason for the hold.
  6. Select Delete automatically when this hold ends only when the approved records process requires an unrecoverable purge after all holds expire.
  7. Confirm the assignment.
  8. Verify the red Legal Hold badge, policy name, and expiry date when present.

While any hold is active, the risk cannot be manually or automatically deleted. This overrides general retention rather than merely adding time to it.

To release a hold early, select the release control on the badge and enter a reason of at least 10 characters. Releasing one hold does not remove another active hold on the same risk.

Danger

Automatic deletion after a hold is permanent. It can remove the risk, comments, relationships, workflow history, and attachments. Do not enable it as a substitute for ordinary soft deletion.

Administrators define policies and review all active holds under Application configuration.