When the review workflow is enforced, each demand follows a structured process with defined triage, assessment, response and approval steps. This ensures consistency, accountability and proper tracking throughout the risk assessment lifecycle. All workflow actions are taken from the Demand Status drawer, opened by clicking the status chip on the demand.
1. The workflow, stage by stage
Draft
The requester creates the demand with a title and completes it as a draft. Nobody is alerted until the requester clicks Submit for Review.
Awaiting Acceptance
On submission, members holding the Analyst role (plus any extra recipients configured in settings) are alerted. A reviewer triages the demand: Accept Demand, Request Information, or Reject Demand, each with a justification.
Needs Info and Updated by Requester
If more information is requested, the demand returns to the requester with the reviewer's message shown on the demand. The requester updates the details and clicks Send for review; the reviewer then takes another look.
In Progress
Once accepted, the risk assessment is worked on: risks are added, profiled and scored, controls recommended.
Awaiting Risk Response
When the analysis is ready, the analyst clicks Send for Risk Response. The full demand, including the risk assessment, becomes visible to the requester, who reviews the identified risks and provides a risk response for each.
Response Provided
The requester confirms with Provide Risk Response. Reviewers then approve the response and complete the demand, or click Request Changes to send the assessment back for rework (status Changes Requested).
Pending Assurance (optional)
If the Assurance review is enforced, completion happens only from this final gate: an Assurance reviewer verifies everything and completes the demand, or sends it back with a reason.
Completed
The demand is completed. Its result stays visible to the requester, and the linked risks live on in the Risk Registry.
2. Approvals and validation modes
Depending on your settings, approving the risk response takes a single approver or every member holding the Analyst role; the same choice exists at the Assurance gate. The drawer shows an approval checklist with each approver's state, and a workspace owner or Account Manager approval can override a pending multiple round. Approvals appear in the workspace activity feed.
3. Safeguards
- A demand under an enforced workflow cannot be completed before the requester has provided the risk response.
- Every status change asks for confirmation, and reject, request-information, request-changes and send-back actions require a written justification shown on the demand.
- The timeline in the Demand Status drawer records every visit to every stage, with author and date and time. Stages the demand has provably visited stay on the timeline even if your current settings would skip them.
For detailed steps, refer to the following sections of this documentation.