Skip to main content

Risk exceptions

Use a risk exception when your team has reviewed an issue and decided to accept it or document why it does not require immediate action.

Record a decision​

  1. Open the full misconfiguration or runtime-finding page.
  2. Choose Accept Risk.
  3. Select a reason: Accepted risk, False positive, Not applicable, or Compensating control.
  4. Add a note explaining the decision and choose an expiry date.
  5. Submit the exception.

The finding page displays the recorded exception. Use the revoke action when the decision no longer applies, and review exceptions before they expire.

Accepting risk records a decision; it does not fix the resource or close the underlying finding. Keep any follow-up work in a linked task.