Risk exceptions
Use a risk exception when your team has reviewed an issue and decided to accept it or document why it does not require immediate action.
Record a decision
- Open the full misconfiguration or runtime-finding page.
- Choose Accept Risk.
- Select a reason: Accepted risk, False positive, Not applicable, or Compensating control.
- Add a note explaining the decision and choose an expiry date.
- Submit the exception.
The finding page displays the recorded exception. Use the revoke action when the decision no longer applies, and review exceptions before they expire.
Accepting risk records a decision; it does not fix the resource or close the underlying finding. Keep any follow-up work in a linked task.