Choose the right response
Viewing detected risks requires the relevant finding access; formal acceptance requires
detection.write. Creating and changing roadmap items requires roadmap.write; creating a proposal from a detected risk additionally requires detection.read. Reading roadmap items requires roadmap.read. Available actions reflect your permissions.
Record a risk acceptance
Open the detected risk’s action menu and select Accept risk. Explain Why is this being accepted? and set Accepted until, then confirm. Both a reason and a future expiry are required. For example, a client might accept a supported finding temporarily while a replacement is scheduled. Record the agreed reason and review date; do not describe the acceptance as proof that the environment meets the control. Use Acceptance history to inspect earlier decisions. An acceptance can lapse. Review an expired acceptance rather than relying on an old approval indefinitely.Create a proposal from a finding
Select Create proposal from the detected risk’s action menu. Review the estimated cost and any target quarter. The new item remains linked to the source finding. If a proposal already exists, open it through the roadmap action instead of creating another. Creating a proposal does not accept or resolve the risk. Review the proposal before approving it; timing can remain unscheduled until a delivery quarter is agreed.Manage the roadmap
Use the client’s Roadmap to add a standalone item when planned work has no source detection. Enter its title, category, severity, unit cost in pounds, quantity, recurring term and target quarter where known. Edit an existing item to correct those details. Read the estimate as unit cost × quantity. For example, a fictional £100 unit cost with quantity three represents £300 for the selected term. One-off, monthly and annual costs are shown separately; they should not be read as one comparable annual total.
Use the item’s decision action to record its state and the requested decision note, and View history to inspect changes. Rejected and completed decisions require a note. A scheduled quarter is a plan, not proof that work happened.
The last step is essential: changing a roadmap state does not change the source result. An approved plan is also distinct from permission to execute a remediation action.
Client responses are separate
An authorised client can respond to a visible proposal through the client portal. That response records their approval or decline. It does not change the MSP’s internal roadmap approval or execute the work.If a decision is blocked or unclear
- Confirm the client, current finding and any existing roadmap link.
- If an acceptance is rejected, check the reason and future expiry.
- If a roadmap change is rejected, inspect the current item and required fields or decision note before retrying.
- If the estate view reports incomplete or stale data, refresh the failed client data before treating its totals as complete.
- After delivery, reassess the source evidence instead of expecting the risk to disappear when the work is marked completed.