Findings
A finding is a documented gap — something an assessment showed isn't fully in place. Findings are how you track what needs fixing and prove to an auditor that you're managing it.
Where findings come from
- Generated automatically when you complete an assessment: every question answered No or Partial becomes an open finding, carrying its risk level and the requirement it relates to.
- Created manually for gaps you discover outside an assessment (use **Create finding**).
A generated finding links back to its source assessment — open it to see the exact question and your answer.
Working a finding
- Risk level (critical → informational) drives prioritization.
- Status: open → in progress → resolved (or accepted as risk / false positive). Set a risk treatment (mitigate / accept / transfer / avoid) to record your decision.
- Assign a finding to a teammate; they're notified.
- Evidence: attach the artifacts that prove the gap is closed.
- Remediation tasks: break the fix into tracked tasks — see the Remediation tasks panel on the finding. Watney can draft them for you.
Tips
- Resolve a finding only when you have evidence the control is implemented and operating — that's what an auditor checks.
- The compliance score weights open findings heavily, so closing them is the fastest way to raise your posture.
Sorting the list
Click a column header to sort the register by that column; click again to reverse it. The sort is applied on the server, so it orders the whole register — not just the rows on the current page — and it is kept when you page through the results or change a filter. The active column shows an arrow, and screen readers announce it through the header's aria-sort state. Twelve of the fifteen register lists sort on the server this way; the evidence, remediation and vendor lists still sort the rows currently displayed.