Creating Risks
Click New Risk at the top of the Risk Manager page to open the New Risk dialog. It has two tabs: Create manually and Import from file.
Create Manually
- Assets — the asset(s) this risk applies to. At least one asset must exist in Asset Manager before you can create a risk. The first asset you pick becomes the primary asset; you can select more than one, and add or remove assets later from Risk Details.
- Heading — a short title for the risk. Optional at this point — you can add or change it later.
- Priority, Status, and Assignee — set these up front if you already know them, or leave them as-is and set them later from Risk Details.
Evidence (optional)
Below the fields above, click Add evidence to open the evidence section — it’s collapsed by default so a quick risk (heading and asset only) doesn’t feel like a long form. Attaching evidence here is exactly the same as adding it later on the Evidence card, it just saves a trip back to the risk once it’s created:
| Field | Description |
|---|---|
| Source | Manual, Design, Test, or Monitor — where this finding came from. Defaults to Manual |
| Reference | A CVE number, report id, or other external identifier |
| Summary | A short description of the finding |
| CVSS score | 0–10; feeds the risk’s Likelihood and Impact |
| Weakness state | The ISO/SAE 21434 Clause-8 state — Event, Weakness, Vulnerability, or Not Applicable. Marking Not Applicable requires a Rationale |
| Attachments | Attach one or more files to this evidence item — click Attach files |
If you record evidence with source Design, Test, or Monitor, that source becomes the new risk’s origin (see Risk Origins). Leaving evidence out — or recording it as Manual — leaves the risk without an origin, shown as — until later evidence sets one.
Once you click Create risk, the new risk is created in Triage and the app opens its Risk Details page immediately so you can continue filling it in.
Import from File
Switch to the Import from file tab for bulk or automated intake from an Excel workbook:
- Asset — a single asset (import only ever targets one).
- Risk type — only Design can be selected; Test and Monitor are disabled because the importer only understands Design-shaped workbooks.
- Risk file — an .xlsx workbook. See Import & Export for the required sheet and column layout.
Imported risks are created with the Design origin directly — there’s no evidence step here, since the workbook’s threat-model data (threat scenarios, attack paths, damage scenarios) is what feeds the score.
After Creation
From Risk Details:
- Accept the risk to move it from Triage to Open.
- Archive to set it aside (reversible from any state).
- Click Edit (top right) to open the Edit risk dialog — change the Heading, Priority, or Status, then Save (or Cancel).
- Use the Context tab to let the AI curate an understanding of the risk and propose field updates or suggested actions.