Confirm risk accepted, false positive and remediated issues with the Issue Review feature
Overview
The Issue Review feature adds a peer-approval step before an issue’s status change to Active, False Positive, Remediated, or Risk Accepted takes effect. Instead of a status change applying immediately, it becomes a request that a designated reviewer must approve. This gives administrators oversight of changes that affect the organization’s Hackability Score, while still allowing issues to close automatically when a vulnerability is no longer detected in a rescan or data ingestion.
Issue Review is configured per organization in Settings, and — once enabled — every relevant status change becomes a request that is tracked on the new Requests page.
1. Enable and configure Issue Review
The activation of this feature can only be done by users with the Organization Owner role.
Required role: Admin or Owner. General Users cannot change this configuration.
1 – Go to Settings in the left-hand navigation.
2 – Under the FEATURES group, select Issue review.
3 – Under Required Issue Reviews, tick the checkboxes for the issue statuses that should require reviewer approval before they take effect: Active, False Positive, Remediated, and/or Risk Accepted.
4 – Optionally, tick the checkboxes on the right to limit review requirements to specific issue severities: Critical, High, Medium, and/or Low.
5 – Click Update to save the configuration.

Note: Issue Review is off while both lists (statuses and severities) are empty. Leaving a list empty otherwise means “include everything”: if no status is selected, every status change requires review; if no severity is selected, every severity is included.
On the same page, under Issue review notifications, choose how you and reviewers are kept informed:
- Real-time notifications — send an email immediately when a request you submitted is reviewed, and/or when a new request is assigned to you as reviewer.
- Periodic reminders — toggle Receive summary email to get a periodic digest of pending requests and requests you created.
Click Update again after changing notification preferences.
3. Request an issue status change
Once Issue Review is enabled for a status, changing an issue to that status no longer applies immediately — it opens a request instead. This applies wherever issue status can be changed, including the Issues list, an issue’s detail page, and a workout’s Assets panel.

1 – Go to Issues in the left-hand navigation.
2- Select one or more issues using the row checkboxes (or use Select the first 1,000 issues to select in bulk).
3 – Click the Mark issue as dropdown that appears in the bulk action bar.
4 – Choose the target status: Active, Risk accepted, Remediated, or False positive.
Note: Upon selecting Risk accepted as the status, you need to add deadline information.
5 – If that status requires review, a Request issue status change panel opens on the right. If it does not require review, the status changes immediately with no further steps.
In the Request issue status change panel, complete the following fields:
- Enter a reason for your request — required, up to 1,000 characters. Briefly explain why you’re making the request.
- Choose a person to review — required. Select the teammate who should approve or reject the request from the Select a reviewer dropdown.
- Set the deadline (shown for Risk accepted requests) — choose No deadline, or Set deadline to pick a date after which the issue is automatically reopened. You’ll receive an email reminder a week before the deadline.
6 – Click Save to submit the request, or Cancel to discard it.
Note: The issue’s status does not change until the reviewer approves the request. The reviewer is notified by email and can approve or reject it from the Requests page. A request is not created if the issue’s current status already matches the requested one.
3. Track and review requests
All review requests — the ones assigned to you to decide on, the ones you’ve submitted, and the full history — live on the Requests page, organized into three tabs.
| Tab | Who sees what | Available actions |
| Pending review | Requests where you are the assigned reviewer. | Approve or Reject each request. |
| Open | Requests you submitted that are still awaiting a decision. | Read-only, except you can Cancel a request before it’s reviewed. |
| Closed | All requests that have been decided (Admins see the full organization history; General Users see only their own). | Review history: requested status, requested by, reviewer, outcome, notes, and dates. Use Columns to show additional fields such as Risk accepted deadline. |
Approve or reject a request
1 – Go to Requests > Pending review.
2 – Locate the request by asset or issue.
3 – Click Approve to accept the requested status change, or Reject to decline it.
Note: Four-eyes principle: you cannot review your own requests — a different Admin or Owner must act as reviewer. This is why your own submissions never appear under Pending review, only under Open.
Cancel a request you submitted
- Go to Requests > Open.
- Locate the request you submitted.
- Click Cancel to withdraw it before a reviewer decides.
4. Manage notifications for issue review
Notification preferences live alongside the Issue Review configuration, at Settings > Issue review:
- Real-time notifications — email immediately when a request you submitted is reviewed, or when a new request is assigned to you.
- Periodic reminders — a periodic summary email of pending requests and requests you created (toggle Receive summary email).
Adjust the checkboxes as needed and click Update.