Risk Acceptance
Risk acceptance records tenant-managed accepted-risk models, source-linked requests, authority decisions, expiry, renewal, revocation, and supersession evidence. It is framework-neutral: teams define their own scope, appetite, tolerance, authority, and expiry policy snapshots instead of relying on built-in regulatory labels.
Use it when a governance source needs a formal accepted-risk decision rather than a local note. The request stores sanitized references and decision snapshots only; raw evidence, source text, prompts, vectors, provider payloads, secrets, and storage keys must stay in the owning source systems.
Operating Model
- Create active acceptance models for reusable authority and expiry policy shapes.
- Create requests against module-owned source references.
- Review requests through actor-derived authority checks; the approver is resolved from the authenticated member, not from submitted payload fields.
- Approve with an expiry or an explicit no-expiry policy decision.
- Renew, revoke, expire, or supersede accepted requests as the risk changes.
Integration Posture
Risk acceptance contributes module-owned permissions, navigation, audit projection, Activity presentation, work-item descriptors, compliance-posture signals, and audit-package export descriptors. Cloud and on-prem deployments expose the same console and organization API route surface.