Workflows

Findings, saved views, and ownership

Inspect reviewed impact, save useful finding filters, preview repository ownership rules, and follow assignment history.

Start from a reviewed finding in the Impact queue. Open its consequence, source references, and root-cause context before deciding who should act. Scanner observations and dependency alerts with unverified architectural applicability remain evidence to review.

Keep useful views

Filter the findings to the team, owner, severity, state, or scope you need, then choose Save finding view. Give the view a clear name and choose personal or workspace visibility where your role permits it.

A saved view stores the query configuration. Opening it applies those filters to current authorized findings; it does not freeze the findings themselves. Renaming, updating, or deleting a view follows its ownership and workspace permissions.

Assign a finding

Choose an eligible workspace member in the finding's owner control. The assignment appears with the finding and is recorded in history. A manually chosen owner takes precedence when automatic routing is applied.

Use the root-cause and inventory guide when several findings appear to describe the same structural issue. Coordinating the cause can avoid assigning several disconnected fixes.

Preview ownership routing

  1. Open Ownership routing and configure a routing policy for the workspace.
  2. Map provider identities from CODEOWNERS to actual workspace members. Unmapped owners do not become new workspace users.
  3. Set default deadlines and any supported overrides. Deadlines are calculated from the finding's first observation; rerunning routing does not reset the clock.
  4. Save the policy, choose the relevant audit, and select Preview assignments.
  5. Inspect matched rules, proposed owners, deadlines, unmatched identities, and warnings. Apply the preview only when it matches the intended responsibility.

Unsupported CODEOWNERS syntax and unresolved identities remain visible. Do not assume every provider rule can be applied identically. Preview the effective result, especially for nested paths and overlapping rules.

Track overdue work

If escalation is enabled, select an eligible escalation recipient and review the configured policy. Assignment history records routing and escalation decisions. Notifications depend on the workspace's configured delivery channel; a recorded decision alone is not proof that an external message was delivered.

Use the workspace portfolio to find unassigned and overdue findings across the workspaces you can access.

Was this guide useful?

Your response stays in this browser unless you open a GitHub issue.
View source