Workflows

Approve and share a report

Review the exact source context, export approved content, and manage expiring report snapshots and reviewer comments.

A report should make its conclusion and its limits easy to understand. Before approval, check the repository, branch, commit, assessed paths, profile version, findings, and coverage gaps. Historical reports may lack some source metadata; those fields remain unknown rather than being invented.

Review the report content

Open the audit report and select the sections and findings that belong in the deliverable. Inspect the preview, including long findings and references, and approve the intended revision with an authorized reviewer.

A restricted path scope remains visible even if you omit the optional coverage section. Changing the report content requires a fresh review and approval. The canonical report revision is the source for its rendered exports; see report formats.

Create an external review

  1. Open Report review links for the approved report.
  2. Select the approved sections and findings to share. Review text redactions and decide whether locations and other optional context should be included.
  3. Preview the content, choose an expiry, and decide whether reviewers may comment.
  4. Create the link and copy the newly issued URL.
  5. Inspect Snapshot and review history to review access records and comments.

The link grants access to its selected snapshot to anyone who holds it. Share it with the intended recipients. It exposes neither the entire workspace nor future report changes. The content is frozen at creation, and later edits cannot silently broaden it.

Comments are plain text and belong to that review. They do not modify the canonical report or approve remediation.

Revoke a link from its history view when it is no longer needed. Expired, revoked, and invalid links cannot open the snapshot. Revocation prevents future access; it cannot remove a copy a recipient already downloaded.

To share a changed report, review and approve the new content, then create a new link. The earlier snapshot remains part of its own history.

Resolve common report problems

SymptomCheck
Approval or sharing is unavailableConfirm your role, the current report revision, and whether the selected content has been approved
A section or finding is absentInspect the report builder's selection and the review link's separate content selection
A report appears cleaner than expectedCheck scope restrictions, collection failures, and evidence-gated exclusions before interpreting the finding count
An export failsRetry that format and retain the error reference; a format failure does not require discarding the audit
A reviewer cannot reopen a linkCheck expiry or revocation and create a new approved snapshot if appropriate

For customer questionnaires, reuse the approved report through the questionnaire workflow.

Was this guide useful?

Your response stays in this browser unless you open a GitHub issue.
View source