Promote from signals
The register's second intake is automatic. When another part of the platform observes something risk-shaped, it emits a risk signal, and the signals land in a triage queue on the Signals tab. A badge on the tab shows how many are waiting.
Where signals come from
Each signal card names its type, and the types map to the platform's observation surfaces:
- Finding — from a vendor assessment in TPRM.
- Assessment gap — a gap identified in a compliance assessment.
- Control failure — a control detected as failing.
- External signal — threat intelligence, news, or OSINT drift collected by continuous vendor monitoring.
- Questionnaire response — a risk surfaced by an answer.
- Evidence gap — evidence that is missing or has expired.
- Manual entry and AI detected — signals raised by a person or flagged by the platform's own analysis.
Alongside its type, a signal carries its origin (system, user, AI, or external), a severity, a confidence score, and a reference back to the source record in the module that raised it.
Triaging the queue
Each signal offers three moves:
- Correlate. SolveGRC looks for an existing risk the signal belongs to. A strong match links the signal to that risk automatically; a weaker one queues the candidates for you to confirm.
- Link to risk. Attach the signal to a register entry you choose.
- Create risk. Promote the signal into a new register entry, pre-filled from the signal's classification and severity.
Linking rather than always creating matters: five signals pointing at one risk is a sharper register than five near-duplicate risks.
Escalations from other modules
You do not have to wait for the queue. Vendor pages and findings in TPRM carry an Escalate to Risk action, and framework and assessment views offer the same for control gaps. The escalation dialog opens pre-filled with the source's severity and suggested domain, and lets you adjust both before it emits the signal. High-severity vendor findings can emit their signal automatically.
Cloud posture has its own bridge: fused cloud findings can be promoted directly into register entries, one per cloud asset, with dollar inputs derived from your business-impact analysis — and re-promoting the same asset updates its existing risk rather than duplicating it. Promoted cloud risks run through the same simulation engine as every other quantified risk.
What provenance travels with a promoted risk
Open a promoted risk and its Signals tab lists every signal linked to it: the signal's type, severity, correlation score, source module, source reference, and whether it has been processed. A risk escalated from a framework gap or an assessment also arrives with its affected controls already mapped. The register records not just that the risk exists, but why.
Once a risk is on the register, the next question is what it costs. Continue to Quantify in dollars.