Every status value across controls, evidence, policies, risks, vendors, findings, audits, training, privacy, integrations, and jobs, with the label the app shows.
Each table lists the stored value, the label the app shows, what it means, and
who or what sets it. Stored values are what the REST API and MCP tools return
and accept in filters; labels are what you see in the UI.
The status picker offers the first five. planned, archived, and inferred
can appear on records but cannot be chosen by hand.
| Status | Meaning | Set by |
|---|
Not Implementednot_implemented | No work started; the control counts against coverage. | You, Cortex, or a sync (inferred) |
In Progressin_progress | Work is under way, or a link partially enabled the control. | You, Cortex, or the linking path |
Implementedimplemented | Operating and fully covered; counts toward coverage. | You, or the coverage check at 100 percent |
Pending Reviewpending_review | Needs a look. Set when coverage drops below 100 on an implemented control, or when linking fully enabled it. | Coverage check or linking path |
Not Applicablenot_applicable | Excluded from scope; ignored by coverage. | You |
Plannedplanned | Scheduled but not started. Not offered in the picker. | Sync or import |
Archivedarchived | Retired control kept for history. Not offered in the picker. | Framework change |
AI Inferredinferred | Status derived from evidence rather than asserted by a person. | Cortex or a sync |
| Status | Meaning | Set by |
|---|
Pending Reviewpending_review | Default on creation; does not count toward coverage until a person marks it valid. | You or a sync |
Validvalid | Accepted; counts toward every requirement it is linked to. | You |
Expiredexpired | No longer counts. Statistics also treat any row past its expiry date as expired, but only privacy evidence has its status rewritten automatically. | You; an automatic expiry check (privacy evidence only) |
| Status | Meaning | Set by |
|---|
Draftdraft | Being written; not shown to staff for acknowledgement. | You or Cortex |
Reviewreview | Waiting for the approver. | You |
Approvedapproved | Current version in force; counts toward linked controls. | The approver |
Archivedarchived | Retired; kept for history and no longer counts. | You |
Tasks have no status of their own. A task's status is the status of the
control, evidence item, policy, risk, or finding it points at, so the
values above and below are what you will see on the Tasks
page.
| Status | Meaning | Set by |
|---|
Identifiedidentified | Logged, not yet analysed. | You, Cortex, or a sync |
Assessingassessing | Likelihood and impact being scored. | You |
Mitigatingmitigating | Treatments in progress. | You |
Monitoringmonitoring | Treated; watching residual risk. | You |
Resolvedresolved | Closed; the risk no longer applies. | You |
Acceptedaccepted | Consciously accepted without further treatment. | You |
AI Inferredai_inferred | Proposed by Cortex or a privacy assessment and not yet confirmed by a person. | Cortex |
Likelihood values are rare, unlikely, possible, likely, certain;
impact values are negligible, minor, moderate, major, catastrophic.
Treatment types are avoid, transfer, mitigate, and accept.
| Status | Meaning | Set by |
|---|
Plannedplanned | Agreed, not started. | You or Cortex |
In Progressin_progress | Being carried out. | You |
Completedcompleted | Done; feeds residual risk. | You |
Cancelledcancelled | Abandoned. | You |
Severity is critical, high, medium, or low. Category is
identity_access (Identity Access), vulnerability, configuration,
compliance, or endpoint_posture (Endpoint Posture). Origin is manual or
integration_scan.
| Status | Meaning | Set by |
|---|
Openopen | Reported and unresolved. | You or a scanner sync |
In Progressin_progress | Being fixed. | You |
Resolvedresolved | Fixed; a re-scan may reopen it. | You or a scanner sync |
Acceptedaccepted | Risk accepted; stays visible. | You |
False Positivefalse_positive | Not a real issue. | You |
Certificates show expiry flags computed at scan time rather than a status. See Certificates.
| Status | Meaning | Set by |
|---|
Not Assessednot_assessed | No assessment recorded yet. | Default on creation |
In Progressin_progress | Questionnaire sent or review under way. | You or the automatic assessment |
Assessedassessed | Assessment complete for this cycle. | You or the automatic assessment |
| Status | Meaning | Set by |
|---|
Not Applicablenot_applicable | No personal data processed; no DPA needed. | You |
Not Requirednot_required | Personal data involved but a DPA is not required for this relationship. | You |
Pendingpending | A DPA is needed and not yet signed. | You |
In Placein_place | Signed DPA on file. | You |
Needs Reviewneeds_review | The DPA exists but something changed. | You or the automatic assessment |
Per-question review states are pending (Pending Review), approved,
needs_clarification (Needs Clarification), and rejected.
| Status | Meaning | Set by |
|---|
Pendingpending | Sent; the vendor has not opened it. | You |
In Progressin_progress | The vendor has started answering. | The vendor |
Submittedsubmitted | All answers in; waiting for your review. | The vendor |
Reviewedreviewed | You have reviewed every answer. | You |
Expiredexpired | The link lapsed before submission. | Automatic expiry |
| Status | Meaning | Set by |
|---|
Activeactive | Current member of staff. | You or an HR sync |
Inactiveinactive | Left or offboarded. | You or an HR sync |
Inconsistentinconsistent | Connected identity sources disagree about this person. | Directory reconciliation |
Deleteddeleted | Removed from the directory; kept for history. | You |
| Status | Meaning | Set by |
|---|
Draftdraft | Being set up; no campaigns run. | You |
Activeactive | Campaigns are generated from it. | You |
Archivedarchived | Retired. | You |
| Status | Meaning | Set by |
|---|
Upcomingupcoming | Scheduled; assignments not yet sent. | Plan schedule |
Activeactive | Assignments out; people can complete them. | Plan schedule |
Completedcompleted | The window closed. | Plan schedule or you |
Archivedarchived | Hidden from the list. | You |
Delivery of the assignment email is tracked separately from the assignment
itself, and an acknowledgement records whether it was given through an emailed
link or while signed in.
| Status | Meaning | Set by |
|---|
Pendingpending | Assigned; not opened. | Campaign |
In Progressin_progress | Opened; not finished. | The person |
Completedcompleted | Attested or recorded manually. | The person or you |
Overdueoverdue | Past the due date and not completed. | Automatic status update |
Cancelledcancelled | Withdrawn. | You |
Audit types are full, focused, and follow_up. The report inside an audit
is draft or finalized.
| Status | Meaning | Set by |
|---|
Draftplanned | Scoped; testing not started. | You |
In Progressin_progress | Controls being tested. | You |
Under Reviewreview | Testing done; report being reviewed. | You |
Finalisedcompleted | Report finalised; read-only. | You |
Cancelledcancelled | Abandoned. | You |
Finding types are non_conformity, observation, and opportunity;
severities are critical, major, and minor. Labels are shown in sentence
case.
| Status | Meaning | Set by |
|---|
Openopen | Raised; no remediation yet. | The auditor |
In remediationin_remediation | Being fixed. | You |
Closedclosed | Remediation reported complete. | You |
Verifiedverified | Closure confirmed by the auditor. | The auditor |
A data source is of kind datamap or ai_inventory.
| Status | Meaning | Set by |
|---|
Activeactive | Receiving pushes; its records are current. | Ingestion |
Stalestale | No push for longer than expected. | Staleness check |
Archivedarchived | Retired; records kept. | You |
Source is derived (materialised from a manifest) or manual.
| Status | Meaning | Set by |
|---|
Derivedderived | Materialised from a pushed manifest and not yet reviewed. | Ingestion |
In reviewin_review | Being completed or checked by a person. | You |
Approvedapproved | Confirmed; appears in the RoPA. | You |
Outcomes are proceed, proceed_with_mitigations, consult_authority, and
abandoned. Triggers are new_special_category, new_cross_border,
signal_based, and manual.
| Status | Meaning | Set by |
|---|
Openopen | Created; not started. | You or a trigger |
In progressin_progress | Being filled in. | You |
Completedcompleted | Outcome recorded. | You |
| Status | Meaning | Set by |
|---|
Openopen | A scan or connector disagrees with the approved record. | Drift detector |
Confirmedconfirmed | You agreed the record must change. | You |
Dismisseddismissed | Not a real change. | You |
Resolvedresolved | The record was updated. | You |
| Status | Meaning | Set by |
|---|
Suggestedsuggested | Cortex proposed a value; nothing changed yet. | Cortex |
Acceptedaccepted | Applied to the record. | You |
Dismisseddismissed | Rejected. | You |
| Status | Meaning | Set by |
|---|
Activeactive | Monitor scans on schedule. | You |
Pausedpaused | Monitor kept; no scans. | You |
Pendingpending | Scan queued. | Noru |
Runningrunning | Scan in progress. | Noru |
Completedcompleted | Scan finished; results stored. | Noru |
Failedfailed | Scan could not finish. | Noru |
Sync log entries are success, error, partial, or in_progress.
| Status | Meaning | Set by |
|---|
Connectedconnected | Credentials valid; syncs run on schedule. | Sync |
Syncingsyncing | A sync is running now. | Sync |
Errorerror | The last sync failed; check the log. | Sync |
Disconnecteddisconnected | Credentials removed or revoked; no syncs. | You or the provider |
Priority is low, normal, high, or urgent. The app shows progress
phrases such as "Processing..." and "Retrying..." rather than raw values.
| Status | Meaning | Set by |
|---|
Pendingpending | Queued; not started yet. | Noru |
Runningrunning | In progress now. | Noru |
Retrying...retrying | Failed once; will run again automatically. | Noru |
Completedcompleted | Finished. | Noru |
Failedfailed | Gave up after retrying. | Noru |
Cancelledcancelled | Stopped before completion. | You or Noru |