{"description":"Runs on the existing issue item. Substantiate a reported issue, assess its severity and cause, select a governed disposition, and approve the triage record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-issue-assessment-issue-triage-closure","source":"issue-assessment","target":"issue-triage-closure"}],"isPublic":true,"itemTypeSlug":"issue","metadata":{"capabilities":["issue-triage-disposition"],"controlVerbs":{"UC-RISK-14":"operates"},"controls":["UC-RISK-14"],"department":"risk-management","domains":["grc"],"kind":"issue-triage-disposition","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:issue-triage-disposition"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-issue-triage-disposition","contentDigest":"sha256:d9b811ef61181c1a3b0c6d4394b65b28259bc28a00192820c9502c0d2ffb73b7","prerequisites":{"anchorItemType":{"slug":"issue"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-issue-remediation-verification"}],"roles":[{"contribution":"expertise","description":"Issue assessment specialist. Assess severity and cause.","id":"reviewer-1","nodeIds":["issue-assessment"]},{"contribution":"approval","description":"Issue disposition authority. Approve issue triage record.","id":"reviewer-2","nodeIds":["issue-triage-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:issue-triage-disposition"}],"releaseId":"sha256:d9b811ef61181c1a3b0c6d4394b65b28259bc28a00192820c9502c0d2ffb73b7","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-issue-triage-disposition"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-issue-triage-disposition","source":"coworkcanvas-gallery","standards":[],"teams":["risk-management"]},"name":"Issue Triage & Disposition","nodes":[{"data":{"instructions":"**Objective**\nAssess severity and cause. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Issue item, source report, exception evidence, incident or complaint records, audit work, policies, requirements, controls, affected transactions, prior issues, and reporter representations.\n2. Use the substantiated condition, affected population, severity criteria, loss or exposure data, control results, related risks, issue history, process and system changes, management responses, and specialist input.\n\n**Procedure**\n1. Validate the reported condition against source evidence, distinguish symptoms from the underlying problem, identify applicable criteria, bound the affected population and period, remove duplicates, and initiate urgent containment when warranted.\n2. Apply the approved severity rubric, quantify or bound exposure, analyze recurrence and aggregation, test proposed causes using evidence, distinguish causal factors from symptoms, and identify uncertainty that could change priority or reporting.\n\n**Record in AssureSwarm**\n1. Capture intake source, issue statement, condition, criteria, affected items and period, reporter, accountable owner, duplicate analysis, immediate safeguards, evidence references, and unresolved questions.\n2. Document severity and rationale, actual and potential impact, affected stakeholders, pervasiveness, recurrence, root cause status and evidence, compensating measures, related issues, and data limitations. Also record severity basis.\n\n**Exit criteria**\nIssue assessment specialist provides expertise: The issue is sufficiently substantiated for assessment, duplicates and unsupported allegations are handled transparently, and urgent exposure has an assigned containment response. The severity and causal analysis are reproducible, contrary evidence is retained, and uncertainties or escalation conditions are explicit before disposition.","kind":"task","label":"Assess severity and cause","requiredApprovals":1},"id":"issue-assessment"},{"data":{"controls":["UC-RISK-14"],"instructions":"**Objective**\nApprove issue triage record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, remediation feasibility, exception authority, duplicate analysis, legal or regulatory advice, reporting thresholds, stakeholder responses, and proposed ownership and dates.\n2. Review every stage result, source evidence, assessment support, approvals, remediation or exception links, reporting confirmations, management responses, and unresolved information requests.\n\n**Procedure**\n1. Compare remediation, exception, monitoring, merge, and unsubstantiated closure paths; verify decision authority; define reporting and escalation; create required linked actions; and prevent administrative closure from concealing unresolved exposure.\n2. Trace the issue statement and severity to support, verify the disposition and approver authority, reconcile owners and dates across linked records, retain contrary evidence, and return unsupported or inconsistent work for correction.\n\n**Record in AssureSwarm**\n1. Record the disposition, rationale, authorized approver, linked remediation or exception, reporting route, owner, target date, monitoring trigger, merged issue reference, and conditions for reconsideration.\n2. Capture the authorized reviewer, triage summary, final severity and disposition, linked remediation or exception references, reporting status, responsible owners, due dates, and remaining limitations. Also record issue triage summary.\n\n**Exit criteria**\nIssue disposition authority provides approval: An approver accepts that the disposition is authorized and evidence-based, required actions and reporting are linked, and unresolved exposure remains visible. The authorized reviewer accepts the triage record as a traceable account of work and decisions, downstream records can proceed consistently, and closure is not represented as assurance.","kind":"task","label":"Approve issue triage record","requiredApprovals":1},"id":"issue-triage-closure"}],"sourceTemplateId":"workflow-library:grc-issue-triage-disposition"}
