devguard

Tasks

Tasks are the concrete units of work that move your compliance program forward. Track what needs to be done, who owns it, and when it is due across every framework, control, and record.

Overview

The Tasks module is your single worklist for everything that needs doing to reach and stay audit ready. A task is a discrete unit of work with an owner, a due date, and a status, so nothing falls through the cracks between adopting a framework and passing the audit.

Tasks arrive in two ways: they are seeded automatically when you adopt a framework (cloned from that framework's task templates and linked to the relevant controls), and they can be created manually at any time, either from the worklist or directly from a record you are working on.

Tasks feed the Roadmap, where their deadlines are laid out on a timeline so you can see what needs to happen by when.

The Worklist

The Tasks page lists every task in your organization as a filterable table. Each row links through to the task's detail view.

ColumnDescription
IDStable short identifier, e.g. TSK-001
TitleWhat the task is
FrameworkThe framework the task belongs to (via its template or linked control)
StatusTo do, In progress, In review, Done, or Cancelled
PriorityLow, Medium, High, or Urgent
DueThe deadline; overdue dates are flagged in red
TypeGeneric, or a typed task derived from a linked record
AssigneeThe role or person responsible

Use the filters to narrow the list by framework, status, or assignee, so each owner can focus on their own open work.

Task Fields

FieldDescriptionExample
TitleA short, descriptive name (required)Document the backup procedure
SlugUnique identifier used in URLs and the API (required)document-the-backup-procedure
DescriptionAdditional context or instructionsCover frequency, retention, restore tests
PriorityHow urgently the task needs attentionLow, Medium, High, Urgent
DeadlineWhen the task is due (drives the Roadmap)31.12.2025
AssigneeThe role or person responsibleSecurity Team
Relates toA single linked record (see below)A.5.1 Policies for information security

Assignee

A task can be assigned to a business role or to an individual member. Assigning to a role keeps ownership stable as people change positions, while assigning to a person is useful for one-off work. A person's own tasks — assigned directly or through a role they hold — are listed on the Tasks tab of their People profile.

Relates to

A task can be attached to at most one record: a control, risk, policy, evidence, asset, vendor, or audit. The attachment is shown on the task detail page and in the Roadmap, and it lets you jump straight from the work item to the thing it is about. You set it when creating a task, or the attachment is filled in for you when you add a task from a record's own Tasks tab.

Status

Task status reflects where the work stands:

  • To do — not started
  • In progress — actively being worked on
  • In review — done and awaiting sign-off
  • Done — complete
  • Cancelled — no longer needed

For most tasks you set the status yourself. Typed tasks that are linked to a policy or a piece of evidence instead derive their status from that record — for example, a policy task shows as Done once its policy is published — so the worklist always reflects the real state of the underlying artifact without double bookkeeping.

Creating Tasks from Records

Beyond the worklist, you can add a task directly from the record you are working on. Every Control, Risk, Policy, Evidence, Asset, Vendor, and Audit detail view has a Tasks tab with an Add task button. Tasks created there are automatically attached to that record, so you never have to re-select it. The same tab on a People profile pre-assigns the new task to that person.

AI Guidance

Not sure how to complete a task? Open the AI Assistant from the task detail page with the task attached as context, and ask how to approach it. The assistant can draft a plan, point you at the relevant controls or policies, and help you get unblocked without leaving the record. See the AI Assistant documentation for more.

Best Practices

  • Assign an owner to every task. Prefer a role over a person so ownership survives staffing changes.
  • Set realistic deadlines. Task deadlines drive the Roadmap; use Plan a roadmap to spread a framework's open tasks toward a target date instead of dating them one by one.
  • Keep statuses honest. A worklist is only useful if it reflects reality — update statuses as work moves, and let typed tasks track their linked records automatically.
  • Work from records, not just the list. When you are in a control, risk, or asset, add follow-up tasks from its Tasks tab so they stay linked to their context.

How is this guide?

On this page