Tasks
Tasks are the concrete units of work that move your compliance program forward. Track what needs to be done, who owns it, and when it is due across every framework, control, and record.
Overview
The Tasks module is your single worklist for everything that needs doing to reach and stay audit ready. A task is a discrete unit of work with an owner, a due date, and a status, so nothing falls through the cracks between adopting a framework and passing the audit.
Tasks arrive in two ways: they are seeded automatically when you adopt a framework (cloned from that framework's task templates and linked to the relevant controls), and they can be created manually at any time, either from the worklist or directly from a record you are working on.
Tasks feed the Roadmap, where their deadlines are laid out on a timeline so you can see what needs to happen by when.
The Worklist
The Tasks page lists every task in your organization as a filterable table. Each row links through to the task's detail view.
| Column | Description |
|---|---|
ID | Stable short identifier, e.g. TSK-001 |
Title | What the task is |
Framework | The framework the task belongs to (via its template or linked control) |
Status | To do, In progress, In review, Done, or Cancelled |
Priority | Low, Medium, High, or Urgent |
Due | The deadline; overdue dates are flagged in red |
Type | Generic, or a typed task derived from a linked record |
Assignee | The role or person responsible |
Use the filters to narrow the list by framework, status, or assignee, so each owner can focus on their own open work.
Task Fields
| Field | Description | Example |
|---|---|---|
Title | A short, descriptive name (required) | Document the backup procedure |
Slug | Unique identifier used in URLs and the API (required) | document-the-backup-procedure |
Description | Additional context or instructions | Cover frequency, retention, restore tests |
Priority | How urgently the task needs attention | Low, Medium, High, Urgent |
Deadline | When the task is due (drives the Roadmap) | 31.12.2025 |
Assignee | The role or person responsible | Security Team |
Relates to | A single linked record (see below) | A.5.1 Policies for information security |
Assignee
A task can be assigned to a business role or to an individual member. Assigning to a role keeps ownership stable as people change positions, while assigning to a person is useful for one-off work. A person's own tasks — assigned directly or through a role they hold — are listed on the Tasks tab of their People profile.
Relates to
A task can be attached to at most one record: a control, risk, policy, evidence, asset, vendor, or audit. The attachment is shown on the task detail page and in the Roadmap, and it lets you jump straight from the work item to the thing it is about. You set it when creating a task, or the attachment is filled in for you when you add a task from a record's own Tasks tab.
Status
Task status reflects where the work stands:
- To do — not started
- In progress — actively being worked on
- In review — done and awaiting sign-off
- Done — complete
- Cancelled — no longer needed
For most tasks you set the status yourself. Typed tasks that are linked to a policy or a piece of evidence instead derive their status from that record — for example, a policy task shows as Done once its policy is published — so the worklist always reflects the real state of the underlying artifact without double bookkeeping.
Creating Tasks from Records
Beyond the worklist, you can add a task directly from the record you are working on. Every Control, Risk, Policy, Evidence, Asset, Vendor, and Audit detail view has a Tasks tab with an Add task button. Tasks created there are automatically attached to that record, so you never have to re-select it. The same tab on a People profile pre-assigns the new task to that person.
AI Guidance
Not sure how to complete a task? Open the AI Assistant from the task detail page with the task attached as context, and ask how to approach it. The assistant can draft a plan, point you at the relevant controls or policies, and help you get unblocked without leaving the record. See the AI Assistant documentation for more.
Best Practices
- Assign an owner to every task. Prefer a role over a person so ownership survives staffing changes.
- Set realistic deadlines. Task deadlines drive the Roadmap; use Plan a roadmap to spread a framework's open tasks toward a target date instead of dating them one by one.
- Keep statuses honest. A worklist is only useful if it reflects reality — update statuses as work moves, and let typed tasks track their linked records automatically.
- Work from records, not just the list. When you are in a control, risk, or asset, add follow-up tasks from its Tasks tab so they stay linked to their context.
How is this guide?
Incidents
Record and manage security and data incidents from detection through to closure — track severity, build a timeline, link the assets, risks and vendors involved, and manage GDPR breach-notification deadlines.
Actions
Automate recurring procedures and routine tasks to maintain compliance and oversight, enabling you to trigger tickets and notifications that keep your controls and policies actively enforced. Manage all connected integrations from the Integrations page.