Action Items
Once you're onboarded, this is where the remediation work lives. Action items are tasks — generated by AI from your findings or created manually by your team — that you track from creation to completion.
How Action Items Are Created
AI-Generated (Action Review)
QuantAssure queues potential actions whenever something happens that may warrant remediation work:
- New findings detected by a scan
- Findings approaching or breaching their SLA deadline
- Policies due for scheduled review
- Threat intelligence advisories affecting your systems
An AI review agent evaluates the queue and decides whether each trigger warrants an action item — considering AI-adjusted severity, system criticality, and compliance impact. Warranted triggers become prioritised action items with a rationale; dismissed triggers are recorded in the audit trail, so nothing disappears silently.
Manual
- Create action items from the Action Items page
- Link to specific findings, policies, or compliance controls
- Useful for tasks not tied to a specific finding
Managing Action Items
Viewing
- Navigate to Action Items
- Filter by status (Open, In Progress, Blocked, Resolved, Closed) or priority
- Sort by created date, updated date, due date, or priority
Assigning
- Assign action items to team members
- Set due dates for accountability
- Assignees see their items on the dashboard
Updating Status
- Open → In Progress → Resolved → Closed
- Mark items Blocked while waiting on something external
- Add comments on the detail page as you work
- Cancel items that are no longer relevant
Priority Levels
| Priority | Use when |
|---|---|
| Critical | Immediate action required — active exploitation risk |
| High | Address within days — significant security gap |
| Medium | Address within weeks — moderate risk |
| Low | Address when convenient — minimal risk |
Compliance Linkage
- Action items linked to findings appear on the ISM control pages those findings map to
- Completing actions improves your compliance readiness
- Action items can also link to systems, policies, and compliance targets