Risk acceptance
Document justified AI agent risk acceptance
Some access is necessary for an agent to do its job. Accepting that risk should create a reviewable decision, not remove the finding.
The problem: exceptions become permanent by accident
A team agrees that an agent may access source code or customer messages, but the reasoning remains in a meeting note. Months later, nobody knows who accepted the exposure or whether the need still exists.
Roxea treats acceptance as a time-bound record attached to the specific finding.
How risk acceptance works in Roxea
On Pro and Business, an owner or admin adds a justification and future expiry date. The responsible user and acceptance date are recorded. The finding stays visible and the raw score does not change.
- Require a written business justification.
- Record who accepted the risk.
- Set a mandatory future expiry date.
- Prevent duplicate active acceptance for the same risk.
- Revoke the acceptance when circumstances change.
- Include accepted risks in relevant reports.
Example: repository read access
A pull-request assistant needs read-only access to private repositories to summarise changes. The engineering owner records that purpose and accepts the finding for ninety days while the team evaluates a narrower repository scope.
FAQ
Questions people ask before a review
Record the reason when a risk cannot be removed.
Keep the finding visible and give every exception a responsible person and review date.