Risk acceptance

Document justified AI agent risk acceptance

Some access is necessary for an agent to do its job. Accepting that risk should create a reviewable decision, not remove the finding.

01

The problem: exceptions become permanent by accident

A team agrees that an agent may access source code or customer messages, but the reasoning remains in a meeting note. Months later, nobody knows who accepted the exposure or whether the need still exists.

Roxea treats acceptance as a time-bound record attached to the specific finding.

02

How risk acceptance works in Roxea

On Pro and Business, an owner or admin adds a justification and future expiry date. The responsible user and acceptance date are recorded. The finding stays visible and the raw score does not change.

  • Require a written business justification.
  • Record who accepted the risk.
  • Set a mandatory future expiry date.
  • Prevent duplicate active acceptance for the same risk.
  • Revoke the acceptance when circumstances change.
  • Include accepted risks in relevant reports.
03

Example: repository read access

A pull-request assistant needs read-only access to private repositories to summarise changes. The engineering owner records that purpose and accepts the finding for ninety days while the team evaluates a narrower repository scope.

FAQ

Questions people ask before a review

Record the reason when a risk cannot be removed.

Keep the finding visible and give every exception a responsible person and review date.

Start an agent audit