Deciding on an approval request, item by item¶
Work your AI submits together arrives as one request. You decide on each item, and the request lands on your last decision.
When your AI finishes a piece of work, it rarely produces just one thing. Asking for your control set, for example, can produce policies, the procedures under them, the controls themselves, and the links that show which control covers which requirement. Everything your AI submits together arrives as one approval request: one list of items, one link, one clock. A very large submission arrives as more than one request.
You decide on each item in that request on its own. This article explains what you can do with each item, when the request lands on your record, and what changes when you are the only person in your workspace.
This works the same way for every framework Kanonik supports.
Where you decide¶
You can decide on a request in two places:
- Needs you, in the dashboard. It lists what is waiting on you in the workspace you have open. If you belong to more than one workspace, switch workspace to see its items. You work down the items one at a time: the main button on each item reads "Approve and next" (or "Accept and next") until the last item.
- The emailed link. You may also receive the request as a link. It opens the same request and switches you into the right workspace. There you tick each item you have reviewed, then one button approves or accepts all the ticked items together. You can also send back or reject an item from the emailed page.
The link is emailed only to the person who asked for the change, at the address on their sign-in account, and only once that address is verified. Nobody else in the workspace is emailed, and the owner is not a fallback. If the address is not verified, or the sign-in service cannot be reached when the request is made, no email is sent. The request is still made and waits in Needs you, where an admin can see it.
Some things happen only in Needs you. An item that was accepted and is waiting to be sealed, whether by a colleague as the second person or by you in a one-person workspace, is sealed in Needs you. The emailed page tells you so.
What you do in one place shows in the other. If you tick an item on the emailed page and then open Needs you, the tick is already there.
What you can do with each item¶
Open an item to read it: the record itself, what the safety check concluded, and how the draft was prepared. Then choose one of these:
- Approve. Tick "I have reviewed this record", then approve. The button stays unavailable until you tick; there is no shortcut.
- Accept. In a workspace with two or more people, some items need a second person (see below). For those, your click is Accept: you take responsibility for what your AI prepared, and the item waits for a colleague to seal it.
- Send back. You want a change. Say what is wrong, in your own words. Your AI revises the item, the revision is checked again, and it comes back to you as a new decision. Send back is offered for drafts your AI can revise in place, such as policies, procedures, controls, assets, vendors and risks.
- Reject. You do not want this item at all. It is discarded and will never land. For an item that cannot be sent back, reject it and ask your AI for a new version.
Send back and reject both need a reason. The reason is kept with the item.
If the safety check rejected an item, what you can do depends on the request:
- A request of one item. You can approve it over the rejection from the emailed link only, by confirming that you are overriding the check and giving your reason. Both are recorded with your approval. Needs you does not offer this.
- A request with other items. The rejected item cannot be approved over the rejection. The other items can still go on your record without it. Send it back where that is offered, or ask your AI to revise it.
When the request lands¶
Nothing reaches your record while you are still working through the list. Your ticks and your per-item decisions are saved as you go, so you can close the page and come back.
The request lands on your last decision. At that moment every item you approved goes on your record, each as its own entry with your name, the time and the words you ticked. Items you sent back or rejected do not land. Items that wait for a second person do not land yet either; they land when that person seals them.
If you reject every item that was still open and then press Approve on the emailed link, the page says "Nothing is left to approve on this request." Nothing goes on your record and the link is not used up.
So a request of eight items where you approve six, send one back and reject one puts six entries on your record, and the other two never appear there as if they had been approved.
Two or more people in the workspace¶
Some records are decisions that, by default, need a second person when your workspace has one:
- policies, procedures and controls,
- decisions on which requirements apply to you,
- exceptions and risk acceptances,
- statements that a control meets a requirement.
Other records, such as evidence, control test results, assets, vendors, risks, remediations, and the links between records, you approve alone.
The first click on a request is always yours, as the person who asked your AI for the work. For a record you may approve alone, your approval puts it on the record. For an item that needs a second person, your Accept parks it as "Accepted, waiting for a second person". A waiting item has no clock: it waits until a colleague acts, and you can still withdraw it.
Your colleague finds the waiting item in their Needs you. They read it, tick that they have reviewed it, and seal it, or send it back or reject it with a reason. The person who seals must be someone other than you. The record shows both acts: who accepted it and who sealed it.
A colleague cannot make the first click on your request. If they open your emailed link, it tells them the link is for a different person, and nothing changes.
People with a read-only role, such as an auditor, see decided work only. They never see what is waiting.
When you are the only person in the workspace¶
If you are the only person in your workspace who can approve (members with a read-only role do not count), there is no second person to seal your governance items. You can approve them yourself, with one extra step.
For each of your own items that would otherwise need a second person, a second box appears beside the first. It reads: "I am the only person in this workspace, and I am sealing my own governance item." Approve stays unavailable until you tick it. When the item lands, your record carries a named exception: it says that you sealed your own item because no one else could, and it keeps those words. The exception shows in your audit export.
Records you may always approve alone, such as evidence or an asset, do not ask for the second box.
When you invite a second person, the exceptions stop from then on: their items wait for your colleague instead.
The clock, used links and Reopen¶
A request's link stays open for up to an hour from when it was created. Needs you shows the time left. If you need longer, you can add another hour in Needs you, a limited number of times; each addition is recorded. Adding an hour replaces the link: your work is saved, the emailed link stops working, and you carry on in Needs you. No new email is sent.
If the time runs out before your last decision, nothing was lost. Nothing was recorded, and your ticks and decisions are kept. Choose Reopen on the request in Needs you. It gives the request a fresh hour, keeps your work, and does not run the safety check again. As with adding an hour, you carry on in Needs you, not on the old emailed link.
A link that has already been used, has closed, or was replaced when time was added says it is no longer usable. If it was used, what it decided is in the Audit Log of the workspace it was sent from. Anything still waiting on you is in Needs you.
Why it works this way¶
Each item is its own decision, and the record shows each one: who decided, when, and in what words. How many items travelled together never changes that. An auditor who asks who approved one control gets a precise answer, whether it came alone or with twenty other items.
More help¶
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.