oolak / Features / Exceptions and risk register
Exceptions and risk register

When something can't be fixed, decide it properly.

Some vulnerabilities can't be patched today. oolak turns each of these into a clear, approved and time-limited decision, and keeps a risk register you can hand straight to an auditor.

Approved, time-limited exceptions in one register.

See the impact first

Before an exception is approved, you see exactly which findings it will cover.

Two people, always

The person who asks can never approve their own request.

Nothing lasts forever

Every risk acceptance has an end date and comes back for review when it expires.

Exceptions and risk register

What's included

  • Exception types are false positive, risk acceptance, pending upgrade, end of life and out of scope.
  • Each exception is a rule, so matching findings are set aside automatically once it is approved.
  • Approval rights are granted separately for exceptions, asset changes and rescans.
  • Every risk acceptance has an owner and a mandatory expiry date.
  • Bulk exceptions can be requested from a filter or a list.
  • False positives are counted and reported on their own.
  • Requests are raised through a step-by-step wizard.
  • Approving an exception closes its ticket automatically.
  • Risk acceptances made in Tenable are mapped to the same register.
  • The register can be exported, and every step is kept in the audit log.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

Can a requester approve their own exception?
Not by default. Separation of duties is enforced per approval area. An organisation can choose to allow self-approval, and that choice is itself recorded.
Can an AI assistant approve an exception?
No. AI assistants and service accounts can only request an exception. Approval always needs a person signed in to the web interface.