Authorizations
API key for authentication
Headers
Organization ID (required for session auth, optional for API key auth)
Body
Risk creation data
Risk title
"Data breach vulnerability in user authentication system"
Detailed description of the risk
"Weak password requirements could lead to unauthorized access to user accounts"
Risk category
customer
, governance
, operations
, other
, people
, regulatory
, reporting
, resilience
, technology
, vendor_management
"technology"
Current status of the risk
open
, pending
, closed
, archived
"open"
Likelihood of the risk occurring
very_unlikely
, unlikely
, possible
, likely
, very_likely
"possible"
Impact if the risk materializes
insignificant
, minor
, moderate
, major
, severe
"major"
Residual likelihood after treatment
very_unlikely
, unlikely
, possible
, likely
, very_likely
"unlikely"
Residual impact after treatment
insignificant
, minor
, moderate
, major
, severe
"minor"
Risk treatment strategy
accept
, avoid
, mitigate
, transfer
"mitigate"
Department responsible for the risk
none
, admin
, gov
, hr
, it
, itsm
, qms
"it"
Description of the treatment strategy
"Implement multi-factor authentication and strengthen password requirements"
ID of the user assigned to this risk
"mem_abc123def456"
Response
Risk created successfully
Risk ID
"rsk_abc123def456"
Risk title
"Data breach vulnerability in user authentication system"
Risk description
"Weak password requirements could lead to unauthorized access to user accounts"
customer
, governance
, operations
, other
, people
, regulatory
, reporting
, resilience
, technology
, vendor_management
"technology"
none
, admin
, gov
, hr
, it
, itsm
, qms
"it"
open
, pending
, closed
, archived
"open"
very_unlikely
, unlikely
, possible
, likely
, very_likely
"possible"
insignificant
, minor
, moderate
, major
, severe
"major"
very_unlikely
, unlikely
, possible
, likely
, very_likely
"unlikely"
insignificant
, minor
, moderate
, major
, severe
"minor"
"Implement multi-factor authentication and strengthen password requirements"
accept
, avoid
, mitigate
, transfer
"mitigate"
"org_abc123def456"
ID of the user assigned to this risk
"mem_abc123def456"
When the risk was created
When the risk was last updated
How the request was authenticated
api-key
, session
User information (only for session auth)