FAQ

Which items can link to which

Quick reference: every link type the product supports and how to make them.

1 min readLast updated 26 April 2026

Every link lives in its own M:N map table and is tenant-scoped. Here's the full matrix.

FromToWhere in UI
ControlFramework sectionControl detail → "frameworks" actions
ControlRiskRisks detail → linked controls; or Controls → "link to risks"
Control testControlControls detail → "Log test"
Control testEvidenceIncluded in the test form as evidence IDs
EvidenceControl or PolicySet at upload time on the Evidence page
PolicyControlPolicies view modal → "Linked controls" panel
PolicyRiskPolicies view modal → "Linked risks" panel
PolicyAcknowledgments / CampaignsPolicies view modal → Ack panel / Campaigns panel
AssetRiskAssets detail → "Link risk"
IncidentRiskIncidents detail → "Linked risks" panel
VulnerabilityAsset / Control / RiskSet on the Vulnerability record directly
VendorData typeVendors detail → "Data types processed"
Audit findingControlSet on the Finding record
BCP BIAPlanBCP detail → "New BIA"

Unlinked records are still queryable (you won't fail validation for leaving things dangling) but they don't count toward any framework percentage, don't contribute to residual scoring, and don't tell the audit story. The gentle nudge: the longer you use the product, the tighter you should pull these links.