Project Commander Docs ← Back to site

Risks Tab — Feature Guide

Risks tab — Add risk button, counts and settings bar, five filter dropdowns, and the AI Generated, Manually Entered, Accepted AI Generated and Closed risks sections
Risks tab — Add risk button, counts and settings bar, five filter dropdowns, and the AI Generated, Manually Entered, Accepted AI Generated and Closed risks sections

What it's for

The Risks tab consolidates everything the project has told the team to worry about. Three sources flow into it: deterministic detectors (the same engine that drives Sprint Risks on the Dashboard), AI-generated suggestions (refinements of detector output through a language model), and manual entries created by the team in retros, planning, or ad-hoc. Every risk has a probability × impact score, a category, an owner via RACI fields, mitigation actions, and (optionally) comments.

The audience is anyone responsible for project health: scrum master, tech lead, product manager, programme manager. Where the Alerts tab catches issue-level data problems, the Risks tab tracks team-level threats — capacity issues, scope creep patterns, deadline slips, recurring people problems, and external dependencies.

Top of the tab

The tab does not repeat its own name — the tab bar directly above already says Risks, and no other finished tab repeats its name either.

+ Add risk sits on its own line at the top right. It opens an inline form headed Add risk whose submit button reads Add (see Add risk form below). The wording matches the Actions tab and the Projects tab — Add to create, Delete to remove (Don, 2026-09-02).

Below it, one pale bar carries the counts on the left and two project-wide settings on the right:

Both tick boxes appear only where the screen has somewhere to save them.

Filters and sort

Five dropdowns sit in one row below the counts bar. Each carries its own name inside it, so the row reads Source: All Status: All Strategy: All Scope: All Sort: Score ↓, with no separate labels beside them. Sort sits at the right-hand end of the row.

AI Generated section

A folding section, visible when Source is All or AI and Status is not Closed. Its header reads ✨ AI Generated (N) followed by the note Accept creates the risk immediately — no dialog; suggested mitigation actions attach automatically, so nobody has to press Accept to find out what it does. The whole section is drawn inside a dashed border.

Each suggestion is one row, not a card:

One click after Accept: the suggestion has gone from AI Generated and the risk it created is in the Accepted AI Generated section
One click after Accept: the suggestion has gone from AI Generated and the risk it created is in the Accepted AI Generated section

The register — three folding sections

The risks themselves sit in up to three folding sections, each with its own header and count:

Each risk is one row of a card-like table — separated rows with a rounded border each, no column headings, and no coloured stripe down the left edge (removed 2026-08-25 so this tab and the Actions tab match).

The risk register — round score badges, folding rows, strategy chips, and Edit / Mark closed / Delete on each row
The risk register — round score badges, folding rows, strategy chips, and Edit / Mark closed / Delete on each row

Reading a row from left to right:

Opening a risk

Clicking the arrow or the title opens the risk in place, directly under its own row. The summary row stays put, so the score and the strategy are still in front of you while you work. Opening it is opening it for editing — the same form the Edit button opens — and beneath the form sit the two things you read rather than type:

Mitigation actions — a line reading Mitigation actions: N open · M done, itself foldable, listing each action with a tick box, the action text (a link into the Actions tab), owner and sprint. Ticking marks the action done; unticking reopens it.

An Add action button (only on open risks) opens an inline form with action text, optional owner, and a sprint dropdown defaulting to the active sprint (or Project scope when no active sprint). On save the action is created and immediately linked to this risk.

Comments — a line reading Comments (N), foldable, showing each comment with author, date, and text. An inline add-form takes comment text + optional author and submits with Enter or the Add button. Comments are stored per risk and rendered in creation order.

The close prompt

When every mitigation action on an open risk is done:

Add risk form

The Add risk form — Title and Description fields, Category dropdown, Scope dropdown (Program / Project / Sprint), Probability and Impact selects with live Score readout, RACI fields (Accountable required, Responsible, Consulted, Informed), Mitigation summary, and Jira issue link field
The Add risk form — Title and Description fields, Category dropdown, Scope dropdown (Program / Project / Sprint), Probability and Impact selects with live Score readout, RACI fields (Accountable required, Responsible, Consulted, Informed), Mitigation summary, and Jira issue link field

An inline card that opens at the top of the tab, headed Add risk, from the + Add risk button (or an alert's Create risk); its submit button reads Add. (The Accept button on an AI suggestion does not open a form — acceptance is one click; see AI Generated section above.) Fields:

When the form is launched from an alert ("Create risk" on a category in the Alerts tab) it pre-fills category, evidence, and probability/impact from the alert's category mapping; the alert provenance is recorded so the N alerts currently match indicator can later light up.

Editing a risk

Edit on a row, and clicking the row's arrow or title, do the same thing: they open the risk in place, directly under its own row, with the same fields as the Add risk form and the values already filled in. Save updates the stored risk; Cancel closes the detail again.

Response strategy

Every risk also carries a response strategy — the team's decision about how to handle the risk while it is still open. Strategy is orthogonal to status (an open + accept risk is a standing decision to absorb the risk, not a closure). The seven values are Undecided, Avoid, Mitigate, Transfer, Accept, Escalate, and Defer; each renders as a coloured chip in the strategy column of the risk's row, with the date it was decided beneath it.

The six standard strategies

Strategy field, audit trail, rationale

Dashboard mix bar + sort priority

The Top Open Risks widget gains a strategy mix bar ("4 mitigate · 2 accept · 1 escalate · 3 undecided") underneath the header. Zero-count buckets are hidden. The widget sort puts Undecided and Escalate risks above Accept at the same severity score so the items demanding attention surface first. Defer risks are excluded from the widget until their review window opens (review-by minus 3 days).

Alerts

Two new categories appear in a Risk strategy domain on the Alerts tab:

Clicking a row in either category navigates to the Risks tab with the risk scrolled into view.

Complete Sprint and Accept risks

The Complete Sprint dialog surfaces risks whose linked mitigation actions are all complete and offers a one-click close. Accept risks are excluded from that list because acceptance is a standing decision, not an actions-driven mitigation. Avoid risks closed through this path record closedReason: avoided instead of mitigated. Escalated risks do not block sprint completion.

Severity formula

Severity is probability × impact with bands:

The round score badge is filled pale in the band's colour and lettered in the matching strong colour — pale rather than solid, because the seriousness is the number itself. The Dashboard's Top Open Risks widget draws the same badge from the same definition, at a smaller size. The default sort is by score so critical risks float to the top.

Detectors that emit AI suggestions

The deterministic detectors that produce suggestions are documented in ALGORITHMS section 13. They include sprint-level detectors (low confidence, single-person load, mid-sprint scope creep, aging issues, capacity hit, untouched in active), project-level detectors (velocity decline, carry-over rising, deadline at risk, estimation quality declining, recurring actions, health trend dropping, critical sprint ahead), and cross-cutting detectors (oversized issues unsplit, and issues untouched in the active sprint).

Each detector has a configurable confidence threshold (default 60%); suggestions below the threshold are suppressed. The threshold is editable in Settings.

Empty / loading / error states

Cross-cutting modes and settings

How the numbers are computed

Probability × impact, banding, detector definitions, and confidence calculation are documented in ALGORITHMS section 13. Title polish and mitigation generation are documented in ALGORITHMS section 21.

Effects on other parts of the app

© 2026 Project Commander · projectcommander.app · Support · Privacy · Security · Terms