Track time-limited security exceptions with a risk owner, compensating controls, recorded assessment and remediation evidence.

Exception Register opens with a security exposure map beside a detailed exception queue. Active and high-risk counts make the current posture clear, while expiry, risk owner, compensating controls and remediation evidence stay connected to every decision. The workspace records assessment, approval and closure history without implying that the app enforces security controls.
Built for IT governance and security operations teams coordinating documented control exceptions.
Track time-limited security exceptions with a risk owner, compensating controls, recorded assessment and remediation evidence.
Record the affected system, business unit, risk owner, business need and requested expiry.
Record risk, controls, reviewer and assessment. Review and adjust the expiry within the saved system policy. Activation requires a future expiry; changed active risk, controls or expiry must return to Assessing first.
Keep progress in history and provide remediation evidence and an outcome before closure.
Maintain system-specific duration limits and required review guidance for new requests.
Record the affected system, business unit, risk owner, business need and requested expiry.
Record risk, controls, reviewer and assessment. Review and adjust the expiry within the saved system policy. Activation requires a future expiry; changed active risk, controls or expiry must return to Assessing first.
Keep progress in history and provide remediation evidence and an outcome before closure.
Retain earlier stages, decision notes and timestamps inside the work record when a review is saved.
The pilot uses 2 tables with fictional records. No external database is needed to explore the source app.
| Table | Sample data | What it stores |
|---|---|---|
| System standards | 5 sample records | Reference codes, names, policy values and review guidance. |
| Exception records | 16 sample records | Fictional work records with contextual fields, saved policy, stages and embedded decision history. |
This records security decisions; it does not enforce security controls, grant access, send expiry alerts or verify reviewer identity. No evidence uploads or security-platform integration. English desktop pilot. Loaded views and counts cover up to 500 rows per table. No concurrent-update protection. Business-write lifecycle, package export and clean installation remain unverified.
This design is a starting point. Describe the look you want, add your logo and brand colors, or ask for new features in a prompt. Use the starter prompt to build your own version in the ToolJet AI builder, or use a suggested prompt to modify an app you already have. Review and test the result.
Suggested prompts describe changes you can request. Additional features and translations still need to be built and tested.
Choose ToolJet Cloud, or download the application package to import into your self-hosted instance once the template is released.
Explore the sample records in ToolJet Database, then add your records and configure the workflow for your team.
Describe your preferred design, branding, and new features in the AI builder. Test your workflow, then share your app with the people who need it.
Track time-limited security exceptions with a risk owner, compensating controls, recorded assessment and remediation evidence. It includes three connected screens, two ToolJet Database tables, five reference records and sixteen fictional work records.
Record the affected system, business unit, risk owner, business need and requested expiry. Record risk, controls, reviewer and assessment. Review and adjust the expiry within the saved system policy. Activation requires a future expiry; changed active risk, controls or expiry must return to Assessing first. Keep progress in history and provide remediation evidence and an outcome before closure.
Yes. New records copy their reference rules. Editing the reference register does not silently rewrite existing work.
This records security decisions; it does not enforce security controls, grant access, send expiry alerts or verify reviewer identity. No evidence uploads or security-platform integration.
Yes. Use the starter prompt to request changes to branding, layout, fields or workflow. Additional features and languages must be built and tested.