Thirty triggers. Auto-escalation built in.
A "Yes" answer on any of these triggers auto-escalates the gate decision. A high-severity Yes triggers a mandatory review by the relevant function (cyber, privacy, compliance) before the gate can be cleared. This is where Projects connects to the rest of the platform.
Cyber + Privacy triggers15 triggers · auto-escalate to Black
LiveCyber and privacy auto-escalation triggers. Includes: handling of sensitive personal data, cross-border data flows, novel cryptography, identity and access changes, third-party data sharing, AI/ML on personal data, regulated-customer impact, public-facing system changes, and operational technology / OT scope. Critical-severity Yes = Auto-Red.
15 triggersSeverity: Low → Critical
Compliance triggers15 triggers · auto-escalate to Black
LiveRegulatory and compliance auto-escalation triggers. Includes: regulated-entity scope, financial-services obligations, healthcare data, prudential reporting impact, cross-jurisdiction obligations, modern slavery scope, AML/CTF scope, environmental obligations, and consumer-protection-law impact. Critical-severity Yes triggers mandatory compliance review.
15 triggersCross-jurisdiction
Customisable trigger setsPer-organisation
LiveTrigger sets are customisable per organisation. Admins can adjust severity thresholds, add organisation-specific triggers (e.g. board-mandated review thresholds, sector-specific obligations), or scope triggers to specific business units. Default set is practitioner-authored; override is admin-only.
ConfigurableAdmin-controlled
AI & Emerging Tech triggersComing next
NextDedicated AI / emerging tech trigger set. Coming next - separating AI-specific risk triggers from the generic cyber/privacy set. Will cover model-risk classification, EU AI Act tier triggers, autonomous decision-making, generative AI scope, and ISO 42001 conformity scope.
Coming nextEU AI Act + ISO 42001 aligned
ESG & Climate triggersRoadmap
RoadmapSustainability, climate, environmental and social impact triggers - including TCFD, AASB S2 climate-related disclosures, modern slavery scope and Indigenous engagement obligations. Particularly relevant for infrastructure and resources projects. Mapping in development.
Roadmap · 2026TCFD · AASB S2
Sector-specific trigger packsRoadmap
RoadmapPre-built trigger packs for specific sectors - financial services (APRA, ASIC), healthcare (TGA, HPRA), telco (ACMA, TIO), critical infrastructure (SOCI Act). Reduces the customisation burden for organisations operating in heavily regulated sectors.
Roadmap · 2026FS · Healthcare · Telco · CI