Improve in-app guidance and explanations for "Outscoping" Tasks

Context & Problem Statement Users are struggling to understand the rules of engagement for "outscoping" a task. Currently, the platform allows users to mark tasks as out of scope, but it lacks contextual help explaining when or why this is appropriate. This leads to user hesitation or, worse, users incorrectly outscoping mandatory requirements, which jeopardizes their ISO/SOC 2 audit readiness.

We need to provide better in-app education at the point of action so users understand the criteria for marking a task as Not Applicable (N/A) and know that auditors will require a valid reason.

Acceptance Criteria (AC)

  • Contextual Help / Tooltips: Add an info icon (i) or tooltip next to the "Outscope" button on the Task view explaining the general concept (e.g., "Only outscope tasks if the underlying technology or process is not used by your organization.").

  • Confirmation Modal: When a user clicks to outscope a task, trigger a confirmation modal instead of an instant state change.

  • Provide Examples: Inside the modal, provide 1-2 bullet points of valid outscoping scenarios (e.g., "Example: Outscoping a 'Physical Security' task because your company is 100% remote.").

  • Mandatory Justification: Update the outscoping workflow to require a text input for "Justification." Users must explain why it is out of scope (e.g., "We do not process credit cards"), as auditors will ask for this.

  • Link to Docs: Include a "Learn More" link in the modal that points to the relevant Support Article or Knowledge Base page about scoping.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

3 months ago

Author

Shreya Yadav

Subscribe to post

Get notified by email when there are changes.