🚨 This review system will be disabled on September 15, 2026.
We are implementing a new action review system that is more transparent and easier to use.
This article explains how the new mechanism works. You can choose whether or not to enable it through a preference: this article will help you make that decision.
What are Reviews?
Reviews in Tenacy are validations or pending actions that require your attention.
You can find them by clicking on the bell icon in the top menu.
🟡 Yellow bell → You have pending reviews.
⚪ Grey bell → No reviews pending.
💡 It’s important to check whenever the bell turns yellow, as some scores depend on the validation of certain reviews.
How to Manage Reviews
✅ Validate a review: Click anywhere on the concerned row, or hover and click the icon on the left.
❌ Close a review (without validating): Hover and click the icon on the far right.
🔄 Reopen closed reviews: Activate the toggle “See closed” at the top of the window.
Once validated, the review disappears from the list.
Types of Reviews
There are 7 types of reviews in Tenacy:
1. Measure Reviews
There are two types of measure reviews:
Implement a measure
Triggered when you finish an implementation action. Tenacy asks you to confirm that the security measure is now implemented.
⚠️ Impact if not ignored:
The measure will stay as non-implemented, giving 0 points on your linked policies or risks.
Improve a measure
Triggered when you finish an improvement action. Tenacy asks you to confirm it’s completed.
⚠️ Impact if ignored:
The measure’s efficiency will remain penalized until you validate the review.
2. Incident Reviews
Triggered when all actions linked to an incident are completed.
⚠️ Impact if ignored:
The incident remains open until you validate or close it manually.
3. Gap Reviews
Triggered when all actions linked to a gap are completed.
⚠️ Impact if ignored:
The gap remains open until you validate or close it manually.
4. Exemption Reviews
Triggered when all actions linked to an exemption are completed.
⚠️ Impact if ignored:
The exemption stays active until you validate it, its end date is reached, or you close it manually.
5. Project Reviews
Triggered when all actions in a project (ISP module) are completed.
⚠️ Impact if ignored:
The project stays open until you validate it, its end date is reached, or you close it manually.
6. Policy Reviews
Triggered when a policy has requirements without linked security measures.
⚠️ Impact if ignored:
None. It’s only a reminder to complete your policy mapping. You can ignore or close it.
7. Action Mapping Reviews
Triggered when imported actions could be implementation or improvement actions.
⚠️ Impact if ignored:
None. It’s just a reminder to check and confirm the action type.










