In Tenacy, completing an action is not a trivial step: it can implement a measure, close a gap, resolve an incident, a derogation or a project, and shift your compliance scores. The action review lets you decide who validates these impacts, and when they are applied.
This switch is controlled by a single preference. This article helps you determine whether enabling it is relevant for you. The detailed behavior of the feature is covered in a dedicated article.
The two possible scenarios
Everything depends on the action.review preference, which you enable or not depending on your organization.
Preference disabled (the default behavior)
A contributor who finalizes an action moves it directly to "Done". The associated impacts are applied immediately, at the moment they close the action. This is the most direct way of working: everyone implements the effects of their own actions.
Preference enabled
A contributor can no longer complete an action themselves. Only a pilot can move an action to done. The contributor sets it to the "To review" status, signaling that it is ready to be checked. A pilot then verifies the work, reviews the expected impacts, and validates by moving the action to "Done". The impacts are only applied at that validation.
💡 The review is not a way of monitoring contributors, but a collective validation mechanism. The pilot confirms the real impact of what has been done on the cyber program, and the contributor gains concrete feedback on their work.
What the enabled preference brings
When the review is enabled, several mechanisms come into play to help the pilot validate with full knowledge of the situation.
A notification as soon as an action is ready. The relevant pilots are alerted through the bell when an action moves to "To review", along with the number of actions waiting.
A dedicated filtered view. From the notification, the pilot accesses all "To review" actions. They can filter them like any action plan: by perimeter, priority, owner, action type, and so on.
Everything needed to decide without leaving the action. A "Links" tab in the action panel gives access to the associated objects, which the pilot can go to directly to check.
💡 For organizations with high volumes, filtering the "To review" view makes it easy to split the validation workload across several pilots.
The review and the PDCA logic
If you manage your compliance through a continuous improvement approach such as ISO 27001, enabling the review materializes the verification step of the PDCA cycle.
Plan and Do: an implementation action is planned, then carried out by a contributor.
Check: instead of being closed directly, the action moves to "To review". The pilot verifies that the expected result is indeed there.
Act: the pilot validates, and the impact (for example the implementation of a measure) is recorded in the security base and the scores.
For an audit, this provides strong traceability: an action carried out by a contributor, then validated by a cyber expert, then reflected in the compliance status.
The questions to ask yourself
To decide whether enabling the preference makes sense, ask yourself these few questions.
Who carries out the actions, and who should validate their effects? If your actions are carried out by contributors but responsibility for the impacts lies with pilots, the review is made for you.
Does closing an action have significant effects in your organization? The more your actions trigger impacts on your measures, gaps or scores, the more useful a validation by an expert before application becomes.
Do you have several contributors? The review makes full sense in organizations where many contributors are involved, and where the pilot wants to keep control over what is actually applied.
Do you need to demonstrate quality control for an audit? Being able to prove that an action was verified before being recorded is an asset in an ISO approach.
Are your teams ready for the change? Enabling the review changes the finalization path for contributors. This is a change to support, especially if you never carried out a review before.
If you answer yes to several of these questions, enabling the preference will directly strengthen the reliability of your management. Otherwise, keeping it disabled remains perfectly suitable: your contributors will continue to finalize their actions fully autonomously.
⚠️ Enabling the preference changes your contributors' path: they will no longer be able to complete an action themselves. Plan to support this change before enabling it.
🔎 For the detailed behavior of the review once enabled, see the article dedicated to the action review.
