Assessment methodologies
An assessment methodology composes factors into a score. It is the most consequential thing you will configure, because every number in the app comes out of it.
Building one
Go to Settings → Assessment methodologies and select Create. Four steps:
1. Model
Name, description, and the scale — 5×5, 4×4, or custom. Also whether residual scoring is manual, automated, or both.
2. Dimensions and factors
Define your dimensions — Impact and Likelihood at minimum, but you can add others such as Velocity or Detectability. Add factors to each dimension and give each a weight.
Weights within a dimension must total exactly 100%. The wizard will not let you save at 110%, and it tells you what you have currently allocated. This is the most common reason a methodology cannot be saved.
3. Matrix and formula
How the dimensions combine into a single score, and the heat matrix that visualises it.
4. Lifecycle and bands
Score bands — Low, Medium, High, Critical — and crucially the obligation each band carries: “Mitigation plan within 30 days”, “Executive notification, 7-day plan”.
Bands with obligations turn a colour-coded register into a governance process. Bands without them are decoration.
Assigning to a register
A register selects its methodology in Settings → Assessment. A workspace can supply a default so new registers start with the right one.
Comparability
The methodology is what decides whether two numbers can be added together. Registers sharing a methodology roll up by score. Registers on different methodologies roll up by appetite band count only — a 25-max score and a 16-max score must never be averaged. The app enforces this and states how many methodologies were mixed in any view that spans them.
Changing a register’s methodology
This creates a branch. The register’s existing scored state is frozen and preserved, and a new branch is created with the scores recalculated under the new model. The old state remains available as evidence of how the register looked when decisions were made against it.
This is deliberate — silently rescoring history would invalidate every committee decision taken on the old numbers — but it means changing a methodology is a significant act, not a settings tweak. Plan it.
Editing a methodology in use
Editing weights, bands or the matrix on a methodology that registers are already using affects all of them. Check which registers before you save; the methodology list shows the count.