Tasks

Last updated: June 5, 2026

Overview

Tasks is a centralized page “Under My Tasks” in Mycroft that surfaces everything your team needs to take action on to stay audit-ready. Tasks are automatically generated when something in Mycroft requires attention. Each task links directly to where the work happens, and resolves itself when the underlying issue is cleared.

How Tasks Work

Every task has three components:

  • Trigger — the event or condition that created the task

  • Link — where to go in Mycroft to take action

  • Resolution — what makes the task disappear

Tasks appear when they're needed and resolve automatically when the underlying issue is addressed. You don't need to manually open, close or archive tasks.

Task Views

My Tasks is accessible from the left navigation bar. Within the page, tasks are organized into three tabs:

Assigned to me

  • Shows all tasks where you are the assignee, with the count shown inline in the tab label

  • This is your personal compliance to-do list

  • The count shown next to My Tasks in the sidebar also reflects this number

  • Available to all users

  • Empty state: "You're all caught up! There are no tasks assigned to you." — includes a View all tasks button to jump to the All tasks tab

Unassigned

  • Shows all tasks that have no assignee, across all task types

  • Allows admins to spot and delegate unclaimed work

  • Available to Admins only

All tasks

  • Shows every open task across your organization, regardless of assignee

  • Resolved tasks do not appear in this view

  • Use the Type dropdown to filter by task type

  • Available to Admins only


Task Types

Overview

Tasks covers the following areas. Each type has its own trigger and resolution logic.

Access Review

Access Review tasks come in two types:

  • Complete annual access review — appears when no access review has been published within the past year. Has no due date or owner until a draft review is opened, at which point the opener becomes the owner. Links to the Access Reviews page.

  • Complete {X} vendor access reviews / Complete access review: {Vendor} — appears when a draft access review is open and vendor-specific reviews need to be completed. Uses the due date set for the vendor review (or falls back to the top-level access review due date). Links to Access Reviews > Draft review.

  • Both resolves when a new access review is published

Renew annual access review

  • Triggered based on the cadence configured in Settings (Default is 1 year after the last published access review)

  • Always has a due date

  • Links to the Access Reviews page

  • Resolves when a new access review is published

Review third-party assessment

  • Triggered when a vendor owner assigns you as a reviewer on a third-party assessment

  • Always groups under Today; shows a due date only if the review is for a renewal

  • Links to the third-party's draft assessment view in TPRM

  • Resolves when the "Review security questionnaire" item is marked complete

Complete third-party assessment

  • Triggered when a third-party assessment is Due Soon or Overdue based on its renewal cadence

  • Links to the TPRM page filtered to assessments pending completion (aggregate), or to the vendor summary view (single)

  • Resolves when a new assessment is published for that third party

Policy Renewal

  • Triggered when a policy moves to Due Soon or Expired (surfaces 30 days before due date)

  • Links to the relevant policy detail view

  • Resolves when a new published version of the policy is created, or the policy is deactivated

Policy Review

  • Triggered when a policy draft is sent to you for review ("For Review" state)

  • Always appears in the Today grouping

  • Links to the relevant policy detail view

  • Resolves when the reviewer approves the draft

Document Renewal

  • Triggered when a document moves to Due Soon or Expired (surfaces 30 days before due date)

  • Links to the relevant document detail view

  • Resolves when a new published version of the document is created, or the document is deactivated

App Scan Findings

  • Triggered when a scheduled App Scan discovers new issues

  • Links to the Issues tab in App Scan, filtered to Open

  • Resolves when the issues are acknowledged

Trust Center Access Request

  • Triggered when a new access request is submitted on your Trust Center

  • Links to the Access Requests tab filtered to Pending

  • Resolves when the request is approved or denied

Integration Error

  • Triggered when an integration enters an error state (e.g., expired credentials, auth failure, sync failure)

  • Links to the relevant integration's detail page

  • Resolves when the integration successfully re-syncs, or the integration is removed

Automatic Test Failed

  • Triggered when an automated test moves to a failing status

  • Always groups under Unscheduled — no due date

  • Aggregate links to the Tests page with Automated type + Failing status filters active; single links to the individual test detail page

  • Resolves when the underlying test returns to a passing status

Important: Task types that depend on integrations (App Scan, Automatic Test Failed, Integration Error) will only appear if the relevant integrations are connected. If these integrations are not set up, those task types will not surface.


Understanding Task Groupings

Overview

Tasks are organized by urgency to help you prioritize what needs attention first.

Groupings

Tasks are grouped into the following buckets:

  • Overdue — Tasks that are past their due date. Overdue tasks always appear as individual items with their due dates shown — they are never aggregated.

  • Today — Tasks due today. Policy Review tasks and third-party assessment Review tasks always surface here regardless of due date.

  • In 7 Days — Tasks due within the next 7 days. Shows a "Due in X days" label rather than the exact date.

  • Upcoming — Tasks due further out.

  • Unscheduled — Tasks with no defined due date (e.g., initial document or policy completion tasks, and all Automatic Test Failed tasks). Unscheduled tasks sort above Upcoming so they are not buried in the list.

Note: Due dates on task items are only shown for renewal tasks that are Due Soon or Overdue (i.e., within 30 days of due date, or past it). Tasks for initial completion do not show due dates.


Setting Up Renewal Dates

Overview

Renewal tasks for Policies, Documents, TPRM assessments, and Access Reviews only surface if renewal dates or cadences are configured on those entities. Without this setup, renewal tasks will not be generated.

How to Configure Renewals

Renewal cadences are set within the relevant section of the platform:

For Risk Assessments:

  1. Navigate to Settings > Risk Management

  2. Set the renewal date or cadence

For Access Reviews:

  1. Navigate to Settings > Access Reviews

  2. Set the desired renewal frequency

For Documents:

Documents automatically have a one year renewal date from the date they are published. There is no way to adjust this renewal cadence at the moment.

For Policies:

Policies automatically have a one year renewal date from the first time they are published. There is no way to adjust this renewal cadence at the moment.

Important: Renewal tasks surface 30 days before the configured due date. If a task isn’t complete by the due date, the task will become Overdue.


Assigning Tasks

Overview

Most tasks are assigned automatically based on the owner or role configured on the related entity (e.g., the document owner, the policy reviewer, the vendor owner).

How Assignments Work by Task Type

  • Access Review tasks — the first-ever "Complete annual access review" task has no owner until a draft is opened; subsequent tasks and vendor-specific review tasks are assigned to the reviewer or owner

  • Third-party Review tasks — assigned to the user designated as reviewer on the assessment

  • Third-party Renewal tasks — assigned to the vendor owner

  • Policy Renewal and Review tasks — assigned to the policy owner or reviewer

  • Document Renewal tasks — assigned to the document owner

  • Trust Center Access Request tasks — assigned to the Trust Center admin

  • Automatic Test Failed tasks — assigned to the test or control owner

If no owner is set on the related entity, the task will appear in the Unassigned view.

Assigning an Unassigned Task

To assign a task from the Unassigned view:

  1. Navigate to My Tasks and select the Unassigned tab

  2. Locate the task you want to assign

  3. Click the task to open the assignment options

  4. Select the appropriate assignee

  5. The task will move to the assignee's Assigned to me tab immediately

Note: Only Admins can access the Unassigned tab.


Permissions

Overview

What you can see in Tasks depends on your role in Mycroft:

All users

  • Can see the Assigned to Me view

  • Can see tasks assigned to them across all task types

  • Cannot see tasks assigned to other users

Admins only

  • Can access the All Tasks view (all open tasks across the org)

  • Can access the Unassigned view

  • Can assign unassigned tasks to team members


Quick Reference Guide

Task Type Summary

  • Access Review (Complete) — no prior review exists or draft is open → links to Access Reviews page or vendor review → resolves when new review published

  • Access Review (Renew) — cadence-triggered, always has a due date → links to Access Reviews page → resolves when new review published

  • Third-party Review — assigned as reviewer → groups under Today → links to draft assessment → resolves when review marked complete

  • Third-party Renewal — assessment Due Soon / Overdue → links to TPRM (aggregate) or vendor summary (single) → resolves when new assessment published

  • Policy Renewal — policy Due Soon / Expired → links to policy detail → resolves when new version published or deactivated

  • Policy Review — policy sent For Review → links to policy detail → resolves when reviewer approves

  • Document Renewal — document Due Soon / Expired → links to document detail → resolves when new version published or deactivated

  • App Scan Findings — scan finds new issues → links to Issues tab → resolves when issues acknowledged

  • Trust Center Access Request — new TC request → links to Pending requests → resolves when approved or denied

  • Integration Error — integration error state → links to integration detail → resolves when re-sync succeeds or integration removed

  • Automatic Test Failed — test moves to failing → always Unscheduled, no due date → links to Tests (aggregate) or test detail (single) → resolves when test returns to passing

Example Workflows

Finding your open tasks

  • Navigate to My Tasks in the left sidebar — the badge count shows tasks assigned to you

  • The Assigned to me tab is selected by default

  • Tasks are sorted by urgency — Overdue and Today appear first

  • Click any task to go directly to the relevant area of Mycroft

Acting on an overdue renewal task

  • Open the task from the Overdue grouping in Assigned to Me

  • Follow the deep link to the relevant document, policy, or assessment

  • Complete the renewal — the task will resolve automatically

Assigning an unassigned task (Admins)

  • Navigate to My Tasks > Unassigned tab

  • Locate the task, assign the underlying entity to the appropriate team member (i.e. assign Ned Stark as owner of a document)

  • The task moves to their Assigned to me tab immediately

Ensuring renewal tasks surface

  • Confirm renewal dates or cadences are configured on documents, policies, risk assessments, and access reviews

  • Tasks surface 30 days before the due date — if no date is set, no task will be generated