Tasks
Last updated: June 5, 2026
Overview
Tasks is a centralized page “Under My Tasks” in Mycroft that surfaces everything your team needs to take action on to stay audit-ready. Tasks are automatically generated when something in Mycroft requires attention. Each task links directly to where the work happens, and resolves itself when the underlying issue is cleared.
How Tasks Work
Every task has three components:
Trigger — the event or condition that created the task
Link — where to go in Mycroft to take action
Resolution — what makes the task disappear
Tasks appear when they're needed and resolve automatically when the underlying issue is addressed. You don't need to manually open, close or archive tasks.
Task Views
My Tasks is accessible from the left navigation bar. Within the page, tasks are organized into three tabs:
Assigned to me
Shows all tasks where you are the assignee, with the count shown inline in the tab label
This is your personal compliance to-do list
The count shown next to My Tasks in the sidebar also reflects this number
Available to all users
Empty state: "You're all caught up! There are no tasks assigned to you." — includes a View all tasks button to jump to the All tasks tab
Unassigned
Shows all tasks that have no assignee, across all task types
Allows admins to spot and delegate unclaimed work
Available to Admins only
All tasks
Shows every open task across your organization, regardless of assignee
Resolved tasks do not appear in this view
Use the Type dropdown to filter by task type
Available to Admins only
Task Types
Overview
Tasks covers the following areas. Each type has its own trigger and resolution logic.
Access Review
Access Review tasks come in two types:
Complete annual access review — appears when no access review has been published within the past year. Has no due date or owner until a draft review is opened, at which point the opener becomes the owner. Links to the Access Reviews page.
Complete {X} vendor access reviews / Complete access review: {Vendor} — appears when a draft access review is open and vendor-specific reviews need to be completed. Uses the due date set for the vendor review (or falls back to the top-level access review due date). Links to Access Reviews > Draft review.
Both resolves when a new access review is published
Renew annual access review
Triggered based on the cadence configured in Settings (Default is 1 year after the last published access review)
Always has a due date
Links to the Access Reviews page
Resolves when a new access review is published
Review third-party assessment
Triggered when a vendor owner assigns you as a reviewer on a third-party assessment
Always groups under Today; shows a due date only if the review is for a renewal
Links to the third-party's draft assessment view in TPRM
Resolves when the "Review security questionnaire" item is marked complete
Complete third-party assessment
Triggered when a third-party assessment is Due Soon or Overdue based on its renewal cadence
Links to the TPRM page filtered to assessments pending completion (aggregate), or to the vendor summary view (single)
Resolves when a new assessment is published for that third party
Policy Renewal
Triggered when a policy moves to Due Soon or Expired (surfaces 30 days before due date)
Links to the relevant policy detail view
Resolves when a new published version of the policy is created, or the policy is deactivated
Policy Review
Triggered when a policy draft is sent to you for review ("For Review" state)
Always appears in the Today grouping
Links to the relevant policy detail view
Resolves when the reviewer approves the draft
Document Renewal
Triggered when a document moves to Due Soon or Expired (surfaces 30 days before due date)
Links to the relevant document detail view
Resolves when a new published version of the document is created, or the document is deactivated
App Scan Findings
Triggered when a scheduled App Scan discovers new issues
Links to the Issues tab in App Scan, filtered to Open
Resolves when the issues are acknowledged
Trust Center Access Request
Triggered when a new access request is submitted on your Trust Center
Links to the Access Requests tab filtered to Pending
Resolves when the request is approved or denied
Integration Error
Triggered when an integration enters an error state (e.g., expired credentials, auth failure, sync failure)
Links to the relevant integration's detail page
Resolves when the integration successfully re-syncs, or the integration is removed
Automatic Test Failed
Triggered when an automated test moves to a failing status
Always groups under Unscheduled — no due date
Aggregate links to the Tests page with Automated type + Failing status filters active; single links to the individual test detail page
Resolves when the underlying test returns to a passing status
Important: Task types that depend on integrations (App Scan, Automatic Test Failed, Integration Error) will only appear if the relevant integrations are connected. If these integrations are not set up, those task types will not surface.
Understanding Task Groupings
Overview
Tasks are organized by urgency to help you prioritize what needs attention first.
Groupings
Tasks are grouped into the following buckets:
Overdue — Tasks that are past their due date. Overdue tasks always appear as individual items with their due dates shown — they are never aggregated.
Today — Tasks due today. Policy Review tasks and third-party assessment Review tasks always surface here regardless of due date.
In 7 Days — Tasks due within the next 7 days. Shows a "Due in X days" label rather than the exact date.
Upcoming — Tasks due further out.
Unscheduled — Tasks with no defined due date (e.g., initial document or policy completion tasks, and all Automatic Test Failed tasks). Unscheduled tasks sort above Upcoming so they are not buried in the list.
Note: Due dates on task items are only shown for renewal tasks that are Due Soon or Overdue (i.e., within 30 days of due date, or past it). Tasks for initial completion do not show due dates.
Setting Up Renewal Dates
Overview
Renewal tasks for Policies, Documents, TPRM assessments, and Access Reviews only surface if renewal dates or cadences are configured on those entities. Without this setup, renewal tasks will not be generated.
How to Configure Renewals
Renewal cadences are set within the relevant section of the platform:
For Risk Assessments:
Navigate to Settings > Risk Management
Set the renewal date or cadence
For Access Reviews:
Navigate to Settings > Access Reviews
Set the desired renewal frequency
For Documents:
Documents automatically have a one year renewal date from the date they are published. There is no way to adjust this renewal cadence at the moment.
For Policies:
Policies automatically have a one year renewal date from the first time they are published. There is no way to adjust this renewal cadence at the moment.
Important: Renewal tasks surface 30 days before the configured due date. If a task isn’t complete by the due date, the task will become Overdue.
Assigning Tasks
Overview
Most tasks are assigned automatically based on the owner or role configured on the related entity (e.g., the document owner, the policy reviewer, the vendor owner).
How Assignments Work by Task Type
Access Review tasks — the first-ever "Complete annual access review" task has no owner until a draft is opened; subsequent tasks and vendor-specific review tasks are assigned to the reviewer or owner
Third-party Review tasks — assigned to the user designated as reviewer on the assessment
Third-party Renewal tasks — assigned to the vendor owner
Policy Renewal and Review tasks — assigned to the policy owner or reviewer
Document Renewal tasks — assigned to the document owner
Trust Center Access Request tasks — assigned to the Trust Center admin
Automatic Test Failed tasks — assigned to the test or control owner
If no owner is set on the related entity, the task will appear in the Unassigned view.
Assigning an Unassigned Task
To assign a task from the Unassigned view:
Navigate to My Tasks and select the Unassigned tab
Locate the task you want to assign
Click the task to open the assignment options
Select the appropriate assignee
The task will move to the assignee's Assigned to me tab immediately
Note: Only Admins can access the Unassigned tab.
Permissions
Overview
What you can see in Tasks depends on your role in Mycroft:
All users
Can see the Assigned to Me view
Can see tasks assigned to them across all task types
Cannot see tasks assigned to other users
Admins only
Can access the All Tasks view (all open tasks across the org)
Can access the Unassigned view
Can assign unassigned tasks to team members
Quick Reference Guide
Task Type Summary
Access Review (Complete) — no prior review exists or draft is open → links to Access Reviews page or vendor review → resolves when new review published
Access Review (Renew) — cadence-triggered, always has a due date → links to Access Reviews page → resolves when new review published
Third-party Review — assigned as reviewer → groups under Today → links to draft assessment → resolves when review marked complete
Third-party Renewal — assessment Due Soon / Overdue → links to TPRM (aggregate) or vendor summary (single) → resolves when new assessment published
Policy Renewal — policy Due Soon / Expired → links to policy detail → resolves when new version published or deactivated
Policy Review — policy sent For Review → links to policy detail → resolves when reviewer approves
Document Renewal — document Due Soon / Expired → links to document detail → resolves when new version published or deactivated
App Scan Findings — scan finds new issues → links to Issues tab → resolves when issues acknowledged
Trust Center Access Request — new TC request → links to Pending requests → resolves when approved or denied
Integration Error — integration error state → links to integration detail → resolves when re-sync succeeds or integration removed
Automatic Test Failed — test moves to failing → always Unscheduled, no due date → links to Tests (aggregate) or test detail (single) → resolves when test returns to passing
Example Workflows
Finding your open tasks
Navigate to My Tasks in the left sidebar — the badge count shows tasks assigned to you
The Assigned to me tab is selected by default
Tasks are sorted by urgency — Overdue and Today appear first
Click any task to go directly to the relevant area of Mycroft
Acting on an overdue renewal task
Open the task from the Overdue grouping in Assigned to Me
Follow the deep link to the relevant document, policy, or assessment
Complete the renewal — the task will resolve automatically
Assigning an unassigned task (Admins)
Navigate to My Tasks > Unassigned tab
Locate the task, assign the underlying entity to the appropriate team member (i.e. assign Ned Stark as owner of a document)
The task moves to their Assigned to me tab immediately
Ensuring renewal tasks surface
Confirm renewal dates or cadences are configured on documents, policies, risk assessments, and access reviews
Tasks surface 30 days before the due date — if no date is set, no task will be generated