Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

State roll-up and roll-down scenarios

State roll-up and roll-down scenarios automatically sync the status of remediation tasks (RTs) and vulnerable items (VITs), ensuring real-time updates across both. This dynamic interaction reduces manual tracking, enhances accuracy, and provides users with an up-to-date view of progress, making vulnerability management more efficient and helping users make informed decisions quickly.

Roll-up behavior

When vulnerable item (VIT)states change, these changes may propagate up to the remediation task (RT)level. The following table summarizes key roll-up scenarios where changes in vulnerable item (VIT) state may influence the associated remediation task (RT) state, based on closure conditions, reassignments, and deferrals.

VITs StateConditionRT State
Open → Under Investigation / Awaiting Implementation \(any sub-state\) / In ReviewVIT transitions to any non-final or non-actionable stateRemains Open
Open → ClosedAll associated VITs have the same sub-stateClosed – <same sub-state as VITs>
Open → ClosedAll associated VITs have different sub-statesClosed – <no sub-state>
Open → some Closed VITs and some Deferred VITsAll associated Deferred VITs have the same sub-stateDeferred – <same sub-state as VITs>\(Until date = earliest of all VITs\)
Open → some Closed VITs and some Deferred VITsAll associated Deferred VITs have different sub-statesDeferred – <no sub-state>\(Until date = earliest of all VITs\)
Open → Closed–Fixed \(after next scan\) → ResolvedVITs marked as fixed but pending verificationRemains Open
Closed–Fixed → OpenVIT reopens after being Closed–FixedRemains Closed–Fixed
Closed–Stale → OpenVIT reopens after being Closed–StaleRemains Closed–Cancelled
Under Investigation → Closed–CI DecommissionedMultiple RTs \(e.g., RT1, RT2\) exist for related VITsEach RT transitions to Closed–Cancelled
Resolved → OpenIf a resolved VIT reopens and the previously associated RT was assigned to a userResolved → Under Investigation
Resolved → OpenIf a resolved VIT reopens and the previously associated RT was unassigned to a userResolved → Open

Roll-down behavior

When the state of a remediation task changes, the state is often propagated to the associated VITs unless overridden by manual updates or specific exceptions. The following table summarizes key roll-down scenarios where changes in remediation task (RT) state may affect the associated vulnerable item (VIT) state, based on precedence rules and special conditions.

RT StateConditionVIT State
Open → Under Investigation / In Review / Closed–False PositiveRT transitions to a non-final or non-actionable stateMirrors RT state change (Open → <same state as RT>)
Open → Deferred (Sub-state: Reason Given)RT deferred with a specified reasonOpen → Deferred (Sub-state: Reason Given)
Open → ResolvedRT marked as resolvedOpen → Resolved
Open → Closed–Cancelled / Closed–Fixed with ExceptionsRT closed without full resolutionRemains Open
RT1: Open → Under Investigation; RT2: OpenOne RT moves to Under Investigation while another remains OpenOpen → Under Investigation
RT1: Open → Under Investigation → Awaiting Implementation; RT2: Under InvestigationOne RT progresses to Awaiting ImplementationOpen → Under Investigation → Awaiting Implementation
RT1: Awaiting Implementation → Deferred; RT2: Awaiting ImplementationOne RT deferred while another remains Awaiting ImplementationAwaiting Implementation → Deferred
RT1: Awaiting Implementation → Closed–Cancelled; RT2: Under InvestigationOne RT cancelled while another is Under InvestigationAwaiting Implementation → Under Investigation
Open → Closed–Fixed with ExceptionsMixed outcome: one VIT closed as fixed with exceptions, another remains openVIT1: Open → Closed–Fixed; VIT2: Remains Open
Open → ResolvedMixed outcome—one VIT closed as fixed and another resolvedVIT1: Open → Closed–Fixed; VIT2: Open → Resolved
Resolved → OpenRT reopens after resolutionVIT2 reopens; VIT1 remains Resolved