Skip to main content

Work queue, reviews and SLAs

Three pages turn what is happening inside your clients into work your staff can pick up: the work queue collects the open items, SLA policies give each a deadline, and reviews put the recurring client meetings on a schedule with their preparation done in advance.

Work queue

Nobody creates a work item by hand. The queue is built from your clients' own records and rebuilt every fifteen minutes; Refresh rebuilds it now (once every 30 seconds). An item appears whenever a client holds one of:

  • a finding open, in remediation or reopened (finding remediation);
  • an evidence request pending, in progress or returned (evidence request);
  • a requirement exception submitted and not yet reviewed (exception review);
  • a control attestation not yet fulfilled (attestation pending);
  • a drift event nobody has acknowledged (drift acknowledge);
  • onboarding stalled below 60% readiness for more than a week (onboarding blocker);
  • a client review past its overdue threshold, or a connector degraded or failing.

Each item carries the client, a severity, an assignee and an SLA deadline, and sits in one of three urgency bands: overdue, at risk (due within 24 hours) or on track. The five counters at the top give total, overdue, at risk, unassigned and yours.

Filter by kind (the chips carry counts), urgency, assignment (all, mine, unassigned), client and sort order, or search titles. Assign an item from its row; select several and Reassign to a member to move up to 200 at once. Auditors can see the queue but not assign. An item leaves the queue when its source record closes in the client.

SLA policies

SLA Policies (Settings, administrators) sets how long each kind of work item gets before it is overdue. Without a policy, built-in defaults apply (for example two weeks for a finding, a week for an evidence request, three days to acknowledge drift, a day for a failing connector).

A policy is one row per work item kind, either MSP-wide or for one service package; a package policy overrides the MSP-wide one for that package's clients. It sets the base duration (presets from 24 hours to 30 days, or any number of hours up to a year) and optional per-severity overrides, so a critical finding can get 24 hours while the rest keep the base. Where a client record already carries its own due date, that date wins. Changes show up in the queue on its next rebuild.

Reviews

A review cadence is a recurring client meeting: monthly, quarterly, semi-annual or annual, of a type (check-in, QBR, program review, custom), anchored to a date, with a preparation window (14 days by default) and an overdue threshold (7 days). Each schedule creates its next occurrence automatically as the prep window opens. Cadence schedules are set up through the API today; Manage Schedules shows them read-only, with cadence, type, anchor, prep window, overdue threshold, whether a packet is generated automatically, and status.

Reviews lists the next 90 days in three groups: overdue, prep ready (inside the prep window) and upcoming, each with client, cadence, type, date, state and reviewer. Open one to prepare it.

Preparing a review

The preparation page shows the occurrence (scheduled and due dates, state, whether a report has been generated) and a prep snapshot of the client over the review period, in five tabs: compliance (each framework's coverage at the start and end of the period, with the delta), findings (totals by severity, overdue, the top ten), drift (unacknowledged, acknowledged, resolved), evidence (stale items) and renewals (due in the next 90 days). Snapshots are refreshed overnight for reviews in preparation.

  • Start Prep takes the preparation lock. Only the lock holder can edit the prep notes, which save themselves two seconds after you stop typing; anyone else sees who holds the lock. A lock older than half an hour can be taken over by starting prep again.
  • Generate QBR produces the packet for the review.
  • Complete Review closes the occurrence with optional notes and schedules the next one.
  • Snooze (administrators) moves the occurrence to a new date with a reason.

The dashboard's Upcoming Reviews card shows the next 30 days with the overdue and prep-ready counts.