Reviewing comments on assessments
You can now add comments directly to any question or requirement while reviewing question‑based and requirement‑based assessments, keeping feedback, queries and context exactly where the work happens.
Tag individual users or user groups with @mentions to notify them instantly via in‑app and email alerts, and assign comments to specific people so they surface in their My Tasks view for clear ownership.
Mark comments as resolved to track discussions to completion, with a full Review Trail preserving the comment history for every question. The result is faster, more collaborative reviews and a defensible audit trail - no more recreating feedback or chasing it across email and spreadsheets.
See the knowledge base for more information.
Miscellaneous improvements
Look for the new "Clear Formatting" button in rich text editors. This feature makes it easy to tidy up formatting after copying and pasting from an external system, and is being rolled out across the platform.
Administration features
SSO issuer checks have been tightened. In your SSO configuration, ensure that whitespace is removed, and ensure trailing slashes exactly match the requirements detailed for your identity provider in the knowledge base.
Roles and permission can now be exported in Excel format from the Roles administration screen.
Risks that need sign-off before they progress — accepted risks, treatment decisions, closures — previously relied on manual follow-up outside the workflow. You can now add Approval stages to your Risk workflow, so designated approvers must review and approve a risk before it moves on.
Approval stages in the Risk workflow. When creating a workflow stage you now choose between a Standard stage and an Approval stage. The stage type is set at creation and cannot be changed later.
Approval stages define who must approve and where the risk goes next, which only supports the static option "Origin stage" or any other configured approval stage.
Flexible approvers and approval logic. On the Stage approvers tab, approvers can be individual users, groups or standard fields (Risk Owners or Access Members). Choose the logic for each stage: All approvers or At least one approver.
Approvals slot into your existing workflow. Standard stages now list approval stages as an option in their entry requirements (Enter from), grouped alongside standard stages. Add an approval stage to a standard stage's entry requirements to require sign-off before risks can enter it — this is how you connect the approval flow end to end.
Submit with context. Moving a risk to an approval stage opens a Submit for approval dialog showing the approval chain ahead, with a rationale field so approvers see why the risk was submitted.
Approve or decline from the risk. Approvers see Approve and Decline buttons directly on the risk. The dialog shows the approval chain, the submitter's rationale, and the approval history to date. A reason is required when declining, and a single decline ends the approval immediately.
Automatic progression. Once the approval logic is satisfied, the risk automatically moves to the stage's configured destination — the next approval stage or back into the standard workflow. If an automatic transition is blocked due to exit requirements of the approval stage or entry requirements of the configured "Go to" stage, risk owners are notified so nothing stalls silently.
Cancel when plans change. Users with risk edit and workflow stage transition permissions can cancel a pending approval, returning the risk to the stage it came from. A cancellation reason is required.
Full audit trail. Every submission, approval, decline, and cancellation is recorded on the risk's History tab, including who acted and when.
Notifications built in. Approvers and risk owners receive in-app and email notifications for approval requests, completions, cancellations, and blocked transitions. These can be managed under Notification management > Approvals.
Go to Administration > Risk workflow and select Create new workflow stage > Approval stage.
On the Stage approvers tab, choose your approvers and the approval logic.
Set the Go to destination — where the risk moves once approved.
On a risk, select the approval stage from the workflow stage dropdown, add a rationale, and select Submit.
Approvers action the request from the Approve / Decline buttons on the risk. Once the logic is met, the risk moves on automatically.
Risk Approvals is available on all plans that include the risk workflow — no setup needed beyond creating your first approval stage.
Existing risks and workflows are unaffected. All current stages remain standard stages, and nothing changes until you add an approval stage.
While an approval is pending, the risk cannot leave the stage until the request is approved, declined, or cancelled.
Creating and editing approval stages uses your existing risk workflow stage permissions.
Head to your Risk workflow settings to add your first approval stage.
📖 Read more in the knowledge base: https://knowledgebase.6clicks.com/configuring-risk-workflow#approval
Attachments can now be downloaded in bulk from the Risks Register
When importing users in bulk, a checkbox is now available to disable welcome emails
A session timeout can now be specified to improve security (Administration -> Settings -> Security)
Assessment responses now accept up to 5000 characters
A Power BI Third Party (Vendor) Dashboard is now available for download (Administration -> Integrations -> Power BI)
File attachments for various record types can now be retrieved from the Developer API
The GET Users endpoint can now return a list of permissions (add $expand=Permissions to the query)
API Keys can now be restricted to certain IP addresses or IP ranges. We encourage you to use IP restrictions whenever possible for an additional layer of security.
The “Set Value For” rule type now supports editable fields. You can choose whether auto-populated values remain read-only or can be updated by respondents during an assessment.
This option allows users to modify system-set values—supporting use cases like guided recommendation writing.
This setting is available during rule creation and applies based on the configured conditions, with safeguards in place to prevent rule conflicts.
Following the release of Advanced Report Templates for Requirement-Based Assessments (RBAs), this capability has now been expanded to Questionnaire-Based Assessments (QBAs), enabling more powerful and flexible report generation across all assessment types.
With this enhancement, reports can go beyond simple data population to dynamically shape outputs using conditions, structured logic, and calculations—making them more relevant, contextual, and insight-driven.
The platform continues to support existing tag-based placeholders alongside advanced placeholders, ensuring backward compatibility while unlocking greater customization.
Refer to the Knowledge Base to learn how to configure rule-based placeholders and make the most of this feature.
We’ve introduced Advanced Report Templates, enabling more powerful and flexible report generation for assessments.
With this enhancement, Assessment reports can go beyond simple data population to dynamically shape outputs based on conditions, structure, and calculations—making them more relevant and insight-driven.
The application will continue to support existing tag-based placeholders alongside advanced placeholders. Refer to the Knowledge Base to learn how to configure rule-based placeholders.
Note:
This feature is currently available for requirement-based assessments (RBAs) and will be extended to Question based Assessments (QBAs) soon.
It is switched off by default as it will continue to be enhanced as a new feature. Please contact the Customer Success team to have it enabled for your environment.
The Power BI Connector v2.8 now supports ongoing data refresh via the On-Premise Data Gateway, using API Keys for connectivity.
You can download the latest connector from Administration > Integrations > Power BI.
See Power BI Connector Gateway setup guide for further information.
We’re expanding automation capabilities in the Custom Workflow Builder with new event triggers and actions — enabling real-time orchestration across your risk workflows and integrations.
You can now automate processes instantly when key events happen within the platform. All triggers fire in near real-time when the event occurs.
Available triggers include:
Risk created - Fires when a risk is created.
Risk updated - Triggers whenever any risk field is modified, capturing both previous and new values.
Risk owner changed - Fires on any ownership change — assignment, reassignment, or unassignment.
Risk workflow stage changed -Triggers on all workflow stage transitions.
Risk custom field changed - Available for individual custom fields and supports conditional downstream workflow configurations.
Risk assessment created - Fires within near real-time when a risk assessment is created.
Risk treatment plan created - Fires when a treatment plan is created..
You can now configure workflows to perform the following actions automatically:
Create Risk - Create new risks with full support for standard and custom fields.
Assign Risk Owner - Assign or reassign owners in bulk via a single API call.
Add Comment / Attachment - Attach comments or files to an existing risk from external processes.
Change Risk Stage - Move risks across workflow stages with validation enforced.
Update Risk - Partially update risk records, including custom fields, without impacting other data.
Create Risk Assessment - Create assessments linked to existing risks, including custom field support.
Update Risk Assessment - Update assessment data across Spoke tenants.
Custom Field Support for Register Items - Create and update assets, issues, and custom register records with full custom field support.
To enable event triggers, contact us at support@6clicks.com and request activation of the Entity Change Event Publisher feature.
Please include:
Tenant name
Instance/environment
For more information, refer to the Custom workflow builder and Event Triggers knowledge base articles.
We have released better support for managing users who unsubscribe from emails.
Users can now unsubscribe and resubscribe to all email correspondence from within the Notification Settings inside the application.
On the user administration screen, administrators can see who is unsubscribed and resubscribe them if necessary
The problem where some mail server filters follow all links in an email and inadvertently cause the address to be unsubscribed has been mitigated.
We are pleased to announce that Arabic (Beta) is now supported within the 6clicks application.
You can enable Arabic in either of the following ways:
Update your browser language preferences (recommended).
Or go to My Settings in 6clicks and select Arabic.
The Knowledge Base also supports Arabic across many pages.
We will continue improving Arabic support, with Arabic translations for emails and Hailey AI coming soon.
Your assessments just got smarter.
With the enhanced Rule Builder, you can now create dynamic, compliance requirement-based assessments (RBAs) that automatically adapt based on context. Rules now actively guide how your fields behave — helping you streamline assessments, improve consistency, and reduce manual effort.
In addition to existing display conditions, you can now:
🔹 Automatically control field values - Use 'set value' Logic to set field values based on defined conditions, ensuring responses stay accurate and aligned.
🔹 Require evidence when it matters - Define exactly when evidence uploads are mandatory.
🔹 Make fields mandatory only when required - With 'Require response for', you can make specific fields compulsory when certain conditions are met.
Setting up rules is simple and structured:
Create rules directly in the Rules tab after setting up your custom fields.
Define conditions using requirement attributes or assessment fields.
Apply actions to assessment fields like compliance status or justification.
Need to make changes? Rules can be edited or deleted while in Draft status.
Rules automatically activate when your assessment moves to In Progress.
Viewing summary of rules at a glace under the rules tab
Guide users automatically. Reduce unnecessary work.
Head to the Assessments module to start creating intelligent assessments today!
This release improves the consistency and usability of how attachments are viewed across the application. The update makes it easier and more intuitive to preview, download, and manage attached files.
Consistent attachment preview behaviour
Clicking a supported file opens it in a new browser tab for online viewing
Ctrl+click or right-click → 'Open link in new tab' opens the file in a new tab while keeping the current tab active.
Supported file types for online preview
PDF files
Images (jpg, jpeg, png, gif, svg, webp)
Text files (.txt, .log)
New permission: Preview attachments
A new permission is added to: '[Register name] > Attachments' permission tree.
When granted, users can preview supported file types online.
This permission is enabled by default for users with attachments access.
Other minor updates
Third-party forms: When an item is created using a third-party form, the history log and the details page now clearly shows that the item was created via the form.
Two control responsibilities can have the same name under distinct control sets.
This release introduces endpoints and event triggers in the 6clicks Developer API, expanding integration capabilities across risks, assessments, and custom registers. These updates support automation, real-time workflows.
Custom field support for custom register items
Custom register items can be created and updated via the Developer API with support for custom fields. All updates follow existing workflow rules and validation logic.
Custom field change trigger (Create)
A new trigger is available when a specific custom field is created. This enables real-time automations based on data changes.
Risk assessment created trigger
A new trigger is available when a risk assessment is created. This supports automated workflows that respond immediately to assessment creation events.
Update risk assessment via API
Risk assessments can be updated through the Developer API to support automated assessment management. Partial updates are supported and subject to existing workflow and stage restrictions.
Update Risk
Risk records can be updated programmatically via the Developer API to keep data synchronized across systems. Updates respect workflow access rules and validation requirements.
Add comments and attachments
Comments and file attachments can be added to risks through the Developer API. This supports automated documentation and audit trail capture through integrations.
For more information and to learn more, go to Administration → Integrations → Developer API → API documentation.
This release introduces a set of practical enhancements across Control responsibilities, Register - comments, and Risk workflow. These updates focus on improving flexibility, consistency, and day-to-day usability while giving administrators greater control across the platform.
Control responsibilities can have the same name across control sets
Users can now create control responsibilities with the same name in different control sets.
To avoid confusion, we recommend using slight name variations, though this is no longer required.
Comments support for Custom Registers
All custom register items now support comments via a dedicated Comments tab.
Comment access is governed by permissions, giving admins control over visibility and usage.
Risk custom fields can be managed even when used in workflows
Risk admins can now edit custom fields even if they are used as entry or exit requirements in risk workflows.
The system automatically handles any cascading changes, removing the need to first remove fields from workflow requirements.
Improved history and status visibility for issues created via Issue forms
Issues created through forms now display consistent created by details and history log entries, aligned with risk forms.
This release includes a set of targeted improvements across notifications, assessments, Hub & Spoke visibility, and custom registers. These updates focus on improving configurability, governance, and usability while giving admins more control and flexibility across the platform.
Responsibility due date reminder notifications now include additional configurable variables, allowing admins to tailor email content with the information they need.
Configure it in : Administration > Notifications > 'Responsibility - Due date reminder'
Assessment-only (AO) spokes now support archiving and deleting Authority from Compliance module.
Hub: Spoke history tracking has been enhanced to record advisor changes:
An entry is now added to the history tab when an advisor is added to or removed from a spoke.
Assessments now support an option to make looped questions as mandatory in question-based assessments (QBA).
User-type custom field for custom registers allows admins to reference users and user groups directly in register items:
Can be shown as a column on the register page.
Supports filtering and bulk updates.
Available across import/export, DevAPI, and Analytics.
For more information, head to KB Article