Diagnose and resolve

Troubleshooting

Resolve common workflow, mapping, scoring, import, assurance and access issues across current PurpleWASP workspaces.

Cannot log in or complete 2FA
  1. Confirm the email address and reset the password when necessary.
  2. Set the authenticator device to automatic date and time.
  3. Use an approved backup code if available.
  4. Record the complete error before contacting support.
A governed document is not visible to the approver
  1. Confirm that the document type requires approval and that Submit for Approval was used.
  2. Verify the selected approver and their active permissions.
  3. Check the approver Pending Approval view and notifications.
  4. Confirm the document is not still Draft, Rejected or Changes Requested.
An approved document cannot be published
  1. Confirm the document type supports publication.
  2. Complete any quiz requirement that applies to the document.
  3. Select an eligible audience.
  4. Choose a valid publication date and retry.
The expected audience is unavailable
  1. Confirm the document type supports the intended targeting mode.
  2. Review the available groups, role/user assignments and audience configuration.
  3. Confirm the intended users are active.
An Asset import failed
  1. Use the current sample CSV and preserve required headers.
  2. Remove blank rows, invalid dates and duplicate identifiers.
  3. Confirm referenced owners or taxonomy values can be resolved.
  4. Test a small sample before a large import.
The Asset value looks wrong
  1. Recheck confidentiality, integrity and availability values.
  2. Confirm whether the organisation uses the expected CIA model.
  3. Review Asset value bands and any recent administrator changes.
The Asset does not appear in the Risk Register
  1. Confirm required classification and CIA values are complete.
  2. Use Assess Now and confirm the action succeeds.
  3. Clear Risk Register filters and refresh.
  4. Confirm your role can access the resulting Risk record.
The qualitative Risk score looks wrong
  1. Distinguish Asset value, inherent/current exposure, residual exposure and target state.
  2. Recheck likelihood/impact inputs and current Controls.
  3. Confirm the correct matrix and acceptance criteria.
  4. Do not treat planned treatment actions as already operating Controls.
The Risk assessment cannot be completed
  1. Check whether residual exposure remains above appetite.
  2. Add or strengthen treatment, or raise the required Risk exception.
  3. Confirm required fields and Control selections are saved.
  4. Review the summary for incomplete stages.
FAIR results appear unrealistic
  1. Confirm the scenario covers one specific threat.
  2. Recheck annual frequency versus per-event values.
  3. Review vulnerability probability and loss magnitude ranges.
  4. Represent uncertainty rather than forcing narrow estimates.
A catalogue Control cannot be updated
  1. Confirm the Control has been adopted into the organisation.
  2. Open the organisation Control record rather than the catalogue reference.
  3. Confirm your role has Control Management write permission.
A Control appears applicable to the wrong Asset
  1. Review the Asset class/category/type and other taxonomy used by applicability rules.
  2. Review organisation scope mappings and exclusions.
  3. Refresh the Asset/Control view after authoritative data is corrected.
Evidence is linked but Control assurance did not change
  1. Confirm the evidence is linked to the intended Control, assessment or test run.
  2. Complete the assessment or test result that records the assurance conclusion.
  3. Do not expect a file/link alone to set Control effectiveness.
An SoA Control marked Not Applicable will not save
  1. Enter a meaningful justification.
  2. Confirm required applicability/status fields are complete.
  3. Check your Compliance/ISMS permissions.
No confirmed SOC 2 engagement is available
  1. Open the SOC 2 setup workflow.
  2. Complete Trust Services Category, system-boundary and engagement-scope details.
  3. Review and confirm the engagement.
  4. Return to the downstream SOC 2 workspace and reload it.
A SOC 2 candidate Control cannot be selected for coverage
  1. Confirm the Control has been adopted into Control Management.
  2. Confirm the organisation Control is not marked Not Applicable.
  3. Confirm the Control is a valid PurpleWASP candidate for the selected criterion.
  4. Return to the Control Coverage Plan and record the organisation coverage decision.
SOC 2 evidence is present but readiness still shows a gap
  1. Confirm the evidence is linked to a selected organisation Control.
  2. Confirm it is current and has enough source/date context.
  3. For Type II, confirm the evidence validity or collection period overlaps the engagement window where period relevance is required.
  4. Check whether a final assessment, active test or completed in-period test run is also missing.
  5. Review active issues or exceptions that may still affect readiness.
SOC 2 Audit Readiness still shows blockers
  1. Open the blocking criterion or Control from the readiness view.
  2. Review implementation, final assessment, current evidence and test state.
  3. Resolve or explicitly govern active issues and exceptions.
  4. Revisit the Criteria Workspace and Coverage Plan if the selected Control set is incomplete or no longer appropriate.
  5. Remember that PurpleWASP readiness is an internal management signal, not the independent auditor opinion.
Cyber Essentials readiness is blocked even though the questionnaire is mostly complete
  1. Open Readiness Review and confirm all applicable questions are answered.
  2. Check evaluated/automatic-fail gaps rather than looking only at completion percentage.
  3. Complete any human-review items for narrative or conditional responses.
  4. Use Remediation to resolve the outstanding technical or questionnaire gap, then refresh the dashboard.
Cyber Essentials Plus cannot progress to technical testing
  1. Open Plus Preflight and review the prerequisite state.
  2. Confirm the underlying Cyber Essentials assessment/scope is available and suitable for the Plus workflow.
  3. Complete the required sample before recording test results.
  4. Resolve blocking findings before treating the Plus outcome/evidence pack as ready.
A NIST CSF 2.0 outcome has no selected organisation Control
  1. Open the outcome in Current & Target or CSF Core.
  2. Review canonical mapping suggestions for Controls already adopted by the organisation.
  3. If an appropriate Control exists, explicitly map it to the outcome.
  4. If no appropriate Control exists, review/adopt/create the Control in Control Management rather than creating a duplicate inside the NIST Profile.
A NIST gap does not match the Control assurance I can see
  1. Remember that Current state is an explicit Profile assessment; Control evidence does not silently update it.
  2. Review mapped-Control implementation, evidence, assessments, tests, issues and exceptions.
  3. If management concludes the outcome state has changed, update the Current Profile assessment explicitly.
  4. Confirm the Target state has not been lowered simply to remove the gap.
SoA status and Control Management disagree
  1. Confirm you are comparing the same standard Control and organisational scope.
  2. Review the SoA compliance decision separately from the organisation/Asset Control implementation state.
  3. Reconcile the records; do not overwrite one merely to make the percentages match.
The Compliance metric did not update
  1. Save the authoritative SoA, activity, evidence or improvement record.
  2. Review the metric's underlying drivers and denominator.
  3. Confirm the record is in the expected status and scope.
  4. Refresh the dashboard after the underlying record is updated.
Discover from Assets shows an unexpected vendor
  1. Review the source Asset vendor values and related Asset count.
  2. If the suggestion is not a managed relationship, dismiss it.
  3. If it is a duplicate or alias, resolve it against the existing third party before accepting.
The recommended TPRM tier looks wrong
  1. Review every tiering factor input and rationale.
  2. Confirm the configured score bands and weights.
  3. If governance permits an override, record a clear confirmation reason.
  4. Do not compare the tier directly with the enterprise Risk score.
A questionnaire score is high but a finding is severe
  1. Review failed questions independently of the total percentage.
  2. Create or maintain the TPRM finding for the material gap.
  3. Assign remediation and escalate to Risk if the exposure requires enterprise treatment.
A monitoring event has not changed vendor status
  1. Monitoring events are reviewable signals, not automatic findings.
  2. Review severity, confidence and source context.
  3. Escalate the event to a finding or incident only when substantiated.
PurpAI is unavailable
  1. Confirm organisation AI features are enabled.
  2. Confirm your role can access the module/context you are trying to query.
  3. Refresh the page and retry with a supported governance question.
  4. If an action is unavailable but ordinary questions work, check whether the action also requires write permission.
PurpAI returned fewer cards than expected
  1. Read the response text for the full result-set context; PurpAI can show a bounded card list while retaining a larger authoritative result count.
  2. Use a follow-up question to narrow the same subject or ask for the next relevant subset.
  3. Check filters and permissions if expected records are completely absent.
A PurpAI record action did not open the expected workflow
  1. Confirm you selected the intended record, especially after a multi-record result.
  2. Retry from a fresh PurpAI result and use an explicit ordinal such as “open the second one”.
  3. For Controls, confirm the requested Assessments, Evidence, Testing, Issues or other workspace exists for that organisation Control.
  4. Where the module does not expose a deeper supported destination, PurpAI may intentionally open the owning record or register instead.
A PurpAI contextual Risk draft did not prefill
  1. Return to PurpAI and prepare the draft again; draft context is intentionally one-time and short-lived.
  2. Confirm the source Asset is still available and you have Risk write permission.
  3. Confirm the Create Risk workflow opened from the PurpAI draft action rather than from a stale copied link.
  4. Review and complete the form normally; PurpAI does not auto-save the Risk.
A confirmed PurpAI action expired or no longer works
  1. Ask PurpAI to prepare the action again rather than reusing the old link.
  2. Confirm you still have Third-Party Risk write permission.
  3. Verify the Third Party is still available and eligible for the requested review or due-diligence workflow.
  4. Confirm the action when prompted; cancelling correctly leaves the workflow unchanged.
Suggested Attention is not showing
  1. Suggested Attention is on demand and does not automatically open with the PurpAI drawer.
  2. Select Suggested attention beside Guide PurpAI.
  3. If no signals are returned, confirm the user can access the relevant modules and that current warning/danger conditions exist.
  4. Use Refresh to re-read current signals; use the close control to dismiss the panel without closing PurpAI.
Microsoft connects, but one or more capabilities are limited or unavailable
  1. Review capability readiness rather than treating Microsoft as one all-or-nothing integration.
  2. For Entra, optional MFA registration, Conditional Access and sign-in activity can depend on licensing/permissions.
  3. For Microsoft 365 Security, inspect collection status: Secure Score/control data can be usable even when incident/alert streams are not provisioned.
  4. For Intune or Defender, verify the tenant actually owns/provisions the service before changing code or adding permissions.
  5. Disable unavailable capabilities; enabled capabilities should continue to run independently.
Intune reports “Request not applicable to target tenant”
  1. Confirm the tenant has an active Intune service/licence.
  2. If licensed, verify DeviceManagementManagedDevices.Read.All and DeviceManagementConfiguration.Read.All are Application permissions with admin consent.
  3. If the tenant is not licensed, disable the Intune capability; this is not a shared Microsoft connection failure.
Defender for Endpoint returns 403 / No active license found
  1. Confirm Defender for Endpoint is licensed and provisioned for the tenant.
  2. Verify Machine.Read.All and Vulnerability.Read.All only after licensing is confirmed.
  3. Disable Defender while unavailable; Entra, Microsoft 365 Security and Azure can continue independently.
Azure authenticates but sees zero subscriptions/resources
  1. Confirm the service principal has Reader at the required subscription scope.
  2. Add Security Reader where Defender for Cloud posture is required.
  3. Run Test Connection/Sync again after RBAC propagation.
An integration job remains queued
  1. Confirm the canonical Integration Management worker is running.
  2. Confirm the job availability time is not in the future and Integration Management database sessions use UTC.
  3. Inspect the worker/service log for claim or database errors.
  4. Do not point the worker back to the retired Asset Management integration runtime.
The Integration Scheduler service is inactive
  1. If the service is configured as a one-shot scheduler, inactive/dead between runs is normal.
  2. Confirm the last execution exited with status 0/SUCCESS.
  3. Confirm the scheduler timer is enabled/active and has a next run time.
  4. Review the scheduler journal/output for errors and confirm it uses the canonical integration_management path.
A Qualys run succeeded but Asset findings did not change
  1. Review the Integration Management run counts and metrics.
  2. Confirm the provider returned vulnerability observations for the expected hosts.
  3. Review Asset-domain integration/matching and vulnerability processing.
  4. Keep provider credentials, jobs and scheduling in Integration Management; do not restore the retired Asset control-plane runtime.
Automated Control evidence did not appear after a run
  1. Confirm the organisation Control is already adopted, applicable and active.
  2. Confirm the canonical automation rule is active and mapped to the expected Control.
  3. Confirm the integration run contains the required observation type or an explicit collection-status record.
  4. Check whether the same run/rule was already materialised; duplicate materialisation is intentionally skipped.
  5. Do not change the Control implementation status merely to make evidence appear.
A user has incorrect access
  1. Review the organisation role and its system/module permission mappings.
  2. Check groups and account status.
  3. Test with a fresh login after saving changes.
  4. Use least privilege and remove conflicting assignments.
Escalate with evidence

Still blocked?

Include the workspace, record ID, affected role, timestamp, expected and actual result, steps to reproduce and complete error text.

  • Remove passwords, tokens and secrets.
  • Use sample data where possible.
  • Attach screenshots that show the full workflow state.