Risk & Compliance
Risk Register
Risks are scored by Probability × Impact (1–25, colour-banded red/orange/yellow/green), with a status (open/mitigating/accepted/closed), category (operational/security/compliance/financial/strategic/technical), an optional linked entity, a mitigation plan and an owner. A 5×5 probability/impact matrix view is also available. Solution Designs and Rules can both create or reference Risk Register entries directly, so a risk raised anywhere in the product still lands in one central register.

Obsolescence
An auto-computed report flagging declining or deprecated technologies, with a risk level (Critical/High/Medium/Low) based on lifecycle status, proximity to a recorded end-of-life date, and whether dependent applications exist, including the "blast radius" of affected systems — so an EOL technology with twelve dependent applications is flagged more urgently than one with none.

Completeness
Scores how fully each record's fields are populated (0–100%) across 8 entity types and flags anything under 80% with the specific missing fields, so a catalog that "has" 500 applications but is mostly blank fields is visible as a data-quality problem rather than looking complete on a headline count.

Data Quality
Two tabs: duplicate detection (name-similarity matching with an adjustable 80–99% threshold, for spotting the same application entered twice under slightly different names) and Validation Rules (8 built-in rules, e.g. "applications must link to a domain", each with a configurable severity) that continuously check the live catalog against those rules rather than only at data-entry time.

Adherence Heatmap
A principle × entity matrix showing adherence levels (weak/partial/moderate/strong/not assessed) with an overall coverage percentage — the aggregate view of the per-entity adherence assessments captured on Principles.

Vendor Risk
A read-only rollup per vendor: a computed risk score, counts of critical applications/technologies/contracts tied to that vendor, upcoming contract renewals, total spend, and flags for concentration risk (too much riding on one vendor) — useful for procurement and third-party risk reviews. Clicking a vendor expands a breakdown of how its composite score is calculated: the concentration, renewal, spend and ownership sub-scores, their weights, and each one's contribution to the total.

Compliance Frameworks
Model compliance frameworks (e.g. NIST, ISO 27001, SOC 2 — one click seeds standard starter frameworks) made up of individual controls, then map each control to the entities that satisfy it as covered, partial, or a gap. A weighted coverage percentage per framework gives an at-a-glance audit-readiness score.

Drift Alerts
A feed of alerts automatically raised by the scheduled drift-detection job: degrading technical condition on an application, a sudden cost spike, or an overdue recertification review, each with a severity (critical/warning) and a link to the affected entity. Alerts can be resolved individually once actioned, or the whole detection pass can be re-run on demand with "Run now" rather than waiting for the next scheduled sweep.
