Notifications
CISO Assistant can send you email notifications to keep you informed about deadlines, assignments, and status changes.
Prerequisites
Email notifications must be enabled by your administrator under Extra > Settings > Enable email notifications. This setting is off by default on a fresh install, no notification emails are sent until an administrator enables it.
Onprem instances only
Your CISO Assistant instance also needs an outgoing mail server configured (EMAIL_HOST, EMAIL_PORT, and DEFAULT_FROM_EMAIL at minimum). If you are not receiving emails, contact your administrator to verify these are set.
Notifications are sent to the email address associated with your account.
On the PRO plan, administrators can also turn each email type on or off individually under Extra > Settings > Email templates. All emails are on by default.
Notification types
Assignments
You receive an email whenever something is assigned to you.
Applied Control
Owner
You are added as an owner
Audit
Authors
You are added as an author
Risk Scenario
Owner
You are added as an owner
Task (template)
Assigned to
You are added as an assignee
Security Exception
Owner
You are added as an owner
Note: Task assignment notifications fire when a task template is assigned. Due-date reminders (below) fire on the task occurrences generated from that template.
Deadlines & Expiry reminders
CISO Assistant sends reminders automatically 30 days, 7 days, and 1 day before a deadline or expiry date. These emails are sent every morning.
For reminders to fire, both fields below must be filled in.
Applied Control
ETA expired
ETA (past due, status not Active)
Owner
Expiry approaching
Expiry date
Owner
Audit
Due date approaching
Due date
Authors
Evidence
Expiry approaching
Expiry date
Owner
Security Exception
Expiry approaching
Expiration date
Owners
Validation Flow
Deadline approaching (flow in submitted state only)
Validation deadline
Approver
Task
Due date approaching
Due date
Assigned to
Note for recurring tasks: reminders are automatically skipped if the recurrence interval is shorter than the reminder horizon (e.g., a daily task will not receive a 7-day warning).
Overdue alerts
If a deadline has already passed and the item is still open, you will receive an overdue alert.
Applied Control — ETA expired
ETA + Owner
Owners
Evidence — expired
Expiry date + Owner
Owners
Task — past due
Due date + Assigned to
Assignees
Security Exception — expired
Expiration date + Owner
Owners
Compliance assignment workflow
When working on a Requirement Assignment inside an audit, notifications follow the review workflow automatically — no extra fields to fill.
Assignment activated (Draft → In progress)
Assignee
Assignment submitted for review
Reviewers (falls back to authors if none are defined)
Assignment reviewed (approved / reopened for review / changes requested)
Assignee
Assignment reopened for editing (sent back to Draft from In progress or Changes requested)
Assignee
Validation flows
Validation flow created and submitted
Approver
Validation flow status changes
Requester or approver, depending on the transition
Security exceptions
Security exception status changes
Owners and the approver
Account notifications
Account created
You (welcome email with login instructions)
Account created via SSO
You (welcome email)
Password reset requested
You (reset link)
Third-party questionnaires (TPRM)
If your organisation uses the Third-Party Risk Management module, external contacts receive an email when a questionnaire is sent to them. This email contains a link to fill in the questionnaire.
Quick reference — what to fill in
Remind owners when a control ETA expires
Applied Control › Owner + ETA
Remind owners before a control expires
Applied Control › Owner + Expiry date
Remind authors before an assessment deadline
Audit › Authors + Due date
Remind owners before evidence expires
Evidence › Owner + Expiry date
Alert owners when evidence has expired
Evidence › Owner + Expiry date
Remind an approver of a validation deadline
Validation Flow › Approver + Validation deadline
Notify assignees of upcoming task due dates
Task › Assigned to + Due date
Remind owners before a security exception expires
Security Exception › Owner + Expiration date
Alert owners when a security exception has expired
Security Exception › Owner + Expiration date
Frequently asked questions
I am not receiving any emails. What should I check? First confirm that email notifications are enabled with your administrator (the global toggle is off by default). Then ask the administrator to verify that EMAIL_HOST, EMAIL_PORT, and DEFAULT_FROM_EMAIL are set. Verify that your account email address is correct in your profile. Finally, check your spam folder.
I filled in the fields but still got no email. Why? Check that the field contains an exact date — reminders are sent only on specific days (30, 7, and 1 day before). If the deadline is sooner than 30 days from when you set it, the 30-day reminder will not fire.
I am receiving too many reminders. Can I opt out? Per-user opt-out is not yet available. On the PRO plan, an administrator can disable a specific email type for the whole instance under Extra > Settings > Email templates.
At what time are reminders sent? Reminders are sent in the early morning (between 6:00 AM and 7:30 AM server time). Account, password-reset, validation-flow, and security-exception status-change event emails are sent immediately when the event occurs, not in this window.
Will I get a reminder every day until the deadline? No. Reminders are sent only on specific days: 30 days before, 7 days before, and 1 day before the deadline. Overdue alerts are sent daily until the item is resolved.
Last updated
Was this helpful?