---
title: Risks and risk acceptance
sidebarLabel: Risks and acceptance
description: The definition of a risk in Advisor, how to read severity and impact, and when to accept a risk instead of fixing it.
updated: 2026-09-27
---

A risk is a rule that a zone's configuration does not meet. Each risk states its severity, the points the score gains once it is fixed and how to fix it.

## Where a risk comes from

On each collection, Advisor compares every zone's configuration with the rules of the [Maturity Score](/en/advisor/conceitos/score-de-maturidade/). Every rule with status **Não conforme** (Non-compliant) or **Parcial** (Partial) becomes an open risk on the [Risks](/en/advisor/postura/riscos/) screen. When the configuration is fixed in Cloudflare, the risk leaves the queue on the next collection and shows up under **Evolução** (Evolution).

## Severity

| Severity | How to read it |
|---|---|
| **Crítica** (Critical) | Exposure to handle first. The menu shows how many critical risks are open. |
| **Alta** (High) | Relevant protection gap. |
| **Média** (Medium) | Important improvement, no immediate exposure. |
| **Baixa** (Low) | Best-practice fine-tuning. |

## Impact

**Impacto no score** (Score impact) shows how many points the score gains once the rule passes. Severity indicates how serious the risk is. Impact indicates how many points the score gains. To plan fixes, sort the queue by severity to reduce exposure or by impact to raise the score.

## What a risk panel shows

| Section | Content |
|---|---|
| **Valor observado** (Observed value) | What the collection found in the zone. |
| **Por que corrigir** (Why fix it) | The practical effect of the gap. |
| **Remediação guiada** (Guided remediation) | Numbered steps to fix it in the Cloudflare dashboard. |
| **Regra** (Rule) and **Impacto no score** | The rule identifier and the points at stake. |

:::note
The fix is made in Cloudflare, by you or by Guardnet. Advisor does not change your account: **Corrigir automaticamente** (Fix automatically) shows as "em breve" (coming soon) and is not available yet.
:::

## Accept a risk

Accept a risk when it is known and tolerated, for example a test zone. Acceptance removes the rule from the score calculation and records who accepted it and why.

1. Go to **Riscos** (Risks) and select the risk.
2. Select **Aceitar risco** (Accept risk).
3. Fill in **Justificativa (obrigatória)** (Justification, required).
4. (Optional) Set **Expira em** (Expires on). After that date, the rule counts toward the score again.
5. Select **Aceitar risco**.

The rule becomes **Ignorada** (Ignored) and the screen shows the confirmation "Risco aceito. A recomendação saiu do cálculo do score." (Risk accepted. The recommendation left the score calculation.)

### Other ways to accept

| Where | Action | Scope |
|---|---|---|
| Zone score panel | **Ignorar recomendação** (Ignore recommendation) | One rule in the zone |
| Zone score panel | **Ignorar zona** (Ignore zone) | Every open rule in the zone, with one justification for all |
| Zone **Registros DNS** (DNS records) tab | **Ignorar melhoria** (Ignore improvement) | Only that record for that rule |

To undo the acceptance, select **Restaurar** (Restore) or **Restaurar regra** (Restore rule). The rule counts toward the score again.

:::caution
Rules with a negative score, penalties, cannot be accepted. The panel shows "Pontuação negativa: não pode ser ignorada" (Negative score: cannot be ignored). A penalty only stops counting once the configuration is fixed.
:::

## Who can accept

Accepting and restoring require the `posture.ignores.write` permission, included in the **Tenant Admin** role. Refer to [Roles and permissions](/en/advisor/referencia/papeis-e-permissoes/).

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/conceitos/riscos-e-aceite/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
