Use cases

Response work with a list that keeps moving.

KnownScope fits when the item list, the questions, and the people answering them change during the response. It isn't tied to CVEs, and it isn't a replacement for ticketing or evidence systems.

Good and poor fit

Good fit

  • The candidate list changes as the team learns.
  • The response needs its own fields and grouped updates.
  • Several teams need one trusted record and a clear handoff.
  • Earlier decisions and their sources must remain reviewable.

Poor fit

  • A stable ticket queue already holds the whole workflow.
  • You need the product to discover, validate, patch, or remediate systems.
  • The primary need is forensic evidence or full case management.
  • Every field needs its own access policy or live multi-cursor editing.

01

Emerging vulnerability

The affected-version list is changing, the scanner does not yet answer the whole question, and several teams hold pieces of the asset picture.

Inputs
Asset exports, scanner findings, vendor lists, and pasted rows can form the first candidate list. An import dry run shows invalid and ambiguous rows before anything is committed.
Work in KnownScope
Define fields for version, reachability, assessment, confidence, or another condition specific to the advisory. Save views for each team, update selected Items together, and use Work logs for decisions and handoffs.
Handoff
Send the fix to the ticket or change system you already run. Use governed files, the API, or signed webhooks for the handoff that fits the team.
Product boundary
KnownScope does not discover vulnerable assets or validate a patch. It accepts governed candidate data from files, the API, and approved read-only Data Sources. Evidence and forensic artifacts remain in the repository approved for them.
  • version
  • reachability
  • assessment
  • confidence

02

Supplier response

A supplier incident may touch applications, integrations, facilities, vehicles, or control environments that do not live in one inventory.

Inputs
Start with supplier records, service inventories, integration lists, and the operational knowledge held by local teams. Each source remains visible after an import.
Work in KnownScope
Track the relationship, affected service, operational dependency, assessment, responsible team, and next action. Group access lets internal teams work from the same Campaign.
Handoff
Use the Campaign for shift changes and leadership questions, then move the fix into the system that owns it.
Product boundary
KnownScope is not a supplier portal, evidence exchange, contract register, or third-party risk platform. It coordinates the internal list and the decisions your team makes about it.
  • supplier
  • dependency
  • assessment
  • next action

03

Investigation or exposure

A report, scan, or internal question has identified something exposed. Nobody knows yet how big the list is.

Inputs
Seed the Campaign with the reported systems, accounts, endpoints, or relationships. Add later candidates without replacing the earlier source record.
Work in KnownScope
Track assessment as not assessed, investigating, affected, or not affected. Keep remediation progress in a separate field. Record why a decision changed, the next check, and the team responsible for follow-up.
Handoff
Transfer Campaign ownership between shifts and give each reader a permission-filtered view. Publish a status snapshot or send permitted data to an approved downstream process.
Product boundary
KnownScope is not a SIEM, forensic case system, evidence store, or complete audit-package exporter. It holds the changing list and its response record.
  • source
  • assessment
  • responsible team
  • next check

Next step

Compare one response with the Campaign model.

An anonymized example is enough. We'll say where KnownScope fits and where another system should keep the work.