Skip to content

List risks linked under a given parent risk. The default `/v1/risks` register hides children — this endpoint is the only way to enumerate them.

GET
/v1/risks/{id}/children
id
required
integer format: int64

Parent RSK numeric ID (e.g. 1 for RSK-00001)

Example
1
id
Array<integer>
title_contains
string | null
description_contains
string | null
opened_by
array | null
updated_by
array | null
impact
array | null
likelihood
array | null
initially_reported_urgency
array | null
type
array | null
Allowed values: Code Configuration Control Deficiency Policy Procedural Vulnerability Third-party
status
array | null
Allowed values: New Urgency Proposed Remediation Closure Proposed Closed
source
array | null
threat_objectives
array | null
urgency
array | null
created_after
string | null format: date-time

Inclusive lower bound on created_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
created_before
string | null format: date-time

Inclusive upper bound on created_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
updated_after
string | null format: date-time

Inclusive lower bound on updated_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
updated_before
string | null format: date-time

Inclusive upper bound on updated_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
discovered_after
string | null format: date-time

Inclusive lower bound on discovered_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
discovered_before
string | null format: date-time

Inclusive upper bound on discovered_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
due_after
string | null format: date-time

Inclusive lower bound on due_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
due_before
string | null format: date-time

Inclusive upper bound on due_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
due_is_null
boolean | null

Match only risks whose due_date is unset. Mutually exclusive with due_after/due_before.

expected_after
string | null format: date-time

Inclusive lower bound on expected_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
expected_before
string | null format: date-time

Inclusive upper bound on expected_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
expected_is_null
boolean | null

Match only risks whose expected_date is unset. Mutually exclusive with expected_after/expected_before.

closed_after
string | null format: date-time

Inclusive lower bound on closed_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-01-01T00:00:00Z
closed_before
string | null format: date-time

Inclusive upper bound on closed_date. RFC 3339 or bare YYYY-MM-DD.

Example
2026-12-31T23:59:59Z
closed_is_null
boolean | null

Match only risks whose closed_date is unset. Mutually exclusive with closed_after/closed_before.

assigned_to
array | null

Accepts UUIDs, the literal null (unassigned), and the sentinel me (the calling user, resolved server-side). Multiple values union — e.g. assigned_to=me&assigned_to=<uuid> returns rows assigned to either.

tags
array | null
page
integer format: int64
default: 1 >= 1 <= 1000000

1-indexed page number. Defaults to 1 (explicit null reads as the default); zero is rejected.

page_size
integer format: int64
default: 50 >= 1 <= 500

Rows per page. Defaults to 50 (explicit null reads as the default); zero is rejected.

order_by
string | null
free_text_contains
string | null
id_contains
string | null
overdue
boolean | null

Filter to overdue (true) or non-overdue (false) risks. Overdue means open and past due_date.

include_children
boolean | null

When true, the list includes risks that are linked under another risk (i.e. rows with a non-null parent_id). Defaults to false so registers and rollups stay collapsed.

urgency_shift
One of:
null

Return only risks whose current urgency has shifted from the urgency they were first reported at. Upgrade matches risks now at least one level more severe; Downgrade matches those now at least one level less severe. Omit to leave the filter off.

Risks linked under this parent

Paginated list envelope: { "results": [...], "pagination": {...} }.

object
pagination
required

Pagination metadata describing the slice.

object
page
required

1-indexed page number of this result slice.

integer format: int64
page_size
required

Number of items requested per page.

integer format: int64
total_items
required

Total number of matching items across all pages.

integer format: int64
total_pages
required

Total number of pages at this page size.

integer format: int64
results
required

The items on this page.

Array<object>

Register row for Organization Risks (RSKs). A Risk plus the relational data shown on the risk register: threat objectives, incident associations, tags, and comment count.

object
comments
required

Count of comments on this risk (not the comments themselves).

integer format: int64
incident_associations
required
Array<string>
Example
INC-00001
linked_children_count
required

Number of risks linked under this risk (i.e. children pointing at it). A risk is itself a linked child when risk.parent_id is set.

integer format: int64
risk
required

The core view of an Organization Risk (RSK).

Relational data — threat objectives, comments, incident associations, and tags — is exposed on RiskRegisterEntry, not here.

object
assigned_to
One of:
null
closed_date
string | null format: date-time
control_statement
string | null
created_date
required
string format: date-time
deleted_date
string | null format: date-time
description
required
string
discovered_date
required
string format: date-time
due_date
string | null format: date-time
expected_date
string | null format: date-time
id
required
string
Example
RSK-00001
impact
One of:
null
impact_reasoning
string | null
initially_reported_urgency
One of:
null
likelihood
One of:
null
likelihood_reasoning
string | null
opened_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
parent_id

When set, this risk is linked under the named parent risk.

string | null
Example
RSK-00001
remediation_task
string | null
source
string | null
status
required

The status of a risk

string
Allowed values: New Urgency Proposed Remediation Closure Proposed Closed
title
required
string
type
required
string
Allowed values: Code Configuration Control Deficiency Policy Procedural Vulnerability Third-party
updated_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
updated_date
required
string format: date-time
urgency
One of:
null
tags
required
Array<object>
object
content
required
string
creator_id
required
string format: uuid
id
required
string format: uuid
org_id
string | null format: uuid
threat_objectives
required
Array<object>

A relational struct that has a threat objective type and its relevancy to a risk.

PartialEq, Eq, and Hash are implemented manually to exclude created_date, which is metadata about when the relation was mutated — not part of the identity.

object
created_date

The time that this relation was mutated

string | null format: date-time
relevance
One of:
null
threat_objective
required

The threat objective type

string
Allowed values: Sabotage Data Disclosure Extortion Customer Targeting Resource Hijacking Fraud

Parent risk not found