> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberopsource.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Remediation Workspace

> Learn how clients collaborate on published findings, treatments, evidence, and remediation progress.

# Remediation Workspace

The Remediation Workspace is the primary client collaboration environment for published findings and remediation activity.

It is designed around the lifecycle of a finding after Cyber Op Source has determined that the client should be able to review and act on it.

## Core workflows

The workspace can support:

* reviewing published findings,
* viewing recommended treatments,
* proposing treatment alternatives,
* working with assigned treatment owners,
* completing client actions,
* adding notes and progress updates,
* providing evidence,
* responding to evidence requests,
* reviewing activity history,
* working with documents and plans,
* using guided evidence or policy-assistance features when enabled.

## Published findings

A finding becomes visible in the Remediation Workspace through a governed publication process. Client users do not directly modify Cyber Op Source's internal finding record.

This separation allows the assessment team to preserve internal working material while presenting a stable, authorized client view.

## Treatments

A treatment represents the work used to address a finding or reduce the associated risk. Treatments may include an owner, target state, status, actions, supporting evidence, and activity history.

Client collaboration can include proposing treatment changes or completing assigned actions. Cyber Op Source retains the trusted assessment-side processing and verification responsibilities defined for the engagement.

## Evidence

Evidence may be requested or voluntarily supplied to demonstrate progress or completion. Good evidence is relevant, attributable, and sufficient to support the specific control or remediation claim.

Examples can include:

* policy or procedure excerpts,
* configuration screenshots,
* reports or exports,
* implementation records,
* approved change documentation,
* test results,
* training records,
* architecture or workflow documentation.

Do not upload unrelated sensitive information simply because the system allows file attachments.

## Activity timeline

Activity history helps users understand what happened over time. Client-facing activity is presented as meaningful human-readable events rather than raw system objects.

Examples may include:

* treatment released to the client,
* client note added,
* proposal submitted,
* action completed,
* evidence provided,
* status updated,
* review completed.

## Security boundary

The Remediation Workspace is intentionally not a direct editor for internal assessment records. Client-safe reads and governed client commands are separated so that the application can support collaboration without granting unrestricted write access to assessment data.

## Learn more

* [Working Findings](/user-guides/working-findings)
* [Treatment Collaboration](/user-guides/treatment-collaboration)
* [Providing Evidence](/user-guides/providing-evidence)
* [Data Handling](/security-and-trust/data-handling)
