Incident & Breach Register Workflow
Security/data incident log: severity, root cause, GDPR-style notification deadline, closure
Incident & Breach Register Workflow gives compliance and IT security teams a dedicated register for security incidents and data breaches: log the incident the moment it is discovered, drive it through a guarded investigation workflow, and never miss a regulatory notification deadline. Built-in SLA timing and a severity-escalation signal turn the register into an early-warning tool, not just a filing cabinet.
Key Features
Incident Register
Log security incidents, data breaches or other events with category, severity (low/medium/high/critical), discovery date, affected data/systems and affected individuals.
Guarded Workflow
Open, investigating, contained and closed states with a reopen path; marking an incident contained requires a root-cause note and closing it requires a resolution summary, enforced as business-rule errors.
GDPR-Style Notification Deadline
A configurable notification window, 72 hours by default matching GDPR Article 33, counted from discovery; overdue and sent-but-late notifications are flagged and searchable.
SLA & Resolution Timing
A target time-to-close per severity tier, automatic SLA-breach detection for both closed and still-open incidents, and running days-open tracking.
Severity-Escalation Signal
A daily scheduled action groups recent incidents by category over a rolling 30-day window and flags a category for escalation review once its incident count crosses a severity-specific threshold.
Corrective Actions
Raise one or more corrective or preventive actions per incident, assign an owner and due date, and track how many are open or overdue.
Investigator Notifications
The assigned investigator is notified by activity and chatter message on assignment and reassignment, and a daily cron warns about approaching or missed notification deadlines without repeating a fresh reminder every run.
Role-Based Access
Every internal user can log incidents and manage the ones they reported or are assigned to investigate, while Incident Managers get full access to every incident and the category configuration.
Use Cases
Screenshots
01 Incidents List
02 Incident Form
05 Categories
Why Choose This Module
Security and data-protection obligations rarely fail because nobody cared; they fail because a deadline or a follow-up action got lost in email. This register keeps every incident, its notification clock and its corrective actions in one auditable place, and proactively nudges the right person before something slips.
Specifications
- Compatible: Odoo 18.0 / 19.0
- License: OPL-1
- Languages: 35+
- Author: Pokutsoft
- Dependencies: mail
- Support: odoo@gencbaris.com
- Update date: 2026-07-13
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
Discuss (mail)
|
| Lines of code | 1329 |
| Technical Name |
incident_breach_register_workflow |
| License | OPL-1 |
| Website | https://pokutsoft.com/ |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module