scf_add_custom_risk_control
Link a scoped control to a custom risk in your organization. Requires the control to be in-scope and editor+ role.
Instructions
Link a scoped control to a custom risk (write — editor+ role). The control must already be scoped (in-scope) for this organization.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| org_id | Yes | Organization UUID — obtain from scf_list_organizations | |
| scf_id | Yes | SCF control ID to link (e.g., 'AST-01') — obtain from scf_list_scoped_controls | |
| risk_code | Yes | Custom risk code in R-ORG-N format (e.g., 'R-ORG-1') — obtain from scf_list_custom_risks |