Project risks and estimate vs. actual hours
Current tracks two different kinds of "are we going to be OK?" on a project. Risks capture what could go wrong — the vendor that might be late, the firewall you might not get access to — each with a severity, an owner, a mitigation plan, and the day someone will look at it again. They live on their own Risks tab. Estimated hours capture how long the work should take, so that when it's done you can compare plan against reality; those stay on the project page. Neither one is ever visible to a partner.
Where the Risks board is
Risks is the last tab in the view strip that runs across the top of the work views: Overview, Timeline, Board, List, Calendar, Dependencies, What-if, Risks. The board follows whichever project is pinned in the bar above it, so changing the project up there changes the board underneath. With All projects pinned you get the portfolio version instead: every risk that isn't closed, on every project you can see, as a card carrying its project's name — and clicking that name pins the project and drops you on its own board.
A project's Overview page keeps a Risks line of its own: the count in each lane, how many are past their review date, and an Open the board button that lands on this project's board with nothing to set.
Who can flag a risk, and who can change one
- +Any staff member can flag a risk. Engineers included — if you can see the project, you can say what worries you about it. That is the change from the old register, which only managers could write to.
- +You can edit, close, and delete the risks you flagged.
- +Project managers and tenant admins can edit, close, and delete every risk on the project, and they are the only ones who can pin a project's status by hand.
- +Partner viewers and account executives are refused project risks entirely, reading and writing both, at the database layer rather than by hiding buttons. The Risks tab is not in a partner's view strip at all.
The three lanes
Lanes are how serious a risk is, not where it stands. Drag a card from one lane to another to change it; the move saves as you drop it and the toast offers Undo. The number beside each lane header is how many cards are in it.
| Lane | What it means |
|---|---|
| Red | Threatens the date, the budget, or the relationship. Somebody acts this week. |
| Orange | Real, and worth watching. It has an owner and a date to look again. |
| Green | Logged so it is not forgotten. No action needed today. |
Likelihood and impact are still there, each Low, Med, or High, multiplying out to a score of 1 to 9 in the editor. The lane is now its own field on top of that, so you can put a low-probability risk in red when the consequence is a lost renewal. A new risk starts in the lane you flagged it from, or orange if you didn't pick one. Risks that already existed when the board arrived were sorted by their old score: 6 and up went to red, 3 to 5 to orange, the rest to green. The 3×3 likelihood-by-impact matrix still exists in Reports, on the Risk lens.
Flag a risk
- 1Pin the project, then open RisksEvery lane has a Flag a risk button at its foot, and the lane you press it in sets the severity for you. The button under the empty board does the same thing in orange.
- 2Give it a short titleThe only required field. "Vendor lead time may slip past the cutover" carries more than "Vendor".
- 3Set the severity and pick an ownerThe owner is any staff member. Leave it on No owner and the card says so until somebody takes it; naming someone else sends them a bell that they own it.
- 4Say what you'll do about itLikelihood and impact, then the mitigation plan. The plan's first line shows on the card, so put the action first.
- 5Check the review dateIt starts fourteen days out. Move it to the day the answer will actually be known.
- 6Click Flag itThe card lands in its lane. On an Autotask-synced project an internal note about the new risk is filed on the PSA project as well.
There is a second door, for the moment you notice something rather than the moment you sit down to write it up. Open any task and the top row of the drawer, next to the copy-link button, carries Flag a risk: a small popover with the task's name already in the title, three severity buttons, and one line for the note. It files the risk against that task with you as the owner, and the card on the board carries a chip that opens the task again.
Where a risk stands: open, mitigating, accepted, closed
Severity is one axis and the life cycle is the other. The marker on the card moves along when you click it: open, then mitigating, then accepted, then closed, then back around to open. Only the person who flagged the risk and the project's managers can move it.
| Status | What it means | Where the card sits |
|---|---|---|
| Open | Live and unaddressed | In its severity lane |
| Mitigating | You're actively working the mitigation | In its severity lane |
| Accepted | You've decided to live with it | In its severity lane, dimmed |
| Closed | It can't hurt you any more | In the Resolved rail under the board |
Review dates, and what happens when one passes
Every risk carries the day somebody will look at it again. It defaults to fourteen days out and you can set it to anything, including nothing. The date rides on the card next to a small calendar icon.
- +Once the date is past, it turns amber and the card gains a Stale marker. The strip under the hero counts them as Review overdue.
- +Reviewed, on the card, pushes the date out another fourteen days and clears the marker.
- +The nightly pass sends the owner a bell that their risk is past review, and no more than one of those every three days.
- +Three days past the date with nobody reviewing it, the project lead gets an escalation. That one fires once per risk.
The Detected tray
Down the right of the board sits Detected: what Current noticed on its own, waiting for a person to agree. Automation never writes a card. It puts a suggestion here, and you decide whether it is real.
- +Current Score factors. Whatever is pulling this project's score down arrives as a signal, red where the deduction is 15 points or more.
- +The nightly AI read of the project — the same risks the AI panel writes, one signal each, at the severity the AI gave them.
- +Stalled tasks, from a schedule watcher that arrived with the board.
Add to board turns a signal into a real card at the same severity, linked to the task where there is one, owned by you, and opens the editor on it so it gets a plan and the right owner instead of sitting there half-written. Not now hides the signal in your browser only, with an Undo; it is a personal "I've seen that", not a decision for the team, and nothing is lost if it comes back. A signal already on the board stops being offered.
What counts as a stalled task
The watcher sizes its patience to the task instead of using one number for everything, because five quiet days mean nothing on a six-month migration and mean a great deal on a week-long install.
- +It reads the task's own window in working days (its start and end dates, weekends taken off at five days in seven), then takes a quarter of that as the quiet threshold — never under 2 working days, never over 10.
- +Quiet for the threshold, with the task at least halfway through its window or its due date inside the threshold, marks it orange.
- +Quiet for twice the threshold marks it red. A red-stalled task on the critical path is one of the things Current Score reads as work stopped.
- +Activity means any of these: your PSA's last activity stamp on the task, an edit in Current, a comment, or a time entry. A new task counts its own creation, so nothing is stalled from birth.
- +The mark clears itself when work resumes or the task is done. Tasks missing a start or end date are never marked, and neither are archived tasks or tasks on a completed project.
One health number, and pinning it by hand
The panel at the top of the board is the project's Current Score: the verdict word, the number out of 100, the trend line, and the three factors costing the most points. It is the same number the project page and Portfolio show, because all of them read the same formula. Four of that formula's factors come from this board — open red risks, risks past their review date, stalled tasks, and work stopped. See "What is Current Score?" for what each one costs.
Sometimes the arithmetic and the truth disagree. A project manager or tenant admin can press Set status by hand, pick a color, and type a reason. The reason is required and the team reads it on the board. The pinned color then stands in for the computed one everywhere, including the project page and Portfolio. The score itself does not move: the pin colors the verdict, it does not rewrite the arithmetic.
- +A pin that is worse than the computed color holds until somebody clears it. If you know the project is off track, Current will not talk you out of it.
- +A pin that is better than the computed color lapses after seven days, and breaks earlier if the score falls more than five points below where it stood when you pinned it.
- +Clear the pin from the same panel whenever you like. Nightly housekeeping also clears the lapsed and broken ones.
Who hears about a risk
| What fires it | Who gets it |
|---|---|
| Somebody made you the owner of a live risk | The new owner. Flagging one for yourself stays silent. |
| A risk arrives red, or is dragged into red | The owner and the project lead, at most once per risk per 20 hours |
| A risk passed its review date | The owner, no more than every three days |
| A risk is three days past review and still untouched | The project lead, once |
| The project changed color | The project lead, in both directions, including the move back to on track |
All five land in the bell. On a project mapped to a Teams channel they post there as well, with an @mention for the person if they have Teams notifications turned on. None of the five sends email.
What your PSA sees
On an Autotask-synced project, three moments file a note on the PSA project: a risk opened, a risk raised to red, a risk closed. The note is titled "[Current risk]" with the event and the risk title, and carries the description as its body. It is internal, always — where Current cannot confirm an internal note type in your Autotask zone it files nothing rather than let a risk note reach a client portal. ConnectWise and HaloPSA don't have this yet, so nothing is written and nothing errors; on a Current-native project nothing is attempted at all. The note is a courtesy copy either way: it is best effort, and a failure never reaches the person who flagged the risk, because the risk is already saved here.
Put estimated hours on a task
- 1Open the taskFrom the project page, the Kanban board, or the Timeline — they all open the same task drawer.
- 2Find Estimated hours in the Details sectionThe field steps in quarter-hours and accepts 0 to 9,999. Anything higher is clamped down to 9,999 when it saves. Leave it empty and the task reads "Not estimated."
- 3Click SaveOn a PSA-synced task the footer button reads Save & sync, and the estimate is written to the PSA task's estimated hours at the same time.
Estimate at the task level, not the project level — that's what makes the rest of the numbers work. The Schedule board puts each task's whole estimated-hours figure on its due date (end date) as a single chip — it does not spread the hours across the days the task spans. Daily capacity is the person's weekly target divided by 5 (a 40-hour target = 8 hours a day), and PTO, holiday and blocked days are zeroed. A task with no estimate still shows as a chip but adds zero hours to the bar, which is why a fully-booked engineer can look free; a task with no assignee or no due date isn't on the grid at all — it sits in the unscheduled tray.
Reading estimate vs. actual
The Estimate vs actual panel sits on the project page beside Budget & actuals. It lists every task that has an estimate or has logged time, with four columns: Task, Est., Actual and Variance.
- +Variance = actual − estimate. A red +6h chip means the task ran six hours over; a green −2h chip means it came in under. Hover the chip for the percentage.
- +Actual hours follow Current's source-of-truth rule: if your PSA reports worked hours for the task, that's what's shown; otherwise it's the time logged in Current. So a synced project where techs log time in the PSA still reads correctly here.
- +Where the figure comes from Current's own time entries, time a manager rejected and time your PSA voided are both left out, so a task can read fewer actual hours than it did before 26 July 2026 and a variance chip can turn from red to green. Where the figure is your PSA's own worked hours, it is your PSA's number: it already leaves out anything the PSA voided, but time a manager rejected can still be inside it, because Current does not re-cut a figure the PSA reported. The same is true of the totals in a project's close-out pack.
- +The Total row's variance only counts tasks that actually carry an estimate — a task nobody estimated but everybody worked on can't fake an over-run.
- +Inside a task, the time section shows the same story live: "4h logged of 6h estimated," with the bar turning amber at 80% of the estimate and red once you pass it.
Estimate over-run is not budget burn
These two panels sit side by side and get confused constantly. They measure different things and only one of them moves a project's health score.
| Estimate vs actual | Budget & actuals | |
|---|---|---|
| Question it answers | Did we plan the work correctly? | Are we consuming the money? |
| Compares | Task estimates vs. hours worked | Budget hours (and $) vs. hours logged |
| Set where | Estimated hours, task by task | Budget hours, rate and budget $ on the project |
| Feeds the health score | No | Only via the PSA-reported budget % |
Feed last quarter's actuals back into your next quote
A single over-run is noise; the same task running 40% long on five projects is a quoting problem. On the Playbooks page, managers see a Hours learning panel — "N suggestions across your templates" — comparing each template task's estimate against how long it really ran on completed projects cloned from that template.
- +A suggestion appears only once at least 3 completed, hours-bearing instances of that task exist across clones of the template — normally 3 completed projects, but same-named tasks inside one project each count as an instance.
- +It only surfaces when reality is off by 15% or more, or when the template task has no estimate at all.
- +The suggested figure is the average actual, rounded to the nearest quarter-hour and clamped to the range Apply accepts (0.25h to 999h); the row also shows the median so you can judge the spread.
- +Apply writes it onto the template task, so the next clone starts from an estimate based on actual hours. Dismiss hides it until the numbers change.
- +Only projects cloned after Current began stamping template lineage count as evidence — suggestions build up as new projects complete.
- +On a task whose actual hours come from Current's own time entries, rejected and voided time no longer counts toward the average, so a suggestion can read slightly lower than it did before 26 July 2026. On a task your PSA reported worked hours for, the suggestion uses the PSA's figure and is unchanged.
For the wider view, Reports carries a Risk report that keeps two sources separate: risks flagged by Current's AI analysis (severity only — not register entries) and the risks your PMs logged by hand, as a heatmap, a status breakdown and a full register. Portfolio can also sort by Open risks or filter to projects that have any. See "Reports: every report on one date range" and "Project templates and PMI playbooks."
