How reports reach your team
Every report goes through a defined lifecycle from the moment a researcher presses Submit. All submissions — whether through your program’s dedicated page or an embedded form — enter with a New status. From there, your admin team takes ownership: reviewing the evidence, assessing severity, communicating with the researcher, and ultimately moving the report to a closed status once a decision has been made. A SuperAdmin can move a report to New – To review to signal that it has been routed and is awaiting formal assignment.Reports submitted via an embedded form are flagged automatically so you can identify them at a glance in the management view. The reporter may or may not have a registered Hackrate account at the time of submission.
The report inbox
Your report inbox is found under Reports → My Program Reports. It displays all vulnerability reports submitted to the programs you have administrative access to. The inbox is built around four distinct view modes that let you focus on exactly the subset of reports relevant to your current task.Open reports
Shows every report whose status is classified as Open — meaning it is still active and requires attention. This is the default view and the best starting point for your daily triage work.
New reports
Shows only reports in New, Needs more info, or New – To review status. This is your incoming queue: reports that are waiting for an initial review or are pending a researcher’s response to your clarification request.
All reports
Shows every report you have access to, regardless of status — including all open and closed reports. Use this when you need a complete picture of your program’s history or want to audit past decisions.
Advanced view
Opens a side-panel with granular filters so you can build custom queries across your entire report dataset. Combine any mix of filters to get exactly the slice of data you need.
Searching and filtering
A global search bar is always visible regardless of the active view mode. It searches across report ID, title, program name, status, severity, and the reporter’s alias in real time, letting you jump directly to a specific report without changing your current view. In Advanced view, a persistent side panel exposes the following filters, which can be combined freely:Available advanced filters
Available advanced filters
- From date / To date — filter by report creation date within an inclusive date range
- Programs — select one or more of your accessible programs; leave empty to include all
- Hacker alias — filter by the submitting researcher’s username
- Statuses — filter by one or more specific status names (e.g. Accepted, Resolved)
- Open / Closed — filter by status type to see only open or only closed reports
- Severities — filter by Critical, High, Medium, Low, or None
Exporting reports to CSV
The Export CSV button in the inbox header opens an export dialog that lets you select exactly which data columns to include and apply optional filters before generating the file.Available export columns
SuperAdmin users can additionally export the Summary, Description, and Impact fields, which contain the full technical content of the report. These fields are restricted to protect sensitive vulnerability details in environments where not all export recipients have SuperAdmin clearance.
Role-based report visibility
Not all team members see the same reports. Your effective role determines which statuses appear in your inbox:- SuperAdmin and StandardAdmin — full access to all 14 report statuses, including early-stage statuses like Pre-submission, New, Needs more info, and all Not Accepted variants
- Analytics — read-only access to aggregate data; cannot see reports in early triage statuses (Pre-submission, New, Needs more info, Duplicate, or any Not Accepted variant)
- Read-Only — read-only access to the same report subset as Analytics
Next steps
Report Statuses
A complete reference for all 14 statuses in the triage workflow, including what each one means and who can see it.
Triaging Reports
Step-by-step guidance for reviewing, validating, assigning, and closing reports as a company admin.
Bounty Rewards
Learn how the bounty table works, how to award payouts from the report view, and how to add bonus amounts.