Request a Response

Benefits

The Request a Response (RaR) feature allows researchers to formally request an update on a submission from either Bugcrowd’s triage team or customer when the submission needs attention. Using RaR promotes timely communication and helps submissions progress smoothly toward resolution.

The Request a Response feature enables you to:

  • Ask a follow-up question about your submission.
  • Request a re-evaluation of the submission’s status or decision.
  • Provide new or additional information relevant to the finding.
  • Withdraw a request at any time.

This feature helps maintain transparent, two-way communication between Researchers and Customers.

Eligibility

You can open a RaR for submissions in the following substates: Triaged, Unresolved, Resolved, Not Applicable, Out of Scope, Not Reproducible, and Informational.

Please note: The “Not Applicable” substate is available only for requests directed to Bugcrowd, not Customers. Researchers who are platform-banned or program-banned cannot raise or withdraw RaRs.

Limits

  • Account Active Limit: You are allowed a limited number of open RaRs simultaneously. This limit is visible within the platform (e.g., “Account active limit: 1 of 2 available”). Withdrawing an active RaR immediately frees up 1 account slot, allowing you to raise a RaR on another submission.
  • Submission Limit: Each submission can have a maximum of two (2) RaRs opened throughout its lifecycle. Withdrawn RaRs permanently count toward this 2-request limit per submission.
  • Limits Example: If you withdraw an active RaR on Submission A, your Account Active limit increases by 1 slot. However, the withdrawn RaR remains counted against Submission A’s lifetime limit.

Collaboration RaR Limits

  • Shared Submission Limit: Researchers maintain individual account quotas, but the 2-request limit is enforced per submission.
  • Pending Collaborations: Only the primary researcher’s RaRs count. If they exhaust the 2-request limit before the collaborator accepts, neither researcher can open a RaR on that submission, even if the collaboration is accepted after an RaR was created.
  • Accepted Collaborations: RaR attempts from either researcher count toward the shared submission limit. Once 2 requests on a same submission are reached, both researchers are restricted from opening a new RaR on that submission.
  • Simultaneous Attempts: Real-time count validation prevents simultaneous requests from exceeding the submission quota.

How to Request a Response

  1. Locate the Submission: Go to the submission that requires an update.
  2. Open the Request: Click “Submit a request” within the submission view.
  3. Confirm: Review the prompt and confirm your request. Once submitted, the relevant party (Bugcrowd or Customer) is notified automatically.

Request a response UI Example UI: Submit a request screen with RaR quota shown

Withdrawing a Request

You can withdraw an active RaR directly from the submission page at any time:

  • Navigate to Activity field of the submission containing your active RaR and click Withdraw request.

Withdraw request

  • Select a required withdrawal reason from the list (if Other is selected, you must enter a custom reason in the text box provided).
  • Review and confirm the withdrawal prompt.

What happens upon withdrawal:

  • Review in Progress: If an Application Security Engineer (ASE) or customer is actively reviewing the request, the confirmation prompt notifies you that withdrawing will cancel the review in progress. Cancelling the prompt leaves the request active.
  • Slot & Queue Position: Your active account slot is freed immediately. Withdrawn requests cannot be restored or re-opened; submitting a new RaR on the same submission places it at the back of the RaR queue rather than regaining its previous position.
  • Limits & Logging: The withdrawn request permanently counts toward the submission’s 2-request lifetime limit. You will receive a confirmation email, and an entry recording the withdrawal reason will be logged in the submission’s Activity feed.

Tracking and Managing Requests

Finding Active and Withdrawn Requests

  1. Go to the Submissions page under the Work tab.
  2. Use filters or search tokens to find active or withdrawn requests:
    • Requested-to:present – View all submissions with an open RaR.
    • Requested-to:none – View submissions without active RaRs.
    • requested-to:bugcrowd or requested-to:customer – Filter by recipient.
    • rar_withdrawal:true - Filter or search for withdrawn RaRs across the platform.

Visibility and Quota Tracking

  • The platform displays your remaining RaR quota or the entire account (e.g., “Account active limit: 2 of 2 available”) and also for the specific submission lifecycle (e.g., Submission limit: 1 of 2 available).
  • If both your active account limit and submission limit are reached simultaneously, the UI prioritizes and displays the submission limit message.
  • For each active RaR, you can view the date it was created, so you can track how long it has been open.

Activity Tracking

All RaR activity - including requests raised, responses provided, and requests withdrawn - is recorded in the submission’s Activity feed. Withdrawn RaRs appear as expandable items in the feed, allowing you to view past request history and the selected withdrawal reason.

Tips

  • Use RaR thoughtfully – clear, concise requests are more likely to receive fast, constructive responses.
  • Avoid opening multiple requests on the same issue unless you have new information to share.
  • Check your Activity for updates before opening another RaR.