In some implementations, a compliance
system may receive, from a
tracking system, a set of data structures representing a set of security vulnerabilities and indicating a corresponding set of severity levels. The compliance
system may determine a set of levels of effort, corresponding to remediating the set of security vulnerabilities. The compliance
system may provide the set of levels of effort to a
machine learning model, in order to generate a proposed change to a set of users that are responsible for remediation, and may output an indication of the proposed change. The compliance system may provide the corresponding set of severity levels and the set of levels of effort to the
machine learning model in order to generate clusters for the set of security vulnerabilities. The compliance system may output, based on the clusters, an indication of which users are assigned to which security vulnerabilities.