the device's id
LOW, MEDIUM or HIGH, or empty to forget the
assessment (which sends nothing)
Optionalreason: unknown
CAEP's risk_reason
Optionaloptions: any
source (risk by default, compromise or admin),
actor and initiatingEntity
{ ok, device, previous, level, changed }, or a refusal
Sets a device's risk level, sending CAEP risk-level-change with principal DEVICE when the level moved.