Policies and approval
Adopt from templates or write your own, take a policy through review, and keep a versioned approval record.
Guides · 2 min read
Auditors ask two things about a policy: does it say the right things, and can you show it was formally approved. The policy module handles both.
Adopting a policy
Start from the template library — each template is written against real control requirements and carries fields you fill in for your organisation. Or create a custom policy and write the body yourself. Either way the result is a draft in your workspace.
The approval workflow
- Draft — edit fields and body freely.
- In review — submit it; the policy is frozen for review.
- Active — an owner or admin approves it. Only admins can approve.
- Revise — move an active policy back to draft as a new version when it needs changing.
Approving snapshots the fully rendered document as an immutable version, recording the approver and timestamp. Later edits create a new version rather than altering the approved one, so the record of what was approved, and by whom, survives.
Acknowledgements
Sync your workforce roster from a connected identity provider and track which people have acknowledged which policies — the evidence that a policy was distributed, not just written.
More in Guides