Policies and approval

Adopt from templates or write your own, take a policy through review, and keep a versioned approval record.

Guides · 2 min read

Auditors ask two things about a policy: does it say the right things, and can you show it was formally approved. The policy module handles both.

Adopting a policy

Start from the template library — each template is written against real control requirements and carries fields you fill in for your organisation. Or create a custom policy and write the body yourself. Either way the result is a draft in your workspace.

The approval workflow

  1. Draft — edit fields and body freely.
  2. In review — submit it; the policy is frozen for review.
  3. Active — an owner or admin approves it. Only admins can approve.
  4. Revise — move an active policy back to draft as a new version when it needs changing.

Approving snapshots the fully rendered document as an immutable version, recording the approver and timestamp. Later edits create a new version rather than altering the approved one, so the record of what was approved, and by whom, survives.

Acknowledgements

Sync your workforce roster from a connected identity provider and track which people have acknowledged which policies — the evidence that a policy was distributed, not just written.

More in Guides

Access reviews and offboardingFind access that should have been removed, and confirm independently that it actually was.Reports and the audit binderReadiness reports, the SOC 2 system description, and a one-click export of everything an auditor asks for.Team and rolesInvite people, what each role can do, and how account activity is recorded.
← All documentation