Policies & Documents
Build a versioned policy library, approve documents through a clear lifecycle, and prove your staff have read them.
The Policies & Documents module is where you create and maintain your policy library. You can start from built-in templates or write from scratch, move each policy through an approval lifecycle, keep a full version history, and collect staff acknowledgements once a policy is published.
Draft, approve, and acknowledge
Draft a policy
Create a policy from a built-in template or from scratch. Assign an owner and link it to related risks and controls.
Move it through review
Progress the policy through its lifecycle — Draft, then Review, then Approved or Published — so approval is deliberate and recorded.
Publish and share for acknowledgement
Once published, generate a shareable acknowledgement link that staff open to read the policy and confirm they've understood it — even without a login.
Track who has acknowledged
See who has confirmed they've read each policy, so you can follow up with anyone outstanding.
Key concepts
- Lifecycle — Draft to Review to Approved/Published keeps documents from being treated as final before they're signed off.
- Versioning — every change is versioned, so you keep a full history and can show what applied at any point in time.
- Ownership and links — each policy has an owner and connects to the related risks and controls it supports.
- Acknowledgements — a shareable link lets staff read and confirm understanding without needing an account.
Works with
- Controls — link policies to the controls they implement. See Controls.
- Risks — connect policies to the risks they help treat. See Risk Register.
- Evidence — published policies and acknowledgements act as evidence. See Evidence.