Policies

Policies state how your organisation works and what it commits to — this chapter walks through drafting one, setting its review cycle, routing it for approval and keeping it under review.

A policy is a written statement of intent: this is what we do, and what staff and auditors can hold us to. The module carries one through its whole life — draft, review, approval, re-review, retirement — and writes every status change to the audit log. It records that work; it does not make the organisation compliant on its own.

Who uses it

The screenshots here were taken as a Contributor, so Approve and delete are absent.

What's on this screen

Open Policies from the Compliance group in the left sidebar; the register opens at /policies. The header carries the title and three controls: a List / Grouped view toggle, Review Triage (AI), and the navy Create Policy button. Below sit the All Statuses and All Levels dropdowns, then a Search policies… box with its Search button.

The table lists every policy — Title, Status (a coloured badge — grey Draft, green Approved), Level, Owner, Version, Controls mapped, and the effective, review and updated dates. Each row begins with a tick-box and ends with a pencil and an eye under Actions.

  1. Choose how the register is drawn: List is the flat table shown here; Grouped redraws it with one section per governance level.
  2. Select Review Triage (AI) to have Aegis rank policies and procedures by review date and narrate a plan — the ranking comes from the dates, not the model. Saved briefings collect below the table.
  3. Select Create Policy. The Create New Policy dialog opens over the page — covered next.
  4. Narrow the register with All Levels, marked here, or All Statuses beside it; the rows reload to matches only. Approvers also get Pending My Approval in the status list.
  5. Type part of a title into Search policies… and select Search. The table filters to matches.
  6. On any row, select the eye to open the policy on its Document information & details tab, or the pencil to open it straight on Content. The title is a link to the same Document information & details tab.
The Policies register — /policies.
The Policies register — /policies.

Creating a policy

The dialog is split into Policy Details and Timeline & Review, with Cancel and Create Policy fixed to the foot as you scroll.

  1. Enter a Policy Title. Required, as the red asterisk shows.
  2. Write the Policy Content. The grey # Purpose / # Scope / # Policy Statement outline is placeholder text that vanishes as you type (or the box opens pre-filled from your company document template, where one is set). Markdown is supported. Also required.
  3. Set the Level — the governance level the Grouped view groups by. It starts at Unclassified; the other choices are Strategic, Tactical and Operational.
  4. Under Timeline & Review, set an optional Effective Date. Below the edge of this capture sit a Review Date and the Review Cycle presets, described under Changing a policy's details.
  5. Select Create Policy. The policy is saved as a Draft and the register refreshes. Cancel or the × discards what you typed.
Creating a policy — /policies.
Creating a policy — /policies.
Only title and content are required

Level, dates and review cycle carry defaults — capture the draft while it is fresh and refine everything later through Edit details.

The policy's own page

A policy opens at /policies/[id]. The header shows the title, status badge, version and last-updated date; a status line on the right reads Ready between AI jobs. Under it runs the toolbar — seven icon buttons, each named in its tooltip — then the tab strip: Document information & details, Content, AI Enhance, Translations, Version history, Controls and Evidences. The AI Enhance tab is present only because an enhancement has been run on this policy; an Improve Writing tab appears the same way after that aid runs. The first tab opens with an Edit details button, the DETAILS, DATES and Approval History cards, a collapsible Changes since last approved version panel and Required Readers.

  1. Select Edit (the pencil) to change the body in place — on a Draft only; otherwise its tooltip reads "Policy must be in Draft status to edit content."
  2. The two violet buttons beside it are the writing aids, on drafts only: Improve Writing rewrites for grammar, clarity and tone; AI Enhance proposes further compliant detail. Each result lands on its own tab as suggestions you apply or dismiss. The navy button after them is the lifecycle action — Submit for Review on a draft.
  3. Select Export to Word to download the policy as a .docx. Upload Word/PDF sends an edited file back into the draft — it first shows what would change, for you to confirm or cancel. Help explains the toolbar.
  4. Select Edit details to change the title, level, dates and review cycle: the cards are replaced in place by a form — covered next. For the level alone, Classify in the DETAILS card sets it without opening the form.
  5. Expand Changes since last approved version to see what has moved — useful when writing a change summary.
  6. Under Required Readers, tick Everyone must read this policy, or pick Required roles and named people through Search users…, then select Save Required Readers.
A policy's Document information & details tab — /policies/[id].
A policy's Document information & details tab — /policies/[id].

Changing a policy's details

Edit details replaces the three cards with a form on the same page — there is no dialog. The heading reads Edit policy details, with the reminder "The policy text is edited on the Content tab" underneath. Cancel and Save changes sit at the foot of the form, below the edge of this capture. While the form is open the address bar reads /policies/[id]?tab=details&edit=1, so the editor can be linked to directly.

  1. Change the Policy Title — the one field the form insists on: emptying it and saving returns "Title is required".
  2. Set the LevelUnclassified, Strategic, Tactical or Operational; the hint spells out what each means.
  3. Set the Effective Date — blank means the policy takes effect on approval.
  4. Set the Review Date — when the policy is next due for review. It is the date Review Triage (AI) ranks on, and this is the one place to move it.
  5. Pick a Review Cycle preset — Monthly (30 days), Quarterly (90, marked Recommended), Bi-annual (180), Annual (365) or Custom cycle. The create form offers the same presets.
Editing a policy's details in place — /policies/[id]?tab=details&edit=1.
Editing a policy's details in place — /policies/[id]?tab=details&edit=1.

Finish with Save changes at the foot of the form. A "Policy details updated" toast confirms it and the cards return with the new values; Cancel discards what you typed. Unlike the body, details can be edited at any status — an approved policy need not return to Draft for a new review date.

The approval lifecycle

A policy carries one status at a time, shown as a badge wherever it appears.

Status What it means What the toolbar offers
Draft Being written. Not binding. Submit for Review
In Review Waiting on an approver. Approve for Manager and above; Return to Draft for editors
Partially Approved Some, not all, steps of a multi-approver chain have signed off (only where that chain is switched on for your tenant). Nothing — the remaining approvers act in the approval-chain panel
Approved The current binding version. Revise and Retire Policy
Retired No longer in force, kept for the record. Reactivate

In exports and audit-log entries these read as Draft, InReview, PartiallyApproved, Approved and Retired. Revise is the way to change an approved policy: it asks for a change summary, snapshots the text into Version history and returns the policy to Draft; each submission and approval lands in Approval History.

Nothing moves the review date for you

Neither editing nor approval advances the Review Date, and Review Triage (AI) ranks on that stored date. A policy whose review you have completed keeps reading as overdue until you open Edit details and set the next date yourself.

Linking evidence and discussing a policy

The Evidences tab ties a policy to evidence (documents that show a control works), held in Evidence. Below the tab strip — on whichever tab is open — sits a Collaboration section carrying the policy's comments and review requests.

  1. Select Evidences, the last tab. The panel header reads LINKED EVIDENCE with the count in brackets.
  2. Select AI search evidence to have Aegis propose items from your library that appear to support this policy — you review each suggestion and decide.
  3. Or select + Link Evidence to search the library and pick items yourself.
  4. Until something is linked, the panel reads "No evidence linked yet." — as below.
  5. Scroll to Collaboration to read existing comments and add your own in the Write a comment… box.
The Evidences tab, with no evidence linked yet — /policies/[id].
The Evidences tab, with no evidence linked yet — /policies/[id].

The AI assist

Policies has five AI aids: Review Triage (AI) on the register, Improve Writing and AI Enhance on a draft, AI search evidence on the Evidences tab, and the upload preview's summary of what a file would change. Each output is a suggestion: a person reads it, edits it and decides — nothing is approved, published or linked without that decision. Where AI is switched off for your tenant, the buttons are absent and every task still works by hand.

Tips and limits

Where this connects

A policy maps to controls through its Controls tab, feeding the coverage in Compliance frameworks and Control mapping. The step-by-step how belongs in Procedures; the proof it is followed lives in Evidence. A policy can treat a risk, comments work as in Collaboration, and every status change reaches the Audit log.