Procedures

A policy says what your organisation commits to; a procedure says how people actually carry it out — written, versioned, reviewed, acknowledged and mapped to controls like any other governance document.

A procedure is the operational layer beneath a policy. Where a policy says "all production changes must be approved", the procedure tells the change manager what to check, in what order, and what to record. Procedures follow the same lifecycle as policies — Draft, In Review, Approved, Retired — and live under COMPLIANCE in the left menu, at /procedures.

Who uses it

Anyone signed in can read the register. A Contributor can create a procedure, edit a draft, run the AI actions and move it through the lifecycle — submit for review, return to draft, revise, retire and reactivate. Approving, rejecting and deleting take a Manager or Admin. Where your organisation has configured designated approvers, the person approving must also be named there — by user or by role; where it has not, the Manager and Admin roles carry the right on their own. A Viewer sees everything read-only: Create Procedure is only rendered from Contributor upwards, and /procedures/new redirects a Viewer to /unauthorized.

What's on this screen

The register at /procedures is one page with one table. The header reads Procedures, "Manage operational procedures and SOPs"; on the right sit a List / Grouped view toggle and the navy Create Procedure button. Below them is the filter row — All Statuses, All Levels, and a Search procedures... box with a Search button. The filters combine.

The table runs a selection checkbox, Title, Status (a coloured chip — grey Draft, amber In Review, green Approved, darker grey Retired), Level (a pill), Owner, Version, Parent Policy, Effective Date, Updated and Actions, which holds a pencil and an eye. The capture was taken as a Contributor in a test organisation: no bin in Actions (that appears from Manager upwards), seeded rows, mostly Unclassified, and dashes where a real organisation would carry a parent policy and an effective date.

  1. Use the List / Grouped toggle to switch between the flat table and a register grouped by governance level. The page changes in place.
  2. Select Create Procedure to reach the full-page create form at /procedures/new.
  3. Choose a value in All Levels to narrow the table to one governance level; it refetches immediately. All Statuses does the same for lifecycle state.
  4. Type a word into Search procedures... and select Search. Only titles containing that word remain, within whatever the dropdowns filter.
  5. Select a Title to open that procedure on the Document information & details tab; clicking elsewhere in the row opens the Content tab instead.
  6. Or use the row actions: the eye opens the details tab, the pencil the Content tab. A Manager also sees a bin, which asks for confirmation first.
The Procedures register with its view toggle, filters and table — /procedures.
The Procedures register with its view toggle, filters and table — /procedures.
Deletion cannot be undone from the app

The bin icon and the bulk Delete procedure action take the procedure out of the register and out of the AI assistant's search index. Both ask for confirmation first, and neither can be reversed from the interface. To keep the document on the record while showing it is no longer in force, use Retire instead.

Creating a procedure

Create Procedure opens a dedicated page, not a popup, headed Create New Procedure: Procedure Details and Timeline side by side, with a Content card beneath. Only Title and Content are required — each carries a red asterisk.

  1. Enter a Title — the name that appears in the register.
  2. Optionally type a Category; the placeholder suggests IT Operations, HR or Security.
  3. Optionally choose a Parent Policy. The dropdown opens on None (standalone) and lists your policies.
  4. Set a Level. It opens on Unclassified; the helper text explains the hierarchy — strategic sets direction, tactical translates it into standards, operational covers day-to-day work instructions. The level drives the Grouped view.
  5. In Timeline, set an Effective Date — when the procedure becomes binding — and adjust the Review Cycle, pre-filled with 365 days.
  6. Write the body in Content: the Edit tab has a formatting toolbar and the Preview tab shows the result. Where your organisation has set a company document template, the editor arrives pre-filled from it. Select Create Procedure at the foot of the page — the procedure is saved as a Draft and you land on its workspace.
The full-page procedure create form — /procedures/new.
The full-page procedure create form — /procedures/new.

The procedure workspace

The detail page at /procedures/{id} is a tabbed workspace. The header carries the title with its status chip, then a "Version 1.0 • Last updated …" line whose right-hand end shows the AI status — Ready when idle, progress or an error while a job runs.

Under that sits one row of action buttons. The row never wraps: the labels appear only on a very wide window (from about 1700 pixels across) and below that the buttons are icons only, as in the figure — hover one, or reach it by keyboard, to read its name. This procedure is In Review, so the row is Edit (greyed out — editing is draft-only), Review & Draft, Return to Draft, Export to Word and Help. A Draft adds Improve Writing, AI Enhance and Upload Word/PDF, and shows Submit for Review instead.

The tab row is the workspace: Document information & details, Content, Document Review, Translations, Version history, Controls and Evidences. AI result tabs join the row only once that action has been run — Document Review is here because a Review & Draft has already been run on this procedure, and Improve Writing and AI Enhance would appear the same way. The details tab holds three cards, ending in APPROVAL STATUS: Awaiting Approval above an Approval History still empty here. Below them sit the collapsed Changes since last approved version panel and Required Readers.

  1. Select Edit (the pencil) to open the body on the Content tab. It works on a Draft only; here it is greyed out.
  2. Select Review & Draft (the clipboard with a tick) to start the AI review assistant. A dialog opens and writes the review out as it goes; when it finishes, the result is kept on a Document Review tab. It is never written into the procedure — you copy across what you want.
  3. Select Export to Word (the down arrow) to download the body as a .docx. On a Draft, Upload Word/PDF beside it brings the edited file back.
  4. Select Help (the question mark, always last) to read what every button in the toolbar does.
  5. Expand Changes since last approved version before you submit or approve — on one never yet approved, there is nothing to compare against.
  6. Under Required Readers, tick Everyone must read this procedure, or use the Required roles checkboxes and the Required individual users search. Select Save Required Readers: a confirmation appears and the Read By list refreshes.
A procedure workspace on its Document information & details tab — /procedures/[id].
A procedure workspace on its Document information & details tab — /procedures/[id].

Review and approval

Lifecycle transitions live in the toolbar; the decision itself is taken on the details tab.

  1. From a Draft, select Submit for Review: the chip turns amber, Approval Status becomes Awaiting Approval, and a Submitted for Review entry joins the history.
  2. An eligible approver opens the details tab, where the APPROVAL STATUS card names the designated approvers, and selects Review & Approve. The Review Procedure dialog offers Approve (optional comments) or Reject, which needs a reason — the owner is notified with it and the procedure returns to Draft.
  3. On an Approved procedure the toolbar offers Revise — a change summary, a snapshot into the version history, a version bump, back to Draft — and Retire, in red. Reactivate returns a retired procedure to Draft. While In Review, anyone who can edit may pull it back with Return to Draft.
Status What it means Who can move it on
Draft Being written; the only editable status. Contributor+ submits for review.
In Review Awaiting a decision. A designated approver (Manager+) approves or rejects; Contributor+ can return it to Draft.
Approved Published and binding. Contributor+ revises or retires it.
Retired Kept for the record, not in force. Contributor+ can reactivate it.

Acknowledgements, controls and evidence

The Read By section is always there. Anyone signed in who has not yet confirmed sees a Mark as Read button; selecting it replaces the button with "You have acknowledged this procedure" and adds them to the list with the date and time. Once a required reader list is saved, the section also shows a running count — "3 of 8 acknowledged" — above a must-read list naming who is still outstanding. Four tabs then connect the procedure outwards.

The AI assist

Three AI actions sit in the toolbar, each parking its result on its own tab instead of changing the procedure. Improve Writing (draft only) rewrites the body section by section for clarity. AI Enhance (draft only) suggests improvements, including framework controls it thinks the procedure should map to. Review & Draft works in any status: it reads the procedure alongside its parent policy and mapped controls and drafts text for the gaps it finds.

One job runs at a time: the header status text shows progress and the other AI buttons grey out, though Export to Word stays available. Every AI action is logged against your organisation's AI usage, and a person reviews each suggestion and decides — the AI never edits, approves, publishes or retires a procedure on its own.

Tips and limits

Where this connects

Procedures implement Policies and satisfy controls in Compliance frameworks. Proof that one is followed belongs in Evidence; for records attached to a live event, see Playbooks. Approvals, acknowledgements and status changes appear in the Audit log; overdue reviews surface in Action items.