Included in the platform
Policy authoring that humans and agents share
Author with a modern editor. Route approvals to the right owner with proper delegations. Version every change. Publish to your trust center in one click — included with the Compliance Platform.
What you get
Modern editor
Inline rich text, embeds, callouts, and tables. Agents read and edit the same surface humans do.
Approval workflow
Multi-step approvals with explicit accountability. Approvers see only the diff that needs their attention.
Version control
Every change diffable, every prior version restorable. Comment threads anchored to specific lines.
Delegations
When an owner goes out, route their approvals to a backup without breaking audit trails.
Framework crosswalks
Each section maps to the controls it supports across frameworks — reuse one policy across SOC 2, ISO, and HIPAA.
Publish to your trust center
Approved policies appear on your public trust page (or branded trust center via the Trust module) automatically. Buyers see what's current; you don't maintain a parallel doc.
Agents at work
Agents that draft, review, and harmonize
Policy work is one of the easiest places to put agents to work productively.
- Draft new policies aligned to one or many frameworks
- Reconcile language across overlapping policies
- Suggest control mappings for each section
- Open review tasks when frameworks publish updates
Frameworks supported
SOC 2 CC2 seriesISO 27001 A.5HIPAA Privacy & Security RulesNIST 800-53 family
Pricing for this module
Policy Management
Included in the Compliance Platform — no separate purchase needed.
Policy Management — frequently asked questions
No. Policy authoring, approvals, versioning, and publishing are included in the Compliance Platform — there's no separate module to buy.
Yes. Each policy section maps to the controls it supports via framework crosswalks, so you can reuse a single policy across SOC 2, ISO 27001, and HIPAA instead of maintaining parallel copies.
Delegations route that owner's approvals to a designated backup without breaking the audit trail, so reviews don't stall while someone is away.
Stop maintaining four copies of the same policy
Author once, map everywhere, approve cleanly, publish automatically.