App navigation: Governance → Policy Center
Policy Center is the system of record for organizational policies – from authoring through review, approval, publishing, and retirement. It links policies to compliance framework citations and tracks who is responsible for each policy.
Screen Layout #
Navigate to Governance → Policy Center to open the Policy Inventory screen. It has two main areas:
- Policy Summary panel – shows live counts of Total Policies and breakdown by status (Active, Draft, Under Review, Awaiting Approval), plus a Review Due panel showing policies due within 30 days and overdue policies. Each status count is a clickable filter.
- Policy list – a filterable, sortable, searchable grid with columns: Actions, Status, Identifier, Title, Owner, Author, Effective From, Next Review Date. The toolbar includes Refresh, Filter, + Create, and a More menu (Export, Retired Policy, Bulk Review, Bulk Approve).
[Screenshot: Policy Inventory screen]
Policy Lifecycle #
| Status | Meaning |
|---|---|
| Draft | Policy is being authored. Not yet submitted for review. |
| Under Review | Submitted to reviewers for evaluation. |
| Awaiting Approval | All reviews complete – waiting for approver sign-off. |
| Active | Approved and published. The current version of the policy. |
| Retired | Superseded or decommissioned. Accessible via the Retired Policy view. |
Creating a Policy #
Prerequisites #
- You must have the Admin, Owner, or Author role.
- Reviewers and approvers must be configured as users before you can assign them.
Step 1 – Open the Creation Wizard #
- Select + on the toolbar.
- In the Policy Action dialog, choose Create Manually. (Choose Upload from File to bulk-create from a template.)
- The policy creation wizard opens with four steps.
Step 2 – Executive Summary #
- Enter the Policy Title, Description, Effective From date, and assign an Owner and Author.
- To link the policy to an Authority Document clause (e.g., ISO 27001), select the Citations toolbar button and add the relevant citation.
Step 3 – Stakeholders #
- Assign one or more Reviewers and Approvers.
Step 4 – Security Objective #
- Select the security objectives this policy addresses (Confidentiality, Integrity, Availability, or custom objectives).
Step 5 – Specification #
- Enter the full body of the policy document.
- Select Complete to submit the policy for review.
[Screenshot: Policy creation wizard – Executive Summary step]
Step 6 – Review #
- Assigned reviewers receive a notification and open the policy (status: Under Review).
- Each reviewer submits their decision. Once all reviewers complete, the policy moves to Awaiting Approval.
Step 7 – Approve #
- Assigned approvers receive a notification and open the policy.
- Once all approvers have approved, the policy status changes to Active.
Tip: Use Bulk Review or Bulk Approve from the More menu on the toolbar to process multiple policies at once.
Viewing an Existing Policy #
- Select the eye icon in the Actions column to open a policy in read-only Detail view.
- The detail view shows all wizard steps as tabs: Executive Summary, Stakeholders, Security Objective, Specification, Review Log, and Archived Versions.
- The Review Log tab shows the full audit trail of all review and approval decisions.
- The Archived Versions tab shows previous versions of the policy for comparison.
[Screenshot: Policy detail view showing the tab navigation]
Bulk Operations #
Use the More menu on the Policy Inventory toolbar to:
- Bulk Review – apply review decisions to multiple selected policies at once.
- Bulk Approve – apply approval decisions to multiple selected policies at once.
- Export – export the current filtered policy list.
