---
title: "Policies"
description: "Policies are central to managing your organization's rules, guidelines, and compliance requirements. This feature allows you to create, manage, and track various policies, ensuring your organizatio..."
last_updated: "2026-05-06T07:36:18.476489+00:00"
canonical_url: "https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/guide/section-2/policies"
---

Policies are central to managing your organization's rules, guidelines, and compliance requirements. This feature allows you to create, manage, and track various policies, ensuring your organization adheres to internal standards and external regulations like SOC 2, ISO 27001, and GDPR.

You can maintain different versions of each policy, allowing for drafting, review, and publication workflows. The system also offers an AI assistant to help you refine and improve your policy content, making compliance management more efficient.

---

### Key Concepts

Before you start, it's helpful to understand a few key terms:

*   **Policy**: A formal statement of principles that guides and determines present and future decisions and actions.
*   **Policy Version**: A specific iteration of a policy. Policies often go through multiple drafts and revisions, each saved as a distinct version.
*   **Published Version**: A policy version that has been officially released and is accessible to relevant stakeholders.
*   **Active Version**: The currently enforced or most relevant published version of a policy.
*   **Policy Content**: The actual text and structure of the policy, typically managed in a rich text editor.

---

## Managing Policies

This section covers how to create, view, update, and delete your organizational policies.

<Steps>
<Step>
### View All Policies
To see a list of all policies in your organization:

1.  Navigate to the "Policies" section of the application.
2.  A list displaying all policies, including their names, descriptions, and current statuses, will be shown.
</Step>

<Step>
### Create a New Policy
You can create a new policy from scratch.

1.  Go to the "Policies" section.
2.  Click the "Create New Policy" button (or similar action).
3.  Fill in the required details:
    *   **Name**: A clear and concise title for your policy (e.g., "Data Privacy Policy").
    *   **Description** (Optional): A brief overview of what the policy covers.
    *   **Content**: The main body of your policy. You will typically use a rich text editor for this.
    *   **Status** (Optional): Initial status, such as `Draft`.
    *   **Review Frequency** (Optional): How often this policy should be reviewed (e.g., `Yearly`).
    *   **Department** (Optional): Which department this policy primarily applies to.
    *   **Requires Signature** (Optional): Indicate if users need to sign this policy.
    *   **Review Date** (Optional): A specific date for the next review.
    *   **Assignee** (Optional): The user responsible for this policy.
    *   **Approver** (Optional): The user who approved this policy.
    *   **Policy Template** (Optional): If you're basing this on an existing template.
4.  Click "Save" or "Create Policy".
</Step>

<Step>
### Update Policy Details
You can modify a policy's general information at any time.

1.  From the list of policies, select the policy you wish to update.
2.  Click the "Edit" button (or similar icon).
3.  Modify fields such as:
    *   **Name**
    *   **Description**
    *   **Status**
    *   **Review Frequency**
    *   **Department**
    *   **Requires Signature**
    *   **Review Date**
    *   **Assignee**
    *   **Approver**
    *   **Archive Policy**: You can also choose to archive a policy if it's no longer in use but needs to be retained for historical purposes.
4.  Click "Save Changes".
</Step>

<Step>
### Delete a Policy
If a policy is no longer needed, you can delete it.

1.  From the list of policies, select the policy you wish to delete.
2.  Click the "Delete" button (often represented by a trash can icon).
3.  Confirm your decision when prompted.

<Callout variant="warning" title="Deletion is Permanent">
Deleting a policy will remove it and all its associated versions from the system. This action cannot be undone. Consider archiving policies instead of deleting them if you need to retain historical records.
</Callout>
</Step>

<Step>
### Download All Published Policies
You can generate a single PDF document containing all your organization's published policies.

1.  Navigate to the "Policies" section.
2.  Look for an option like "Download All Policies" or "Export All Published Policies".
3.  Click this option. The system will generate a PDF bundle with your organization's branding and provide a signed URL for you to download it.

<Callout variant="info">
This feature is useful for audits, compliance checks, or providing a comprehensive policy manual to new employees.
</Callout>
</Step>
</Steps>

---

## Managing Policy Versions

Policies evolve over time. Version control allows you to track changes, draft new updates without affecting the live policy, and maintain a history of all revisions.

<Steps>
<Step>
### View Policy Versions
To see all versions associated with a specific policy:

1.  Select the policy you are interested in from the main policies list.
2.  Navigate to the "Versions" tab or section for that policy.
3.  You will see a list of all versions, including their status (e.g., Draft, Published), creation date, and any associated changelog.
</Step>

<Step>
### Create a New Policy Version
You can create a new version, often based on an existing one, to make updates without altering the currently active policy.

1.  Go to the "Versions" section of a specific policy.
2.  Click "Create New Version" (or similar).
3.  You may have options:
    *   **Base on existing version** (Optional): Select a `sourceVersionId` to copy content from an earlier version. If not specified, a new empty version might be created or it might copy from the active version.
    *   **Changelog** (Optional): Add a brief note describing the purpose of this new version (e.g., "Initial draft for quarterly updates").
4.  Click "Create". A new draft version will be added to the policy.
</Step>

<Step>
### Update Policy Version Content
Once a new version is created (or if you're editing an existing draft), you can modify its content.

1.  From the policy's "Versions" list, select the specific version you want to edit.
2.  Click the "Edit Content" button.
3.  Use the rich text editor to make your desired changes to the policy text.
4.  Click "Save Changes" to update the version's content.
</Step>

<Step>
### Publish a Policy Version
When a policy version is ready for official release, you can publish it.

1.  From the policy's "Versions" list, select the version you wish to publish.
2.  Click the "Publish" button.
3.  You will have options:
    *   **Set as Active** (Optional): Choose whether this published version should immediately become the active, live policy.
    *   **Changelog** (Optional): Add a note about the changes included in this published version (e.g., "Updated access controls section").
4.  Confirm the publication.
</Step>

<Step>
### Set an Active Policy Version
You can designate any published version as the current active policy.

1.  From the policy's "Versions" list, select the *published* version you want to make active.
2.  Click the "Set as Active" button (or similar action).
3.  Confirm your choice. This version will now be the primary policy in effect.
</Step>

<Step>
### Submit a Policy Version for Approval
If your workflow requires formal approval, you can submit a version for review.

1.  From the policy's "Versions" list, select the version you want to submit.
2.  Click "Submit for Approval".
3.  You will need to specify the `Approver ID` (the user who needs to approve this version).
4.  Confirm the submission. The policy's status will likely change to `Needs Review`.
</Step>

<Step>
### Delete a Policy Version
You can delete specific versions of a policy, especially if they are drafts or no longer relevant.

1.  From the policy's "Versions" list, select the version you wish to delete.
2.  Click the "Delete" button (often a trash can icon).
3.  Confirm your decision.

<Callout variant="warning" title="Cannot Delete Active/Published Versions">
You typically cannot delete an active or published policy version directly. You may need to unpublish it or set another version as active first.
</Callout>
</Step>
</Steps>

---

## AI Assistant for Policy Editing

The AI assistant can help you draft, refine, and ensure the compliance of your policies. It acts as an expert GRC (Governance, Risk, and Compliance) editor.

<Steps>
<Step>
### Access the AI Chat
1.  Select the policy you want to work on from the main policies list.
2.  Navigate to the policy's editing interface or a dedicated "AI Chat" section.
</Step>

<Step>
### Provide Instructions
1.  In the chat interface, type your instructions or questions for the AI.
    *   **Example**: "Update the data retention section to specify a 7-year retention period."
    *   **Example**: "Review this policy for GDPR compliance and suggest improvements."
    *   **Example**: "Explain the purpose of the 'Purpose' section."
2.  Send your message to the AI.
</Step>

<Step>
### Review AI Suggestions
The AI will stream its response, acting as a GRC expert. It can:
*   Help you understand and improve your policies.
*   Suggest specific changes.
*   Ensure policies remain compliant with relevant frameworks (e.g., SOC 2, ISO 27001, GDPR).
*   Maintain professional, clear language.

<Callout variant="info" title="How AI Provides Policy Updates">
When the AI suggests changes to the policy content, it will first explain what changes it will make and why. Then, it will provide the **COMPLETE updated policy content** within a code block labeled `policy`. You should copy this entire block to replace your current policy content.
</Callout>
</Step>

<Step>
### Apply AI-Suggested Changes
1.  If the AI provides updated policy content in a `policy` code block, copy the entire content from that block.
2.  Paste this content into your policy's content editor, replacing the existing text.
3.  Save the policy version.
</Step>
</Steps>

---

## Policy Attributes Reference

Here's a quick reference for the various attributes you can set for your policies and their versions.

### Policy Status

| Value           | Description                                       |
| :-------------- | :------------------------------------------------ |
| `draft`         | The policy is under development and not yet final. |
| `published`     | The policy has been officially released.          |
| `needs_review`  | The policy has been submitted for approval or review. |

### Review Frequency

| Value       | Description                                       |
| :---------- | :------------------------------------------------ |
| `monthly`   | Policy should be reviewed every month.            |
| `quarterly` | Policy should be reviewed every three months.     |
| `yearly`    | Policy should be reviewed once a year.            |

### Departments

| Value   | Description                                       |
| :------ | :------------------------------------------------ |
| `none`  | Policy does not apply to a specific department.   |
| `admin` | Applies to administrative functions.              |
| `gov`   | Applies to governance-related functions.          |
| `hr`    | Applies to Human Resources.                       |
| `it`    | Applies to Information Technology.                |
| `itsm`  | Applies to IT Service Management.                 |
| `qms`   | Applies to Quality Management Systems.            |

## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/llms.txt) for all pages in this wiki.
