Create controls inside a policy so that each measure has a clear location and version. You need the relevant policy permission and an editable policy version.

Choose the parent

Open Policies, select the policy and check its version status. Select the category or subcategory that should contain the control, then choose Add element.

At a category, the drawer offers Subcategory and Control. Select Control and confirm the parent displayed beneath the drawer title. A policy root offers category creation rather than direct control creation.

Describe the measure

The app previews an automatically assigned internal reference. The display code starts from that reference and remains editable. Enter a name and description that explain the measure and how its operation can be demonstrated.

For example, “Review privileged access every quarter” is easier to assess when its description identifies the responsible team, the review scope, retained records and handling of exceptions.

Choose Add to create the control. Confirm its position in the tree, then complete its owners, evaluation, attributes, evidence and framework links. These supporting details are maintained on the resulting control record.

Creation saves the new element. Cancel closes the creation form without adding it.