The Policies module maintains written requirements and the controls that put them into practice. Start from the policy register, then open a policy to work in its structure and detail view.

ALTE LTD policy register showing ten policies, approval states, versions, completion, controls, framework links and owners.
The policy register brings together version status, control completion and framework references. Open full size.

Structure and content

A policy is a top-level document. Categories and subcategories organise its controls and supporting text. Every element has an editable display code and a fixed registered reference.

Create a policy from scratch or review framework changes that can create or update policy elements. Rich-text descriptions support readable headings, lists, links and other document content.

Assessment and traceability

Record current and target maturity where available, maintain control completion and weighting, and classify controls with the workspace catalogues. Assign owners and reviews and retain the evidence behind the assessment.

Link policy elements to framework requirements for traceability. Control links provide compliance mapping; links on a policy, category or subcategory provide organisational reference. Review the meaning of each relationship instead of assuming every link proves implementation.

Versions and collaboration

Prepare major or minor versions, inspect previous copies and use the configured approval process. Drafts, versions in review, approved versions and historical copies have different editing rules.

Collaborative text fields can show other contributors' work when the connection and permissions allow it. Wait for an editor to become ready, preserve the intended scope and check save feedback. Presence does not grant an exclusive editing lock.

Access and sharing

Policy Management controls policy access; Policy Confidential Details separately governs the assessment layer. Readers without confidential access receive a restricted reading experience.

Where authorised, generate a public read-only snapshot using the sharing controls and a chosen expiry and content scope. This is a separate publication action from saving or approving the policy.