Categories and subcategories give your policies their internal structure: categories group related subcategories and controls, and subcategories group controls within a category. Managing them well keeps each policy readable and auditable.
1. Manage the Structure
- Add: hover a policy or category in the tree and use the + button ("Add a category to this policy", "Add a subcategory or control"); display codes are suggested automatically.
- Edit: update the displayed code, name and rich-text description from the element's details panel; descriptions support live co-editing.
- Delete: remove an element from its More options menu; its children are deleted with it after confirmation.
- Reorder and move: drag and drop to reorder elements or move them elsewhere in the structure. Invalid moves (for example a category that still has subcategories, or nesting too deep) are flagged immediately; confirmed moves are applied when you click Save in the save bar.
2. Assess and Assign
- Maturity: set current and target maturity levels with descriptions, optionally applied recursively to sub-elements.
- Owners: assign one or several owners, optionally recursively.
- Evidences and comments: attach supporting documentation and discuss changes on the element (confidential layer).
- Framework links: link categories and subcategories to framework elements for organisational traceability.
- Periodicity reviews and share links: schedule recurring reviews and share the element externally with expiring links.
3. Add Controls
Categories and subcategories are where controls live: the actionable measures your organisation implements and tracks. Add them from the + button or import them from the control catalogue; see the Controls documentation for the full workflow.
Note: like policies, every category and subcategory carries a permanent auto-generated registered code alongside the display code you can edit, ensuring uniqueness and traceability.