Categories and subcategories give your policies their internal structure: categories group related subcategories and controls, and subcategories group controls within a category. Managing them well keeps each policy readable and auditable.

1. Manage the Structure

  • Add: hover a policy or category in the tree and use the + button ("Add a category to this policy", "Add a subcategory or control"); display codes are suggested automatically.
  • Edit: update the displayed code, name and rich-text description from the element's details panel; descriptions support live co-editing.
  • Delete: remove an element from its More options menu; its children are deleted with it after confirmation.
  • Reorder and move: drag and drop to reorder elements or move them elsewhere in the structure. Invalid moves (for example a category that still has subcategories, or nesting too deep) are flagged immediately; confirmed moves are applied when you click Save in the save bar.

2. Assess and Assign

  • Maturity: set current and target maturity levels with descriptions, optionally applied recursively to sub-elements.
  • Owners: assign one or several owners, optionally recursively.
Owners button
  • Evidences and comments: attach supporting documentation and discuss changes on the element (confidential layer).
  • Framework links: link categories and subcategories to framework elements for organisational traceability.
  • Periodicity reviews and share links: schedule recurring reviews and share the element externally with expiring links.

3. Add Controls

Categories and subcategories are where controls live: the actionable measures your organisation implements and tracks. Add them from the + button or import them from the control catalogue; see the Controls documentation for the full workflow.

Note: like policies, every category and subcategory carries a permanent auto-generated registered code alongside the display code you can edit, ensuring uniqueness and traceability.