Use This Doc For
/compliance/policies/compliance/policies/[id]
Purpose
Policies turn obligations and management decisions into controlled expectations for a defined audience. Requirements describe what people must do; acknowledgements and completions show who acted against a specific policy version.
Policy Lifecycle
The managed lifecycle is:
- draft — content and requirements can be prepared
- in-review — reviewers assess the proposed version
- approved — an approver and approval time are recorded
- published — the version is active for its audience
- retired — the version is no longer active
An in-review policy can return to draft. A retired policy can return to draft as a new version; that increments the version and clears the prior approval, publication, and retirement timestamps. A published policy must be retired before a new draft cycle.
Ask A Coworker To Draft One
You can ask a coworker, such as the HR specialist, to write a policy for you. The coworker creates it as a draft and tells you where to review it. It can also edit its own draft and move it to in-review when the content is ready.
A coworker cannot approve, publish, or retire a policy. Those steps stay with a
person on /compliance/policies, so a drafted policy is a proposal, not an
active rule. Read the draft before you approve it: the coworker wrote the
words, and you own what the policy says.
Audience is not yet a structured field. If a policy applies to part of your workforce, say so in the notes and check the scope yourself before you publish.
Publish A Policy
- Define the title, category, owner, body or file reference, effective date, review date, and related obligation.
- Add requirements such as acknowledgement, training, certification, attestation, or document submission. Include applicability, frequency, and due timing.
- Move the draft into review, return it for changes when necessary, and record approval only after the reviewer is satisfied.
- Publish the approved version.
- Monitor acknowledgements and requirement completions against the active employee population and the policy version.
- Follow up on missing or expired completion evidence.
Requirements can be completed only while the policy is published. Some requirement types are self-completable; others require compliance-management permission. Acknowledgements record the version acknowledged, so a new version needs a deliberate new distribution and acknowledgement decision.
Decisions And Consequences
- Approve records the current employee as approver when an employee profile is available.
- Publish makes the version available for acknowledgement and completion.
- Retire ends the published lifecycle but preserves the record.
- Returning a retired policy to draft begins a new version and clears prior lifecycle timestamps; it does not convert old acknowledgements into acknowledgements of the new version.
- Deleting a requirement removes that requirement record. Use deletion only for a genuine creation error; otherwise preserve history and replace the policy version deliberately.
What To Watch
- policy updates without a corresponding acknowledgement plan
- operational rules living only in policy prose with no execution path
- old policy versions still being treated as active
- published requirements with no owner, due timing, or completion evidence
- acknowledgement percentages interpreted without checking the applicable audience
Recovery
Before publication, return an in-review policy to draft and correct it. After publication, retire the version and begin a new draft cycle rather than silently changing what people already acknowledged. If an acknowledgement or completion is disputed, preserve the record and investigate the employee, version, method, and date.