Feature · Library

Policies that re-draft themselves when the rule changes.

Cited authoring, real-time collaborative drafting, and policy-to-control sync share one surface.

SectionLibrary
UpdatedSeptember 2026
Information Security Policy · v4.2
Live · 3 editors
JRAMRC
Cited authoring · every paragraph carries its authority
  • §3.1 Access is provisioned on a least-privilege basis and reviewed quarterly.FFIEC · Authentication
  • §3.2 Privileged credentials are rotated and logged in the PAM system.SOC 2 · CC6.1
  • §4.0 Exceptions require documented approval and an expiry date.NIST 800-53 · AC-06
Redline proposed · Reg Z changeFour-eye approval
Illustrative product preview. It does not show tenant data.
01 · Policies & drafting

Cited authoring

Every paragraph can carry its authority, so you can trace each part of a policy to the rule behind it.

  • 01You attach citations from Citations & Authorities as you write.
02 · Policies & drafting

Collaborative drafting

Drafts are edited live by multiple authors on a self-hosted Hocuspocus (Tiptap/Yjs) collaboration server (Drafts, collab/).

  • 01Multiple authors edit in real time, with presence and comments.
  • 02Collaboration is self-hosted, so your drafts stay in your tenant.
03 · Policies & drafting

AI-drafted redlines

When Reg updates flags a moved paragraph, the Drafter and Policy Mapping agents propose the redline. A person approves it.

  • 01Redlines arrive as proposals and never as silent edits.
  • 02The change is linked back to the regulation that triggered it.
04 · Policies & drafting

Approval and e-sign

Policies move through versioned, four-eye approval with e-signature (esign).

  • 01Sign-off requires four eyes.
  • 02Approval is e-signed, and the version is recorded.
05 · Policies & drafting

Policy-to-control sync and templates

Policies stay aligned to the controls that implement them, and fourteen policy templates give you a running start (policy_templates).

  • 01Policy ↔ control sync keeps the two from drifting.
  • 0214 policy templates ship as starting points.
Proof points

Grounded in shipped behaviour.

  • 14 policy templates seed the library (policy_templates).
  • Drafts are edited live by multiple authors on a self-hosted Hocuspocus (Tiptap/Yjs) server (collab/).
  • When Reg updates flags a moved paragraph, the Drafter and Policy Mapping agents propose the redline. A person approves it.
  • Approval is four-eye with e-signature (esign).

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

Can multiple people edit a policy at the same time?
Yes. Drafts support real-time collaborative editing (Tiptap/Yjs) on a self-hosted Hocuspocus server.
What happens to a policy when a regulation changes?
Reg updates flags the moved paragraph and the Drafter and Policy Mapping agents propose the redline as a draft. You review and approve it.
Are policies connected to controls?
Yes. Policy ↔ control sync keeps a policy aligned with the controls that implement it.
Do you provide policy templates?
Fourteen policy templates ship as starting points. You can author your own from there.

See policies & drafting on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.