Policies
Policies are the written security policies your compliance program rests on: access management, incident response, acceptable use, and the rest. On the Policies page you draft them from Oneleet templates, an uploaded PDF, or a blank document, publish them as numbered versions, optionally route each version through a reviewer first, and collect acknowledgements from the employees and contractors who have to read them. Published policies also drive the policy checks on your controls and the “signed applicable policies” readiness check on new hires.
Workspace admins create, edit, publish, and delete policies. Reviewers, who can be any members you assign, approve or reject versions, and employees and contractors sign published policies from the employee portal.
Set up your first policies
Section titled “Set up your first policies”The first time you open Policies, you start at Choose base policy set. Pick Essential (for startups and low-risk environments), Comprehensive (for enterprise, FinTech, and HealthTech), or Custom to skip the bulk draft and add policies one at a time. The templates offered match your workspace’s selected compliance frameworks. Expand a template under Policy Preview to read it with your workspace name filled in.
Click Prepare policies, and Oneleet drafts one policy per template with [Company Name] replaced by your workspace name. On the We’ve drafted N policies step, each row shows who the draft applies to (click the audience to change it) and a Publish switch. To leave a draft out of your set, click Remove policy (the minus icon). Drafts with a reviewer have the switch disabled and labeled Requires review, and you publish them later through the review flow.
Finish with Publish policies (N) to publish the switched-on drafts, or Save as drafts to keep everything unpublished. The Adapting policies guide covers both options and how to adapt template wording to your company. In the onboarding checklist, this step is Add security policies, and you can put it off with I’ll do this later.
Add a policy
Section titled “Add a policy”Click New policy on the Policies page to open Add policy, where you start from a template, from scratch, or from a PDF you already have. Every new policy starts as a draft and doesn’t apply to anyone until you publish it.
From a template
Section titled “From a template”Click Browse templates, then Use template on the one you want. The create form opens prefilled with the template’s title, description, category, and content, with [Company Name] already replaced. Edit what you need and click Create.
From scratch
Section titled “From scratch”Click Create from scratch to open the same form empty. Fill in Policy title and the policy content, which are required, and click Create.
From a PDF
Section titled “From a PDF”Drop or paste a PDF under “Or upload existing documents” to open Upload policy, with Name prefilled from the filename. Only PDF files are accepted. Click Create.
A PDF policy works like any other for publishing, review, and acknowledgements. Any draft version can switch between PDF and markdown from its edit page.
Set a reviewer and category
Section titled “Set a reviewer and category”Two fields on the create form also apply to every later version:
- Policy reviewer (or Review required in the upload form): a user or one or more groups. Without a reviewer, you can publish the policy directly. With one, every version has to be submitted for review and approved before it goes live. To change the reviewer later, click Edit on the policy page.
- Category: the policy types this policy covers, such as Access Management or Incident Response. The category is what links the policy to the policy checks on your controls. Templates set it for you.
Publish a policy
Section titled “Publish a policy”On a draft with content, click Publish version on the policy page or the version page, and confirm with Publish. If the policy has a reviewer, the button is Submit for review instead; see Review a version before publishing. For markdown policies, Oneleet generates a PDF in the background, and the page shows Generating PDF… until it’s ready.
Once the version is published, the policy applies to its audience, appears in the employee portal, and counts toward the policy checks on your controls. Publishing doesn’t email anyone. People find the policies they need to sign in the employee portal, new hires are pointed to them in their invite email, and you can send reminders to anyone who hasn’t signed.
Publish a new version
Section titled “Publish a new version”Versions track a policy’s content only. The name, description, category, and audience aren’t versioned: when you change them from Edit on the policy page, the change applies to the published version right away.
To change the content:
-
On the policy’s Versions tab, click New version on the current version’s card. It’s available only when the policy has no draft or version in review.
-
Click Edit version, make your changes, and click Save. For markdown policies, edit the text on the Write tab and check it on Preview. For PDF policies, upload the new file under Upload your new version.
-
Click Publish version and choose an acknowledgement requirement:
- Require new acknowledgements publishes a new major version (the number before the dot goes up). Everyone in the audience has to sign again.
- Don’t require new acknowledgements publishes a minor version under the same major number. Existing signatures carry over.
-
Click Publish policy. The new version replaces the current one.
Collect acknowledgements
Section titled “Collect acknowledgements”Choose who has to sign
Section titled “Choose who has to sign”Each policy has an Audience, set from Edit on the policy page. By default, new policies apply to Everyone in organization. You can narrow that to All employees, All contractors, or Specific groups with Groups to include. Any audience other than Specific groups can also leave out members of particular groups with Exclude specific groups. Specific groups needs at least one group in the People Directory.
The audience isn’t fixed at publish time: someone who joins the workspace later owes a signature as soon as they match it. Guests and former employees are never asked to sign.
Sign a policy in the employee portal
Section titled “Sign a policy in the employee portal”In the employee portal, employees see their policies under Needs signing and Signed, with a “Sign all policies by” deadline seven days after the newest policy was created. They read each policy to the bottom and click Accept policy, then Next to move to the next unsigned one.
Admins who are in a policy’s audience can also click Sign on the policy page.
Track signatures
Section titled “Track signatures”The Acknowledgements tab lists everyone in the audience and whether they’ve signed. A signature made on an earlier version links to that version, so you can see exactly what someone accepted. Export downloads the list as a CSV.
Click Send reminders to email a “Review and accept company policies” reminder to everyone who hasn’t signed. In the dialog, people reminded in the last day start out deselected, though you can still select them. Anyone reminded in the last five minutes can’t be reminded again yet.
Review a version before publishing
Section titled “Review a version before publishing”Submit for review
Section titled “Submit for review”On the draft, click Submit for review (or Resubmit for review after a rejection) and confirm. The version’s badge changes to Waiting for review by the named reviewer or groups, shown as In review in the list, and nobody can edit the version while it’s in review.
Submitting doesn’t notify the reviewers. They find versions waiting for them by that badge on the policy page.
Review a version
Section titled “Review a version”The named reviewer and members of a reviewer group can review, as long as they’re active members of the workspace. On the version page:
-
Click Review version and choose a Review action. For a policy’s first version, the choice is Approve or Reject. For later versions, it’s Approve and require new signatures (a new major version), Approve without requiring new signatures (a minor version), or Reject.
-
Optionally, click Add note to record why.
-
Click Complete review.
Approving publishes the version immediately. Rejecting returns it to draft with a Rejected by badge, and the author can edit and resubmit.
Download policies
Section titled “Download policies”Select policies in the list and click Download for a zip of markdown files or PDFs, or use Download PDF on a row or in a policy’s ⋮ menu. Copy markdown in the same menu copies a markdown policy’s text.
By default, the PDFs Oneleet generates for markdown policies include the version history. To change this, go to Settings > General settings > Policy PDFs; the change applies from the next version you publish. Workspaces created before this setting existed have it off.
Use policies elsewhere in Oneleet
Section titled “Use policies elsewhere in Oneleet”- Controls: each policy category corresponds to a policy check on the relevant controls. On a control’s page, the check shows Add policy when no policy covers that category, Publish policy when one exists but isn’t published, and otherwise how many of the audience have signed. Checks update whenever a policy is created, published, approved, or deleted.
- Trust Center: only published policies can be added to the Trust Center as documents.
- People: the per-hire readiness check “All people have signed applicable policies” tracks publishing and signatures. The “Review and accept company policies” reminder is also available from the People page.
Delete a policy
Section titled “Delete a policy”In the policy’s ⋮ menu, click Delete… and confirm with Delete policy. The policy is removed from the employee portal right away, along with any Trust Center documents linked to it. Oneleet keeps deleted policies and their signatures, but only Oneleet support can restore them, so treat deletion as permanent.
To discard a draft instead of the whole policy, click the trash icon on the draft’s card in the Versions tab and confirm with Delete version. You can’t delete the published version. If the draft is the policy’s only version, deleting it deletes the policy.