Policies
Policies are your company’s written security rules, such as how you manage access and how you respond to incidents. In Oneleet, you draft them from templates or your own documents, get each version approved if the policy needs sign-off, publish it, and then track who has acknowledged it. Approval and acknowledgement are separate steps: a reviewer approves a version before it’s published, and everyone in the policy’s audience signs the published version afterwards.
Policies are part of Compliance. Admins create, edit, publish, and delete policies and send reminders. A policy’s assigned reviewer, who needs the Member role or higher, approves or rejects its versions. People sign the policies that apply to them in the Oneleet Portal.
Set up policies from a template set
Section titled “Set up policies from a template set”The first time you open Policies, Oneleet offers to draft a starter set of policies from templates. The same setup is the Add security policies step of the onboarding checklist. To skip it there for now, click I’ll do this later.
On Choose base policy set, pick one:
- Essential: “Best for startups and low-risk environments.”
- Comprehensive: “Best for Enterprise, FinTech, and HealthTech.”
- Custom (not offered on the onboarding checklist step): add policies one at a time instead, as described in Add a policy.
The set only includes templates that apply to your workspace’s compliance frameworks, so if your workspace has no framework yet, the set is empty and Prepare policies stays disabled. Expand a template under Policy Preview to read it before you continue.
Click Prepare policies. Oneleet drafts the policies with your workspace name filled in wherever a template says [Company Name], and lists them so you can adjust each one before anything is published:
- Click a policy’s audience to change who has to sign it.
- Click Remove policy to leave a policy out, or Restore policy to bring it back. Removed policies are deleted when you finish.
To finish, click Add policies to put the policies in your policy library as drafts. You can publish each one later. If AI policy review is available, click Review with AI to have each draft reviewed, which also finishes and opens the Policies page, where you can follow each review’s progress. Click Maybe later to finish without reviewing.
Then fill in each policy’s placeholders and publish it as described in Review and publish a policy. After publishing, ask people to sign.
To adapt a template’s wording to how your company works, see Adapting policies.
Add a policy
Section titled “Add a policy”On the Policies page, click New policy, then choose how to start:
- Browse templates: find a template and click Use template. This list has every Oneleet template in both its Essential and Comprehensive versions, not only the ones for your frameworks.
- Create from scratch: write the policy yourself.
- Upload a PDF: drop or paste a PDF under “Or upload existing documents”.
Before you click Create, set the two fields that shape how the policy works later. Policy reviewer (Review required when you upload) decides whether versions need approval before they’re published, as described in Review and publish a policy. Category (Type when you upload) links the policy to the policy checks on your controls, as described in Connect policies to controls and the Trust Center.
Every new policy starts as a draft at version 1.0 with the audience Everyone in organization. Neither the create form nor the Upload policy dialog has an audience field, so narrow the audience afterwards if the policy doesn’t apply to everyone.
Uploads accept PDF files only, and an uploaded PDF is kept exactly as you uploaded it. The search on the Policies page doesn’t match text inside uploaded PDFs. To update an uploaded policy, create a new version and upload the new PDF, or write the new version as text.
Choose who signs a policy
Section titled “Choose who signs a policy”A policy’s audience is the set of people who have to sign it. To change it, open the policy, click Edit, and pick an Audience in the Edit policy dialog:
- Everyone in organization: the default.
- All employees
- All contractors
- Specific groups: only members of the groups you choose under Groups to include. This option appears once your workspace has at least one group, which you create in the People Directory.
For any audience except Specific groups, select Exclude specific groups to leave out the members of certain groups. An exclusion wins over the audience, so someone in an excluded group never has to sign that policy. Switching to Specific groups clears your exclusions.
Oneleet works out each audience from your current list of people, so someone who joins your workspace, changes type, or is added to a group owes a signature right away, and the policy’s signed counts change without anyone editing it. Guests and former employees never have to sign, but people whose status is Not onboarded or Onboarding do. Setting someone’s status to Offboarding or Former makes them a former employee, which removes them from every audience.
Review and publish a policy
Section titled “Review and publish a policy”A policy with no reviewer can be published as soon as its draft has content. If the policy has a Policy reviewer, that reviewer has to approve each version, and approving is what publishes it. Review and approval happen entirely inside your workspace, and neither Oneleet nor your auditor takes part in them.
Publish without a reviewer
Section titled “Publish without a reviewer”Open the policy or its draft version, click Publish version, and confirm in the dialog. For an update to a policy that’s already published, the dialog also asks whether people need to sign again, as described in Choose whether people sign again.
To publish several new policies at once, click Publish draft policies on the Policies page. This publishes every policy that has never been published and has no reviewer, and you can’t choose which ones. A new draft version of a published policy isn’t included, so publish that from its own version page.
Oneleet records whoever publishes a version as its approver. The version card reads Published by with that person’s name, and the PDF’s version history names them as the approver.
Get a version approved by a reviewer
Section titled “Get a version approved by a reviewer”-
On the draft, click Submit for review and confirm. The version’s badge changes to Waiting for review by followed by the reviewer’s name or groups.
-
Let the reviewer know. Submitting doesn’t send them an email or notification, so they find the version through its badge or the “Review draft policy version” link on the policy page.
-
The reviewer opens the version, clicks Review version, chooses a Review action, optionally adds a note, and clicks Complete review.
The reviewer chooses one of these. The two options for an update match the choices in Choose whether people sign again.
- Approve: publishes the policy’s first version.
- Approve and require new signatures: publishes an update the same way as Require new acknowledgements.
- Approve without requiring new signatures: publishes an update the same way as Don’t require new acknowledgements.
- Reject: returns the version to draft with a Rejected by badge.
After you submit a version, you can’t edit or withdraw it until the reviewer rejects it. You can then edit the draft and click Resubmit for review, which clears the rejection badge and the reviewer’s note.
A reviewer with the Member role can approve or reject a version without being able to edit, publish, or delete the policy. Admins who aren’t the assigned reviewer can’t approve or reject at all. If the reviewer’s status changes to Offboarding or Former, they can no longer review but stay assigned to the policy.
To hand a version that’s in review to someone else, click Edit on the policy page and change the reviewer. The new reviewer can approve or reject the version right away, and the badge switches to their name. The previous reviewer can no longer approve or reject it. Neither of them is notified, so let the new reviewer know.
Policy PDFs and version history
Section titled “Policy PDFs and version history”When you publish a policy written in Oneleet, Oneleet generates a PDF of it in the background, and the policy shows Generating PDF… until the file is ready. The PDF carries the policy title, your workspace name, the version, and the published date.
By default, newer workspaces also include a version history in these PDFs, listing each published version with its published date and approver, while older workspaces don’t. To change this, turn Policy PDFs on or off in Settings > General. The change applies to PDFs generated afterwards, starting with the next version you publish, and never to uploaded PDFs.
Collect acknowledgements
Section titled “Collect acknowledgements”Publishing a policy doesn’t email or notify anyone, and Oneleet doesn’t send reminders on a schedule. People find the published policies that apply to them in the Oneleet Portal, and new hires also get the employee invite, which mentions policies. To prompt people to sign, click Send reminders.
On the Oneleet Portal’s Policies page, each person sees the published policies in their audience. Drafts and versions in review never appear there, and a policy with a draft in progress keeps showing its published version. To sign, a person opens a policy, scrolls to the bottom, and clicks Accept policy, which appears only after they reach the end (for a PDF, once every page has loaded). The portal’s “Sign all policies by” date is the newest policy’s creation date plus 7 days, and it doesn’t trigger reminders or affect the monitor.
Workspace members in a policy’s audience can also sign it on the policy page by clicking Sign.
Track who has signed
Section titled “Track who has signed”Open the policy’s Acknowledgements tab and filter to Not yet acknowledged, or click Export to download a CSV.
The All people have signed applicable policies monitor checks every person a policy applies to, except people being offboarded. It fails for a person as soon as they owe a signature, including new hires whose status is still Not onboarded, and your SLA for policy signing sets when that failure starts breaching the SLA. Publishing a version that requires new acknowledgements makes everyone in its audience fail again until they sign.
Auditors assigned to your audit see each person’s policy signatures, with the version they signed and when, in the Auditor Portal’s Scope section, under each policy in its Policies section, and in the audit snapshot.
Send reminders
Section titled “Send reminders”Click Send reminders on a policy’s Policy or Acknowledgements tab, or send the same reminder from the People page. The dialog lists every person with any outstanding task in the Oneleet Portal, such as an unsigned policy or security training, not only this policy’s audience. The email is a general reminder to “Review and accept company policies” and links to the portal home rather than to this policy.
Anyone reminded in the past day starts out deselected in the dialog, but you can still select them, while someone reminded in the last 5 minutes can’t be reminded again. Each click of Send N reminders counts once toward a sending limit, however many people you select. When you reach the limit, nothing is emailed, and an error notification titled “Reminders already sent” appears.
Update a policy
Section titled “Update a policy”To change a policy’s title, description, category, reviewer, or audience, click Edit on the policy page. These changes apply to the published policy right away and don’t create a new version.
To change the policy’s text, create a new version:
-
On the policy page, open the Versions tab and click New version on the current version’s card.
-
Click Edit version, make your changes, and click Save. Leaving the editor without saving discards your edits.
-
Publish the draft, or submit it for review if the policy has a reviewer.
New version isn’t available while the policy already has a draft or a version in review. The new draft copies the current text but not the current PDF, so an uploaded policy’s new draft opens empty under Upload your new version. Upload the updated file there, or click Switch to markdown to write the version as text. A version holds either text or a PDF, so uploading a PDF replaces the draft’s text and saving text removes an uploaded PDF. If two people edit the same draft at the same time, the later save overwrites the earlier one.
To discard a draft, click the trash icon on its card in the Versions tab. Only drafts can be deleted, and if the draft is the policy’s only version, Oneleet asks you to delete the whole policy instead.
Choose whether people sign again
Section titled “Choose whether people sign again”On a policy with a reviewer, the reviewer decides whether people need to sign again when they approve an update, with Approve and require new signatures or Approve without requiring new signatures, as described in Get a version approved by a reviewer. Without a reviewer, you decide in the Publish new policy version dialog when you publish the update:
- Require new acknowledgements publishes the draft as a new major version, where the first number goes up and the second resets to 0. Everyone in the audience has to sign it again.
- Don’t require new acknowledgements publishes it as a minor version, where only the second number goes up. Existing signatures still count.
Choose Require new acknowledgements for material changes and for your yearly policy review, and Don’t require new acknowledgements for minor changes. The draft shows a minor version number until it’s published, and choosing Require new acknowledgements renumbers it. Because signatures carry across minor versions, the Acknowledgements tab can show a signature made on an earlier version, with a link to that version.
Connect policies to controls and the Trust Center
Section titled “Connect policies to controls and the Trust Center”A policy counts toward a control’s policy check through its Category. The check passes as soon as any policy in that category has a published version, regardless of who has signed it, and the signing counts shown on the check are for information only. When no policy in the category exists, the check offers Add policy, and when there’s only a draft, it offers Publish policy. Checks update in the background after you add a policy with New policy, edit or delete a policy, or publish or approve a version from its policy page.
A policy with no category isn’t linked to any control, so set Category through Edit on policies you upload or write from scratch. When several policies share a category, the check links to the first published one it finds.
Only published policies can be added to the Trust Center. A Trust Center document always shows the policy’s current version, so publishing a new version updates it without you changing anything in the Trust Center.
Delete a policy
Section titled “Delete a policy”Open the ⋮ menu on the policy page, click Delete…, and confirm with Delete policy. The policy disappears from the Oneleet Portal right away, its control checks go back to “No policy found”, and its Trust Center document is removed.
Signatures and files are kept. To restore a deleted policy, contact us. A restore brings back the policy’s versions, but not a draft you deleted separately beforehand, and it doesn’t add the policy back to the Trust Center.
What this means for your audit
Section titled “What this means for your audit”Policies need a review and approval every year, and ISO 27001 requires management approval of policies. Oneleet doesn’t schedule this review, so run it yourself by publishing a new version with Require new acknowledgements, or by having the reviewer choose Approve and require new signatures. Each version card records who published or approved that version.
Auditors test that new hires acknowledge your policies and that everyone acknowledges them yearly. The All people have signed applicable policies monitor and each policy’s Acknowledgements tab show where you stand, and the yearly version with required acknowledgements starts the next round of signing. Minor versions don’t need new acknowledgements, but publish material changes as a version that does.
Auditors look for version history in policy PDFs, so make sure Policy PDFs is turned on in Settings > General.
An approved version or a passing policy check is recorded in Oneleet. It doesn’t mean your auditor has reviewed or accepted the policy.
Limits and edge cases
Section titled “Limits and edge cases”- Selecting policies on the Policies page and clicking Download gives a zip with written policies as
.mdfiles and PDFs as.pdffiles. - Export as PDF on a policy with no generated PDF yet opens your browser’s print dialog, and it appears only while the Policy tab is open.
- If a published policy keeps showing Generating PDF…, the PDF didn’t generate. Contact us to regenerate it.
- When a Oneleet staff member publishes or approves a version in your workspace, the PDF’s version history leaves the approver blank.
- If you delete every policy, the Choose base policy set step comes back.