Find the policies you need to acknowledge
When a policy is approved, the people in its audience are asked to read it and acknowledge it. You can see what you've been asked to acknowledge in three places:
- My Tasks. Open Compliance in a Box and go to the My Tasks tab. The Policies to acknowledge table lists each policy with a Read version N link to the exact approved version, its due date (Due or Overdue) and an Acknowledge button. If the list is empty, it says You have no policies to acknowledge.
- The policy page in Confluence. On a policy page, the Compliance item under the page title reads Please acknowledge when you have that policy to acknowledge.
- Confluence notifications. If your Compliance Admins have reminders switched on, you get a Confluence task, and the usual Confluence notification, when you're asked and again as the due date approaches. See Dashboard, tasks and reminders.
On the Policies tab, policies you still need to acknowledge carry a Required for you label, and the Required for me filter shows only those.
Acknowledge a policy
Acknowledging is a click-through: you confirm that you've read the policy and understand it.
- Open the policy. In My Tasks, click Acknowledge or the policy's name to open it in the app. Or, on the policy page in Confluence, click Please acknowledge under the title.
- In the Please acknowledge this policy panel, click the approved version N link and read that version. The panel also shows the due date.
- Select I have read and understand this policy.
- Click Acknowledge. You'll see Thank you. Your acknowledgement is recorded.
From then on, the panel shows Acknowledged with the version and date, and while the page matches the approved version, the Compliance item on the Confluence page includes You acknowledged. Your acknowledgements are also listed under My history on the My Tasks tab.
What exactly you acknowledge
You always acknowledge the approved version of the policy, not whatever is on the page right now. The app records which version that was (its Confluence page version) and a fingerprint of its content, so your acknowledgement can be tied to the exact text you read.
- If someone has edited the page since it was approved, the panel says The page has edits that aren't approved yet. Read the approved version linked above. Read the linked version, then acknowledge as usual.
- If a newer version is approved while you're reading, the app refuses your click with A newer version of this policy was approved. Reload and read it before acknowledging. Read the new version and try again.
Note: if you've just joined a team or a group, a policy may appear in My Tasks as Not yet required. The app adds you to the list of people who must acknowledge it during its daily check. You can acknowledge it straight away, and it counts.
When a policy changes later
Whether you're asked again depends on how the change is approved:
| What happens to the policy | What it means for you |
|---|---|
| The page is edited, but the new version isn't approved yet | Nothing. The approved version stays the one to acknowledge. |
| A new version is approved as a minor change | Nothing. Your existing acknowledgement still counts. |
| A new version is approved as a material change | You're asked to acknowledge the new version, with a new due date. |
The policy owner decides when they submit a new version: the submit form has a Material change (employees must acknowledge it again) checkbox, meant to be left off for typo fixes and formatting. See Policies and approvals. Your earlier acknowledgements always stay on record.
Which policies need acknowledging
Not every policy asks employees to acknowledge it. Policies that everyone should read, such as the Acceptable Use Policy and the Code of Conduct, do. More specialist ones, such as the Risk Management Policy, don't; they are still approved and reviewed. The SOC 2 content reference lists which policies require acknowledgement.
When you create a custom policy by importing an existing page, the import has an Employees must acknowledge it once approved option, selected by default. See Importing and custom policies.
Set a policy's audience
A policy's audience is the set of people who must acknowledge it. There are two choices:
- All employees (the default)
- Everyone in the Employee groups chosen under Settings > Access.
- Specific groups
- Everyone in the Confluence groups you pick, whether or not they are in the employee groups. For example, the Secure Software Development Policy could go to your engineering group only.
Compliance Admins set the audience:
- In Compliance in a Box, open the Policies tab and click the policy.
- In the Audience section, choose All employees or Specific groups.
- For specific groups, pick them under Groups that must acknowledge.
- Click Save audience.
Each audience change is recorded in the audit log.
How an audience change affects an open campaign
The list of people asked in the current campaign was fixed when it opened, and saving a new audience doesn't rewrite it. But the app's daily check compares each open campaign with the policy's current audience. So after you change an audience, the next daily check:
- asks people who are now in the audience but weren't asked yet, due 30 days from that day;
- stops requiring people who are no longer in the audience and haven't acknowledged yet (they show as Left the audience).
Acknowledgements already given are never removed. Changing the Employee groups in Settings works the same way for every policy whose audience is All employees. The next campaign uses the new audience in full.
How acknowledgement campaigns work
An acknowledgement campaign is one round of asking a policy's audience to acknowledge one approved version.
When a campaign opens
- When a policy that requires acknowledgement is approved for the first time.
- Every time a later version is approved as a material change.
A version approved without the material-change box opens no campaign: the current one carries on, and acknowledging either the earlier or the newer version counts. If a campaign that should have opened didn't (for example, because of an interruption), the app's daily check opens it. Retired policies never get a new campaign.
Who is asked, and by when
When a campaign opens, the app lists everyone in the policy's audience at that moment. For a large audience this takes a little while, and the policy shows Acknowledgements: preparing the list of people who must acknowledge… until it's done. After that the policy page shows when the campaign opened and its due date.
Everyone in the campaign has 30 days from the day it opens. After the due date, anyone who hasn't acknowledged is Overdue. People added later have 30 days from the day they're added.
When a newer campaign replaces an older one
A new campaign replaces the policy's previous one. Requests to acknowledge the old version disappear from people's tasks and from the tracking views; everyone in the audience is asked to acknowledge the new version instead. The old campaign stays in the audit log and in the Policy Acknowledgement Report.
People who join or leave the audience
Once a day, the app compares each open campaign with the policy's current audience:
- Joiners (new hires, people who move into an audience group) are asked to acknowledge the current version, due 30 days from the day they're picked up. If they had already acknowledged it, that counts at once.
- Leavers who hadn't acknowledged are no longer required and show as Left the audience. If they come back while the campaign is still current, they're asked again with a new due date.
The daily check never adds deactivated or closed accounts. If an audience suddenly has no members at all, for example because its group was deleted, the app releases nobody; check the policy's audience instead.
Track acknowledgements
The Acknowledgements tab shows who has acknowledged the current version of each policy. Only Compliance Admins see it: who has and hasn't acknowledged is personal information.
Policy owners see the percentage acknowledged for their own policies, in the Acknowledged column of the Policies tab and on each policy's page in the app.
By policy
The By policy view has one row per policy, with its Audience, the approved Version being acknowledged (Not approved yet if there's no campaign), the Opened and Due dates, Progress (acknowledged out of required, with a percentage), and the Outstanding and Overdue counts.
Click a policy's name to see everyone in its campaign: each person's State, Due date, when they acknowledged and which page version, and when they were Last reminded. Use Show to filter by state, and Load more to see more people.
By employee
The By employee view has one row per person and one column per policy with a current campaign. Filter by Policy, State or Person, and turn on Include former users to include deactivated and closed accounts. A dash means the person isn't asked to acknowledge that policy's current version.
What the states mean
| State | Meaning |
|---|---|
| Acknowledged | The person acknowledged this version, or a later one. |
| Outstanding | Not acknowledged yet, and not past the due date. |
| Overdue | Not acknowledged, and past the due date. |
| Not required | The person no longer has to acknowledge it. The label shows why; see When an acknowledgement is no longer required. |
Progress counts only people who are still required. Someone who was released but had acknowledged anyway counts as acknowledged. When nobody is required, progress shows a dash rather than 100%.
For your auditor, the app keeps a Policy Acknowledgement Report among the generated Evidence & Reports pages, and every acknowledgement is recorded in the audit log. See Evidence, reports and audits.
When an acknowledgement is no longer required
A person can stop being required to acknowledge a policy for several reasons. They then show as Not required, labelled with the reason below. In every case, acknowledgements they already gave are kept.
| Label | What happened |
|---|---|
| Left the audience | They're no longer in the policy's audience. They're asked again if they rejoin while the campaign is current. |
| Excused | A Compliance Admin excused them, with a reason (see below). |
| Former user | Their account was deactivated on your site. If it's reactivated, they're asked again with a new due date. |
| Account closed | Atlassian closed the account. The app then erases the account from its records, and the person appears as Former user from then on. |
| Policy retired | A Compliance Admin retired the policy, so nobody needs to acknowledge it any more. |
For more on deactivated and closed accounts and how the app handles personal data, see Administration.
Excuse someone
Use this for someone who shouldn't have to acknowledge the current version, such as a person on long-term leave.
- On the Acknowledgements tab, in By policy, click the policy's name.
- Find the person (their state must be Outstanding or Overdue) and click Excuse.
- Enter a reason under Reason (kept in the audit log).
- Click Excuse.
The person then shows as Excused; hover over the label to see your reason. Excusing covers only the current version: if a material change opens a new campaign, they're asked again.
Reminders
With the Policies to acknowledge reminder switched on (it is by default, under Settings > Reminders), the app reminds people automatically: when they're first asked, shortly before the due date, and a limited number of times while overdue. Compliance Admins can also send a reminder by hand from the Acknowledgements tab: Remind on a policy's row reminds everyone outstanding after you confirm, and Remind next to a person in the policy's list reminds just them. Each reminder is a task on the person's private Compliance tasks page, so Confluence notifies them, and anyone already reminded today is skipped. How reminders work and how to tune them is in Dashboard, tasks and reminders.