User guide

Importing and custom policies

For Compliance Admins who already have policies written in Confluence. This chapter covers copying that text into the app's policy pages, adding policies the framework doesn't include, and retiring them later.

  • Compliance Admins

When to import

When the app sets up your compliance space, every policy page starts from a template. If your company already has policies written down in another Confluence space, you don't have to retype them. You can copy their text into the app's managed policy pages, and bring in policies that have no template as custom policies.

Importing only copies text. It never approves anything and never carries over approvals or sign-offs from the old pages: every imported policy still goes through the normal approval workflow described in Policies and approvals.

Two ways to bring in text

Each policy's page in the app (Policies tab, then the policy) has a Bring in existing text section while nothing is waiting for approval. It offers two routes:

Paste it in
Open the policy page in the Confluence editor, replace the text with yours, publish, then come back and Submit for approval. This is an ordinary page edit, so the policy owner can do it too. Attachments and images have to be re-added by hand.
Import from another page
Compliance Admins can copy the text of one or more existing Confluence pages with the import wizard. This is the better choice when you have several policies to bring in, or a policy with no template.

The rest of this chapter is about the import wizard.

Before you start

  • Compliance Admins only. Only Compliance Admins see the import wizard and can run it.
  • Set up the space first. The compliance space and its pages must already be generated.
  • You only see pages you can open. The wizard searches Confluence as you, so it finds pages in any space you have permission to view, and nothing else. A restricted page you can't view won't appear, even though it exists.
  • Pages the app manages can't be sources. They show Managed by the app in the search results.
  • Policies waiting for approval can't be imported into. An import would change the page under the approvers, so withdraw the submission or let it be decided first.
  • One import at a time. Only one import can run on your site at once, with up to 100 pages in it.
  • A license is required. While the app's license is inactive it is read-only, so imports (and retiring policies) are refused. See Administration.

Use the import wizard

Open the wizard in one of these ways:

  • On the Policies tab, click Import existing policies.
  • In Settings, under Frameworks & pages, click Import existing policies (optional) once all pages are set up.
  • On a policy's page, in Bring in existing text, click Import from another page. The wizard then preselects that policy as the target of the first page you add.

The wizard has four steps: Pick pages, Map to policies, Review and Import.

Step 1: Pick pages

  1. Type part of a page title in Page title. Results appear as you type, newest changes first.
  2. Optionally, enter a Space key (optional) to search a single space. Click Show more for further results.
  3. Click Add next to each page you want to import. The app reads the page and lists anything that won't copy cleanly (see What is and isn't copied). Hover a warning to see what it means.
  4. Check the Pages to import list. Click Remove to drop a page.
  5. Click Next: map to policies.

Step 2: Map to policies

On the left, Policies not mapped yet lists the policies no page is mapped to, untouched ones first. Untouched means the page is still the template as it was created; Edited means someone has changed it. On the right, Your pages lists each page you picked with its warnings.

  1. For each page, choose a target in Import into:
    • an existing policy, to replace its text (edited policies are marked (edited)), or
    • New custom policy, for a policy the framework doesn't have. Give it a Policy title (it starts as the source page's title) and decide whether Employees must acknowledge it once approved. This is ticked by default.
  2. If the target policy has already been edited, tick the box that confirms you want to Replace the edited text of that policy. Older versions stay in the page history.
  3. If the page has content that won't survive the copy, tick I understand what won't be copied.
  4. Click Next: review. The button stays disabled until every page has a target and every required box is ticked.

Each policy can receive only one page per import, and a policy that is waiting for approval isn't offered as a target.

Step 3: Review

The review lists each page and what it will be Imported into. Check it, then click Import 1 policy (or Import N policies). Click Back to change anything.

When you confirm, the app checks each page again. If a source page changed since you added it, or a target policy was submitted for approval in the meantime, the import stops, nothing is written, and the wizard tells you what to fix.

Step 4: Import

The pages are written in the background. You'll see a progress bar and a table with a status for each page: Waiting, Writing, Imported, Failed or Skipped. When a page is done, click Open the policy to go to it.

The import ends with Import finished, or Import finished with problems if some pages weren't imported. The table explains why, for example because someone edited the policy page while the import ran, or the policy page is in the trash. Fix the cause and import that page again.

Note: if you leave the wizard after starting an import but before confirming it, the wizard shows An import was started but never confirmed the next time you open it. Nothing has been written yet: click Discard it to start again. Unconfirmed imports are discarded automatically after 24 hours.

What is and isn't copied

The import copies the page's text and formatting as they are. The source page itself is never changed. Some content can't come across cleanly, and the wizard warns you about it per page:

WarningWhat happensConfirmation needed
Attachments not copied Attachments and images stored on the source page aren't copied, and neither are macros that display the page's own files. They show as broken until the owner re-attaches them. The wizard names example files so you know what to re-add. Yes
Dynamic content Macros that show other content (include, children, Jira and similar) change what readers see without a new page version, so an approval can't pin them. Replace them with the text itself before approving. Yes
Mentions The page mentions people or assigns tasks. Copying it notifies them: Confluence emails everyone mentioned. Yes
Too large Pages over 900 KB can't be imported. Split the page, or paste it into the policy page by hand. Can't be imported
Task list Task lists are copied as they are, including ticked items. No
Inline comments Inline comments stay on the source page; the highlighted text is kept. No
External images Images linked from another website are kept as links, but they can change without a new page version. No
Macro: name A macro the app doesn't recognise is copied as it is. Check that it renders the same. No

Page comments, labels, restrictions and the source page's history stay with the source page.

After an import

  • A new, unapproved version. The imported text becomes a new version of the policy page. Its page history shows it as imported from the source page by Compliance in a Box, and older versions stay in the history.
  • Draft or changes pending. A policy that was never approved is a Draft; one that was approved before shows Changes pending. The last approved version stays the approved one until the new text is approved.
  • Nothing is approved or sent for acknowledgement. Importing doesn't create approvals or acknowledgement campaigns. The owner reviews the text, re-attaches any files, and clicks Submit for approval as usual.
  • Recorded in the audit log. Each imported page, and each custom policy created, is recorded in the audit log (the Audit Log tab).

Tip: remove or replace dynamic macros and re-attach images before submitting. Approvers approve the exact page version they review, and any later edit cancels the submission.

Custom policies

A custom policy is a policy your company needs that the framework doesn't provide a template for, such as a remote work policy. You create one by mapping a page to New custom policy in the import wizard; that is the only way to add one. If the policy isn't written yet, import a short placeholder page and write the rest in the new policy page.

When the import runs, the app:

  • creates a new page under Policies in the compliance space, with the imported text and the title you gave it. The title must not match another page in the compliance space;
  • makes you, the admin who ran the import, its owner and its approver. Change them in Settings → Owners & approvers;
  • locks the page like every other managed page, so only its owner and Compliance Admins can edit it;
  • sets a yearly review, and requires acknowledgement once approved unless you unticked that option.

From then on a custom policy follows the same lifecycle as any other policy: submission, approval, acknowledgement campaigns, reminders and annual review. It appears on the Policies tab with a Custom label, in My Tasks, in acknowledgement tracking and in the policy approval log.

The difference: custom policies aren't mapped to framework controls, so the Controls Matrix doesn't list them. Unlike framework policies, a custom policy can be retired.

Retire a custom policy

When a custom policy is no longer part of your program, retire it. Only custom policies can be retired. Framework policies are what the framework requires, so they stay.

  1. Open the policy from the Policies tab.
  2. Click Retire policy. The button is shown to Compliance Admins and is not available while a version is waiting for approval.
  3. Under Why is it retired? (required), enter a reason of at least 10 characters. It is kept in the audit log.
  4. Click Retire policy to confirm.

When a policy is retired:

  • nobody is asked to acknowledge or review it any more. Open acknowledgements are waived and show as Policy retired;
  • it leaves the dashboard, My Tasks, reminders and new acknowledgement campaigns, and it can't be submitted for approval or imported into;
  • it stays on the Policies tab with a Retired label, the date and the reason. Its approvals, acknowledgements and history stay as evidence, and the retirement is recorded in the audit log;
  • the Confluence page stays where it is. Archive it yourself if you like.

Important: retiring can't be undone. If you might need the policy again, keep it active instead.