User guide

Policies and approvals

For policy owners, approvers and Compliance Admins: how a policy is set up, who can change it, and how a new version gets reviewed, approved and kept on its review schedule.

  • Owners
  • Approvers
  • Compliance Admins

What a policy is

In Compliance in a Box, a policy is an ordinary Confluence page in your compliance space that the app manages. You read and edit it in Confluence like any other page. On top of the page, the app keeps track of:

  • An owner: the person accountable for the policy. The owner edits the page and submits new versions for approval.
  • Approvers: one to ten people who must approve each new version before it becomes the approved policy.
  • An audience: who must acknowledge the policy, either all employees or specific groups.
  • A review schedule: a next review date, worked out from the last approval.
  • A status: whether the page matches an approved version, is waiting for approval, or has changed since it was approved.

Every approval is tied to an exact Confluence page version, so you can always show which text was approved, by whom and when. The app never edits the text of a policy page after it creates it; only people change policy text, and every change shows up as a new version that needs approval.

The policies themselves come from the framework you chose during setup (see SOC 2 content reference). You can also bring in text you already have or add your own policies; see Importing and custom policies.

The Policies tab

Open Compliance in a Box and select the Policies tab. Everyone with a part in the compliance program sees it: employees, owners, approvers and Compliance Admins. It lists every policy with its status, owner and the exact version that was approved.

ColumnWhat it shows
PolicyThe policy's title. Select it to open the policy's page in the app.
StatusThe policy's status (see Status reference), plus extra labels where they apply: Required for you if you still need to acknowledge it, Page in trash, Page archived or Page deleted if the Confluence page was removed, and Custom or Retired for custom policies.
OwnerThe policy's owner.
Approved versionThe approved page version and approval date, for example "v8 · 2026-09-30". The link opens that exact version in Confluence, even if the page has been edited since.
Next reviewThe next review date, flagged Review due or Overdue when it is close or past (see Periodic reviews).
AcknowledgedThe share of the audience that has acknowledged the approved version. Compliance Admins see it for every policy and owners for their own; the column is hidden for everyone else.

Use the filter buttons above the list to narrow it down:

All
Every policy.
Awaiting my approval
Policies with a submitted version that is waiting for your decision.
Required for me
Policies you still need to acknowledge.
Mine
Policies you own.
Review due
Policies whose review is due within 30 days or overdue.

A policy's page in the app

Select a policy in the list to open its page in the app. This is where owners submit, approvers decide and everyone can see the policy's approval record. At the top you'll find the policy's status, owner, the current Confluence page version and the next review date, with Open page to go to the policy in Confluence and Back to Policies to return to the list.

Below that, depending on your role and the policy's state, the page shows:

  • Action buttons: Submit for approval, Mark as reviewed, Approve, Reject and Withdraw submission. You only see the actions you can take right now.
  • Your acknowledgement, if you are in the policy's audience. See Policy acknowledgements.
  • Pending submission: the page version that was submitted, who submitted it and when, the change summary, and each approver's decision so far (Waiting, Approved or Rejected, with their comment).
  • A warning about the last submission if it was rejected (with the approvers' comments) or cancelled (with the reason).
  • Approved version: the version that is currently the approved policy, its change summary, when it was approved and by whom. A submission marked as a material change carries a Material change label, and a "no changes" review carries Review only.
  • Bring in existing text: for owners and Compliance Admins, instructions for pasting in policy text you already have. See Importing and custom policies.
  • Audience: for Compliance Admins only (see Setting the audience).
  • History: a table of past submissions with the Version (linked to that exact page version), who submitted it and when, the Outcome (Pending, Approved, Rejected or Cancelled) and each approver's Decisions. It shows the most recent submissions; the full record is in the audit log and the Policy Approval Log report (see Evidence, reports and audits).

Who can edit a policy

Every policy page is locked: only the policy's owner and Compliance Admins can edit it. Everyone else who can see the compliance space can read the page (and, where your site allows it, comment), but can't change the text.

The lock exists because a policy is a commitment your company makes to its auditor. Keeping edits to the accountable owner and the people running the program means the approved text can only change in ways someone is answerable for, and every change becomes a new version that has to go through approval again.

The app sets the lock with Confluence page restrictions and keeps it in line with your assignments. When a Compliance Admin changes a policy's owner, the lock moves to the new owner. If someone removes a restriction by hand, the app's daily check puts it back and records the change in the audit log.

Note: Page restrictions need Confluence Standard or above. On Confluence Free, pages can't be locked, so anyone who can edit the space can edit every policy. The app warns about this in Settings. Approvals still work, because they are tied to page versions either way.

Assigning owners and approvers

Compliance Admins assign owners and approvers. When the app creates the policy pages, the admin who generated them becomes each policy's owner and approver; change these to the right people before you start submitting.

  1. In Compliance in a Box, open Settings and, under Permissions, select Owners & approvers. (A policy with no approver also links there from its page in the app.)
  2. Find the policy in the list and select Edit.
  3. In Owner, choose the person accountable for the policy. The owner can edit the page; nobody else can, except Compliance Admins.
  4. In Approvers, choose 1 to 10 people. Approvers must be able to see the compliance space.
  5. Select Save. If you changed the owner, the page lock and the owner's access to the space update in the background.

The same list covers recurring activities. Its Needs attention column flags problems to fix:

FlagWhat to do
No approverNobody can approve this policy, so it can't be submitted. Add at least one approver.
Can’t see the spaceThis approver doesn't have access to the compliance space. Give them access, or choose someone else.
Former user: pick a new ownerThe owner's account was deactivated or closed. Choose a new owner.
Former user: replace this approverAn approver's account was deactivated or closed. Replace them.

Important: The approvers of a submission are fixed at the moment it is submitted. Changing a policy's approvers affects the next submission, not one that is already waiting. To apply new approvers to a pending submission, withdraw it and submit it again.

Setting the audience

A policy's audience decides who must acknowledge it. Compliance Admins set it in the Audience section of the policy's page in the app:

  • All employees (the default): everyone in the employee groups chosen in Settings.
  • Specific groups: only the Confluence groups you pick under Groups that must acknowledge, for example an engineering group for a secure development policy.

Select Save audience to keep your choice. Changes apply to the next version that needs acknowledging; people already asked to acknowledge stay asked. Acknowledgements are covered in full in Policy acknowledgements.

Editing and submitting a version

Policy text lives in Confluence, so you write and edit it there as normal. As soon as you publish an edit to an approved policy, the app notices and the policy's status changes to Changes pending. You don't have to open the app for this to happen. When the text is ready, submit it for approval.

The owner or a Compliance Admin can submit. You can do it from the policy's page in the app or from the byline on the Confluence page itself (see The byline on a policy page).

  1. Publish your edits to the policy page in Confluence.
  2. Select Submit for approval.
  3. The form confirms which page version you are submitting. Under What changed?, describe the changes for the approvers. This is required.
  4. Decide whether to tick Material change (employees must acknowledge it again). Tick it when the change affects what people must do; leave it off for typo fixes and formatting. This option doesn't appear on a policy's first submission.
  5. Select Submit. The policy's status changes to Pending approval.

The button is unavailable until the policy has at least one approver. If you open the form and someone publishes another edit before you submit, the app refuses the submission and asks you to reload, so you never submit a version you haven't seen.

What "material" means

The first time a policy is approved, everyone in its audience is asked to acknowledge it (for policies that require acknowledgement). After that, only approving a version marked as a material change opens a new acknowledgement campaign and asks the audience to acknowledge again. A minor change, once approved, becomes the approved policy without asking anyone to acknowledge again. See Policy acknowledgements.

Mark as reviewed: approving with no changes

If the page's content is identical to the approved version, you see Mark as reviewed instead of Submit for approval. Use it for a periodic review where nothing needs to change. The note is optional (it defaults to "Reviewed: no changes."), it is never a material change, and it still goes to the approvers like any other submission. Once approved, it counts as the policy's review.

Approving or rejecting

When a version is submitted, each of its approvers needs to decide on it. As an approver, you'll find it in a few places:

  • My Tasks, under Approvals waiting for you (see Dashboard, tasks and reminders).
  • The Awaiting my approval filter on the Policies tab.
  • The byline on the policy page, which reads Your approval needed.

To decide:

  1. Read the submitted version. The page version link in the decision form, and the version links on the policy's page in the app, open exactly the text that was submitted.
  2. Select Approve or Reject, either on the policy's page in the app or in the byline.
  3. Add a comment. It is optional when you approve; when you reject, Why? (required) must be filled in so the owner knows what to fix.
  4. Confirm with Approve or Reject.

How a version gets approved

  • Every approver must approve. The version becomes the approved policy when the last of its approvers approves. Until then, the app records your decision and shows "waiting for the other approvers".
  • One rejection is enough to send it back. The submission ends, and the owner can revise the page and submit again. The approvers then decide on the new submission from scratch.
  • Each approver decides once per submission. A decision made after the outcome is settled is kept on record but doesn't change it.
  • Only the approvers fixed at submission count. Compliance Admins can't approve on someone else's behalf.

When a version is approved, it becomes the policy's approved version, its next review date is set, and, if it is the first approval or a material change, an acknowledgement campaign opens.

Withdrawn and cancelled submissions

A submission can end without a decision in three ways. In each case the policy's page in the app shows The last submission was cancelled with the reason, and the owner can submit again when ready.

The owner or an admin withdraws it
Select Withdraw submission on the policy's page in the app. Use this to fix something before the approvers decide, or to apply changed approvers. Withdrawing isn't available from the byline.
The page is edited after it was submitted
Any published edit to the policy page cancels a pending submission automatically. Make your edits, then submit the new version.
The page is trashed, archived or deleted
A removed page can't be approved, so its submission is cancelled and the policy is flagged (for example Page in trash). Restore the page in Confluence to carry on.

Why edits cancel a submission

Approvals in Compliance in a Box are version-bound. A submission records the exact Confluence page version and a fingerprint (a hash) of its content. An approver's decision is accepted only if the page is still at that version; if it has moved on, the app cancels the submission instead of recording the decision, and tells the approver "The page was edited after it was submitted, so the submission has been cancelled. Ask the owner to resubmit." This guarantees that nobody approves text they haven't seen, and that the approved version you show an auditor is precisely what was approved.

The same binding protects approved policies. Editing an approved page doesn't change the approval: the approved version stays exactly as approved, and the policy shows Changes pending until the new text is approved too.

The byline on a policy page

Every managed policy page shows a Compliance in a Box item in its byline, just below the page title. Its label tells you the policy's state at a glance, starting with anything you personally need to do:

Byline labelMeaning
Your approval neededA submitted version is waiting for your decision.
Please acknowledgeYou are in the audience and haven't acknowledged the approved version yet.
Approved v7 · 2026-03-01The page is the approved version (here, page version 7, approved on that date). It may end with You acknowledged, Review due or Review overdue.
Changes pending approvalThe page has been edited since it was approved.
Awaiting approvalA version has been submitted and is waiting for its approvers.
DraftNo version has been approved yet.
Page in the trash, Page archived, Page deletedRestore the page to keep it in the compliance program.

Select the byline item to open a small panel. It shows the status, a link to the approved version (or Not approved yet), the owner and the next review date. When the page has unapproved edits it says so, for example "This page (v9) has changes that aren’t approved yet." Depending on your role, the panel also lets you:

  • Acknowledge the policy, if you are in its audience.
  • Submit for approval or Mark as reviewed, if you are the owner or a Compliance Admin.
  • Approve or Reject, if you are an approver of the pending submission.

The panel also shows which page version is waiting for approval and each approver's decision, and warns when the last submission was rejected. These use the same forms and rules as the app. Select Open in Compliance in a Box to go to the policy's page in the app, for example to withdraw a submission or see the full history.

Periodic reviews

Each policy has a review cadence, which is 12 months for the SOC 2 policies. The next review date is the date of the latest approval plus the cadence. Every approval counts as a review, whether it approves changed text or a Mark as reviewed submission, so approving a new version also resets the review clock.

  • From 30 days before the date, the policy is flagged Review due.
  • After the date has passed, it is flagged Overdue.

The flags appear in the Next review column and the Review due filter of the Policies tab, on the policy's page in the app, in the byline, and in the owner's My Tasks. The app also records each due and overdue review in the audit log, once per review cycle. A due or overdue review doesn't change the policy's status or its approved version; the policy stays approved until someone edits it.

To complete a review as the owner:

  1. Read the policy and decide whether it still reflects how your company works.
  2. If nothing needs to change, select Mark as reviewed and submit.
  3. If it needs changes, edit the page in Confluence, then select Submit for approval.
  4. Once the approvers approve, the next review date moves forward by the cadence.

For reminders about upcoming reviews, see Dashboard, tasks and reminders.

Self-approval and independent approvers

An owner can also be an approver of their own policy, and whoever submitted a version can approve it. The app allows this, because a new installation starts with the same admin as owner and approver of everything, but it doesn't hide it:

  • When you approve a policy you own or submitted, the form warns you with Self-approval: your approval is recorded as a self-approval, and auditors may ask for an independent approver.
  • Self-approvals carry a Self-approval label next to the decision wherever approvers are listed.

An approval is independent when at least one of the approving decisions came from someone other than the owner and the submitter. If a policy's approved version has no independent approval, the Compliance Admins' Dashboard lists it under "approved without an independent approver", and the Policy Approval Log report and the audit log record that there was no independent approver. To fix it, add another approver in Owners & approvers and have the next version approved by them, or be ready to explain the arrangement to your auditor.

Status reference

A policy's status is worked out from its approved version, any pending submission and the current Confluence page version.

StatusMeaningWhat happens next
DraftNo version has been approved yet. New policy pages start here.The owner reviews the text and submits it for approval.
Pending approvalA page version has been submitted and is waiting for its approvers. The byline reads Awaiting approval.All approvers approve, or one rejects. Editing the page, withdrawing or removing the page cancels the submission.
ApprovedThe page is exactly the approved version.Nothing until the next edit or review.
Changes pendingThe page has been edited since the approved version. The approved version still stands. The byline reads Changes pending approval.The owner submits the new version for approval.

After a rejection or a cancelled submission, the policy goes back to the status it had before the submission, usually Draft or Changes pending. On a submission, the outcomes in the history are Pending, Approved, Rejected and Cancelled.