Evidence

Policies

Create policies by hand, from a template, with AI, or from Confluence; approve, review, and download the master list.

RolesViewerEditorAdminRoute/policiesShown toCompliance organizations

What it is

Policies are the governing documents your frameworks expect: the information security policy, access control policy, incident response plan, and so on. The policies page lists them with status, version, type, owner, review date, and the controls and frameworks each one covers. From here you create new policies, approve or delete them in bulk, and download the master document list an auditor asks for. Editing happens in the policy editor.

Where to find it

EvidencePolicies
The policies table with status and framework filters and the insight stripThe policies table with status and framework filters and the insight strip
The policies page. Audit readiness is the share of policies approved.

The insight strip shows Audit readiness, Policies, Approved, and Draft.

Key actions

Create a policy

Click the create button in the header.
Enter a title (placeholder "New policy").
Pick a Source, described in the table below.
Set the Frequency, the review cadence the policy's next review date is computed from.
Click Create policy, Generate policy, or Import policy, depending on the source.
The create policy dialog with the four source options and the frequency selectThe create policy dialog with the four source options and the frequency select
The create dialog. The submit button changes with the source.
SourceWhat happensSubmit button
ManualAn empty policy opens in the editorCreate policy
TemplatePick from Choose a template; the template body is copied into a new draftCreate policy
AI generatedDescribe the policy ("Describe the policy you want to generate. Noru will use your organization context, frameworks, evidence, risks and controls as input.") and a draft is written for youGenerate policy
From integrationPick a Confluence integration and page; the page is imported as a draft noted "Policy imported from Confluence"Import policy

New policies open as Draft.

Search and filter

Search reads "Search policies…". Filters are Framework, Status, Type, and Owner. Columns are Policy ID, Version, Name, Type, Description, Status, Controls, Frameworks, Review Date, Owner, and Last Updated.

Approve in bulk

Select rows and click Approve. The Approve Policies dialog confirms; policies that are already approved or archived are skipped. Approving from the list applies to the current content, so read the draft in the editor first when it was generated or imported.

Delete in bulk

Select rows and use the delete action. The Delete Policies dialog confirms. Deleting removes the policy from every control it was linked to.

Download the master document list

Open the more menu and choose Download master document list. It exports a CSV of every policy with its version, status, owner, and review date, the usual format an auditor requests as the document register.

Open a policy

Click a row to open /policies/[id] in the policy editor.

Statuses and fields

StatusMeaningSet by
DraftdraftBeing written or revised; not yet counted as approvedCreation, generation, import, or Create New Draft
ReviewreviewContent is complete and waiting for an approverYou
ApprovedapprovedIn force; satisfies Required policy slots on linked controls and counts toward audit readinessYou, or bulk Approve
ArchivedarchivedRetired; kept for history and skipped by bulk actionsYou
ColumnMeaning
VersionCurrent version in the form year dot number, for example 2026.3
TypeThe kind of document, used by templates and filters
ControlsHow many controls link to this policy
FrameworksWhich frameworks those controls belong to
Review DateNext review, computed from the last approval and the Frequency

With no policies the page shows No policies found and Create First Policy.

Tips and gotchas

Generate first, then edit. AI generated and the framework regeneration dialog produce drafts that already reference your context answers; editing a draft is faster than writing from a blank Manual policy.

Bulk Approve does not read the policy

Approval is a compliance statement. Bulk Approve is for policies someone has already reviewed in the editor, not for clearing the Draft count.

Approving a policy does not bump its version. Versions change only when content changes; see the policy editor.

What Noru does not do

A generated or imported policy is a draft written from your context and the framework's expectations. Noru does not know whether your organization does what the draft says, does not send it for legal review, and does not notify staff when it is approved; acknowledgement campaigns are run separately under Training and acknowledgement.

Last updated on