Policy Library and Drafting
Your policies can start from the built-in AI policy library — ten templates, from the AI Governance Charter to the AI Incident Response Policy — or be drafted by Watney from your organization's own context.
Adopting from the library, as a set
Choose Start from a template on a new policy. Each template's statements are tagged with the framework controls they address, and the policy saves as a draft for you to review.
Templates depend on each other for their defined terms: the Acceptable Use Policy, for example, uses "system owner" from the AI Governance Charter and "risk tier" from the AI Risk Management Policy. When a template relies on policies you do not have yet, the form offers them, ticked, and adopts them as drafts with it. Untick any you already cover another way. Nothing is adopted without being shown.
Drafting with Watney
- On the Policies page, click ✨ Draft with Watney (org admins, when AI is enabled).
- Pick a policy type and generate. Watney drafts a full, sectioned policy tailored to your team size, vendors and assessment posture, inserting
[PLACEHOLDER: …]markers wherever a specific fact is required but not known. - Review the preview, then Save as draft policy. It lands in your library with draft status and version 0.1.
Grounding & safety
- The model receives your organization's name and aggregate context (counts and posture summaries), plus the text you supply: your drafting instruction and the current policy's own headings and body. Those are free text, so they may contain personal data, and they are sent to the AI model provider to produce the draft.
- Watney is instructed not to claim your organization performs a control it hasn't indicated, and to use placeholders for unknown facts; check the draft for any statement your organization cannot support.
- The output is always a draft. Complete every placeholder, edit for your environment, and obtain legal/compliance sign-off before activating it — saving a draft never activates a policy.
Publishing it
A policy can't jump from draft straight to active. It has to pass through under review first, because a policy should be reviewed before it is adopted — and once a policy is active you can send it to your workforce to acknowledge. A signed acknowledgment of text nobody reviewed is weaker evidence than no policy at all.
So the route is Draft → Under Review → Active, from the policy editor or by selecting policies on the list and changing their status together. Activating also requires that no [PLACEHOLDER: …] marker remains and that a next review date is set.
You can retire a policy from any state. A retired policy can come back as a draft or go under review, but never straight to active — a reinstatement gets the same scrutiny as a new publication. Restoring an older version deliberately returns the policy to draft for the same reason.