Join waitlist
Introducing PolicyWizard

Policy operations for teams that need audit proof, not paperwork.

Draft or securely import policies, route decisions, assign and attest the right people, and export the evidence from one governed compliance workspace.

One launch email. See our privacy notice.

MultitenantMicrosoft Entra ID SSODocker or Azure-hosted
Illustrative policy workspace

Evidence, in view.

Ready
PDF/DOCXValidated import
DirectThreat coverage
ScopedDepartment access
Import Verified content
Access Scoped visibility
Evidence Coverage CSV
Mobile attestation Due today Cached offline
Hash-chain verified
Custom roles enforced
Coverage CSV export
Policy Detail Pending Review

Remote Work & Data Security Policy

v4 · IT & Cybersecurity · Edited 3 days ago

What shipped since the last site refresh

Threat coverage Compare declared policy controls with Agent Threat Rules targets, then export visibility-aware CSV evidence.
People & access A dedicated admin console brings user activation, department membership, role assignment, and custom permissions together.
Scoped visibility Keep policies tenant-wide or restrict them to selected departments across list, search, reading, exports, and version history.
Secure import Validated PDF and DOCX files up to 75 MiB become owned drafts with an import event in the audit trail.
Safer tenancy Operator-controlled bootstrap keeps the first administrator explicit, validated, and audit logged.

Built for compliance teams across regulated industries

Healthcare Financial Services Manufacturing Higher Education Insurance Government Contractors

How it works

From first draft to audit day.

One system carries every policy through its whole lifecycle — no spreadsheets, no email chains, no dropped threads.

01

Draft or import

Start from a curated template across seven compliance domains, or securely import a validated PDF or DOCX into an owned draft.

02

Route for approval

Per-policy, per-category, full workflow, or ad hoc — approval routing matches how your organization actually decides.

03

Publish & attest

Publish with version history built in, then collect and track employee attestations automatically.

04

Track & audit

Every edit, approval, and signature lands in a tamper-evident audit trail, ready to export on demand.

Everything compliance needs

One system, the whole policy lifecycle.

01

Guided templates & onboarding

Curated starter templates, reusable template packs, and onboarding flows that prefill policy drafts from tenant data.

02

Structured policy editor

Rich text editing with structured sections, cross-references, and parent/child policy relationships.

03

Version control & rollback

Full change history with unified diffs and automatic change-impact scoring — review exactly what changed and roll back to any prior version.

04

Sequential approval workflows

Ordered approval steps, per-policy or per-category routing, reminders, escalation, and ad hoc review when exceptions happen.

05

Attestation tracking

Automated attestation requests and reminders — including optional quiz-based comprehension checks with a pass threshold — tracked down to the employee.

06

Mobile-ready policy work

Native iOS and Android experiences combine MSAL and Microsoft Entra ID sign-in with assigned policies, approvals, notifications, and quiz-based attestations.

07

Offline cache & sync

Mobile clients keep assignments, policy content, and notifications available with cache-aware sync and health-checked server configuration.

08

Enterprise-ready access

Microsoft Entra ID SSO, mobile MSAL authentication, security groups, and role-based access with organization-scoped data.

09

Document export

Export any policy, including any past version, to PDF or Word (.docx) — ready to print, sign, or share outside the platform.

10

Notifications & webhooks

In-app and email notifications, plus signed webhook delivery to your own systems — each endpoint gets its own secret, shown once at creation.

11

People & Access

Manage tenant users, active accounts, department hierarchy and membership, role assignment, and custom-role permissions from one capability-aware console.

12

Threat coverage reporting

Compare explicit policy-control mappings with Agent Threat Rules targets, separate direct and missing evidence, and export a CSV for review.

13

Department-scoped visibility

Keep a policy tenant-wide or restrict it to selected departments; the same boundary applies across search, reading, exports, version history, and relationships.

Template library

Seven compliance domains, ready to go.

Start from a vetted template and adapt it, or build your own from scratch.

HIPAA

Privacy, security, and breach-notification policy for healthcare organizations.

OSHA

Workplace safety and hazard-communication policy for regulated worksites.

Finance

Financial controls, expense, and data-handling policy templates.

HR

Employee conduct, leave, and workplace policy templates.

IT

Acceptable use, data retention, and systems-access policy.

Cybersecurity

Incident response, access control, and data-protection policy.

General Compliance

Ethics, vendor management, and organization-wide policy templates.

See it in action

A compliance dashboard that actually gets read.

Status, approvals, reviews, and a compliance score — one screen, always current.

policywizard.app/dashboard
12
Draft
5
Pending Review
8
Approved
34
Published
6
Archived
94
Compliance Score
HIPAA 18
IT & Security 14
HR 11

Mobile and offline

Policy work follows the team, even when the network does not.

Native iOS and Android access now combines Microsoft Entra ID and MSAL authentication with health-checked server settings, cached policy content, offline-aware assignments, device-token lifecycle support, notifications, and attestation flows.

Policy reader

Employees can open assigned policies on iOS or Android, with cached content available after first load.

Approvals on the move

Approvers can see queues, review context, and act without waiting to get back to a desktop.

Attestation quizzes

Read-and-acknowledge or quiz-based attestations support comprehension checks and due-date tracking.

Connectivity-aware sync

Offline banners, cache-aware repositories, and background sync keep mobile work predictable.

Policy intelligence

Show where your policies meet changing risk.

Sync Agent Threat Rules intelligence, compare declared policy controls with relevant targets, and export a visibility-aware evidence file. The result is a clearer review queue, not an unearned compliance claim.

Capability feed Active
Evidence

Threat coverage reporting

Compare explicit policy mappings with Agent Threat Rules targets, distinguish direct, missing, ambiguous, and unmapped evidence, and export a CSV.

Admin

People & Access console

Tenant administrators can search people, manage active accounts, assign roles, and maintain departments with lockout and hierarchy safeguards.

Roles

Explicit custom permissions

Custom roles receive only the capabilities granted to them, while tenant isolation, policy visibility, lifecycle, and lock checks stay in force.

Visibility

Department-scoped policy access

Limit a policy to the departments that need it without creating a second repository or relying on a separate portal.

Security & compliance

Built for regulated data from day one.

Security isn’t a feature we bolted on. It’s the foundation everything else is built on.

Deployment-aware encryption

TLS protects data in transit. Integration secrets are encrypted, and at-rest protection uses supported cloud services or encrypted storage configured for your deployment.

Tenant isolation

Application data is scoped by organization and protected with role-based access controls.

Tamper-evident audit logs

Hash-chained logging supports tamper detection, admin search, long-term retention, reporting, and evidence-package export.

Enterprise SSO & custom roles

Microsoft Entra ID integration, security-group roles, and explicit custom permissions control who can read, change, approve, publish, and administer.

Connector abuse protection

Network guards reduce SSRF risk in directory and HRIS connectors, with TLS certificate checks for third-party integrations including ADP.

Safe document handling

Upload validation and DOCX zip-bomb protections help keep imported policy files inside expected operating limits.

Threat-intelligence guardrails

Agent Threat Rules metadata is bounded at import, and regex evaluation uses timeout-aware safeguards. Catalog, coverage, and runtime detection remain deliberately separate concerns.

Controlled tenant bootstrap

A validated, operator-controlled onboarding path creates the first administrator with a hash-chained audit event instead of a first-user-wins rule.

Deploy self-hosted via Docker, or fully managed on Azure — your infrastructure, your choice.

Integrations

Fits into the stack you already run.

PolicyWizard doesn’t ask you to change how your organization is structured — it plugs into the systems you already use for identity, HR, and day-to-day work.

01

Directory & identity sync

Sync users, groups, and access automatically from Microsoft Entra ID, on-prem Active Directory, or Google Workspace, so policy access always matches your org chart.

02

Publish where work happens

Push approved, published policies straight to SharePoint, Microsoft Teams, or Google Drive — no separate portal for employees to remember.

03

HRIS sync

Configure BambooHR, Workday RaaS, or ADP for auditable workforce synchronization that keeps existing people and department data current for assignments and attestations.

Early access plans

Simple plans, locked in early.

Pricing goes live at general availability. Join the waitlist to lock in founding-member rates.

Team

For a single department getting policy under control.

Early access founding rate at launch
Core template library
Up to 3 approval workflows
Standard dashboards
Email notifications
Join waitlist

Most popular

Business

For multi-department compliance programs.

Early access founding rate at launch
All 7 template domains
Unlimited approval workflows
Attestation tracking & reminders
Audit trail exports
Join waitlist

Enterprise

For regulated, multi-entity organizations.

Custom contact us
Microsoft Entra ID SSO & RBAC
Self-hosted or Azure-managed
Dedicated audit reporting
REST API access
Talk to us

FAQ

Questions, answered.

PolicyWizard includes controls designed to support HIPAA requirements, including transport security, access controls, retention settings, and tamper-evident audit logging. Compliance also depends on deployment configuration, signed agreements, and your administrative and physical safeguards.

Stress-free audits start with one signup.

Join the waitlist for early access to PolicyWizard — we’ll reach out as spots open.

One launch email. See our privacy notice.