Skip to main content

The Policy Wizard and AI-Generated Policies

Three ways to draft a policy — the step-by-step Wizard, a manual upload, or one-click AI generation for SOC 2 — plus how approval and publishing work.

Written by Upendra Varma

Manage → Organisation → Policies is your library of compliance policies. If you have SOC 2 enabled and haven't created its required policies yet, you'll see an offer to generate them automatically:

AI-generating your SOC 2 policies

Auto Generate Policies uses ComplyJet AI to draft every required SOC 2 policy for you in about two minutes, based on a few questions about your company. This only applies to SOC 2-linked policies — other frameworks show a plain "create your policy" option instead (Wizard or manual upload), not this AI path.

Drafting a policy manually

Open any draft policy to manage its versions:

You can populate a draft one of three ways:

  • Policy Wizard — fill in a step-by-step form, section by section, with merge-tag fields (like [Company Name]) auto-filled from your org details. Each section is previewed as rendered text and can be hand-edited if the template wording doesn't fit — with a Revert to Template option if you want to undo your edits back to the original wording.

  • Manually Upload — attach a file you've already written elsewhere.

  • AI auto-generate — as above, for SOC 2 policies.

Once wizard fields exist for a policy, the manual upload option disappears (and vice versa) — a policy is drafted one way or the other, not both.

Publishing from the Wizard

Publishing generates a branded PDF from your wizard content. This requires your company logo and legal name to already be set in Settings — if either is missing, publishing will fail with a message telling you so.

Approval and acceptance

Submit for Approval routes a version to whoever you pick as approver. Only that specific person sees an Approve button — everyone else just sees the pending status. Once approved, that becomes the current version employees are asked to read and accept; older approved versions stay visible but read-only, with no accept action.

Deactivating vs. deleting

Deactivate moves a policy to the Excluded tab — reversible, and the only option once any version exists. Delete only works for a custom policy with zero versions. If you need to permanently remove a policy that already has content, deactivating is as far as you can go.

Did this answer your question?