Skip to main content

Policies

21 articles
Policy Center OverviewUse the Policy Center to manage the policies required for audit readiness and ongoing compliance. From a single place, you can create, edit, review, approve, publish, and track policies throughout…
Create a policyThis article explains how to create a custom policy and replace an existing Drata template.
Assigning Policies to Specific GroupsControl which personnel must acknowledge each policy by assigning policies to specific identity provider groups, all personnel, or no personnel.
View and edit a policyThis article explains who can edit a policy, how to make updates, and how approvals and versioning work in the new experience.
Add comments in your policyThis article explains when you can comment or edit a policy, how comments work, and how Policy Owners manage edits during reviews.
Delete a Policy DraftLearn how to delete a policy version in Draft status, including which policy types and versions can be deleted.
Understanding the Approval ProcessLearn how policy approvals work in Drata, how to configure approvers and tiers, and how to publish a policy once approval is complete.
Policy Owner Notifications
Map policies to controls in DrataMapping policies to controls allows Drata to evaluate control readiness and run policy-related compliance tests.
Manage policy renewals
Download your Policies
Archive and restore policiesThis article explains when policies can be archived, why some policies can’t be archived, and how to restore archived or replaced policies.
External Policy: Use BambooHR to manage your policiesUse this workflow if your organization manages policies and acknowledgments in BambooHR and uses Drata for audit evidence and control mapping.
External Policy: Use Confluence or Notion to manage your policiesUse this workflow if your organization manages policy content in Confluence or Notion and uses Drata as the system of record for audit evidence and control mapping.
Managing Policies Synced from Confluence in Drata
Manage and Configure Policy Controls in Drata
Creating an SLA for Employee Onboarding CompletionUse this article to understand and configure the onboarding grace period that determines when compliance tests begin evaluating new personnel.
AI-powered control suggestions for policiesUse AI suggestions to map policies to controls, reduce manual work, and keep compliance mappings accurate and up to date.
Configure Policies to Support Compliance Test Completion in Drata
Linking directly to specific employee security policiesEmbedding links to Drata policies in other tools or locations
Common Policy Management Issues in Drata (and How to Resolve Them)