What you'll achieve
You'll bring existing policies, framework adoptions and assurance responses into a pack, check the view for an intended audience, and publish that reviewed view.
Who this is for
This guide is for an Organisation Collaborator with the permission or assigned action described below. If the navigation or action is missing, check the selected organisation, effective account level, feature state and role before assuming the product is unavailable.
Before you start
Check that you have:
- Permission to create and publish compliance packs.
- An agreed audience and purpose for sharing.
- Current source records and approval from their owners.
1. Create the pack
Open Assurance > Compliance packs and choose Create compliance pack. Give it a clear title and description so the recipient can tell which organisation, service or period it covers. Complete the required fields and save, then open the pack.
2. Add existing content
Open Contents. Under Add content, search for the policies, framework adoptions or assurance responses you want to include. Select the existing records. Review the Content, Type, Position and Status columns; an item being selectable does not mean it is ready to share.
3. Set each item's sharing
Use Manage sharing beside an item where available. Review its disclosure level and Live or Snapshot mode. Live content can reflect later source changes; a Snapshot represents the selected point in time. Organisation ceilings and tighter source restrictions can limit what the recipient receives.
4. Preview the intended audience
Choose Preview sharing. Select the relevant scenario: Client, Group administrator, Auditor or Public. Choose Refresh preview after changing the scenario. Read the actual recipient view, including exclusions and owner-cap reasons. These are audience scenarios; selecting Client is not the same as inviting a particular client.
5. Publish the reviewed view
Check the download option and the exact content the recipient can see. Choose Publish reviewed view for the initial publication or Publish scenario for an additional scenario when available. A changed preview needs a fresh review. Then verify the intended relationship or public sharing route separately.
6. Maintain the pack
Published contents are locked. If a change is needed, follow the displayed unpublish route before editing, then preview and publish again. Explain the change to affected recipients where necessary. Removing an item from the pack does not delete the source record.
Check it worked
- The pack shows its expected publication state.
- The reviewed scenario includes only the intended records and fields.
- Download permission and Live/Snapshot choices match the sharing decision.
- The intended recipient route works with the recipient's access.
If something goes wrong
| What you see | What to do |
|---|---|
| Content is absent from the preview | Inspect the source restriction and organisation disclosure ceiling. Ask the owner rather than widening disclosure automatically. |
| Publish is unavailable | Refresh and review the current scenario, then check publication permission. |
| Contents cannot be edited | The pack is published. Follow the unpublish-and-review lifecycle. |
| A recipient still cannot open the pack | Check their relationship and access; publishing a scenario does not itself establish every recipient relationship. |
Human judgement, security and privacy
The preview is the most useful check before disclosure: read it as the recipient would. Public means openly accessible, so remove confidential or unnecessary personal information before publishing.
What's next
Record the audience and review date. Revisit the pack when a linked policy, credential or assurance response changes.
Need help?
Use your organisation's approved Backstory support route. Include the organisation, page and action that failed, but do not include passwords, invitation links, secret keys or unnecessary personal or confidential content.