What you'll achieve
You will connect policy content, implemented controls, framework obligations and evidence without treating any one record as proof of compliance.
Who this is for
This guide is for an Organisation Collaborator with the permission or assigned action described below. If the navigation or action is missing, check the selected organisation, effective account level, feature state and role before assuming the product is unavailable.
Before you start
Check that you have:
- Permission to manage the relevant policies, controls or framework adoption.
- An accountable owner and review route.
- Source requirements and evidence.
1. Begin with the obligation
Open Frameworks and the adopted framework, or the source requirement you are addressing. Confirm scope, applicability and owner.
2. Reuse the control register
Open Controls and search before creating. Link the canonical control to each context where it applies and record local implementation and evidence separately.
3. Maintain the policy
Open Policies. Create or edit a draft, confirm ownership and lifecycle state, and link the controls or framework obligations it supports.
4. Review evidence
Check that evidence is current, relevant and attributable. An attachment proves only that a file exists; record what it demonstrates and the period it covers.
5. Move through review and publication
Use the agreed review or workflow route. Publication, approval and attestation are distinct events; confirm each state explicitly.
Check it worked
- The policy has an owner and correct lifecycle state.
- Controls are linked without duplicate canonical records.
- Framework status is supported by current evidence and review, not inferred from a document upload.
If something goes wrong
| What you see | What to do |
|---|---|
| A control already exists | Use the existing canonical control and add the contextual implementation. |
| Evidence is stale | Keep the gap visible and assign a new evidence action. |
| Two policies conflict | Stop publication and resolve ownership and governing version. |
Human judgement, security and privacy
Backstory records the chain from requirement to evidence, but people remain accountable for interpreting applicability and sufficiency.
What's next
Schedule the next review and, where needed, create a separate attestation campaign.
Need help?
Use your organisation's approved Backstory support route. Include the organisation, page and action that failed, but do not include passwords, invitation links, secret keys or unnecessary personal or confidential content.