Online security policy acceptance

Publish your security policy and record who read and accepted it, with name, date, UTC time and IP in an immutable log.

How it works

How the flow runs and what is recorded

The admin publishes the PDF

The current policy enters as a document. New version, new acceptance. History is not rewritten.

The employee reads and accepts in the portal

From their portal, not from an email thread. They read. They accept. The gesture is tied to that version.

Name, date, UTC time and IP

The record is immutable. There is no “soft delete” toggle of the acceptance. If the auditor asks for the trail, it is there.

It is not the admin audit log

The log of who changed a course or a permission lives in compliance and security. This is the roster accepting a PDF.

The policy is accepted and a record remains — not a PDF on a drive

Security-policy acceptance, here, is the flow in which the admin

It is not an email with “reply OK”. It is not a spreadsheet. It is the evidence the auditor asks for when they ask who read the current policy and when.

Training talks about courses and adoption

This is not a course. It is an acceptance act with a trail. Mixing it with the ISO quiz is the error: the quiz proves training happened; this record proves the published document was accepted.

The strong link is compliance

This is policy acceptance. Compliance is program evidence.

What it is for

What it is for when the auditor asks for the trail

It is for ISO, for internal policies, for onboarding that cannot be “we

It is for when legal asks who accepted the March version, not the 2021 one. It is for a distributed roster with no paper signature.

It is not training

Publishing the policy does not replace the standard’s course. It is not a DPA. Account data processing lives in legal and the Trust Center.

In the cycle

How it connects to training and compliance

Adaptive security awareness training can coexist: the joiner takes the course and accepts the policy. Two gestures. The employee portal is the place; portal detail is a pillar anchor, not a new URL. Compliance exports program evidence. Here is the acceptance act. The course PDF certificate does not replace this record, or the other way around.

Questions

Questions about policy acceptance

What is recorded?
Name, date, UTC time and IP, immutably, tied to the published version.
Can an acceptance be deleted?
The record is presented as immutable. “How to delete” is documentation and is not sold here as a marketing feature.
Does it replace the standard’s course?
No. Accepting a PDF does not prove training. Training does not prove the current policy was accepted.
Where does the auditor see it?
In the exportable record of the act. The wider frame is on compliance.
Is there a product screenshot?
No. Book a demo to see the console.

Publish the policy and leave the trail the auditor asks for

In the demo we look at the PDF, the portal and the record with UTC time and IP. No paper signature from the branch.