What is a Policy?
A policy is a governing document describing what an organization does to ensure security and compliance. It outlines responsibilities and general procedures meant to implement and maintain specific security and compliance controls. An organization will generally outline specific procedures in separate procedure documents.
When you use a Secureframe template, many topics already live as sections inside an existing policy. You usually do not need a new standalone policy for items like confidentiality, background checks, or visitor security.
Open the template, click Edit Policy, and look for the matching heading in the Body. You can also add a section if you need extra language. For the full map of which template houses each topic, see FAQs: Policies and acknowledgments.
How to Create a new Policy
Creating a policy is a guided two-step flow.
Step 1 — Set details
In the Secureframe dashboard, select Policies in the left sidebar menu.
Click Create policy at the top right.
Fill in the policy details:
Policy name
Policy owner
Whether employees are required to accept the policy
Which groups the policy applies to
Required fields are marked with an asterisk (*). The Edit groups link opens in a new tab, so you won't lose your place in the form.
Click Next to continue.
Step 2 — Add text
Paste in your policy text, or upload the policy directly as a PDF.
If pasting in a policy: Use the built-in toolbar to adjust formatting, and the Insert token dropdown in the side panel to auto-fill information such as Company Name, Date Modified, and Policy Owner.
If uploading a policy directly as a PDF: Click the Upload policy box and select a PDF file. You may upload multiple PDFs if needed. To remove one, click the X next to the file. You can add free text alongside the PDF, or leave the text blank.
The side panel in this step shows Attachments and Tokens.
Saving and publishing
You can save as a draft at any point in the flow.
Or publish directly when the policy is ready for acknowledgment — no extra confirmation prompt is required.
Either action returns you to the Policies list.
Note: If a policy is in draft and has no owner, any Admin can assign themselves as the owner and then publish it. Once a policy has an owner, only that policy owner can save and publish it. Click here to learn how.
How to edit an existing Policy
Everything for a policy now lives on a single page.
From the Policies list, click the policy you want to edit. This opens the policy editing page directly — there is no separate Edit policy step.
The policy text appears on the left. The side panel on the right holds all of the policy's settings:
Owner
Groups — assign a policy to a defined set of people rather than all employees. For example, a Change Management policy may only apply to your Development group.
Employee acceptance
Placeholders (tokens)
Make your updates to the title, body, or any setting in the side panel.
From the same page you can also:
Switch between the written text and any uploaded PDFs
Preview the policy before publishing
View the policy's version history
Save your changes as a draft, or publish when ready.
Unsaved changes: If you navigate away mid-edit, Secureframe shows a prompt offering Discard and exit or Save as draft. This covers changes to side-panel settings as well as the policy text.
Note: Only policy owners can publish the policy. Click here to learn how.
Publishing a policy
Published policies can be edited directly. When you publish, Secureframe walks you through:
Describing your changes — a short summary of what was updated.
Deciding whether employees need to re-accept the policy. Secureframe shows how many groups would be affected by requiring re-acceptance.
First-time publishes also offer the option to connect the policy to its related tests. See Linking a published Policy to a Policy Test.
Drafts and archived policies
Return a published policy to draft. Useful when a policy needs significant rework before it goes back out to employees.
Republish a draft with a simple confirmation.
Archive a policy you no longer need.
View an archived policy read-only, or restore it to a draft to bring it back into use.
Policy Writing Assistance using with Comply AI
Where: Policies → Open any policy → AI button in the editor toolbar
The policy editor includes a built-in AI writing assistant. Select any text and choose from a menu of AI-powered actions to improve your policy content instantly.
Open the policy you want to work on.
Click AI in the toolbar, or highlight a section of text and click AI, to summarize, improve writing, change tone, and more.
Action | Description |
Summarize content | Extract key points from selected text |
Improve writing | Fix grammar, spelling, and clarity |
Simplify language | Reduce complexity for broader audiences |
Expand upon | Add more depth and detail |
Trim content | Remove redundancy and tighten prose |
Change tone | Professional, Casual, Direct, Confident, Friendly |
Change style | Business, Legal, Journalism, Medical, Poetic |
Translate | Spanish, French, German, Italian, Dutch |
Additional Policy Features
Pre-built Tokens to autofill your company's information such as company name, date modified, policy owner, and security email, etc. Use the Insert token dropdown in the editor's side panel to add one.
Each token in the dropdown shows the actual value it will fill in (your real company name rather than a code) so you can confirm you're inserting the right one. This works even before the policy has been saved for the first time.
Conditional Sections allow you to incorporate dynamic sections into your policies based on your connected integrations. Rather than just auto-filling a value like standard tokens, conditional sections can show or hide entire sections of policy content depending on your environment, such as which integrations you have connected or whether you're on a specific compliance plan. When creating or editing a policy, a Conditional Sections area will display a list of all detected integrations you can use as tags within your policy content. This is especially useful if you manage policies across multiple customers or want to maintain a single global policy that automatically adjusts its language based on each customer's setup.
PDF Upload feature if you already have your own policies created.
Require employee Acceptance for those important documents related to your compliance obligations.
Policy Groups will allow you to assign specific policies to a set group of people. Ex, A Change Management policy may only go to your Development Group rather than All Employees.
High Priority Vendors token is used in policies like the Business Continuity and Disaster Recovery Plan to display a list of your high-priority vendors {{high_priority_vendor_list}}
Default tokens such as Backup Frequency and Minimum Retention Period are available for specific policy types to auto-fill relevant configuration values.
Frequently Asked Questions
Which policy houses confidentiality?
Information Security Policy, under People Security. There is no standalone Confidentiality Policy.
If you mean classifying Confidential data, use the Data Classification Policy. See FAQs: Policies and acknowledgments for the full template map.
Where do HR or Operations topics go in the default templates?
There is no HR Policy or Operations Policy template. HR topics split across Information Security Policy, Code of Conduct, Access Control and Termination Policy, and Performance Review Policy. Operations topics split across Internal Control, Change Management, Configuration and Asset Management, and the Business Continuity and Disaster Recovery Plan.
Who can publish a policy in Secureframe?
If a policy is in draft and does not yet have an owner, any Admin can assign themselves as the owner, make edits if needed, and then publish it.
Once a policy has an owner, however, only the assigned policy owner may publish it. If you need a policy published but are not the owner, you’ll need to either reassign ownership to yourself or request that the current owner publish it.
What happens if I upload a PDF to an existing Policy that already has text?
If you upload a PDF and leave the existing Text, personnel will have a tab and be able to see both Text and PDF. If you prefer the user to only see the PDF in this scenario, then delete all the text and leave only the PDF.
Accepting the policy applies to both the text and PDF versions, even if both are displayed.
If I make policy changes partway through the year, can I require users to re-read and accept the policy?
Yes. When you publish an update to a policy, Secureframe walks you through describing your changes and choosing whether employees need to re-accept.
Before you confirm, Secureframe shows how many groups would be affected, so you can judge the impact of requiring re-acceptance.
If you don't require re-acceptance, employees keep their existing acknowledgment until their next annual cycle.
How can I update the values of the tokens in policies?
Most token values are pulled automatically from Company Settings > Company Details. To change them, go to that page and update the relevant fields — company name, security email, and so on. The changes flow through to every policy using those tokens.
Company-level values specific to policy content — backup frequency, minimum data retention period, and the high-priority vendor list — are updated from the Edit tokens window in the policy editor.
Why do I get "invalid template syntax: Unclosed tag {{...}}" when saving or assigning a policy owner?
This error means the policy body contains invalid or incomplete
{{...}}syntax. Secureframe policies support tokens and conditional sections, but each opening{{must have a matching closing}}and use a supported token name.Common causes include leftover template placeholders (for example,
{{Add sections for other data}}), typos (for example,{{company}}instead of{{company_name}}), or unclosed braces.To resolve this, open the affected policy in Edit Policy mode, search the body for
{{, and either replace invalid entries using the token menu in the right sidebar or remove the placeholder entirely. Then click Save and Publish before attempting to assign an owner again.
Why can't I bulk assign a policy owner?
If any selected policy contains invalid tokens, the bulk assign owner action can fail with a template syntax error.
Fix invalid tokens in each affected policy first, then retry the bulk assign. See the FAQ above on invalid template syntax for steps.
How do I know which token name to use?
Use the token menu in the policy editor sidebar rather than typing
{{...}}manually. This inserts the correct token name and formatting.See the Additional Policy Features section above for an overview of available tokens, including company name, date modified, policy owner, and conditional sections.
Why do I see vendors like Intune or Jira in Conditional Sections, but they do not appear in the published policy?
The policy editor lists available Conditional Sections in the sidebar. That list does not mean the section is already visible in the published policy.
Premade Conditional Sections only display when the matching Secureframe integration is connected and active.
If the policy was already published before you connected the integration, open the policy, refresh the tokens, then save and publish again so the new section can appear.
If Secureframe does not offer an integration for that vendor, the section will not populate automatically. Add the language manually in the policy body.
Does adding a vendor on the Vendors page unlock Conditional Sections?
No. Conditional Sections require a connected, active Secureframe integration.
Listing a tool on the Vendors page alone does not turn on integration-based Conditional Sections.
Do I need to write vendor-specific language into each policy myself?
Not for premade Conditional Sections included in Secureframe policy templates. Connect the integration, refresh tokens on any already published policies, and those sections should display without extra writing.
Yes, if you need content for a vendor that is not covered by the templates, or for a tool with no Secureframe integration. Secureframe cannot automatically write policy text for every vendor.
Why is Fortinet (or another vendor without a Secureframe integration) not showing up in my policies?
Conditional Sections only activate for tools with a Secureframe integration that is connected and active.
Vendors without a Secureframe integration will not auto-populate into policies. Include that content manually where needed.
I already have policies in another platform, can I link these policies to Secureframe via HTML?
We do not currently support HTML linking for Policies.
If you do not wish to utilize our pre-built policies, you can upload a PDF of your own in the Create Policy section located here.
All my acknowledgment tests are passing, as they should since everyone has accepted them according to them, but the tests themselves show up as "none" for accepted?
This usually means require employee acceptance was not turned on when the policy was published.
Open the policy, turn on employee acceptance in the side panel, and save.
Once enabled, the data will backfill correctly to the test.
Where can I set the {{backup_frequency}} token used in the Business Continuity and Disaster Recovery Plan?
Go to your Policies page and open your Business Continuity and Disaster Recovery Plan.
Open the Edit tokens window from the side panel.
Set Backup frequency to the value you want (for example, Monthly or Weekly).
Save the policy.
Once saved, {{backup_frequency}} will populate wherever it's used in the policy.
What is an employee handbook in Secureframe?
An employee handbook in Secureframe is typically a collection of published policies that define company expectations, workplace conduct, and security requirements. Rather than being a single document, the handbook is often made up of multiple individual policies that employees acknowledge inside the platform.
Do I need a separate “employee handbook” document?
Not necessarily. Many companies use Secureframe policies instead of a traditional handbook PDF by publishing individual policies and assigning them to employees for acknowledgment. This approach makes it easier to:
Keep content up to date
Track acknowledgments
Show auditors proof that employees reviewed required policies
Some companies still upload a handbook PDF, while others fully manage handbook content through individual policies.




