What it's for
Producing the written policies a security reviewer expects, tailored to your agent rather than copied from a template pack.
When you use it
Early — approved policies are 25% of your score and are required before they can back questionnaire answers. Then again whenever your agent materially changes.
What's on the screen
Five cards: Acceptable Use, Risk Management, Incident Response, Data Handling, Vendor & Model Management. Each shows a draft or ✓ approved badge, version, generation date, approver and approval date once signed, and buttons: Review, Approve & sign, Generate draft / Regenerate. Unapproved documents carry an amber warning.
How it works
Generation sends your agent profile plus the relevant scoped controls to the Anthropic API, asking for a document with a control-mapping table. Without an API key you get a structured template pre-filled with the same data, clearly labelled.
Approval records your identity and a timestamp. Only approved policies count toward readiness, appear on the trust page, are citable in answers, and are included in the evidence package with their approval metadata in the file header.
Regenerating creates a new version and resets approval — the new version needs signing again. Prior versions are retained.
Gotchas
- Generating all five and approving none scores 0% for the policy component.
- Read before you sign. If the document commits you to quarterly reviews, put it in the calendar first.
- Policies are org-wide, not per-agent, though generation uses the selected agent's profile.