← Help & guides
Step-by-step guides4 min read

Generate and approve your policies

Five documents, why generation is only half the job, and what approval actually unlocks.

The five documents

Veriflow generates five policies, each tailored to your agent's profile and mapped to your scoped controls:

  1. AI Acceptable Use Policy
  2. AI Risk Management Policy
  3. AI Incident Response Plan
  4. AI Data Handling Policy
  5. AI Vendor & Model Management Policy

Click Generate draft on any of them. With an Anthropic API key configured, they're written for your specific agent. Without one, you get a structured template pre-filled with your wizard answers and control mappings, clearly marked as a draft.

Generation is half the job

A generated policy is a draft. Until a human approves it, it:

  • does not count toward your readiness score
  • does not appear on your public trust page
  • cannot be cited as a source in questionnaire answers

This is intentional. "This policy was generated by AI three days ago and nobody read it" is the fastest way to lose a security reviewer's confidence.

Approving

Read the draft (Review), edit if needed, then click Approve & sign. Veriflow records who approved it and when, and that metadata travels with the document into your evidence package.

Approve only what you'd actually defend in a call. If a policy claims you do quarterly reviews, put the reminder in your calendar before you sign it.

Regenerating

Regenerate creates a new version and resets approval — the new version needs signing off again. Old versions are retained.

More in Step-by-step guides