The five documents
Veriflow generates five policies, each tailored to your agent's profile and mapped to your scoped controls:
- AI Acceptable Use Policy
- AI Risk Management Policy
- AI Incident Response Plan
- AI Data Handling Policy
- AI Vendor & Model Management Policy
Click Generate draft on any of them. With an Anthropic API key configured, they're written for your specific agent. Without one, you get a structured template pre-filled with your wizard answers and control mappings, clearly marked as a draft.
Generation is half the job
A generated policy is a draft. Until a human approves it, it:
- does not count toward your readiness score
- does not appear on your public trust page
- cannot be cited as a source in questionnaire answers
This is intentional. "This policy was generated by AI three days ago and nobody read it" is the fastest way to lose a security reviewer's confidence.
Approving
Read the draft (Review), edit if needed, then click Approve & sign. Veriflow records who approved it and when, and that metadata travels with the document into your evidence package.
Approve only what you'd actually defend in a call. If a policy claims you do quarterly reviews, put the reminder in your calendar before you sign it.
Regenerating
Regenerate creates a new version and resets approval — the new version needs signing off again. Old versions are retained.