Policies

Getting started with Policies

Policies arrives pre-filled with the policies your frameworks require, all sitting at "Not started" until you give them content. You then have three ways to do that: write the policy in the built-in editor, upload an existing file, or link to one held elsewhere.

Policies overview and filters

When you open Policies, you'll see an overview of all policies applicable to your organisation. These policies initially have "Not started" status and are ready to be set up:

Initialized policies overview

Info

If you have a licence with Tidal Policy templates, you'll see these policies as "Draft". You don't need to write these yourself anymore!

Note

Do you see an empty screen or are policies missing? Do you see them in the 'Out of scope' tab?

Then these policies are not yet linked to controls in your environment. See "In scope vs Out of scope" below for how to bring them in scope.

For each policy you see:

Policy fields

  • Name and Tidal ID
  • Type (paperclip for uploaded files)
  • Owners (if already assigned)
  • Status (Not started, Draft, Approved, To Review)
  • Last approval (if applicable)
  • Actions (Start button to begin)

Status meanings

  • Not started: No document linked yet
  • Draft: Document available but not yet approved
  • Approved: Approved document within the last 12 months
  • To Review: No recent approval (older than 12 months)

Search and filter

  • In scope / Out of scope tabs - Switch between policies that count towards compliance and policies that don't
  • Search bar - Type policy names or Tidal IDs to find specific policies
  • Status filter - Filter on Not started, Draft, Approved, or To Review
  • Framework filter - Show only policies required by a specific framework
  • Type filter - Distinguish between internally managed and uploaded documents (paperclip icon)
Tip

Use the status filter to work efficiently: filter on "Draft" to find policies ready for approval, or on "To Review" to catch up on overdue reviews.

In scope vs Out of scope

Scope decides which policies count. A policy is in scope when a control asks for it, and out of scope when no control does — the same rule that governs tests.

What determines scope

Every policy and required document has its own policy test in Tidal, named after the policy (for example "Acceptable use policy"). That test decides the scope:

In scope policies:

  • Policy test is linked to at least one control in your ISMS
  • Count towards framework progress and compliance scoring
  • Shown by default when you open Policies or Documents

Out of scope policies:

  • Policy test is linked to no control at all
  • No effect on your scores - the policy isn't required in your environment
  • Only visible under the "Out of scope" tab
Info

A policy test is an ordinary Tidal test, so it follows the ordinary scope rule: linked to a control means in scope.

Read more about this in Getting started with Tests.

Bringing a policy in scope

  1. Open Policies (or Documents) and click the "Out of scope" tab
  2. Find the policy you want to add and note its name
  3. Go to Controls and open the control that should require this policy
  4. Go to the "Tests" tab of the control
  5. Select the text field and search for the policy name - policy tests sit under the "Tidal Control" group
  6. Choose the test - the link saves automatically
  7. Return to Policies - the policy now sits under "In scope" and can be started
Tip

Not sure which control belongs to a policy? Filter your controls on the relevant framework and pick the control whose requirement the policy describes. A policy may be linked to several controls; one link is enough to make it in scope.

Taking a policy out of scope

  1. Go to Controls and open the control its policy test is linked to
  2. Go to the "Tests" tab and click the X on the chip of the policy test
  3. Repeat for every control the policy test is linked to - as long as one link survives, the policy stays in scope
  4. The policy moves to the "Out of scope" tab and stops counting towards your scoring
Note

Taking a policy out of scope deletes nothing. Drafts, approved versions and version history all survive, and reappear the moment you bring the policy back in scope.

For the steps on the control side, see Editing and managing controls.

Policies and Documents

Required documentation is split over two menu items:

  • Policies - Directive documents you establish and approve, such as an access control policy or an acceptable use policy
  • Documents - Required documents, such as an internal audit report, an organisation chart, or your information security objectives

The screens are the same: same overview, same statuses, same editor, same three routes for filling a document, and the same In scope / Out of scope mechanism described above.

What differs is what accumulates over time. A policy is one document you maintain, so approving it produces versions of the same thing. A required document is a recurring obligation, so each cycle adds a separate document — the 2026 audit report sits alongside the 2025 one rather than replacing it.

Info

Read more about that difference, and how to file each cycle, in Getting started with Required Documents.

Info

Looking for uploaded files you attach to tasks as evidence? Those live under Settings → Evidence, not on the Documents page.

Read more about this in Evidence management and overview.

Starting your first policy

Clicking Start on a policy asks you which of the three routes you want to take.

Choice menu

When you click the "Start" button of a policy, a choice menu appears with three options:

Start menu

1. Create with editor

  • Create policies from scratch with our built-in editor
  • Full word processing capabilities
  • Automatic version control
  • Integrated approval and review flow
Tip

We recommend new users start with the Policy Editor. This offers the most functionality and is easiest to get started with. You can always switch to another method later.

2. Upload file or use already uploaded document

  • Upload PDF or Word documents
  • Maintain your current documents and workflows
  • Easy version replacement (each 'upload' is a new version)
  • Integrated approval and review flow

3. Link to an external location

  • Link policies that are managed externally
  • Use URLs to your existing documentation management system
  • Maintain overview without duplicating documents
  • Integrated approval and review flow

Understanding policy types

The choice you make affects how you proceed with this policy. Below is a brief explanation of the main functionalities per policy type:

Internally managed policies

  • Created and edited in Policies
  • Full functionality available
  • Automatic PDF generation with metadata

Uploaded documents

  • Recognisable by paperclip icon
  • Download/Upload capability
  • Editing outside Tidal
  • Each 'upload' is a new version

Externally managed policies

  • URL-based
  • Editing and version management outside Tidal
  • Approvals and reviews possible in Tidal
Warning

With externally managed policies, you are responsible for version management yourself. Make sure your external system provides sufficient audit trails.

You can still use the approval and review flows within Tidal to demonstrate compliance.