Policies in Mycroft
Last updated: March 25, 2026
Policies in Mycroft let you manage written policies as living documents you can review, update, and test over time. Each policy has structured sections, assigned owners, optional reviewers, and a direct connection to Controls and Tests.
Policy: A structured document organized into sections (Purpose, Scope, Policy content, Compliance, Enforcement, Policy review and modification).
Policy version: A snapshot of policy content at a point in time.
Draft: Unpublished changes to a policy. A policy can have one active draft at a time.
Published policy: The current, approved version visible to auditors and used by tests.
Not started: A policy that has been created but has no content yet.
General or business owner: The person responsible for the business side of the policy.
Security owner: The person responsible for the security side of the policy.
Reviewer: A person who must sign off on a draft before it can be published.
Policy test: One or more tests automatically created when a policy is created. At minimum, a test is created to verify the policy has a published version. If employee acceptance is enabled, a second test is created to track employee acknowledgments. Both can be linked to controls.
You work with policies from the Policies list page and the individual Policy detail page. Policy tests live in Tests but can be linked to controls from either the test or the policy's Controls tab.