Creating a New Policy
Last updated: March 25, 2026
Only custom policies can be created from scratch. Default policies come pre-configured with your organization's account.
To create a new policy:
Go to Policies.
Select + Add policy.
In the Add custom policy panel, fill in the required fields:
Enter a Policy name.
Add a Description that explains what the policy covers. This description helps the Mycroft assistant generate relevant content.
Under Employee acceptance, choose how employees should acknowledge the policy:
All employees: Every employee must acknowledge this policy.
Select employees: You choose specific employees this policy applies to.
No acceptance: No employee acknowledgment is required.
Under Policy owners, assign at least one of the following:
General or business owner
Security owner
(Optional) Check Require Reviewers if reviewers must approve the draft before it can be published. When enabled, all assigned reviewers must sign off before Save & publish becomes active.
Leave Link to ERM-8: Policies Sign-off Control checked (recommended) to automatically track this policy's publication and approvals in the ERM-8 control.
Select Add policy.
Once created, the policy detail page opens in a Not started state with no content. Mycroft presents three options under Select a method:
Start from scratch: Mycroft uses your policy name and description to generate an initial draft across the policy sections. Review and adjust this content before publishing.
Import & edit: Upload an existing policy document, pull it into the structured editor, and adjust the content as needed.
Upload original: Upload a finalized policy to store as-is. Mycroft keeps this version unchanged and displays it as a read-only file.
Select the option that best fits what you have, then follow the prompts to create your first version.
Note: Default policies come pre-configured with structure and content generated by Mycroft. To edit one, open it from the Policies list and create a new draft version.