Policy Management

New Feature: Policy Management

Published on 04.05.20263 min read

Distributing a policy is easy. Proving it has been read, by the right people, on the right version, when the auditor asks, is where most teams come unstuck.

The manual approach is familiar: a SharePoint folder, a PDF attached to an email, and a spreadsheet someone updates when they remember to. It feels manageable until a compliance deadline arrives or a new hire joins and nobody is sure what they have been shown. And somewhere in the middle of it all, a battle between IT and HR for who is responsible.

The alternative is a full learning management system. But for most SMB and mid-market companies, that means a lengthy procurement process, a system employees need to learn, and more overhead for an IT team that is already stretched.

Policy management in the Pistachio platform sits between the two. No spreadsheets, no system to learn, and no ongoing administration. Just a clean, audit-ready way to track who has seen what.

"When it came to compliance audits, our customers could easily demonstrate when employees completed security training, but not when they had seen internal policies. Policy management in Practice fixes that - without adding another tool for the IT team to look after."

— Hanna Steingrímsdóttir, VP of Product

Spinner

Simple by Design

Setting up a new policy takes less than two minutes. Upload a PDF, assign it to your entire organization or a specific department, and Practice handles the rest. Employees are notified, acknowledgments are tracked, and you have a clear view of who has and has not confirmed each document.

When a policy changes, upload the revised version. Version history is maintained automatically, giving you a clean record of what was in place and when, without any manual upkeep.

How Teams Are Using It

  • Compliance acknowledgment: Finance teams confirm they have read AML or DORA documentation, with automatic reminders for anyone who has not responded. Acknowledgment records are exportable when audit season arrives.

  • Operational policies: IT distributes instructions for new MFA apps, password managers, or internal tools and tracks who has read them instead of assuming the email was seen.

  • Onboarding: New hires see all relevant policies from day one in one place. No chasing documents and no gaps in what they have been shown.

  • Security alerts: When Presence flags a spike in suspicious activity, admins can distribute updated guidance to the whole organization immediately, with confirmation that it has been seen.

  • Annual and recurring compliance: Updated policies for certifications or audits are uploaded yearly, with version history and acknowledgment records ready when they are needed.

  • Incident response: After a security incident, updated instructions reach every employee quickly, so teams act consistently rather than relying on whether someone saw an email.

Audit-Ready Without the Admin Work

When it is time to demonstrate compliance, whether for ISO 27001, NIS2, Cyber Essentials, or an internal review, you can export a full report showing acknowledgment status across your organization. Send reminders to anyone who has not confirmed and know exactly where you stand before the auditor arrives.

New hires get immediate access to all relevant policies as soon as they are added to Practice. There are no onboarding gaps and no document hunting in their first week.

One Platform, One Less Compliance Challenge

Lightweight to set up, automatic to run, and one less thing on the IT team's plate. That is how Pistachio approaches every problem, and policy management is no different.

Policy management is available in Pistachio now. No matter which product your organization is using, it’s immediately available to you. Email contact@pistachioapp.com to see how Practice handles security awareness training and policy compliance in one place.

10 minutes to set up. Even less to manage.

We’ve designed our platform so you can feel confident your cybersecurity training needs are covered, all by the click of a button.

Turn on toggle