Skip to content

Employee Policy Portal ("My Policies")

Where to find it: Primary navigation, under My Work, select My Policies (/my-policies).

The Employee Policy Portal provides an intuitive, self-service interface where staff members review corporate policies assigned to their role or department, read full policy documents, and record legally defensible acknowledgements.

Requires the policy.attest permission.


The Employee Experience

When an employee logs into OrviQ and navigates to /my-policies, the platform resolves their personal assignments securely from the active session:

  1. Assigned Policies List: The employee views all published policies assigned to them through active attestation campaigns, categorized as Pending Review or Previously Completed.
  2. Version-Pinned Document View: Opening a policy presents the complete text of the exact published version pinned to that campaign. If compliance editors draft newer revisions, the employee remains pinned to their assigned release until a new campaign is activated.
  3. Structured Reading: Policies are presented in clean, readable sections with atomic statements, definitions, and operational responsibilities clearly outlined.

"Opened" != "Acknowledged"

To maintain strict evidentiary standards during regulatory examinations, OrviQ enforces a hard separation between opening a document and formally attesting to it:

  • Document Open (opened_at): When an employee clicks into an assigned policy, the backend immediately records an immutable opened_at timestamp. This proves the user had the document on screen.
  • Explicit Attestation Required: Simply opening or scrolling through a policy never auto-completes an acknowledgement. The user must take an intentional, separate action by clicking Acknowledge or Decline.

Attestation Decisions

When an employee completes their review, they record one of two formal decisions:

1. Acknowledged (acknowledged)

The employee submits a formal declaration:

"I confirm that I have read, understood, and agree to comply with the obligations set forth in this policy."

  • Records employee email, IP address, user agent, exact timestamp, and pinned policy version SHA-256 hash.
  • Serves as an immutable evidentiary assertion (ASN-YYYY-NNNN) feeding organizational governance indicators.

2. Declined (declined)

If an employee cannot comply with a policy clause (e.g. due to role constraints, physical limitations, or conflicting operational duties), they may decline:

  • Mandatory Reason Note: The employee must supply a written explanation detailing why they cannot acknowledge the policy.
  • Compliance Notification: Declining an attestation alerts the policy manager and compliance officer, allowing them to initiate a consultation, explore role re-assignments, or submit a Policy Exception.

Campaign & Attestation Lifecycle

Attestation campaigns are administered by compliance teams and executed by employees:

Campaign States (Administrative)

  • draft: Target employee audience, policy version, and due dates configured.
  • active: Dispatched to employees; visible in /my-policies.
  • closed: Campaign completed; final participation statistics sealed.
  • cancelled: Campaign retracted prior to completion.

Individual Attestation States (Employee)

  • pending: Assigned to employee; unacknowledged.
  • acknowledged: Successfully attested by employee.
  • declined: Formally declined with employee rationale.

Semantic Doctrine

Semantic Doctrine: Attestation != Effectiveness or Compliance

A high policy attestation rate is vital for establishing employee awareness, but OrviQ enforces strict doctrine regarding its meaning:

  • Attestation is not compliance: An employee signing an attestation confirms that they have received and acknowledged the document. It does not prove that the employee complies with the policy during daily operations.
  • Attestation is not control effectiveness: 100% attestation on an Information Security Policy does not mean security controls are operating effectively.
  • Attestation is one evidence dimension: In the Evidence Fabric, an employee attestation is recorded as a subjective observation (attestation origin); operating effectiveness requires objective technical testing and control indicator verification.

Permissions Reference

ActionPermission KeyRequired Role(s)
Access My Policies portal and submit attestationspolicy.attestAll platform users (Tenant Admin, Manager, Officer, Risk Manager, Control Owner, Auditor, Read Only)
Create and activate attestation campaignspolicy.writeTenant Admin, Compliance Manager, Compliance Officer
View enterprise attestation progress and campaign dashboardspolicy.readTenant Admin, Compliance Manager, Compliance Officer, Auditor

OrviQ Enterprise Governance, Risk & Compliance Platform