Tuesday, 11:20 · One comment on one policy

It starts with six words in a comment.

“Is this still what we do?” A colleague leaves it on the access control policy. It is a small comment with a long tail: three other documents quote that rule, and two customer answers were built on it last quarter.

Tuesday, 11:20 · Is this still what we do?
Tuesday, 11:20 · Is this still what we do?
Tuesday, 11:45 · The rule has relatives
Tuesday, 11:45 · The rule has relatives

First, see what depends on it.

Lea opens the policy and follows its links. The rule appears in the onboarding standard, the supplier answer set and a register entry with a different owner. Before she changes a word, she can see everything the change will touch, which is the part that normally gets discovered too late.

  • Linked policies, standards and registers
  • Owner, version, status and review date on every document
  • Version history with the reason for each change

Follow that comment yourself

Open the linked policy, ask the question, then build a controlled pack. Sample data.

vault.iqu-erion.com

POL-01

Information security policy

Owner:
Head of Security
Version:
3.2
Status:
Published
#iso27001#governance
3.2Version
2Open comments
Safe to share

This policy sets how information is classified, handled and protected. It applies to all staff, contractors and systems.

Roles and approval authority are held in the role register and referenced here, not repeated. See .

Access is granted on least privilege and reviewed quarterly. The review procedure is defined in .

Retention periods are defined per data category in and are binding for all systems.

Linked sources:

Tuesday, 15:30 · The change gets reviewed, not guessed
Tuesday, 15:30 · The change gets reviewed, not guessed

The comment becomes a reviewed change.

The wording is proposed, checked against the source and approved by a person. The assistant can draft and cite, but it cannot quietly rewrite a policy. Once the change is approved, every answer that leans on that rule is drawing from the corrected version.

  • Comments become proposed changes
  • A human approves before the document changes
  • Dependent answers follow the approved wording

The shortcut everyone takes

A general AI will answer anything. It just does not know your company.

Asked in a general chatbot

The reply reads well and sounds certain. It describes how a company like yours usually handles access reviews. It does not know your rule, your version, your owner or what you already told this customer last year. Someone still has to verify every line before it can be sent.

Asked inside your own documents

The same question is answered from the policies your company actually maintains, and the answer names the documents it used. Lea opens the wording, sees who owns it and when it was last reviewed, and forwards it. The verification is the answer, not a second job.

Wednesday, 09:20 · The next person does not need Lea
Wednesday, 09:20 · The next person does not need Lea

And the question does not come back.

When the same question arrives in the next questionnaire, the answer is there with its source attached, and the reviewer can inspect it without a call. Lea keeps her attention for the questions that are genuinely new. That is the quiet part of this that matters most.

  • Full-text search and tag filters
  • Cited, read-only assistant
  • Scoped access for external reviewers

How the knowledge base works

Document control

  • Owners, versions, status and tags
  • Linked policies, standards and registers
  • Version history, differences and change reasons

Review and retrieval

  • Full-text search and tag filters
  • Action owners and due dates
  • Cited, read-only assistant

Controlled sharing

  • Selectable PDF and Markdown packs
  • Branded contents and page numbering
  • Restricted notes excluded from exports

Access

  • Role-based access
  • External reviewer access
  • Mobile-friendly vault and export

The work around the documents stays visible

Policy work is never one person. Reviews, evidence and open actions can be tracked directly in iquerion, or in the tool your organisation already runs, so nobody has to chase status in a chat thread.

Track it in iquerion

Actions, owners, due dates and review status sit next to the document they belong to.

Jira

Track it in Jira

Work items can be created and kept in sync with your existing Jira projects and workflows.

Productive

Track it in Productive

Tasks and delivery work can run in Productive, with the document as the reference point.

Integrations are configured during setup for the tools you use. The document stays the single source; the task tool stays where your teams already work.

Where we stop

  • No self-service signup or public customer vault.
  • The assistant proposes answers. It does not silently change policy.
  • Endpoint security and security operations remain outside the product.

Which request is holding up your next decision?

Bring the assessment, the audit request or the IT question. We will map the evidence and the next hand-off with you.