Tuesday, 11:20 · One comment on one policy
It starts with six words in a comment.
“Is this still what we do?” A colleague leaves it on the access control policy. It is a small comment with a long tail: three other documents quote that rule, and two customer answers were built on it last quarter.


First, see what depends on it.
Lea opens the policy and follows its links. The rule appears in the onboarding standard, the supplier answer set and a register entry with a different owner. Before she changes a word, she can see everything the change will touch, which is the part that normally gets discovered too late.
- Linked policies, standards and registers
- Owner, version, status and review date on every document
- Version history with the reason for each change
Follow that comment yourself
Open the linked policy, ask the question, then build a controlled pack. Sample data.
POL-01
Information security policy
- Owner:
- Head of Security
- Version:
- 3.2
- Status:
- Published
This policy sets how information is classified, handled and protected. It applies to all staff, contractors and systems.
Roles and approval authority are held in the role register and referenced here, not repeated. See .
Access is granted on least privilege and reviewed quarterly. The review procedure is defined in .
Retention periods are defined per data category in and are binding for all systems.
Linked sources:

The comment becomes a reviewed change.
The wording is proposed, checked against the source and approved by a person. The assistant can draft and cite, but it cannot quietly rewrite a policy. Once the change is approved, every answer that leans on that rule is drawing from the corrected version.
- Comments become proposed changes
- A human approves before the document changes
- Dependent answers follow the approved wording
The shortcut everyone takes
A general AI will answer anything. It just does not know your company.
Asked in a general chatbot
The reply reads well and sounds certain. It describes how a company like yours usually handles access reviews. It does not know your rule, your version, your owner or what you already told this customer last year. Someone still has to verify every line before it can be sent.
Asked inside your own documents
The same question is answered from the policies your company actually maintains, and the answer names the documents it used. Lea opens the wording, sees who owns it and when it was last reviewed, and forwards it. The verification is the answer, not a second job.

And the question does not come back.
When the same question arrives in the next questionnaire, the answer is there with its source attached, and the reviewer can inspect it without a call. Lea keeps her attention for the questions that are genuinely new. That is the quiet part of this that matters most.
- Full-text search and tag filters
- Cited, read-only assistant
- Scoped access for external reviewers
How the knowledge base works
Document control
- Owners, versions, status and tags
- Linked policies, standards and registers
- Version history, differences and change reasons
Review and retrieval
- Full-text search and tag filters
- Action owners and due dates
- Cited, read-only assistant
Controlled sharing
- Selectable PDF and Markdown packs
- Branded contents and page numbering
- Restricted notes excluded from exports
Access
- Role-based access
- External reviewer access
- Mobile-friendly vault and export
The work around the documents stays visible
Policy work is never one person. Reviews, evidence and open actions can be tracked directly in iquerion, or in the tool your organisation already runs, so nobody has to chase status in a chat thread.

Track it in iquerion
Actions, owners, due dates and review status sit next to the document they belong to.
Track it in Jira
Work items can be created and kept in sync with your existing Jira projects and workflows.
Track it in Productive
Tasks and delivery work can run in Productive, with the document as the reference point.
Integrations are configured during setup for the tools you use. The document stays the single source; the task tool stays where your teams already work.
Where we stop
- No self-service signup or public customer vault.
- The assistant proposes answers. It does not silently change policy.
- Endpoint security and security operations remain outside the product.
Which request is holding up your next decision?
Bring the assessment, the audit request or the IT question. We will map the evidence and the next hand-off with you.

