Policy and standards

A policy set is a document set, and it drifts.

One policy is a document. Twelve policies answering to two frameworks, written at different times by different people, is a system that goes wrong quietly. Byline treats the set as the unit: shared controls, coverage measured against what the documents actually claim, and review dates that come due whether or not anyone remembers.

What it keeps track of

A shared control catalogue Controls live once and are cited by every work. Aliases and retired identifiers are resolved rather than quietly corrected, so a policy citing an old number is reported as citing an old number.
Coverage with its gaps A matrix of the framework against what the documents claim, measured from the resolved claims. A gap is reported as a gap rather than rounded up.
Document control Owner, approver, effective date and review cycle per document. Cycles are read as written, annual or quarterly or every eighteen months, and a document goes due and then overdue on its own.
Cross-policy consistency Review the set against itself, so two documents do not define the same term differently or set two different retention periods.
Issued as one bundle Compile a set into a single issued document with its control table generated into it. Fields you have not set print as not set.
Compare two versions What changed in force between a draft and what it replaced: an obligation weakened from must to should, a requirement dropped, a quantity moved, a placeholder left open.