When your security team asks where the policies live, the answer is: they never left your tenant. RisqRadar stores a pointer and the governance record — nothing else.
Numbered (POL-SEC-0004), owned, categorized, and searchable — the register your auditor asks for, instead of a spreadsheet.
Set the cadence once. Owners and admins get emailed before reviews come due, and overdue policies are flagged in the register.
Ordered approvers, decisions with notes, full history. The final approval activates the policy — and pins the exact document version approved.
If a policy changes in SharePoint after it was approved, RisqRadar notices and flags it. Link-based governance you can actually trust.
Send read-and-acknowledge campaigns to anyone by email. Recipients sign with their name on a personal link — no accounts, no licenses.
Every creation, edit, approval, and acknowledgment is recorded immutably and exports to CSV for auditors.
RisqRadar already quantifies cyber risk in dollars. Link a policy to the control it implements and the risk scenario that control mitigates, and your story to the board becomes: “this policy implements this control, which reduces a $1.2M/yr quantified risk — and 94% of staff have attested to it.” Policy management is where you start; quantified risk is where it leads.
No. RisqRadar stores a pointer (URL or SharePoint item reference) plus governance metadata — number, owner, status, approvals, acknowledgments. The documents stay in your tenant, under your permissions, DLP, and retention rules.
Just an email address. Each recipient gets a personal, unguessable link where they read the policy and type their name to acknowledge. No account, no seat, no cost per recipient.
Not to start. Plain URL links work with any storage — SharePoint, Google Drive, Confluence. Connecting Microsoft Graph (Policy Plus) adds search-and-attach, durable links that survive renames, version pinning, and drift detection.
For plain links: nothing. For the Graph integration: an Entra app registration your admin controls, used server-side only. Our security overview covers the full data-flow for reviewers.