RisqRadar Policy

SharePoint holds your policies.
RisqRadar makes them governed.

Numbering, review cycles, approvals, attestation, and an audit-ready trail — layered over the documents you already have. No migration. No document custody.

Flat per-organization pricing · unlimited attestation recipients

SharePoint keeps
  • The document files themselves
  • File permissions & sharing
  • Native version history
  • Co-authoring in Office
  • Your eDiscovery, DLP & retention
RisqRadar governs
  • Register: numbers, owners, status
  • Review cycles & reminders
  • Approval workflow & decisions
  • Approved-version pin + drift alerts
  • Attestation with signed acknowledgments
  • Append-only governance trail

When your security team asks where the policies live, the answer is: they never left your tenant. RisqRadar stores a pointer and the governance record — nothing else.

Everything a policy program needs. Nothing a DAM drags in.

A real policy register

Numbered (POL-SEC-0004), owned, categorized, and searchable — the register your auditor asks for, instead of a spreadsheet.

Review cycles that run themselves

Set the cadence once. Owners and admins get emailed before reviews come due, and overdue policies are flagged in the register.

Sequential approvals

Ordered approvers, decisions with notes, full history. The final approval activates the policy — and pins the exact document version approved.

Drift detection

If a policy changes in SharePoint after it was approved, RisqRadar notices and flags it. Link-based governance you can actually trust.

Attestation without seats

Send read-and-acknowledge campaigns to anyone by email. Recipients sign with their name on a personal link — no accounts, no licenses.

An append-only trail

Every creation, edit, approval, and acknowledgment is recorded immutably and exports to CSV for auditors.

The part no policy tool can copy

RisqRadar already quantifies cyber risk in dollars. Link a policy to the control it implements and the risk scenario that control mitigates, and your story to the board becomes: “this policy implements this control, which reduces a $1.2M/yr quantified risk — and 94% of staff have attested to it.” Policy management is where you start; quantified risk is where it leads.

Questions IT and compliance will ask

Do our documents get uploaded to RisqRadar?

No. RisqRadar stores a pointer (URL or SharePoint item reference) plus governance metadata — number, owner, status, approvals, acknowledgments. The documents stay in your tenant, under your permissions, DLP, and retention rules.

What do attestation recipients need?

Just an email address. Each recipient gets a personal, unguessable link where they read the policy and type their name to acknowledge. No account, no seat, no cost per recipient.

Do we need to connect SharePoint?

Not to start. Plain URL links work with any storage — SharePoint, Google Drive, Confluence. Connecting Microsoft Graph (Policy Plus) adds search-and-attach, durable links that survive renames, version pinning, and drift detection.

What does IT need to approve?

For plain links: nothing. For the Graph integration: an Entra app registration your admin controls, used server-side only. Our security overview covers the full data-flow for reviewers.

Your first policy can be governed today

Keep SharePoint. Delete the tracking spreadsheet.