A whole policy set, updated from a single decision.
A policy suite is one argument spread across 24 documents. When a decision changes, Abstract finds every clause it touches, proposes the edits document by document, and keeps the trail an auditor wants to see.
The security review decides supplier checks move from annual to quarterly.
Now somebody has to find every document that assumes "annual": the supplier policy, vendor tiering, the risk register, two SOPs. Miss one and your ISMS disagrees with itself, which is exactly what an auditor is paid to notice.
One decision in, a consistent set out.
Point at the decision.
Drop in the review transcript or state the change. Abstract extracts the decisions and identifies the affected documents.
Fan out.
Sub-agents read every document in the set in parallel and propose changes only where the decision actually bites. "No change" is a real answer.
Review in one pass.
Work through the proposals document by document. Each change carries its source line and a confidence label. Accept, tweak or reject; the decision log is your audit evidence.
9 accepted, 0 rejected. Every change carries its source and confidence.
The 3 March security review produced three decisions. You hand Abstract the transcript. Twenty-four sub-agents read the ISMS in parallel and come back with 38 proposed changes across 12 documents; nine documents genuinely need nothing. The MFA decision alone touches four policies. You review the lot in one sitting, tweak the vendor-tiering wording, and export the change log. Revision histories update in every affected document.
Every proposal is traceable.
Every proposal is traceable: which decision, which source line, which document, who approved it and when.
Inferred changes, implied by a decision rather than stated, are labelled as inferred and always wait for you.
Decisions in, audit evidence out.
Sources: transcripts and decision docs as files today. Outputs: DOCX and PDF per policy, or publish the set internally In beta.
Version, branch and review like code if your team wants to; ordinary review if it doesn't.
Questions
Is this only for ISO 27001?
No. Any folder of documents that has to agree with itself: SOPs, HR policies, quality manuals, security policy suites.
Can it write the policies from scratch?
It can draft from your templates and context, but the wedge is maintenance: keeping a living set consistent beats generating a dead one.
What does the auditor actually see?
A decision log: change, source, rationale, approver, date, per document.