Use case · Policies and compliance

A whole policy set, updated from a single decision.

A policy suite is one argument spread across 24 documents. When a decision changes, Abstract finds every clause it touches, proposes the edits document by document, and keeps the trail an auditor wants to see.

An ISMS folder in Abstract: one decision fanning out to sub-agents that read every policy in parallel and propose changes where the decision applies.
The pain

The security review decides supplier checks move from annual to quarterly.

Now somebody has to find every document that assumes "annual": the supplier policy, vendor tiering, the risk register, two SOPs. Miss one and your ISMS disagrees with itself, which is exactly what an auditor is paid to notice.

How it works here

One decision in, a consistent set out.

01

Point at the decision.

Drop in the review transcript or state the change. Abstract extracts the decisions and identifies the affected documents.

02

Fan out.

Sub-agents read every document in the set in parallel and propose changes only where the decision actually bites. "No change" is a real answer.

03

Review in one pass.

Work through the proposals document by document. Each change carries its source line and a confidence label. Accept, tweak or reject; the decision log is your audit evidence.

The cross-document review: proposed policy changes listed with their source lines and confidence labels, nine accepted and none rejected.

9 accepted, 0 rejected. Every change carries its source and confidence.

The moment

The 3 March security review produced three decisions. You hand Abstract the transcript. Twenty-four sub-agents read the ISMS in parallel and come back with 38 proposed changes across 12 documents; nine documents genuinely need nothing. The MFA decision alone touches four policies. You review the lot in one sitting, tweak the vendor-tiering wording, and export the change log. Revision histories update in every affected document.

What you can trust

Every proposal is traceable.

Every proposal is traceable: which decision, which source line, which document, who approved it and when.

Inferred changes, implied by a decision rather than stated, are labelled as inferred and always wait for you.

Works with your stack

Decisions in, audit evidence out.

Sources: transcripts and decision docs as files today. Outputs: DOCX and PDF per policy, or publish the set internally In beta.

Version, branch and review like code if your team wants to; ordinary review if it doesn't.

FAQ

Questions

Is this only for ISO 27001?

No. Any folder of documents that has to agree with itself: SOPs, HR policies, quality manuals, security policy suites.

Can it write the policies from scratch?

It can draft from your templates and context, but the wedge is maintenance: keeping a living set consistent beats generating a dead one.

What does the auditor actually see?

A decision log: change, source, rationale, approver, date, per document.

Bring the policy folder you're afraid to open.

Early access · free while in beta · no credit card