Skip to main content

Approving and assigning

An installed program is a proposal until your organisation approves it. This page covers what you are approving and what happens next.

What lands where

Everything the program created is waiting on a decision, but the two kinds arrive in different places:

  • Training versions land in Quality > Review queue, pending review. They are waiting for you.
  • Controlled documents land in Controlled documents as drafts. They reach the review queue only once somebody sends each one for review, which is a deliberate step so that a document nobody has read yet is not put in front of an approver.

Nothing is assigned to anyone yet, and the program card on Compliance programs tracks exactly what is left.

The worklist on the program card

The card counts the remaining work and links to the surface that does each step:

  1. Send each document for review, and make it effective once approved.
  2. Approve each training version.
  3. Activate targeting, which enrols everybody the rules match.

Activating targeting before the content is approved does not enrol anybody, and the product tells you so rather than reporting that it created nothing.

Who may approve

Approval requires a quality role, and the approver must not be the person who installed or authored the item. This holds for training versions, for controlled documents and for translations alike. The system enforces it and refuses the approval rather than warning about it.

Plan for that before you install: if you are the only administrator, nobody can approve what you installed, and there is no way around it by design. The install page says so before the point of no return.

This is segregation of duties, and it is the reason a program is defensible. An auditor asking "who decided this policy applies here?" gets the name of someone in your organisation who reviewed it, not the name of the vendor who wrote it or the administrator who clicked upload.

What to actually review

Do not rubber-stamp it. The publisher wrote a good general program; you are deciding whether it fits this organisation.

  • Does the policy match how you actually work? A policy promising a two-day review window when your process gives four hours creates a finding, not compliance.
  • Do the escalation paths name real routes? A program cannot know your escalation structure. Where it refers to one generically, make sure the reader can find it.
  • Is the enablement at the right depth for these people? Adjust the role mapping rather than watering down the content.
  • Can the people you mapped to oversight actually intervene? If not, fix that before approving, not after.

You can approve, reject with a reason, or send it back. A rejected version returns to draft so the reason is recorded and the item can be revised.

Making documents effective

Approving a document is not the same as publishing it. A document becomes readable to your organisation when it is made effective, which is a separate, deliberate step.

For a translated variant, the same rule applies: it stays a draft until it has been approved by a second person and made effective. A translation is not a formatting change, so it does not skip the queue.

How assignments reach people

Once training is approved and active, the program's assignment rules apply. People matching a rule are enrolled and see the training in their list.

A rule carries both halves of what a role owes: the training its people take, and the policies they must read and confirm. Those documents appear under Policies to read on the person's training list once the document is effective, and the coverage per document is in Reports > Policies.

If a role matches nobody

Check the attribute filters. A publisher targets roles like "actually uses an AI tool" with attribute flags, which narrow the selection on top of the departments you picked, so a role can target every department and still reach nobody. The mapping editor shows those filters and lets you remove them, and you set the matching flag on a person from Users.

Changing your mind

Targeting is not a one-time decision. Edit targeting on the program card changes the audience of any role, including one you chose to decide later during the install. Narrowing a rule never removes evidence somebody already earned.

Assignment is additive and repeatable. Re-running it does not duplicate work for people who already have it, and narrowing a rule later does not remove evidence someone already earned.

A new hire matching a rule is picked up automatically. That is the point of mapping to attributes rather than to a list of names.

What evidence you end up with

Per person, per role, per content version:

  • What they completed, when, and which exact version of the content they saw.
  • An electronic signature where the item requires one, with a server-side timestamp and IP.
  • For scenario assessments, the reviewer's grading against each criterion, with the reviewer's name and the date. The outcomes are reportable in Reports > Competence, and no certificate is issued for an assessment a reviewer has not cleared.

Grading a scenario assessment

Programs that carry scenario assessments give you something a quiz cannot: evidence about how somebody would act, not just what they can recall.

The person writes a response in their own words. It arrives in your Quality > Review queue under Responses to grade, together with the publisher's guidance on what a competent response notices and does. You set a level for each criterion and record the grade.

Two things about that are worth knowing before you install such a program.

It costs reviewer time, and that is the trade. A knowledge check grades itself. A scenario needs a person who understands the work to read a few paragraphs and form a view. Budget for it, and give the reviewer role to somebody whose judgement you would actually rely on.

The person being assessed never sees the grading key. It lives in a place only the quality function can read. Showing it would turn the assessment into a reading exercise, which is exactly what the format exists to avoid.

Full detail is on Triage the review queue.

The version a person was trained on becomes immutable once evidence references it, so a later revision can never quietly change what someone was shown.

A note on what evidence proves

Program items declare what kind of evidence they produce, and the difference is real:

  • A knowledge check proves recall. It is honest evidence of awareness and nothing more.
  • A scenario assessment proves the person acted appropriately in a realistic situation, graded against criteria by a reviewer.

A program should not describe a knowledge check as proof of competence, and neither should you when presenting evidence to an auditor. Read the evidence column on the program's catalog page before you rely on it.

Next

Updates and recertification.