Installing a program
You need an administrator role. Plan about half an hour, most of which is the role mapping.
1. Get the program file
Your publisher sends you a signed program file. It carries the program, its version and the publisher's signature.
Check the version against what you were sold. A program's version is meaningful: a major version means something changed that requires people to be retrained.
2. Load it
Go to Compliance programs and choose Install a program. That opens a four-step page: the file, what it installs, who it applies to, and confirm. You can move back and forth freely, and nothing is written until the last step.
Pick the file. Before anything is created, you see:
- The publisher, the program and its version.
- The signature result.
- Everything it would create, listed in full.
- The languages it ships in, checked against the content languages your organisation has configured.
- Anything worth a second look, such as a role that currently matches nobody.
Nothing has been written yet at this point. You can stop here with no trace.
Two different questions about the signature
The product treats these separately, because they are not the same question.
Is the file intact? Always checked, no exceptions. If the contents do not match what the publisher signed, the file was altered after it left them and the install is refused outright. There is no override for this and there should not be.
Is that really your publisher's key? Answered only if an administrator has previously registered that publisher's key on this instance. If they have, you see Trusted publisher. If they have not, you see Publisher not vouched for, which means the file is genuine and unaltered but nothing here proves who produced it. You may still install it, and you have to tick a box saying you accept content from that publisher. Your choice is recorded on the install record and in the audit trail.
Registering a publisher key is a one-off setup step for your administrator. Ask your publisher for their key fingerprint and compare it out of band, over a channel other than the one the file arrived on.
3. Map the roles
This is the step that matters, and the only one nobody can do for you.
A program describes roles, not your organisation. It might define a role called "human oversight" and describe the kind of person who holds it. Your job is to say who that is here, using the same dimensions you already use for assignment: department, activity, plant, line, workstation, and profile attributes.
The program suggests a default mapping. Treat it as a starting point, not an answer.
Two mistakes to avoid:
Mapping by job title. Titles rarely match what people actually do. Map by activity and by who genuinely holds the authority the role describes.
Assigning oversight to someone who cannot intervene. If the person you map to an oversight role cannot in practice reject an output, halt a process or escalate without penalty, you have not created oversight. You have created a record claiming oversight that an auditor can disprove by asking them one question. Map the role to whoever really has that authority, or fix the authority first.
Roles are listed compactly, one line each, showing what the role receives, the audience you have given it and how many people that reaches. Open a role to decide it, and each role takes one of four answers:
- Everyone. Every person in the organisation receives this role's content. Correct for an awareness role, and rarely correct for one that carries real authority.
- Specific people. You set the audience with the pickers. At least one filter is required, because a filter-free audience is everyone, and that is a different answer.
- Decide later. The role exists here but you do not yet know who is in it. The content installs, nobody is enrolled on that path, and the role stays outstanding on the program card until you set its audience. Use this rather than guessing.
- Not applicable. You have nobody for this role. Nothing is created for it.
You cannot continue while a role has no answer, and the step tells you which ones. If the install is going to take longer than this sitting, Leave the remaining roles until later answers them all at once, honestly, in one click.
None of these is permanent. Edit targeting on the program card changes any of them later, without re-installing anything.
Deciding several roles at once
Tick the roles in the list and apply one answer to all of them. A program with a dozen roles where nine do not exist in your company is normal, and answering that nine times is data entry rather than a decision. Copy from takes the audience you built for one role and applies it to the others you ticked.
Attribute filters, and why a role can match nobody
A publisher often targets a role by an attribute rather than by an org-chart dimension, because "actually uses an AI tool" is not a department. Those filters are shown in the mapping editor and they narrow the selection on top of the departments you pick, so a role can target every department and still reach nobody.
The panel tells you how many people carry each filter today. Zero is the whole explanation, and it means the fix is on the people rather than on the pickers.
Mark people opens the list of everyone in your organisation, with those who already carry the flag ticked. Tick the rest, save, and the flag is stored on each person. It is durable organisation data, not install state, so it keeps working for every other program and every rule that uses the same flag, and it shows on each person in Users.
If the flag is not how you want to describe the role in your organisation, remove the filter here and target by department or activity instead.
What each role receives
The role panel lists the documents and training the decision assigns, by title. Read it before you decide who is in the role, because a role that assigns two policies and a graded assessment is a bigger commitment than one that assigns a reading item.
4. Read the numbers before you commit
Each role shows how many people it currently matches, and the summary tells you how many people in total would be enrolled in at least one item. Those numbers update every time you change a mapping.
Read them properly. This is the cheapest moment to discover that a rule catches 400 people instead of 40, or that a department you forgot has nobody covered.
The counts come from the same matching engine that performs the real assignment, so what you see is what you get. Open a role to see some of the matched people by name, because a mapping that reaches the wrong forty people looks exactly like one that reaches the right forty. A role matching zero people is called out, because content nobody is assigned is the most common way a program looks installed and does nothing.
The last step before you install lists every decision you made, role by role, with its audience and its reach.
5. Install
Now the program writes to your instance. It creates the controlled documents, the training versions and the assignment rules.
Everything lands unapproved. Documents arrive as drafts and training versions arrive pending review. Nothing reaches a single learner until your quality function approves it.
Each item is audited as it is created, exactly like content you author yourself.
You will need a second person. Whoever installs a program cannot approve its content, documents included. If you are the only administrator, the program cannot go live until a colleague with a quality role can approve it. The confirm step says this before you commit.
6. Approve, then activate targeting
The assignment rules exist from the moment you install, but they cannot enrol anyone in content that has not been approved yet. That order is deliberate rather than a limitation.
The program card carries a worklist of exactly what is left: how many documents are effective, how many training versions are approved, and whether targeting has anything to enrol yet. Each step links to the screen that does it.
Once your quality function has approved the content, come back to Compliance programs and choose Activate targeting. Everyone the rules match is enrolled, and you are told how many assignments were created. Running it twice is safe, because it only ever adds what is missing. Running it too early is refused with an explanation rather than quietly enrolling nobody.
Changing who a program applies to, later
Targeting is not a one-shot decision, and treating it as one is the mistake this screen is built to avoid. Choose Edit targeting on the program card at any time to open the same screen you used during the install, now showing what each role reaches today.
Use it when a role you deferred finally has an owner, when a department is added, when a mapping turns out to reach nobody, or when you got one wrong. Saving rewrites the program's assignment rules in place.
Widening a role enrols the people it now matches, once the content is approved. Narrowing it stops future assignments and never deletes a completion, an acknowledgement or a signature somebody already gave. Rules a role no longer needs are deactivated rather than deleted, so the record of what was assigned and why stays intact.
What if the install fails partway
Every regulated write records its justification before it takes effect. If that record cannot be written, the change is rolled back rather than left half-applied. You will not end up with an approved document that has no audit trail.
Next
Approving and assigning covers what happens after the install.