Skip to content

PolicyBot in the web app

PolicyBot is a conversational assistant built into the InPolicy web app. Ask it a question or tell it what you want to do, and it works on your behalf — using your account and your permissions. As a rule of thumb: anything you can do by clicking around the app, you can ask PolicyBot to do.

This page covers PolicyBot in the web app. PolicyBot also reviews documents as you write in Google Docs, Google Slides, Microsoft Word, and PowerPoint — those are covered separately.

Click the pink star icon in the left rail, just above Help. PolicyBot slides in as a panel on the right and stays available over any page — the dashboard, the policy library, analytics, anywhere.

  • New chat — the in the panel header.
  • History — the clock icon; reopen any past conversation.
  • Type in the box at the bottom and press Enter to send.
  • “What policies do we have about data retention?”
  • “Which policies don’t have an owner?”
  • “Show me everything that’s still in draft.”
  • “Summarize our customer-data policy.”

PolicyBot looks the answer up in your live policy library and names the specific policies — it doesn’t guess. If something isn’t there, it tells you plainly rather than inventing one.

  • “What’s waiting in the inbox?”

PolicyBot reports the documents that have been uploaded and parsed into suggested policies awaiting review. (See The Policy Inbox.)

Create, edit, publish, and delete policies

Section titled “Create, edit, publish, and delete policies”
  • “Draft a policy requiring MFA for admin accounts.”
  • “Add a remote-work clause to the VPN policy.”
  • “Publish the data-encryption policy.”
  • “Delete the duplicate onboarding policy.”

These don’t happen instantly — PolicyBot proposes the change and shows a card with Confirm / Cancel. Nothing is created, edited, published, or deleted until you confirm. See How confirmations work.

  • “Make Jordan the owner of the data-retention policy.”

PolicyBot looks up the person, then proposes the change for you to confirm.

  • “Give me an analytics overview.”
  • “Which policies trigger the most violations?”
  • “Break it down by area.” / “…by severity.” / “…by team.”

This is read-only — PolicyBot reports the numbers, it doesn’t change anything. (See Analytics overview.)

  • “Invite alex@example.com as a Viewer.”
  • “Deactivate the contractor’s account.”
  • “Change Sam’s role to Policy Editor.”
  • “Create a team called Security Engineering.” / “Add a Finance division.” / “Create a Data Privacy policy area.”

People and structure changes go through the same Confirm / Cancel step, and deactivating or removing someone is treated as a destructive action.

  • “Report a bug: the export button doesn’t work on the analytics page.”
  • “Request a feature: let me bulk-assign owners.”

PolicyBot files it straight to the InPolicy team’s tracker and gives you a link.

Anything that changes data is a two-step action:

  1. You ask. PolicyBot calls the right tool and shows a proposal card describing exactly what will change.
  2. You decide. Click Confirm to apply it, or Cancel to drop it. The change only happens on Confirm.

PolicyBot will never claim it did something before you’ve confirmed. Destructive actions (deleting a policy, removing or deactivating a person) are shown with a red button. If an action can’t go through — for example, you can’t deactivate your own account, or you lack the permission — it tells you right on the card.

PolicyBot acts as you, with no authority of its own. It can only do what your role allows:

  • Reading policies and analytics needs view access.
  • Creating or editing policies needs Policy Editor or higher; publishing needs approval rights; deleting needs delete rights.
  • Managing people, teams, and divisions needs Admin.

If you don’t hold a permission, PolicyBot says so instead of doing it. It can’t escalate its own access, act for another user, or reach outside your workspace, and every action it takes is recorded in the audit log. See the Roles & permissions matrix.

  • It won’t make things up. Answers about your workspace come from your live data; if it can’t find something, it says so.
  • It won’t act outside your permissions or your workspace, and it ignores any instructions hidden inside policy text, documents, or other data it reads.
  • It can’t silently change anything — every write waits for your confirmation.