PolicyBot in the web app
PolicyBot is a conversational assistant built into the InPolicy web app. Ask it a question or tell it what you want to do, and it works on your behalf — using your account and your permissions. As a rule of thumb: anything you can do by clicking around the app, you can ask PolicyBot to do.
This page covers PolicyBot in the web app. PolicyBot also reviews documents as you write in Google Docs, Google Slides, Microsoft Word, and PowerPoint — those are covered separately.
Opening PolicyBot
Section titled “Opening PolicyBot”Click the pink star icon in the left rail, just above Help. PolicyBot slides in as a panel on the right and stays available over any page — the dashboard, the policy library, analytics, anywhere.
- New chat — the + in the panel header.
- History — the clock icon; reopen any past conversation.
- Type in the box at the bottom and press Enter to send.
What you can ask it to do
Section titled “What you can ask it to do”Find and understand policies
Section titled “Find and understand policies”- “What policies do we have about data retention?”
- “Which policies don’t have an owner?”
- “Show me everything that’s still in draft.”
- “Summarize our customer-data policy.”
PolicyBot looks the answer up in your live policy library and names the specific policies — it doesn’t guess. If something isn’t there, it tells you plainly rather than inventing one.
Triage the inbox
Section titled “Triage the inbox”- “What’s waiting in the inbox?”
PolicyBot reports the documents that have been uploaded and parsed into suggested policies awaiting review. (See The Policy Inbox.)
Create, edit, publish, and delete policies
Section titled “Create, edit, publish, and delete policies”- “Draft a policy requiring MFA for admin accounts.”
- “Add a remote-work clause to the VPN policy.”
- “Publish the data-encryption policy.”
- “Delete the duplicate onboarding policy.”
These don’t happen instantly — PolicyBot proposes the change and shows a card with Confirm / Cancel. Nothing is created, edited, published, or deleted until you confirm. See How confirmations work.
Assign owners
Section titled “Assign owners”- “Make Jordan the owner of the data-retention policy.”
PolicyBot looks up the person, then proposes the change for you to confirm.
Check analytics
Section titled “Check analytics”- “Give me an analytics overview.”
- “Which policies trigger the most violations?”
- “Break it down by area.” / “…by severity.” / “…by team.”
This is read-only — PolicyBot reports the numbers, it doesn’t change anything. (See Analytics overview.)
Manage people and structure
Section titled “Manage people and structure”- “Invite alex@example.com as a Viewer.”
- “Deactivate the contractor’s account.”
- “Change Sam’s role to Policy Editor.”
- “Create a team called Security Engineering.” / “Add a Finance division.” / “Create a Data Privacy policy area.”
People and structure changes go through the same Confirm / Cancel step, and deactivating or removing someone is treated as a destructive action.
Report a bug or request a feature
Section titled “Report a bug or request a feature”- “Report a bug: the export button doesn’t work on the analytics page.”
- “Request a feature: let me bulk-assign owners.”
PolicyBot files it straight to the InPolicy team’s tracker and gives you a link.
How confirmations work
Section titled “How confirmations work”Anything that changes data is a two-step action:
- You ask. PolicyBot calls the right tool and shows a proposal card describing exactly what will change.
- You decide. Click Confirm to apply it, or Cancel to drop it. The change only happens on Confirm.
PolicyBot will never claim it did something before you’ve confirmed. Destructive actions (deleting a policy, removing or deactivating a person) are shown with a red button. If an action can’t go through — for example, you can’t deactivate your own account, or you lack the permission — it tells you right on the card.
Permissions
Section titled “Permissions”PolicyBot acts as you, with no authority of its own. It can only do what your role allows:
- Reading policies and analytics needs view access.
- Creating or editing policies needs Policy Editor or higher; publishing needs approval rights; deleting needs delete rights.
- Managing people, teams, and divisions needs Admin.
If you don’t hold a permission, PolicyBot says so instead of doing it. It can’t escalate its own access, act for another user, or reach outside your workspace, and every action it takes is recorded in the audit log. See the Roles & permissions matrix.
What it won’t do
Section titled “What it won’t do”- It won’t make things up. Answers about your workspace come from your live data; if it can’t find something, it says so.
- It won’t act outside your permissions or your workspace, and it ignores any instructions hidden inside policy text, documents, or other data it reads.
- It can’t silently change anything — every write waits for your confirmation.