Understand Policy Statuses

Prev Next

Each policy goes through several stages in its compliance lifecycle. Understanding these statuses helps you track where each policy stands and what action, if any, is needed.

Policy Statuses

Here's an explanation of each policy status in Scrut:

Not Uploaded

A policy is in the Not Uploaded status when no document has been attached to it. This is the starting state for every new policy in Scrut.

Draft

Once you attach a document to a policy (by creating one, uploading a file from Google Drive, Confluence, or SharePoint, or linking an external document), it moves to Draft. A policy stays in Draft until you explicitly move it to the next status.

  • If the approval workflow is turned off, you can publish the policy directly from Draft.

  • If the approval workflow is turned on, the policy must go through the approval process before it can be published.

Pending Approval

The Pending Approval status indicates the policy is in the approval chain and waiting for the current approver to act. A policy moves to Pending Approval when it's sent for approval, and it stays in this status through each intermediate approval until the final approver acts. This status is applicable only if the policy approval workflow is turned on.

Approved

The Approved status indicates that the policy has undergone internal review and has been approved by designated approvers within your organization. However, the policy has not been officially published. Hence, the associated controls are still non-compliant. This status is applicable only if the policy approval workflow is turned on. Once approved, the policy is ready to be published.

Published

The Published status indicates that the policy has been finalized, reviewed, and approved, and it is now ready for distribution and implementation across the organization. Policies in the Published status are considered official and count as evidence for compliance audits. Employees, contractors, and other relevant parties can access, read, understand, and follow them in their activities.

Needs Review

The Needs Review status indicates that the policy needs review and republishing to ensure ongoing compliance with evolving organizational rules and policies. Policies move from Published to Needs Review based on the configured recurrence cycle.

How Policy Approval Workflow Impacts Policy Status

The path a policy follows depends on whether the approval workflow is turned on or off for that policy.

When the Approval Workflow Is Off

After you attach a document, you can publish the policy directly. Once published, it moves to Needs Review when the recurrence is triggered, and returns to Published after it is reviewed and republished.

Not Uploaded → Draft → Published → Needs Review (Cycle Repeats)

When the Approval Workflow Is On

After you attach a document, the policy goes through the approval process during which it is in the Pending Approval status. Once all approvers sign off, it moves to Approved. From there, you can publish it. When the recurrence is triggered, the policy moves to Needs Review and goes through the approval process again before returning to Published.

Not Uploaded → Draft → Pending Approval → Approved Published → Needs Review (Cycle Repeats)