Your first campaign, in six steps.

The goal is one evidence export you can open and read: a real policy version, a real acknowledgement, a real outstanding list. One policy and a handful of recipients gets you there in an afternoon. Rolling out to everyone is the second campaign, and it is much easier once you have seen the first one work.

Create a free workspace and start

Free for up to 15 employees, no card. The same checklist appears in the product as a progress list, driven by what has actually happened in your workspace rather than by ticked boxes.

  1. 1. Choose one policy

    In the app: Policies
    • Pick a policy that is already agreed and that people would expect to acknowledge — usually the information security policy or acceptable use.
    • Do not start with the one that is still being argued over. A first campaign is for testing the workflow, not for settling content.
    • A new workspace comes with three starting templates (acceptable use, data classification, incident response). Use one, import your own PDF, or write it in the builder.

    Done when: One policy exists in the workspace with the text you intend people to confirm.

  2. 2. Publish the version

    In the app: Policies → the policy → Publish
    • Take the policy through review and approval, then publish it.
    • Publishing freezes that text as a numbered version with its own identifier. Later edits create a new version and leave this one intact.

    Done when: The policy shows as published and has a current version. Campaigns can only be sent against a published version — this is the step that unblocks everything after it.

    If it stalls: If Publish is unavailable, the policy is still in draft or in review. Approvals live under Approvals; a single-admin workspace can approve its own.

  3. 3. Select the recipients

    In the app: Campaigns → New campaign
    • Keep the first audience small — one team, or three colleagues who will actually click. You are proving the loop, not covering the organisation.
    • Paste addresses directly, or pick directory groups if Microsoft Entra or Google Workspace is connected. You do not need a directory connection to send.
    • Set a due date and a reminder interval. Reminders only ever go to people who have not confirmed.

    Done when: The draft campaign lists every intended recipient exactly once. Addresses that appear in both a group and your pasted list are merged, so nobody is invited twice.

    If it stalls: Free workspaces cover up to 15 people. If activation is blocked on capacity, trim the audience for this first run rather than upgrading to test.

  4. 4. Send it

    In the app: Campaigns → the draft → Activate
    • Activate the campaign. Each recipient gets their own link to that exact version — no account and no login needed on their side.
    • Send one to yourself as well. Walking the recipient's path is the fastest way to see what your colleagues are being asked to do.

    Done when: The campaign shows as active with an activation timestamp, and each recipient has a delivery state you can see.

    If it stalls: If delivery stays queued or comes back rejected, check the address and the sender setup under Settings → Email deliverability. The campaign page shows the per-recipient provider state, so you can tell a bad address from a sending problem.

  5. 5. Review progress

    In the app: Campaigns → the campaign
    • Watch the split between confirmed and outstanding. The outstanding list is the useful one.
    • Let reminders do the chasing. Escalate to a manager only for cases that are genuinely overdue.
    • Where someone cannot reasonably confirm — extended leave, for example — record an exception with a compensating control and an expiry, rather than leaving them silently missing.

    Done when: At least one recipient has acknowledged, and every outstanding recipient has a reason you could explain out loud.

  6. 6. Export the evidence

    In the app: Campaigns → the campaign → Export
    • Export the summary PDF for the readable overview, and the CSV for the per-recipient detail.
    • Open the CSV and find one person: their policy version id, their timestamp, their content hash. That is the record an audit turns on.
    • Export mid-campaign, not only at the end. An export with outstanding recipients in it is a truthful snapshot, and it is what you will actually be asked for.

    Done when: You are holding an evidence file for a real policy version with a real acknowledgement in it. This is the point at which the workflow has proved itself.

    If it stalls: The evidence export needs at least one completed acknowledgement for the version the campaign was sent against — otherwise there is nothing to evidence yet.

After the first export

Two things are worth doing next, in this order. Read the auditor walkthrough so you can explain the export rather than just hand it over. Then run a second campaign across the full audience in scope — the first one proved the workflow; the second one is the evidence you will actually take into the audit.

Policyflow does not make an organisation certified and cannot promise that an auditor will accept any particular record as sufficient. What it does is make the acknowledgement evidence a by-product of sending the policy, instead of a reconstruction job in the week before the audit.