VeritomeHelp Centre
/
Browse documentation
Programmes

Steps: Aria drafts, a person approves, then it counts

Open a step, answer its questions or let Aria draft from what you already have, then approve. Only approval files the record as evidence and creates the control.

Updated Veritome documentation

A step opens in the same drawer an obligation does — from Obligations (the organisation-scope rows), from the programme card's next step, from Policies, or from its row in Documents.

The drawer

The header names the framework and the clauses the step closes. Below it are three tabs — Guided form, Evidence and Audit — and a workflow row with the step's status · owner · reviewer · approver · due date, which autosaves as you change it. The right rail carries Why this matters, What good looks like, the Aria block and an at-a-glance summary. A Related line lists supporting references in other frameworks; it is shown, never counted.

The guided form's fields are the step's key questions. Most are free text; a yes/no-shaped question renders as a Yes / Partly / No choice.

The six statuses

StatusMeaning
Not startedNothing captured.
In progressSomeone is answering.
Awaiting reviewSent to the reviewer.
EvidencedApproved — the record is filed and the control exists.
Done by overlapEvery requirement was already evidenced elsewhere; see Overlap credit.
Not applicableOutside the count — set by hand, or by the plan for a conditional GDPR step whose condition does not hold.

You can set the first three and Not applicable yourself. Evidenced is reached only through approval and Done by overlap only through the plan; neither can be typed in.

Aria drafts

Two ways to ask. Ask Aria on a single field returns a suggestion you read before applying — nothing is stored until you accept it. Draft with Aria on the whole step reads your register — the systems, the risks, the suppliers, the records you already hold — and drafts every empty field at once. That draft is a proposal: it lands in Aria's Inbox with a note of what was read, and applying it fills empty fields only. What you wrote by hand is never overwritten.

Aria drafts and proposes; it never files. A draft counts for nothing until a person approves the step.

Approve and file

Approve and file is available to the step's approver or an organisation admin, and it is the only door to Evidenced. Approval is one transaction:

  1. The record is filed as approved.
  2. One evidence item is created and linked to every requirement the step satisfies — in this programme and, for a shared record, in its sibling programme too.
  3. A control appears on Controls, carrying that evidence and naming the step that produced it.
  4. The step becomes Evidenced, and the sibling programme is re-planned so a shared step there flips to Done by overlap.

For the Statement of Applicability steps there is one more check: an exclusion without a justification sentence is refused (see The Statement of Applicability).

Why approval is the only door

Because an unapproved machine record is worthless to an auditor, and because oversight by a natural person is the point. There is no auto-approve for a programme step, on any autonomy setting.

Guidance you can trust

Every step's guidance was generated from the owner's verified framework matrix and carries the reviewer's name and date. For a binding-law framework — the GDPR — that stamp is what activates the programme at all: a GDPR programme is generated only while every one of its templates is reviewed. The voluntary standards ship reviewed guidance the same way.