The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Documents people understand and auditors accept.
We write your company's body of policies, standards, and procedures in language people can actually follow, not the intranet prose nobody reads. A document nobody understands does not change behavior, and it fails audits too, because practice never matches the paper.
What changes between tiers is where the list comes from. If you do not know which documents matter for your case, and that is most companies, you start with the assessment: we interview the areas and the list comes out of your business and your risk. If you want the essentials done well and fast, you take the standard package, and if you already arrived with the list ready, driven by an audit or client requirement, you go straight to drafting.
Every document comes with an owner, a review deadline, and an approval chain defined in the matrix that accompanies the set. We prepare the material for approval, support the internal rollout, and, in the tiers that include training, we train the areas involved with attendance records, which is what auditors ask for to accept that the policy is alive.
On your side, we need time with the areas that will be interviewed or will validate the texts, and someone with the authority to approve the set. We write and prepare; the act of approving and publishing is your governance, and it is what gives the document its validity.
The stages and deliverables below describe the Assessment before writing modality. The other modalities appear when you request the proposal.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Writing
We write each document in the language of the people who will follow it, rather than the intranet prose nobody reads.
Approval and publication
We prepare the material for approval, set an owner and a review date for each document and support the internal rollout.
Training the teams
We present what was built to the people who will live with it day to day and we record attendance. Without that record, an audit treats the document as if it did not exist.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.