Skip to main content

Records: documents, policies, and tests

Records is your central hub for compliance evidence, where the documents, policies, and tests that prove your controls are in place all live together, each with its own status and renewal schedule.

Written by Taylor Laing

The Records types: Document and Policy

The Records list itself holds two types:

Type

What it is

Typical use

Document

A file or reference that demonstrates a control is in place

Procedures, registers, meeting minutes, training records

Policy

A managed policy document, versioned and (where required) acknowledged by workers

Code of conduct, psychosocial safety policy, grievance policy

Tests live on the control, not in the Records list: A control's evidence can also include a Test (a record that a check or control test was performed). Tests are a control-level requirement: on the control detail page each control has Documents, Policies, and Tests sections, and a test can be automated, document-based, policy-based, integration-driven, a manual review, or an attestation. The central Records list filters only by Document and Policy.

What each Record row shows

The Records list is a single table. Each row shows:

Column

Meaning

Name

The record title

Scope

The group or committee the record applies to

Type

Document or Policy

Priority

How important the record is to your posture

Expires

When the current version expires

Frameworks

Which active frameworks the record satisfies

Status

Complete, Incomplete, Due Soon, or Overdue

Search, Filter (including by Type), and Sort sit above the table, and the header summarises your overall completion.

Status and renewal

Records use the same status vocabulary as controls (Complete, Incomplete, Due Soon, Overdue), and their renewal date is driven by the frequency of the obligation they satisfy. As a Record approaches or passes its expiration date, its status changes and any control it evidences recalculates too.

This is what keeps your evidence honest over time: a policy that's overdue for review shows up as overdue on every control it supports.

How Records connects to controls

Records don't stand alone; they exist to evidence controls:

  1. A control declares what evidence it needs.

  2. You attach a Record (a document, policy, or test) to satisfy that requirement. See Adding evidence to a control (Records).

  3. Once approved, the Record counts toward the control and updates its status.

  4. Update the Record later (a new policy version, a refreshed test) and every control that references it picks up the change automatically.

Records is not Drive

ReFresh has a second, separate content area, Drive (/app/documents), and it's easy to confuse the two:

Records (/app/records)

Drive (/app/documents)

Purpose

Compliance evidence: proof for controls and obligations

A general content hub for authoring and storing material

Governed by

Status, renewal, and review

Tags, references, and soft-delete to Trash

Content

Documents, policies, tests

Rich-content documents you author, plus files and links

Records is the compliance-linked subset of your content: records with obligations attached (expiry, status, framework mapping). Drive is where documents live in general. A document authored in Drive can be attached to a control, at which point it becomes a Record. Use Records for anything that has to hold up as evidence; use Drive for working or reference material. See Using Drive (the content hub).

Did this answer your question?