1Your workspace
Everything happens inside one active organization at a time. You sign in, land on a dashboard summarising that organization — documents, items in review, glossary terms, and what is expiring soon — and switch context only when you mean to.
How you use it
- The organization switchersits in the top bar. Pick an organization and the whole app — Documents, Glossary, Compliance — shows only that organization’s content. Your choice is remembered between visits.
- Group documents into folders (one level, no endless nesting). Drag a document by its grip onto a folder — or back to the root. Deleting a folder never deletes its documents.
- Organization admins configure Company settings — display name, legal name, address, registration number and logo for exports — and the business contextthat grounds AI drafting, on the organization’s own page.
2Writing in clauses
A document is a hierarchy of numbered clauses (1 → 1.1 → 1.1.2), not a text blob. Numbering is derived from structure: add, remove, reorder or re-nest a clause and every number updates itself — you never renumber by hand.
Keyboard-first editing
How you use it
- Drag and drop any clause by its grip — sub-clauses travel with it — or use the on-hover up/down and indent/outdent controls.
- Because references and definitions target the clause’s identity, never its number, reorganising a policy is always safe.
3Importing documents
The fastest way to start: bring in the PDF and Word policies you already have. The importer detects structure and numbering — from clause numbers or font sizes in PDFs, from heading styles and list levels in Word — and turns them into structured documents.
How you use it
- Import file → choose a .pdf or .docx → review the detected structure before anything is created.
- Read the “Changes made during import” list — it names exactly what was removed (page headers, tables of contents), renumbered, or not carried over. Content is never silently altered.
- If a definitions section is found, one tick lifts those terms into the central glossary and removes them from the body — no duplication.
4The glossary
Define a term once per organization and it is detected wherever it appears, across every document. Every match starts as a suggestion — you confirm it or mark an occurrence as “not this term” — so the vocabulary stays deliberate, not automatic noise.
How you use it
- Define terms in the Glossary tab, or select a phrase while writing and turn it into a term (or an alias) without leaving the document.
- Suggested terms: as you write or import, Clausery spots defined-looking phrases and, when the same term appears in more than one document, lists it for review — you define it in one click or dismiss it for good. Click Suggest and AI drafts the definition from how the term is used across your documents, for you to edit. The glossary grows only from terms genuinely shared across documents, and never without your say-so.
- Each document shows a “Definitions used in this document” panel — every term that appears, with its definition, editable in place.
- One source of truth: edit a definition once and every committed document using it is automatically re-versioned and flagged for re-approval — nothing goes stale silently.
5Cross-document links
Link a phrase to another document — or to a specific clause in it. References render as footnotes (“Security Standard, 3.1.1.2”) whose clause number is resolved live: restructure the target and the reference follows.
How you use it
- Select a phrase → + Link → pick the target document and, optionally, the exact clause. The phrase gets a blue underline and a numbered footnote.
- A “Linked from” panel shows which documents reference the one you are editing — and the system warns before you delete a clause that others cite.
- Link instead of copy-pasting: the authoritative clause stays authoritative, and your reference stays correct.
6Versions & comparison
Committed documents move only by versions. Commit a named version (major / minor / patch) with a change summary, then compare any two points — or a version against the working draft — clause by clause.
How you use it
- Each comparison row names who added, changed or deleted it, with their job title — like git blame for policies. Nothing is anonymous, even deleted content stays attributed.
- A “Linked documents changed”note appears when a referenced clause’s number shifted between the two points.
- Commit a version before any review or board sign-off — a clean before/after for auditors.
7Approval & validity
Every document has an owner. Anyone can edit; the owner approves. Each document declares how far its approval must go: owner (function head) only, on through the management board, or all the way to the supervisory board — or defines its own custom chain, stage by stage, with a deadline on each. Any stage can reject with a comment instead.
How you use it
- Only a committed version can be approved. An approved version is frozen exactly as approved — an immutable snapshot, no matter how the live draft evolves afterwards.
- Custom routing per document. Replace the standard ladder with your own chain — board stages and named approvers (say, the DPO must personally sign the privacy policy), each with an optional deadline that shows a due badge and turns red when overdue. Or let the AI suggest the routing from the document and your team roster — you review and save.
- Rejection with comments. Whoever may approve the current stage can instead reject it with a comment explaining what to fix. The document returns to Draft for rework, the rejection stays in the approval history, and any previously approved version remains in effect — never a gap.
- Every document carries a review period (2 years by default). Validity badges show in date review within 6 months within 2 months / expiredon the document, in the list, and as an “Expiring soon” count on the dashboard.
- The previous version stays in effect until the next one is approved — there is never a gap — and re-approving an unchanged document simply extends its validity.
- The documents list flags “Uncommitted changes” when a document is in effect but its working draft has edits not yet committed — so pending work (including edits from Propagating a change) is visible at a glance, not hidden until you open the document.
- Policy acknowledgement. Flag a document as requires acknowledgementand every member confirms they’ve read the in-effect version; owners see who has and hasn’t. A new approved version re-opens acknowledgement automatically.
8Generating a document set
Starting from a blank Documents page is the hardest part. Generate document set proposes your entire regulator-aligned document set in one go, organized by who is accountable for each part of it — you review and edit before anything is created.
How you use it
- Click Generate document set on the Documents page, pick a framework, and Clausery designs the set from that framework’s expected-document catalog, your organization’s business context, and the documents you already have — proposing what’s missing, not what you’ve already written.
- The proposal is grouped by accountable owner — a CISO group, a DPO group, an MLRO group, and so on — each with a suggested approval level and review period. Assign a real person to each group, edit any document’s title, category, approval level or review period, or untick the ones you don’t want.
- Create N documents makes one folder per owner group and seeds every document the same way a manually created one starts — ready for the AI drafting assistant below to fill each one in. A title you already have is skipped and reported, never duplicated. Works without an AI key too: you still get a full proposal built from the framework’s built-in document catalog.
9AI drafting assistant
Open a freshly created document and the editor offers to draft it with you: a few clarifying questions, a proposed skeleton of sections, then per-section content suggestions. Nothing enters the document until you approve it.
How you use it
- Answer 2–4 short questions (scope, responsibilities, your tools) → review the proposed skeleton — rename or remove sections — then approve. Every main section then offers “Suggest content”: a few concrete paragraphs you edit before inserting. If a section has sub-sections, it fills each one — a section intro plus content per sub-section — instead of a single flat block, and can even propose new sub-sectionsyou rename or discard before they’re created.
- Suggestions are grounded in your organization’s business context, reuse your glossary terms, and reference your other documents instead of restating them. When a section overlaps existing content, Clausery proposes a cross-link to the exact clause — ticked by default — so you link rather than repeat, with one click.
- Works without an AI key too: you still get a standard compliance outline and structured writing prompts. Inserted text is normal, editable content, attributed to you, and goes through the usual commit → approval flow.
10Propagating a change
When one thing changes for your organization — a new data processor, a renamed product, a new regulator — it usually needs updating across several documents. Describe the change in plain language and Clausery finds the documents it affects and proposes the edits each one needs.
How you use it
- From the Considerable change button on the Documents page, describe what changed. Clausery scans the whole bundle and lists the documents it affects — matching on content, not just titles — each with a reason and a confidence level.
- For any affected document, Propose edits returns concrete clause-level suggestions — rewrite this clause, add a new one here — grounded in your business context and using your existing wording. Review, edit or deselect each one before applying.
- Applywrites the approved edits into that document’s working draft, attributed to you; you then commit a new version and re-approve as usual, so every change stays on the audit trail. Works without an AI key too — it points you at the clauses that mention the change.
- Every run is kept as audit evidence: an assessment log records what changed, when and by whom it was assessed, which documents were flagged, and the edits applied because of it — proof that organizational changes were assessed, not just remembered.
11Compliance coverage
Pick an applicable framework — ISO 27001, ISO 27701, ISO 42001, DORA, GDPR, NIS2, PCI DSS, Solvency II, UK operational resilience, EBA outsourcing, US BSA/AML, or ECB cloud-outsourcing expectations — and see the documents it expects, split into necessary and good-to-have. Run a coverage check and each requirement is marked Covered, Partial, or Missing, with the matching documents and why.
How you use it
- Matching reads document content, not just titles— your “Access Management” document is recognised as the expected Access Control Policy.
- The expected-document list is editable: add, rename, reclassify or remove requirements, or regenerate the list from scratch.
- Close each gap two ways: Create in system (a new pre-titled document with the AI assistant tuned to that requirement) or Upload existing (straight into the importer). The check never changes your documents — re-run it and watch the gaps close.
12Sanity check
Coverage tells you whether you have the right documents. The sanity check tells you whether the documents you have agree with each other. One button compares the whole set and flags where it doesn't — with a suggested fix for each.
How you use it
- On the Documents page, click Run sanity check. Clausery compares every document and reports three kinds of problem: conflicts (two documents that contradict each other), duplicates (two that cover the same ground), and missing cross-links(two that discuss the same topic but don’t reference each other).
- Every finding names the documents involved and comes with a concrete suggested fix — which document to edit, what to consolidate, or which cross-link to add. Suggest changes then proposes the exact minor edits for the document you pick, right in the report, to review and apply — and a missing cross-link can be added with a single Create cross-link click.
- It is read-only — it never changes your documents. Works without an AI key too: it still finds likely duplicates and missing links by comparing content, and tells you plainly that spotting contradictions needs AI.
13Exporting & audit packs
Export any document as a clean PDF or Word file for auditors, board packs, or archiving — or export your whole approved set as a single ZIP. If the document is in effect, the export is the approved version exactly as approved — wording and numbering frozen — even if a newer draft has diverged.
How you use it
- Every page carries your company branding — logo, legal name, address, registration number — with page numbers in the footer.
- The layout leads with a Definitions section (only the terms used in that document), then the numbered body with clickable footnote references (full target name, version, publish date, clause), a Referenced by list, and the full version history table.
- One-click audit pack. Export every approved document as a single ZIP (PDF or Word), each at its approved version, with a manifest. Set an approval-date timeframeto give an auditor exactly the window they’re reviewing.
- Every file is named “company - document - version”, so exports are self-describing on disk.
- A document that has never been approved exports with an unmistakable “DRAFT — NOT YET APPROVED” watermark on every page — an unreviewed draft can never pass for a finished one.
14Users, roles & trust
Three access levels — superadmin, organization admin, and member — with a role per organization, plus management-board and supervisory-board delegate flags for board approvals. Job titles appear beside names everywhere responsibility is shown.
How you use it
- Admins manage members in the Users tab: add by email (new accounts get a one-time temporary password), change roles, toggle the management-board and supervisory-board delegate flags. Everyone manages their own name, job title and password under My account.
- Sign in with a password plus optional authenticator-app MFA, or with Google or Microsoft Entra ID single sign-on. Each company approves its own email domains and chooses whether anyone on an approved domain may join automatically or only pre-defined accounts may sign in. Repeated failed sign-ins are rate limited — password guessing is cut off server-side — and authenticator secrets are encrypted at rest.
- Read-only auditor access. Invite an external reviewer as a read-only auditor with an optional access-expiry date: they sign in and inspect approved versions, approvals, version history and exports, while every write is blocked and the editing UI is removed.
- An audit trail of privileged changes. Approval routing, document governance, company and sign-on settings, roles and board delegates, package changes and account deletions are recorded with who, what and when — plus a before/after view. It cannot be edited or deleted by anyone, and it never stores passwords or authenticator secrets.
- Deleting a user is non-destructive: the account can no longer sign in, but everything the person authored stays attributed — the audit trail survives personnel changes.
- The rules on this page — tenant isolation, the approval state machine, immutable snapshots, glossary and link integrity — are verified by an automated test suite against a real database before every change to the system is accepted.
Working efficiently — the short version
- 1Import existing PDFs and Word files instead of retyping.
- 2Build the glossary once — definitions appear everywhere automatically.
- 3Link, don’t copy — reference the authoritative clause.
- 4Type with the keyboard and let numbering manage itself.
- 5Commit at milestones and use Compare to review what changed.
- 6Trust the warnings — they are your audit trail.
14 days, no payment details — import a real policy and see it structured on day one.