Skip to content

Attestations and policy packages

Some framework requirements cannot be demonstrated by any AWS configuration: a sanction policy, a risk analysis, workforce training. StackTakt covers these with attestation documents: structured documents a named person completes and approves. An approved, unexpired document sets its requirements to Attested on the Compliance page. Attested is deliberately distinct from Demonstrated: a document is a recorded decision by a person, not an observed technical control.

The Documentation Center lists every document a tenant owes, derived from its adopted frameworks. Each template carries prompts, guidance, and standard language: reviewed model clauses citing what they are modeled on (the Security Rule text and NIST SP 800-66 for HIPAA; the AICPA Trust Services Criteria for SOC 2).

Standard language is a starting point, never an answer. Every organization-specific fact is a {{PLACEHOLDER}} token, and a document holding an unresolved token cannot be submitted or approved. Nothing auto-fills: a policy set that reads complete but describes an organization nobody checked is the failure mode this design exists to prevent.

  1. Draft: opening a template creates the document with its starter scaffolding. Complete each section; insert or replace with standard language where it fits, then make it yours.
  2. Submit for review: refused while any required section is empty or any placeholder remains.
  3. Approve: a named approver, recorded distinctly from the author, with an optional note. Approval starts the review clock (365 days by default).
  4. Expired: past its review date, the document stops attesting and its requirements fall back until it is reviewed and approved again.

Editing an approved document reopens it as a draft and withdraws the attestation until it is approved again. Every revision is kept; history is append-only.

A consultant completing the same nineteen documents for every client needs reuse without shortcuts. A policy package captures one tenant’s completed documents as an immutable, numbered version at organization scope; applying a version to another tenant creates drafts for that tenant to review and approve.

Two rules keep this honest:

  • Approvals never travel. Applying a package always produces drafts. Copying an approval across tenants would put attestations into the record that nobody made.
  • Applying is additive by default. A tenant’s own existing text is skipped and named, never silently overwritten; a switch exists to replace deliberately, and replaced documents reopen as drafts.