Finance
Purchasing Approval Matrix
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDPROOF SPACE
See how SALARA turns a policy document into activated Organizational Intelligence, then ask a question and Replay the evidence behind the answer.
Policy document experiences
Each available document is backed by activated Organizational Intelligence.
Finance
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDHuman Resources
54 approved policy statements are activated from this source.
DOC-HR-0005 · SRC-1DE734B79FD1BA337ED2D3E066EEInformation Security
19 approved policy statements are activated from this source.
DOC-IT-0003 · SRC-594156BCE10E5BB8CEFC271A91E2Information Security
20 approved policy statements are activated from this source.
DOC-SEC-0004 · SRC-565D08896030A88C111A7224DF98Information Security
31 approved policy statements are activated from this source.
DOC-SEC-0005 · SRC-6E538DE827A73F0439799AD79070IT Operations
58 approved policy statements are activated from this source.
DOC-OPS-0003 · SRC-5991452A065397B573265DC07B98Document content
These approved statements are the content Runtime can use. Answers stay inside this activated boundary.
IT Operations · Activated document
- Every exception must be recorded in the incident record.
ASSERT-009CCCFE7EFBBA10FC30A9084F1D20BF · v1- A Severity 1 incident requires executive notification within one hour.
ASSERT-00F9D0E142887E750630A646873D7C78 · v1- Corrective actions are tracked to closure by the Field Operations Director.
ASSERT-016C60CC6D4F576AE5A2DC03186C9D93 · v1- Severity 1 is an incident causing complete loss of a customer-facing service.
ASSERT-108600BB54591621FD592DA5FBC66AB9 · v1- An incident affecting more than one hundred customers is classified as Severity 1.
ASSERT-122AB786C509BF5FD278E6850A9E5207 · v1- Severity 2 escalation to the executive team requires Field Operations Director approval.
ASSERT-13394C7A08DBC8ED9D509B9E9DEA53FB · v1- Evidence must be preserved before any remediation that alters system state.
ASSERT-1A7F8B2B76A828234DE26D7443BC4227 · v1- Evidence is any record supporting later reconstruction of the incident.
ASSERT-281B3B015C424D990BA59F35AA12B19A · v1- A Severity 1 incident involving customer data requires notification to the CISO.
ASSERT-317BEB5B472D1202080D538B8C53FF34 · v1- A Severity 1 incident requires a post-incident review.
ASSERT-35CBD578B90144A3A0F121BFCBF379EF · v1- A Severity 1 response must continue uninterrupted until service is restored.
ASSERT-3E25451EEA3FD410AD1F58C5E371A085 · v1- Information Security owns evidence handling for a security incident.
ASSERT-406ED7717DF586090DDA7870E3179962 · v1- Every responder must preserve logs relevant to an active incident.
ASSERT-441C1BA3AA70E9EDD3B6FCF6110ED532 · v1- The incident commander may authorize an emergency change during a Severity 1 incident.
ASSERT-4D2BD971CDA24A2944239DB053A8DB96 · v1- Severity is assigned by the on-call operations lead at declaration.
ASSERT-4EF31471F2226F31453C97A4DEA959EA · v1- The Field Operations Director owns this standard.
ASSERT-547B9D8FEA152932096E3BB424871906 · v1- An exception to a response window requires Field Operations Director approval.
ASSERT-55AE9E837E640EDB4928EEBFD3FEFC3A · v1- This standard applies to every operational incident affecting a Compass One service.
ASSERT-56102F42528320EC13DA201E387500C9 · v1- Severity 3 is an incident with limited impact on a single customer.
ASSERT-562E30E5FB7C9B61E77F3D9B87943AFC · v1- The Technical Support Director owns customer notification.
ASSERT-57E8EBF53538B6FF810BB0DE7C7CB41C · v1- External communication requires approval from the VP Customer Experience.
ASSERT-63AF62119BF4AFF93E11C70F2D8C7616 · v1- A Severity 1 incident lasting beyond four hours requires continuity plan activation.
ASSERT-6F2C153C2F40AA7F364F96544908D3F1 · v1- The incident commander is the individual accountable for coordinating the response.
ASSERT-718FE4FF93E141946F3456A5F0D06A54 · v1- Any responder may raise the severity of an active incident.
ASSERT-7B15DABF710EFB9C295D39785336BC8F · v1- A Severity 1 incident requires acknowledgement within fifteen minutes.
ASSERT-7BB7D0C5B43D5499BE70B77753A6C4D6 · v1- A safety event involving injury is classified as Severity 1.
ASSERT-7DA6B6140A5B8266B38484B34C54F441 · v1- An incident with an available workaround is classified as Severity 2.
ASSERT-7ECDCE5F58E3B40F27B2F03AC30C9C28 · v1- Security incident reporting is stated in DOC-SEC-0002.
ASSERT-80DBEE60AB5D23A8025CD442CB7CC8E6 · v1- Deletion of incident evidence during an active investigation is prohibited.
ASSERT-8F63ED7F34F21EBBC16365C953AEAED2 · v1- A Severity 3 incident requires acknowledgement within one business day.
ASSERT-9192EB6A4156D52F67844C6E4A1B5148 · v1- A Severity 1 incident requires a status update every thirty minutes.
ASSERT-94DCA5A9FDCC99823BEEC81BEB289ED4 · v1- A Severity 2 incident requires a status update every two hours.
ASSERT-972DF6B48B8D2719D83FA2FC86CBFD39 · v1- A Severity 1 incident requires an assigned incident commander within thirty minutes.
ASSERT-A488009EDC5AC9E375F4356598C0799A · v1- The incident commander has authority to escalate to any Compass One function.
ASSERT-AC039A71B122CFD019CAF86FFB699392 · v1- A post-incident review must identify at least one corrective action.
ASSERT-AD6F2F41ABBAEB4F28A6825AD2E77232 · v1- The post-incident review is owned by the incident commander.
ASSERT-AFCF30A98819DEFAB25CED4D63EED443 · v1- The on-call operations lead must be notified first for every incident.
ASSERT-AFF18211BFC0F522166281D83FA1D867 · v1- Executive notification is directed to the COO.
ASSERT-B0416DE5D5B0F906B2491981B130CB7C · v1- An incident is an unplanned event that degrades a Compass One service.
ASSERT-B43E5082CD26281C4CEF3EB9E9A11BC7 · v1- A planned maintenance event is not classified as an incident.
ASSERT-B9EEE8E7EFC1A22559991446078C228B · v1- A Severity 2 incident requires acknowledgement within one hour.
ASSERT-BC65947F7BF9F6DC9AC36EE25BE4EB09 · v1- The incident commander owns all internal incident communication.
ASSERT-BCAE82F6D59EF3210F3D634B7CA3AAAB · v1- Severity may be raised at any point during an active response.
ASSERT-C41FD18B8DB7CB098054F72162180EB6 · v1- Customer escalation routing is stated in DOC-CUS-0001.
ASSERT-C4B3FB58C7EF4DC9B13081D5330E35A6 · v1- A Severity 2 incident requires a review when customer impact exceeds two hours.
ASSERT-C60235CFF2B3B62A4A35CBB40736AC16 · v1- A Severity 2 incident requires executive notification when unresolved after four hours.
ASSERT-D23DED5AC53A34C1B18A5109EE7C0A6C · v1- A security incident is handled through DOC-SEC-0002 rather than this standard.
ASSERT-D3F6A2844544944ECE793193646DC77A · v1- Incident evidence is retained for twenty four months.
ASSERT-D6DA2F0339BB8171EAEA9518FA02B86B · v1- Continuity activation requires notification to the COO.
ASSERT-D7D237A54D98307562CC38B66B1E5774 · v1- Customer notification for a Severity 1 incident is issued within four hours.
ASSERT-D7FA281061C5AD57C40A565FE6E50637 · v1- Speculation about cause is prohibited in customer communication.
ASSERT-DD9EA3F38CC38810FD23417198448A9F · v1- The incident commander is accountable for the coordinated response.
ASSERT-DE8C84CF08DF663782538BF57164E95D · v1- The post-incident review must be completed within five business days.
ASSERT-DF72E66D2B030AE3E1B65DCC9A54F36D · v1- Severity 2 is an incident causing partial degradation of a customer-facing service.
ASSERT-E383F37F84FA18404253D0AAC7112684 · v1- An incident involving loss of customer data is classified as Severity 1.
ASSERT-E74CCF2E6AE43587D04855C51A8365B5 · v1- The continuity plan is activated by the Field Operations Director.
ASSERT-E8CEB59AD57A7EF6203CFFBAD79A4F6F · v1- Information handling requirements are stated in DOC-SEC-0005.
ASSERT-ECA548EFD92A31CDAF4802FB8C19B82F · v1- The on-call operations lead is accountable for initial severity assignment.
ASSERT-F91ACAABDBD2C5477134A3866E52E470 · v1From the activated intelligence
These examples are derived deterministically from approved Assertions in the active compiled artifact.
What does the policy say about - Every exception must be recorded in the incident record?
Ask this questionWhat does the policy say about - A Severity 1 incident requires executive notification within one hour?
Ask this questionWhat does the policy say about - Corrective actions are tracked to closure by the Field Operations Director?
Ask this questionWhat does the policy say about - Severity 1 is an incident causing complete loss of a customer-facing service?
Ask this questionWhat does the policy say about - An incident affecting more than one hundred customers is classified as Severity 1?
Ask this questionWhat does the policy say about - Severity 2 escalation to the executive team requires Field Operations Director approval?
Ask this questionOne discipline, four ways to explore