Welcome to the Enveedo Knowledge Hub
Documentation Management: documents, versions and approvals
How to create documents, manage versions, request internal or external approvals, publish the current version and track periodic review.

Documentation Management is Enveedo's module for managing your security program's documents — policies, processes, standards and more — with their versions, their approval workflow and a single current version per document.

Documents can be linked to the other entities in the platform — assets, risks, controls, processes, vendors, people, incidents, findings, privacy register and assessments — so that each document is tied to the program element it supports.

How it works: the overall flow

Create → Version → Approve → Publish → Maintain

You create the document, add a version (file or link) and run the approval flow — by an Enveedo user, or by requesting approval through a link sent by email. Once approved, the version is published as current, and the platform tracks periodic review: when the approval expires, the document is flagged as needing review again.

Document modes

When you create a document you define how it will work:

  • Controlled document: the full lifecycle — versions, approval workflow, explicit publishing and periodic review. This is the mode for policies, processes, standards and any document that requires an official, formally approved version.
  • Single file (no versioning): a document with a single piece of content (file or link), available from the moment it is created, with no versions, no statuses and no approval workflow. Its content can be updated without creating a new version. This is the mode for reference files that do not need a formal approval cycle.

The mode is set at creation and cannot be changed afterwards.

Creating a document

  1. In the module, select New Document.
  2. Fill in the document details: ID, title, category, description and — where applicable — the review frequency.
  3. Select the document mode.
  4. For a controlled document, fill in the first version: number, author and content (file or link). The first version is optional: you can create the document record and add the content later.
  5. Confirm. The document appears in the list.

Supported formats: PDF, Word, Excel, PowerPoint, text, CSV, JSON and images (JPEG, PNG), up to 50 MB per file. A link can be used instead of a file.

Versions

  • Version numbering is defined by the user (1.0, 2.3, Rev C) when each version is created, and must be unique within the document.
  • While a version is in Draft status, its file or link can be replaced freely. If an approval request was in progress, the replacement invalidates it: the approver cannot approve content they did not review.
  • Any version of the document can be downloaded from the version history.

Requesting approval of a version

There are two mechanisms, with the same outcome: approver, date and channel are recorded as evidence.

Internal approval (declarative)

Records a decision already made through another channel — a meeting, an email, a signed document.

  1. On the version, select the internal approval option.
  2. Indicate the approver (from the People module) and the approval date. Past dates are allowed, so historical inventories can be loaded with their real dates.
  3. Confirm. The person recording the approval and the person who granted it are separate fields, and both are stored.

External approval (email + verification code)

Intended for approvers who do not use the platform.

  1. On the version, select send for external approval and indicate the approver (they must exist in the People module, with an email address).
  2. The approver receives an email with a personal link (valid for 14 days).
  3. On access, they verify their identity with a one-time code sent to their inbox.
  4. They review the document and approve or reject it; a rejection requires a reason.

The request can be cancelled (the link is disabled immediately) or resent (a new link is generated, with the form pre-filled).

To send a version for approval, it must have content (file or link). A rejection does not delete anything: the version stays in Rejected status together with its reason, and the process continues by correcting and requesting approval again, or through a new version.

Publishing and the current version

  • Publishing is an explicit action on an approved version; approval on its own does not publish.
  • There is at most one published version per document: when a new one is published, the previous one is unpublished automatically.
  • The published version is the current one: it is the one that gets downloaded, the one shown in the list and the one the rest of the platform references.

Periodic review

If the document has a review frequency, the platform tracks its validity. When the approval expires, the document appears in the expired filter. At that point you can request re-approval of the same version — through the external email-and-code flow, or by recording it internally — and, once re-approved, publish it again.

Expiration signals are visual: the next review column in the list and the expired filter. We recommend making a check of this filter part of your regular operations.

Document preview

  • 5 formats can be previewed: PDF, text, CSV, JPEG and PNG.
  • Office formats are downloaded, with no on-screen preview. This is a privacy decision: displaying them embedded would require processing the document outside the Enveedo environment.
  • The preview always corresponds to the published version.

Associations with other modules

Documents can be linked to assets, risks, controls, processes, vendors, people, incidents, findings, privacy register and assessments. Associations apply equally to controlled documents and single files, and are visible from both ends of the relationship: from the document and from the linked entity.

Deleting documents and versions

Deletion is permanent: there is no recovery bin. For that reason it requires explicit confirmation, and the trace of the operation (what was deleted, by whom and when) is recorded in the audit log.

Frequently asked questions

I can't publish a version. There are two possible reasons, and the screen indicates which one applies: the version is not approved (you need to approve it) or its approval has expired (you need to re-approve it).

The approver isn't receiving the verification code. Codes are valid for 10 minutes and up to 3 can be requested per hour; if several were requested, the latest one must be used. Check the spam folder. If the link has expired (14 days), resend the request from the version.

The approver got locked out when entering the code. Five incorrect codes lock access for 30 minutes. After that, they can try again; no action is required from the company.

The portal says "This document has changed". The version's content was replaced after the request was sent, so the request became invalid. A new request must be sent with the current content.

I changed the review frequency and the document now shows as expired. The change recalculates the next review from the existing approval date. If the new frequency puts that date in the past, the document is expired and must be re-approved.

I deleted a version by mistake. Can it be recovered? No: deletion is permanent. The trace of the operation stays in the audit log, but the file cannot be recovered.

I uploaded an Office document and it doesn't preview. This is expected: Office formats are downloaded, with no on-screen preview, as a privacy decision.

I don't see the module in the menu. Either the company does not have the module enabled, or your user has the "no access" level. Both are resolved by an administrator.