Compliance

Most document control requirements come down to the same four questions. Who approved this? Which version did they approve? How do you know it was really them? And how do you know it is still current?

Capable Approval answers all four inside Confluence, so your controlled documents can live where your team already works, instead of in a separate system nobody opens between audits.


#The four building blocks

Requirement

What Capable does

Documented approval

A named list of reviewers, a required number of approvals, and a recorded decision on the page itself. See How approvals work.

Version control of the approval

Every approval is tied to one page version. Edit the page and the approval resets, so nothing stays approved after it changes.

Attributable signature

Optional authenticator codes on every response, recorded against that specific answer. See Sign approvals with a code.

Periodic review

Expiry brings documents back for re-approval on a schedule, and notifies everyone when they are due.


#ISO 9001 and ISO 27001

Both want controlled documents: approved before use, reviewed and re-approved periodically, with changes and current revision status identified.

You need

Use

Approval before use

Automatic approvals on page creation, so nothing exists unapproved

Periodic review

Expiry, typically 6 or 12 months

Current revision identified

The approval macro on the page, showing the approved version

Evidence of all of the above

An export from Search and reporting


#SOC 2

Auditors typically want to see that policies were reviewed and approved by the right people, on a defined cadence, with evidence. Approval teams give you the right people consistently, expiry gives you the cadence, and the export gives you the evidence in one file.


#FDA 21 CFR Part 11

Part 11 is the strictest of the four, because it governs electronic signatures rather than just approvals. Here is an honest scorecard.

Part 11 expects

Capable

Detail

Signatures linked to their records

YES

Each response is bound to the page and the version.

Signer identity verified

YES

With authenticator codes required for the space.

An audit trail that cannot be edited

YES

The history is append only.
See What is recorded.

Records show the meaning of the signature

YES

Approve, reject or comment, with an optional note.

Signature manifestation in exported copies

PARTLY

The approval macro carries into PDF and site exports, but the CSV export does not show which responses were signed.

Administrative actions audited

NO

Not in the approval record. See the gaps below.


#Where you still need your own controls

Being straight about the gaps is more useful to you than a page of ticks.

  • Administrative changes are not in the approval history. Turning the code requirement on or off, editing space settings, changing team membership and resetting an authenticator leave no trace in the approval record. If your standard requires that, keep a separate change log.

  • The CSV export does not mark signed responses. The padlock is visible in Confluence but not in the file, so an export on its own does not evidence which approvals were signed.

  • There are no backup codes for authenticators, and clearing one is not logged. Have a documented process for lost devices.

  • An approver can change their answer after completion. The history keeps both, but if your process needs a decision frozen, that has to be a procedural control.

  • Approvals can be withdrawn, and withdrawing does not notify the people who were asked.
    See Remove or restart an approval.

image-20260902-094438.png
image-20260902-094502.png

#A configuration that fits most regulated spaces

If you want a starting point rather than a menu, set the space up like this.

1
Approve on creation
2
A team per document type
3
Require a code
4
Set the review cycle
5
Show it on the page
6
Watch what is due

Turn on automatic approvals for page creation or pages with a specific label, so a controlled document cannot exist in the space without a review attached to it.

image-20260902-093557.png

Approve on creation
2
A team per document type
3
Require a code
4
Set the review cycle
5
Show it on the page
6
Watch what is due

Create an approval team for each document type, with the quorum your procedure actually requires. This is what stops the reviewer list drifting from your written process.

image-20260902-093648.png

Approve on creation
A team per document type
3
Require a code
4
Set the review cycle
5
Show it on the page
6
Watch what is due

Switch on require 2FA to approve for the space, which turns every response into a signed one.

image-20260902-093731.png

Approve on creation
A team per document type
Require a code
4
Set the review cycle
5
Show it on the page
6
Watch what is due

Set an expiry matching your review cycle, on the team rather than page by page, so it applies to everything that team signs off.

Screenshot 2026-09-02 at 10.38.46.png

Approve on creation
A team per document type
Require a code
Set the review cycle
5
Show it on the page
6
Watch what is due

Put the approval macro in banner view at the top of every controlled document, so anyone opening it sees the current revision status without hunting for it.

image-20260902-092218.png
Screenshot 2026-09-02 at 10.23.52.png

Approve on creation
A team per document type
Require a code
Set the review cycle
Show it on the page
6
Watch what is due

Save a search of everything expiring next month and review it at your management meeting. That single habit is what turns all of the above into evidence you can hand an auditor.

Screenshot 2026-09-02 at 10.40.28.png


Audit-ready, without a second system to maintain.