# Compliance Most document control requirements come down to the same four questions. Who approved this? Which version did they approve? How do you know it was really them? And how do you know it is still current? Capable Approval answers all four inside Confluence, so your controlled documents can live where your team already works, instead of in a separate system nobody opens between audits. ⚠️ **A tool cannot make you compliant.** Certification depends on your processes, your evidence and your auditor. What follows is what Capable contributes, stated plainly, so you can see where it fits and where you still need controls of your own. --- ## The four building blocks | **Requirement** | **What Capable does** | | ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Documented approval** | A named list of reviewers, a required number of approvals, and a recorded decision on the page itself. See [How approvals work](https://help.gocapable.com/approval/how-approvals-work.html). | | **Version control of the approval** | Every approval is tied to one page version. Edit the page and the approval resets, so nothing stays approved after it changes. | | **Attributable signature** | Optional authenticator codes on every response, recorded against that specific answer. See [Sign approvals with a code](https://help.gocapable.com/approval/sign-approvals-with-a-code.html). | | **Periodic review** | [Expiry](https://help.gocapable.com/approval/expiry-and-re-approval.html) brings documents back for re-approval on a schedule, and notifies everyone when they are due. | --- ## ISO 9001 and ISO 27001 Both want controlled documents: approved before use, reviewed and re-approved periodically, with changes and current revision status identified. | **You need** | **Use** | | ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Approval before use | [Automatic approvals](https://help.gocapable.com/approval/automatic-approvals.html) on page creation, so nothing exists unapproved | | Periodic review | Expiry, typically 6 or 12 months | | Current revision identified | [The approval macro](https://help.gocapable.com/approval/the-approval-macro.html) on the page, showing the approved version | | Evidence of all of the above | An export from [Search and reporting](https://help.gocapable.com/approval/search-and-reporting.html) | --- ## SOC 2 Auditors typically want to see that policies were reviewed and approved by the right people, on a defined cadence, with evidence. Approval teams give you the right people consistently, expiry gives you the cadence, and the export gives you the evidence in one file. --- ## FDA 21 CFR Part 11 Part 11 is the strictest of the four, because it governs electronic _signatures_ rather than just approvals. Here is an honest scorecard. | **Part 11 expects** | **Capable** | **Detail** | | ------------------------------------------ | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Signatures linked to their records | YES | Each response is bound to the page and the version. | | Signer identity verified | YES | With authenticator codes required for the space. | | An audit trail that cannot be edited | YES | The history is append only.See [What is recorded](https://help.gocapable.com/approval/what-is-recorded.html). | | Records show the meaning of the signature | YES | Approve, reject or comment, with an optional note. | | Signature manifestation in exported copies | PARTLY | The approval macro carries into PDF and site exports, but the CSV export does not show which responses were signed. | | Administrative actions audited | NO | Not in the approval record. See the gaps below. | --- ## Where you still need your own controls Being straight about the gaps is more useful to you than a page of ticks. * **Administrative changes are not in the approval history.** Turning the code requirement on or off, editing space settings, changing team membership and resetting an authenticator leave no trace in the approval record. If your standard requires that, keep a separate change log. * **The CSV export does not mark signed responses.** The padlock is visible in Confluence but not in the file, so an export on its own does not evidence which approvals were signed. * **There are no backup codes** for authenticators, and clearing one is not logged. Have a documented process for lost devices. * **An approver can change their answer after completion.** The history keeps both, but if your process needs a decision frozen, that has to be a procedural control. * **Approvals can be withdrawn**, and withdrawing does not notify the people who were asked. See [Remove or restart an approval](https://help.gocapable.com/approval/remove-or-restart-an-approval.html). ![image-20260902-094438.png](https://help.gocapable.com/images/0273c57c-574f-4b52-a46f-1b6529a9eac6.webp) ![image-20260902-094502.png](https://help.gocapable.com/images/d46f4b06-c794-4678-8430-35bbd0bc5675.webp) --- ## A configuration that fits most regulated spaces If you want a starting point rather than a menu, set the space up like this. 1 Approve on creation 2 A team per document type 3 Require a code 4 Set the review cycle 5 Show it on the page 6 Watch what is due Turn on [automatic approvals](https://help.gocapable.com/approval/automatic-approvals.html) for page creation or pages with a specific label, so a controlled document cannot exist in the space without a review attached to it. ![image-20260902-093557.png](https://help.gocapable.com/images/ae8bfdf3-f51a-4aff-b5c4-92bfacaecb70.webp) --- ✓ Approve on creation 2 A team per document type 3 Require a code 4 Set the review cycle 5 Show it on the page 6 Watch what is due Create an [approval team](https://help.gocapable.com/approval/teams-and-assignment.html) for each document type, with the quorum your procedure actually requires. This is what stops the reviewer list drifting from your written process. ![image-20260902-093648.png](https://help.gocapable.com/images/605b8d0b-58c1-45b8-bc9d-ef608a9eced4.webp) --- ✓ Approve on creation ✓ A team per document type 3 Require a code 4 Set the review cycle 5 Show it on the page 6 Watch what is due Switch on **require 2FA to approve** for the space, which turns every response into a signed one. ![image-20260902-093731.png](https://help.gocapable.com/images/f8beaf01-3e20-48aa-ac4f-b1f04163a486.webp) --- ✓ Approve on creation ✓ A team per document type ✓ Require a code 4 Set the review cycle 5 Show it on the page 6 Watch what is due Set an expiry matching your review cycle, on the team rather than page by page, so it applies to everything that team signs off. ![Screenshot 2026-09-02 at 10.38.46.png](https://help.gocapable.com/images/e734ec8a-0484-4f13-a504-dbb932d21719.webp) --- ✓ Approve on creation ✓ A team per document type ✓ Require a code ✓ Set the review cycle 5 Show it on the page 6 Watch what is due Put the approval macro in banner view at the top of every controlled document, so anyone opening it sees the current revision status without hunting for it. ![image-20260902-092218.png](https://help.gocapable.com/images/516bc80e-4674-4272-825f-f23fff367a35.webp) ![Screenshot 2026-09-02 at 10.23.52.png](https://help.gocapable.com/images/cbbc681e-2745-4d6c-b2fe-1f36e51fcbd3.webp) --- ✓ Approve on creation ✓ A team per document type ✓ Require a code ✓ Set the review cycle ✓ Show it on the page 6 Watch what is due Save a search of everything expiring next month and review it at your management meeting. That single habit is what turns all of the above into evidence you can hand an auditor. ![Screenshot 2026-09-02 at 10.40.28.png](https://help.gocapable.com/images/ab70f636-e48a-4d08-a00d-4dbbf0b6f793.webp) --- ## Related [What is recordedThe full evidence trail, field by field.](https://help.gocapable.com/approval/what-is-recorded.html) [Sign approvals with a codeAuthenticator codes on every response.](https://help.gocapable.com/approval/sign-approvals-with-a-code.html) [Automatic approvalsNothing exists in the space unapproved.](https://help.gocapable.com/approval/automatic-approvals.html) [Expiry and re-approvalYour periodic review cycle.](https://help.gocapable.com/approval/expiry-and-re-approval.html) [Search and reportingProducing the evidence file.](https://help.gocapable.com/approval/search-and-reporting.html) [Known limitationsWhat we know does not work yet.](https://help.gocapable.com/approval/known-limitations.html) --- _Audit-ready, without a second system to maintain._