Attestations and policy packages
Some framework requirements cannot be demonstrated by any AWS configuration: a sanction policy, a risk analysis, workforce training. StackTakt covers these with attestation documents: structured documents a named person completes and approves. An approved, unexpired document sets its requirements to Attested on the Compliance page. Attested is deliberately distinct from Demonstrated: a document is a recorded decision by a person, not an observed technical control.
Templates and standard language
Section titled “Templates and standard language”The Documentation Center lists every document a tenant owes, derived from its adopted frameworks. Each template carries prompts, guidance, and standard language: reviewed model clauses citing what they are modeled on (the Security Rule text and NIST SP 800-66 for HIPAA; the AICPA Trust Services Criteria for SOC 2).
Standard language is a starting point, never an answer. Every
organization-specific fact is a {{PLACEHOLDER}} token, and a document
holding an unresolved token cannot be submitted or approved. Nothing
auto-fills: a policy set that reads complete but describes an
organization nobody checked is the failure mode this design exists to
prevent.
The document lifecycle
Section titled “The document lifecycle”- Draft: opening a template creates the document with its starter scaffolding. Complete each section; insert or replace with standard language where it fits, then make it yours.
- Submit for review: refused while any required section is empty or any placeholder remains.
- Approve: a named approver, recorded distinctly from the author, with an optional note. Approval starts the review clock (365 days by default).
- Expired: past its review date, the document stops attesting and its requirements fall back until it is reviewed and approved again.
Editing an approved document reopens it as a draft and withdraws the attestation until it is approved again. Every revision is kept; history is append-only.
Policy packages
Section titled “Policy packages”A consultant completing the same nineteen documents for every client needs reuse without shortcuts. A policy package captures one tenant’s completed documents as an immutable, numbered version at organization scope; applying a version to another tenant creates drafts for that tenant to review and approve.
Two rules keep this honest:
- Approvals never travel. Applying a package always produces drafts. Copying an approval across tenants would put attestations into the record that nobody made.
- Applying is additive by default. A tenant’s own existing text is skipped and named, never silently overwritten; a switch exists to replace deliberately, and replaced documents reopen as drafts.