Downloadable Guides
| Guide Name | Description |
|---|---|
| PolicyPro Glossary | This PDF provides definitions for commonly used words related to the PolicyPro application. |
| User Guide | This guide provides information on navigating and managing the PolicyPro application. |
PolicyPro FAQs
Getting Started
What is PolicyPro™?
PolicyPro™ is Exostar’s compliance automation tool. It helps organizations build, maintain, and document security policies across all 14 CMMC domains. Rather than writing policies from scratch, you answer a structured questionnaire, and PolicyPro™ uses those answers to generate complete, audit-ready policy documents.
How do I provide answers to PolicyPro™’s questions?
There are two ways: the chat interface, where you answer questions one at a time with AI-guided prompts on the Policy Screen, or Import, where you upload a CSV or Excel file of answers. You can use either method, or a combination of both, whichever is easiest.
Where can I see my progress across the CMMC domains?
The Main Screen shows a status badge and progress bar for each of the 14 CMMC domains: Completed (all questions answered), In-Progress (some questions answered), or Not Started (no questions answered).
Workspaces
What is a workspace?
A workspace is PolicyPro™’s container for one organization’s questionnaire answers, policies, and users. If you support more than one organization from a single login, you belong to more than one workspace.
How do I switch between workspaces?
Click the workspace switcher pill, which displays your current workspace name, in the header of the My Policies, Policy Screen, or Manage Users screens. A dropdown opens listing every workspace you belong to, along with your role in each. Select a workspace to switch to it immediately; PolicyPro™ reloads for that workspace.
How do I see the full list of workspaces I belong to?
Use “View all workspaces” in the workspace switcher dropdown, or sign in fresh, to return to the Workspace Selector. There you can search by organization name and select any workspace you belong to.
Main and Policy Screens
What does the Main Screen show?
The Main Screen lists all 14 CMMC domains as cards, each showing a completion status badge and progress bar. Clicking a domain’s name opens its Policy Screen.
What is the Policy Screen for?
The Policy Screen is where you work on a single CMMC domain: answer its questions through the chat interface, generate its policy document, and review prior versions of that document.
Answering Questions, Generating Policies, and Version History
Can I get help while I’m answering a question in the chat?
Yes. The chat interface includes a Getting Help option mid-questionnaire so you can get guidance on a question without losing your place.
Do I have to answer every question before I can generate a policy?
No. As of Release 1.3, you can generate a policy document at any completeness level. Previously all questions had to be answered first; now PolicyPro™ generates from however many questions are currently answered, and you can regenerate later as you answer more.
Can I see previous versions of a generated policy document?
Yes. Open the Policy Screen for the domain, then click the version indicator in the policy document panel toolbar to open the version history panel, which lists every previously generated version.
How do I restore a previous version of a policy document?
Open the version history panel, click the version you want to restore, then click Restore this version. PolicyPro™ replaces the current policy document with the selected version.
Export/Import
How do I export my questionnaire answers?
On the Main Screen, click Export to download a CSV file containing all questions across all 14 CMMC domains. You can also export a single domain’s questions from the Export button at the bottom of that domain’s chat panel on the Policy Screen.
How do I import answers from a file?
On the Main Screen, click Import to upload a CSV or Excel file across all domains, or use the Import button on a single domain’s Policy Screen to import just that domain. PolicyPro™ validates the file, then opens the Review Extracted Answers dialog so you can review each proposed change before applying it.
What happens if the file I import conflicts with answers I’ve already entered?
The Review Extracted Answers dialog shows a status for every row: Will Update (the file’s answer differs from what’s stored and will replace it), Will Set (the question is currently unanswered), or No Change (the file matches what’s already stored). You choose which rows to apply before clicking Import.
Which column can I edit in an exported CSV before reimporting it?
Only the Answer column. The Category/Domain, Question, and Valid Response columns must not be edited; PolicyPro™ uses them to match rows back to the correct questions.
Users, Roles, and the Audit Log
Who can invite new users to a workspace?
Only Admins. The Manage Users screen, where invitations are sent, is visible to Admins only.
How many people can I invite at once?
Up to 10 email addresses in a single invitation batch.
What roles are available, and what can each one do?
Admin has full access, including managing users, roles, and the audit log. Editor can answer questionnaires, generate policies, and use Export and Import, but cannot access Manage Users. Viewer has read-only access to domain cards and policy content and can use Export, but not Import.
How long is an invitation link valid?
Seven days by default. If a link expires before the invitee completes account setup, the row shows an Expired status in Manage Users, and an Admin can resend the invitation.
What happens if I remove a user or cancel a pending invitation?
Both actions take effect immediately and require confirmation first. Removing an active user revokes their access right away; re-invitation is required to restore it. Cancelling a pending invitation stops the invitation link from working immediately, and the invitee is not notified.
Is there a record of who had access to a workspace and when?
Yes. The audit log records every invitation sent, accepted, cancelled, or expired, every role change, and every user removal, each with a timestamp, the acting user, and the affected user. Log entries are immutable.