> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberopsource.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Documents & Plans

> How client-facing documents, plans, and related artifacts are used in Compliance OS.

# Documents & Plans

Compliance OS can provide a governed place for client-facing security documents and plans that support an engagement or ongoing program.

## Typical content

Depending on your engagement, documents and plans may include:

* policies,
* procedures,
* remediation plans,
* roadmaps,
* governance plans,
* security program documents,
* implementation guidance,
* approved client deliverables.

Not every engagement uses every document workflow.

## Published versus draft material

A document appearing in a client-facing application should be treated as information intentionally made available to the authorized audience. Draft internal Cyber Op Source work does not automatically become client content.

If a document is labeled draft, review, superseded, or withdrawn, follow that status rather than assuming the file is current.

## Reviewing documents

When reviewing:

1. confirm the document title and version,
2. check its status,
3. confirm the intended audience or applicability,
4. review effective dates when present,
5. note whether approval or client action is required.

## Plans and roadmaps

A plan describes intended work. A roadmap helps organize initiatives over time.

Neither should be interpreted as proof that a control has already been implemented. Completion should be supported by actual work status and, where required, evidence.

## Policy assistance

If a policy assistant or document assistant is enabled, it may help locate or explain information from authorized client-visible content.

Use the source document as the final reference when wording matters. AI-generated answers can summarize or navigate content but should not silently replace approved policy language.

## Keeping documents current

If you identify outdated or incorrect client-facing material, notify your Cyber Op Source engagement lead so the appropriate revision, replacement, supersession, or withdrawal process can be followed.
