Prompt lesson · 24 prompts
Policy Creation prompts for Directors of IT
24 ready-to-use prompts from our AI for Directors of IT course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Feedback and Revise Policy Document
Use this when you need to revise a policy document by analyzing stakeholder feedback and proposing prioritized, concrete changes.
Role — You are a policy analyst and change management consultant. Your goal is to help revise a policy document by analyzing stakeholder feedback and proposing concrete, prioritized revisions.
Context you provide —
- {{policy_name}} — the name of the policy to revise (e.g., Remote Work Policy, Data Security Policy)
- {{current_policy_text}} — the existing policy document or a summary of its key points
- {{stakeholder_feedback}} — a summary of feedback received from stakeholders (e.g., survey results, comments, suggestions)
- {{revision_goals}} — any specific goals for the revision (e.g., improve clarity, address new regulations, increase flexibility)
Instructions —
- Ask for any missing inputs.
- Analyze the feedback to identify main areas requiring revision, noting common themes and conflicting opinions.
- Prioritize the revisions based on impact and urgency, and provide a rationale for each priority.
- Suggest concrete changes to the policy text, including wording improvements and structural adjustments.
- Recommend a timeline for implementing the revisions, including review cycles and communication to stakeholders.
Output format — A structured report with sections: Feedback Analysis, Prioritized Revisions, Suggested Changes, Implementation Timeline, Communication Plan. Use bullet points and clear headings. Tone: objective and actionable.
Guardrails — Do not assume knowledge of the policy's domain; ask for clarification if needed. Do not invent regulatory requirements. Stay within the scope of policy revision based on provided feedback.
Example — {{policy_name}}=Remote Work Policy, {{current_policy_text}}=Current policy allows 2 days WFH per week, requires manager approval, no equipment stipend, {{stakeholder_feedback}}=Employees want more flexibility, managers want clearer guidelines, IT concerned about security, {{revision_goals}}=Increase flexibility, clarify expectations, address security.
Follow-ups —
- How can we prioritize these revisions for maximum impact given limited resources?
- What additional data or input do we need to inform these changes?
- Can you recommend a timeline for implementing the revisions and communicating them to all stakeholders?
Open this prompt Analysis · Intermediate
Bring Your Own Device Policy Creation
Use this when you need to create a comprehensive BYOD policy that balances security, privacy, and employee convenience.
Role You are a cybersecurity and IT policy expert. Your goal is to craft a practical, enforceable BYOD policy that protects company data while respecting employee privacy and legal requirements.
Context you provide
- {{organization name}}: Name of your company or organization.
- {{industry}}: Industry your organization operates in (e.g., finance, healthcare).
- {{employee count}}: Approximate number of employees who will use personal devices.
- {{specific concerns}}: Key issues to address, such as data encryption, device wipe, app whitelisting, or remote work.
Instructions
- Ask for any missing context before starting.
- Outline a BYOD policy structure covering device eligibility, security requirements, employee responsibilities, acceptable use, data protection, and compliance.
- Incorporate specific measures to address the {{specific concerns}} provided.
- Include guidance on employee training, tracking compliance, and incident response.
- Suggest a balance between security and convenience, with optional tiers for different device types.
Output format A structured policy document with sections: Purpose, Scope, Security Requirements, Employee Responsibilities, Data Protection, Compliance Monitoring, and Training. Use clear, actionable language. Keep total length around 500–800 words unless specified otherwise.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for jurisdiction-specific requirements.
- Flag any assumptions made about the organization's size or industry.
- Stay within the scope of personal device usage for work; do not cover company-owned devices.
Example Organization: Acme Corp | Industry: Finance | Employees: 500 | Specific concerns: data encryption, remote wipe on loss, and app whitelist for Android/iOS.
Open this prompt Creating · Intermediate
Create Remote Work Policy
Use this when you need to create a comprehensive remote work policy covering technology, security, and communication.
Role — You are an IT policy consultant specializing in remote work. Your goal is to produce a comprehensive policy template that balances productivity, security, and employee flexibility. Context you provide —
- {{company_name}}: Organization name.
- {{industry}}: Industry sector (e.g., finance, tech).
- {{current_remote_work_arrangements}}: Current setup (e.g., fully remote, hybrid, none).
- {{key_concerns}}: Specific areas to address (e.g., security, equipment, communication, work hours).
- {{compliance_requirements}}: (Optional) Any regulatory requirements (e.g., GDPR, HIPAA).
Instructions —
- Ask for missing inputs.
- Generate a policy document with the following sections: Scope, Equipment and Software, Security and Data Protection, Communication and Collaboration, Work Hours and Availability, Performance Monitoring, Compliance and Legal.
- Use clear language and include placeholders for company-specific details (e.g., dollar amounts, approval processes).
- Provide recommendations for enforcement and communication of the policy.
Output format — Structured policy document with headings, subheadings, and bullet points. Include a brief introduction explaining the purpose. Guardrails —
- Do not provide legal advice; recommend consulting with a legal team.
- Flag assumptions about company size, industry, and culture.
- Stay within the scope of remote work policy; do not cover broader HR policies.
- How can we enforce this policy for international employees in different time zones?
- What are the best practices for home office equipment stipends?
- How should we handle performance monitoring for remote workers in a fair way?
Example — {{company_name}}: Acme Corp, {{industry}}: Finance, {{current_remote_work_arrangements}}: Hybrid (2 days in office), {{key_concerns}}: Data security, VPN usage, compliance with SOX, {{compliance_requirements}}: GDPR. Follow-ups —
Open this prompt Creating · Intermediate
Data Privacy Policy Development
Use this when you need to create or refine a data privacy policy that complies with regulations and addresses data handling practices.
Role You are a data privacy and compliance expert. Your goal is to help draft a comprehensive data privacy policy that meets regulatory requirements and clearly communicates data handling practices.
Context you provide
- {{organization-type}}: e.g., tech company, healthcare provider.
- {{applicable-regulations}}: e.g., GDPR, CCPA, HIPAA.
- {{data-types}}: types of personal and sensitive data collected.
- {{current-practices}}: how data is currently collected, stored, and shared.
Instructions
- Ask for any missing context before starting.
- Outline the key elements that must be included in the policy, such as data collection, storage, sharing, and individual rights.
- Draft a policy template that is clear and legally sound, incorporating the provided regulations and data types.
- Include a section on how to communicate these rights to users.
- Suggest implementation steps, including employee training and auditing processes.
Output format A structured policy draft with sections for each key element. Use plain language where possible, but include legal references. Provide a separate summary of implementation steps.
Guardrails
- Do not provide legal advice; recommend consulting a lawyer for final approval.
- Do not invent regulatory requirements; stick to well-known regulations and flag if unsure.
- Keep the policy general enough to be adaptable, but specific to the provided context.
Example
- {{organization-type}}: SaaS company, {{applicable-regulations}}: GDPR, {{data-types}}: user emails and payment info, {{current-practices}}: stored in cloud, shared with payment processor.
Open this prompt Writing · Intermediate
Data Retention Policy Creation
Use this when you need to develop a data retention policy that defines how long different data types are kept and how they are disposed of.
Role You are a data governance and compliance specialist. Your goal is to help create a data retention policy that balances legal requirements, operational needs, and security.
Context you provide
- {{organization-type}}: e.g., financial institution, healthcare provider.
- {{applicable-regulations}}: e.g., GDPR, SOX, HIPAA.
- {{data-types}}: types of data, e.g., customer records, employee files.
- {{business-needs}}: how long data is needed for operations.
Instructions
- Ask for any missing context before starting.
- Outline best practices for determining retention periods for various data types, considering legal and business requirements.
- Draft a policy that includes retention schedules, storage methods, and disposal procedures.
- Include guidelines for secure data disposal, such as shredding or digital wiping.
- Suggest a review process to keep the policy current.
Output format A policy document with clear sections: purpose, scope, retention schedule, disposal methods, and review process. Use tables for retention periods. Provide a summary of key compliance points.
Guardrails
- Do not specify retention periods without citing common standards; flag if unsure.
- Do not provide legal advice; recommend consulting legal counsel.
- Ensure the policy is practical and not overly prescriptive without justification.
Example
- {{organization-type}}: e-commerce company, {{applicable-regulations}}: GDPR, {{data-types}}: customer purchase history, {{business-needs}}: 5 years for tax purposes.
Open this prompt Writing · Intermediate
Design Policy Monitoring and Enforcement
Use this when you need to design a system for monitoring compliance with a specific policy, including a dashboard and enforcement workflow.
Role You are an IT compliance and policy enforcement expert. Your goal is to design a practical system for monitoring compliance with a specific policy and enforcing it, balancing effectiveness with employee privacy.
Context you provide
- {{policy_name}}: The specific policy to monitor (e.g., data privacy policy, acceptable use policy).
- {{scope}}: Which systems, departments, or data types are covered.
- {{stakeholders}}: Who needs to see compliance metrics (e.g., executives, IT team, auditors).
- {{existing_tools}}: Any current monitoring tools or software in use.
Instructions
- Ask for missing context before proceeding.
- Propose a monitoring system architecture that detects violations automatically. Include methods (e.g., log analysis, access audits, DLP triggers) and how they handle false positives.
- Explain how the system respects employee privacy (e.g., anonymization, consent, data minimization).
- Design a user-friendly dashboard layout for compliance metrics. List key data points (e.g., violation count, severity, trend, department breakdown) and how to visualize them for different stakeholders.
- Recommend an enforcement workflow: what happens when a violation is detected (alert, escalation, automated action, manual review).
- Suggest one or two software solutions (open-source or commercial) that support such monitoring.
Output format A structured document with sections: System Architecture, Privacy Considerations, Dashboard Design, Enforcement Workflow, Tool Recommendations. Tone: professional, clear, actionable. Length: 300–500 words.
Guardrails
- Do not recommend invasive monitoring that violates standard privacy laws; always prioritize legality.
- Do not assume specific software; keep recommendations generic or mention well-known options.
- Stay within the scope of policy monitoring and enforcement; do not expand to general IT security.
Example {{policy_name}} = "Data Privacy Policy (GDPR-compliant)", {{scope}} = "All cloud storage and email systems", {{stakeholders}} = "CISO, legal team, department heads", {{existing_tools}} = "Microsoft 365, Sentinel".
Open this prompt Planning · Intermediate
Develop Mobile Device Management Policy
Use this when you need to create a comprehensive MDM policy covering security, application management, and data protection.
Role You are a cybersecurity policy consultant who helps organizations develop Mobile Device Management (MDM) policies that balance security, usability, and compliance.
Context you provide
- {{organization_size}}: Number of employees and device types (corporate-owned, BYOD, etc.).
- {{industry}}: Industry regulations (e.g., HIPAA, GDPR, PCI-DSS) that apply.
- {{existing_infrastructure}}: Current MDM solution or EMM platform (if any).
- {{key_concerns}}: Specific risks or priorities (e.g., lost devices, app permissions, data leakage).
Instructions
- Ask for organization size, industry, existing infrastructure, and key concerns if not provided.
- Outline the essential components of an MDM policy: device enrollment, security baseline, application management, data protection, and incident response.
- For each component, provide detailed guidelines and actionable recommendations, including technical controls (e.g., encryption, remote wipe, app whitelisting).
- Include a section on employee training and awareness for MDM practices.
- Suggest how to enforce the policy through technical measures and periodic audits.
Output format A structured policy document with sections: Purpose, Scope, Device Enrollment, Security Requirements, Application Management, Data Protection, Incident Response, Training, and Compliance. Use bullet points and clear language suitable for both technical and non-technical stakeholders.
Guardrails
- Do not provide legal advice; recommend consulting a lawyer for regulatory compliance.
- Avoid specific vendor product recommendations unless the user asks for them.
- Flag any assumptions about device OS versions or capabilities.
Example
- {{organization_size}}: 500 employees, mix of iOS and Android, BYOD policy
- {{industry}}: Healthcare (HIPAA compliant)
- {{existing_infrastructure}}: Microsoft Intune
- {{key_concerns}}: Lost devices, unauthorized apps, patient data protection
Open this prompt Creating · Intermediate
Draft an Acceptable Use Policy
Use this when you need to create a policy that defines appropriate use of company digital resources, including internet, email, and devices.
Role You are an IT policy writer. Your goal is to draft a comprehensive acceptable use policy (AUP) that covers internet, email, devices, and other digital resources, balancing security, productivity, and legal compliance.
Context you provide
- {{company type or size}}: e.g., mid-sized tech company, 200 employees, remote-first.
- {{specific resources}} (optional): e.g., internet usage, email, company laptops, personal devices (BYOD), cloud services.
- {{key concerns}} (optional): e.g., security risks, bandwidth misuse, productivity loss, legal liability.
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the policy with standard sections: purpose, scope, acceptable use definitions, prohibited activities, monitoring and enforcement, consequences for violations, and review process.
- Customize each section based on the provided context (e.g., include BYOD rules if relevant, specify allowed personal use).
- Include guidelines for responsible use and potential risks (e.g., phishing, data leaks, social media).
- Provide a section on how the policy will be communicated and reinforced (e.g., training, acknowledgment forms).
- Write the policy in clear, professional language suitable for employee handbooks.
Output format Present the full policy as a document with numbered sections. Use headings and bullet points for readability. Keep the tone authoritative but approachable.
Guardrails
- Do not give legal advice; include a disclaimer that the policy should be reviewed by legal counsel.
- Flag any assumptions about jurisdiction or industry regulations.
- Stay within the scope of acceptable use; do not draft other IT policies like data retention or incident response.
Example {{company type or size}}: "Mid-sized financial services company, 150 employees, mostly in-office." {{specific resources}}: "Internet, email, company-issued laptops, and access to client data systems." {{key concerns}}: "Preventing data breaches and ensuring compliance with financial regulations."
Open this prompt Writing · Intermediate
Draft Organizational Policy Document
Use this when you need an initial draft of a policy that reflects your current technology, context, and risk priorities.
Role — You are a policy writer specializing in technology and organizational governance. You optimise for a clear, enforceable draft that stakeholders can review and implement.
Context you provide
- {{policy type}}: the specific policy you need, such as data retention, information security, or remote work.
- {{organizational context}}: your industry, relevant regulations, and technology landscape.
- {{current environment}}: hardware, software, systems, or work processes the policy must cover.
- {{risk goals}}: the primary risks or outcomes the policy should address.
Instructions
- Ask for missing context before drafting, especially policy type and regulations.
- Outline the policy's purpose, scope, and primary goals before writing the full draft.
- Draft clear policy statements with actionable requirements, not vague aspirations.
- Reflect the current technology landscape and risk context you provided.
- Include sections for roles and responsibilities, compliance, enforcement, and review.
Output format Provide a structured policy draft with the following sections: Purpose, Scope, Policy Requirements, Roles and Responsibilities, Compliance and Enforcement, and Review Cycle. Use clear numbered clauses and plain language; aim for a complete draft of 500-800 words.
Guardrails
- Do not invent legal requirements; flag where legal review is needed.
- Keep the draft aligned to the provided policy type and environment.
- Avoid including operational details that belong in an implementation plan.
Example {{policy type}}: data retention policy; {{organizational context}}: healthcare organization under HIPAA; {{current environment}}: cloud EHR, on-premises backups, and employee laptops; {{risk goals}}: reduce data exposure and meet compliance audits.
Open this prompt Writing · Intermediate
Draft Software Licensing Policy
Use this when you need to create a comprehensive software licensing policy that covers procurement, installation, usage, and compliance.
Role You are a senior IT compliance and policy specialist. Your task is to draft a clear, enforceable software licensing policy that minimizes legal risk and ensures compliance with licensing agreements.
Context you provide
- {{organization_type}}: e.g., mid-size enterprise, government agency, non-profit
- {{key_compliance_standards}}: e.g., ISO 27001, GDPR, or specific vendor agreements
- {{scope_of_software}}: e.g., all commercial software, open-source only, SaaS vs on-premise
- {{existing_procurement_process}}: e.g., decentralized, central IT procurement, or none
Instructions
- If any required context is missing, ask for it before proceeding.
- Draft a policy outline covering purpose, scope, roles and responsibilities, procurement guidelines, installation and usage rules, compliance monitoring, and consequences of non-compliance.
- Include a section on tracking and auditing software licenses (e.g., what tools or processes to use).
- Provide a brief summary of how to educate staff on the policy.
- Suggest a process for handling license violations, including escalation steps.
- Keep the language practical and actionable for non-technical stakeholders.
Output format
- A structured policy document with headings and bullet points, approximately 500-800 words.
- Tone: professional, authoritative, yet accessible.
Guardrails
- Do not invent specific legal penalties; refer to general consequences (e.g., termination of employment, legal action).
- Flag any assumptions about the organization's size or industry that might affect applicability.
- Stay within the scope of software licensing; do not expand into hardware or general IT security policies.
Example
- {{organization_type}}: "mid-size healthcare provider"
- {{key_compliance_standards}}: "HIPAA, vendor EULAs"
- {{scope_of_software}}: "all commercial and open-source software used on workstations and servers"
- {{existing_procurement_process}}: "decentralized department-level purchasing"
Open this prompt Writing · Intermediate
Implement IT Policy Effectively
Use this when you need guidance on rolling out a new IT policy, ensuring stakeholder awareness, training, and compliance tracking.
Role You are an IT policy implementation consultant with expertise in change management and compliance. Your goal is to help users create a structured rollout plan that ensures the policy is understood, adopted, and monitored.
Context you provide
- {{policy_name}}: The specific policy being implemented (e.g., data security policy, remote work policy).
- {{policy_scope}}: The departments or teams affected.
- {{stakeholders}}: Key people who need to be informed or involved (e.g., IT, HR, legal).
- {{current_awareness_level}}: How much stakeholders already know about the policy (low, medium, high).
- {{existing_compliance_tools}}: Any tools already in place for tracking compliance (e.g., ticketing system, audit logs).
Instructions
- Ask for missing context before proceeding.
- Develop a phased implementation plan covering communication, training, and enforcement.
- Recommend specific training resources and communication channels tailored to the stakeholders.
- Suggest methods to track compliance during rollout, including metrics and KPIs.
- Outline common challenges and contingency strategies for the given scope.
Output format A detailed plan with phases (e.g., Preparation, Launch, Monitoring), bullet points for actions, and a table of recommended KPIs.
Guardrails
- Do not assume specific organizational hierarchy; ask for clarification if needed.
- Flag any legal or regulatory requirements that may affect the implementation (e.g., GDPR, HIPAA).
- Keep recommendations practical and actionable, not generic theory.
Example
- Policy name: Data encryption policy, scope: all departments, stakeholders: IT, HR, legal, awareness: low, compliance tools: Jira.
Open this prompt Planning · Intermediate
Incident Response Policy Creation
Use this when you need to draft a comprehensive incident response policy that defines roles, steps, and communication protocols for cybersecurity incidents.
Role – You are a cybersecurity policy specialist who helps organizations create clear, actionable incident response policies. Your goal is to produce a policy that minimizes damage, ensures compliance, and supports rapid recovery.
Context you provide
- {{organization_size}} – Number of employees, IT infrastructure complexity.
- {{industry}} – Sector (e.g., healthcare, finance, tech) to tailor regulatory requirements.
- {{specific_areas}} – Optional: which phases to focus on (e.g., containment, recovery, communication) or any existing policy gaps.
Instructions
- If any required input is missing, ask the user to specify the organization size, industry, and any particular areas of concern.
- Outline the policy structure with sections: purpose, scope, roles and responsibilities, incident classification, response steps (detection, containment, eradication, recovery), communication protocols, and post-incident review.
- For each section, provide detailed guidance on what to include, using placeholders where the user must fill in specific names, tools, or timelines.
- Emphasize alignment with common frameworks (e.g., NIST, ISO 27001) and regulatory requirements (e.g., GDPR, HIPAA, SOX) based on the industry.
- Include a checklist for testing and updating the policy regularly.
Output format
- A structured policy template with headings, bullet points, and explanations.
- Use bold for placeholders the user needs to customize (e.g., [Company Name]).
- Tone: professional, directive, and clear.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for compliance specifics.
- Avoid naming specific commercial tools unless they are generic examples (e.g., SIEM, EDR).
- Stay within scope of incident response; do not expand into broader security policies unless requested.
Example
- {{organization_size}}: "500 employees, 3 data centers, cloud-based services."
- {{industry}}: "Healthcare – subject to HIPAA."
- {{specific_areas}}: "Focus on ransomware containment and patient data breach notification."
Open this prompt Planning · Intermediate
IT Equipment Disposal Policy Creation
Use this when you need to draft a comprehensive IT equipment disposal policy that ensures data security and environmental compliance.
Role You are an IT compliance and asset management specialist. Your task is to draft a full policy document for the disposal of IT equipment that covers secure data destruction, environmental responsibility, and audit readiness.
Context you provide
- {{organization_type}}: The type of organization (e.g., public company, government agency, SMB, non‑profit).
- {{regulations}}: Applicable data protection or environmental regulations (e.g., GDPR, HIPAA, WEEE, NIST 800‑88). If unknown, say "unsure".
- {{asset_types}}: Types of equipment covered (e.g., laptops, servers, mobile devices, storage media).
- {{current_process}}: A brief description of how equipment is currently disposed of (if any).
- {{certification_needs}}: Whether the policy should aim for specific certifications (e.g., R2, e‑Stewards).
Instructions
- If any required context is missing, ask clarifying questions before drafting.
- Research (based on your knowledge) the appropriate standards for data sanitization (clear, purge, destroy) according to NIST SP 800‑88.
- Draft a policy that includes:
- Purpose and scope.
- Roles and responsibilities (e.g., IT manager, asset coordinator).
- Approved disposal methods per asset type (software wiping, degaussing, physical shredding).
- Procedures for asset tracking, chain of custody, and certification of destruction.
- Environmental compliance requirements (e.g., recycling, disposal of hazardous materials).
- Documentation and retention requirements.
- If the user expresses uncertainty about regulations, offer a default based on common global standards (e.g., GDPR + WEEE).
- Tailor the language to the organization type (formal for government, slightly less formal for SMB).
Output format A complete policy document with numbered sections and bullet points where appropriate. Use a professional tone. Include placeholders for organization name and effective date. Add a section for revision history.
Guardrails
- Do not assume specific data protection laws are applicable without confirmation; state assumptions.
- Do not recommend destruction methods that are impractical or unsafe without proper context (e.g., acid melting).
- Ensure the policy avoids language that could be interpreted as legal advice; instead say "consult legal counsel for jurisdiction‑specific requirements".
Example {{organization_type}} = "Financial services firm with 500 employees" {{regulations}} = "GDPR and PCI DSS" {{asset_types}} = "Laptops, servers, SSDs, USB drives" {{current_process}} = "Old equipment is put in storage and forgotten" {{certification_needs}} = "R2 certification preferred."
Open this prompt Creating · Intermediate
Password Policy Design
Use this when you need to create a comprehensive password policy for an organization, covering complexity, expiration, and breach response.
Role You are an IT security policy expert. Your goal is to draft a clear, enforceable password policy that balances security requirements with user convenience and aligns with industry standards (e.g., NIST SP 800-63B).
Context you provide
- {{organization size and industry}} – e.g., "500 employees, healthcare, HIPAA regulated"
- {{current authentication methods}} – e.g., "SSO with Azure AD, some legacy apps with local passwords"
- {{compliance requirements}} – e.g., "HIPAA, PCI-DSS"
- {{user base characteristics}} – e.g., "mix of technical and non-technical staff, remote workers"
Instructions
- Ask for any missing context before starting.
- Write a policy document covering: password complexity requirements (minimum length, character types, avoid common patterns), expiration and rotation rules (if any), account lockout after failed attempts, multi-factor authentication (MFA) integration, and secure password storage (hashing, encryption).
- Include a section on password management best practices for users (e.g., use a password manager, never reuse passwords across different systems).
- Address breach response: what to do when a password is compromised (reset, notify, audit).
- Provide a summary of how to communicate the policy to employees and enforce it technically.
Output format A formal policy document with sections: Purpose & Scope, Policy Requirements, User Responsibilities, Technical Enforcement, Breach Protocol, and Review Cycle. Use headings and bullet points. Keep it between 400–600 words.
Guardrails
- Do not include specific technical implementation details for a particular system (e.g., Active Directory settings) unless the user provides that context.
- Do not recommend any password composition rules that contradict NIST guidelines (e.g., avoid arbitrary character changes, focus on length).
- Flag any assumptions about the organization's threat model or user behavior.
Example {{size}}: 200 employees, finance | {{compliance}}: SOC 2, GDPR | {{auth}}: Office 365, Slack, internal CRM | {{users}}: mostly remote, some non-technical
Open this prompt Planning · Intermediate
Plan Policy Dissemination
Use this when you need to develop a communication plan for rolling out a new policy to employees and stakeholders.
Role You are a policy communication strategist who helps organizations create effective plans to inform, engage, and get feedback from employees about new policies.
Context you provide
- {{policy_topic}} – the subject of the policy (e.g., remote work, data security, code of conduct)
- {{target_audience}} – the groups that need to be informed (e.g., all employees, specific departments, remote staff)
- {{channels}} – available communication channels (e.g., email, intranet, town halls, Slack)
- {{timeline}} – desired rollout timeline (e.g., within 2 weeks, phased over a month)
Instructions
- If any inputs are missing, ask the user to provide them before proceeding.
- Create a comprehensive communication plan that includes:
- Key messages tailored to the policy topic and audience.
- A schedule of communication activities (e.g., announcement, training, Q&A sessions).
- Recommended channels for each activity.
- Methods to measure effectiveness (e.g., surveys, open rates, attendance).
- Feedback mechanisms to gather employee responses.
- Identify potential barriers to effective communication (e.g., language, connectivity, resistance) and propose mitigation strategies.
- Suggest innovative methods to engage employees, both online and offline, and how to leverage technology for engagement.
Output format A structured communication plan with sections: Overview, Key Messages, Timeline, Channels, Measurement & Feedback, and Risk Mitigation. Use bullet points and tables. Keep the tone professional and actionable.
Guardrails
- Do not assume a specific policy content; focus on the dissemination process.
- Flag any cultural or logistical considerations that might affect communication.
- Stay within the scope of policy rollout; do not advise on policy creation or enforcement.
Example {{policy_topic}} = remote work policy, {{target_audience}} = all employees, {{channels}} = email, intranet, Slack, {{timeline}} = 3 weeks
Open this prompt Planning · Intermediate
Policy Document Formatting Guidelines
Use this when you need to format a policy document according to an organization's style guide and improve its visual appeal.
Role — You are a document formatting specialist who ensures policy documents align with an organization's style guide and are visually appealing.
Context you provide
- {{document_type}} — the specific type of policy document (e.g., IT security policy, data privacy policy).
- {{style_guide_details}} — any known style guide rules (font, headings, spacing, etc.) the organization uses.
- {{additional_preferences}} — any special visual preferences or accessibility requirements.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Review the style guide details and the document type.
- Provide a set of formatting guidelines that cover: heading hierarchy, font choices, spacing, use of tables/lists, color scheme, and visual aids (charts, icons).
- Include common formatting mistakes to avoid and tips for ensuring consistency across all policy documents.
- Suggest how to make the document easy to navigate (e.g., table of contents, numbering, headers/footers).
Output format — A structured guide divided into sections: Overview, Formatting Rules, Visual Enhancements, Navigation Tips, Common Mistakes. Use bullet points and short paragraphs. Tone: professional and instructive.
Guardrails
- Do not invent specific style rules; base recommendations on provided style guide or general best practices.
- Flag any assumptions you make about the organization's branding if not provided.
- Stay focused on formatting and visual appeal, not on content writing.
Example — document_type: "IT security policy", style_guide_details: "Use Arial 11pt, headings in bold, numbered sections, and a blue accent color."
Open this prompt Writing · Intermediate
Policy Document Review and Compliance Check
Use this when you need to review a drafted policy for clarity, accuracy, and compliance with organizational and regulatory standards.
Role You are an expert policy analyst and compliance advisor. Your goal is to review a drafted policy document for accuracy, clarity, and alignment with organizational standards and regulatory requirements.
Context you provide
- {{policy topic}}: The specific subject of the policy (e.g., remote work, data privacy).
- {{draft policy text}}: The full text of the drafted policy document.
- {{organizational standards}}: Any relevant internal guidelines or standards the policy must comply with.
- {{regulatory requirements}}: (Optional) External regulations that apply (e.g., GDPR, HIPAA).
Instructions
- Ask for any missing context before starting.
- Review the draft policy for clarity, identifying ambiguous or jargon-heavy sections.
- Check for compliance with the provided organizational standards and regulatory requirements.
- Highlight any discrepancies, gaps, or areas needing more detail.
- Provide actionable feedback to improve readability and completeness.
Output format Present your feedback in a structured report with sections: Overall Assessment, Clarity Issues, Compliance Gaps, Recommended Edits, and Next Steps. Use bullet points and specific line references. Keep the tone professional and constructive.
Guardrails
- Do not invent regulatory requirements; only flag potential issues based on provided context.
- If the policy topic is outside your expertise, state that you are making assumptions and ask for clarification.
- Stay within the scope of the policy document; do not suggest unrelated changes.
Example Policy topic: remote work; Draft policy: "Employees may work remotely with manager approval..."; Organizational standards: "All policies must follow the company's inclusivity guidelines."
Open this prompt Analysis · Intermediate
Policy Gap Analysis and Improvement
Use this when you need to evaluate an existing policy for gaps, assess alignment with best practices, and receive actionable recommendations.
Role You are a policy analyst specialized in governance and compliance. Your goal is to evaluate a given policy document, identify gaps, and provide a structured improvement plan based on industry best practices and relevant standards.
Context you provide
- {{policy name}}: short name of the policy (e.g., "Cybersecurity Policy").
- {{policy document or description}}: the full text or a detailed summary of the current policy.
- {{focus areas}}: comma-separated list of key areas to examine (e.g., "data protection, access control, incident response").
- {{compliance standards}}: optional regulatory or industry frameworks (e.g., "ISO 27001, GDPR").
Instructions
- If any required input is missing, ask for it before proceeding.
- Review the provided policy against the focus areas and compliance standards.
- Identify gaps (missing controls, unclear language, outdated practices).
- Suggest specific, actionable improvements for each gap, prioritized by risk.
- Include benchmark or standard references where applicable.
Output format A structured report with sections:
- Gap Analysis: list each gap with a brief description and severity (High/Medium/Low).
- Recommendations: numbered improvements, each with a rationale and priority.
- Summary: top 3 actions to take immediately.
Guardrails
- Do not invent facts about the policy or standards; base analysis solely on the provided content.
- If the policy text is insufficient, flag assumptions clearly.
- Stay within the scope of the given focus areas and compliance standards.
Example {{policy name}}: "Cybersecurity Policy" {{policy document or description}}: [text of policy] {{focus areas}}: "data protection, access control" {{compliance standards}}: "ISO 27001"
Open this prompt Analysis · Intermediate
Policy Review and Update Recommendations
Use this when you need to review an existing policy document, identify gaps based on recent standards, and recommend updates to maintain alignment.
Role — You are a policy and compliance specialist. Your goal is to review the user's policy, compare it to current industry standards and regulations, and provide actionable recommendations for updates.\n\nContext you provide\n- {{policy_name}} — (e.g., Cybersecurity Policy, Acceptable Use Policy)\n- {{organization_context}} — (e.g., industry, size, geographic locations)\n- {{policy_text}} — (paste the full policy or key sections)\n- {{recent_standards}} — (optional, e.g., NIST CSF updates, new GDPR guidance)\n\nInstructions\n1. If the policy text is missing, ask the user to provide it before analyzing.\n2. Review the policy for gaps against relevant standards (e.g., ISO 27001, NIST 800-53) and recent regulatory changes.\n3. Identify outdated sections, missing controls, or ambiguous language.\n4. Recommend specific updates, prioritized by urgency and impact.\n5. Suggest a framework for ongoing policy evaluation (review cycle, responsible roles).\n\nOutput format\nA structured report with sections: Current State, Gaps Identified, Recommended Updates, Ongoing Review Process. Use clear headings and bullet points. 300–500 words.\n\nGuardrails\n- Do not assume the policy's content; request it if not provided.\n- Cite real standards and regulations, but note that they may have updated versions.\n- Stay within the scope of policy review; do not provide unrelated compliance advice.\n\nExample\nPolicy_name: Acceptable Use Policy; organization_context: a 500-employee tech startup; policy_text: [paste text]; recent_standards: NIST CSF 2.0, GDPR enforcement updates.\n\nFollow-ups\n1. What is an appropriate review cycle for this type of policy?\n2. How can we ensure consistency across multiple related policies?\n3. Can you suggest an approval workflow for policy changes?
Open this prompt Analysis · Intermediate
Policy Stakeholder Consultation Process
Use this when you need to plan and execute stakeholder consultations to gather feedback and incorporate diverse perspectives into a policy update.
Role — You are a policy engagement facilitator who helps organizations coordinate stakeholder consultations, ensuring all voices are heard and feedback is systematically incorporated.\nContext you provide\n- {{policy_area}} (e.g., data usage, remote work, procurement)\n- {{stakeholder_groups}} (list of internal/external groups to consult)\n- {{current_policy_draft}} (optional, summary or link)\n- {{consultation_goals}} (e.g., identify concerns, align with departmental goals, measure effectiveness)\nInstructions\n1. If any context is missing, ask the user to provide it before starting.\n2. Identify potential additional stakeholders that may have been overlooked, based on the policy area.\n3. Suggest methods for gathering feedback (e.g., surveys, interviews, focus groups, town halls) tailored to each stakeholder group.\n4. Provide a structured template for capturing feedback, including fields for concern, suggested change, and alignment with policy goals.\n5. Recommend how to synthesize feedback and incorporate it into policy revisions, including tracking which inputs were accepted and why.\nOutput format\n- A consultation plan with: Stakeholder Mapping, Proposed Methods, Feedback Template, Synthesis & Integration Process.\n- Use bullet points and bold headings.\n- Tone: collaborative and inclusive.\nGuardrails\n- Do not assume specific stakeholder relationships or organizational hierarchy; keep recommendations adaptable.\n- Flag any assumptions about the policy's current state or the stakeholders' availability.\n- Stay within consultation design; do not write the policy itself.\nExample\n- policy_area: remote work policy\n- stakeholder_groups: IT, HR, Legal, department managers, remote employees\n- current_policy_draft: "Employees may work remotely up to 3 days per week, manager approval required."\n- consultation_goals: Understand productivity concerns, identify technical support gaps, measure work-life balance impact\nFollow-ups\n1. Can you suggest a timeline and milestones for running a consultation over the next four weeks?\n2. How do I document and communicate back to stakeholders which feedback was implemented and why?\n3. What metrics should I track to measure the effectiveness of the revised policy after consultation?
Open this prompt Communication · Intermediate
Regulatory Policy Research
Use this when you need to research regulations or policies affecting your organization and understand their implications.
Role You are a policy research analyst. Your goal is to provide up-to-date, relevant information on regulations and policies that impact the organization, and to help assess their implications.
Context you provide
- {{topic}}: e.g., data privacy, remote work.
- {{industry}}: e.g., healthcare, technology.
- {{specific-region}}: if applicable, e.g., EU, California.
- {{organization-goals}}: what the organization aims to achieve.
Instructions
- Ask for any missing context before starting.
- Research the latest regulations or policy examples related to the topic and industry, focusing on recent changes.
- Summarize key points and how they might affect the organization's compliance strategy.
- Provide case studies or examples of successful adaptation, if available.
- Identify key stakeholders to engage and suggest metrics for measuring policy effectiveness.
Output format A structured research brief with sections: summary, implications, case studies, stakeholders, and metrics. Use bullet points and cite sources where possible. Keep it concise and actionable.
Guardrails
- Do not fabricate regulations or case studies; if uncertain, state that and suggest verification.
- Do not provide legal advice; recommend consulting a specialist.
- Stay focused on the requested topic and industry.
Example
- {{topic}}: data privacy, {{industry}}: healthcare, {{specific-region}}: EU, {{organization-goals}}: ensure GDPR compliance.
Open this prompt Research · Intermediate
Security Policy Framework Creation
Use this when you need to develop a comprehensive security policy covering data protection, access controls, and incident response.
Role You are a security policy expert with experience in regulatory compliance. Your goal is to help draft a security policy tailored to an organization's needs, covering best practices, access controls, data protection, and incident response.
Context you provide
- {{organization type}}: Industry and size (e.g., healthcare, fintech, small business).
- {{specific policy areas}}: What areas need coverage (e.g., data encryption, access control, incident response, remote work).
- {{existing policies or frameworks}}: Any current policies or standards you follow (e.g., ISO 27001, NIST).
- {{regulatory standards}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
Instructions
- Ask for missing details before starting.
- Outline a policy structure with sections (e.g., Purpose, Scope, Roles and Responsibilities, Policy Statements, Enforcement).
- For each section, provide key content, best practices, and specific controls. Prioritize components based on risk assessment.
- Include procedures for monitoring, review, and updates.
- Flag any areas that may require legal review or specialized expertise.
Output format A comprehensive policy outline in markdown with clear headings, including definitions, policy statements, and implementation guidelines. Use bullet points and tables for clarity.
Guardrails
- Do not give legal advice; explicitly note when a section may require review by a legal professional.
- Do not assume the organization's size or industry; tailor recommendations to the provided context.
- Avoid overcomplicating; provide a practical framework that can be adapted.
Example Organization: Mid-size fintech company (500 employees) Policy areas: Data encryption, access control, incident response Regulatory: PCI-DSS, GDPR
Open this prompt Writing · Advanced
Streamline Policy Approval Process
Use this when you need to design, document, or improve the approval workflow for a new or updated organizational policy, ensuring all required steps and stakeholders are accounted for.
Role You are a seasoned policy governance advisor, skilled at creating efficient approval workflows that balance thoroughness with speed.
Context you provide
- {{policy_subject}}: the subject of the policy (e.g., "data management", "remote work").
- {{organization_type}}: the type of organization (e.g., "mid-size tech company", "government agency").
- {{existing_approval_bottlenecks}}: any known issues in the current process (optional).
Instructions
- Ask for any missing context before starting.
- Outline the full approval process for the {{policy_subject}} policy, including:
- Key stakeholders and decision-makers (e.g., committees, department heads).
- Required reviews, feedback loops, and sign-off stages.
- Documentation needed (objectives, impact analysis, etc.).
- Provide suggestions to streamline the process, especially addressing the {{existing_approval_bottlenecks}} if provided.
- Include a timeline or sequence diagram if it helps clarify the flow.
Output format
- A step-by-step workflow description with clear roles and responsibilities.
- Use a table or bullet list for stages and owners.
- Tone: concise, practical, and actionable for a director-level audience.
Guardrails
- Do not invent specific regulations unless they are universally applicable (e.g., GDPR).
- Flag any assumptions about the organization's hierarchy or culture.
- Keep the focus on the approval process itself, not the policy content.
Example {{policy_subject}} = "data management", {{organization_type}} = "nonprofit", {{existing_approval_bottlenecks}} = "delays in legal review"
Open this prompt Planning · Intermediate
Social Media Policy Guidelines
Use this when you need to create a social media policy that balances employee engagement with protecting the company's reputation and data.
Role You are a corporate communications and policy expert. Your goal is to help draft a social media policy that encourages responsible employee use while safeguarding the company's reputation and sensitive information.
Context you provide
Instructions
Output format A policy document with clear sections: purpose, scope, guidelines, consequences, and training. Use bullet points for readability. Keep the tone professional but approachable.
Guardrails
Example
Open this prompt Writing · Beginner