A process map becomes a compliance artifact the moment somebody asks who approved it. Auditors do not want a picture of the process. They want to know what changed, who approved it, when, and whether the version on the wall is the version that was signed off. Most mapping tools answer the first question badly and the rest not at all.
The hard part is not recording changes. It is separating the changes that mean something from the ones that do not. Sapeum stopped writing a revision for pure position changes, because moving a box is not a decision, and later added a separate cosmetic revision type covering expand, collapse and visibility edits, which are muted in the history list. What is left reads clearly: added and removed step cards, humanized field names, relative timestamps, and a chip on each entry marking it manual, agent, cosmetic or initial. Every entry records the person who made it.
One revision, opened. The step it touched, the field it changed, and the two sentences it added.
Review runs as a queue rather than a meeting. The Approvals sidebar lists every step awaiting approval with its diff and an approve or reject control, with Approve all and Reject all for the bulk case, and it hides itself when there is nothing to review. Versions carry an explicit status, moving from unverified through proposed and verified to approved, and that status shows in the version switcher. A map's standing is a property of the map, not a claim in an email thread. Reviewers who should not edit get a full read-only canvas.
Twelve changes waiting. Each one can be taken individually, or the whole queue cleared in one action.
Underneath, deletions are recoverable rather than destructive, and access is protected by multi-factor sign-in with device trust. Sapeum completed a SOC 2 Type 2 audit in September 2026. None of this is interesting, and all of it is the difference between a diagram and evidence.
Sapeum keeps a defensible record of what your processes were, what changed, and who approved it. Try Sapeum.