07/Governance

Documentation that holds up when someone asks who changed what.

Built into normal editing, not a separate exercise.

Versions, attribution and review are built into normal editing, so the process record stays current and stays defensible without a separate effort.

Onboarding v2.4

Version history · audit trail

v2.4 · published ✓ Audit-approved
Sarah K. · 2h ago
v2.3 · approval chain simplified
Mike R. · 3d ago
v2.3-experiment · forked
Sarah K. · 5d ago
v2.2 · archived
Jane L. · 2w ago
SOC 2 Type 2 compliant Trust center

Change history

Answer who changed this and when, without an investigation

Every edit is a version with a name and a timestamp against it, which is the question an auditor actually asks.

  • Full version history with per-change attribution
  • Structured change records and clear ownership
Change record · v2.4
Removed "Director review"
Sarah K. · 2h
Added "Single approval"
Sarah K. · 2h
Approved by Mike R. Sign-off
1h

Approvals

Know which version was in force on any given date

Versions move through review before they publish, so there is an explicit answer to which version was in force on any date.

  • Reviewable documentation for compliance-sensitive work
  • Living documentation, refined over time
Publication state
Draft
In review
Approved
Current
Published

One source, many uses

One current process serves onboarding, audit and handover

The same maintained process serves onboarding, audit evidence and succession, instead of three documents quietly drifting apart.

  • Reusable for training, handover and succession
  • Linked knowledge across related workflows
Used by
New-hire onboarding pack People
SOC 2 evidence request Compliance
Succession handover Ops
Quarterly process review Ops

Audit evidence without a separate exercise

The history is already there when someone asks.

Documentation your teams actually trust

A map demonstrably current gets consulted.

Handover without the guesswork

The process is already documented and attributed.

Common questions

Can we see who changed what?

Yes. Every version carries attribution and a timestamp, and changes are recorded as structured change records against an owner rather than inferred from file metadata.

Does this satisfy compliance requirements?

Sapeum provides reviewable, versioned documentation with per-change attribution and clear ownership, which is what compliance-sensitive reviews depend on. Sapeum has completed an independent SOC 2 Type 2 examination, with the report available under NDA; see trust.sapeum.com for current details.

Can old versions be recovered?

Yes. Version history is retained, including forked and archived versions, so you can see what a process looked like at any earlier point.

What happens when the person who owned a process leaves?

The process is already documented, attributed and current, because maintaining it was part of normal work rather than a project. Nobody has to reconstruct it from scratch.

Is process data held securely?

Sapeum is designed with enterprise-grade security practices: encryption at rest and in transit, role-based access controls, and auditable change history. Sapeum has completed an independent SOC 2 Type 2 examination; trust.sapeum.com has the current position.