
## Create policies

URL: https://docs.atlan.com/product/capabilities/governance/stewardship/how-tos/create-policies

:::warning Who can do this?
 You must be an [admin user](https://docs.atlan.com/llms/governance/access-control/delegate-administration/llms.txt) in Atlan to [enable](https://docs.atlan.com/llms/governance/stewardship/automate-policy-compliance/llms.txt), [create](https://docs.atlan.com/llms/governance/stewardship/create-policies/llms.txt), [manage](https://docs.atlan.com/llms/governance/stewardship/manage-policies/llms.txt), and approve data governance policies.

:::

You can create a policy to document guidelines for the following:

- How's data processed and managed within your organization?
- Who is responsible for the data under various circumstances?
- What can you do to reduce potential business problems from the improper use of data?

Before you can create a data governance policy, you must have an Atlan admin [enable the policy center module](https://docs.atlan.com/llms/governance/stewardship/automate-policy-compliance/llms.txt) in your Atlan workspace. To create a policy, complete the following steps.

## Create a policy

To create a new policy:

1. In your Atlan workspace, click **Settings** from the left menu and then click **Settings**.
2. Under the _Policy center_ heading, click **Policy center**.

 If you are using the **Old UI (Classic)**, from the left menu of any screen, click **Governance**, then under the _Governance_ heading of the _Governance center_, click **Policy center**.
3. From the _Policy Center_, click the **\+ New policy** button to create a new policy.
4. In the _Create a new policy_ dialog, enter the following details:
 1. For _Policy name_, enter a meaningful name for your policy.
 2. For _Policy type_, choose a policy type.
 3. For _Owners_, assign individual users or groups as policy owners.
 4. Click **Create** to get started.

## Define the policy

### Add a purpose

Once you have created a policy, you can define its purpose. This is the mission statement of your policy, where you can outline what you want the policy to accomplish.

To define the purpose of your policy:

1. In the _Overview_ tab of the policy page, under _Purpose_, you can either:
 - Click **Edit** to manually describe the purpose of your policy and then click **Save**.
 - Click **ask Atlan AI** to add an Atlan AI-generated description. In the _Generate purpose using Atlan AI_ form, enter the following details:
 1. For _Enter industry_, enter the name of your industry - for example, `Finance`.
 2. To define the area of impact of your policy, click the dropdown to select _Global_, _Regional_, or _Local policy_.
 3. For compliance type, select _Standard_, _Regulation_, or _Other_.
 4. For _Enter compliance_, enter the compliance regulation.
 5. For _Describe the policy_, enter a brief description of your policy.
 6. Click **Generate Purpose** to generate an Atlan AI-generated purpose.
2. (Optional) Click **\+ Add resource** to [add resources](https://docs.atlan.com/llms/catalog/discovery/add-a-resource/llms.txt) to your policy description.

### Describe the policy

You can set out the best practices, goals, and guidelines for your policy document.

To describe your policy:

1. Switch to the **Purpose** tab of your policy page.
2. In the _Policy_ section, click **Edit** to write your policy. You can either manually draft the policy description or use Atlan AI to do the same and then edit as needed.
3. Click **Save** to save your changes.

### (Optional) Add policy exceptions

A policy exception is a method for maintaining a policy but granting exceptions to authorized individuals or entities. Doing so will allow them to circumvent one or more restrictions.

To add a policy exception:

1. In the _Purpose_ tab of the policy page, under _Policy Exceptions_, click **Add policy exception**.
2. In the _New policy exception_ form, enter the following details:
 1. For _Exception name_, enter a meaningful name.
 2. For _Purpose_, briefly describe the purpose of this exception.
 3. For _Users_, select the individual users or groups to whom this exception should apply.
 4. Click **Add exception** to save your changes.
3. (Optional) Click **\+ Add new** to add more policy exceptions.

## Define scope and rules

:::info **Did you know?** 
 Your selected assets will not be linked to the draft policy until after it has been approved. It may also take a few hours after the policy has been approved for the assets to be linked while the linkage workflow runs in the background.

:::

### Select asset scope

You can determine the assets within the scope of your policy. Policy rules will only apply to the filtered subset of assets you select.

To select assets:

1. Switch to the **Scope & Rules** tab of your policy page.
2. For _Asset scope_, use the asset filters to select the relevant assets. The operators and values will vary depending on the selected attributes.
3. (Optional) To add more filters, click **Add filter**.
4. (Optional) To preview the assets included in the scope of your policy, click **View all**.
5. Click **Save scope** to save asset selection.
6. (Optional) To the right of any filter, click the three horizontal dots and then:
 - To remove a filter, click **Delete**.
 - To turn off a filter, click **Disable**. Click **Enable** to turn on any disabled filters.

### Create compliance rules

To implement and enforce your policy, you can create a set of rules to specify permitted or restricted actions, enable compliance with data standards, and ensure accountability.

If the assets scoped to the policy do not comply with all the rules, Atlan will trigger an [incident](https://docs.atlan.com/llms/governance/stewardship/manage-policies/llms.txt) to alert you. This incident can help you understand the specific rules that have been violated by the assets, making them noncompliant with the policy.

Atlan currently supports creating 10 rules per policy.

To define compliance rules:

1. In the _Scope & Rules_ tab of your policy page, _Assets must comply with the scope defined above_ is the default rule for all policies. You must first determine your asset scope before you can create compliance rules.

 :::note
 The default rule **Assets must comply with the scope defined above** continuously monitors whether scoped assets still meet the scope criteria. If an asset no longer meets the scope (for example, if its certificate status changes from _Verified_ to another status), Atlan treats this as a rule violation, marks the asset as non-compliant, and triggers an incident.

 The asset isn't removed from the policy when it leaves scope. It remains linked as non-compliant until it meets the scope criteria again. To stop tracking such assets, revise the policy with a new compliance rule. The existing incident remains open while the assets are non-compliant.
 :::
2. For _Compliance rules_, use the attribute filters to create a rule with which scoped assets must comply. The operators and values will vary depending on the selected attributes. Atlan currently supports creating policy rules based on the following metadata attributes:
 - [Certificates](https://docs.atlan.com/llms/catalog/discovery/add-certificates/llms.txt)
 - [Owners](https://docs.atlan.com/llms/catalog/discovery/add-owners/llms.txt)
 - [Terms](https://docs.atlan.com/llms/governance/glossary/what-is-a-glossary/llms.txt)
 - [Tags](https://docs.atlan.com/llms/governance/tags/what-are-tags/llms.txt)
 - [Custom metadata](https://docs.atlan.com/llms/governance/custom-metadata/what-is-custom-metadata/llms.txt)
3. (Optional) To add more rules, click **Add another rule**.
4. Click **Save rules** to save the rules you created for the policy. Atlan will scan scoped assets to ensure that these match all the rules. An incident will be triggered for any asset that does not comply with _all_ the policy rules.
5. (Optional) To the right of any rule, click the three horizontal dots and then:
 - To remove a rule, click **Delete**.
 - To turn off a rule, click **Disable**. Click **Enable** to turn on any disabled rules.

## Define policy validity

To define the validity period of your policy:

1. In the _Policy Details_ sidebar of the _Overview_ tab, for _Valid till_, click the pencil icon to set a validity period.
2. From the calendar, set a date for when the policy will expire.
3. For _Review period_, click the pencil icon to set a review period. For _...days before expiry_, enter a numeric value for when the policy should be reviewed before its expiration date.

By default, Atlan will display a warning message on the policy 30 days prior to its expiration date. You can adjust the review period to set a different timeline. During the review period, you can either [revise the expiring policy](https://docs.atlan.com/llms/governance/stewardship/manage-policies/llms.txt) or extend its validity period.

## Select approval workflow

To select an approval workflow:

1. Switch to the **Relationships** tab of your policy page.
2. From the left menu, select **Approval Workflows**.
3. In the _Approval Workflows_ section, click **Add approval workflow**.
4. In the _Select Approval Workflow_ dialog, click the relevant approval workflow for your policy.
5. (Optional) Hover over **Approvers** to view a list of approvers.
6. Click **Save** to save your selections.

## (Optional) Add terms related to this policy

You can add business context to your policies in Atlan.

- In the _Overview_ tab of the policy page, under _Linked Terms_, click the **+** button to add related terms.

## (Optional) Add related policies

You may want to group data governance policies by policy type, business function, and more. You can optionally create relationships between your policies in Atlan to build a more comprehensive framework of data governance.

To add related policies:

1. Switch to the **Relationships** tab of your policy page.
2. From the left menu, select **Related Policies**.
3. In the **Related Policies** section, click **Add related policies**.
4. In the left menu of the _Add policies related to_... dialog, click the relevant policies to connect to your policy.
5. Click **Add policies** to save your selections.

## Submit for approval

Once you have reviewed your policy, in the top right of your screen, click **Submit for approval** to submit your policy for approval.

If the policy has been approved and the workflow linking the policy to your selected assets has run successfully, the policy you created will become active and govern linked assets.

For governed assets, linked policies will appear on the [asset sidebar](https://docs.atlan.com/llms/catalog/discovery/what-are-asset-profiles/llms.txt). You can hover over a linked policy in the asset sidebar to view details in a popover, including policy type, purpose, and certification status, and even navigate to the policy in the policy center.

:::info **Did you know?** 
 If you have any questions about setting up policies, head over to [Troubleshooting policies](https://docs.atlan.com/llms/governance/stewardship/troubleshooting-policies/llms.txt).

:::

---
