Enterprise Data Policy · Alpha

Enterprise Data Policy

Turn your written data policies into enforced, audit-ready controls. Upload documents or link to them; Dobby's AI translates each into enforceable Org-level policies — mapped to ISO 27001, NIST CSF & GDPR.

What this module does

Most organizations already have data policies — written in a Word doc, a Confluence page, or a PDF. The hard part is turning that prose into something a machine can enforce. The Enterprise Data Policy module closes that gap: point Dobby at your policy documents and it produces structured, enforceable Org-level policies that join the same four-layer hierarchy (Platform → Org → Tenant → Process) the Policy Scanner evaluates on every workload run.

How it works

1 · Bring your policies

Upload your existing data / AI / security policy documents (PDF, Markdown, TXT, JSON, YAML) or paste links to where they're hosted. Add as many sources as you like.

2 · AI translates them

Dobby's AI reads each source and extracts the discrete, enforceable rules it states — each with a severity and, where it maps, a framework reference. It never invents rules the document doesn't contain.

3 · Enforced as Org policies

Each extracted rule becomes an Org-level (Layer 2) policy in your policy hierarchy, applied across every team and workload and evaluated by the Policy Scanner on every run.

Files and links

  • Files — upload one or many. Supported: PDF, TXT, Markdown, JSON, YAML (up to 10MB each).
  • Links — paste an https URL to a hosted policy page or document. Links are fetched server-side behind an SSRF guard (no internal/private addresses).

Keeping policies in sync

Source documents change. Click Re-resolve on any source and Dobby re-reads the file or URL. If nothing changed it says so and does nothing. If the content changed, it re-extracts and diffs against the policies that source produced last time — adding new rules, removing ones the document no longer states, and keeping the rest — so your enforced controls stay faithful to the source.

Framework mapping

ISO 27001
Information security management controls
NIST CSF
Identify · Protect · Detect · Respond · Recover
GDPR
EU data-handling & data-subject obligations

Getting started

  1. Open the Module Marketplace in your organization and activate Enterprise Data Policy (org admins only).
  2. From the module's Open action, upload your policy documents or add links.
  3. Review the extracted policies under your org's Policies, and tune severity or wording — they're yours to edit.
Enterprise Data Policy | Dobby AI Docs