heyGRC Docs

Where your policies live

Point heyGRC at your own policies, controls and vendors: connect Google Drive, paste a link, or sync from Probo or Drata, and reviews quote your rules.

heyGRC reviews your pull requests against your own compliance rules, not a generic checklist. Before it can do that, you point it at the places those rules already live. You never retype or rewrite anything here: heyGRC reads your documents and quotes your words back in the review.

There are three ways to bring your rules in. You can use any of them, or all of them.

Connect Google Drive

Connect the Google account that holds your policy documents, then pick a file. heyGRC reads the file you picked, extracts the rules from it (clauses, commitments, retention rules), and uses them in reviews. If your browser blocks Google's file picker, paste a share link for the same file instead: both paths add the same document.

What heyGRC does with a Drive document:

  • It reads the document again every day, so edits you make in Drive reach your reviews without you doing anything.
  • It quotes the exact words from the document in a review, with the document named as the source.
  • If the file becomes unreadable (permissions changed, file deleted), the review says so instead of silently using old text.

Any document with a public web address works: a published policy page, a wiki page, a hosted PDF. Paste the link in the console and heyGRC reads the page the same way it reads a Drive file: extracted rules, daily re-read, quoted words in reviews. A link is the right choice when your policies are already published somewhere and you want heyGRC to follow the live version.

Sync from Probo or Drata

If your compliance program lives in Probo or Drata, you do not need to pick documents one by one. The heyGRC plugin reads your workspace once and keeps it in sync: policies, controls, vendors and risks, on a daily schedule. Setup is three steps in the console (install the plugin, create a setup key, run the setup command), and the page updates live while the first sync arrives.

The sync is on for some organizations. If your console does not show it, write to us and we will turn it on for yours.

Where you see all of it: the Context page

The Context page in the console lists every source you connected or synced, with what heyGRC knows from each one: how many documents, how many rules, and whether the source is current. When a source changes, heyGRC shows the change and asks before it affects your reviews, so a policy edit upstream never quietly weakens a rule. When you remove a source, its rules stop being checked and heyGRC says so.

In short:

  • Connect Google Drive or paste a link when your rules live in documents.
  • Sync from Probo or Drata when your rules live in a compliance platform.
  • The Context page shows what heyGRC knows and whether it is current.

What heyGRC never does

  • It never edits your documents. To change a rule, change it where it lives; heyGRC follows.
  • It never asks you to retype rules into a form. The words come from your own sources.
  • It never quotes a document marked secret, and it says when it refused to.

On this page