Kanonik

Help center

Approving a batch of changes in one click.

Accept a reviewed set of changes with a single approval. Every item still seals on its own.

When your AI builds out a piece of your program, it rarely produces just one thing. Asking for your control set, for example, can produce several policies, the procedures under them, the controls themselves, and the links that show which control covers which requirement. Approving each of those one at a time works, but it is a lot of clicks for a set of changes you reviewed together and want to accept together.

Batch approval lets you accept a related set of changes with a single approval. You review the set, you click once, and every item in it is recorded together. Batch approval works the same way for every framework Kanonik supports, so the behaviour below is identical whether you are building toward one framework or several at once.

What the one click actually does

A batch is a grouping, not a shortcut. When you approve a batch, Kanonik still records each item as its own decision on your permanent record. A batch of eight changes becomes eight individual, sealed entries, each with its own timestamp and its own place on the tamper-evident timeline. The batch is simply the convenience of approving them in one action; it never merges them into a single blurry entry, and it never substitutes one item for another.

So after a batch approval you can still answer, for any single item, "who approved this, and when" with a precise answer. Nothing about the record-keeping is weaker because the items were approved together.

What never changes, no matter how you approve

Four protections always apply, to every item, whether you approve it on its own or as part of a batch:

  • A person always approves. Batch approval reduces clicks, never the click itself. Changes never apply on their own.
  • The person who proposed a change cannot be the person who approves it. This separation holds for every item in every batch.
  • The safety check runs on every item, on the server, before anything can be approved. A batch does not let an item skip it.
  • Every approved item is sealed on the tamper-evident record with the approver's identity and the time of approval.

Batch approval changes how many clicks a review takes. It does not change what gets checked or what gets recorded.

What goes in one click, and what gets its own decision

This is the part worth understanding, because it is what keeps a single click safe. When you open a set to approve, Kanonik sorts it into two groups for you.

Routine items go in the one click. An item is routine when the safety check has already passed it with enough confidence and it is not a high-stakes decision. These are the everyday building blocks: a drafted policy, a procedure, a control, a control-to-requirement link, an asset or vendor record, a risk you are treating. A real set is usually mostly these, and they are exactly the things you reviewed together and want to accept together.

A routine batch can span different kinds of thing, because the work you actually do is mixed. Mapping your whole Statement of Applicability, for instance, touches controls, requirements, and the links between them at once. A batch holds whatever you reviewed together, across kinds, and the attestation you sign names exactly what the set spans, so the record stays precise.

Some items are pulled out for their own focused decision. Three kinds of item are never folded into a one-click batch, even when they arrive in the same set:

  • High-stakes decisions. Accepting a risk rather than treating it, granting an exception, excluding a control from your scope, or retiring a control already in place are decisions an auditor will look at closely. Each one gets its own deliberate decision and its own attention, never a shared click.
  • Anything the safety check flagged. If an item did not clearly pass the server-side check, or passed only with low confidence, it is set aside so you can look at it on its own and decide whether to send it back or to override the check on the record.
  • Audit findings. A finding is a judgment about whether something conforms, and each one usually leads to its own corrective action. Accepting a stack of findings in a single click would not give each the attention it needs, and it would sit poorly with an auditor who expects findings to be considered on their own merits. Findings are always reviewed one at a time. That safeguard is permanent, by design.

If every item in a set turns out to need its own focused decision, there is nothing to batch, and Kanonik tells you so plainly rather than offer an empty one-click approval. You then work through those items individually.

The attestation you are signing

When you accept a batch, you confirm a short, exact statement of what you are sealing: how many items, that each one passed the safety check at or above the confidence bar, that the content of each was shown to you inline, and which kinds of thing the set covers. That statement is recorded with your approval, so the evidence on your record matches precisely what you were shown and what you agreed to. It never claims more review than the set supports: a set of one kind says so, and a mixed set names the several kinds it spans.

Choosing how much review a batch requires

Different organizations have different tolerances. A small business moving fast on its first program may want to accept a reviewed set quickly. A regulated business with a demanding auditor may want every item examined closely before anything is accepted. Kanonik lets you set the level of review a batch requires, so the tool matches your risk posture rather than forcing one rhythm on everyone.

The levels run from lighter to stricter:

  • Lighter review suits an organization that accepts more responsibility for moving quickly. The approver confirms the set and accepts it, with a longer window to do so.
  • Standard review asks the approver to look over each item in the set before accepting.
  • Strict review requires close, item-by-item attention, with a shorter window, before the accept action becomes available. This is the setting for the most demanding environments.

Whichever level you choose, the four protections above still apply. The level changes how much scrutiny the approver gives, not whether the work is governed.

Why a lighter setting is still defensible

Choosing a lighter review is a legitimate, risk-based management decision, and Kanonik treats it as one. The choice of review level is itself recorded as a deliberate decision: who set it, when, and what it was changed from. Combined with the per-item record every approval already produces, that means an auditor sees a considered posture your leadership chose and can account for, rather than an unexplained gap. Moving to a lighter setting is treated as a significant decision in its own right, so the change is attributed and recorded like any other.

The practical guidance: pick the level that matches the stakes of the work and your own tolerance, revisit it as your program matures, and let the record show the choice was made on purpose.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.