# July 2026 release: Recurring cycles | Policy Confirm

Canonical URL: https://policyconfirm.com/blog/july-2026-release-policy-confirm
Source: Policy Confirm (https://policyconfirm.com)
Published: 2026-07-19
Modified: 2026-07-19
Summary: July 2026 Policy Confirm release: recurring cycles, catch-up cycles, supervisors, coverage warnings, live group membership, and a new notification center.

---
Product updates July 19, 2026

# July 2026 release: Recurring cycles, supervisors, and full coverage

Originally published: July 2026

Last updated: July 2026

July was about coverage and continuity. The point of a policy acknowledgement process is that nobody is missed, so this release makes sure every recipient is accounted for, that gaps are flagged before they turn into audit findings, and that the routine work runs on a schedule instead of on your memory. Here is everything that shipped.

The full list of features and their release dates is always available from the dashboard inside the application.

## Recurring cycles

You can now set up a recurring rule that repeats a cycle every 3, 6, or 12 months, with recipients and policy versions resolved fresh at each run.

Periodic re-acknowledgement is a standing requirement under most frameworks (annual policy sign-off is common for ISO 27001 and SOC 2), and until now it depended on someone remembering to start the cycle again. A recurring rule removes that dependency. Because recipients and versions resolve at run time, each cycle reflects who is actually in the group and which version is current, not a snapshot from months ago. The distribution that used to sit on your to-do list every year now runs on the schedule you set.

## New group members join active cycles

People added to a group while a cycle is active are now included in that cycle and notified automatically.

Previously a cycle was a fixed set of recipients captured at the moment of send, so someone who joined the next day was not part of it. Now group membership stays live for the duration of the cycle. A new hire in week two of a rollout receives the same policy as everyone else, tied to the same version. Coverage follows the group, not the send moment.

## Recipients awaiting distribution

Recipients who have policies assigned but were never sent a cycle are now counted in a banner on the Recipients page. One click creates a prefilled catch-up cycle for exactly those people.

Assigning a policy to someone is not the same as them confirming it. A recipient can end up waiting because there was no active cycle for them to join when they were added, or because automatic inclusion in active cycles was not enabled. Either way, it is easy to assume they are covered when no cycle has actually reached them, and that is the kind of silent gap that only surfaces when an auditor asks for one specific person's record. The banner makes the gap visible and closes it in a single action.

## Automatic catch-up cycles

You can optionally have the catch-up cycle for waiting recipients created automatically, on a weekday you choose. Enable it under Settings.

For teams with steady onboarding, waiting recipients accumulate every week. Rather than watching the banner, you can let the system draft the catch-up cycle on a fixed day. New joiners are folded into the process without anyone having to notice them first.

## Coverage warnings

Recipients who belong to no group, and groups that are not linked to any policies, are now flagged with warning triangles, so nobody silently receives nothing.

The most dangerous gap is the one you cannot see. A recipient who belongs to no group, or a group with no policies attached, will never receive anything, and will never appear as a non-responder either, because nothing was ever sent. Coverage warnings surface these structural gaps before a cycle runs, while there is still time to fix them.

## Supervisors

You can now assign supervisors to groups and let them follow up on confirmations through a read-only status page, without a Policy Confirm account. Activate the feature under Settings.

Follow-up usually belongs with the person closest to the team, a line manager or department head, rather than the central compliance owner. But you do not want to hand out full accounts just to chase confirmations, and you do not want to be the one chasing every team yourself either. A supervisor gets a read-only view of their group's status and can follow up on the people who have not confirmed, with no access to settings, recipients, or other groups. It is delegation without expanding the access surface, which is itself something auditors ask about.

## Notification center

A bell in the menu now collects completed cycles, drafted cycles, expiring policies, new members, and more. Each notification links straight to the relevant page.

Governance work is easy to lose between other tasks. A policy quietly approaches its expiry date, a recurring rule drafts a cycle, a cycle finishes. The notification center puts these in one place, so nothing depends on you happening to open the right screen at the right time.

## Policies without files

Policies can now be set to Ready and sent in cycles without an uploaded PDF, for organizations that keep their documents elsewhere. Enable this under Settings.

Some organizations hold their canonical policy documents in an existing system (an intranet, a document management platform, a controlled document library) and do not want a second copy living inside the acknowledgement tool. This option lets you run the confirmation process, with its versioning, recipients, timestamps, and proof, while the document itself stays in whatever source of truth you already maintain. The acknowledgement record is still tied to a named policy and a specific version.

## Owners and administrators

Roles have been renamed to make responsibilities explicit. Owners (previously called admins) manage users, billing, and settings. Administrators handle the daily work. Owners can change roles and appoint several owners, and anyone can leave an organization on their own.

Separating who can change the account from who runs the day-to-day process is a basic segregation-of-duties principle, and one auditors look for. The rename makes that distinction clear. Being able to appoint more than one owner removes the single-point-of-failure risk of one person holding all control, and letting anyone leave an organization themselves keeps membership accurate without routing every departure through an owner.

## What this adds up to

Every feature in this release serves the same principle. A policy acknowledgement process is only as strong as its weakest gap, the recipient who was never sent anything, the cycle nobody remembered to repeat, the new joiner who slipped through between rollouts. This release closes those gaps and keeps the routine running on its own, so what your audit trail shows is the whole picture, not just the part you managed to handle by hand.

If you are still tracking acknowledgements through email threads and spreadsheets, you can replace that process in an afternoon. The principle behind why the switch pays off is covered in [Excel vs. dedicated policy tracking: The hidden risks](https://policyconfirm.com/blog/excel-vs-policy-tracking-risks) .

### Get started. Free up to 10 recipients.

Recurring cycles, supervisors, coverage warnings, the notification center, catch-up cycles, and the new roles are all live. Start using them today.

[Get started](https://app.eu.policyconfirm.com)

Try with up to 10 recipients No credit card

Get started in seconds Magic link access

Choose between EU or US hosting

## About the author

The team behind Policy Confirm has hands-on experience across full-stack development, product growth, compliance leadership, and executive technology roles such as CTO and CPTO. They have led and supported ISO 27001 implementations, policy governance initiatives, and audit-driven compliance projects in regulated environments. This background informs a practical, audit-oriented approach to policy management and policy acknowledgements.

## Related content

-   [What is a policy acknowledgement system?](https://policyconfirm.com/blog/what-is-policy-acknowledgement-system)
-   [How to prove policy acknowledgement in an audit](https://policyconfirm.com/blog/how-to-prove-policy-acknowledgement-audit)
-   [Excel vs. dedicated policy tracking: The hidden risks](https://policyconfirm.com/blog/excel-vs-policy-tracking-risks)
-   [Audit ready compliance checklist: What auditors actually look for](https://policyconfirm.com/blog/audit-ready-compliance-checklist)

## Legal disclaimer

The information provided in this article does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only. You should contact your attorney to obtain advice with respect to any particular legal matter.
