# May 2026 release: Bulk imports and eSign | Policy Confirm

Canonical URL: https://policyconfirm.com/blog/may-2026-release-policy-confirm
Source: Policy Confirm (https://policyconfirm.com)
Published: 2026-05-23
Modified: 2026-05-23
Summary: May 2026 Policy Confirm release: bulk imports, electronic signatures, automated reminders, per-recipient PDF certificates and data retention controls.

---
Product updates May 23, 2026

# May 2026 release: Bulk imports, electronic signatures, and optional policies

Originally published: May 2026

Last updated: May 2026

May was a substantial release month for Policy Confirm. Several updates affect how organizations set up the system, how confirmations are captured, and how the resulting evidence is structured. This post walks through each change, why it was made, and what it means in practice.

The full list of features and their release dates is always available from the dashboard inside the application.

## Bulk import of recipients and groups

Setting up Policy Confirm for a larger organization used to mean adding recipients and groups one entry at a time. For organizations with several hundred employees across multiple departments, this was a barrier to getting started.

Three changes in May address this.

**Bulk recipient upload.** Recipients can now be imported from an Excel or CSV file. Each row becomes a recipient in the system.

**Group assignment in bulk upload.** The recipient file can now include a group column. Recipients arrive in the system already mapped to the correct groups, so distribution cycles can be created immediately after import. There is no separate mapping step.

**Bulk upload of groups.** Groups themselves can be imported in bulk. This is useful when mirroring an existing departmental structure from HR records or an organizational chart.

For organizations preparing for an ISO 27001 or SOC 2 audit, this matters because the cleaner the initial structure, the easier it is to demonstrate which groups received which policies. The principle behind this is covered in [Policy version control best practices](https://policyconfirm.com/blog/policy-version-control-best-practices) : evidence is strongest when the relationship between policies, recipients, and groups is unambiguous from the start.

## Required policy view before confirmation

Recipients must now open each policy by clicking the View button before they can confirm it. This adds an explicit interaction step between distribution and confirmation, and strengthens the evidentiary chain: the audit trail records not only that the recipient confirmed, but that they actively opened the policy beforehand.

The change is enabled by default and applies to all new confirmations.

## Electronic signature on confirmations

Recipients can now be required to draw a signature before confirming a policy. The signature is captured at the moment of confirmation and stored alongside the verified recipient identity, the specific policy version, the timestamp, and the confirmation ID.

This is a Simple Electronic Signature under eIDAS, the appropriate signature tier for internal policy acknowledgements. The evidentiary strength of each confirmation comes from a layered record: attributed identity through the magic link, an explicit act of intent through the drawn signature, the exact policy version reviewed, and a tamper-evident audit log around the event. Together these elements form a defensible record that holds up under audit and legal review.

Electronic signature is configured under settings. When enabled, all confirmations in the organization require a drawn signature before they can be completed.

If you want background on why a click-to-confirm with verified identity already constitutes defensible evidence, [Why Outlook read receipts are not legal proof of policy compliance](https://policyconfirm.com/blog/outlook-read-receipts-legal-proof) explains the distinction between delivery, access, and acknowledgement.

## Confirmation receipt by email

Recipients now receive an automatic email after confirming a policy. The email links back to a read-only view of the same confirmation page, showing the policies that were confirmed and the details of when each confirmation occurred.

This gives recipients a personal record of what they acknowledged, which reduces follow-up questions and avoids situations where a recipient asks to see a policy again but no longer has access to the original link.

## Optional policies

Not every policy in a cycle needs to be required. A policy can now be marked as optional during creation. Optional policies appear in a dedicated section on the recipient confirmation page, available to read but not blocking confirmation.

Each recipient must still have at least one required policy. The optional flag is set per policy, so the same policy carries its status across every cycle it is included in.

Common uses include supplementary guidelines, reference documents, and policies that apply only to some recipients within a mixed group. The mechanism gives organizations more flexibility in how a cycle is composed without weakening the evidence on the required items.

## Bulk status update for policies

Policies move through states during their lifecycle: draft, ready, archived. Moving several policies between states used to require opening each one individually. The bulk action handles this in a single step: select the policies, choose the target status, apply.

This is practical when archiving an outdated set of policies after a major version release, or when promoting a batch of drafts to ready before opening a cycle.

## Reopen finalized cycles

A finalized cycle is closed, which is the intended behaviour for most situations. Occasionally, though, a recipient needs to be added after the fact, a missed confirmation needs to be captured, or a correction needs to be made.

Finalized cycles can now be reopened from the cycle view. After the necessary changes are made, the cycle can be finalized again. The audit trail records the reopening event, who performed it, and any subsequent confirmations. The change is fully traceable, which preserves the integrity of the underlying evidence.

## Automated reminders

Reminders no longer need to be sent manually. A cycle can now be configured to send automated reminders before the cycle end date, or weekly reminders that continue past the end date until each recipient confirms. Manual reminders are still available from inside the cycle when something needs to be sent on demand.

This reduces the operational overhead of chasing non-responders and improves the rate at which cycles reach full confirmation. Reminder activity is recorded in the audit trail, which is what auditors expect to see as evidence of remediation effort. The principle is covered in [Audit ready compliance checklist: What auditors actually look for](https://policyconfirm.com/blog/audit-ready-compliance-checklist) .

## Per-recipient PDF certificates

Proofs already capture the complete record of who confirmed what and when. The new option generates an individual PDF certificate for each recipient from any proof export.

Each certificate contains the recipient's identity, the policies they confirmed, the version of each policy, the confirmation timestamp, and the confirmation ID. The use case is straightforward: when individual evidence needs to be shared with an auditor, attached to an HR file, or sent to a customer doing due diligence on a single named employee, the certificate can be exported on its own without sharing the full cycle proof.

## Delete proofs

Proofs can now be deleted directly from the proof overview. This is useful when a proof was generated for a test cycle, contains test data, or has been superseded by a regenerated version.

The underlying confirmations are not affected. Only the generated proof artifact is removed.

## Confirmation history retention

The retention period for confirmation records on inactive recipients is now configurable under settings. When the period expires, the records are deleted automatically.

This supports the data minimization principle under GDPR Article 5(1)(c) and gives organizations explicit control over how long personal data linked to confirmations is retained. Active recipients and the cycles they participate in are not affected by this setting.

## Date and time format settings

Date and time display is now configurable across the application. Regional date formats are supported, as is 12 or 24-hour time. The setting applies to the in-app view, exported proofs, and per-recipient certificates.

## Filtering, sorting, and pagination across all tables

Every table in the application now supports filtering and sorting on all columns, with configurable rows per page and pagination controls. This applies to recipients, groups, policies, cycles, and proofs.

For organizations managing several hundred recipients or a large policy library, this makes it possible to locate specific records without scrolling through long lists. It also makes audit preparation faster, since records can be filtered down to exactly the subset the auditor has asked about.

## Refined design and styling

The visual layer of the application has been tightened across the board. Spacing has been adjusted, colors have been updated for better consistency, and buttons and components now share a unified style. The result is a calmer interface that puts less between the user and the task at hand.

This is not a single feature but a cumulative refinement applied across every screen. Existing workflows are unchanged.

## Redesigned dashboard and feature overview

The dashboard layout has been redesigned. The information density is higher where it matters, the navigation is clearer, and a dedicated feature overview now lists every new feature with the date it was added.

The feature overview is the canonical place to see what has changed inside the application and when. It is updated with each release, so users do not need to consult external release notes to know what is new.

## Summary

May added functionality across three areas: setup (bulk imports for recipients and groups, required policy view before confirmation), confirmation evidence (electronic signatures, confirmation receipt by email, per-recipient certificates, configurable retention), and lifecycle control (optional policies, bulk status updates, cycle reopening, automated reminders, proof deletion). Broader UX improvements include refined design and styling, filtering, sorting, and pagination across all tables, and a redesigned dashboard with a dedicated feature overview that makes ongoing changes easier to follow inside the app.

If there's functionality you're missing or have other requests, use the request feature in the dashboard or reply to any email from us.

### See the new features in your organization

Policy Confirm now supports bulk imports, electronic signatures, optional policies, and per-recipient certificates. Start using them today.

[Get started](https://app.eu.policyconfirm.com)

Try with up to 10 recipients No credit card

Get started in seconds Magic link access

Choose between EU or US hosting

## About the author

The team behind Policy Confirm has hands-on experience across full-stack development, product growth, compliance leadership, and executive technology roles such as CTO and CPTO. They have led and supported ISO 27001 implementations, policy governance initiatives, and audit-driven compliance projects in regulated environments. This background informs a practical, audit-oriented approach to policy management and policy acknowledgements.

## Related content

-   [What is a Policy Acknowledgement System?](https://policyconfirm.com/blog/what-is-policy-acknowledgement-system)
-   [Audit ready compliance checklist: What auditors actually look for](https://policyconfirm.com/blog/audit-ready-compliance-checklist)
-   [Policy version control best practices: Why v1.0 matters](https://policyconfirm.com/blog/policy-version-control-best-practices)
-   [How to track staff policy reading (and what actually works)](https://policyconfirm.com/blog/how-to-track-staff-policy-reading)

## Legal disclaimer

The information provided in this article does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only. You should contact your attorney to obtain advice with respect to any particular legal matter.
