Freeze the requirement
Record the approved change, scope, effective date, owner and exact source language before testing begins.
For policy governance, compliance and internal-audit teams in multi-entity organisations: RuleDiff tests whether an approved group-policy change reached the relevant local policies, procedures, forms and guidance.
Today: a fixed-scope Azure pilot. You receive an impact map, cited matches, gaps, contradictions and explicit uncertainty. No tenant integration, source-file changes or automated compliance verdict is required for the back-test.
Source requirementMaterial ICT incidents must be escalated to Group Risk within four hours of classification.
GP-07.4The implementation gap
A single group requirement can surface differently in local policies, operating procedures, forms, guidance and exceptions.
Teams reconstruct that cascade through spreadsheets, interviews and memory. RuleDiff makes inheritance evidence explicit, comparable and reviewable without replacing existing systems.
SharePoint and your GRC remain authoritative systems of record.
The back-test starts with a change your organisation approved.
Each result includes a citation, reason and explicit uncertainty.
Policy work, made visible
Product · RuleDiff
A semantic inheritance-testing layer for Microsoft 365. It connects approved parent requirements to the language used in local policies, procedures, forms and guidance.
Better copilots improve the reasoning layer; RuleDiff retains the durable lineage, versioned rule record, deterministic OOXML patch semantics, evaluation history and approval evidence across model changes.
The synthetic example starts with an approved group ICT risk policy change requiring four-hour incident escalation. The workbench compares local documents, identifies a conflicting deadline and shows an illustrative remediation proposal for the accountable owner to review.
Record the approved change, scope, effective date, owner and exact source language before testing begins.
Compare how the requirement appears across entities, procedures, forms, guidance and stated exceptions.
Classify addressed, not addressed or cannot determine, with exact passages and conflicts—not a confidence-only score.
Preserve scan coverage, reviewer decisions and the complete source-to-evidence trail for audit and future change.
The RuleDiff model
RuleDiff combines language-model reasoning with deterministic Office document analysis. Each finding carries an explicit verification state and remains subject to human judgment.
Reasoning
AI helps identify where the meaning of an approved parent requirement may appear in differently worded local documents.
Verification
Dates, thresholds, owners, frequencies, citations and document coverage are checked deterministically.
Document engineering
Native Open XML parsing preserves headings, tables, lists and locations that text-only retrieval tends to flatten.
Governance
Named owners confirm whether a finding is a gap, valid local exception, accepted difference or unresolved uncertainty.
Initial focus
RuleDiff begins where one approved group policy must cascade through many entities, jurisdictions and operational documents: insurance, payments, fintech, energy, healthcare and other regulated organisations.
Parent policies, local policies, procedures, forms and guidance
SharePoint, Purview, ServiceNow and GRC remain authoritative
Cited passages, contradictions, exceptions and owner decisions
Designed for consequential work
Reviewers can move from a finding back to the exact parent requirement, local passage and comparison rationale.
The pilot data set, tenant permissions, model provider, EU processing location, retention and deletion are written into the scope before files move.
RuleDiff overlays selected repositories and returns evidence; SharePoint or your GRC keeps ownership, versioning and approval.
RuleDiff finds and explains. Accountable owners classify, accept or resolve every material finding.
Policy Cascade Backtest
One approved master-policy change, three entities and up to 30 DOCX policies, procedures, forms or guidance files. We withhold the known historical result, run RuleDiff blind and adjudicate the comparison together—without connecting to your live tenant.
Request a back-testApproved language, scope, effective date, owner and source fingerprint.
Exact passages classified as addressed, not addressed or cannot determine.
Conflicting deadlines, owners, frequencies and scope, plus stated local exceptions.
Incremental findings, misses, false positives, review effort and next-step economics.
A strong first partner has
Before we start
You provide the approved parent-policy change, the complete in-scope DOCX set and a historical result kept from RuleDiff until the blind run is complete. RuleDiff tests policy inheritance; it does not interpret law, certify compliance or modify controlled originals.
How success is judged
RuleDiff and the withheld historical result are compared blind. Your policy owners adjudicate material findings, valid local exceptions, misses and false positives. We also measure review time, document coverage and evidence usability.
Supported in the pilot
Selected DOCX files, including headings, tables, lists, links and numbering. Scanned PDFs, macros, protected or encrypted files, embedded objects and automated translations are excluded unless explicitly scoped and tested. XLSX, PPTX and PDF follow after the DOCX workflow is independently validated.
After the back-test
A successful back-test can progress to a live, read-only SharePoint workflow in a dedicated Azure EU environment with a scoped Microsoft identity. Deployment, integration and recurring terms follow from measured volume and review workflow.
Buyer questions
No. Your organisation supplies an approved policy change. RuleDiff tests how its meaning cascaded through the selected document set and exposes evidence for accountable review.
No. It overlays selected repositories and returns an evidence package. Your existing system remains the system of record and its approval workflow remains authoritative.
The back-test uses only the agreed files. Before transfer, the scope names the Azure EU region, model provider, storage, retention, deletion, subprocessors and permissions. The NDA and data-processing terms are completed before any file transfer.
RuleDiff and the historical human implementation are run as blinded baselines. Your accountable policy owners then adjudicate the in-scope document universe. The report shows incremental findings, misses, false positives, uncertainty, review time and scan coverage.
Group policy or compliance approves the parent change; local owners classify findings and exceptions; the accountable policy owner accepts the final evidence record.
Dotaction
Dotaction is a Netherlands-based B2B software company. We develop RuleDiff for organisations that need to prove how approved policy changes reached operational documents in Microsoft 365.
Built for Microsoft 365
RuleDiff combines Microsoft cloud architecture, semantic policy analysis and native Office document engineering. It adds an assurance layer while your repositories, permissions and approval processes remain authoritative.
Start with evidence
Bring one completed policy rollout, three entities and the documents that should have inherited the change. We will respond personally with a proposed blind back-test scope.
Prefer email? Write to contact@dotaction.io.
Dotaction in the Netherlands controls the information submitted on this site. There are no advertising trackers. Your browser's session storage preserves an unsent draft. When you submit the form, an Azure Function processes the information and forwards it to Dotaction's monitored inbox; Azure operational logs may temporarily contain submission data. Enquiries are processed on the basis of Dotaction's legitimate interest in responding and reviewed for deletion after 30 days unless needed for an active business conversation or legal obligation. Information is not sold or used for model training. You can instead email contact@dotaction.io. To request access, correction, deletion, restriction or objection, or to report a security concern, use the same address. You may also complain to the Dutch Autoriteit Persoonsgegevens.