RuleDiff by Dotaction · Policy cascade assurance

Policy changed.
Did every document follow?

For policy governance, compliance and internal-audit teams in multi-entity organisations: RuleDiff tests whether an approved group-policy change reached the relevant local policies, procedures, forms and guidance.

Today: a fixed-scope Azure pilot. You receive an impact map, cited matches, gaps, contradictions and explicit uncertainty. No tenant integration, source-file changes or automated compliance verdict is required for the back-test.

The implementation gap

The policy is approved once.
Implementation fragments by entity.

A single group requirement can surface differently in local policies, operating procedures, forms, guidance and exceptions.

Teams reconstruct that cascade through spreadsheets, interviews and memory. RuleDiff makes inheritance evidence explicit, comparable and reviewable without replacing existing systems.

Nota GRC replacement

SharePoint and your GRC remain authoritative systems of record.

Nota legal interpretation engine

The back-test starts with a change your organisation approved.

Nota black-box compliance score

Each result includes a citation, reason and explicit uncertainty.

Policy work, made visible

The decision is human.
The evidence should be complete.

Product · RuleDiff

From approved policy
to rollout evidence.

Policy Cascade Backtest

A semantic inheritance-testing layer for Microsoft 365. It connects approved parent requirements to the language used in local policies, procedures, forms and guidance.

Better copilots improve the reasoning layer; RuleDiff retains the durable lineage, versioned rule record, deterministic OOXML patch semantics, evaluation history and approval evidence across model changes.

DOCX-only illustrative policy cascade—not legal advice, compliance assurance or benchmark results · one approved parent change → local evidence → findings → accountable decision

The synthetic example starts with an approved group ICT risk policy change requiring four-hour incident escalation. The workbench compares local documents, identifies a conflicting deadline and shows an illustrative remediation proposal for the accountable owner to review.

01

Freeze the requirement

Record the approved change, scope, effective date, owner and exact source language before testing begins.

02

Test inheritance

Compare how the requirement appears across entities, procedures, forms, guidance and stated exceptions.

03

Explain the finding

Classify addressed, not addressed or cannot determine, with exact passages and conflicts—not a confidence-only score.

04

Seal the evidence

Preserve scan coverage, reviewer decisions and the complete source-to-evidence trail for audit and future change.

The RuleDiff model

Documents become
a testable system.

RuleDiff combines language-model reasoning with deterministic Office document analysis. Each finding carries an explicit verification state and remains subject to human judgment.

01

Reasoning

Find semantic inheritance

AI helps identify where the meaning of an approved parent requirement may appear in differently worded local documents.

Source-linked
02

Verification

Test what can be exact

Dates, thresholds, owners, frequencies, citations and document coverage are checked deterministically.

Repeatable
03

Document engineering

Read the real artifact

Native Open XML parsing preserves headings, tables, lists and locations that text-only retrieval tends to flatten.

Reviewable
04

Governance

Keep decisions human

Named owners confirm whether a finding is a gap, valid local exception, accepted difference or unresolved uncertainty.

Accountable

Initial focus

Multi-entity policy estates.
Regulated operations.

RuleDiff begins where one approved group policy must cascade through many entities, jurisdictions and operational documents: insurance, payments, fintech, energy, healthcare and other regulated organisations.

01
NowPolicy cascade assurance

Parent policies, local policies, procedures, forms and guidance

02
Works withYour existing control plane

SharePoint, Purview, ServiceNow and GRC remain authoritative

03
ReturnsReviewable assurance evidence

Cited passages, contradictions, exceptions and owner decisions

Designed for consequential work

Fast enough for change.
Controlled enough for proof.

01

Each candidate finding cites its source

Reviewers can move from a finding back to the exact parent requirement, local passage and comparison rationale.

02

Security is agreed before access

The pilot data set, tenant permissions, model provider, EU processing location, retention and deletion are written into the scope before files move.

03

Your systems remain authoritative

RuleDiff overlays selected repositories and returns evidence; SharePoint or your GRC keeps ownership, versioning and approval.

04

Approval is explicit

RuleDiff finds and explains. Accountable owners classify, accept or resolve every material finding.

Policy Cascade Backtest

One completed rollout.
Blind-tested.

Ten business days · fixed scope

One approved master-policy change, three entities and up to 30 DOCX policies, procedures, forms or guidance files. We withhold the known historical result, run RuleDiff blind and adjudicate the comparison together—without connecting to your live tenant.

Request a back-test
01

Versioned requirement register

Approved language, scope, effective date, owner and source fingerprint.

02

Cross-entity evidence matrix

Exact passages classified as addressed, not addressed or cannot determine.

03

Gap and contradiction register

Conflicting deadlines, owners, frequencies and scope, plus stated local exceptions.

04

Blind back-test report

Incremental findings, misses, false positives, review effort and next-step economics.

A strong first partner has

One completed policy rolloutwith an approved parent change and a result that can be withheld for blind testing
Entity variation10–30 connected DOCX policies, procedures, forms or guidance across three entities
An accountable ownerin policy governance, compliance, operational risk or internal audit
A reason to improvetime, coverage, consistency or auditability

Before we start

You provide the approved parent-policy change, the complete in-scope DOCX set and a historical result kept from RuleDiff until the blind run is complete. RuleDiff tests policy inheritance; it does not interpret law, certify compliance or modify controlled originals.

How success is judged

RuleDiff and the withheld historical result are compared blind. Your policy owners adjudicate material findings, valid local exceptions, misses and false positives. We also measure review time, document coverage and evidence usability.

Supported in the pilot

Selected DOCX files, including headings, tables, lists, links and numbering. Scanned PDFs, macros, protected or encrypted files, embedded objects and automated translations are excluded unless explicitly scoped and tested. XLSX, PPTX and PDF follow after the DOCX workflow is independently validated.

After the back-test

A successful back-test can progress to a live, read-only SharePoint workflow in a dedicated Azure EU environment with a scoped Microsoft identity. Deployment, integration and recurring terms follow from measured volume and review workflow.

Buyer questions

Know the boundary before the pilot.

Does RuleDiff interpret regulation or certify compliance?

No. Your organisation supplies an approved policy change. RuleDiff tests how its meaning cascaded through the selected document set and exposes evidence for accountable review.

Does it replace SharePoint, Purview, ServiceNow or GRC?

No. It overlays selected repositories and returns an evidence package. Your existing system remains the system of record and its approval workflow remains authoritative.

Where does pilot data go?

The back-test uses only the agreed files. Before transfer, the scope names the Azure EU region, model provider, storage, retention, deletion, subprocessors and permissions. The NDA and data-processing terms are completed before any file transfer.

How do you measure accuracy?

RuleDiff and the historical human implementation are run as blinded baselines. Your accountable policy owners then adjudicate the in-scope document universe. The report shows incremental findings, misses, false positives, uncertainty, review time and scan coverage.

Who approves each step?

Group policy or compliance approves the parent change; local owners classify findings and exceptions; the accountable policy owner accepts the final evidence record.

Dotaction

Product thinking.
Microsoft depth.

Dotaction is a Netherlands-based B2B software company. We develop RuleDiff for organisations that need to prove how approved policy changes reached operational documents in Microsoft 365.

RuleDiff implementationPolicy back-tests, Microsoft 365 integration and document engineering
Diagram showing RuleDiff as an assurance layer across Microsoft 365 documents and human review

Built for Microsoft 365

Native documents. Accountable decisions.

RuleDiff combines Microsoft cloud architecture, semantic policy analysis and native Office document engineering. It adds an assurance layer while your repositories, permissions and approval processes remain authoritative.

Start with evidence

Which change
should we replay?

Bring one completed policy rollout, three entities and the documents that should have inherited the change. We will respond personally with a proposed blind back-test scope.

By sending, you acknowledge the privacy information below. This is not marketing consent.

Prefer email? Write to contact@dotaction.io.

What happens next01 · A 30-minute change review02 · A written back-test scope03 · A mutual go / no-go decision
Privacy, in plain language

Dotaction in the Netherlands controls the information submitted on this site. There are no advertising trackers. Your browser's session storage preserves an unsent draft. When you submit the form, an Azure Function processes the information and forwards it to Dotaction's monitored inbox; Azure operational logs may temporarily contain submission data. Enquiries are processed on the basis of Dotaction's legitimate interest in responding and reviewed for deletion after 30 days unless needed for an active business conversation or legal obligation. Information is not sold or used for model training. You can instead email contact@dotaction.io. To request access, correction, deletion, restriction or objection, or to report a security concern, use the same address. You may also complain to the Dutch Autoriteit Persoonsgegevens.