Appearance
Policy Setup Wizard
Set up your organization's AI governance policies in minutes with the guided Policy Setup Wizard. Answer a few questions and VeriPrompt auto-configures routing, access controls, data protection, and compliance settings for your entire company.
Overview
The Policy Setup Wizard is a 6-step guided dialogue designed for company administrators and CISOs. Instead of manually configuring dozens of individual settings, the wizard asks focused questions about your organization and use cases, then applies smart defaults across all configuration domains in a single step.
Who it's for:
- Account Owners setting up a new organization
- Account Admins reconfiguring policies after organizational changes
- CISOs establishing AI governance guardrails
What it configures:
- Routing policies (provider selection, geo-fencing, cost/quality/speed priorities)
- Provider access policies (BYOK, platform keys, provider restrictions)
- Data protection (PII sanitization mode, encryption, data retention)
- Access profiles and role-based permissions
- Chat role policies with token limits
- Geofencing rules for data processing locations
- Spending budgets and guardrails
When Does the Wizard Appear?
First Login (Auto-Redirect)
When an Account Owner or Admin logs in for the first time and the company has no policies configured yet, VeriPrompt automatically redirects to the wizard. You can click "Skip for now" to explore the platform first — a reminder banner will appear on the Hub page so you can start the wizard later.
Settings Page (Anytime)
You can always access the wizard from Settings → Reconfigure Policies. This is useful when:
- Your organization's compliance requirements change
- You expand to new regions
- You onboard new teams or departments
- You want to update spending limits
The 6 Steps
Step 1: Use Cases
Select what you'll primarily use VeriPrompt for. You can choose multiple:
| Use Case | What It Configures |
|---|---|
| Compliant AI Access | Strict sanitization, encryption, budget limits, security-first routing |
| Prompt Libraries | Quality-focused routing, project organization, team roles |
| AI Development | Speed-focused routing, BYOK access, developer profiles |
| AI Routing Gateway | Balanced routing, mixed provider access |
| API Prompt Execution | Cost-optimized routing, API key generation |
| Data Protection | Automatic PII sanitization, encryption enabled, minimal retention |
Your selections drive the smart defaults for all subsequent steps.
Step 2: Organization & Compliance
Organization type — Determines baseline compliance expectations:
- Technology / Software
- Financial Services / Banking
- Healthcare / Pharma
- Government / Public Sector
- Legal / Professional Services
- Education / Research
Compliance frameworks — Select all that apply:
- GDPR (auto-enables encryption, EU geo-fence suggestion)
- HIPAA (auto-enables encryption, US-only suggestion)
- SOC 2, ISO 27001, PCI DSS
Data processing location — Control where your AI requests are processed:
- Quick presets:
EU only|US only|EU + US|No restrictions - Or manually search and select specific regions and countries
- Toggle between "Allow only selected" and "Block selected" modes
Step 3: Team Structure
Team size:
- Individual (skips role setup)
- Small Team (2–10)
- Department (10–50)
- Enterprise (50+)
Projects: Choose whether to organize work into separate projects with scoped policies.
Roles: Select which role profiles to create:
| Role | Access Level |
|---|---|
| Admins | Full configuration, user management, billing |
| Developers | API access, prompt building, analytics |
| Business Users | Chat-only access with curated prompts |
| Security Reviewers | Read-only audit and monitoring access |
Each selected role creates a pre-configured Access Profile with appropriate permissions.
Step 4: AI Providers & Routing
Provider access mode:
- VeriPrompt Pooled Keys — Simplest setup, pay per use
- BYOK (Bring Your Own Keys) — Full control over provider accounts
- Mixed — Combine platform and own keys
Routing priority — How VeriPrompt ranks providers:
- Cost Optimization
- Quality First
- Speed (lowest latency)
- Security (most compliant only)
- Balanced
Provider restrictions (shown for regulated organizations):
- All Providers
- Major Only (OpenAI, Anthropic, Google)
- Custom Whitelist
Step 5: Data Protection & Guardrails
PII Sanitization:
- Automatic — All prompts scanned and sanitized before reaching providers
- Manual — Users choose when to sanitize per conversation
- Disabled — No sanitization
Encryption at rest: AES-256 encryption for all stored data.
Data retention: How long to keep data:
- Minimal (7 days) — Security-first
- Standard (30 days) — Balanced
- Extended (90 days) — For audit trails
- Custom — Set individual retention for data, logs, and responses
Spending limits:
- Per-user monthly budget
- Company-wide monthly budget
- No limits
Budget amounts are displayed in your company's local currency (auto-detected from your company profile).
Step 6: Review & Apply
Review all your selections in a clear summary card. For each section you can:
- Edit — Navigate back to any step to change settings
- Export JSON — Download your configuration for review or approval by stakeholders
- Apply All — Creates all policies, profiles, and settings in a single operation
Smart Defaults
The wizard pre-fills sensible defaults based on your selections. For example, if you select "Financial Services" + "GDPR" + "Compliant AI Access":
- Encryption: Enabled
- PII Sanitization: Automatic
- Data Retention: 7 days
- Routing: Security-first
- Provider Restriction: Major providers only
- BYOK: Required
- Budget Limits: Enabled
You can always override any pre-filled value.
State Persistence
If you close or refresh the browser mid-wizard, your progress is automatically saved. When you return to the wizard, you'll continue from where you left off.
What Gets Created
When you click "Apply All", VeriPrompt creates or updates in a single transaction:
| Record | Description |
|---|---|
| Company Settings | GDPR compliance, encryption, retention days |
| Routing Policy | Company default with geo-fence rules and routing weights |
| Provider Access Policy | BYOK settings, allowed providers, budget limits |
| Geofencing Policy | Region/country restrictions (if configured) |
| Access Profiles | One per selected role with appropriate permissions |
| Chat Role Policies | Token limits and retention per role |
| Audit Log | ONBOARDING_SETUP_COMPLETED with all selections recorded |
Re-Running the Wizard
When you re-run the wizard from Settings, it updates existing records rather than creating duplicates. Your routing policy, access profiles, and other settings are modified in place.
API Reference
The wizard uses the Onboarding Setup API:
GET /api/v1/onboarding/setup
Returns the current onboarding state for the company.
Response:
json
{
"success": true,
"isConfigured": true,
"company": {
"gdprCompliant": true,
"encryptionEnabled": true,
"dataRetentionDays": 7
},
"hasProviderAccessPolicy": true,
"accessProfiles": [
{ "id": "clx...", "name": "Company Admin" },
{ "id": "clx...", "name": "Developer" }
],
"hasGeofencingPolicy": true
}POST /api/v1/onboarding/setup
Applies the full onboarding configuration.
Request body:
json
{
"useCases": ["compliant_access", "data_protection"],
"organizationType": "finance",
"complianceFrameworks": ["GDPR", "SOC2"],
"geoProcessing": {
"mode": "allow",
"regions": ["EU"],
"countries": []
},
"teamSize": "department",
"enableProjects": true,
"roles": ["admins", "developers", "business_users"],
"providerAccess": "byok",
"routingPriority": "security",
"providerRestriction": "major",
"sanitizationMode": "automatic",
"encryptionEnabled": true,
"dataRetention": "7",
"budgetMode": "company",
"budgetAmount": 10000
}Access: ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN
Troubleshooting
Q: I skipped the wizard. How do I start it? Go to Settings → Reconfigure Policies or navigate directly to /onboarding/setup.
Q: Will re-running the wizard duplicate my policies? No. The wizard updates existing records. Your routing policy ID and access profile IDs remain the same.
Q: I selected the wrong compliance framework. Can I change it? Yes. Re-run the wizard from Settings and update your compliance selections. The existing policies will be updated accordingly.
Q: Why don't I see the provider restriction question? This question only appears when you've selected a regulated organization type (Finance, Healthcare, Government, Legal) or compliance frameworks in Step 2.
Related Features
- Intelligent Routing — Deep dive into routing policies
- PII Sanitization — How sanitization works
- BYOK (Bring Your Own Key) — Managing your own API keys
- Zero-Knowledge Encryption — Encryption architecture
