Skip to content

Policy Setup Wizard ​

Set up your organization's AI governance policies in minutes with the guided Policy Setup Wizard. Answer a few questions and VeriPrompt auto-configures routing, access controls, data protection, and compliance settings for your entire company.

Overview ​

The Policy Setup Wizard is a 6-step guided dialogue designed for company administrators and CISOs. Instead of manually configuring dozens of individual settings, the wizard asks focused questions about your organization and use cases, then applies smart defaults across all configuration domains in a single step.

Who it's for:

  • Account Owners setting up a new organization
  • Account Admins reconfiguring policies after organizational changes
  • CISOs establishing AI governance guardrails

What it configures:

  • Routing policies (provider selection, geo-fencing, cost/quality/speed priorities)
  • Provider access policies (BYOK, platform keys, provider restrictions)
  • Data protection (PII sanitization mode, encryption, data retention)
  • Access profiles and role-based permissions
  • Chat role policies with token limits
  • Geofencing rules for data processing locations
  • Spending budgets and guardrails

When Does the Wizard Appear? ​

First Login (Auto-Redirect) ​

When an Account Owner or Admin logs in for the first time and the company has no policies configured yet, VeriPrompt automatically redirects to the wizard. You can click "Skip for now" to explore the platform first — a reminder banner will appear on the Hub page so you can start the wizard later.

Settings Page (Anytime) ​

You can always access the wizard from Settings → Reconfigure Policies. This is useful when:

  • Your organization's compliance requirements change
  • You expand to new regions
  • You onboard new teams or departments
  • You want to update spending limits

The 6 Steps ​

Step 1: Use Cases ​

Select what you'll primarily use VeriPrompt for. You can choose multiple:

Use CaseWhat It Configures
Compliant AI AccessStrict sanitization, encryption, budget limits, security-first routing
Prompt LibrariesQuality-focused routing, project organization, team roles
AI DevelopmentSpeed-focused routing, BYOK access, developer profiles
AI Routing GatewayBalanced routing, mixed provider access
API Prompt ExecutionCost-optimized routing, API key generation
Data ProtectionAutomatic PII sanitization, encryption enabled, minimal retention

Your selections drive the smart defaults for all subsequent steps.

Step 2: Organization & Compliance ​

Organization type — Determines baseline compliance expectations:

  • Technology / Software
  • Financial Services / Banking
  • Healthcare / Pharma
  • Government / Public Sector
  • Legal / Professional Services
  • Education / Research

Compliance frameworks — Select all that apply:

  • GDPR (auto-enables encryption, EU geo-fence suggestion)
  • HIPAA (auto-enables encryption, US-only suggestion)
  • SOC 2, ISO 27001, PCI DSS

Data processing location — Control where your AI requests are processed:

  • Quick presets: EU only | US only | EU + US | No restrictions
  • Or manually search and select specific regions and countries
  • Toggle between "Allow only selected" and "Block selected" modes

Step 3: Team Structure ​

Team size:

  • Individual (skips role setup)
  • Small Team (2–10)
  • Department (10–50)
  • Enterprise (50+)

Projects: Choose whether to organize work into separate projects with scoped policies.

Roles: Select which role profiles to create:

RoleAccess Level
AdminsFull configuration, user management, billing
DevelopersAPI access, prompt building, analytics
Business UsersChat-only access with curated prompts
Security ReviewersRead-only audit and monitoring access

Each selected role creates a pre-configured Access Profile with appropriate permissions.

Step 4: AI Providers & Routing ​

Provider access mode:

  • VeriPrompt Pooled Keys — Simplest setup, pay per use
  • BYOK (Bring Your Own Keys) — Full control over provider accounts
  • Mixed — Combine platform and own keys

Routing priority — How VeriPrompt ranks providers:

  • Cost Optimization
  • Quality First
  • Speed (lowest latency)
  • Security (most compliant only)
  • Balanced

Provider restrictions (shown for regulated organizations):

  • All Providers
  • Major Only (OpenAI, Anthropic, Google)
  • Custom Whitelist

Step 5: Data Protection & Guardrails ​

PII Sanitization:

  • Automatic — All prompts scanned and sanitized before reaching providers
  • Manual — Users choose when to sanitize per conversation
  • Disabled — No sanitization

Encryption at rest: AES-256 encryption for all stored data.

Data retention: How long to keep data:

  • Minimal (7 days) — Security-first
  • Standard (30 days) — Balanced
  • Extended (90 days) — For audit trails
  • Custom — Set individual retention for data, logs, and responses

Spending limits:

  • Per-user monthly budget
  • Company-wide monthly budget
  • No limits

Budget amounts are displayed in your company's local currency (auto-detected from your company profile).

Step 6: Review & Apply ​

Review all your selections in a clear summary card. For each section you can:

  • Edit — Navigate back to any step to change settings
  • Export JSON — Download your configuration for review or approval by stakeholders
  • Apply All — Creates all policies, profiles, and settings in a single operation

Smart Defaults ​

The wizard pre-fills sensible defaults based on your selections. For example, if you select "Financial Services" + "GDPR" + "Compliant AI Access":

  • Encryption: Enabled
  • PII Sanitization: Automatic
  • Data Retention: 7 days
  • Routing: Security-first
  • Provider Restriction: Major providers only
  • BYOK: Required
  • Budget Limits: Enabled

You can always override any pre-filled value.

State Persistence ​

If you close or refresh the browser mid-wizard, your progress is automatically saved. When you return to the wizard, you'll continue from where you left off.

What Gets Created ​

When you click "Apply All", VeriPrompt creates or updates in a single transaction:

RecordDescription
Company SettingsGDPR compliance, encryption, retention days
Routing PolicyCompany default with geo-fence rules and routing weights
Provider Access PolicyBYOK settings, allowed providers, budget limits
Geofencing PolicyRegion/country restrictions (if configured)
Access ProfilesOne per selected role with appropriate permissions
Chat Role PoliciesToken limits and retention per role
Audit LogONBOARDING_SETUP_COMPLETED with all selections recorded

Re-Running the Wizard ​

When you re-run the wizard from Settings, it updates existing records rather than creating duplicates. Your routing policy, access profiles, and other settings are modified in place.

API Reference ​

The wizard uses the Onboarding Setup API:

GET /api/v1/onboarding/setup ​

Returns the current onboarding state for the company.

Response:

json
{
  "success": true,
  "isConfigured": true,
  "company": {
    "gdprCompliant": true,
    "encryptionEnabled": true,
    "dataRetentionDays": 7
  },
  "hasProviderAccessPolicy": true,
  "accessProfiles": [
    { "id": "clx...", "name": "Company Admin" },
    { "id": "clx...", "name": "Developer" }
  ],
  "hasGeofencingPolicy": true
}

POST /api/v1/onboarding/setup ​

Applies the full onboarding configuration.

Request body:

json
{
  "useCases": ["compliant_access", "data_protection"],
  "organizationType": "finance",
  "complianceFrameworks": ["GDPR", "SOC2"],
  "geoProcessing": {
    "mode": "allow",
    "regions": ["EU"],
    "countries": []
  },
  "teamSize": "department",
  "enableProjects": true,
  "roles": ["admins", "developers", "business_users"],
  "providerAccess": "byok",
  "routingPriority": "security",
  "providerRestriction": "major",
  "sanitizationMode": "automatic",
  "encryptionEnabled": true,
  "dataRetention": "7",
  "budgetMode": "company",
  "budgetAmount": 10000
}

Access: ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN

Troubleshooting ​

Q: I skipped the wizard. How do I start it? Go to Settings → Reconfigure Policies or navigate directly to /onboarding/setup.

Q: Will re-running the wizard duplicate my policies? No. The wizard updates existing records. Your routing policy ID and access profile IDs remain the same.

Q: I selected the wrong compliance framework. Can I change it? Yes. Re-run the wizard from Settings and update your compliance selections. The existing policies will be updated accordingly.

Q: Why don't I see the provider restriction question? This question only appears when you've selected a regulated organization type (Finance, Healthcare, Government, Legal) or compliance frameworks in Step 2.