Chat keeps the document ID you already issued
A policy is one controlled record. If the next draft invents a new ID, you do not have a new version. You have a second document you then have to reconcile.

A compliance file is not finished when the prose looks right. It is finished when it is the same record next week: same ID, same place in the register, a version bump instead of a new identity. ISO/IEC 27001:2022 (published October 2022) is built around documented information that can be identified, reviewed, and replaced on purpose. That is why a policy carries a reference number, not only a title.
Chat used to fight that. You generated an access-control policy, it left the workspace as POL-005, and the next time you asked for a revision in another thread it minted POL-006. The words were a rewrite. The identity was a new document. Your register, your SoA links, and the file you already sent for review still pointed at the old ID. The assistant had written a lookalike.
That is a document-control failure, not a wording failure.
What we shipped
In a workspace, standard chat can now reuse a document ID that already exists instead of inventing the next number in the sequence.
When a generated file includes a document ID (for example POL-005, or a Document ID: / Dokument-ID: line), later chat in that same workspace can keep it. The list comes from documents you have already exported in the workspace, including other conversations. You do not turn anything on. There is no extra mode.
This is live in Fast and Think. It does not apply to Beyond, to Agent Tasks, or to generate-from-API / MCP. If a later draft still invents a new ID, say the existing one in the prompt. The help page states the same limits.
This sits next to a quieter July fix: once a document is generated, identifier lines (document ID, version, classification, owner, approver, dates) stay in the Word, PDF, and Markdown download instead of being stripped as if they were pipeline metadata. Keeping the ID through export was step one. Making the next draft see that ID is step two.
Before and after
Before, chat could lose track of IDs issued in other conversations and might invent or continue a different sequence. POL-005 became POL-006, or ISMS-POL-004 if the prompt used a different house style. You either accepted a growing pile of lookalikes, or you pasted the real ID back into the prompt every time, or you fixed the header by hand after download. None of those is document control. They are cleanup.
After, chat in that workspace can see the IDs that already left as files. Ask for a revision of the access-control policy and the draft can keep POL-005. The version line can move. The identity does not have to.
It will not invent a numbering scheme for you, and it will not assign IDs as a policy. If the earlier file never carried a document ID, there is nothing to reuse. If you want a brand-new record, ask for one. The change is that the default no longer has to be "mint the next code."
Why the ID is the product
Frontier models are good at drafting a policy. They are not good at remembering that last Tuesday's Word file is the same controlled record as this morning's rewrite. That memory is not in the model. It is in the workspace: the files you already exported, the IDs those files already carry.
The bet is the same one behind point-level citations and finding a past conversation. For serious compliance work, the valuable move is not a longer answer. It is an answer that stays attached to the thing you already decided. A citation that names the paragraph. A thread you can find again. A document that keeps its ID.
Without that, chat produces files. With it, chat can produce the next version of a document.
Who it is for
- Practitioners maintaining an ISMS document set, who already have IDs in a register and cannot afford a rewrite that silently becomes a second policy.
- Consultants running one workspace per client, who generate a pack over several conversations and need the access-control policy to stay
POL-005on Tuesday after it wasPOL-005on Monday. - Anyone reviewing a generated pack against a Statement of Applicability or a document register, where a changed ID looks like a new controlled document even when the intent was a version.
If you generate one-off notes and never put an ID on them, nothing here will bother you. The page earns its keep when the header is load-bearing.
Try it
Open a workspace that already has exported generated documents with document IDs. In Fast or Think, ask for a revision of one of those documents. The new draft should keep the existing ID. If it does not, put the ID in the prompt and generate again.
A rewrite that changes the identity is not a version. It is a new document you now have to explain. Chat should not do that by default.
Related Posts

Claude is the harness. ISMS Copilot is the GRC specialist.
We are not trying to replace the agent you already use. Keep Claude Code, Cursor, Codex, OpenCode, or Grok for the work. When the task turns into compliance, your agent hands it to a specialist over MCP and gets the answer back.

Run Beyond from the editor you already work in
Fast and Think already followed you into Claude Code and Cursor. The multi-document checking mode lived in the browser. It does not have to.

ISO 27017 moves to the 2026 edition: the assistant reads both citation languages
A 2024 Statement of Applicability cites the 2015 CLD set. A 2026 audit may cite the new controls. The assistant recognizes both editions' citations.
