ISMS Copilot
Product Updates

Chat keeps the document ID you already issued

A policy is one controlled record. If the next draft invents a new ID, you do not have a new version. You have a second document you then have to reconcile.

by ISMS Copilot··5 min read
Chat keeps the document ID you already issued

A compliance file is not finished when the prose looks right. It is finished when it is the same record next week: same ID, same place in the register, a version bump instead of a new identity. ISO/IEC 27001:2022 (published October 2022) is built around documented information that can be identified, reviewed, and replaced on purpose. That is why a policy carries a reference number, not only a title.

Chat used to fight that. You generated an access-control policy, it left the workspace as POL-005, and the next time you asked for a revision in another thread it minted POL-006. The words were a rewrite. The identity was a new document. Your register, your SoA links, and the file you already sent for review still pointed at the old ID. The assistant had written a lookalike.

That is a document-control failure, not a wording failure.

What we shipped

In a workspace, standard chat can now reuse a document ID that already exists instead of inventing the next number in the sequence.

When a generated file includes a document ID (for example POL-005, or a Document ID: / Dokument-ID: line), later chat in that same workspace can keep it. The list comes from documents you have already exported in the workspace, including other conversations. You do not turn anything on. There is no extra mode.

This is live in Fast and Think. It does not apply to Beyond, to Agent Tasks, or to generate-from-API / MCP. If a later draft still invents a new ID, say the existing one in the prompt. The help page states the same limits.

This sits next to a quieter July fix: once a document is generated, identifier lines (document ID, version, classification, owner, approver, dates) stay in the Word, PDF, and Markdown download instead of being stripped as if they were pipeline metadata. Keeping the ID through export was step one. Making the next draft see that ID is step two.

Before and after

Before, chat could lose track of IDs issued in other conversations and might invent or continue a different sequence. POL-005 became POL-006, or ISMS-POL-004 if the prompt used a different house style. You either accepted a growing pile of lookalikes, or you pasted the real ID back into the prompt every time, or you fixed the header by hand after download. None of those is document control. They are cleanup.

After, chat in that workspace can see the IDs that already left as files. Ask for a revision of the access-control policy and the draft can keep POL-005. The version line can move. The identity does not have to.

It will not invent a numbering scheme for you, and it will not assign IDs as a policy. If the earlier file never carried a document ID, there is nothing to reuse. If you want a brand-new record, ask for one. The change is that the default no longer has to be "mint the next code."

Why the ID is the product

Frontier models are good at drafting a policy. They are not good at remembering that last Tuesday's Word file is the same controlled record as this morning's rewrite. That memory is not in the model. It is in the workspace: the files you already exported, the IDs those files already carry.

The bet is the same one behind point-level citations and finding a past conversation. For serious compliance work, the valuable move is not a longer answer. It is an answer that stays attached to the thing you already decided. A citation that names the paragraph. A thread you can find again. A document that keeps its ID.

Without that, chat produces files. With it, chat can produce the next version of a document.

Who it is for

  • Practitioners maintaining an ISMS document set, who already have IDs in a register and cannot afford a rewrite that silently becomes a second policy.
  • Consultants running one workspace per client, who generate a pack over several conversations and need the access-control policy to stay POL-005 on Tuesday after it was POL-005 on Monday.
  • Anyone reviewing a generated pack against a Statement of Applicability or a document register, where a changed ID looks like a new controlled document even when the intent was a version.

If you generate one-off notes and never put an ID on them, nothing here will bother you. The page earns its keep when the header is load-bearing.

Try it

Open a workspace that already has exported generated documents with document IDs. In Fast or Think, ask for a revision of one of those documents. The new draft should keep the existing ID. If it does not, put the ID in the prompt and generate again.

A rewrite that changes the identity is not a version. It is a new document you now have to explain. Chat should not do that by default.

Related Posts