Hey everyone, been using Sprinto for a few months now to manage our SOC 2 compliance. Just saw the announcement about the new AI policy generator feature and jumped in to test it with our dev team's access review policy.
First impressions are... mixed? It's incredibly fast at drafting a baseline document, and the language is definitely more polished than my first pass usually is. But I'm curious how others are handling the "specificity gap."
For example, it generated a solid policy about quarterly access reviews for our SaaS platform. But it didn't know to include our specific rule about revoking vendor access within 24 hours after contract termination. I had to manually insert that critical bit.
So my question for the community: are you using this as a true first draft, or more of a template library? Have you found ways to "train" it or feed it context so the outputs are more tailored to your actual workflows?
Also, from a product analytics angle, I'm wondering if they're planning to let you seed it with your existing policy snippets. That would be a game-changer for iterative updates. Right now, I feel like I'm getting 70% there instantly, but that last 30% of company-specific nuance takes just as long as writing from scratch. 😅
What's everyone else's experience been? Are there certain policy types where it's shining?