Skip to main content
The compliance remediation policy is a written document, in Markdown, that Primo AI reads before it touches any ticket. Without a published policy it acts on nothing. Publishing it is what switches auto remediation on. A policy can only ever narrow what Primo AI does. No sentence in it grants an action the product forbids — see Limits and platform constraints.

Write it with the assistant

The policy page carries an embedded Primo AI chat. It interviews you and writes the policy for you, grounded in your real compliance rules, your MDM controls, and your fleet — so the draft references the issue types you actually have rather than a generic list.
1

Open the policy

Go to Compliance > Compliance issue settings and open the remediation policy.
2

Answer the assistant's questions

It asks which issues you want worked, how far Primo AI should go on its own, and how it should talk to your employees.
3

Review the draft

The draft is yours to edit directly. The assistant writes it; it does not own it.
4

Publish

Publishing switches auto remediation on and the state chip reads Auto remediation: ON.

Cover the four sections

The policy template is always the same four sections.

Scope

Which issues Primo AI works, and which it never touches. Name them the way they appear in your settings.

What Primo AI does on its own

The fixes it applies without asking, and the cases it hands straight back to your team.

Talking to employees

When it may write to an employee, in which tone and language, and how many messages. Primo AI writes once per issue by default — say so here if you want it narrower.

Company knowledge

Facts about your fleet that change how an issue should be read: which Linux distributions you run, which office’s network blocks the agent, which devices are held in stock, which teams are never written to directly. Primo AI adds to this section itself over time, on an admin’s confirmation — see Read a compliance ticket.

Example policy

Use this as a starting point, then replace every line with your own reality.

Maintain it over time

  • The policy has a draft and a published version. Editing the draft changes nothing until you publish.
  • Unpublishing turns auto remediation off for new tickets. Tickets already assigned to Primo AI stop with a note rather than acting.
  • When Primo AI adds a fact to Company knowledge on your approval, the change is recorded as made by Primo AI, and its note names the admin who approved it.
  • If you have unfinished draft edits, Primo AI saves its addition but skips the publish, and says so.

Contact

If the policy assistant cannot see your rules or controls, or publishing does not switch the state chip to ON, contact support@getprimo.com with:
  • Your company name
  • The time you published
  • A screenshot of the state chip