Appearance
Hop And Haul Policy Index
Document ID: PLCY-IDX-001
Version: 1.8
Effective Date: January 21, 2026
Last Review: January 21, 2026
Owner: Hop And Haul Team
CONFIDENTIAL
This document is CONFIDENTIAL and for internal use only. Do not distribute outside the organization.
1. Purpose
This document serves as the authoritative index of all Hop And Haul policy documents, establishing governance structure, ownership, review cadence, and regulatory mapping.
2. Policy Document Registry
SaaS Model
Hop And Haul is a SaaS platform. See Governance & Assumptions for role definitions and responsibility boundaries.
| Document ID | Title | Version | Owner | Last Review | Next Review |
|---|---|---|---|---|---|
| PLCY-GOV-001 | Governance & Assumptions | 1.0 | Hop And Haul Team | Dec 22, 2025 | Quarterly |
| PLCY-SYS-001 | System Description | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-BUF-001 | Safety Buffer Parameters | 1.2 | Hop And Haul Team | Jan 21, 2026 | Jun 2026 |
| PLCY-LIA-001 | Accident & Liability Framework | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-INC-001 | Incident Response Procedures | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-VOI-001 | Voice Agent Integration Policy | 1.7 | Hop And Haul Team | Jan 21, 2026 | Jun 2026 |
| PLCY-VOI-002 | Voice Agent Technical Specification | 1.2 | Hop And Haul Team | Jan 21, 2026 | Jun 2026 |
| PLCY-VOI-003 | Voice Escalation Procedures | 1.1 | Hop And Haul Team | Jan 21, 2026 | Jun 2026 |
| PLCY-COM-001 | Driver Communication Policy | 3.0 | Hop And Haul Team | Jan 21, 2026 | Jun 2026 |
| PLCY-ADM-002 | Admin Call Routing Configuration | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-VAL-001 | Pre-Transaction Validation | 1.1 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-SEC-001 | Security Controls | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-ACC-001 | Access Control Matrix | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-DATA-001 | Data Classification Policy | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-AUD-001 | Audit Trail Specifications | 1.2 | Hop And Haul Team | Jan 21, 2026 | Dec 2026 |
| PLCY-CON-001 | Consent & Authorization Log | 1.2 | Hop And Haul Team | Jan 21, 2026 | Dec 2026 |
| PLCY-FIN-001 | Financial Controls | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-RAT-001 | Rating System Policy | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-RET-001 | Records Retention Policy | 1.0 | Hop And Haul Team | Dec 22, 2025 | Dec 2026 |
| PLCY-CTL-001 | Control Testing Procedures | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-DRP-001 | Disaster Recovery Plan | 1.1 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-RSK-001 | Risk Assessment Policy | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-INF-001 | Infrastructure Sizing | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-ORG-001 | Organization & Domain Policy | 1.0 | Hop And Haul Team | Dec 22, 2025 | Jun 2026 |
| PLCY-FRP-001 | Findings & Remediation Plan | 1.0 | Hop And Haul Team | Dec 22, 2025 | Quarterly |
| PLCY-IDX-001 | Policy Index (this document) | 1.8 | Hop And Haul Team | Jan 21, 2026 | Quarterly |
2.1 Federal Compliance Documents
| Document ID | Title | Version | Owner | Last Review | Next Review |
|---|---|---|---|---|---|
| PLCY-FED-001 | Federal Compliance Overview | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-FED-002 | SSP-Lite (System Security Plan) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-FED-003 | Risk Register (Federal) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-FED-004 | Development Roadmap | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-FED-005 | Control Mapping Matrix | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-NIST-AC-001 | NIST Access Control Policy (AC) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-NIST-AU-001 | NIST Audit & Accountability Policy (AU) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-NIST-IR-001 | NIST Incident Response Policy (IR) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-NIST-CMSI-001 | NIST Config Mgmt & Integrity Policy (CM/SI) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
| PLCY-NIST-SA-001 | NIST Vendor Risk Management Policy (SA) | 1.0 | Hop And Haul Team | Dec 30, 2025 | Jun 2026 |
3. Trust Service Criteria Mapping
3.1 Common Criteria (CC) Coverage
| Criteria | Description | Primary Documents |
|---|---|---|
| CC1 | Control Environment | PLCY-IDX-001, PLCY-SYS-001 |
| CC2 | Communication & Information | PLCY-COM-001, PLCY-VOI-001, PLCY-AUD-001 |
| CC3 | Risk Assessment | PLCY-BUF-001, PLCY-INC-001, PLCY-RSK-001 |
| CC4 | Monitoring Activities | PLCY-CTL-001, PLCY-AUD-001 |
| CC5 | Control Activities | PLCY-VAL-001, PLCY-SEC-001 |
| CC6 | Logical/Physical Access | PLCY-ACC-001, PLCY-SEC-001 |
| CC7 | System Operations | PLCY-INC-001, PLCY-SYS-001 |
| CC8 | Change Management | PLCY-SEC-001 |
| CC9 | Risk Mitigation | PLCY-LIA-001, PLCY-BUF-001 |
3.2 Availability Criteria Coverage
| Criteria | Description | Primary Documents |
|---|---|---|
| A1.1 | Capacity Planning | PLCY-SYS-001, PLCY-DRP-001 |
| A1.2 | Recovery Objectives | PLCY-INC-001, PLCY-DRP-001 |
| A1.3 | Testing Recovery | PLCY-INC-001, PLCY-DRP-001, PLCY-RSK-001 |
3.3 Confidentiality Criteria Coverage
| Criteria | Description | Primary Documents |
|---|---|---|
| C1.1 | Identify Confidential Info | PLCY-DATA-001 |
| C1.2 | Dispose Confidential Info | PLCY-DATA-001, PLCY-RET-001 |
3.4 Processing Integrity Coverage
| Criteria | Description | Primary Documents |
|---|---|---|
| PI1.1 | Input Validation | PLCY-VAL-001 |
| PI1.2 | Processing Controls | PLCY-VAL-001, PLCY-FIN-001 |
| PI1.3 | Output Review | PLCY-AUD-001 |
3.5 Privacy Criteria Coverage
| Criteria | Description | Primary Documents |
|---|---|---|
| P1-P8 | Privacy Principles | PLCY-DATA-001, PLCY-CON-001 |
4. Regulatory Alignment Matrix
| Regulation | Applicable Documents |
|---|---|
| 49 CFR 392.80 (Texting prohibition) | PLCY-COM-001, PLCY-VOI-001 |
| 49 CFR 392.82 (Handheld phone prohibition) | PLCY-COM-001, PLCY-VOI-001 |
| 49 CFR 390.6 (Coercion prohibition) | PLCY-COM-001, PLCY-VOI-001, PLCY-RAT-001 |
| FMCSA HOS regulations | PLCY-VAL-001, PLCY-BUF-001 |
| DOT accident reporting | PLCY-LIA-001, PLCY-INC-001 |
| State recording consent laws | PLCY-VOI-001, PLCY-CON-001 |
| Workers' compensation | PLCY-LIA-001 |
| IRS worker classification | PLCY-FIN-001, PLCY-SYS-001 |
5. NIST 800-53 Control Family Mapping
5.1 FedRAMP Moderate Baseline Coverage
| Control Family | Family Name | Primary Documents | Coverage |
|---|---|---|---|
| AC | Access Control | PLCY-SEC-001, PLCY-ACC-001, PLCY-NIST-AC-001 | 80% |
| AT | Awareness & Training | PLCY-RSK-001 | 67% |
| AU | Audit & Accountability | PLCY-AUD-001, PLCY-NIST-AU-001 | 94% |
| CA | Assessment & Authorization | PLCY-CTL-001 | 56% |
| CM | Configuration Management | PLCY-SEC-001, PLCY-DRP-001, PLCY-NIST-CMSI-001 | 82% |
| CP | Contingency Planning | PLCY-DRP-001 | 92% |
| IA | Identification & Authentication | PLCY-SEC-001 | 83% |
| IR | Incident Response | PLCY-INC-001, PLCY-NIST-IR-001 | 90% |
| MA | Maintenance | PLCY-DRP-001 | 67% |
| MP | Media Protection | PLCY-RET-001 | 75% |
| PE | Physical & Environmental | N/A (Inherited from AWS) | 100% |
| PL | Planning | PLCY-FED-004 | 78% |
| PM | Program Management | PLCY-IDX-001 | 75% |
| PS | Personnel Security | N/A (Inherited) | 100% |
| RA | Risk Assessment | PLCY-RSK-001, PLCY-FED-003 | 89% |
| SA | System & Services Acquisition | PLCY-NIST-SA-001 | 64% |
| SC | System & Communications | PLCY-SEC-001 | 78% |
| SI | System & Information Integrity | PLCY-SEC-001, PLCY-NIST-CMSI-001 | 78% |
| SR | Supply Chain Risk | PLCY-NIST-SA-001 | 58% |
5.2 Federal Compliance Documents
| Document ID | Title | NIST Families |
|---|---|---|
| PLCY-FED-001 | Federal Compliance Overview | All |
| PLCY-FED-002 | SSP-Lite | All |
| PLCY-FED-003 | Risk Register (Federal) | RA, PM |
| PLCY-FED-004 | Development Roadmap | PL, PM |
| PLCY-FED-005 | Control Mapping Matrix | All |
| PLCY-NIST-AC-001 | Access Control Policy | AC |
| PLCY-NIST-AU-001 | Audit & Accountability Policy | AU |
| PLCY-NIST-IR-001 | Incident Response Policy | IR |
| PLCY-NIST-CMSI-001 | Config Mgmt & Integrity Policy | CM, SI |
| PLCY-NIST-SA-001 | Vendor Risk Management Policy | SA, SR |
For detailed control-by-control mapping, see Control Mapping Matrix.
6. Review Schedule
6.1 Review Frequency
| Frequency | Documents |
|---|---|
| Quarterly | PLCY-FRP-001, PLCY-IDX-001 |
| Semi-Annual | PLCY-BUF-001, PLCY-INC-001, PLCY-VOI-001, PLCY-COM-001, PLCY-VAL-001, PLCY-SEC-001, PLCY-ACC-001, PLCY-CTL-001, PLCY-DRP-001, PLCY-RSK-001, PLCY-INF-001, PLCY-ORG-001 |
| Annual | PLCY-SYS-001, PLCY-LIA-001, PLCY-DATA-001, PLCY-AUD-001, PLCY-CON-001, PLCY-FIN-001, PLCY-RAT-001, PLCY-RET-001 |
6.2 Review Triggers (Outside Scheduled)
- Significant incident requiring policy change
- Regulatory update affecting covered topics
- Audit finding requiring remediation
- Material change in operations
- New product/feature launch
7. Document Ownership
All policy documents are owned and maintained by the Hop And Haul Team.
Customer Roles (Fleet Operator - Not Hop And Haul Staff)
Where policies reference operational roles like "Safety Director" or "Operations Manager," these refer to customer staff, not Hop And Haul employees. See Governance & Assumptions for details.
8. Cross-Reference Dependencies
| Document | References | Referenced By |
|---|---|---|
| PLCY-BUF-001 | - | PLCY-VOI-001 |
| PLCY-RET-001 | - | PLCY-LIA-001, PLCY-INC-001, PLCY-DATA-001, PLCY-AUD-001, PLCY-SEC-001, PLCY-DRP-001 |
| PLCY-VAL-001 | PLCY-BUF-001 | PLCY-SYS-001, PLCY-LIA-001 |
| PLCY-COM-001 | PLCY-BUF-001 | PLCY-VOI-001 |
| PLCY-SEC-001 | - | PLCY-ACC-001, PLCY-DATA-001, PLCY-DRP-001, PLCY-RSK-001, PLCY-INF-001 |
| PLCY-INC-001 | PLCY-VOI-001 | PLCY-LIA-001, PLCY-DRP-001, PLCY-RSK-001 |
| PLCY-DRP-001 | PLCY-INC-001, PLCY-SEC-001, PLCY-AUD-001, PLCY-RET-001 | PLCY-RSK-001, PLCY-INF-001 |
| PLCY-RSK-001 | PLCY-DRP-001, PLCY-INC-001, PLCY-SEC-001, PLCY-AUD-001 | - |
| PLCY-INF-001 | PLCY-DRP-001, PLCY-SEC-001, PLCY-RSK-001 | - |
| PLCY-ORG-001 | PLCY-ACC-001, PLCY-SEC-001, PLCY-RET-001, PLCY-DATA-001 | - |
9. Version Control Standards
9.1 Version Numbering
- Major version (X.0): Significant restructuring or scope change
- Minor version (X.Y): Content additions or modifications
- Patches: Tracked in document control section
9.2 Change Documentation
All policy changes require:
- Version increment
- Date update
- Author attribution
- Change summary in document control section
9.3 Approval Requirements
| Change Type | Required Approvers |
|---|---|
| New policy | Document owner + Executive sponsor |
| Major revision | Document owner + Compliance Manager |
| Minor revision | Document owner |
| Emergency change | Any executive + Compliance review within 48 hours |
10. Document Control
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | December 22, 2025 | Hop And Haul Team | Initial release |
| 1.1 | December 22, 2025 | Hop And Haul Team | Added PLCY-INF-001, PLCY-ORG-001; updated DRP to 1.1 |
| 1.2 | December 22, 2025 | Hop And Haul Team | Added PLCY-GOV-001 |
| 1.3 | December 22, 2025 | Hop And Haul Team | Updated PLCY-BUF-001, PLCY-VAL-001 to v1.1 (HOS/ELD, same-day constraints) |
| 1.4 | December 30, 2025 | Hop And Haul Team | Added Federal Compliance section and NIST 800-53 mapping |
| 1.5 | December 30, 2025 | Hop And Haul Team | Added PLCY-VOI-002, PLCY-VOI-003, PLCY-ADM-002 (Voice Agent technical docs) |
| 1.6 | December 30, 2025 | Hop And Haul Team | Updated PLCY-VOI-001 to v1.5, PLCY-VOI-002 to v1.1 (dispatch coordination model, one-touch headset prerequisite, Samsara route updates) |
| 1.7 | January 2, 2026 | Hop And Haul Team | Samsara Messages Integration: Updated PLCY-COM-001 to v2.0 (Samsara Messages API as primary communication, voice as last resort), PLCY-VOI-001 to v1.6 (voice fallback section), PLCY-AUD-001 to v1.1 (Samsara Message events), PLCY-CON-001 to v1.1 (new consent_method values) |
| 1.8 | January 21, 2026 | Hop And Haul Team | Driver Communication Policy v3.0: Replaced PLCY-COM-001 with new policy structure (voice-first, 15-min buffers, 5-min response window, standard call scripts, prohibited language, driver rights). Updated: PLCY-VOI-001 to v1.7, PLCY-VOI-002 to v1.2, PLCY-VOI-003 to v1.1 (aligned with new policy). PLCY-BUF-001 to v1.2 (15-min buffer requirement). PLCY-CON-001 to v1.2 (driver rights). PLCY-AUD-001 to v1.2 (new event types). |