Controls & Frameworks

Auditor Access

Give an external auditor scoped, time-boxed, read-only access to review a framework and its evidence — without adding them as a full team member.

Overview

When it is time for an audit, you don't have to hand an auditor a full account or email evidence around. The Auditor Portal gives an external auditor a scoped, read-only view of a single framework: its requirements, the controls mapped to them, and the evidence behind each control. Access is limited to the framework you choose and to a time window you set, and you can revoke it at any time.

An auditor invited this way has no standing access to anything else in your organization. Their entire view comes from the access grant you give them, so adding an auditor never exposes the rest of your account.

Auditor access comes with the frameworks add-on. See Adopting frameworks to set that up first.

Inviting an auditor

An Owner or Admin invites an auditor and scopes the invitation to a specific framework and a time period. The auditor receives an invitation, signs in, and lands directly in the portal for that framework.

What the auditor can see

Within the framework you granted, an auditor can:

  • Review each requirement and the controls mapped to it.
  • Open a control to see its tests, status, and attached evidence.
  • Export the framework's requirements, controls, and evidence for their working papers.

The auditor's access is read-only. They cannot change controls, evidence, settings, or anything outside the framework and time window you granted.

Managing and revoking access

You can see active auditor grants, extend or shorten a time window, and revoke access at any point. When the time window ends, access closes on its own — there is no separate cleanup step. Because the grant is scoped to one framework, giving an auditor access to a second framework is a second, separate grant.

Next steps