Inviting an external auditor
Grant a time-boxed, read-only AUDITOR account for an external reviewer, and use Preview as auditor to see exactly what they will see.
Invite an auditor straight from the Team page
On /dashboard/team, open Invite Member and choose Auditor from the Role dropdown. Selecting Auditor reveals an Access window (days) field (1 to 90, defaulting to 30). The option is available to org admins and super admins; managers see it disabled with a note to ask an admin.
What the AUDITOR role means once granted
Every write action is denied to the AUDITOR role, including while an admin is running Preview as auditor. Auditors can browse policies, controls, evidence, and the audit log, and export an audit pack, but cannot change anything.
Access windows are time-boxed
An auditor invite carries an access window of 1 to 90 days (30 by default). When the window passes, the member is automatically soft-revoked (moved to an offboarded access tier) rather than staying active indefinitely.
Summary
- Grant a time-boxed, read-only AUDITOR account for an external reviewer, and use Preview as auditor to see exactly what they will see.
- Use this guide to complete the workflow with audit-ready evidence and ownership.
- If you hit a blocker, run troubleshooting first, then escalate with context.
Steps
1. Preview the experience before granting access
As an org admin, select Preview as auditor near the bottom of the sidebar. This starts a 2-hour, server-verified, read-only preview session, filters your own sidebar to auditor-readable surfaces, and shows a "Previewing as auditor - read only" banner with an Exit button.
2. Send the AUDITOR invitation from the Team page
On /dashboard/team, select Invite Member, enter the reviewer email, choose Auditor from the Role dropdown, and set the Access window (1 to 90 days, defaulting to 30). Only org admins and super admins can send an auditor invite. We email the invite; copy the link if mail bounces.
3. Confirm the auditor lands on the audit dashboard
Once accepted, the auditor sees /dashboard/auditor: compliance posture by standard, open findings, recent published policy changes, recent audit-log activity, and an Export audit pack action.
4. Exit preview when you are done checking
Select Exit on the read-only banner to leave preview mode and return to your normal admin view.
Verification
- The auditor account can view policies, controls, evidence, and the audit log, but every mutating action returns a read-only error.
- The access window matches what was requested at invite time and expires automatically rather than needing manual offboarding.
- Preview as auditor shows the same read-only experience a real auditor would get, not a superset of it.
Troubleshooting
I cannot find an Auditor option in the Invite Member dialog.
The Auditor option is only available to org admins and super admins. If you are signed in as a manager, the option appears disabled with a note to ask an admin. Ask an org admin to send the invite.
The auditor reports they cannot take an action you expected them to.
This is expected. AUDITOR accounts are denied all write actions, with the message "Auditors have read-only access. Ask an admin to perform this action."
The auditor lost access earlier than I expected.
Check the access window that was set at invite time (default 30 days, max 90). Once it passes, access is revoked automatically; a fresh invitation is needed if the engagement continues.
Workflow screenshots

FAQ
Can an auditor see everything an admin sees?
No. Auditors get a curated read-only dashboard and read access to policies, controls, evidence, and the audit log. They do not get settings, billing, team management, or any authoring surface.
Was this article helpful?
Next article
Create your organization and choose the right starting plan
Set up your first organization with the plan that matches rollout depth and governance needs.
Continue to next guideRelated articles
Publish assurance artifacts with scoped visibility and access review controls.
5 min read
Set up your first organization with the plan that matches rollout depth and governance needs.
5 min read