The auditor role exists for exactly one job: letting someone review what
happened without being able to change it. Use it for an external auditor, a
regulator's reviewer, or anyone internal who should see everything but touch
nothing.
Before you start
You need members.manage permission. For the general invite flow — sending the
invite, expiry, what an invited person sees before accepting — see
Create your workspace and invite your team.
This page covers only the role itself.
What an auditor can do
- Read the workspace, products, alerts, and cases.
- Generate and download evidence packs. This is deliberate, not an oversight: the entire point of the role is a reviewer who can produce proof of what happened without being able to alter it.
- Read the audit log.
What an auditor can't do
Everything a member can do beyond reading is withheld: an auditor can't upload
an SBOM, decide or triage an alert, write to or submit a case, manage workspace
settings or members, manage the VDP, or touch billing. There's no partial
read-write auditor mode — the role is read-only across the board, with the single
exception of generating evidence packs, which is itself a read operation on
existing data rather than a change to anything.
Steps
- Invite the person the same way you'd invite anyone else.
- Pick Auditor as their role.
- Send the invite.
What you should see
Once accepted, the person appears in your member list with the Auditor role. They can sign in and see everything read access covers; anything requiring a write permission simply isn't offered to them in the interface.