compliance-ownerauditorP1Updated
Was this page helpful?

The auditor role exists for exactly one job: letting someone review what happened without being able to change it. Use it for an external auditor, a regulator's reviewer, or anyone internal who should see everything but touch nothing.

Before you start

You need members.manage permission. For the general invite flow — sending the invite, expiry, what an invited person sees before accepting — see Create your workspace and invite your team. This page covers only the role itself.

What an auditor can do

  • Read the workspace, products, alerts, and cases.
  • Generate and download evidence packs. This is deliberate, not an oversight: the entire point of the role is a reviewer who can produce proof of what happened without being able to alter it.
  • Read the audit log.

What an auditor can't do

Everything a member can do beyond reading is withheld: an auditor can't upload an SBOM, decide or triage an alert, write to or submit a case, manage workspace settings or members, manage the VDP, or touch billing. There's no partial read-write auditor mode — the role is read-only across the board, with the single exception of generating evidence packs, which is itself a read operation on existing data rather than a change to anything.

Steps

  1. Invite the person the same way you'd invite anyone else.
  2. Pick Auditor as their role.
  3. Send the invite.

What you should see

Once accepted, the person appears in your member list with the Auditor role. They can sign in and see everything read access covers; anything requiring a write permission simply isn't offered to them in the interface.