Auditor room and export
The external half of the engagement: your auditor works in a portal of their own — separate sign-in, separate world, scoped to exactly one engagement at a time — and the engagement ends with evidence frozen and exported as a package you can stand behind later.
Invite the auditor
In the expanded engagement panel, the External Auditor Access section has one button that matters: Invite to Portal. Enter the auditor's email (name and firm optional) and send. They receive an invitation email, set up their own portal account with its own password — and optionally two-factor authentication — and sign in at the auditor portal.
The section then lists every portal auditor on the engagement, with their firm, last sign-in, and a two-factor indicator. Revoke cuts an auditor's access to this audit immediately; if the same person audits you on other engagements, those are unaffected.
Portal access is a real authenticated account per auditor, invited per engagement. The old style of emailing an access link around is retired — a link that anyone can forward is not a defensible access record.
What the auditor sees — and doesn't
The portal is deliberately small. An auditor gets one screen: the engagement summary and stats, the evidence request list, and per request the attached evidence, a comment thread, and accept/reject for submitted evidence. They can also raise new evidence requests of their own — title, category, control reference, priority, due date — so fieldwork follow-ups land in your queue instead of your inbox.
What they do not get is your workspace. No modules, no registers, no documents beyond what was attached to their requests. An auditor with several clients on SolveGRC sees one engagement at a time and switches explicitly; nothing bleeds across organizations or across audits.
Every download an auditor takes passes a release gate. Evidence must have been explicitly sealed for external release by your side, and files that arrived through vendor submissions must additionally have passed malware screening — a file that fails either check simply cannot be downloaded from the portal. The consequence for your team: if an auditor reports a file they cannot download, seal it (or wait out the scan) rather than looking for a workaround.
Everything the auditor does in the portal — views, downloads, verdicts, comments — is recorded, and the Auditor Activity panel on your side shows that record.
Freeze the evidence
When collection is done and the auditor is forming conclusions, use Freeze Evidence in the engagement panel. Freezing locks every evidence request — no uploads, edits, or status changes on your side, and reviews, comments, and new requests pause on the auditor's side, where a banner tells them the audit is frozen. A lock icon marks the frozen audit in your table.
The point is defensibility: the auditor's opinion is about a fixed body of evidence, and the freeze guarantees that body did not shift after the fact.
Unfreeze requires a written reason, and the record keeps who froze, who unfroze, and why — so even the exception is provable.
Export a defensible package
The Evidence Packages section turns the collected evidence into an artifact:
- New Package snapshots all evidence with uploaded files into a named package.
- CSV exports the package manifest — the itemized record of what was in scope.
- Files downloads the evidence files themselves.
A package moves from draft to finalized to exported, and the export is stamped with when it happened and who did it. Freeze first, then package: a package cut from frozen evidence, with its manifest, is the thing you hand over when someone asks — this year or three years from now — exactly what the auditor was given.
That is the full engagement: created and scoped, evidence collected against requests, reviewed by the auditor in their own portal, then frozen and exported. Start again at the Overview for the map, or see Reuse and packs for how the same evidence serves customers outside a formal audit.