Skip to main content

Auditor room and export

The external half of the engagement: your auditor works in a portal of their own — separate sign-in, separate world, scoped to exactly one engagement at a time — and the engagement ends with evidence frozen and exported as a package you can stand behind later.

Invite the auditor

In the expanded engagement panel, the External Auditor Access section has one button that matters: Invite to Portal. Enter the auditor's email (name and firm optional) and send. They receive an invitation email, set up their own portal account with its own password — and optionally two-factor authentication — and sign in at the auditor portal.

The section then lists every portal auditor on the engagement, with their firm, last sign-in, and a two-factor indicator. Revoke cuts an auditor's access to this audit immediately; if the same person audits you on other engagements, those are unaffected.

No shared logins, no magic links

Portal access is a real authenticated account per auditor, invited per engagement. The old style of emailing an access link around is retired — a link that anyone can forward is not a defensible access record.

What the auditor sees — and doesn't

The portal is deliberately small. An auditor gets one screen: the engagement summary and stats, the evidence request list, and per request the attached evidence, a comment thread, and accept/reject for submitted evidence. They can also raise new evidence requests of their own — title, category, control reference, priority, due date — so fieldwork follow-ups land in your queue instead of your inbox.

What they do not get is your workspace. No modules, no registers, no documents beyond what was attached to their requests. An auditor with several clients on SolveGRC sees one engagement at a time and switches explicitly; nothing bleeds across organizations or across audits.

Every download an auditor takes passes a release gate. Evidence must have been explicitly sealed for external release by your side, and files that arrived through vendor submissions must additionally have passed malware screening — a file that fails either check simply cannot be downloaded from the portal. The consequence for your team: if an auditor reports a file they cannot download, seal it (or wait out the scan) rather than looking for a workaround.

Everything the auditor does in the portal — views, downloads, verdicts, comments — is recorded, and the Auditor Activity panel on your side shows that record.

ScreenshotThe auditor portal: engagement summary and stats, the evidence request list with status badges, and an expanded request showing attached evidence, downloads, and the accept/reject controls.

Freeze the evidence

When collection is done and the auditor is forming conclusions, use Freeze Evidence in the engagement panel. Freezing locks every evidence request — no uploads, edits, or status changes on your side, and reviews, comments, and new requests pause on the auditor's side, where a banner tells them the audit is frozen. A lock icon marks the frozen audit in your table.

The point is defensibility: the auditor's opinion is about a fixed body of evidence, and the freeze guarantees that body did not shift after the fact.

Unfreeze requires a written reason, and the record keeps who froze, who unfroze, and why — so even the exception is provable.

Export a defensible package

The Evidence Packages section turns the collected evidence into an artifact:

  1. New Package snapshots all evidence with uploaded files into a named package.
  2. CSV exports the package manifest — the itemized record of what was in scope.
  3. Files downloads the evidence files themselves.

A package moves from draft to finalized to exported, and the export is stamped with when it happened and who did it. Freeze first, then package: a package cut from frozen evidence, with its manifest, is the thing you hand over when someone asks — this year or three years from now — exactly what the auditor was given.

ScreenshotFreeze and export controls: the Evidence Freeze toggle with its frozen timestamp, and the Evidence Packages table with manifest and file export actions.

That is the full engagement: created and scoped, evidence collected against requests, reviewed by the auditor in their own portal, then frozen and exported. Start again at the Overview for the map, or see Reuse and packs for how the same evidence serves customers outside a formal audit.