Saltar al contenido

Traceability and compliance

Showing your history to an outsider

An auditor, a lawyer, a client: what to give them and what not.

Updated on 13/08/2026

The moment comes to show how you work to someone outside. The temptation is to prepare a folder of what you will show them, and that is exactly what not to do: if you made the selection, whoever is looking knows it and will ask for the rest.

The three ways, best to worst

HowWhenWhat it leaves
Scoped read accessAudits, periodic reviewsNothing loose, and a record of what they looked at
Export with its datesWhen they must keep it: a lawyer, a courtA file you no longer control
ScreenshotsNever, if avoidableSomething anyone could fabricate

What to scope before granting access

  • The scope: the site, client or period the review covers, and nothing else.
  • The time: access for the duration of the engagement, not indefinitely.
  • The level: read-only. Nobody outside needs to change anything.

Important

If your cases contain third parties' documents — a subcontractor's workers, a client's clients — granting broad access is not only your decision: you are showing information about people who never authorised it. Scope it to the actual review.

Watch out

Do not modify or reorganise anything while a review or a claim is running. Every change is logged with its date, and a change made after it starts always reads in the worst possible way.

Worth knowing

Scoped access usually impresses more than a prepared dossier: it shows the control genuinely exists, not that you can assemble a folder.

Is what they looked at recorded?

Yes, with date and time.

Can I remove access when it ends?

Yes, and it should be done that day.

What if they ask for something out of scope?

Grant it if appropriate, by widening the scope expressly. Broad access "just in case" is not the answer.

A real case

The situation

A large client asks to audit how documentation on their sites is controlled.

What you do

  1. Grants scoped read access to their three sites
  2. For the duration of the audit

What you get

The auditor sees what they need, it is logged, and not one document from another client leaves.

The situation

The history is shown by sending screenshots.

What you do

  1. Shares the file with controlled access

What you get

The third party verifies rather than believes.

The situation

Too much is shared when showing a case.

What you do

  1. Shares only what is relevant

What you get

What was asked for is delivered, and nothing more.

The situation

There is no record of what was shown.

What you do

  1. Records what was shared and with whom

What you get

The handover is demonstrable afterwards.

The situation

Access stays open after the review.

What you do

  1. Revokes access on completion

What you get

The history does not stay exposed.

The situation

The auditor wants to verify it themselves.

What you do

  1. Gives them read-only access to the file

What you get

They verify without intermediaries.

This article answers

  • give an auditor access to case files
  • show a client the history
  • share traceability with a third party
  • export the log for a lawyer