Traceability and compliance
Showing your history to an outsider
An auditor, a lawyer, a client: what to give them and what not.
The moment comes to show how you work to someone outside. The temptation is to prepare a folder of what you will show them, and that is exactly what not to do: if you made the selection, whoever is looking knows it and will ask for the rest.
The three ways, best to worst
| How | When | What it leaves |
|---|---|---|
| Scoped read access | Audits, periodic reviews | Nothing loose, and a record of what they looked at |
| Export with its dates | When they must keep it: a lawyer, a court | A file you no longer control |
| Screenshots | Never, if avoidable | Something anyone could fabricate |
What to scope before granting access
- The scope: the site, client or period the review covers, and nothing else.
- The time: access for the duration of the engagement, not indefinitely.
- The level: read-only. Nobody outside needs to change anything.
Important
If your cases contain third parties' documents — a subcontractor's workers, a client's clients — granting broad access is not only your decision: you are showing information about people who never authorised it. Scope it to the actual review.
Watch out
Do not modify or reorganise anything while a review or a claim is running. Every change is logged with its date, and a change made after it starts always reads in the worst possible way.
Worth knowing
Scoped access usually impresses more than a prepared dossier: it shows the control genuinely exists, not that you can assemble a folder.
›Is what they looked at recorded?
Yes, with date and time.
›Can I remove access when it ends?
Yes, and it should be done that day.
›What if they ask for something out of scope?
Grant it if appropriate, by widening the scope expressly. Broad access "just in case" is not the answer.
A real case
The situation
A large client asks to audit how documentation on their sites is controlled.
What you do
- Grants scoped read access to their three sites
- For the duration of the audit
What you get
The auditor sees what they need, it is logged, and not one document from another client leaves.
The situation
The history is shown by sending screenshots.
What you do
- Shares the file with controlled access
What you get
The third party verifies rather than believes.
The situation
Too much is shared when showing a case.
What you do
- Shares only what is relevant
What you get
What was asked for is delivered, and nothing more.
The situation
There is no record of what was shown.
What you do
- Records what was shared and with whom
What you get
The handover is demonstrable afterwards.
The situation
Access stays open after the review.
What you do
- Revokes access on completion
What you get
The history does not stay exposed.
The situation
The auditor wants to verify it themselves.
What you do
- Gives them read-only access to the file
What you get
They verify without intermediaries.
This article answers
- give an auditor access to case files
- show a client the history
- share traceability with a third party
- export the log for a lawyer