Saltar al contenido

Your workspace

The auditor role: looking without touching

For whoever has to review and should not be able to change anything, not even by accident.

Updated on 13/08/2026

Some people come in to check, not to work: an external auditor, your accountants, a quality manager from your client, a partner who wants to see how things are going. Giving them the same role as an operator is convenient on day one and irritating for the rest of the year.

Why a read-only role is worth it

With an editing roleWith an auditor role
They can change something by accidentThey cannot, and that reassures both sides
Their actions blend in with the team'sWhat they do stands out in the log
You have to trust they will not touchNo trust needed: they cannot
If they do touch something, it is awkward to explainTheir review does not alter what is reviewed

Important

The fourth row is what really matters in an audit. If the reviewer can modify, any later difference invites the awkward question of whether they caused it. A role that cannot write removes that doubt permanently, and protects the auditor as much as you.

What someone with that role can do

That is exactly what they need to do their job. If at some point they must contribute something — a report, minutes — better they send it and you upload it: the file keeps a single owner.

Watch out

The nuance that sometimes surprises: **read-only is not invisible**. What they consult is recorded in the activity log like any other action, with their name and the time. That is desirable — it lets you answer years later who saw what — but tell whoever comes in, especially an outsider. It is not surveillance: it is the same traceability required of everything else.

When NOT to use it

  1. 1

    If that person will supply documentation

    Then they are not a reviewer: they are a participant, and there are better routes.

  2. 2

    If they only need to see one document

    No access needed: send it by their link.

  3. 3

    And if it is someone on your team complaining about the role

    They probably need a different one, not an upgrade of this one.

Worth knowing

Like any outside access, this one is withdrawn when the engagement ends, not when someone remembers. An auditor from two years ago who can still log in is the most awkward finding in your own permissions review.

Does it take a seat?

Yes, it counts as a user while active; hence withdrawing it at the end.

Can they export?

It depends what you enable. If they will export, better known beforehand than discovered after.

What if they need something I did not grant?

Let them ask: widening takes a minute and there is a record of what was widened and when.

A real case

The situation

A company gives its external auditor an editing role so nothing is missing.

What you do

  1. Switches to the read-only role and explains their access is logged
  2. Withdraws access when the report closes

What you get

The audit runs with nobody able to question whether the reviewer altered what was reviewed.

The situation

An auditor asks for access and is given an editing role.

What you do

  1. Grants read-only access

What you get

They look without being able to touch.

The situation

There is concern the auditor might change something unintentionally.

What you do

  1. Uses the role that cannot write

What you get

The risk disappears.

The situation

The auditor finishes and their access stays active.

What you do

  1. Revokes access on completion

What you get

Access reflects who is collaborating today.

The situation

There is no record of what they consulted.

What you do

  1. Checks the access log

What you get

You know what was shown to them.

The situation

The auditor only needs to see one part.

What you do

  1. Limits the scope to what is relevant

What you get

They see what was asked for and nothing more.

This article answers

  • read-only access
  • auditor role on the platform
  • let someone review without editing
  • access for an external auditor