---
id: KB-TZ-007
url: https://app.codecontract.io/help/traceability-and-compliance/showing-your-history-to-an-outsider
idioma: en
categoria: trazabilidad
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-TZ-005, KB-CF-003]
citadoPor: [KB-TZ-011, KB-TZ-021]
---

# Showing your history to an outsider

_An auditor, a lawyer, a client: what to give them and what not._

**Responde a:** give an auditor access to case files · show a client the history · share traceability with a third party · export the log for a lawyer

The moment comes to show how you work to someone outside. The temptation is to prepare a folder of what you will show them, and that is exactly what not to do: if you made the selection, whoever is looking knows it and will ask for the rest.

## The three ways, best to worst

| How | When | What it leaves |
| --- | --- | --- |
| Scoped read access | Audits, periodic reviews | Nothing loose, and a record of what they looked at |
| Export with its dates | When they must keep it: a lawyer, a court | A file you no longer control |
| Screenshots | Never, if avoidable | Something anyone could fabricate |

## What to scope before granting access

- The scope: the site, client or period the review covers, and nothing else.
- The time: access for the duration of the engagement, not indefinitely.
- The level: read-only. Nobody outside needs to change anything.

> [!IMPORTANT]
> If your cases contain third parties' documents — a subcontractor's workers, a client's clients — granting broad access is not only your decision: you are showing information about people who never authorised it. Scope it to the actual review.

> [!WARNING]
> Do not modify or reorganise anything while a review or a claim is running. Every change is logged with its date, and a change made after it starts always reads in the worst possible way.

> [!NOTE]
> Scoped access usually impresses more than a prepared dossier: it shows the control genuinely exists, not that you can assemble a folder.

**Is what they looked at recorded?**

Yes, with date and time.

**Can I remove access when it ends?**

Yes, and it should be done that day.

**What if they ask for something out of scope?**

Grant it if appropriate, by widening the scope expressly. Broad access "just in case" is not the answer.

## Ejemplos

**A large client asks to audit how documentation on their sites is controlled.**

- Grants scoped read access to their three sites
- For the duration of the audit

→ The auditor sees what they need, it is logged, and not one document from another client leaves.

**The history is shown by sending screenshots.**

- Shares the file with controlled access

→ The third party verifies rather than believes.

**Too much is shared when showing a case.**

- Shares only what is relevant

→ What was asked for is delivered, and nothing more.

**There is no record of what was shown.**

- Records what was shared and with whom

→ The handover is demonstrable afterwards.

**Access stays open after the review.**

- Revokes access on completion

→ The history does not stay exposed.

**The auditor wants to verify it themselves.**

- Gives them read-only access to the file

→ They verify without intermediaries.
