Creating an audit
Click New Audit to start. The dialog asks for two things, both required:- Compliance Framework — the framework being audited, picked from your active frameworks
- Invite your auditor — the auditor’s email address
When you invite an auditor, they receive an email with access to a dedicated audit view. Auditors have limited permissions — they can view and comment on evidence but cannot modify your compliance data.
Audit dashboard
Each audit displays three key sections:Timeline
Key milestones — when the audit started, when the auditor was assigned, and current status.
Evidence Status
Donut chart of evidence items. Its legend reads Not Ready, Flagged, Ready, Accept, and No Applicable — the last two are worded differently here than in the status dropdown.
Compliance Process
Progress bars for Controls, Automated Tests, Policies, and Documents.
Audit statuses
Working with your auditor
Each evidence row carries a single status dropdown, not a set of action buttons. Opening it offers five values:- Ready — the evidence is ready for the auditor to look at
- Not Applicable — the requirement does not apply
- Flagged — the auditor needs more information or has concerns
- Not Ready — the evidence is not yet in a reviewable state
- Accepted — the evidence satisfies the requirement
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)