Once you add an auditor and assign them to an audit, they don't log into your ComplyJet account — they get an entirely separate Auditor Portal, with its own login and its own left nav, scoped to only the clients and audits they've been assigned to.
What they can see, once assigned to an audit
Inside that one audit, your auditor gets:
Evidence — every evidence item generated for that audit's framework, with full detail: the underlying test data, a pass/fail trend chart across the audit window, and the ability to accept, flag, and comment on each item.
Framework and Controls — how your controls map to the framework's requirements, and evidence status rolled up per control.
Supporting Data — read-only access to the underlying records behind that evidence: People, Policies, Inventory, Devices, Risk, Vendors, Access, and Vulnerabilities, scoped to the audit window (e.g. only employees who joined or left during that period, not your full all-time roster).
Comments — a place to ask you questions on specific evidence items, which you'll see and can reply to from your side.
Downloads — your auditor can export evidence, mappings, and supporting data for offline review.
This is intentionally broad — an auditor needs to independently verify evidence, not just take your word for it, so they see the same underlying records you do for anything in scope of their assigned audit.
What they can't see or do
Audits you haven't assigned them to. Access is per-audit, not blanket access to your whole account — a HIPAA-only auditor doesn't see your SOC 2 audit unless they're separately assigned to it.
Anything outside the audit window, for tabs where that scoping applies (like People or Vulnerabilities).
Change your data. The portal is read-only except for their own review actions (accepting, flagging, commenting) — they can't edit your policies, evidence, or records.
Revoking access
The Setup → Settings → Auditors list doesn't have a per-audit unassign or removal action today. If you need an auditor's access cut off — an engagement ending, or added in error — reach out via chat and our team can help.

