Giving auditors access
Auditors get first-class read-only seats, not screenshots. Grant the Read Only role and every screen stays fully readable while every mutation is disabled, each with a plain reason (“Read-only access. Approving needs operator access to this tenant.”).
Setting it up
Section titled “Setting it up”- On the Identity screen, create a group for the engagement (for example “Auditors”).
- Grant it the Read Only role at the scope the engagement covers: the whole tenant, or specific AWS accounts inside it. An auditor scoped to two of six accounts sees full detail for those two and the tenant container read-only.
- Add the auditor’s account to the group. Remove them from the group when the engagement ends; their account and audit-trail references remain.
Auditors need a seat in your organization; there are no anonymous share links.
What a read-only seat sees
Section titled “What a read-only seat sees”- Deployments: every plan, approval record, apply log, and control snapshot, with the approver’s name on each.
- Evidence: each deployment’s evidence package, item by item, and the Download PDF export built for handing over. The package describes demonstrated capabilities with citations; it does not assert a compliance status.
- Compliance: the requirement matrix with its contributor arithmetic, statuses, caveats, and open drift findings.
- Docs: the derived system overview, runbook, and control narrative, plus attestation documents with their approval history.
- Activity: the append-only audit timeline. Nothing updates or deletes an audit record, and a deployment’s whole thread is one correlation ID.
One disclosure worth stating up front: the audit timeline and attestation documents are tenant-wide, so an account-scoped auditor still sees the tenant’s full timeline and documents.
Why this works for audits
Section titled “Why this works for audits”The trail an auditor needs is the trail the product already writes: who requested, who approved (self-approval is blocked or explicitly flagged), what applied, what the configuration actually was at capture time (hashed), and what changed since. The auditor reads the same system of record you operate from, rather than a curated export.