Granting Auditor Access
There are two ways to provide auditors with access to your LowerPlane data:- Invite by Email
- Generate Access Link
Invite specific auditors by email address. Each auditor creates their own account with the Auditor role.
Select the Auditor role
Choose Auditor from the role dropdown. This grants read-only access scoped to compliance data.
Set an expiration date
Configure when the auditor’s access should automatically expire. Set this to the expected audit completion date plus a reasonable buffer (e.g., 2 weeks after the audit window closes).
Access Expiration
Every auditor access grant should have an expiration date. LowerPlane supports:| Setting | Description |
|---|---|
| Fixed date | Access expires on a specific calendar date |
| Duration | Access expires after a set number of days from creation (e.g., 30 days, 90 days) |
| Manual revocation | Access remains until explicitly revoked (not recommended) |
Extending Access
If an audit runs longer than expected:- Navigate to the auditor’s user entry or access link.
- Click Extend Access.
- Set a new expiration date.
- Save the change. The extension is logged in the audit trail.
Audit Firm Management
For organizations that work with the same audit firms regularly, LowerPlane lets you manage audit firm details:| Field | Description |
|---|---|
| Firm name | Name of the audit firm |
| Primary contact | Lead auditor or engagement manager |
| Contact email | Firm’s or lead auditor’s email address |
| Engagement type | SOC 2, ISO 27001, HIPAA, PCI-DSS, or GDPR |
| Audit period | Start and end dates of the current engagement |
- Track which firm conducted each audit
- Manage multiple auditor accounts from the same firm
- Maintain a history of audit engagements
Monitoring Auditor Activity
LowerPlane logs all auditor activity for your review:| Activity | What Is Logged |
|---|---|
| Login | When the auditor accessed the portal |
| Page views | Which sections and controls the auditor reviewed |
| Evidence access | Which evidence files were viewed or downloaded |
| Search queries | What the auditor searched for |
| Session duration | How long each session lasted |
- Security monitoring — Verify that auditor access is used appropriately.
- Audit preparation — Understand which areas the auditor focused on, which can help you prepare for follow-up questions.
Auditors are not notified that their activity is logged. This is standard practice for access monitoring and is itself a compliance control (audit logging of system access).
Revoking Access
To immediately revoke an auditor’s access:Find the auditor
Navigate to Settings > Users and locate the auditor account, or go to the access link management page.
Access Management as Compliance Evidence
Your auditor access management practices are themselves compliance evidence:| Framework | Relevant Controls |
|---|---|
| ISO 27001 | A.9.2.2 (Access provisioning), A.9.2.6 (Removal of access rights) |
| SOC 2 | CC6.2 (Prior to access, registration and authorization), CC6.3 (Removal when no longer needed) |
- When auditor access was granted
- What scope was provided
- When access expired or was revoked
- All auditor activity during the access period
Maintaining clean auditor access records demonstrates mature access management practices. Future auditors will review how you managed previous auditor access as part of their assessment.
Best Practices
- Always set expiration dates. No auditor access should be open-ended.
- Use the Auditor role, not Member or Admin. The Auditor role provides exactly what auditors need and nothing more.
- Revoke promptly after audit completion. Do not wait for automatic expiration if the audit finishes early.
- Review access before granting. Ensure the auditor’s identity is verified before providing access to your compliance data.
- Password-protect access links. Share passwords through a separate channel from the link itself.
- Monitor activity during the audit. Review the activity log periodically to ensure access is being used appropriately.
- Document the engagement. Record the audit firm, engagement type, and period for each audit.