Skip to main content

How to add Auditors to my Secureframe Instance

Written by Brady Price

Customers requesting Auditor Access

Customers can now automatically provision Auditor access using our Audit Module.

A few benefits include:

  • Track new audits

  • Select your own audit form

  • Auto provision Auditor Access

  • Track historical audits

  • and more


Audit Partners requesting Auditor Access

Secureframe has created a new Auditor Partner Console (APC) specifically for Auditors. This auditor specific instance will make it easier to access client accounts, in a more secure and self-service way, once approved by those customers.

A few benefits include:

  • Easily access customer instances - Access all of your customer instances through a single dashboard, once customer consent is provided.

  • Manage your client access for your audit teams - Administrators have the ability to grant their audit teams access to approved customer instances based on who is responsible for that client engagement.

  • Use Microsoft Office 365 / Google Workspace to access client accounts - Integrate your Office 365 or Google workspace for a more secure way to access approved client accounts

Contact [email protected] if you are an Audit partner with Secureframe and would like access to our new Audit Dashboard Guide here.


Secureframe Audit Readiness

Secureframe offers a free Audit Readiness with all subscriptions and recommend scheduling these before you provide auditor access. Not required, just recommended.

This services is to ensure that our customers go comfortably and confidently into their audit knowing that they’ve had Secureframe as a trusted resource help review all the necessary tests and evidence with a extra set of eyes.

We check to ensure all integration-, platform-, and upload-based tests are passing with the right type of evidence to avoid any findings or audit issues ahead of time.

If not already, make sure you reach out to your Customer Success Manager or email [email protected] to request a free Audit Readiness call.


Auditor Permissions

Data Access

  • Ability to view and export uploaded evidence, automated testing evidence and any other data in the platform

App Access (View/read only and Exports)

  • Company settings

  • Dashboard

  • Tasks

  • Personnel

  • Asset Inventory

  • Policies

  • Vulnerabilities

  • Integrations

  • Vendors

  • Vendor access

  • Risk management

  • Data room

  • Questionnaires

  • Knowledge base

  • Trust Center

Note: The Tests, Frameworks, and Controls modules are hidden by default for auditors. Auditors are encouraged to use the Audits Module to review evidence and complete their assessment. If an auditor requires access to these modules, a company admin can grant it through the Auditor Access tab within the Audits Module.


Frequently Asked Questions (FAQ)

Should I add auditors myself or can Secureframe do this for me?

  • Yes, with our new Audit Module customers can now provision Auditors as they wish.

  • Please also be aware that Secureframe offers Audit Readiness service free of charge, so we recommend that each customer connect with your CSM ahead of time for a practice run on the audit.

Should I take advantage of the Audit Readiness?

  • Yes, we 100% recommend this. It is included in your subscription and it's an opportunity to have someone review evidence, check scoping, and more with plenty of time to fix before the actual audit starts.

As an auditor, how can we make it easier for our clients to provision our access without going through onboarding, training, and background tasks every single time?

  • As an auditor or partner, you can (or we can) set your Auditor/Admin access as non-personnel status. This will still allow you access, but remove you from the need to complete onboarding-related tasks like Policies, Training, and Background Checks. Once added, auditors will appear under the dedicated Auditors tab on the Personnel page.

I just added an Auditor to my instance using the CSV upload. Is there anything else I should do?

  • We do not recommend adding Auditors via CSV upload, instead we recommend using the Audit Module to provision access.

  • Auditors have their own dashboard, so rather than uploading them manually one by one, to each customer instance, we simply link an approved Auditor instance to a customer instance for a more streamlined approach.

Can tasks be sent out to auditors in Secureframe?

  • Auditors cannot be assigned as the owner of a task in Secureframe. However, if you select “Send Email” as the delivery method when creating a task, you can manually enter the auditor’s email address. This will send a new task notification directly to their inbox.

Note: The auditor will not see the task in-platform under their own account, since they cannot be selected as an owner. The email notification is the only supported delivery method for auditors.

Does the Auditor role have access to use the tasks system during an Audit?

  • Yes, Auditors will have access to use the Secureframe Tasks system to create internal/external tasks for admins before or during an Audit.

  • This is commonly used among customers and auditors to ensure action items are completed in platform on specific audit related needs.

How do I disable or de-provision an auditor's access?

If the auditor appears in the Non-Personnel section of your Personnel page:

  1. Click the three-dot menu next to the auditor’s account

  2. Select “Mark as contractor” or “Mark as employee”

  3. Go to the Active tab in the Personnel table and search for the auditor

  4. Click into the auditor’s profile > Edit > remove admin access or change their role

  5. Return to the three-dot menu and reclassify the user as an auditor

Note: Only Super Admins can remove access for other users.

If you don’t see the auditor listed in the Non-Personnel section

I added an auditor but they cannot see the audit or see "no active audits." What should I check?

  • Confirm the auditor was provisioned through the Audits Module for the specific audit, not only added as personnel via CSV upload.

  • Confirm the audit is in an active or upcoming state and the auditor is assigned to that engagement in the Audits Module.

  • Auditors should access customer instances through the Auditor Partner Console (APC), not by logging into the customer instance directly unless explicitly provisioned. See Auditor Partner Console: Dashboard Guide.

  • If APC shows access but the auditor still cannot open the audit, contact Support with the auditor email, customer instance name, and audit framework.

The auditor did not receive a magic link email. What should we do?

  • Confirm the auditor email address is correct in the Audits Module and matches what they use to sign in.

  • Ask the auditor to check spam or quarantine folders. Plus-addressed emails (for example [email protected]) can be filtered by some mail systems.

  • Request a new magic link from the login page. If the auditor is an APC user, confirm they are signing in through the APC dashboard, not the customer login URL.

  • If delivery still fails after retrying, contact Support with the auditor email and approximate time the link was requested.

How does an auditor switch between customer organizations?

  • Auditors with APC access should use the Auditor Partner Console to view all approved customer instances from one dashboard.

  • If an auditor was added directly to a customer instance and cannot switch orgs, they likely need APC access. Audit partners can contact [email protected] to request APC setup.

  • Customer admins provision access per audit through the Audits Module. Each engagement must be approved separately.

Why are the auditor Access role or Add buttons greyed out?

  • If you are adding an auditor through the regular Team or Personnel area, some role and add options may not be available because auditor access should be provisioned through the Audits Module or Auditor Partner Console workflow.

  • Open the relevant audit in the Audits module and add the audit firm or auditor from there. If the firm is not available, select the appropriate firm option or contact Support with the auditor email, audit firm name, customer instance, and audit framework.

  • For independent auditors or firms listed as Other, Support may need to help provision access manually.

What are the correct steps for an auditor to access a customer instance through APC?

  • Customer: open the Audits module, create or open the audit, and add the audit firm / auditor for that engagement. This provisions access and links the customer instance to the firm's APC.

  • Auditor (firm admin): confirm the auditor is on the APC Team tab and assigned to that client under Audits.

  • Auditor: sign in to the regional Auditor Partner Console, open Auditor Dashboard, find the customer, and open the assigned audit.

  • Auditors should use APC, not the customer's normal Secureframe login URL, unless they were provisioned a different way. See Auditor Partner Console: Dashboard Guide.

How do we verify auditor email, customer instance, and audit framework are set up correctly?

  • In the customer instance Audits module, confirm the audit exists, the framework is correct, and the auditor's email matches the address they use to sign in.

  • In APC, confirm that customer appears under Audits and the auditor is assigned on the client Summary tab.

  • Confirm the auditor is signing into the correct regional APC (US vs UK/EU).

  • If APC shows the client but the audit is missing, or the customer audit does not list the auditor, contact Support with auditor email, customer instance name, and audit framework.

Why does the auditor see "Onboarding is not available, please contact your company's admin"?

  • This usually means the auditor is hitting the customer instance or employee onboarding flow instead of APC, or they were added as personnel in a way that triggers onboarding.

  • Prefer provisioning through the Audits module / APC so the user is treated as an auditor (non-personnel), not an employee who must complete onboarding.

  • Have the auditor sign in through the Auditor Partner Console and open the customer from the dashboard, rather than using a direct customer onboarding or employee invite link.

  • If they were added via CSV or as a normal user, remove that path and re-add them through the Audits module / APC workflow.

Is auditor access enough to review evidence, or do they need guest Admin?

  • For most audits, Auditor access is enough. Auditors can review and export evidence for the engagement through the Audits module.

  • You do not need to grant guest Admin for a standard evidence review. Admin is a broader role and is not required for typical auditor fieldwork.

  • Tests, Frameworks, and Controls are hidden by default for auditors. If they need those modules, a company admin can grant them from auditor access settings in the Audits module.

  • Prefer Auditor access unless your firm and customer agree Admin is required for a specific reason.

Can we invite auditors with their firm email, or do we need a temporary company email?

  • Use the auditor's normal firm email. You do not need to create a temporary company email for them.

  • Enter that same email in the Audits module so it matches the address they use for APC magic link / SSO sign-in.

  • Avoid plus-address aliases when possible if the firm's mail filters block them. If delivery fails, see APC login troubleshooting.

Our auditor asked us to enable the Controls module. Where do we do that?

  • Customers provision auditor access through the Audits module, not by flipping a separate Controls switch on the main navigation.

  • By default, auditors do not see the Tests, Frameworks, and Controls modules. They are expected to review evidence and related audit work through the Audits experience.

  • When you add an auditor in the Audits module, you can enable access to those modules for that auditor if your engagement needs it.

  • There is no separate company-wide "enable Controls module" toggle for auditors outside of auditor provisioning in Audits.

  • If an auditor still cannot see what they need after provisioning, contact Support with the auditor email and audit name.

Why is Save disabled when adding an auditor?

  • Save stays disabled until required fields are complete, including a selectable audit firm / auditor and any required audit details.

  • Add auditors from the Audits module for that engagement, not from Team/Personnel role pickers that may leave Add/Save unavailable.

  • If the firm is missing or only Other is available, Support may need to help provision the firm/auditor. Include auditor email, firm name, customer instance, and framework when you contact Support.

  • Deleting and recreating the audit rarely fixes a firm-linking issue. Confirm firm selection and required fields first.

Did this answer your question?