Home Page | Previous Page |
What Drata Is
Drata is a trust management and continuous compliance automation platform used by your client to manage security, risk, and compliance programs (for example, SOC 2, ISO 27001, and other frameworks). It connects to the client’s technology stack (cloud providers, identity providers, ticketing systems, etc.) to:
Continuously monitor and test controls
Automatically collect and centralize evidence
Maintain an organized control/evidence library for audit readiness
Your client is using Drata so that you and they are working from the same, consistent set of controls and evidence during the audit.
The Drata Audit Portal (Auditor View)
Your access to the client’s environment is through the Drata Audit Portal, a secure, read‑focused workspace that mirrors what the client sees, but scoped for external auditors. From the portal you can:
View the audit overview (framework, period, status, assigned auditors)
Review requests, related controls, and mapped evidence
Download pre‑audit packages and control evidence packages, generated from the same data source as the client’s view
Set or adjust audit samples and, where enabled, create/manage requests and mark them Completed
Your client controls your permissions (for example, read‑only, ability to download packages, and which specific audits you can see). All actions are logged for transparency.
What You Can Expect to See
Within the Audit Portal, you will typically have access to:
Audit list & details – active and historical audits, including name, period, and status
Requests – each mapped to relevant controls and evidence, with status such as New, Prepared, Completed, or Deleted
Control Evidence package – ZIP file snapshot of mapped evidence for the defined sample period, identical for both client and auditor
Pre‑audit package – exports of policies, control mappings, and other artifacts, again generated from the same underlying data the client sees
Messages – secure, audit‑specific messaging between you and the client within Drata (for clarifications or follow‑up requests)
This structure is designed to reduce out‑of‑band evidence transfer (email, shared drives) and keep the audit trail centralized.
Key Resources for Auditors
Auditor Webinar Series (Live & On‑Demand)
Periodic webinars hosted by Drata’s team that dive deeper into:How auditors work in the Drata Audit Portal
Best practices for sample selection, evidence review, and request workflows
Common implementation and scoping patterns across frameworks
Registration (with access to upcoming/live sessions and, where available, recordings): Registration Link
Help Center: Auditor Experience
Written guide describing the auditor view in Drata, including how it compares to the customer view and how evidence packages behave.
How This Supports the Audit
By using Drata, your client is aiming to:
Provide consistent, tamper‑evident evidence directly from connected systems
Reduce manual evidence collection and file handling
Give auditors a single, structured environment to review controls, evidence, and requests
Maintain a clear, exportable audit trail for future periods and follow‑up work
If you have questions about portal access, permissions, or specific reports, your primary contact remains your client; they can adjust access or introduce you to Drata Support or their Drata team as needed.
