Skip to main content

What auditors can see in Audit Hub

A comparison guide showing what auditors can see in Audit Hub compared to what customers can see in Drata.

⚠️ Select your experience

The steps to understand what auditors can see depend on your interface version. Select a link to skip to the instructions for your version.

Customers who joined Drata on or after Feb 24, 2026 are automatically on the New Experience.

Instructions for the New Experience ⬇️

This article explains what auditors can see in Audit Hub and how that compares with what customers manage in Drata. Both sides work from the same underlying audit data, evidence, and audit packages, but access and actions depend on how the audit is configured.

Use the sections below to compare the auditor view and the customer view at the same stage of the audit workflow.

Choosing the client and audit

What the customer sees

The customer creates the audit in Drata, selects the framework and audit period, and adds the auditor to the engagement. Once the auditor is assigned, they can access the audit from the Audit Portal.

What the auditor sees

After signing in to the Audit Portal, the auditor can view the list of assigned clients.

After selecting a client, they can see the available audits for that client and open the audit they need to review.

Screenshot displays the View in read-only button for auditors

Main audit overview

What the auditor sees

After the auditor opens a specific audit, they land on the main audit page. From there, they can typically see the audit name, audit period, completion state, assigned auditors, request summary, request list, and Audit Resources.

What customers should keep in mind

  • Customers control the framework, audit period, and auditor assignment for the audit.

  • Auditors and customers work from the same underlying audit data and package sources.

  • Read-only access expands what the auditor can view, but it does not allow edits.

  • If a package download fails or takes longer than expected, retry it from Audit Resources. If the issue continues, contact Drata Support.


Instructions for the Classic Experience ⬇️

When conducting an audit, we want to ensure that what you see is also what your auditors see, with no discrepancies or misaligned views in terms of what the auditor can access when performing an audit.

Before Diving In

  • You must have an active audit within Drata

  • You cannot have the Risk Manager or Workspace Manager role within Drata

  • Drata maintains a high level of data transparency between our customers and the auditors that are invited to perform audits. Control evidence, audit pre-packages, evidence requests, and request details are always the same for both parties

  • Auditors do have some additional functionality (e.g. ability to change statuses to 'completed', request evidence, delete requests etc.) that is different from the customer experience

  • You cannot invite an auditor with a personal email, or an email that matches your Drata tenant domain

Here's How

The Auditor View is almost identical to the customer view. Below you will see comparisons and additional information between both your view and the auditor view, which are extremely similar.

Main Page

Customer View: Main Audit Framework Page

Auditor View: Main Audit Framework page

Audit Resources

One of the main features that maintains complete transparency are the downloadable evidence and audit packages. This ensures that the evidence being reviewed can be accessed by both the auditor and customer in the exact same state.

Customer View: Pre-audit package

Auditor View: Pre-audit package

Request Page

The request page is to view details about the requests that have been selected. You can view basic details about the request, related controls, download related controls, and view messages related to the request.

Troubleshooting Missing Requirements in Audit Hub

  1. Verify Auditor Assignment: Check that an auditor is assigned to the audit.

  2. Custom Request List or Default Framework: Confirm that the auditor has uploaded a custom request list or selected the default framework requirements.

  3. Validate the Audit Period: Ensure that the audit period is valid for accessing the requirements.

  4. Adjust Filters: Check for filters or search criteria that might be hiding requirements. Broaden or clear filters to view all related items.

Did this answer your question?