Marking a user as Out of Scope excludes that person from audit testing and automated compliance checks while preserving an audit trail. This helps ensure audit scope accurately reflects who accesses customer data and in-scope systems.
When to mark personnel as Out of Scope
Mark a user as Out of Scope when that person:
Does not access customer data
Does not access systems that handle customer data
Should not be included in compliance testing for the current audit scope
Auditors expect Out of Scope users to be rare and clearly justified.
Mark personnel as Out of Scope
Open Personnel page.
Locate the user you want to update.
In the Personnel status column, select Out of Scope from the dropdown.
Enter a business rationale when prompted.
Save your changes.
When you mark a user as Out of Scope:
The user cannot sign in to Drata unless the user holds an admin role
Drata excludes the user from automated compliance checks
The user does not complete employee onboarding
Drata retains the personnel record for audit purposes
