Skip to content

Auditor and independent review access

Gamut provides separate access patterns for assurance review and runtime-policy decisions. Neither requires an administrator role.

Auditors receive a read-only assurance profile constrained by tenant, workspace, plan and role. They can inspect the permitted systems, assessments, risks, policies, evidence, findings, tests, workpapers and audit records, but cannot mutate governance records or export where the role does not permit it.

Invite the reviewer to the exact workspace and period required. Review the invitation status and remove access when the engagement ends. Free-plan review invitations may be time and count limited; paid-plan behaviour follows the current entitlement.

The dedicated approver role is for independent decisions on submitted Runtime Access Policies in assigned Enterprise workspaces. The approver can inspect policy context and approve or reject. The role cannot draft, edit, delete, submit, suspend or revoke policy; administer users; operate Gateway; or mutate unrelated product records.

MFA must be enrolled before an approval or rejection. The creator or submitter cannot approve the same policy. The plan must include production Gateway and policy approval; assigning the role does not create an entitlement.

  • Correct tenant and workspace assignment.
  • Minimum role for the review purpose.
  • Individual account and verified identity.
  • MFA for sensitive approval.
  • No creator-approver conflict.
  • Access expiry and removal recorded.