Files extension
Who checks, on an open record
The auditor sees every share, access and login of every Files user; they can investigate, ask for explanations and revoke. And every action of theirs — inspection, report, question, investigation — is logged and visible to administrators. For the DPO, the compliance officer, the reviewer who must answer “who had access to this, and when”.
A dossier per person, not a search through the logs
Once a person is chosen, the auditor has four tabs: the access granted to them — on which folders, at which level, by whom —, the shares they made, those they received, their login history. From there they can open an investigation on a share, ask a question the user answers in their own area, remove an access, export everything to CSV or generate the PDF report. Auditor is a privilege of the user type; administrators always have it, and the designation of others is tracked with its history.
How it works
-
Designate the auditors
From the Auditor panel the administrator designates people — or assigns the privilege to a user type, “Reviewer” for instance. Designations and revocations stay in the history, with date and author.
-
Inspect and ask
The auditor opens a person’s dossier, looks at the access tree — inherited ones and those on subtrees included — and, if something does not add up, starts an investigation on that share or asks a written question. The user sees it in their area and answers there.
-
Act and document
Remove the access that should not have been there, close the investigation with its outcome, generate the access report as PDF or the CSV export for the supervisory body. Everything the auditor did is in the auditors’ activity register, which administrators see and auditors do not.
The auditor sees everything. And everyone sees what the auditor looked at.
What you can do
-
Four tabs per user
Access granted, shares made, access received, login history. Complete lists up to ten thousand rows, beyond which Files points to the CSV export, so screen and file match.
-
Investigations with an outcome
An investigation opens on a specific share or access, is resolved with a written outcome and remains available. The person involved sees they are under investigation.
-
Tracked questions and answers
“Why did you share this folder with firm X?” The user receives the question in their area and answers in writing. Question and answer stay together in the dossier.
-
PDF and CSV reports
Access report for the whole tenant or a single person, as a PDF ready to attach and as CSV for those who need to cross-check data.
-
The auditors’ register
Every inspection, view, report, question and investigation is logged. Administrators see it; the auditor sees only their own, in “My activity”. Nobody checks without leaving a trace.
-
With Access change reason
If that extension is on, the auditor receives every access level change by email with its reason: the check arrives before anyone asks for it.
Frequently asked questions
Can the auditor open files?
Not as auditor: the role sees metadata — who has access to what, who shared, who logged in — not contents. To open a file they need normal access to the folder, like anyone else.
Who can be an auditor?
Anyone with the privilege in their user type, or designated from the panel. Tenant administrators always are. Managing auditors in turn requires the privilege to manage members.
Does the user know they are being checked?
They know auditors exist and see the questions and investigations that concern them. They do not see the auditors’ activity register: that belongs to administrators.
The other Files features
Move your company files to the cloud
Request a demo: we’ll show you how Files makes storage and sharing simple and secure.