Files extension

Who checks, on an open record

The auditor sees every share, access and login of every Files user; they can investigate, ask for explanations and revoke. And every action of theirs — inspection, report, question, investigation — is logged and visible to administrators. For the DPO, the compliance officer, the reviewer who must answer “who had access to this, and when”.

A dossier per person, not a search through the logs

Once a person is chosen, the auditor has four tabs: the access granted to them — on which folders, at which level, by whom —, the shares they made, those they received, their login history. From there they can open an investigation on a share, ask a question the user answers in their own area, remove an access, export everything to CSV or generate the PDF report. Auditor is a privilege of the user type; administrators always have it, and the designation of others is tracked with its history.

How it works

  1. Designate the auditors

    From the Auditor panel the administrator designates people — or assigns the privilege to a user type, “Reviewer” for instance. Designations and revocations stay in the history, with date and author.

  2. Inspect and ask

    The auditor opens a person’s dossier, looks at the access tree — inherited ones and those on subtrees included — and, if something does not add up, starts an investigation on that share or asks a written question. The user sees it in their area and answers there.

  3. Act and document

    Remove the access that should not have been there, close the investigation with its outcome, generate the access report as PDF or the CSV export for the supervisory body. Everything the auditor did is in the auditors’ activity register, which administrators see and auditors do not.

The auditor sees everything. And everyone sees what the auditor looked at.

What you can do

  • Four tabs per user

    Access granted, shares made, access received, login history. Complete lists up to ten thousand rows, beyond which Files points to the CSV export, so screen and file match.

  • Investigations with an outcome

    An investigation opens on a specific share or access, is resolved with a written outcome and remains available. The person involved sees they are under investigation.

  • Tracked questions and answers

    “Why did you share this folder with firm X?” The user receives the question in their area and answers in writing. Question and answer stay together in the dossier.

  • PDF and CSV reports

    Access report for the whole tenant or a single person, as a PDF ready to attach and as CSV for those who need to cross-check data.

  • The auditors’ register

    Every inspection, view, report, question and investigation is logged. Administrators see it; the auditor sees only their own, in “My activity”. Nobody checks without leaving a trace.

  • With Access change reason

    If that extension is on, the auditor receives every access level change by email with its reason: the check arrives before anyone asks for it.

Frequently asked questions

Can the auditor open files?

Not as auditor: the role sees metadata — who has access to what, who shared, who logged in — not contents. To open a file they need normal access to the folder, like anyone else.

Who can be an auditor?

Anyone with the privilege in their user type, or designated from the panel. Tenant administrators always are. Managing auditors in turn requires the privilege to manage members.

Does the user know they are being checked?

They know auditors exist and see the questions and investigations that concern them. They do not see the auditors’ activity register: that belongs to administrators.

Move your company files to the cloud

Request a demo: we’ll show you how Files makes storage and sharing simple and secure.

Request a demo