Platform · trust

Give your auditor a login, not a folder of exports

Most of what an audit costs is waiting — for an extract, for an explanation, for someone to find the invoice behind a balance. A scoped read-only role with real drill-down removes most of that, and it is the single most requested capability we hear from controllers who have been through a first audit.

Bring your auditor

We will walk your audit team through the drill path and the automation record without a salesperson on the call.

1 / 3
Six-level drill-downPeriod-scoped and expiringAgent actions included
Your auditor gets this path read-only, including the agent action at the bottom.

What they get

Six things, without asking you.

Drill-down to source

From a balance sheet line to the account, the transaction, the journal entry, the source document, and the agent action that produced it. Six levels, no request required.

Exportable everything

Trial balances, period tie-outs, the general ledger detail, and the full audit trail in CSV or JSON. An auditor who has to ask you for extracts is an auditor billing you for waiting.

Genuinely read-only

The role cannot post, edit, approve, or change configuration. It is enforced in the data layer rather than by a permission checkbox, so there is no path that grants it accidentally.

PBC list support

Standard prepared-by-client requests mapped to saved views, so the annual scramble to assemble the same twelve extracts becomes a link you send.

The automation record

Which actions were taken by agents, at what authority level, under which policy version, with what confidence — in the same schema as human actions.

Scoped by period

Access limited to the periods under audit, with an expiry date. Auditor accounts do not linger open for years after the engagement ends.

The question auditors are starting to ask

Automated activity inside a financial system is squarely within the scope of a controls assessment, and audit firms are getting more specific about it. The questions arriving now are what the software was permitted to do, how that permission was granted and by whom, whether it changed during the period, and how you would detect it acting outside its scope.

Those are answerable here because authority is enforced as middleware and every grant is logged. An auditor can pull the authority matrix as configured for each month of the period, see every change to it with actor and timestamp, and reconcile that against the population of automated postings.

“What was the software allowed to do, and did that change during the period?” is becoming a standard question. Most systems cannot answer it at all.

Sampling gets easier, not harder

A common worry is that automation makes sampling harder because there are more transactions with less human review. In practice it goes the other way: the population is more uniform, the control is deterministic and testable rather than depending on a person’s diligence, and every item carries a complete record of how it was produced.

An auditor testing a policy-based control can inspect the policy definition, confirm it was in force for the period, and test that the population conforms — which is a stronger assertion than sampling twenty-five manually keyed invoices to infer whether a human control operated consistently.

What we do not claim

Auditor access does not make an audit cheap, and no software does. Judgement areas — revenue recognition treatment, allowance estimates, going concern, related parties — still require the same conversations. What this removes is the mechanical friction: extracts, drill-downs, and the "can you send me the invoice behind this" email that gets repeated forty times.

We join the call

We will walk your audit team through the drill path, the authority matrix, and the trail export directly, without a salesperson present. Controllers tell us this is disproportionately useful in a first audit, and it costs us nothing.

Questions

What audit teams ask.

Does the auditor role cost extra?
No. External auditor seats are included on every tier, because charging for the role that verifies your books would be a strange thing to monetise.
Can we limit what they see?
Access is scoped to the periods and entities under audit and carries an expiry. Within that scope drill-down is complete — a partial audit trail is worse than none because it invites the question of what was withheld.
What formats do exports come in?
CSV and JSON, plus direct delivery into a warehouse for larger engagements. Trial balance, GL detail, period tie-outs, and the full audit trail.
Do agent actions appear differently from human ones?
Same schema, clearly attributed. An agent action carries additional fields — model version, policy applied, confidence — that a human action does not, which is what makes automated activity testable.
Can our auditor test the correctness of the ledger itself?
They can read the published property-based test suite and the third-party attest review of the engine. That is a separate assurance from SOC 2, which covers security rather than whether the arithmetic is right.

Make the next audit shorter.

Bring your audit team to a walkthrough. No salesperson, forty minutes, and it front-loads the questions.