Read-only by construction
The auditor role has no write permission anywhere in the role matrix.
FOR AUDIT AND ASSURANCE
Every generated artefact names its source, generation time, scope, and staleness. Enterprise provides a dedicated read-only auditor role.
Context
You need to test a control, sample its evidence, and cite the sample — without being given a login that can change anything.
Every generated artefact names its source, generation time, scope, and staleness. Enterprise provides a dedicated read-only auditor role. Generated evidence is never itself an authority.
On this page
The auditor role has no write permission anywhere in the role matrix.
Audit history is stored separately from telemetry and is append-only.
Personal has no history. Team has shared audit history without a dedicated auditor role.
Collection boundary
Precyz does not assert that a control passed. It shows you the record and tells you where the record came from.
Communication content, URLs, paths, query strings, DNS names beyond the registrable domain, headers, cookies, tokens, files, screenshots, form data, keystrokes, usernames, email addresses, hardware serial numbers, or precise location.
Coverage is not complete. Some traffic paths are not observable from the interfaces we use, and geolocation is advisory rather than authoritative.
Not included
Reports, no dedicated auditor role
90-day audit history
Quoted audit history and auditor role