External auditor role with Edit functionality
AnsweredI've assigned my external auditors the external auditor role within my workspace. As a private company, we've historically allowed our auditors edit-access within Microsoft Word to drafts of our audited financials. In Workiva, would an external auditor with the external auditor role, with editor access allowed in a specific Workiva document give my external auditors the ability to edit in that specified document?
0
-
Hi Steven Zimmer,Short Answer is no. The External Auditor role will NOT allow your auditors to edit a Workiva document, even if editor permission is granted on that document.
This is because roles act as the ceiling for what users can do. In Workiva, roles and permissions work together — but the role always sets the maximum capability:- Roles → Control what features and experiences a user can access
- Permissions → Control the level of access (Viewer/Editor/Owner) to a specific file or document
Key rule: If you have a Viewer role and someone gives you Editor permission to a document, you still won't be able to edit the document because of your Viewer role.
The External Auditor role is a GRC-specific database role, not a workspace role like "Editor" or "Viewer." Its designed purpose is to allow auditors to:
- Access Testing/Audits, Remediation, Reports, and Dashboards
- View and export test forms (with appropriate permissions and workflow status)
It does not grant document editing capabilities in the Files/Documents experience.
To allow your external auditors to edit a specific Workiva document (like your audited financials draft), they would need:
1. The workspaceEditorrole (not just the External Auditor GRC role)
2. Editor-level permission on that specific documentYou can assign both roles simultaneously - the External Auditor role for GRC access and the Editor workspace role for document editing. If multiple roles are assigned, the role with the most access takes precedence.Consider whether granting the fullEditorworkspace role is appropriate for your auditors, as it gives broader document editing capabilities across the workspace. If you want to limit editing to only specific documents, you can combine theEditorworkspace role with tightly scoped document-level permissions.1
Comments
2 comments