Skip to content
Notifications
Clear all

TIL: You can assign controls to 'owners' who aren't full Drata users (guest role)

41 Posts
40 Users
0 Reactions
74 Views
(@harukik)
Honorable Member
Joined: 3 months ago
Posts: 400
 

Oh, that's a neat trick! So it's for one-off tasks, basically? Like asking someone to just upload the monthly server log, but nothing else.

Does it send the guest a normal email link to do the thing, or do they get some weird portal login?



   
ReplyQuote
(@clarag)
Reputable Member
Joined: 3 months ago
Posts: 274
 

Yeah, exactly! One-off or super specific tasks are the sweet spot.

They get a normal email with a link, which is nice. But in my testing, that link just takes them to a portal login page anyway. So they still have to set up a Drata guest account with a password first. It's not as seamless as just clicking and doing the thing in the email.

Did you run into that too, or did yours work differently?



   
ReplyQuote
(@henryg78)
Estimable Member
Joined: 3 months ago
Posts: 165
 

That login step is standard. You can't bypass it without giving them a full account, which defeats the purpose.

The friction isn't the login itself, it's the account lifecycle. You now have a dormant guest account after they complete the one task. We ran a script that listed all guest accounts older than 90 days with no recent activity and found dozens. Each is a minor compliance finding waiting to happen if you have strict access review controls.

For true one-offs, we now use a service account with the guest role and a shared mailbox. The process owner emails the evidence to that address, and we upload it. It adds a step for us, but eliminates the guest account sprawl.


EXPLAIN ANALYZE


   
ReplyQuote
(@anitak)
Reputable Member
Joined: 2 months ago
Posts: 337
 

That "spoon to dig a trench" analogy is spot on for the user experience. Your point about the real process owners being able to provide evidence is the key benefit, though.

A practical caveat I'd add is about context. When you assign a control to a guest, they only see that one task in isolation. They can't see the control framework, the policy it links to, or why it matters. You need to build all that context into the task description itself, otherwise you just get a confused file upload with no understanding. It shifts the communication burden upstream.

It's a useful feature for breaking a logjam, but it definitely trades a license cost for manual coordination effort.


—Anita


   
ReplyQuote
(@crm_hopper)
Honorable Member
Joined: 7 months ago
Posts: 472
 

That's it exactly. The quality of those instructions becomes a single point of failure. And good luck getting anyone outside the security team to write them well.

We once had a control for "review vendor SOC2" assigned to a finance guest. The description just said "upload the report." They uploaded a 300-page PDF with no summary page or attestation letter. The compliance lead spent two hours hunting for the right page. So much for saving money.


CRM is a necessary evil


   
ReplyQuote
(@charliea)
Reputable Member
Joined: 2 months ago
Posts: 247
 

Exactly. That's the hidden cost they never show in the demo.

Seen it happen where the guest tries to help, but can't see the linked policy or what evidence was accepted last cycle. So they over-deliver a mountain of irrelevant files. Now someone has to sort through it, and the cycle time for that control doubles.

The spoon works if you already marked the exact spot to dig. Most instructions aren't that good.


Demo or it didn't happen


   
ReplyQuote
(@eliot77)
Reputable Member
Joined: 2 months ago
Posts: 244
 

The hardened API contract comparison is almost too generous. An API has defined schemas and error codes. Here, you're expecting someone with zero context to get the input format perfect on the first try, with only prose instructions.

The real comedy is that this feature is marketed as reducing friction, but it only works if you first introduce massive friction by writing a multi-page spec for a single upload field. At that point, the license seat looks cheap.


Show me the data


   
ReplyQuote
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
 

The cycle time doubling is the real killer. It's not just sorting through the junk, it's the back-and-forth emails that follow when you have to reject the evidence and ask for the right file. Suddenly your one-click guest assignment turns into a week-long email thread that burns more engineering minutes than just doing it yourself.

But that's the magic of these platforms, isn't it? They externalize the coordination overhead onto your team and call it a feature. "Look, we saved a license seat!" by consuming three hours of a senior dev's time writing specs and playing evidence librarian.


null


   
ReplyQuote
(@charlotte2)
Reputable Member
Joined: 3 months ago
Posts: 337
 

The lawnmower analogy is cute, but it skips the part where your neighbor accidentally dumps the grass clippings back on your driveway because they couldn't find the compost bin. You've just traded a "can't log in" excuse for a "I didn't know what to upload" support ticket.

Saving a license seat is great until you calculate the hourly rate of the person now writing forensic-level instructions for a single upload field. That's not delegation, it's just moving the bottleneck.


But what about the edge case?


   
ReplyQuote
(@dianaf)
Reputable Member
Joined: 3 months ago
Posts: 260
 

Yeah, the lawnmower analogy is a good one. It made me realize the "guest role" works if you're only lending out the most basic, single-purpose tools.

The first time I tried this, I assigned a control to our HR lead. The task was just "confirm these background check policies are posted." Simple, right? They uploaded a screenshot of their desktop with the file folder open, not the actual policy document. They couldn't see the example from last cycle or the acceptance criteria I'd written for the team.

It still saved a seat, but it cost me two Slack threads and a quick call to explain what a policy document even looks like. So yeah, a spoon is about right.



   
ReplyQuote
(@ethanb8)
Reputable Member
Joined: 3 months ago
Posts: 417
 

The lawnmower analogy is a good way to frame it. The core benefit is real - you finally get the actual process owner involved without buying a full seat.

The part that catches teams off guard is the neighbor's expectation. Handing them the lawnmower assumes they know how to start it, where the gas is, and what to do with the clippings. The guest role hands them the tool but none of the institutional knowledge that makes it useful. You save the license cost, but you often spend it in support time instead.


Keep it civil, keep it real


   
ReplyQuote
Page 3 / 3