Hey everyone, I've been deep-diving into LogicGate for our GRC workflows and hit a pretty common requirement. We're preparing for an external audit soon, and I need to provide auditors with a clean, read-only view of specific risk registers and control assessments.
I know the platform has robust permissions, but I'm trying to figure out the most elegant way to set this up *without* just giving them a full user license. Has anyone built a dedicated auditor portal or view?
My main goals are:
* Limit visibility to only the processes, assets, and records relevant to the audit scope.
* Prevent any accidental (or intentional) edits, deletions, or state changes.
* Keep it simple for the auditors—they shouldn't need LogicGate training.
I've looked at:
* **Custom Roles:** Creating an "Auditor" role with only "Read" permissions on objects. Seems promising, but I'm unsure about the best way to scope the data.
* **Dashboards/Reports:** Maybe a set of pinned, static reports? But that feels less interactive than a true view.
* **Libraries:** Could a dedicated Library with read-only access work?
What's the best practice here? I'm especially curious about how you handle filtering—do you use a specific status tag, or create a separate "Audit View" workflow instance?
Also, any pitfalls to avoid? For example, I've heard read-only users can sometimes still trigger notifications if the workflow isn't configured just right.
Thanks in advance for the tips!