Invite my team and auditors

Duration: 5 minutes For whom: Admin / Owner of an SME Prerequisite: having a created organisation

CyberPassport manages 4 roles:

Role Main permissions
Owner Everything (creator of the org). Only one per organisation.
Admin Everything except deleting the org. Multiple admins possible.
Collaborator Answer questions, upload evidence, view reports. No access to Settings.
Auditor Read-only access to the published assessment and the Evidence Vault. No access to drafts.

Invite a collaborator

A collaborator is part of your team. They take part in the assessment (answering the questionnaire, uploading evidence).

Steps

  1. Go to Settings → Team (/settings/team).
  2. Click "Invite a collaborator".
  3. Enter their work email address.
  4. Choose the role: Admin or Collaborator.
  5. Click "Send invitation".

📸 Screenshot location: collaborator invitation modal

On the invitee's side

The invited person receives an email (subject: "[CyberPassport] {your org} invites you to join their cybersecurity assessment"). By clicking the link:

  • If they already have a CyberPassport account (with the same email address): they are added to your organisation immediately.
  • If they don't have an account: they go through the signup flow, then are automatically attached.

⚠️ Important: the invitation expires after 72 hours. If the invitee doesn't click within that time, you'll need to re-invite them.

🟣 Tip: to re-invite, on the Team page, find the pending invitation and click "Resend".


Invite an external auditor

An auditor is not a member of your organisation — they are a consultant, a customer, or a regulator to whom you grant read-only access to your published assessment.

Steps

  1. Go to Settings → Team → Auditors (dedicated section).
  2. Click "Invite an auditor".
  3. Enter their email address.
  4. Click "Send".

📸 Screenshot location: auditor invitation modal

What the auditor sees

  • The narrative AI report of your published version only (not your drafts)
  • The score by framework and by domain
  • The evidence uploaded to the vault, with a download link
  • The publication history (the previously sealed versions)

What the auditor CANNOT do

  • ❌ Modify your assessment
  • ❌ Upload / delete / modify evidence
  • ❌ See your drafts in progress
  • ❌ Invite other people

⚠️ Important: if you publish a new version after inviting the auditor, they will automatically see the new version the next time their page refreshes — no need to re-invite. The old seal remains verifiable for regulators who may have noted the old hash.

💡 Good to know: the auditor invitation expires after 30 days. Ideal for a one-off audit; for permanent access (e.g. an audit firm tracking your maturity over time), renew the invitation.


Managing my team day to day

See who has access to my org

Settings → Team: lists all members + their role + their join date + their status (active / awaiting invitation).

📸 Screenshot location: Team page with the list of members + auditors

Change a member's role

  1. On the member's row, click the menu → "Change role".
  2. Choose the new role.
  3. Confirm.

⚠️ Important: moving an Owner to Admin requires transferring org ownership to someone else first (an Owner must always exist).

Revoke an access

  1. menu → "Revoke access".
  2. Confirm.
  3. The person immediately loses access — their JWT token is invalidated at the next refresh.

🟣 Tip: for an auditor, you can also let their invitation expire (30 days) without doing anything. It's less aggressive than a revocation.

Audit log

All sensitive actions (invitation, revocation, role change, publication, evidence deletion) are recorded in Settings → Security → Audit log.

📸 Screenshot location: audit log with a few lines (invite_auditor, publish_assessment, etc.)

Filterable by action type, by user, by date. Exportable to CSV.


Special case — connecting my organisation to a partner (B2B)

If you want to share your report with a customer / supplier / partner who also uses CyberPassport:

  1. Go to Connected organisations (main sidebar).
  2. Click "Connect an organisation".
  3. Search the directory or enter an organisation slug.
  4. Send a connection request.
  5. Once the request is accepted, your published report becomes visible on the partner's side.

📸 Screenshot location: Connected organisations page

💡 Good to know: this is different from inviting an auditor. A B2B partner sees your report in their own dashboard (on the large-group side: they see their N suppliers; on the SME side: they see their connected customers).


Next step

→ If you are an invited auditor: For external auditors → If you want to know all about sealing: Verify a sealed report