Assessor access
External assessors review controls and evidence against the same system of record your team operates — without a separate portal product.
This page is for coordinating with assessors. Actor boundaries and RBAC details: Access Model. What a fingerprint or seal proves: Verification.
What is live today
| Capability | Maturity | What it gives you |
|---|---|---|
| Scoped Auditor / Read-Only Viewer role | Live | Org admin invites the assessor into the customer tenant with read-only access for the engagement |
| In-product review | Live | Assessor reads risks, controls, policies, and evidence packages in the Arbiter dashboard — not a separate SKU |
| SHA-256 fingerprinted evidence | Live | Tamper-evident check at upload; if the file changes, the fingerprint breaks |
| Structured export packages | Live | Hash-verified audit-package ZIP and related examination handoffs (authenticated surfaces) |
Assessors do not receive write access to your register. Partner Read and MCP inherit the same RBAC as the minting user — an assessor-scoped key cannot mutate what the assessor cannot see in the UI.
What a fingerprint proves
A SHA-256 fingerprint proves the bytes you have now match what was fingerprinted then. It does not prove that an assessor agreed with your control narrative, or that Arbiter’s internal review was correct.
By default, integrity stops at SHA-256 fingerprints (tamper-evident). Optional Stratum sealing (Verified on-chain) is available by arrangement and proves anchoring of a published digest — not correctness of risk scores. See Verification.
How to get set up
- Customer org admin opens Arbiter → Users / Roles.
- Invite the assessor with the Auditor or Read-Only Viewer role template (shipped).
- Assessor signs in and reviews scoped records and packages for the engagement.
- For programmatic read, mint an API key under that assessor’s user — the key inherits their read-only permissions.
Coordinate engagement scope (which records, which frameworks) with your BlockSkunk contact if needed. Independent public verification without an Arbiter login is not shipped — do not promise a public verify URL.
What is not claimed yet
| Claim | Status |
|---|---|
| Dedicated assessor portal SKU / separate tenancy | Not in v1 — in-product scoped roles only |
| Public verify URL / offline verify pack without login | Planned — not started |
| “Cryptographically sealed” without Stratum configured | Do not claim — see Disclosure Boundary |