Skip to content

Assessor access

External assessors review controls and evidence against the same system of record your team operates — without a separate portal product.

This page is for coordinating with assessors. Actor boundaries and RBAC details: Access Model. What a fingerprint or seal proves: Verification.

What is live today

CapabilityMaturityWhat it gives you
Scoped Auditor / Read-Only Viewer roleLiveOrg admin invites the assessor into the customer tenant with read-only access for the engagement
In-product reviewLiveAssessor reads risks, controls, policies, and evidence packages in the Arbiter dashboard — not a separate SKU
SHA-256 fingerprinted evidenceLiveTamper-evident check at upload; if the file changes, the fingerprint breaks
Structured export packagesLiveHash-verified audit-package ZIP and related examination handoffs (authenticated surfaces)

Assessors do not receive write access to your register. Partner Read and MCP inherit the same RBAC as the minting user — an assessor-scoped key cannot mutate what the assessor cannot see in the UI.

What a fingerprint proves

A SHA-256 fingerprint proves the bytes you have now match what was fingerprinted then. It does not prove that an assessor agreed with your control narrative, or that Arbiter’s internal review was correct.

By default, integrity stops at SHA-256 fingerprints (tamper-evident). Optional Stratum sealing (Verified on-chain) is available by arrangement and proves anchoring of a published digest — not correctness of risk scores. See Verification.

How to get set up

  1. Customer org admin opens Arbiter → Users / Roles.
  2. Invite the assessor with the Auditor or Read-Only Viewer role template (shipped).
  3. Assessor signs in and reviews scoped records and packages for the engagement.
  4. For programmatic read, mint an API key under that assessor’s user — the key inherits their read-only permissions.

Coordinate engagement scope (which records, which frameworks) with your BlockSkunk contact if needed. Independent public verification without an Arbiter login is not shipped — do not promise a public verify URL.

What is not claimed yet

ClaimStatus
Dedicated assessor portal SKU / separate tenancyNot in v1 — in-product scoped roles only
Public verify URL / offline verify pack without loginPlanned — not started
“Cryptographically sealed” without Stratum configuredDo not claim — see Disclosure Boundary

Was this page clear?