← All documentation
Auditor Packet
The Auditor Packet is a single ZIP you can hand an external auditor — a point-in-time snapshot of the evidence they typically ask for, generated from Reports → Auditor Packet.
What's in it
findings.csv— every finding (code, title, risk, status, category, assessment, due date).policies.csv— your policies (type, version, status, effective/review dates).risk-register.csv— the risk register (likelihood, impact, score, treatment, status, due date).evidence/— the actual evidence files plus amanifest.csvlisting each one (only the current version of each file; superseded versions are skipped).README.txt— a cover sheet with the organization, the generated timestamp, who prepared it, and which sections are included.
Notes
- The packet is a point-in-time snapshot — the README timestamp is the "as of" date.
- Generating it requires an admin or auditor role (the same permission as any export), and it counts toward your organization's export rate limit.
- Like every export, the packet comes with a plan; it is not in the demo.
- If you ask for the AI cover narrative and it cannot be written, the README says why at the top: AI is off for your organization or plan, Watney is paused (until a date, or until we turn it back on for you), or a temporary fault (download the packet again).
- Evidence files are read only from your organization's evidence store; a file that can't be located is listed in the manifest as unavailable rather than silently dropped.