Auditor Features
Auditor pages give compliance and security reviewers read-only insight into access activity — everything they need to review, nothing they can change. Auditors cannot create, approve, or revoke anything.
Auditor access is granted by membership in the IDC group configured as AUDITOR_GROUP_ID (see Getting Started). It is independent of admin access — a user can be an auditor, an admin, both, or neither.
There are two auditor pages:
- Approval History — every approval-required request and how it was decided.
- Session Activity — every real elevated-access session and its CloudTrail event log.
Both pages update themselves as activity happens, so a reviewer can leave one open and watch decisions and sessions arrive.