Auditors scoping three civic entities need broad read visibility into policies, risks, and controls in scope. What access pattern is appropriate?
Select an answer to reveal the explanation.
Short Explanation
Auditors need a library card, not the master keys to rebuild the library. Read across the entities in scope is enough; full GRC admin is overkill and risky. Screenshots-only is the other extreme.
Full Explanation
Least-privilege auditor access typically includes sufficient read (and engagement-task) rights across scoped entities, controls, and risks without elevating every auditor to GRC administrator. Admin-for-convenience, zero entity access, or allowing auditors to alter entity architecture during fieldwork violate that persona pattern.