๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Compliance Contacts

Keep one list of everyone who holds a compliance role, such as your Privacy Officer or external auditor, whether or not they have a console login.

Where to find it
Compliance โ€บ Contacts
Who can use it
Anyone whose GRC role can view compliance data; editing contacts needs edit rights; assigning roles and inviting needs GRC administrator rights
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

Auditors often ask "who is your designated Privacy Officer?" or "who is responsible for security?". This page answers that. It lists console users and external contacts together, with each person's organization, job title and compliance roles.

External contacts, such as an auditor, an assessor or a fractional privacy officer, do not need a console account. You can give them a role here for documentation, and invite them to a limited sign-in: they receive an email link and confirm with a six-digit code sent to the same address. It is not a console account, and you can revoke it at any time.

What you see

The Compliance Contacts page, with the add an external contact, filters, contacts table and row actions numbered 1 to 4.
The Compliance Contacts page. Numbers match the list below.
  1. Add an external contact: adds someone without a console login.
  2. Filters: search by name, email, organization or role; Everyone, Console users or External contacts; and Any role.
  3. Contacts table: Name, Email, Organization, Job title, Type, GRC roles, Sign-in, Status and actions. Every column sorts.
  4. Row actions: Set GRC roles, Edit details, Invite to a limited sign-in (or Re-send the sign-in link), Revoke the sign-in, and Remove this contact.

How to use Compliance Contacts

How to add an external auditor

  1. Select Add an external contact.
  2. Enter Name, Email, Organization, Job title and any Notes.
  3. Select Save.

How to assign a compliance role

  1. Select Set GRC roles (the star icon) on the person's row.
  2. Choose one or more roles. Hold Ctrl (or Cmd) to choose more than one.
  3. Select Save roles.

How to invite an external contact to sign in

  1. Select Invite to a limited sign-in on their row.
  2. Choose Access expires after: 7, 30 (default), 90 or 180 days.
  3. Select Send the invitation. The Sign-in column changes to "invited".

How to end someone's access

  1. Select Revoke the sign-in and confirm. They are signed out immediately and the link stops working.
  2. To take them off the list completely, select Remove this contact.

Tips

  • Sign-in status: "console account" for users, "not invited", green "invited", amber "expired" and red "revoked" for external contacts. Hover to see the expiry and last sign-in.
  • A console user's name and email come from their console account and are changed in Users & Permissions.
  • Sending a new invitation replaces the old link, which stops working immediately.
  • These roles describe who does what. They do not grant powers in the compliance module; those come from each user's GRC role in Compliance Settings.

Troubleshooting

  • "No GRC roles have been defined for this organization yet.": Define roles first, then assign them.
  • "This contact has an active sign-in link. Revoke it before changing their email address.": Revoke, change the email, then invite again.
  • "That person has a console account. Remove them in Users & Permissions instead.": Console users cannot be removed here.
  • "The invitation was created but the email could not be sent.": Try sending it again.
  • "Could not save that contact. Is that email address already on the list?": Each email can appear only once.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.