Audits · Draft Reports
Assigning Draft Report Reviewers and Approvers
Set up an owner, entire-report reviewers, and section-level approvers so your team can share the work of reviewing a draft report before it goes to auditors.
Applies to: SOC 2 Type 1 & Type 2 Draft ReportsAudience: Admins & Report Owners
In this article
Overview
Draft Report review used to allow only a single approver. Now you can distribute review responsibility across multiple people — assigning some reviewers to the report as a whole, and others to specific sections or subsections — so no one person has to read and approve the entire document alone.
There are three layers to this workflow:
Role | What they do |
Report Owner | The final approver. Only the owner can complete the final approval and send the report to the auditors. |
Entire Report reviewers | Reviewers assigned to review the whole document. |
Section / subsection reviewers | Reviewers assigned to just one part of the report, useful for spreading review work by topic or ownership. |
Note: By default, all admins can act as the report owner. You can narrow this to a specific person.
Step 1 — Set the report owner
Open the Draft Report tab. From your audit, go to Draft Report, then open the report.
Open Assign Sections. Click Assign Sections in the top-right of the report view to open the Assign Review panel.
Choose a Report Owner. By default, this is set to "All admins." Select a specific person from the dropdown if you want one individual to hold final approval.
The Assign Review panel opens with a Report Owner field at the top.
Step 2 — Assign reviewers to the entire report
Use the Entire Report section when you want one or more people to review the whole document from start to finish.
Check "Entire Report."This activates the assignment field below it.
Add reviewers. Search for and select each person who should review the full report.
Choose the approval rule:
Any one reviewer approves — the section is marked approved as soon as a single assigned reviewer signs off.
All reviewers must approve — every assigned reviewer has to approve before it's considered complete.
Two reviewers assigned to the entire report, with the approval rule set underneath.
Once reviewers are assigned, the entire report is flagged In Review.
The Entire Report card now shows an "In Review" status, and the approval rule can be switched to "All reviewers must approve" for stricter sign-off.
Step 3 — Assign reviewers to individual sections
If you need more granular control — for example, having subject-matter owners each approve just their part — scroll down to the Sections list. Toggle Show subsections to assign at the subsection level instead of whole sections.
Pick a section(or subsection) from the list.
Assign one or more reviewersto it, the same way you did for the entire report.
Set its approval ruleindependently — each section can have its own "any one" or "all must approve" setting.
Assigning several sections at once
Rather than repeating the assignment for every section, you can apply one set of reviewers to many sections in a single action:
Select the sectionsyou want to assign together using the checkboxes (or click Select all sections).
Use the "Assign to..." fieldthat appears above the list to choose the reviewer(s).
Click Applyto push that assignment to every section you selected.
With sections selected, an "Assign to…" field lets you apply the same reviewer(s) to all of them at once.
When you're finished, click Save Assignments. Assignees are notified automatically.
Reviewing and approving your assigned sections
Reviewers see only the sections assigned to them. Opening the Draft Report shows an Assigned to You panel listing just those sections, along with a running count (e.g. "1 of 19 approved").
Each assigned section shows an "In Review" tag, an Approve Section button, and a "Go to Section" shortcut that jumps to that part of the document.
Click "Go to Section"to jump straight to that part of the report.
Read the section, and add a comment if you have a question or note.
Click "Approve Section."A confirmation dialog appears where you can add an optional note before confirming.
Approving a section is final for that reviewer — add any context in the optional note field first.
Note: Once you approve a section, that approval can't be undone from this dialog, so use the note field for anything the next reader should know.
Final approval and sending to auditors
Once all required reviewers have approved their assigned sections, the Report Owner sees a Final Approval panel at the top of the sections list.
The Report Owner completes the process with "Final Approve and Send to Auditors."
Clicking Final Approve and Send to Auditors completes the review cycle and delivers the report to your auditors.
FAQ
Who can be the Report Owner?
Any admin, by default. You can restrict it to one specific admin from the dropdown at the top of Assign Review.
Can different sections have different approval rules?
Yes. The "any one reviewer" vs. "all reviewers must approve" setting is configured independently for the entire report and for each section.
What happens if I assign the same reviewer to multiple sections?
They'll see every assigned section in their own "Assigned to You" list and can approve each one individually.
Can reviewers comment without approving?
Yes. The Comments feature is available alongside section review, so reviewers can raise questions before a section is approved.
Is HITRUST included in this workflow?
No — HITRUST draft reports aren't available in Thoropass. Those become accessible through MyCSF when ready for review.
