Skip to main content

Draft Report Approvals

Details configuration process for report & section approvers for the Audit Draft Report

A
Written by Andrew Persons

Audits · Draft Reports

Assigning Draft Report Reviewers and Approvers

Set up an owner, entire-report reviewers, and section-level approvers so your team can share the work of reviewing a draft report before it goes to auditors.

Applies to: SOC 2 Type 1 & Type 2 Draft ReportsAudience: Admins & Report Owners

In this article

Overview

Draft Report review used to allow only a single approver. Now you can distribute review responsibility across multiple people — assigning some reviewers to the report as a whole, and others to specific sections or subsections — so no one person has to read and approve the entire document alone.

There are three layers to this workflow:

Role

What they do

Report Owner

The final approver. Only the owner can complete the final approval and send the report to the auditors.

Entire Report reviewers

Reviewers assigned to review the whole document.

Section / subsection reviewers

Reviewers assigned to just one part of the report, useful for spreading review work by topic or ownership.

Note: By default, all admins can act as the report owner. You can narrow this to a specific person.

Step 1 — Set the report owner

  1. Open the Draft Report tab. From your audit, go to Draft Report, then open the report.

  2. Open Assign Sections. Click Assign Sections in the top-right of the report view to open the Assign Review panel.

  3. Choose a Report Owner. By default, this is set to "All admins." Select a specific person from the dropdown if you want one individual to hold final approval.

Assign Review panel showing the Report Owner dropdown

The Assign Review panel opens with a Report Owner field at the top.

Step 2 — Assign reviewers to the entire report

Use the Entire Report section when you want one or more people to review the whole document from start to finish.

  1. Check "Entire Report."This activates the assignment field below it.

  2. Add reviewers. Search for and select each person who should review the full report.

  3. Choose the approval rule:

    • Any one reviewer approves — the section is marked approved as soon as a single assigned reviewer signs off.

    • All reviewers must approve — every assigned reviewer has to approve before it's considered complete.

Entire Report section with two reviewers added and 'Any one reviewer approves' selected

Two reviewers assigned to the entire report, with the approval rule set underneath.

Once reviewers are assigned, the entire report is flagged In Review.

Entire report card showing In Review status and the section approval toggle set to All reviewers must approve

The Entire Report card now shows an "In Review" status, and the approval rule can be switched to "All reviewers must approve" for stricter sign-off.

Step 3 — Assign reviewers to individual sections

If you need more granular control — for example, having subject-matter owners each approve just their part — scroll down to the Sections list. Toggle Show subsections to assign at the subsection level instead of whole sections.

  1. Pick a section(or subsection) from the list.

  2. Assign one or more reviewersto it, the same way you did for the entire report.

  3. Set its approval ruleindependently — each section can have its own "any one" or "all must approve" setting.

Assigning several sections at once

Rather than repeating the assignment for every section, you can apply one set of reviewers to many sections in a single action:

  1. Select the sectionsyou want to assign together using the checkboxes (or click Select all sections).

  2. Use the "Assign to..." fieldthat appears above the list to choose the reviewer(s).

  3. Click Applyto push that assignment to every section you selected.

19 sections selected with a bulk 'Assign to' dropdown open and an Apply button

With sections selected, an "Assign to…" field lets you apply the same reviewer(s) to all of them at once.

When you're finished, click Save Assignments. Assignees are notified automatically.

Reviewing and approving your assigned sections

Reviewers see only the sections assigned to them. Opening the Draft Report shows an Assigned to You panel listing just those sections, along with a running count (e.g. "1 of 19 approved").

Draft Report sections panel with Approve Section and Go to Section buttons for each assigned section

Each assigned section shows an "In Review" tag, an Approve Section button, and a "Go to Section" shortcut that jumps to that part of the document.

  1. Click "Go to Section"to jump straight to that part of the report.

  2. Read the section, and add a comment if you have a question or note.

  3. Click "Approve Section."A confirmation dialog appears where you can add an optional note before confirming.

Approve Section confirmation dialog with an optional note field

Approving a section is final for that reviewer — add any context in the optional note field first.

Note: Once you approve a section, that approval can't be undone from this dialog, so use the note field for anything the next reader should know.

Final approval and sending to auditors

Once all required reviewers have approved their assigned sections, the Report Owner sees a Final Approval panel at the top of the sections list.

Final Approval panel with a Final Approve and Send to Auditors button

The Report Owner completes the process with "Final Approve and Send to Auditors."

Clicking Final Approve and Send to Auditors completes the review cycle and delivers the report to your auditors.


FAQ

Who can be the Report Owner?

Any admin, by default. You can restrict it to one specific admin from the dropdown at the top of Assign Review.

Can different sections have different approval rules?

Yes. The "any one reviewer" vs. "all reviewers must approve" setting is configured independently for the entire report and for each section.

What happens if I assign the same reviewer to multiple sections?

They'll see every assigned section in their own "Assigned to You" list and can approve each one individually.

Can reviewers comment without approving?

Yes. The Comments feature is available alongside section review, so reviewers can raise questions before a section is approved.

Is HITRUST included in this workflow?

No — HITRUST draft reports aren't available in Thoropass. Those become accessible through MyCSF when ready for review.

Did this answer your question?