For Internal Audit
Evidence you can follow back to its source
Every finding keeps its origin, every control keeps its mapping reasoning, and platform activity is written to an append-only log, so testing does not begin with reconstructing what happened.
- Immutable platform audit log, alongside per-module trails
- Segregation-of-duties conflict rules with recorded exceptions
- Evidence passed through explicit review, not just attached
- Permission bundles granular enough to evidence who could do what
| Action | asset-viewer | asset-coordinator | asset-approver | asset-admin |
|---|---|---|---|---|
| View | Allowed | Allowed | Allowed | Allowed |
| Create and edit | Not allowed | Allowed | Not allowed | Allowed |
| Submit for intake | Not allowed | Allowed | Not allowed | Allowed |
| Send to review | Not allowed | Allowed | Not allowed | Allowed |
| Send back | Not allowed | Allowed | Allowed | Allowed |
| Approve | Not allowed | Not allowed | Allowed | Allowed |
| Activate | Not allowed | Not allowed | Allowed | Allowed |
| Module settings | Not allowed | Not allowed | Not allowed | Allowed |
Every module ships bundles at this granularity. Segregation-of-duties conflicts are declared as rules, with logged exceptions.
Goals & pressures
What you are accountable for
Sentinel Unity is shaped around how this role actually works in regulated organizations, not generic GRC marketing language.
Goals
- Establish who could perform an action, not just who did
- Trace a reported score back to the evidence behind it
- See remediation sequencing and where it actually stalled
- Test control design and operation as separate questions
Common pressures
- Audit trails that can be edited by an administrator
- Role models too coarse to demonstrate duty separation
- Evidence folders with no record of who accepted them
- Findings whose originating assessment is no longer identifiable
Platform modules
How Sentinel Unity supports this role
Real modules from one connected platform with shared controls, evidence, and audit history across risk, compliance, and audit workflows.
See Sentinel Unity from the internal audit seat
A walkthrough scoped to the work you actually own, using your frameworks and entity structure.