The EU value-chain cap has been in force since 3 July 2026. It limits what large customers can ask suppliers for.See what applies to you →

Give your auditor a login, not a folder.

This page is written for the assurance provider rather than for the company engaging them. If you are auditing a CoreCanopy inventory, this is what you get and what you can check.

The access itself

  • Read-only. Every figure’s trace and the audit chain are open to you. Nothing can be changed.
  • Scoped to one report. The grant carries the scope; it is not a parameter you or anyone else can widen.
  • Single-use link, with the terms stated before you accept rather than after.
  • Every screen you open is written to the company’s own audit trail, which they can read.
  • The company can end your access at any time, and you can see that it has been ended.

An auditor here is a first-class role in the authorization model, not a user account with extra flags. That distinction matters: were an auditor merely a member of the organisation, they would see every report the organisation had ever filed. An assurance surface whose scope is a request parameter is one forgotten filter away from being a tenant-wide read.

What your assurance provider will ask for.

Six questions, in the order they usually arrive, and where each one is answered.

Where did this figure come from?

Open it. The activity rows, the quantity as entered, any unit conversion, the factor with its publisher, dataset version and valid window, the GWP basis, and the per-gas result.

Why that factor and not another?

The resolver records its deliberation: how it decided, which region level it used, how many candidates it considered, and the runners-up it rejected with the reason for each.

Who entered it, and who accepted it?

Both, with timestamps. Imported rows land needing review and stay out of the totals until a named person accepts them.

Has anything changed since it was filed?

Each audit entry cites the hash of the entry before it. You can run the check yourself and see the sequence range it covers.

What is missing from this inventory?

The completeness register, generated from the organisation’s own sites and declarations, plus the stated-omissions page printed on the report itself.

Can I have it outside the system?

An evidence export in CSV and XLSX, with the licence of every factor cited, so your working papers do not depend on our continued existence.

What we do not claim

CoreCanopy does not provide assurance and does not describe its own output as audited, assured or verified. An external review of the calculation methodology by an independent practitioner is scheduled and budgeted but has not yet taken place. Until it has, we describe the output as ready, and the distinction is deliberate.

Four of fifteen Scope 3 categories are modelled. Category 1 is spend-based on a United States economic proxy for non-US organisations, and the report says so on the face of the disclosure. Market-based Scope 2 currently falls to a disclosed grid fallback because the residual mix dataset is not licensed to us.

Auditor access does not consume a seat. An auditor is a separate subject type rather than a member of the organisation, so granting you access costs the company nothing and users are unlimited on every tier regardless. We would rather you were in the system looking at lineage than reconciling a spreadsheet someone exported for you.

Book a walkthrough