# Audit engagements (https://developers.asip.io/docs/queries/audit-engagements)

Scheduled and completed audits at your stations, for the audit team. The executive summary appears only once the report is issued.

> **Status: Available on request.** API keys, the read-only Data API, the MCP server (with an API key) and signed webhooks are live on app.asip.io. Developer access is off by default for every company: ask ASIP to enable it for yours (https://developers.asip.io/docs/how-to-get-access). One-click OAuth sign-in for AI connectors (claude.ai, ChatGPT, Copilot) is not available yet; use an API key. The changelog at https://developers.asip.io/docs/changelog says when each part becomes available.

|           |                                                                                                                                                  |
| --------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| Data API  | `GET /api/v1/data/audit-engagements` and `GET /api/v1/data/audit-engagements/feed` ([endpoint reference](/docs/api-reference/audit-engagements)) |
| MCP query | `query://asip/audit_engagements`                                                                                                                 |
| Scope     | `audits:read`                                                                                                                                    |
| Module    | Audits, switched on at the station                                                                                                               |
| Filters   | `cursor`, `limit`, `updatedSince`, `stationId` (list only)                                                                                       |
| Order     | `updatedAt`, then `id`: the feed delivers new **and changed** engagements                                                                        |

## Who can read it

The audit team, and only in an oversight role. The key's owner needs **both**:

* an **oversight role**; and
* one of the audit permissions **Act as official auditor** or **Review submitted audits**.

Anyone else gets `403 restricted`. Records come from the stations in the owner's scope where the Audits
module is on.

## What each record carries

| Field                                               | Meaning                                                                      |
| --------------------------------------------------- | ---------------------------------------------------------------------------- |
| `id`, `module`, `url`                               | The engagement's ASIP id, `audits`, and a link to it in ASIP.                |
| `reference`                                         | The engagement's reference.                                                  |
| `stationId`, `lineOfBusinessCode`                   | Where the audit takes place.                                                 |
| `scopeStandardKeys`                                 | Keys of your company's registered standards the audit covers.                |
| `title`, `auditType`, `status`                      | What is audited, the kind of audit, and where it is in its workflow.         |
| `plannedStartAt`, `plannedEndAt`                    | The planned dates.                                                           |
| `actualStartAt`, `actualEndAt`                      | The actual dates, or `null`.                                                 |
| `openingMeetingAt`, `closingMeetingAt`, `timezone`  | Meeting times and the audit's time zone.                                     |
| `reportIssuedAt`                                    | When the report was issued, or `null` if it has not been.                    |
| `executiveSummary`                                  | The lead auditor's executive summary: **`null` until the report is issued**. |
| `closedAt`, `cancelledAt`, `createdAt`, `updatedAt` | Lifecycle times.                                                             |

## What is left out, and why

* **The executive summary before the report is issued.** Until then the findings are unreleased, and
  the platform never returns unfinished work (see [The Rulebook](/docs/rulebook#unfinished-work)).
  Check `reportIssuedAt`: while it is `null`, `executiveSummary` is always `null`.
* **Who the auditors are.** The lead and support auditors' user ids, the accountable capacity and who
  created the engagement are not returned. The platform does not hand out people ids.
* **Why an engagement was cancelled** (`cancelledReason`) and the internal `version` counter.

## Feed

The feed is ordered by `updatedAt`, so a change to an engagement, such as the report being issued,
delivers it again. Like every feed, it stops 30 seconds behind the current time. See
[Keeping in sync with /feed](/docs/api-reference#keeping-in-sync-with-feed).
