Create a comment for a control within an audit
Creates a new comment on a control within an IRL audit. The comment author must be an auditor in the audit firm making the request. The comment will be associated with the control and visible to all authorized users.
Returns 404 when the control is not part of the audit.
Rate limit: 50 requests / minute.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Comments enable auditors and customers to collaborate on a control within an audit. All comments are immediately visible to authorized parties once created.
The text content of the comment. Must be at least 1 character. Can include questions, clarifications, or explanations related to the control.
Email address of the comment author. Must match an existing Vanta user who belongs to the audit firm making the API request. This email uniquely identifies the author across systems.
Timestamp when the comment was created in the external audit management system. This allows synchronizing comment timestamps from external systems. Format: ISO 8601 UTC timestamp.
Response
Ok
A comment on a control within an audit. These threaded discussions let auditors and customers collaborate on a specific control — asking questions, documenting reasoning, or recording follow-ups — directly against the control being assessed.
Audit control comments are scoped to a single audit engagement and are distinct from any organization-internal control comments.
The unique identifier for the comment within Vanta's system. Format: ObjectId as a string (e.g., "6890e473dce1da5d8406f5e7").
The comment message content. Can include explanations, questions, or clarifications about the control.
Timestamp when the comment was created. Format: ISO 8601 UTC timestamp.
Timestamp when the comment was last edited. Null if the comment has never been modified. Format: ISO 8601 UTC timestamp.
Timestamp when the comment was soft-deleted. Null if the comment has not been deleted. Soft deletes retain the comment for audit history while hiding it from normal operations. Format: ISO 8601 UTC timestamp.
Email address of the comment author. This email uniquely identifies users between Vanta and external audit systems. Null when the comment author can't be matched to a Vanta user.
Human-readable display name of the comment author. Null if the author's name is not available (e.g., user was deleted). This enables correct author attribution in integrations where users cannot be reliably matched across systems by email alone.