External repository
In Short
An external repository is a content system a client already operates — a document management platform, content store, or shared drive — that a review program draws material from. Connecting to one raises a question generic integrations do not: which boundary the content is being reviewed inside.
Definition
Most organizations do not want to relocate their document estate to start a review program. The material lives where it lives, and the review needs to reach it.
Three properties determine whether such a connection is safe.
Authorization is delegated, not assumed. The connection carries a specific, revocable grant to the material in scope — not standing access to the repository. A connector holding broader access than the engagement requires is an exposure whether or not that access is exercised.
Scope is explicit. The material in scope for review is identified, and the connector reaches that material rather than whatever it is technically able to read. This matters because repository permissions are usually broader than any single engagement.
Provenance survives the hop. A review outcome refers to a specific version of a specific document. If the connection loses that reference, the outcome becomes difficult to tie back to what was actually reviewed — a problem that only surfaces when someone asks.
The direction of movement is the design decision. Content referenced from an external repository stays under that system's governance, with the review boundary applying to the review artefacts. Content copied in comes under the review program's boundary and its retention posture, creating a second location the client must account for. Neither is wrong, but the choice should be deliberate, since the answer to "where is this material now?" differs.
Why It Matters
Integration convenience and boundary discipline pull against each other. The easy connection is a broad credential that reads everything; the defensible one is scoped to the engagement and revocable when it ends.
Clients also need a clear answer about where their material resides during and after review. That answer follows from whether content was referenced or copied, so the question is worth settling before the connection is built.
How QueryTek Uses It
QueryTek Review connects to client repositories through authorized, engagement-scoped handoffs rather than standing broad access, and keeps review artefacts inside the tenant boundary. Supported connectors and authorization models are covered in engagement onboarding.
Related Terms