Security and audit
One access model for everything on the platform - a site, a list, a dashboard, a flow, an agent, a safe - and one place to ask the two questions that matter: who can see this, and who did that.
What it is for
- One model, every kind of thing
- Access is given to a person, a department, a position, a group or everyone, on a ladder of roles. A thing inherits from where it lives unless you say otherwise.
- The access map
- Start from a person and see everything they can reach, and through which entry. Start from a thing and see everyone who can reach it.
- Sign-in is your identity provider's
- People sign in with OpenID Connect. Passwords, second factors and the link to your directory live there; the platform follows that session.
- Ask why
- Pick a person and a thing: the Security Center says whether they can reach it, and names the entry that decides.
- An audit trail
- The Audit Center answers who did what, when, and with what outcome - as a timeline you can filter, with what changed shown side by side, and a check that the trail itself is intact.
- Apps and agents inside the same rules
- An app runs in a sandbox with declared capabilities. An agent acts as someone. Neither is a way around a permission.
- Rules for the assistant
- A compliance gate gives the assistant your organisation's guidelines and checks each drafted answer against them before it is shown.
- Health, too
- The Insights Center shows how fast pages and lists are, which requests are slow, and suggestions for what to do about it.
Getting started
- Open the Security Center.
- Pick a person: the map shows what they can reach and why.
- Open a thing from the map to change who may reach it.
Tasks
Find out why someone can see a thing
- Open the access map.
- Start from the person.
- Each thing is listed with the entry that grants it: their department, a group, their own name.
See what changed, and who changed it
- Open the Audit Center.
- Filter the timeline by person, by action or by time.
- Open an event: it shows what was changed, before and after.
Questions
Which identity providers work?
Sign-in is OpenID Connect. Divan is run with Authentik, which federates to Active Directory and other directories.
Does search leak what I cannot open?
No. Every kind of result is checked by the rule that guards it before it is shown.
Related
- Organisation
- Departments, positions, and who answers to whom.
- Vault
- Credentials that are used, never shown.
- Search
- One search, across everything you may open.
- Agent Studio
- AI agents that work as staff - and wait for people.