Documentation

Audit & compliance.

Audit log

What it is. A complete, tamper-evident record of everything that happens — logins, query submissions and decisions, datasource changes, channel edits. It's your answer to "who did what, when" for security reviews and compliance. Records are append-only and cryptographically chained, so a deleted or altered entry is detectable after the fact (query result data is never stored).

Configure it. Nothing to switch on — it captures automatically. Review it at /admin/audit-log:

Audit log admin page with action and resource filters, an actor / resource ID search, an Export CSV button, a Verify chain button, and a chronological list of recent USER_LOGIN events with actor avatars and IP addresses.
/admin/audit-log — filter, paginate, verify the HMAC chain, and export to CSV.
  1. Filter and search. Narrow by action, resource type, actor user id, or resource id; an optional start/end date pair scopes the window.
  2. Verify chain. The Verify chain button re-walks every row's HMAC link in order and surfaces the first mismatch — useful as a recurring auditor check.
  3. Export CSV. Streams the current filter as RFC 4180 CSV with the same columns shown in the UI. Long-running exports respect the same query budget as the table view (use date filters to keep them bounded).

Tune it. The chain-signing key defaults to a per-deployment value derived from ENCRYPTION_KEY; set AUDIT_HMAC_KEY (hex, ≥ 32 bytes) explicitly when you want to manage or rotate it yourself. Inserts run through a dedicated AUDIT_DB_USER / AUDIT_DB_PASSWORD role that has no UPDATE / DELETE rights on the log.

Compliance reports & signed exports

What it is. Ready-made compliance reporting with audit-grade exports. Two pre-built reports answer common auditor questions over a chosen period: classified-data access (which executed queries touched PII / PCI / PHI / GDPR / FINANCIAL / SENSITIVE data, joined to your data-classification tags) and a regulatory audit trail of DDL / DELETE operations with the approvers' names. Use it to hand a regulator or internal auditor evidence they can verify themselves.

Configure it. Build and export reports from the compliance dashboard at /admin/auditor — open to the read-only AUDITOR role and to admins. Each report exports as a digitally signed PDF or CSV that an auditor can verify offline against the public key at /api/v1/admin/compliance/signing-certificate; every export is itself recorded in the audit log with its content hash, so it's tamper-evident end to end.

Tune it. ACCESSFLOW_COMPLIANCE_MAX_REPORT_PERIOD (largest window, default P366D) and ACCESSFLOW_COMPLIANCE_MAX_ROWS (row cap before a report is marked truncated, default 50000). Signing reuses JWT_PRIVATE_KEY — no extra secret required.

The read-only AccessFlow Auditor dashboard with the compliance report builder for classified-data-access and regulatory audit-trail reports over a chosen period.
/admin/auditor — the read-only Auditor role builds and signs compliance reports over the immutable query snapshots.

Data lifecycle & right-to-erasure

Admin. Define retention/erasure rules at /admin/lifecycle/policies — per datasource, target a table / column set / classification tag with a retention window (ISO-8601, e.g. P30D or P7Y) plus arbitrary conditions (a structured, parameter-bound predicate builder and a JSqlParser-validated raw-WHERE escape hatch — SQL datasources only) and an action: hard-delete, soft-delete, or pseudonymize (salted SHA-256 / format-preserving / tokenization), with an optional cron schedule. A dry-run preview reports impact without executing. The scan job stages eligible work (honouring the cron); tune it with ACCESSFLOW_LIFECYCLE_POLICY_SCAN_INTERVAL (default PT1H). Staged runs now execute automatically through the proxy — ACCESSFLOW_LIFECYCLE_POLICY_EXECUTION_INTERVAL (default PT5M).

Any user can file a right-to-erasure request at /lifecycle/erasure using the same rich configuration (subject identifier and/or target table + conditions). It flows through AI-assisted scope detection and review-plan-based peer review: any eligible REVIEWER or admin reviews it at /lifecycle/erasure-reviews (per the datasource review plan, multi-stage; the submitter can never approve their own), and stale reviews auto-reject via ACCESSFLOW_LIFECYCLE_REVIEW_TIMEOUT (default PT168H). Approved requests are executed through the proxy — soft-deleted rows vanish from reads, DELETEs become marker updates, aged PII resolves to an irreversible salted hash at read time — with tamper-evident proof-of-deletion audit records and a retention-adherence compliance export. Tune the executor with ACCESSFLOW_LIFECYCLE_ERASURE_EXECUTION_INTERVAL (default PT1M).

Personalized dashboard & weekly digest

The default post-login home (/dashboard) is self-scoped — every user sees only their own data, no admin role required: pending approvals as a reviewer, their recent queries with status/risk trend sparklines, an AI optimization-suggestion backlog they can dismiss or open in the editor, and their own behavioural-anomaly alerts. Widgets are customizable (show/hide, collapse, drag-and-drop reorder) and persist per browser. Users can export the week's summary as a digitally signed PDF/CSV on demand, and opt in to a weekly email digest delivered to their email and any configured chat channels. The digest job is clustered-safe; tune it with ACCESSFLOW_DASHBOARD_WEEKLY_DIGEST_POLL_INTERVAL (how often the job wakes, default P1D) and ACCESSFLOW_DASHBOARD_WEEKLY_DIGEST_PERIOD (minimum gap between digests per user, default P7D).