Divan Talk to us
All documentation

Security and audit

One access model for everything on the platform - a site, a list, a dashboard, a flow, an agent, a safe - and one place to ask the two questions that matter: who can see this, and who did that.

The platform underneath About Security and audit

What it is for

One model, every kind of thing
Access is given to a person, a department, a position, a group or everyone, on a ladder of roles. A thing inherits from where it lives unless you say otherwise.
The access map
Start from a person and see everything they can reach, and through which entry. Start from a thing and see everyone who can reach it.
Sign-in is your identity provider's
People sign in with OpenID Connect. Passwords, second factors and the link to your directory live there; the platform follows that session.
Ask why
Pick a person and a thing: the Security Center says whether they can reach it, and names the entry that decides.
An audit trail
The Audit Center answers who did what, when, and with what outcome - as a timeline you can filter, with what changed shown side by side, and a check that the trail itself is intact.
Apps and agents inside the same rules
An app runs in a sandbox with declared capabilities. An agent acts as someone. Neither is a way around a permission.
Rules for the assistant
A compliance gate gives the assistant your organisation's guidelines and checks each drafted answer against them before it is shown.
Health, too
The Insights Center shows how fast pages and lists are, which requests are slow, and suggestions for what to do about it.

Getting started

  1. Open the Security Center.
  2. Pick a person: the map shows what they can reach and why.
  3. Open a thing from the map to change who may reach it.

Tasks

Find out why someone can see a thing

  1. Open the access map.
  2. Start from the person.
  3. Each thing is listed with the entry that grants it: their department, a group, their own name.

See what changed, and who changed it

  1. Open the Audit Center.
  2. Filter the timeline by person, by action or by time.
  3. Open an event: it shows what was changed, before and after.

Questions

Which identity providers work?

Sign-in is OpenID Connect. Divan is run with Authentik, which federates to Active Directory and other directories.

Does search leak what I cannot open?

No. Every kind of result is checked by the rule that guards it before it is shown.

Organisation
Departments, positions, and who answers to whom.
Vault
Credentials that are used, never shown.
Search
One search, across everything you may open.
Agent Studio
AI agents that work as staff - and wait for people.