Security and audit : Who can see what, and why. Who did what, and when.
One access model for everything on the platform - a site, a list, a dashboard, a flow, an agent, a safe - and one place to ask the two questions that matter: who can see this, and who did that.
What it does
Security and audit, point by point.
One model, every kind of thing
Access is given to a person, a department, a position, a group or everyone, on a ladder of roles. A thing inherits from where it lives unless you say otherwise.
The access map
Start from a person and see everything they can reach, and through which entry. Start from a thing and see everyone who can reach it.
Sign-in is your identity provider's
People sign in with OpenID Connect. Passwords, second factors and the link to your directory live there; the platform follows that session.
Ask why
Pick a person and a thing: the Security Center says whether they can reach it, and names the entry that decides.
An audit trail
The Audit Center answers who did what, when, and with what outcome - as a timeline you can filter, with what changed shown side by side, and a check that the trail itself is intact.
Apps and agents inside the same rules
An app runs in a sandbox with declared capabilities. An agent acts as someone. Neither is a way around a permission.
Rules for the assistant
A compliance gate gives the assistant your organisation's guidelines and checks each drafted answer against them before it is shown.
Health, too
The Insights Center shows how fast pages and lists are, which requests are slow, and suggestions for what to do about it.
Getting started
Three steps in.
- Open the Security Center.
- Pick a person: the map shows what they can reach and why.
- Open a thing from the map to change who may reach it.
Questions
What people ask about Security and audit.
Which identity providers work?
Sign-in is OpenID Connect. Divan is run with Authentik, which federates to Active Directory and other directories.
Does search leak what I cannot open?
No. Every kind of result is checked by the rule that guards it before it is shown.