Overview
The Access Graph turns your logs into a map of who accessed what. It links identities to the Connectors they went through and the Resources they reached. Use it to answer questions such as “Who reaches the production database?” or “Which agents trigger the most policies?” The graph reflects observed traffic, not granted permissions. An identity appears only after it has sent traffic that matches your query.Open the Graph
1
Open Logs
Go to Logs. You need the Logs permission.
2
Switch to the graph
In the toolbar, click Graph, next to Logs and Aggregations.
3
Scope the data
Set the time range and the log query. The graph uses the same filters as the log table.
Read the Graph
Nodes are arranged in layers, and edges show traffic between them:
Use the controls to shape the view:
- Sort by: rank nodes by Log Volume or Triggered Policies
- Direction: lay the layers out Horizontal or Vertical
- Nodes per layer: show the top 1 to 100 nodes in each layer
Investigate a Node
Click a node to open its details. The panel shows information about the identity, Connector, or Resource. It also lists the policy actions it triggered, an activity summary with its Connected Nodes and Paths, and sensitive fields when Formal has classified them. From the panel:- Click Focus Query on This Node to add the node to the log query. Click Unfocus to remove it.
- Hover over a connected node and click Filter Query to This Connection to keep only the logs between the two nodes. Connections that triggered policies show a warning icon.
- Switch back to Logs to read the matching log entries.
API
The graph is also available throughcore.v1.GraphService:
See the API reference for request fields.
Next Steps
Logs
Search and filter logs
Triggered Policies
Review requests that triggered policies