Skip to main content

Overview

The Access Graph turns your logs into a map of who accessed what. It links identities to the Connectors they went through and the Resources they reached. Use it to answer questions such as “Who reaches the production database?” or “Which agents trigger the most policies?” The graph reflects observed traffic, not granted permissions. An identity appears only after it has sent traffic that matches your query.

Open the Graph

1

Open Logs

Go to Logs. You need the Logs permission.
2

Switch to the graph

In the toolbar, click Graph, next to Logs and Aggregations.
3

Scope the data

Set the time range and the log query. The graph uses the same filters as the log table.
Verify: The graph shows columns of nodes for the identities, Connectors, and Resources in the logs you selected.

Read the Graph

Nodes are arranged in layers, and edges show traffic between them: Use the controls to shape the view:
  • Sort by: rank nodes by Log Volume or Triggered Policies
  • Direction: lay the layers out Horizontal or Vertical
  • Nodes per layer: show the top 1 to 100 nodes in each layer

Investigate a Node

Click a node to open its details. The panel shows information about the identity, Connector, or Resource. It also lists the policy actions it triggered, an activity summary with its Connected Nodes and Paths, and sensitive fields when Formal has classified them. From the panel:
  • Click Focus Query on This Node to add the node to the log query. Click Unfocus to remove it.
  • Hover over a connected node and click Filter Query to This Connection to keep only the logs between the two nodes. Connections that triggered policies show a warning icon.
  • Switch back to Logs to read the matching log entries.

API

The graph is also available through core.v1.GraphService: See the API reference for request fields.

Next Steps

Logs

Search and filter logs

Triggered Policies

Review requests that triggered policies