> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Explore the Access Graph

> Visualize which people, agents, and machines reach which Resources through which Connectors

## Overview

The Access Graph turns your logs into a map of who accessed what. It links identities to the Connectors they went through and the Resources they reached. Use it to answer questions such as "Who reaches the production database?" or "Which agents trigger the most policies?"

The graph reflects observed traffic, not granted permissions. An identity appears only after it has sent traffic that matches your query.

## Open the Graph

<Steps>
  <Step title="Open Logs">
    Go to [Logs](https://app.formal.ai/logs). You need the **Logs** permission.
  </Step>

  <Step title="Switch to the graph">
    In the toolbar, click **Graph**, next to **Logs** and **Aggregations**.
  </Step>

  <Step title="Scope the data">
    Set the time range and the log query. The graph uses the same filters as the log table.
  </Step>
</Steps>

**Verify:** The graph shows columns of nodes for the identities, Connectors, and Resources in the logs you selected.

## Read the Graph

Nodes are arranged in layers, and edges show traffic between them:

| Layer | Contains |
| - | - |
| **Humans** | People who sent traffic |
| **Agents** | AI agents, such as coding agents running through the Formal Endpoint |
| **Machines** | Machine users, such as services and CI jobs |
| **Connectors** | Connectors that carried the traffic |
| **Resources** | Resources that received it |

Use the controls to shape the view:

* **Sort by:** rank nodes by **Log Volume** or **Triggered Policies**
* **Direction:** lay the layers out **Horizontal** or **Vertical**
* **Nodes per layer:** show the top 1 to 100 nodes in each layer

## Investigate a Node

Click a node to open its details. The panel shows information about the identity, Connector, or Resource. It also lists the policy actions it triggered, an activity summary with its **Connected Nodes** and **Paths**, and sensitive fields when Formal has classified them.

From the panel:

* Click **Focus Query on This Node** to add the node to the log query. Click **Unfocus** to remove it.
* Hover over a connected node and click **Filter Query to This Connection** to keep only the logs between the two nodes. Connections that triggered policies show a warning icon.
* Switch back to **Logs** to read the matching log entries.

## API

The graph is also available through `core.v1.GraphService`:

| Method | Returns |
| - | - |
| `GetAccessGraph` | Nodes and edges for a log query and time range, with a top-N limit per layer |
| `GetAccessGraphNodeDetails` | Details and policy breakdown for one node |

See the [API reference](/docs/api/introduction) for request fields.

## Next Steps

<CardGroup cols={2}>
  <Card title="Logs" icon="file-lines" href="/docs/guides/observability/logs">
    Search and filter logs
  </Card>

  <Card title="Triggered Policies" icon="clock-rotate-left" href="/docs/guides/policies/suspensions">
    Review requests that triggered policies
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.