When something goes wrong with access control, the first question is always 'what happened?' Canopy records every security-sensitive action automatically: who did it, what changed, and when. No instrumentation required.
Permissions inherit across nodes. Roles are assigned at different levels. Access changes ripple through the tree, and the impact isn't always obvious. Audit logs make that complexity traceable: every change, every actor, every affected resource.
When a user reports they can't access something, audit logs show exactly what changed and when. Trace the chain: who removed the role, when the node was moved, which API key made the call.
Every entry includes timestamps, actor identification, and resource details. Whether you need SOC 2 evidence, internal security reviews, or incident response records, the data is already captured.
Canopy records every security-sensitive operation by default, comprehensive and automatic. No opt-in toggles, no manual instrumentation. If it affects access control, it's in the log.
Nothing to wire up in your application. Logging happens at the platform layer.
No opt-in toggles. Every account captures the full record from day one.
If an operation affects access control, it lands in the log, every time.
Recorded consistently, whoever (or whatever) performed the action.
Role assignments and permission changes across every node.
Creation, activation, deactivation, and profile changes.
Nodes added, moved, renamed, or removed from the tree.
Key creation, rotation, revocation, and integration changes.
Invites sent, accepted, resent, or revoked.
Sign-ins, session changes, and credential operations.