PROTOTYPE Clickable mockup · simulates the finished app ◃ Product overview
Petanque Life Operator Console
Production OP

Audit, security & governance

The append-only audit log (7-year WORM retention), platform security operations and legal governance. Role catalog and grants live on Access control; DSAR case handling on DSAR & compliance.

Search & filter · actor, target, action, tenant, time, reason · saved searches per operator · F21.11.03
TimeActionActorTarget · tenantReason / metadata
10:41:22 sys.impersonate.start maria.ek user u-8812 (Astrid S) · Nordvik grant SG-2214 · #4471
10:38:04 sys.payments.refund jonas.holm payment PAY-77066 · Provence 450 SEK · #4462
10:32:19 tenant.flag.override maria.ek tenant sjostad · league_play targeted testing
09:58:41 sys.user.lock lena.vik user u-7741 (Håkan L) · Granholm brute-force triage
09:12:03 sys.impersonate.end maria.ek user u-8812 · session imp-4410 14 reads · 0 writes
≤ 100 k rows streams sync; larger sets queue an export job → signed URL, 7 d expiry (F21.11.04). Cursor pagination. Full schema per row: actor, actual_user (impersonation), action, target, tenant, impersonation_id, reason, ip, ua, request_id, session, metadata, seal columns (F21.11.02).
Impersonation sub-view · aggregated by impersonation_id · F21.11.05
maria.ek → Astrid Sjöbergimp-4410
2 Jul 09:02–09:12 · view · 14 reads · 0 writes · drill into filtered audit list →
jonas.holm → Håkan Lindqvistimp-4396
28 Jun 14:11–14:26 · interactive · 31 reads · 3 writes · drill into filtered audit list →
Integrity · WORM after 24 h, SHA-256 hash chain · F21.11.01 · F21.11.06
CHAIN OK daily integrity check · latest digest 03:05 · tamper ⇒ SEV1 incident
sys_securityfresh-auth
SIEM export · per-tenant sink, 15-min delta push · F21.11.07
Svenska Bouleförbundet Azure Monitor pushed 4 min ago
Fjordkedjan Boule AB Splunk HEC pushed 11 min ago
platform (internal) Datadog pushed 2 min ago
States
⏳ Searching 4.2 M audit rows…
📭 No rows match — widen the time range.
⚠ Export job failed — artifact sink unreachable.
Active user sessions · cross-tenant · bulk revoke · F21.17.01
astrid@nordvikpetanque.se
Nordvik · player
app · Stockholm 4 min ago
kassor@sjostadboule.se
Sjöstad · club_admin
web · Malmö 18 min ago
hakan@granholmpk.se
Granholm · referee
web · Umeå · suspicious 1 h ago
Suspicious-activity queue · 3 rules · triage: none / lock_user / revoke_sessions · F21.17.02
impossible_travel hakan@granholmpk.se · Stockholm → Bangkok in 40 min open
brute_force 12 failures / 5 min on kassor@sjostadboule.se open
new_device_hva federation admin login from unseen device triaged · revoke_sessions
Failed-login heatmap · group by IP or e-mail · 24 h · F21.17.03
00:00 → 23:00 UTC · spike 11–13 = brute-force cluster on /24 195.67.x.x
API keys & OAuth clients · rotate / revoke, secret shown once · F21.17.04
dk_7f2…a1 Nordic Boule Media · api:read, results:read
last used 2 min ago
active
m2m_44c…9e Fjordkedjan ERP sync · invoices:read
last used 1 h ago
active
dk_5a1…d9 Stale importer
last used 214 d ago
revoked
Service principals + secret rotation runbooks · 6 secret classes · F21.17.05–06
SP inventory: sp-petanque-sys-cost-reader expires in 41 d · rotation scheduled.
jwt_keys step 3/5 — dual-validation window in progress
sendgrid completed 12 Jun done
db scheduled 15 Jul scheduled
Per-tenant IP allowlist · enforced at tenant auth · F21.17.07
Emergency kill-switch · two-person arming · F21.17.08
Freeze a tenant completely. Single-use approval code (10 min TTL) from a second sys_security admin; every non-sys request answers 503 until disarmed.
Sign-in policy · F21.01.01–02 · F21.01.05–06
Providers: Microsoft OAuth or Google OAuth — no password, no OTP; JWKS-verified per provider
Allowlist gate: off-allowlist e-mails rejected even with a valid token · optional per-e-mail provider pin
Session: 60 min sliding · 8 h hard ceiling (immutable across reauth)
Fresh-auth gate: sensitive ops require re-auth < 5 min via WebAuthn (401 → transparent resolve)
Allowlist editor (SYS_ADMIN_EMAILS) · F21.01.02
sys_securityfresh-auth
My passkeys · mandatory second factor · F21.01.03
🔑 YubiKey 5C (maria.ek) registered 12 May · last used today 07:58
🔑 MacBook Touch ID (maria.ek) registered 3 Apr · last used yesterday
Operator sessions · force-logout (sys_security, reason required) · F21.01.07
maria.ek@petanque.life
Google OAuth + WebAuthn
started 07:58 · hard_exp 15:58 this session
jonas.holm@petanque.life
Microsoft SSO + WebAuthn
started 08:40 · hard_exp 16:40 active
API token view · reveal + 30 s auto-mask, audited · F21.01.09
••••••••••••••••••••••••
curl / httpie / python snippets for your own sys-JWT — no new tokens are minted.
Break-glass account · sealed envelope procedure · F21.01.08
Sealed YubiKey envelope + runbook. Use only when both OAuth providers are down. Every use opens a mandatory post-incident review. Roles catalog + four-eyes grants live on Access control (F21.01.04).
Legal document publisher · versions, diff viewer, re-acceptance · F21.13.03–04
Terms of Service v3.2 published 1 Jun re-accept campaign: 84% done
DPA v2.1 published 12 Mar
Privacy Policy v4.0 draft diff vs v3.9 ready review
SLA v1.3 published 1 Jan
Subprocessor list · public page + changelog + tenant notification · F21.13.07
Azure (hosting) · SendGrid (e-mail) · Stripe (payments) · Bankgirot (bank) · Expo (push)
Last change 12 May: added Litmus (e-mail preview) — 27 tenants notified automatically.
Breach notification workflow · GDPR Art. 33, 72 h clock · F21.13.08
Trigger: SEV1 incident + personal-data impact ⇒ guided workflow (assess → document → notify authority ≤ 72 h → notify affected users). No active breach case.
Security posture · CIS, SBOM age, pentest findings · F21.13.05
CIS benchmark: 94% pass · 3 warnings
SBOM: regenerated 8 d ago (target ≤ 30 d)
Pentest (May 2026): 0 critical · 2 medium — 1 remediated, 1 in progress
DPIA register · flags features needing review · F21.13.06
Session replay (rrweb) approved w/ conditions review due 2026-09
AI plane (RAG) in assessment blocker for GA
Fraud scoring on signups approved
Retention policy overview · configured TTL vs observed age · F21.13.09
CollectionTTLObservedStatus
sys_audit_entries 7 years (WORM) oldest 412 d ok
session replays 30 d oldest 29 d ok
ApiUsageEvent 90 d oldest 121 d anomaly
sandbox users 30 d oldest 11 d ok

GDPR request tracker + execution with SLA timers (F21.13.01–02) render on DSAR & compliance; the read-only GDPR snapshot (F21.13.10) sits on the user detail in User directory.