Skip to content
Security

Quiet by default. Auditable by design.

AtGlance is engineered for organisations whose first question is “where does the data live?” — and whose second is “who can change what?”

Self-hosted, by design

The Console runs entirely inside your boundary. There is no telemetry to atglance.live.

PAT tokens with scopes

Each CLI host carries a Personal Access Token. Tokens are short-lived, revocable, scoped per system.

RBAC at the route layer

auth.session + auth.pat + admin.role middleware composed declaratively. Policy enforcement is impossible to forget.

Configuration backups, immutable

Every imported configuration is hashed and versioned. File storage can be local or S3 with object-level locks.

Database circuit breaker

When the database is unhealthy, mutations buffer to the cache. Replays are idempotent. No silent data loss.

Auditable everything

register / deregister / reactivate / config-import all write to the activity log with operator and timestamp.

RBAC

Three roles. Strict separation.

Capability superadmin admin user
Tenancy & billing Yes No No
Manage organisations Yes Yes No
Manage users & roles Yes Yes No
Register / deregister systems Yes Yes No
View configuration backups Yes Yes Yes
Trigger reactivation Yes Yes No
Read assigned workspaces only No No Yes
Generate PAT tokens Yes Yes Yes