Audit & reports

Every change Trinitis makes is recorded, and access across your platforms is visible in one place.

Audit log

The audit log is append-only: entries cannot be edited or deleted, and timestamps come from the database clock. Each entry records the event type, outcome, actor, related policy and connection, a summary, and structured detail.

Export the audit log as CSV or JSON.

Access intelligence

Trinitis reads query history from each connected platform (every 5 minutes by default) and shows who accessed what, with real data values stripped. Filter by connection, user and outcome — allowed, denied or failed — or show only ungoverned access.

Available on Snowflake, Databricks, BigQuery, Redshift and PostgreSQL. Not yet available on S3 / Iceberg.

Grant drift detection

When enabled for your account, Trinitis flags:

  • grants that were revoked outside Trinitis,
  • masks that were removed, and
  • shadow grants created outside Trinitis.

Available on Snowflake, Databricks, BigQuery, Redshift and PostgreSQL. Not available on S3 / Iceberg.