← Features

Four team roles, and an audit log of every change

Let the people who need data help themselves, and still always know who did what to it, and when.

What it does, who uses it, when

  • Roles that match the work

    Owners and Admins look after members, connections and table structure; Editors edit data and pipelines; Viewers only look.

  • Invite with a link

    Create an invite link for an email and role and send it however your team talks. Links last 7 days and work only for the invited email.

  • An audit log you can use

    Filter by category (data, schema, pipelines, access), period and member, open the before and after, and export to CSV.

  • Single sign-on (Pro plan)

    Sign in through your organisation’s OpenID Connect provider. Accounts are created on first sign-in (allowed email domains only, with the default role you pick), and you can require members to use SSO only.

How it works

Invite members

Enter an email, choose a role, and send the invite link.

Adjust roles as work changes

Change a role or remove a member any time. Only Owners manage the Owner role.

Look back

Open the audit log to see who changed what, the old value, and the request behind it.

A real task

Join PostgreSQL and MySQL tables without moving dataPlain SQL cannot join a PostgreSQL table with a MySQL table. Compare CSV exports, postgres_fdw and Join Canvas, with the steps to do it.Read how →

Works well with

  • Database connections

    Connect PostgreSQL, MySQL, SQL Server, Oracle, SQLite and MongoDB over TLS or an SSH tunnel, mark them read-only, and let the team use them without knowing the password.

    Details
  • Data Explorer

    Open a table, filter, sort and edit it like a spreadsheet, export to CSV, and keep the before and after of every edit in the audit log.

    Details

Frequently asked questions

What does the audit log record?

Data edits, inserts, deletes and exports; SQL and DDL runs; pipeline changes and runs; file imports; and changes to connections, members and API keys. Each entry has who, when, IP and the before and after.

How far back can I look?

It depends on the plan: Free 7 days, Dev 30 days, Pro 365 days.

Who can see the audit log?

Workspace Owners and Admins. Other members do not see it, and nobody can edit or delete audit entries from the app.

What kind of SSO is supported?

OpenID Connect (OIDC), on the Pro plan. An Owner or Admin sets the issuer URL, client ID and client secret (kept in Vault), the allowed email domains and the default role. SAML is not supported.

Bring all your databases into one place

Start free, or book a demo and we will walk through it with your own team’s data.