What's new ⬇ Download Reportworq
⬇ Guide PDF

Security audit#

A Security Audit is a generated document that answers "what can this person see, and why?". It is built from the same security checks Reportworq applies when someone signs in, so it describes what each user can actually reach rather than what an administrator intended.

When to use it. For an access review (who could see what on a given date), to explain why a user's report comes back empty or a folder is missing, or to confirm that a change to an entitlement or group did what you meant.

Run an audit of every user#

  1. Open Settings > Security. Only system administrators can open this screen.
  2. Select Security Audit in the header.
  3. In the Security Audit dialog, choose a format: Markdown, PDF or Excel.
  4. Leave Include report data (slower) selected to list the runs, output variations and data slices each user can reach in each report. Clear it for a faster sweep of entitlements only; the document states that report data was excluded.
  5. Select Generate. A progress message in the header counts through the users, and the file downloads when it is ready.

The audit covers every enabled account, alphabetically, one section each. Disabled accounts are not included. Each user is evaluated as that user, not as you, so an administrator's own bypass is never mistaken for the other users' access. A very large instance is capped at the first 250 enabled accounts, and the document says so in an integrity note.

What the document contains#

Choose a format#

Format Best for
Markdown Reading, comparing two runs, or handing to an AI assistant. The default.
PDF A bookmarked quick reference, one bookmark per user.
Excel The all-users audit only. A Data sheet with one row per visible item, plus By User and By Capability pivots, for filtering who can see what.

Let users audit themselves#

By default only administrators can run an audit. To let everyone else generate a statement of their own access:

  1. Open Settings > Configuration, on the Web Server tab.
  2. Under Security, select Allow users to perform a security audit and save.

Users then see Security Audit in their account menu (the avatar menu at the top right) and get Markdown or PDF of their own access, with no Excel option. A user's own audit shows their workspaces' integrations and credential names but not the instance-wide credential configuration. The same setting controls whether a user's AI assistant can run the security_audit tool, which requires an OAuth sign-in; it is refused for an instance API key because a key carries no user identity. Administrators are unaffected by the setting.

Notes and limits#

Feedback on this page

Comments, questions, requests, or something missing or unclear? Email us - the page you are on is filled in for you.

Email feedback on this page

Or write to support@reportworq.com directly.