accessflow / website
bablsoft/accessflow/website/llms.txt
AccessFlow is an open-source access proxy for SQL databases, cloud data warehouses, NoSQL engines, and outbound APIs — PostgreSQL, MySQL, MariaDB, Oracle, SQL Server, ClickHouse, Snowflake, Google BigQuery, Databricks SQL, MongoDB, Couchbase, Redis, Cassandra, ScyllaDB, Elasticsearch, OpenSearch, Amazon DynamoDB, and Neo4j, plus outbound REST, SOAP, GraphQL, and gRPC APIs. AI-reviewed queries, API calls and CI/CD deployments, configurable approval workflows, and a tamper-evident audit log — self-hosted under Apache 2.0. AccessFlow sits between people (and AI agents) and production data as…
# AccessFlow > AccessFlow is an open-source access proxy for SQL databases, cloud data warehouses, NoSQL engines, and outbound APIs — PostgreSQL, MySQL, MariaDB, Oracle, SQL Server, ClickHouse, Snowflake, Google BigQuery, Databricks SQL, MongoDB, Couchbase, Redis, Cassandra, ScyllaDB, Elasticsearch, OpenSearch, Amazon DynamoDB, and Neo4j, plus outbound REST, SOAP, GraphQL, and gRPC APIs. AI-reviewed queries, API calls and CI/CD deployments, configurable approval workflows, and a tamper-evident audit log — self-hosted under Apache 2.0. AccessFlow sits between people (and AI agents) and production data as a full query proxy: a submitted query or API call is parsed and validated, analyzed for risk by a configurable AI provider (Anthropic, OpenAI, Ollama, Hugging Face, or any OpenAI-compatible endpoint — with Voyage AI available separately as an embeddings-only provider for the RAG knowledge base), routed through multi-stage human approval chains, and only then executed — with schema allow-lists, dynamic data masking, row-level security, and row caps enforced at execution time. Every step lands in an INSERT-only, hash-chained audit log. Engines are grouped into three families. **Relational** (`RELATIONAL`) covers PostgreSQL, MySQL, MariaDB, Oracle, and Microsoft SQL Server through their own database drivers. ClickHouse ships as a built-in catalog connector on that same driver path (`dbType=CUSTOM`) — one-click install with an SHA-256-pinned driver — and any other JDBC-compatible engine works via an admin-uploaded driver JAR. **Cloud data warehouses** (`WAREHOUSE`) covers Snowflake, Google BigQuery, and Databricks SQL through AccessFlow engines that use each vendor's own authentication model — key-pair JWT, service-account JSON, and personal access tokens respectively — rather than a database driver. **NoSQL** covers the document engines MongoDB and Couchbase (SQL++/N1QL), the key-value engines Redis and Amazon DynamoDB (PartiQL), the wide-column engines Apache Cassandra and ScyllaDB (CQL), the search engines Elasticsearch and OpenSearch (JSON Query DSL), and the graph engine Neo4j (Cypher over Bolt). Every non-JDBC engine ships as an SHA-256-pinned download resolved on demand through the connector catalog. Beyond query review, AccessFlow governs outbound **API access** (REST, SOAP, GraphQL, gRPC) through the same submit → AI → review → execute pipeline, with response masking and data-classification tags. A third governed surface is **deployment approval governance**: CI/CD pipelines (GitHub Actions, GitLab CI, Azure Pipelines, Jenkins, CircleCI, Bitbucket Pipelines, or generic curl) ask AccessFlow for permission to release and block on a fail-closed deployment gate, with per-environment policies, freeze windows, scheduled releases, audited break-glass and post-deploy outcome and rollback tracking. It also provides just-in-time and break-glass access grants, policy-as-code routing, behavioural anomaly detection (UBA), advisory approval-likelihood prediction that scores a pending query against the organization's own past review decisions without ever deciding one, request chaining and grouping, data-lifecycle automation (retention, right-to-erasure, pseudonymization), access recertification campaigns, and signed compliance exports. Authentication is JWT (RS256) with optional SAML 2.0, OAuth 2.0 / OIDC (Google, GitHub, Microsoft, GitLab, Okta, Keycloak, Auth0, and other IdPs), and TOTP. It is self-hosted (Docker Compose or Helm), ships a built-in MCP server so AI agents can discover schemas and validate and submit queries through the same governance pipeline, and offers a Terraform/OpenTofu provider plus reusable CI actions for infrastructure-as-code management. Source code lives at https://github.com/bablsoft/accessflow. ## Product - [AccessFlow](https://accessflow.io/): The product homepage — what AccessFlow is, the one approval pipeline it puts in front of databases, outbound APIs and CI/CD deployments, the eighteen engines it governs, the install commands, and the FAQ - [Database access control — all 12 capabilities](https://accessflow.io/features/): Every AccessFlow capability in one place, grouped into database access governance, API access governance, deployment approval governance and the platform underneath — each card links to the deep dive that carries the mechanism - [Database access governance](https://accessflow.io/features/database-access-governance/): The full path one query takes — parsed at the proxy against a schema allow-list, risk-scored by the AI analyzer, routed to a reviewer by policy, executed under dynamic masking and row-level security, optionally bundled into a grouped request, and retired by a retention or right-to-erasure rule - [API access governance](https://accessflow.io/features/api-access-governance/): Governing outbound REST, SOAP, GraphQL and gRPC calls — connectors holding AES-256-GCM encrypted auth with OAuth2 token minting, OpenAPI / WSDL / SDL / proto / Postman schema ingestion into a read/write-classified operation catalog, response masking and classification tags, and the same review pipeline as a database query - [Deployment approval governance](https://accessflow.io/features/deployment-governance/): Gating CI/CD releases — pipelines and ordered environments, per-pipeline trigger and break-glass grants, AI release-risk analysis and routing policies, the fail-closed deployment gate a CI job blocks on, freeze windows, rollback follow-up reviews, and a version matrix showing which version each environment is running and how far behind it has fallen - [Database proxy security architecture](https://accessflow.io/security/): Where AccessFlow keeps datasource credentials (AES-256-GCM at rest or a Vault / AWS Secrets Manager / Azure Key Vault secret reference), what the proxy can read while a query runs, SAML / OAuth / SCIM sign-in and IdP-driven offboarding, and the INSERT-only hash-chained audit log behind the signed compliance exports - [Database connectors](https://accessflow.io/connectors/): Every database engine AccessFlow governs and how each one loads — the eighteen-connector catalog grouped into SQL, cloud data warehouses and NoSQL, a per-engine category/connection/install reference, the SHA-256-pinned manifest and on-demand AccessFlow-engine model, and how to add a JDBC engine that is not in the catalog - [Database access management use cases](https://accessflow.io/use-cases/): Seven teams and the access problem each one brings to AccessFlow — shared production credentials, just-in-time and break-glass access for on-call, AI-triaged review at scale, tamper-evident audit evidence and recertification, classification-driven masking and erasure, the same pipeline over outbound REST/SOAP/GraphQL/gRPC calls, and CI/CD deploys held at a fail-closed approval gate - [AccessFlow roadmap](https://accessflow.io/roadmap/): What AccessFlow can do today grouped by capability — proxy and data access, AI and monitoring, review and access, API and deployment governance, compliance, auth and audit — plus the milestone in progress and the planned backlog, with links to the GitHub milestones - [Changelog](https://accessflow.io/changelog/): Every stable release since v1.0, newest first, one permanent anchor per version — the page a self-hosted install's update hint links to; the machine-readable pointer is https://accessflow.io/version.json ## Connectors One page per governed engine — how AccessFlow connects to it, what it parses, what it refuses, and the exact shape of row-level security. - [PostgreSQL access governance](https://accessflow.io/connectors/postgresql/): the bundled database-driver connector, and the database AccessFlow itself runs on - [MySQL access governance](https://accessflow.io/connectors/mysql/): its own database driver, with an EXPLAIN FORMAT=JSON dry-run - [MariaDB access governance](https://accessflow.io/connectors/mariadb/): its own connector and driver rather than a MySQL alias - [Oracle Database access governance](https://accessflow.io/connectors/oracle/): EXPLAIN PLAN FOR with the scratch PLAN_TABLE rows cleaned up afterwards - [Microsoft SQL Server access governance](https://accessflow.io/connectors/mssql/): the documented plain-Statement SHOWPLAN carve-out and why the dry-run degrades under row security - [ClickHouse access governance](https://accessflow.io/connectors/clickhouse/): a catalog connector on the generic JDBC dialect - [Snowflake access governance](https://accessflow.io/connectors/snowflake/): key-pair JWT auth, a short-lived connection per query, and an EXPLAIN-based scan-byte estimate - [Google BigQuery access governance](https://accessflow.io/connectors/bigquery/): service-account credentials, a project id instead of a host, and a native dry-run byte estimate - [Databricks SQL access governance](https://accessflow.io/connectors/databricks/): the Statement Execution API with no vendor driver at all - [MongoDB access governance](https://accessflow.io/connectors/mongodb/): both query forms, the $where ban, and row security as a $match stage - [Couchbase access governance](https://accessflow.io/connectors/couchbase/): SQL++ with CURL and JavaScript UDFs refused - [Redis access governance](https://accessflow.io/connectors/redis/): a strict command allow-list, key-prefix grants, and row security that fails closed by design - [Amazon DynamoDB access governance](https://accessflow.io/connectors/dynamodb/): PartiQL over cloud credentials, with a WHERE splice that filters on any attribute - [Apache Cassandra access governance](https://accessflow.io/connectors/cassandra/): key-aware row security that never injects ALLOW FILTERING - [ScyllaDB access governance](https://accessflow.io/connectors/scylladb/): the same CQL engine as Cassandra, from the same pinned JAR - [Elasticsearch access governance](https://accessflow.io/connectors/elasticsearch/): Painless refused anywhere in the tree, and row security as a non-widening bool filter - [OpenSearch access governance](https://accessflow.io/connectors/opensearch/): the same engine as Elasticsearch over a different HTTP client stack - [Neo4j access governance](https://accessflow.io/connectors/neo4j/): Cypher over Bolt, with row security spliced onto each MATCH clause ## Comparisons Sourced, dated comparisons with the products AccessFlow is evaluated against. Every claim about another product cites its public documentation, unverifiable cells say "Not documented", and each page names where the other tool is the better fit. - [Compare AccessFlow with Bytebase, hoop.dev, StrongDM and Teleport](https://accessflow.io/compare/): The hub — how the comparisons are written, what AccessFlow is and is not, and which page to read first - [AccessFlow vs Bytebase](https://accessflow.io/compare/accessflow-vs-bytebase/): Every-statement review versus schema change management, with the edition each capability lives in - [AccessFlow vs hoop.dev](https://accessflow.io/compare/accessflow-vs-hoop-dev/): A proxy you submit a statement to versus a gateway your existing clients connect through - [Open-source StrongDM alternative](https://accessflow.io/compare/open-source-strongdm-alternative/): What the self-hosted proxy replaces in StrongDM's database slice, and what it does not - [Open-source Teleport Database Access alternative](https://accessflow.io/compare/open-source-teleport-database-access-alternative/): Reviewing the statement instead of the session, and the two licences compared ## Docs - [Governed database access for AI agents](https://accessflow.io/ai-agents/): How AI agents query production through AccessFlow's MCP server — scoped API keys, the twelve-tool surface, AI risk analysis and human approval before execution, masking and row-level security on samples, caller-scoped audit - [Documentation home](https://accessflow.io/docs/): Hub for the operator and admin documentation — install AccessFlow, complete first-run setup, and configure every entity in the review pipeline - [Install & first run](https://accessflow.io/docs/install/): Run AccessFlow with Docker Compose, Kubernetes and Helm, or from source, then complete first-time setup with the browser wizard or GitOps bootstrap - [Guides](https://accessflow.io/docs/guides/): Step-by-step manuals for setting up AccessFlow, in the order a new deployment needs them - [Run your first query](https://accessflow.io/docs/guides/first-query/): From a fresh install to a query that is reviewed, approved and executed — the guide to start with - [Add a datasource](https://accessflow.io/docs/guides/datasource/): Install an engine connector, connect a database, read its schema, and limit and mask what can be queried - [Send notifications](https://accessflow.io/docs/guides/notifications/): Configure system email so invitations work, then route review events to Slack, Teams, PagerDuty or a signed webhook - [Invite your team](https://accessflow.io/docs/guides/team/): Create accounts, choose roles, group people, and grant database access that expires on its own - [Connect SSO](https://accessflow.io/docs/guides/sso/): Sign in through your identity provider with OAuth 2.0 / OIDC or SAML 2.0, and provision users over SCIM - [Turn on AI analysis](https://accessflow.io/docs/guides/ai-analysis/): Point AccessFlow at an AI provider so every query reaches review with a risk level and an explanation - [Govern an API call](https://accessflow.io/docs/guides/api-governance/): Put review and approval in front of outbound REST, SOAP, GraphQL and gRPC calls - [Gate a CI/CD pipeline](https://accessflow.io/docs/guides/deployment-approval/): Make a CI/CD deploy job wait for human approval before it releases, and record who approved it - [Automate with Terraform](https://accessflow.io/docs/guides/terraform/): Declare datasources, review plans and policies as code with the Terraform / OpenTofu provider - [Ask the help assistant](https://accessflow.io/docs/guides/help-assistant/): Start AccessFlow, bind an AI provider, and ask the in-app assistant anything about the application — answered from the bundled documentation, with citations, for new users and admins alike - [Users & roles](https://accessflow.io/docs/configuration/users-roles/): Configure organizations, quotas, users, RBAC roles, groups and service accounts, grant just-in-time or break-glass access, and monitor scheduled jobs - [Datasources](https://accessflow.io/docs/configuration/datasources/): Add governed datasources, tag sensitive columns, apply masking and row-level security policies, upload JDBC drivers, and watch pool health - [Connectors](https://accessflow.io/docs/configuration/connectors/): Install SQL, NoSQL and data-warehouse engine connectors from the catalog, and register outbound REST, SOAP, GraphQL and gRPC API connectors - [Review workflows](https://accessflow.io/docs/configuration/review-workflows/): Build multi-stage approval chains with review plans, automate decisions with routing policies and SQL review rules, and run access recertification campaigns - [AI](https://accessflow.io/docs/configuration/ai/): Configure AI providers for query risk analysis, add a RAG knowledge base, trace prompts with Langfuse, and enable behavioural anomaly detection - [Auth & SSO](https://accessflow.io/docs/configuration/auth/): Connect to your identity provider with OAuth 2.0 / OIDC or SAML 2.0 single sign-on — Google, GitHub, Microsoft, GitLab, Okta, Keycloak and more - [Notifications](https://accessflow.io/docs/configuration/notifications/): Route review and audit events to email, Slack, Discord, Telegram, Teams, PagerDuty, ServiceNow, Jira and signed webhooks, and configure system SMTP - [Audit & compliance](https://accessflow.io/docs/configuration/audit-compliance/): Read the tamper-evident audit log, generate signed compliance exports, run retention and right-to-erasure policies, and use the personalized dashboard - [End-user workflows](https://accessflow.io/docs/workflows/): How analysts submit queries and API calls, draft SQL from natural language, schedule runs, and how reviewers approve or reject them - [Infrastructure as Code](https://accessflow.io/docs/iac/): Manage AccessFlow declaratively with the Terraform / OpenTofu provider, service-account API keys, and the reusable GitHub Actions and GitLab CI templates - [Integrations & boundaries](https://accessflow.io/docs/integrations/): Every way into AccessFlow (web UI, REST API, MCP, Terraform, CI, SCIM, SSO) and what it is not — no ODBC/JDBC/ADO.NET driver, no database wire protocol, no hosted edition; complete engine, sign-in and AI-provider lists ## Engineering reference - [Project README](https://raw.githubusercontent.com/bablsoft/accessflow/main/README.md): Project overview and quick start - [Overview](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/01-overview.md): Problem statement, goals, non-goals, value proposition - [Architecture](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/02-architecture.md): Subsystems, technology stack, request flow - [Data model](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/03-data-model.md): Internal entities, audit log schema, retention - [REST API](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/04-api-spec.md): Endpoints, payloads, WebSocket events - [Backend](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/05-backend.md): Modular backend, proxy engine, workflow state machine - [Frontend](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/06-frontend.md): React/Vite layout, SQL editor, TanStack & Zustand - [Security](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/07-security.md): JWT, SAML, OAuth, encryption, audit integrity - [Notifications](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/08-notifications.md): Email, Slack, Discord, Telegram, Teams, PagerDuty, signed webhook delivery - [Deployment](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/09-deployment.md): Docker Compose, Helm, env-var reference - [Development](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/11-development.md): Repo layout, tests, coding standards, Git workflow - [Roadmap](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/12-roadmap.md): Milestones, contribution path - [MCP server](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/13-mcp.md): Stateless tool surface for AI agents — discover, validate, sample, submit; API keys - [Connectors](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/14-connectors.md): Declarative connector catalog, manifests, install lifecycle - [AccessFlow engine SDK](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/15-engine-sdk.md): Authoring guide for native NoSQL and data-warehouse AccessFlow engines - [Infrastructure as Code](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/16-iac.md): Terraform/OpenTofu provider, CI Actions, service-account keys, registry publishing - [API Access Governance](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/17-api-governance.md): Govern outbound REST/SOAP/GraphQL/gRPC calls — connectors, schema ingestion, permissions - [Deployment Approval Governance](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/18-deployment-governance.md): Gate CI/CD deployments behind approval workflows — pipelines, environments, freeze windows, the fail-closed gate - [Deterministic SQL Review Rules](https://raw.githubusercontent.com/bablsoft/accessflow/main/docs/19-sql-review.md): The named rule catalog, per-environment OFF / WARN / BLOCK severities, ruleset resolution, the submission chokepoint where a BLOCK escalates to a person and never rejects, the live editor lint, and the documented exemptions ## Optional - [GitHub repository](https://github.com/bablsoft/accessflow): Source code, issues, releases (Apache 2.0) - [Agent rulebook](https://raw.githubusercontent.com/bablsoft/accessflow/main/CLAUDE.md): Authoritative implementation rules for AI agents contributing to the codebase - [Install / quick start](https://accessflow.io/#install): Docker Compose, Helm, and from-source install commands - [Common questions](https://accessflow.io/#questions): Short answers to the most-asked questions about AccessFlow - [Helm chart repository](https://bablsoft.github.io/accessflow): Published Helm chart index for Kubernetes installs - [Sitemap](https://accessflow.io/sitemap.xml): Every indexable URL on this site
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

