3. Scope

Part of the Access Transparency manual — see also 1. Introduction, 2. What's New, 4. Setup, 5. Usage, 6. Troubleshooting.
Reference only — see 4. Setup for how to configure each of these.
3.1 Assets, management & administration items
New itemtypes
- PluginAccesstransparencyUserinteractions — internal table storing document-open events captured by the plugin's JS tracker
Modified itemtypes
- User — a new "Access Transparency" tab (requires the
plugin_accesstransparency_viewREAD right to see) - Document — a new "Access Transparency" tab showing which users opened that document (same right required)
- Profile — a new "Access Transparency" tab for granting/revoking the view right
- Config — a new "Access Transparency" tab for configuring log retention and excluded logins
Permissions
plugin_accesstransparency_view(right name:plugin_accesstransparency_view, field:plugin_accesstransparency_view, READ) — controls access to the User and Document "Access Transparency" tabs. Assigned per-profile under Administration → Profiles → profile → "Access Transparency" tab.
Automatic Actions
- PurgeInteractionLogs — a cron task that runs hourly by default (set via
CronTask::register()in setup.php), purging rows fromglpi_plugin_accesstransparency_userinteractionsolder than the configured retention cutoff (set under Setup → General → Access Transparency → "Log retention").
3.2 Automatic actions
The cron task PurgeInteractionLogs (class PluginAccesstransparencyUserinteractions, method PurgeInteractionLogs) runs on the schedule defined at registration time (default: hourly):
- If retention is set to "keep all" (
DELETE_ALLinPluginAccesstransparencyConfig), the task skips any deletion. - If retention is set to "delete all" (
KEEP_ALL), every row inglpi_plugin_accesstransparency_userinteractionsis deleted. - If retention is set to a number of months (e.g.
"12 months"), rows older thancurrent_time - (months * 30.44 * 24 * 3600)seconds are deleted.
The task is called via Session::addMessageAfterRedirect() logging the number of deleted rows.
See 4.2 Configuration.
3.3 Notifications
None.
3.4 Rules
None.
3.5 Permissions
The plugin enforces one right, checked at two points:
- Tab visibility — Session::haveRight('profile', READ) gates the Profile tab; Session::haveRight('plugin_accesstransparency_view', READ) gates the User and Document tabs. Both checks live in the respective class's
displayTabContentForItem()method. - CSV export — both export routes (
front/export_user_csv.phpandfront/export_document_csv.php) checkSession::haveRight('plugin_accesstransparency_view', READ)before serving the file.
Additionally, the CSV export routes respect standard GLPI visibility rules for the User or Document in question — a user can only export history for items they would otherwise be allowed to view.
See 4.3 Permissions.
Generated for Access Transparency 1.2.0-beta2 on GLPI 11.0.8 — 2026-08-24.