Skip to main content

3. Scope

logologo

Part of the Access Transparencyaccesstransparency manual — see also 1. Introduction, 2. What's New, 4. Setup, 5. Usage, 6. Troubleshooting.

Reference only — see 4. Setup for how to configure each of these.

3.1 Assets, management & administration items

New itemtypes

  • PluginAccesstransparencyUserinteractionsDocument opens — internalevery tabletime storinga document-openuser eventsopens capturedor bypreviews a document through GLPI's normal UI, that event is recorded so it can show up on the plugin'document's JSand trackerthe user's "Access Transparency" tabs.

Modified itemtypes

  • User — a new "Access Transparency" tab (requires the plugin_accesstransparency_view READ right to see)
  • Document — a new "Access Transparency" tab showing which users opened that document (same right required)
  • Profile — a new "Access Transparency" tab for granting/revoking the view right
  • Config — a new "Access Transparency" tab for configuring log retention and excluded logins

Permissions

  • plugin_accesstransparency_view (right name: plugin_accesstransparency_view, field: plugin_accesstransparency_view, READ)Historical — a single Read-only permission that controls accesswhether toa profile can see the "Access Transparency" tabs on User and Document "Accesspages. Transparency"Grant tabs.or Assignedrevoke per-profileit under Administration → Profiles → profile → "Access Transparency" tab. There's no separate right for exporting: anyone who can see the tab can also export it as CSV, for the same items they're already allowed to view.

Automatic Actions

  • PurgeInteractionLogsPurge old interaction logs — a cronscheduled task (Setup → Automatic actions) that runsautomatically hourlyremoves byold defaultdocument-open (setrecords viaonce CronTask::register()they in setup.php), purging rows from glpi_plugin_accesstransparency_userinteractions older thanpass the configured retention cutoffperiod you choose on the "Access Transparency" configuration page (set under Setup → General → "Access TransparencyTransparency" → "Log retention"). It runs on its own; no action needed unless you want to change how long records are kept, or want to trigger a purge immediately by running the task by hand.

3.2 Automatic actions

ThePurge cronold taskinteraction PurgeInteractionLogslogs (classSetup PluginAccesstransparencyUserinteractions,→ methodAutomatic PurgeInteractionLogs)actions) runsautomatically deletes old document-open records once they're older than the retention period configured on the schedule"Access definedTransparency" atconfiguration registration timepage (default:Setup hourly)→ General → "Access Transparency" → "Log retention"):

  • IfKeep retentionall — nothing is setever todeleted.
"keepDelete all"all (DELETE_ALL— inevery PluginAccesstransparencyConfig),document-open record is removed each time the task skips any deletion.runs. If retention is set to "delete all" (KEEP_ALL), every row in glpi_plugin_accesstransparency_userinteractions is deleted. If retention is set to aA number of months (e.g.— "12only months"), rowsrecords older than current_timethat - (months * 30.44 * 24 * 3600) secondscutoff are deleted.removed; recent ones stay.

The task is called via Session::addMessageAfterRedirect() logging the number of deleted rows.


See 4.2 Configuration.

3.3 Notifications

None.

3.4 Rules

None.

3.5 Permissions

The plugin enforces one right, checked at two points:

    Tab visibility — Session::haveRight('profile', READ) gatesSeeing the Profile"Access tab;Transparency" Session::haveRight('plugin_accesstransparency_view',tab READ)on gates the User and Document tabs. Both checks live in the respective class's displayTabContentForItem() method. CSV export — both export routes (front/export_user_csv.php and front/export_document_csv.php) check Session::haveRight('plugin_accesstransparency_view', READ) before serving the file.

    Additionally, the CSV export routes respect standard GLPI visibility rules for thea User or Document page requires the Historical permission on the logged-in questionuser's profile (Administration → Profiles → profile → "Access Transparency" tab). It's Read-only — athere's usernothing to grant beyond "can see it or can't." CSV export uses the same permission: if you can onlysee the tab, you can export historyit, and only for itemsUsers/Documents they wouldyou're otherwise be allowed to view.

    See 4.3 Permissions.

    Generated for Access Transparencyaccesstransparency 1.2.0-beta2 on GLPI 11.0.80 — 2026-08-24.