Skip to content

docs(authzed): product-availability pill on concept pages; Audit Logging self-hosted section framed as SpiceDB Enterprise - #586

Open
Corey-T1000 wants to merge 17 commits into
mainfrom
docs/audit-logging-product-scope
Open

docs(authzed): product-availability pill on concept pages; Audit Logging self-hosted section framed as SpiceDB Enterprise#586
Corey-T1000 wants to merge 17 commits into
mainfrom
docs/audit-logging-product-scope

Conversation

@Corey-T1000

@Corey-T1000 Corey-T1000 commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

A reader from Zoom landed on audit-logging#self-hosted and read it as SpiceDB open source. The only scope sentence was line 10 of the page, and "Self-Hosted" collides with self-hosting OSS.

ProductBadge (components/product-badge.tsx), under the H1 of concept pages:

AVAILABLE ON [Cloud] [Dedicated] [Enterprise] [✕ Not in Open Source]

  • sand pills = ships with it; dashed pills with a DIY suffix = build it yourself (mirrors the Feature Matrix's DIY cells); one stone "Not in …" pill spells out the exclusions
  • no struck-out or dimmed tiers: the negative has to read in one glance for someone arriving from a deep link
  • rendered under every H1 site-wide (mdx-components.ts); the tiers come from the route via lib/products.ts: section defaults (SpiceDB = all four, Managed SpiceDB = Cloud/Dedicated/Enterprise, Materialize = Dedicated, install/operator pages = Open Source/Enterprise) plus a per-page map copied from the Feature Matrix. Full table below for product review
  • sibling of the Materialize FeatureBadge; same geometry and type, the two rows stack on Materialize pages

Audit Logging and Restricted API Access

  • ### Self-Hosted### SpiceDB Enterprise (self-hosted), #self-hosted anchor kept via a custom heading id
  • warning callout above the flag table: the --extender-* flags exist only in the Enterprise binary
  • callouts name the binary: the --extender-* flags are spicedb serve flags on the Enterprise build, absent from open source; Restricted API Access gets a worked spicedb serve example. Fixes OSS-466
  • flag names backticked: bare --flag cells were being typographically converted to —flag

Site-wide styling (app/globals.css, components/content-status.css)

  • tables: horizontal rules only, mono uppercase header row, 14px body, tighter cells, row hover; long code values wrap instead of forcing a horizontal scroll (18 pages carry tables, four checked in both themes)
  • callouts re-keyed from Tailwind yellow/blue/red/green/purple to Sandworm sand / blue / red / teal / violet
  • content-review banner re-keyed from hand-picked amber/green to sand / teal

tsc and prettier clean. Light and dark checked locally.

Review page for product sign-off: /review lists every page, the tiers its pill shows, and where that decision came from (Feature Matrix, section default, or please confirm with a note). Preview and local only, hidden from nav; the route gets deleted once the map is signed off.

On Materialize pages the feature pills join the product row after a divider, and a page on exactly one tier reads "Dedicated only" instead of listing the three it is not on.

Product availability per page (from lib/products.ts; ✅ available · DIY · ✕ not in; blank = no pill)
Page Title Open Source Cloud Dedicated Enterprise
/authzed/api/http-api HTTP API Documentation
/authzed/concepts/audit-logging Audit Logging
/authzed/concepts/deployments Deployments
/authzed/concepts/feature-maturity Feature Maturity
/authzed/concepts/management-dashboard Management Dashboard
/authzed/concepts/multi-region Multi-Region Deployments DIY DIY
/authzed/concepts/private-networking Private Networking DIY DIY
/authzed/concepts/rate-limiting Rate Limiting
/authzed/concepts/restricted-api-access Restricted API Access DIY
/authzed/concepts/security-embargo Security Embargo
/authzed/concepts/update-channels Update Channels DIY DIY
/authzed/concepts/workload-isolation Workload Isolation DIY DIY
/authzed/guides/cloud Getting Started with AuthZed Cloud
/authzed/guides/picking-a-product Picking the right AuthZed Product
/authzed/guides/postgres-fdw Using Postgres FDW with AuthZed Cloud/Dedicated
/authzed/guides/setting-up-private-networking Setting up Private Networking
/materialize/api/client-sdks Client SDKs
/materialize/api/download-permission-sets DownloadPermissionSets
/materialize/api/lookup-permission-sets LookupPermissionSets
/materialize/api/watch-permission-sets WatchPermissionSets
/materialize/concepts/hydration Hydration
/materialize/concepts/managing-client-state Managing Client State
/materialize/concepts/permission-set-lifecycle The Permission Set Lifecycle
/materialize/concepts/permission-sets Permission Sets
/materialize/concepts/snapshots Snapshots
/materialize/concepts/watched-permissions Watched Permissions
/materialize/getting-started/limitations Limitations
/materialize/getting-started/overview What is Materialize?
/materialize/guides/recommended-architecture Recommended Architecture
/materialize/guides/relational-database Syncing to a Relational Database
/mcp/authzed/authzed-mcp-server AuthZed MCP Server
/mcp/authzed/spicedb-dev-mcp-server SpiceDB Dev MCP Server
/mcp Model Context Protocol
/ AuthZed Documentation
/spicedb/api/http-api HTTP API Documentation
/spicedb/best-practices Best Practices
/spicedb/concepts/caveats Caveats
/spicedb/concepts/commands
/spicedb/concepts/consistency Consistency
/spicedb/concepts/datastore-migrations Datastore Migrations
/spicedb/concepts/datastores Datastores
/spicedb/concepts/expiring-relationships Writing Relationships that Expire
/spicedb/concepts/querying-data Querying Data
/spicedb/concepts/read-after-write Read-After-Write Consistency
/spicedb/concepts/reflection-apis Reflection APIs
/spicedb/concepts/relationships Relationships
/spicedb/concepts/schema Schema Language Reference
/spicedb/concepts/watch Watching Relationship Changes
/spicedb/concepts/zanzibar Google Zanzibar
/spicedb/getting-started/client-libraries Official Client Libraries
/spicedb/getting-started/coming-from/cancancan SpiceDB for Ruby on Rails CanCanCan users
/spicedb/getting-started/coming-from/opa SpiceDB for Open Policy Agent (OPA) users
/spicedb/getting-started/configuration Configuring SpiceDB
/spicedb/getting-started/discovering-spicedb SpiceDB Documentation
/spicedb/getting-started/faq Frequently-asked Questions
/spicedb/getting-started/first-steps First steps
/spicedb/getting-started/install/debian Installing SpiceDB on Ubuntu or Debian
/spicedb/getting-started/install/docker Installing SpiceDB with Docker
/spicedb/getting-started/install/kubernetes Installing SpiceDB on Kubernetes
/spicedb/getting-started/install/macos Installing SpiceDB on macOS
/spicedb/getting-started/install/rhel Installing SpiceDB on RHEL or CentOS
/spicedb/getting-started/install/windows Installing SpiceDB on Windows
/spicedb/getting-started/installing-zed
/spicedb/getting-started/protecting-a-blog Tutorial: Protecting a Blog Application
/spicedb/integrations/langchain-spicedb Use SpiceDB with LangChain & LangGraph for RAG & AI Agent Authorization
/spicedb/integrations/pinecone Access Control in RAG with Pinecone and SpiceDB
/spicedb/integrations/testcontainers Testing RAG Pipelines with Testcontainers and SpiceDB
/spicedb/modeling/access-control-audit Access Control Audit
/spicedb/modeling/access-control-management Access-Control Management
/spicedb/modeling/attributes Attributes
/spicedb/modeling/composable-schemas Composable Schemas
/spicedb/modeling/developing-a-schema Developing a Schema
/spicedb/modeling/migrating-schema Migrating a Schema in SpiceDB
/spicedb/modeling/protecting-a-list-endpoint Protecting a List Endpoint
/spicedb/modeling/recursion-and-max-depth Cyclical Relationships and Traversal Limits
/spicedb/modeling/representing-users Representing Users
/spicedb/modeling/validation-testing-debugging Validation, Testing, Debugging SpiceDB Schemas
/spicedb/ops/data/bulk-operations Bulk Importing Relationships
/spicedb/ops/data/migrations Migrating from SpiceDB to SpiceDB
/spicedb/ops/data/writing-relationships Writing relationships
/spicedb/ops/deploying-spicedb-operator Deploying the SpiceDB Operator
/spicedb/ops/eks Installing SpiceDB on Amazon EKS
/spicedb/ops/load-testing Load Testing SpiceDB
/spicedb/ops/observability Observability Tooling
/spicedb/ops/operator SpiceDB Operator
/spicedb/ops/performance Improving Performance
/spicedb/ops/postgres-fdw Using Postgres FDW with SpiceDB
/spicedb/ops/resilience Improving Resilience
/spicedb/tutorials/agentic-rag Building Agentic RAG with SpiceDB, LangChain & Weaviate
/spicedb/tutorials/ai-agent-authorization Secure AI Agents with Fine Grained Authorization
/spicedb/tutorials/federated-authorization
/spicedb/tutorials/rag-motia-spicedb Build a Multi-Tenant RAG with Fine-Grain Authorization using Motia and SpiceDB
/spicedb/tutorials/secure-rag-pipelines Secure Your RAG Pipelines With Fine Grained Authorization

…t Logging's self-hosted section as SpiceDB Enterprise

A reader from Zoom landed on audit-logging#self-hosted and read it as SpiceDB
open source. The only scope sentence was line 10 of the page, and 'Self-Hosted'
collides with self-hosting OSS.

- ProductBadge: 'Available on' + every tier in Feature Matrix order; unavailable
  tiers stay in the row, struck out; DIY tiers mirror the matrix's DIY cells
- Audit Logging: pill under the H1, section renamed 'SpiceDB Enterprise
  (self-hosted)' keeping the #self-hosted anchor, Enterprise-only callout above
  the flag table
- Same pill on Restricted API Access, Workload Isolation, Private Networking,
  Management Dashboard
Spelled-out 'Not in …' pill replaces struck-out tiers (three rounds with Corey:
strikethrough reads slow, product colour-coding adds a decode step). DIY tiers
are dashed stone with a mono DIY suffix; nothing excluded means no negative
pill. Lab route and variants removed.
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Preview deployment status for this pull request.

Name Status Preview Updated (UTC)
docs 🟢 Ready Visit Preview Sep 10, 2026 02:36am

Nextra's default is a full grid (1px on every cell, zebra rows, 16px body,
px-4 py-2). On flag lists and feature matrices it reads as a spreadsheet.
Now: horizontal rules only, a mono uppercase header row, 14px body, tighter
cells, row hover. Long code values (connection URIs) break instead of pushing
the table into a horizontal scroll; the last column keeps a 6rem floor so short
values like 1000000 stay on one line. 18 pages carry tables; four checked in
both themes.
…icted API Access tables

Bare '--extender-…' cells were being typographically converted to an em dash,
so the rendered flag read '—extender-enabled'. Wrapped in code so they render
verbatim and in mono. Also restores the missing space before 'authzed-audit'.
…piceDB Enterprise

Same trap as Audit Logging: a '### Self-Hosted' heading over extender flags,
reachable by deep link, with the product scope only in the intro. Renamed with
the #self-hosted anchor kept, Enterprise-only callout above the flag table.
Warning was Tailwind yellow-700 on yellow-50, info was blue-700 on blue-100;
neither is a site colour. Now: sand for warning, blue-500 for info, red-400 for
error, teal for the green type, violet for important, using the same 10% tint /
50% border / full ink recipe as the product and feature pills. Light mode darkens
the ink one step via relative colour syntax, with the plain token as the fallback
where that syntax is unsupported.
Hand-picked amber and green replaced with sand (updated) and teal (new) in the
same tint / border / ink recipe as callouts and pills.
Product asked for the pill across the whole doc set. Rather than 90 inline
tags, mdx-components.ts renders <ProductBadge /> under every H1 and
lib/products.ts decides the tiers from the route: section defaults (spicedb =
all four, authzed = managed, materialize = Dedicated, install/operator pages =
self-hosted) plus a per-page map copied from the Feature Matrix. The five
concept pages that carried inline tags now get theirs from the map. Landing
pages and the product-comparison guide render no pill. The Materialize feature
pills stack directly under the product row.

@authzed-catherine authzed-catherine left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Those pills are a good improvement!

…/review page for product sign-off

- Materialize pages had two stacked rows (product pill, then feature pills).
  The feature pills now join the product row after a thin divider; the 13
  inline <FeatureBadge /> tags go, the route already knew the features.
- A page on exactly one tier reads 'Dedicated only' instead of a pill plus
  'Not in Open Source, Cloud, Enterprise'.
- /review (preview + local only, hidden from nav): every page, the four
  tiers it renders, and the source of that decision (Feature Matrix, section
  default, or please-confirm with a note). Click-through to each page.
  Delete the route once the map is signed off.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
The teal→violet gradient read as light blue next to the sand pills. Now a
teal-only disc from the shared --teal-* tokens, deep on light, brighter on dark.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
Check glyph 12→15px in the 24px disc, disc gradient a step deeper in both
themes (teal-500→700 light, teal-400→700 dark) with a white check on both.
/review keeps its column labels pinned under the navbar through 93 rows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
Corey-T1000 and others added 2 commits September 9, 2026 16:58
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
A user could not find which command-line tool --extender-authzed-fgam-endpoint
belongs to. Both callouts now name it: flags on 'spicedb serve' in the
Enterprise binary, absent from open source (unknown-flag error). Restricted
API Access gets a worked 'spicedb serve' example and the same intro sentence
as Audit Logging naming the tiers.

Fixes OSS-466

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
@Corey-T1000

Copy link
Copy Markdown
Contributor Author

Folded in OSS-466 "Clarify FGAM settings don't apply to OSS" (f40736f).

The reporter couldn't tell which command-line tool takes --extender-authzed-fgam-endpoint. This PR already framed the section as Enterprise, so the gap was naming the binary:

  • Both Enterprise callouts (Audit Logging, Restricted API Access) now say the --extender-* flags are spicedb serve flags on the Enterprise build, and that open source spicedb rejects them with an unknown-flag error.
  • Restricted API Access gets a worked spicedb serve example above the flag table, and the same intro sentence as Audit Logging naming the tiers.

Preview: https://docs-git-docs-audit-logging-product-scope-authzed.vercel.app/docs/authzed/concepts/restricted-api-access#self-hosted

@authzed-catherine one thing to confirm: the example uses file:///etc/spicedb/fgam.yaml as an illustrative path. Does the flag shape match the current Enterprise build?

…e TOC breakpoint

Its margins assumed it followed its own row; inside the product row they
stacked with the row's bottom margin into a ~5rem gap before the body.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBAotXKGpJiWpayK6uvWKZ
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants