Have something to say?
AI usage statistics per flow
This will be useful for team members when they optimise on the AI quota usage. Users need to see: - Flow A: x amount of credits used - Flow B: y amount of credits used
Automatic Provision Users (Default Permission)
The user suggests enabling a default feature in their AP instance to let people discover and learn from each other's projects. One suggestion is to have default role to view for all users when invited.
Detect CPU Usage / Memory Per Project
Can we improve the platform admin tools to make it easier to identify which project or flow is causing CPU or memory issues? I was able to track it down using audit logs, but the process isn’t very intuitive.
Centralized Integration Hub Proxy for Agents: Unified Auth, Granular Access Control, and Audit Logging
Overview Position Activepieces as a centralized control plane for all third-party app integrations—governing authentication lifecycle, mediating API traffic (for AI agents and internal workflows), and enforcing granular access control with complete auditability. Key Capabilities 1. Centralized Authentication & Credential Lifecycle Unified Connection Management: Connect and authenticate all third-party applications in one centralized dashboard. Streamlined Re-authentication: Manage token expirations and credential renewals from a single interface, eliminating fragmented re-auth across separate workflows. 2. Granular Access Control & API Mediation Proxy for AI Agents & APIs: Route requests from AI agents or external consumers through Activepieces before reaching downstream app APIs. Permission Scoping & Guardrails: Enforce strict access boundaries independently of downstream tokens (e.g., allow read-only operations while blocking create, update, or delete mutations). 3. Governance & Audit Logging Permission Observability: Track active permissions, scopes, and credential health across all integrated services in real time. Comprehensive Audit Trail: Maintain immutable logs of all API invocations, token lifecycle events, and access attempts for security and compliance monitoring.
Request Connection
Users are onboarded to Activepieces but often don’t know how to use or manage connections. To avoid connection sprawl, only a limited number of users are allowed to create connections. For users who do not have permission, we need a “Request Connection” feature where they can: Request a new connection Provide a reason for the request Optionally forward the request to a Slack channel so platform admins can review and approve it Problem: Without this feature, users get blocked, feel confused or frustrated, and may drop off the platform. Goal: Improve onboarding and user experience while keeping connection creation controlled and visible to administrators.
Last Used in API Key
Problem: Currently, the API key table does not show when each key was last used. This makes it difficult to identify inactive or unused keys. Proposed Solution: Add a “Last Used” column to the API key table. Benefit: This will make it easier to spot and revoke unused keys, improving security and cleanup efficiency.
Filter in the project flows page here to filter flows that is using AI
I see the AI pieces are usually tagged with this annotation.
Data Retention at Project Level
An Embed customer has an enterprise customer who requested to configure AP_EXECUTION_DATA_RETENTION_DAYS at the project level, they want to delete the logs.
Export Audit Log to S3
Pushing the audit logs contentiously to s3, to perform automated checks by splunk.
Project Update Audit Event
The user would like which user have updated the Task Quota and AI Credit Quota.
Disable Certain Actions in Platform Admin
The ability to disable certain actions, but not the piece mainly due to: If action has known bug Such as Google Get Next Rows, doesn’t handle the concurrent runs
#FreeTheAuditLog
Let this be my petition that audit logs be freely available for anybody and everybody on all versions. I can understand restricting white labeling, I can understand restricting RBAC, API keys, custom pieces - all of these things make sense to be for an “enterprise” user and thus sensibly restricted. But I read “Unlock Audit Logs” and I quietly steam :( Good couple people on the AP team are familiar with my character and they’re also familiar with the fact that I genuinely love ActivePieces and I love what the team is doing with it….BUT… No difference if an instance of AP is being used by one person, or five people, or an entire marketing department - unauthorized access matters, universally, and a proper audit log may be one of the only ways to determine if unauthorized access has occurred. Please let the masses have at least the audit log. You can keep all the other fun enterprise features for yourself - but give users the audit log as a standard, so that whether an instance is being used by one user or more no matter the version, they can shoulder a responsible effort into detecting and responding to any potential intrusion.
Issue with expired AP sessions?
Following up from ash’s redirect here There’s an issue I (believe) I’ve observed where essentially… Log into ActivePieces (in this case I used Microsoft Edge) Do some ActivePieces tasks, make something break something do whatever Let the session just sit in the background for a short while (??), then abandon it. After the session expiry tolls, return to ActivePieces via your instance root url (eg: activepieces.company.com) In select circumstances, ActivePieces seems to (??) try to log in/load the expired session/load resources with expired credentials but since they’re expired, it returns a 401 Unauthorized as shown after showing the AP-styled “loading” page: In order for me to start using ActivePieces on a new session again, I have to manually start one by visiting “INSTANCE_URL/sign-in” to “log in” to ActivePieces, which then stops this error from occuring until it reproduces itself later on. a) Per the error, something’s breaking here in an ungentle manner and may need a bug check. b) If Unauthorized, Authorization Required. For me as much as getting this error is nice it would be nicer to be redirected to INSTANCE_URL/sign-in so that I can self-remedy my lack of valid authorization.