Audit Log
Know who did what, and when.
What it adds
An append-only record of security- and data-sensitive actions.
What your agent is told to do
4
What your agent is told to do
4-
1
Log the actions that matter: sign-ins, permission changes, deletions, exports, billing changes, admin actions.
-
2
Capture actor, action, target, timestamp, and IP.
-
3
Make it append-only. An audit log that can be edited is not an audit log.
-
4
Give admins a way to search and filter it.
Edge cases it handles
5
Edge cases it handles
5- Never log passwords, tokens, or full payment details — the audit log becomes a breach target.
- Logging must not break the action it's recording; a failed log write shouldn't roll back a user's work.
- The log will grow fast — plan retention and archival from day one.
- A deleted user must remain attributable in the log.
- Impersonated actions must record both the admin and the user.
Definition of done
8
Definition of done
8- All security- and data-sensitive actions are logged.
- Entries capture actor, action, target, time, and IP.
- The log is append-only.
- No secrets are ever written to it.
- Retention and archival are defined.
- Admins can search and filter it.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Content Reporting
Content Reporting
Let users flag content that needs a human to look at it.
What it does
A reporting flow that captures a reason, a snapshot of context, and enough signal for a moderator — without exposing the reporter.
How it works
- 1 Add a report action to every user-generated surface: posts, comments, profiles, files, messages. Offer a short list of concrete reasons plus an optional free-text field.
- 2 Capture the context a moderator needs at the moment of reporting — the content ID, its current body, the author, and a timestamp — so the review is not dependent on the content still existing.
- 3 Give the reporter an immediate self-serve action alongside the report: hide this item, mute this author, or both. A report that takes hours to review leaves the user staring at the thing they reported.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/content-reporting
Scheduled Job Monitor
Scheduled Job Monitor
Find out a nightly task stopped running before your users do.
What it does
A record of every recurring schedule, the runs it was expected to make, and alerts when a run is missed or late.
How it works
- 1 Register every recurring task with its schedule expression, its time zone, and an expected maximum duration. A schedule that is not registered cannot be monitored.
- 2 Record the start and the completion of each run separately. A task that started and never finished is a different failure from one that never started, and they need different alerts.
- 3 Compute the expected run times forward from the schedule and compare them against actual starts. Alert on a missed run, and alert separately when a run starts on time but overruns its expected duration.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/scheduled-job-monitor
Maintenance Mode
Maintenance Mode
Pause the app on purpose instead of serving a generic 500.
What it does
An operator-controlled outage window that shows a real maintenance page, lets staff through, and tells API clients the truth.
How it works
- 1 Make the mode a runtime flag an operator can flip without a deploy, and store it somewhere that stays reachable when the database is the thing being maintained.
- 2 Allowlist bypass for authenticated staff and for the health check endpoint, so the people fixing the problem can still use the app and the load balancer does not remove every instance.
- 3 Return 503 with a Retry-After header for API and crawler requests, and render the maintenance page for browsers. A 200 on a maintenance page tells search engines your content is now an apology.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/maintenance-mode
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.