Audit Log
Know who did what, and when.
What it adds
An append-only record of security- and data-sensitive actions.
What your agent is told to do
4
What your agent is told to do
4-
1
Log the actions that matter: sign-ins, permission changes, deletions, exports, billing changes, admin actions.
-
2
Capture actor, action, target, timestamp, and IP.
-
3
Make it append-only. An audit log that can be edited is not an audit log.
-
4
Give admins a way to search and filter it.
Edge cases it handles
5
Edge cases it handles
5- Never log passwords, tokens, or full payment details — the audit log becomes a breach target.
- Logging must not break the action it's recording; a failed log write shouldn't roll back a user's work.
- The log will grow fast — plan retention and archival from day one.
- A deleted user must remain attributable in the log.
- Impersonated actions must record both the admin and the user.
Definition of done
8
Definition of done
8- All security- and data-sensitive actions are logged.
- Entries capture actor, action, target, time, and IP.
- The log is append-only.
- No secrets are ever written to it.
- Retention and archival are defined.
- Admins can search and filter it.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Content Reporting
Content Reporting
Let users flag content that needs a human to look at it.
What it does
A reporting flow that captures a reason, a snapshot of context, and enough signal for a moderator — without exposing the reporter.
How it works
- 1 Add a report action to every user-generated surface: posts, comments, profiles, files, messages. Offer a short list of concrete reasons plus an optional free-text field.
- 2 Capture the context a moderator needs at the moment of reporting — the content ID, its current body, the author, and a timestamp — so the review is not dependent on the content still existing.
- 3 Give the reporter an immediate self-serve action alongside the report: hide this item, mute this author, or both. A report that takes hours to review leaves the user staring at the thing they reported.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/content-reporting
Scheduled Job Monitor
Scheduled Job Monitor
Find out a nightly task stopped running before your users do.
What it does
A record of every recurring schedule, the runs it was expected to make, and alerts when a run is missed or late.
How it works
- 1 Register every recurring task with its schedule expression, its time zone, and an expected maximum duration. A schedule that is not registered cannot be monitored.
- 2 Record the start and the completion of each run separately. A task that started and never finished is a different failure from one that never started, and they need different alerts.
- 3 Compute the expected run times forward from the schedule and compare them against actual starts. Alert on a missed run, and alert separately when a run starts on time but overruns its expected duration.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/scheduled-job-monitor
Cache Invalidation Controls
Cache Invalidation Controls
Clear stale cached data without flushing everything or restarting.
What it does
An operator control that invalidates cache entries by namespace, tenant, or resource — scoped, propagated across processes, and recorded.
How it works
- 1 Define named invalidation scopes rather than free-text key entry. An operator picks a namespace, a tenant, or a specific resource; they do not type raw cache keys.
- 2 Enforce tenancy on every scope. One workspace's operator must be structurally incapable of clearing another workspace's entries — check the scope against their permissions before building the key pattern, not after.
- 3 Propagate invalidation to every process and region that holds a copy. In-process and edge caches will not hear about a change made in a shared store unless you tell them, and a clear that only affects one server is worse than no clear because it looks like it worked.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/cache-invalidation-controls
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.