diff --git a/docs/config.json b/docs/config.json
index 34ee77859b0..208a1485882 100644
--- a/docs/config.json
+++ b/docs/config.json
@@ -1893,7 +1893,7 @@
"nodeIP": "ip-172-31-35-170"
},
"access_graph": {
- "version": "1.13.0"
+ "version": "1.20.1"
},
"ansible": {
"min_version": "2.9.6"
diff --git a/docs/img/access-graph/add-node-type.png b/docs/img/access-graph/add-node-type.png
deleted file mode 100644
index ddcba0468ba..00000000000
Binary files a/docs/img/access-graph/add-node-type.png and /dev/null differ
diff --git a/docs/img/access-graph/allow-action-node.png b/docs/img/access-graph/allow-action-node.png
index 0254ed1e279..e60af86a58f 100644
Binary files a/docs/img/access-graph/allow-action-node.png and b/docs/img/access-graph/allow-action-node.png differ
diff --git a/docs/img/access-graph/allow-path.png b/docs/img/access-graph/allow-path.png
index c1aa88eed94..d894065a487 100644
Binary files a/docs/img/access-graph/allow-path.png and b/docs/img/access-graph/allow-path.png differ
diff --git a/docs/img/access-graph/collapse-node.png b/docs/img/access-graph/collapse-node.png
deleted file mode 100644
index 4e9806c03e3..00000000000
Binary files a/docs/img/access-graph/collapse-node.png and /dev/null differ
diff --git a/docs/img/access-graph/deny-action-node.png b/docs/img/access-graph/deny-action-node.png
index 1edc7c53b48..055b9c8d612 100644
Binary files a/docs/img/access-graph/deny-action-node.png and b/docs/img/access-graph/deny-action-node.png differ
diff --git a/docs/img/access-graph/deny-path.png b/docs/img/access-graph/deny-path.png
index 46635cbf425..210f86ee3c6 100644
Binary files a/docs/img/access-graph/deny-path.png and b/docs/img/access-graph/deny-path.png differ
diff --git a/docs/img/access-graph/expand-node.png b/docs/img/access-graph/expand-node.png
deleted file mode 100644
index f133c11d30f..00000000000
Binary files a/docs/img/access-graph/expand-node.png and /dev/null differ
diff --git a/docs/img/access-graph/expand-one-level.png b/docs/img/access-graph/expand-one-level.png
deleted file mode 100644
index 43e3b69fa5b..00000000000
Binary files a/docs/img/access-graph/expand-one-level.png and /dev/null differ
diff --git a/docs/img/access-graph/expand-two-levels.png b/docs/img/access-graph/expand-two-levels.png
deleted file mode 100644
index 92c2205dc5e..00000000000
Binary files a/docs/img/access-graph/expand-two-levels.png and /dev/null differ
diff --git a/docs/img/access-graph/identity-group-node.png b/docs/img/access-graph/identity-group-node.png
new file mode 100644
index 00000000000..468f15cc0e4
Binary files /dev/null and b/docs/img/access-graph/identity-group-node.png differ
diff --git a/docs/img/access-graph/identity-node.png b/docs/img/access-graph/identity-node.png
new file mode 100644
index 00000000000..4e57afefeed
Binary files /dev/null and b/docs/img/access-graph/identity-node.png differ
diff --git a/docs/img/access-graph/integrations.png b/docs/img/access-graph/integrations.png
new file mode 100644
index 00000000000..0c1222e8178
Binary files /dev/null and b/docs/img/access-graph/integrations.png differ
diff --git a/docs/img/access-graph/main-view.png b/docs/img/access-graph/main-view.png
index d0994789d2a..e7377c0be1d 100644
Binary files a/docs/img/access-graph/main-view.png and b/docs/img/access-graph/main-view.png differ
diff --git a/docs/img/access-graph/remove-node-type.png b/docs/img/access-graph/remove-node-type.png
deleted file mode 100644
index 242510b8d59..00000000000
Binary files a/docs/img/access-graph/remove-node-type.png and /dev/null differ
diff --git a/docs/img/access-graph/resource-group-node.png b/docs/img/access-graph/resource-group-node.png
index 93fc01f7afe..e306ab83fc9 100644
Binary files a/docs/img/access-graph/resource-group-node.png and b/docs/img/access-graph/resource-group-node.png differ
diff --git a/docs/img/access-graph/resource-node.png b/docs/img/access-graph/resource-node.png
index cc569dd77d2..ceb2bf74acd 100644
Binary files a/docs/img/access-graph/resource-node.png and b/docs/img/access-graph/resource-node.png differ
diff --git a/docs/img/access-graph/search-item-checkbox-click.png b/docs/img/access-graph/search-item-checkbox-click.png
deleted file mode 100644
index 5428b79909a..00000000000
Binary files a/docs/img/access-graph/search-item-checkbox-click.png and /dev/null differ
diff --git a/docs/img/access-graph/search-item-click.png b/docs/img/access-graph/search-item-click.png
deleted file mode 100644
index be5ade930ab..00000000000
Binary files a/docs/img/access-graph/search-item-click.png and /dev/null differ
diff --git a/docs/img/access-graph/search.png b/docs/img/access-graph/search.png
index 5f639889bc6..be454845a04 100644
Binary files a/docs/img/access-graph/search.png and b/docs/img/access-graph/search.png differ
diff --git a/docs/img/access-graph/show-access-path-resource.gif b/docs/img/access-graph/show-access-path-resource.gif
index 9404a66cb62..e77994988ec 100644
Binary files a/docs/img/access-graph/show-access-path-resource.gif and b/docs/img/access-graph/show-access-path-resource.gif differ
diff --git a/docs/img/access-graph/show-access-path.gif b/docs/img/access-graph/show-access-path.gif
index 4d21a404954..a98ca9a6c27 100644
Binary files a/docs/img/access-graph/show-access-path.gif and b/docs/img/access-graph/show-access-path.gif differ
diff --git a/docs/img/access-graph/sidebar.png b/docs/img/access-graph/sidebar.png
index 8af489e10a2..45270be5b56 100644
Binary files a/docs/img/access-graph/sidebar.png and b/docs/img/access-graph/sidebar.png differ
diff --git a/docs/img/access-graph/sql-editor.png b/docs/img/access-graph/sql-editor.png
new file mode 100644
index 00000000000..cadedcebf08
Binary files /dev/null and b/docs/img/access-graph/sql-editor.png differ
diff --git a/docs/img/access-graph/temporary-action-node.png b/docs/img/access-graph/temporary-action-node.png
deleted file mode 100644
index e53ac5bed25..00000000000
Binary files a/docs/img/access-graph/temporary-action-node.png and /dev/null differ
diff --git a/docs/img/access-graph/temporary-resource-group-node.png b/docs/img/access-graph/temporary-resource-group-node.png
deleted file mode 100644
index 73e46c7c78a..00000000000
Binary files a/docs/img/access-graph/temporary-resource-group-node.png and /dev/null differ
diff --git a/docs/img/access-graph/temporary-user-group-node.png b/docs/img/access-graph/temporary-user-group-node.png
deleted file mode 100644
index 3e9fcb2f06e..00000000000
Binary files a/docs/img/access-graph/temporary-user-group-node.png and /dev/null differ
diff --git a/docs/img/access-graph/user-group-node.png b/docs/img/access-graph/user-group-node.png
deleted file mode 100644
index 50d80f4d454..00000000000
Binary files a/docs/img/access-graph/user-group-node.png and /dev/null differ
diff --git a/docs/img/access-graph/user-node.png b/docs/img/access-graph/user-node.png
deleted file mode 100644
index 0686c861fa8..00000000000
Binary files a/docs/img/access-graph/user-node.png and /dev/null differ
diff --git a/docs/pages/access-controls/access-graph.mdx b/docs/pages/access-controls/access-graph.mdx
index c00bd63b237..f5e17e94a22 100644
--- a/docs/pages/access-controls/access-graph.mdx
+++ b/docs/pages/access-controls/access-graph.mdx
@@ -23,126 +23,56 @@ under the Permission Management section.
## Graph nodes
-Teleport Access Graph divides your infrastructure into eight main components:
+Teleport Access Graph divides your infrastructure into six main components:
-1. Users
+1. Identities
-
+
-Users are the people who access your infrastructure. They can be employees,
-contractors, or bots.
+Identities are the actors that can access your infrastructure. They can be employees,
+contractors, machines or bots.
+
+The number on the right hand side shows "standing privileges".
+Standing privileges is the number of resources that an identity can access without
+creating an access request.
2. User Groups
-
+
-User Groups are collections of users. They can be used to organize users
-based on their role or team.
+Identity Groups are collections of identities. They can be used to organize users
+based on their role or team, and they can be nested.
-3. Temporary user groups
-
-
-
-Temporary User Groups are created when a user is granted temporary access to a
-resource. They are automatically deleted when the user's access expires.
-
-4. Actions
+3. Actions

-Actions are the things that users can or cannot do. Actions are related to
+Actions are the things that identities can or cannot do. Actions are related to
resources. For example, a user can SSH into a node.
-5. Deny Actions
+4. Deny Actions

-Deny Actions are the things that users cannot do. Deny Actions are related to
+Deny Actions are the things that identities cannot do. Deny Actions are related to
resources. For example, a user cannot SSH into a node.
-6. Temporary Actions
-
-
-
-Temporary Actions are created when a user is granted temporary access to a
-resource. They are automatically deleted when the user's access expires.
-
-7. Resource Groups
+5. Resource Groups

Resource Groups are collections of resources. They can be used to organize
resources based on their role or team.
-8. Resources
+The number on the right hand side shows the number of resources that a resource group contains.
+
+6. Resources

Resources are the things that users can or cannot access. They can be
servers, databases, or Kubernetes clusters.
-## Searching
-
-To search for a graph node, either click the search button in the sidebar on the left,
-or press the `s` key.
-
-
-
-You can then search through all node types. If you select a result using your keyboard
-arrow keys, you can press either `Tab` to add the node to the graph, or `Enter` to replace
-the graph with just the individual node.
-
-## Changing what is visible
-
-By default, Teleport Access Graph shows all types of nodes and paths. You can see what
-node types are visible by looking at the sidebar on the left.
-
-
-
-### Showing/removing individual graph nodes
-
-To show or remove an individual graph node, open up the node type in the sidebar and
-click on the node you want to show or remove.
-
-
-
-Clicking on the node name will toggle the visibility of that node.
-
-
-
-Clicking on the checkbox will select only that node.
-
-### Adding/removing graph node types
-
-To add a graph node type that isn't in the view, select it from the list of available
-node types.
-
-
-
-To remove the graph node type, expand the node type in the sidebar and click on the
-remove button.
-
-
-
-### Expanding/collapsing graph nodes
-
-If a graph node has connections to other nodes, it can be expanded to show those
-connections. To expand a node, hover over the edge of the node. If there are
-connections in that direction, the edge will turn blue. Clicking on the edge
-will expand the node.
-
-
-
-You can keep expanding graph nodes until you reach the end of the path.
-
-
-
-
-
-To collapse a graph node, click on the edge that was used to expand it.
-
-
-
## Graph paths
Teleport Access Graph shows the relationships between users, roles, and
@@ -161,14 +91,14 @@ Paths can be divided into two categories:

-Allow paths connect users to resources. They show what a user can access
+Allow paths connect identities to resources. They show what an identity can access
and what actions they can perform.
2. Deny paths

-Deny paths connect users to resources. They show what a user cannot access
+Deny paths connect identities to resources. They show what a identity cannot access
and what actions they cannot perform. Deny paths take precedence over allow
paths.
@@ -184,13 +114,80 @@ Teleport Access Graph can help you to answer questions like:

+## Navigation
-## How Teleport resources are represented
+
-Teleport Access Graph imports all Teleport resources and keeps them up to date, so every time you make a change
+The left hand side menu contains the main navigation options:
+
+- Graph view
+- Search
+- SQL editor
+- Integrations
+
+## Graph View
+
+Graph view is the main view that shows the connections between identities and resources.
+By default, an aggregated view of access paths grouped by identity is showed.
+
+## Search
+
+To search for a graph node use the search bar at the top of the page or the search icon on the right hand side.
+
+
+
+You can then search through all node types and all imported entities.
+
+## SQL Editor
+
+Access Graph allows creating SQL like queries to explore the graph.
+
+
+
+The query language allows to create different views of the graph, ex:
+
+Show only allowed paths
+
+```sql
+SELECT * FROM access_path WHERE kind = 'ALLOWED';
+```
+
+Show only denied paths
+```sql
+SELECT * FROM access_path WHERE kind = 'DENIED';
+```
+
+Show all access paths for a user
+
+```sql
+SELECT * FROM access_path WHERE identity = 'bob';
+```
+
+Show all access paths for a user AND resource
+
+```sql
+SELECT * FROM access_path WHERE identity = 'bob' AND resource = 'postgres';
+```
+
+More actionable examples is available under ? icon.
+
+## Integrations
+
+
+
+Integrations page shows integrations that can be enabled or are already enabled in Access Graph.
+
+
+ Resources imported into Teleport through Teleport enabled integrations are automatically imported into
+ Access graph without any additional configuration.
+
+
+## How resources and identities are represented
+
+Access Graph imports all resources and identities from Teleport and keeps them up to date, so every time you make a change
to your Teleport resources, the Access Graph will reflect those changes.
-### Users
+### Identities
Users are created from Teleport Users.
Local users are imported as soon as they are created.
@@ -222,6 +219,7 @@ Actions take precedence over Allow Actions.
Temporary Actions are created when a user is granted temporary access to a
resource. They are automatically deleted when the user's access expires.
+The temporary actions can be identified by having `Temporary: true` property.
#### Resource Groups
diff --git a/docs/pages/access-controls/access-graph/aws-sync.mdx b/docs/pages/access-controls/access-graph/aws-sync.mdx
index 60d7a61179d..2d303aa17b1 100644
--- a/docs/pages/access-controls/access-graph/aws-sync.mdx
+++ b/docs/pages/access-controls/access-graph/aws-sync.mdx
@@ -45,6 +45,7 @@ AWS account:
- User Groups
- IAM Roles
- IAM Policies
+- EC2 Instances
- EKS Clusters
- RDS Databases
- S3 Buckets
diff --git a/docs/pages/access-controls/access-graph/self-hosted-helm.mdx b/docs/pages/access-controls/access-graph/self-hosted-helm.mdx
index 944fbefaccc..2d3654008bf 100644
--- a/docs/pages/access-controls/access-graph/self-hosted-helm.mdx
+++ b/docs/pages/access-controls/access-graph/self-hosted-helm.mdx
@@ -22,10 +22,10 @@ to Teleport Enterprise customers.
- Kubernetes >= v1.21
- Helm >= (=helm.version=)
-- A running Teleport Enterprise cluster v14.3.4 or later.
+- A running Teleport Enterprise cluster v14.3.6 or later.
- For the purposes of this guide, we assume that the Teleport cluster is set up
[using the `teleport-cluster` Helm chart](../../deploy-a-cluster/helm-deployments.mdx)
- in the same Kubernetes cluster that will be used to deploy Teleport Access Graph .
+ in the same Kubernetes cluster that will be used to deploy Teleport Access Graph.
- An updated `license.pem` with Teleport Policy enabled.
- A PostgreSQL database server v14 or later.
- Access Graph needs a dedicated [database](https://www.postgresql.org/docs/current/sql-createdatabase.html) to store its data.
@@ -34,7 +34,7 @@ to Teleport Enterprise customers.
- Amazon RDS for PostgreSQL is supported.
- A TLS certificate for the Access Graph service
- The TLS certificate must be issued for "server authentication" key usage,
- and must contain a X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
+ and must contain an X.509 v3 `subjectAltName` extension with the Kubernetes service name for TAG
(`teleport-access-graph.teleport-access-graph.svc.cluster.local` by default).
diff --git a/docs/pages/access-controls/access-graph/self-hosted.mdx b/docs/pages/access-controls/access-graph/self-hosted.mdx
index c076ee0b1f9..d950401d50b 100644
--- a/docs/pages/access-controls/access-graph/self-hosted.mdx
+++ b/docs/pages/access-controls/access-graph/self-hosted.mdx
@@ -18,7 +18,7 @@ to Teleport Enterprise customers.
## Prerequisites
-- A running Teleport Enterprise cluster v14.3.4 or later.
+- A running Teleport Enterprise cluster v14.3.6 or later.
- An updated `license.pem` with Teleport Policy enabled.
- Docker version v(=docker.version=) or later.
- A PostgreSQL database server v14 or later.