Lnav Ad Hoc Access Control solves this problem inside the log viewer you already trust. Lnav reads local and remote logs, indexes them, and lets you query with SQL-like precision. Ad hoc access control layers on top so you can grant or restrict log visibility at runtime without server restarts or static configuration files.
This is not a full RBAC rewrite. It’s tight, scoped control that lets you give another engineer visibility into a specific session, file, or query for a set period of time. You can lock down sensitive fields, block certain log types, and segment access per role or environment. No redeploy. No full-service downtime.
With Lnav ad hoc permissions, temporary access can be created from the CLI or via API. This enables incident response, debugging, or auditing workflows where speed and safety matter. Credentials expire on schedule, and attempts to bypass restrictions are logged. The feature integrates cleanly with SSH tunneling, containerized deployments, and CI/CD systems.