Staff app diagnostics
Learn what ONYX1 records in the staff app, what is masked, how long it is kept, and who can watch replays.
On this pageWhat is collected
When enabled, staff app diagnostics help ONYX1 investigate support issues and faults. Their planned purpose includes checking staged software rollouts, but remote feature-flag evaluation is off in v1. They apply to the authenticated staff app when the collection requirements are met.
What is collected
Staff app session replays, sanitised error diagnostics and limited app events help ONYX1 understand a fault or support issue. Diagnostic events can include a general app area, normalised route and software release, with a short code for some errors. Event properties contain no full URL, query string, fragment or text you entered. Replay data uses normalised route patterns instead of full URLs. All page text and input values are masked before replay data is sent. Network request and response contents, headers and browser console messages are not captured.
PostHog identity uses only the staff user's ONYX1 ID, tenant ID and role. It does not use names, email addresses or phone numbers as replay identity. A staff member's browser connects directly to PostHog Inc.'s United States service, which receives the browser's IP address as network data.
The customer portal, enquiry form and widget, platform console and public pages are outside staff diagnostics. Sign-in, MFA setup and account-recovery routes are also outside the staff app provider. Payment card details are entered on Stripe-hosted checkout, outside the staff app. Signature drawing uses a canvas that replay capture does not record. My account and Settings → Security remain eligible for diagnostics; all input values on those pages, including password or MFA fields, are masked like other inputs.
PostHog Inc. processes staff diagnostics in the United States under its Data Processing Agreement. ONYX1 relies on the safeguards in that agreement as the basis for the New Zealand to United States disclosure under Information Privacy Principle 12 of the Privacy Act 2020.
Retention and replay access
ONYX1 keeps staff app session replays and diagnostic event data for no more than 3 days after collection. The period may be shorter. Turning diagnostics off stops future collection but does not delete records already collected.
Only ONYX1's platform owner can watch replays inside PostHog in the United States, reached through the platform console's owner-only lookup. The lookup uses a safe error fingerprint to find recordings for the relevant staff member within a short time window; it lists matching recording IDs and timestamps but does not play them or create a public replay link. Tenant owners and staff cannot watch replays or access PostHog.
Turn diagnostics off
Only the workspace owner can change diagnostics for the workspace. In Settings → Security, select Turn off for this workspace to stop collection for everyone, or Turn on for this workspace to allow it when the other requirements are met. This setting does not give your team access to PostHog or to replay content. See Security settings.
Each staff user can change only their own preference in My account. In ONYX1 staff diagnostics, the first-use prompt says Review this notice before continuing. Select Continue to acknowledge the notice or Turn off for my account to opt out. After that, use Turn off for my account or Turn on for my account to change your preference. Your choice does not change the workspace setting or another person's preference. See Your account, password and two-factor authentication.
