Regixo docs
🔧 For the engineer·Screen reference·see the whole journey ↗
Reference · screen by screen

Screen reference — the free portal

A screen-by-screen reference for the free portal (regixo open): each screen, what it’s for, and the part of it you act on. Use it to look one thing up. To be walked through the free portal as a lived session, start with the walkthrough Your first session →.

The pictures below are cropped from the running product — the screen’s masthead and nav so you can find it in your own Regixo, then the one region that screen exists to do. Everything else on each screen is described in the text.

run
$ regixo open

Run this one yourself, not through your agent — it keeps running until you press Ctrl+C, so give it a terminal of its own.

Run it in a terminal of its own and leave it there — the portal is that command, so the terminal stays busy for as long as you want the portal up. Don’t ask a coding agent to run it: a portal your agent starts belongs to its session, so you can’t stop or restart it, and it dies when the agent moves on. Why →

It opens http://localhost:4319 in your browser. It runs on your machine, binds to localhost only, and needs no login — there’s nothing to sign into.

What it is, and isn’t The free portal is a read-only lens over your map, plus a small set of correction writes (fix a classification, add a description, assert a data flow, define a term, switch mode). It never scans, connects a source, forwards a draft, or takes payment — those stay in the CLI or the compliance portal. Where a screen shows a command, it copies it to your clipboard; it doesn’t run it.

A masthead (“Regixo · data catalog · free & local”) sits over a nav with one flat link and three dropdowns:

The screen you’re on shows a small “you’re here” marker. Nothing else sits under the header: Regixo shows no setup checklist and no progress meter, because it will not tick a step it cannot verify. What it can see — for example, how many datasets still have no description — it counts for you on the Overview, under “What you can do next.”

Overview

The home screen answers two questions. What have I got? — four stat tiles: N sources connected · N datasets mapped · N hold personal data · special category · Art. 9. And what happens next? — the draft card: from the same map Regixo has already started your GDPR record, and this is where you hand it over.

what you'll see — the Overview: the four counts, and the draft card that hands the record over
Regixo data catalog · free & local

Your data map is ready.

§
A compliance draft is already started for you DRAFT

From this same map, Regixo also drafted a GDPR Article 30 record36 activities, with the legal calls left for a person. Finishing it is a legal job, not an engineering one — just know it’s ready to hand over.

Forward a copy. Your compliance team gets a link they can open — no account needed.

say

“Forward my Regixo draft record to our compliance team. Show me what would be uploaded before you send it.”

Show the commandHide the commandShow the sentenceHide the sentence
run

Above the tiles sits a coverage banner; below the card, a “What you can do next” section that counts real, verifiable work for you (for example, how many datasets still have no description). When a source’s last scan ages past the warn threshold (30 days, loud at 90 — configurable in regixo.yml), Overview and Map carry an honest staleness banner instead: “This map may be out of date”, listing each overdue source with its age and pointing at regixo watch.

You can do: click a stat tile to drill into the filtered Map, use Browse the data map →, and take the next step from a say / run panel (regixo describe, regixo add, regixo watch). There is no search box here — search lives on the Map, once. Empty state: “No data mapped yet” with the regixo start to run.

Map — the data lens

The core screen (Catalog ▾ → Map), and the one place the free portal lets you write. It’s a workbench: a toolbar on top, then a rail and a pane that scroll independently. You browse in the rail — one collapsible fold per source, every dataset a row with its column count and a personal-data dot, “holds personal data” first. Above the folds (not shown here) sit a search box, a Source picker and the Personal data · Art. 9 · Art. 10 · Undescribed facets, each with a live count.

what you'll see — the Data map: the source rail, with the stripe fold open

Before you pick anything, the pane carries an orientation line, a trust panel (Reached · Fresh · Confirmed · Sealed — the same verdict an agent gets from get_provenance) and a source-overview grid. Open a dataset and it switches to that dataset’s detail: what it is, its columns — each with the Correct control below — a description box, and a vertical-river lineage graph (upstream above, this dataset on the trunk, downstream below).

what you'll see — the Data map: a dataset’s columns (3 of 11), with the Correct control open
Regixo data catalog · free & local

Data map

63 datasets · 170 personal-data columns

re-scan · stays local

stripe / stripe / payment_method

● 10 personal✓ corrected
ColumnTypePersonal data
billing_address_countrystripe-field optional● Address by field name
Correct
A mechanical fix, never a legal judgement. It overrides Regixo’s detection, survives every re-scan, and is logged in What changed.
billing_namestripe-field optional● Personal data corrected by you
Correct
A mechanical fix, never a legal judgement. It overrides Regixo’s detection, survives every re-scan, and is logged in What changed.
idstripe-field optionalnot personal
Correct
A mechanical fix, never a legal judgement. It overrides Regixo’s detection, survives every re-scan, and is logged in What changed.

You can do — the Map is where the free portal’s write controls live. Correct is in the frame above; here is the whole set:

Control (label)What it doesCLI twin
Search box + typeaheadRanked search of datasets, columns & glossary (“Best matches” / “matched on meaning”).regixo search
Personal data / Art. 9 filter pillsFilter the list to personal-data or special-category datasets.?pii=1 / ?special=1
Column row → CorrectA “This column is” select — Personal data / Special category · Art. 9 / Criminal offence · Art. 10 / Not personal data — plus Revert to Regixo’s call. A mechanical fix; survives a re-scan.regixo classify
Draft a description / Confirm / ClearAdd a plain-English description to a dataset (drafted from metadata, marked “suggested” until you confirm).regixo describe
Lineage + Assert / remove“Assert a flow from <dataset> to:” a target dataset — a cross-system, dataset-level edge no scanner can infer. It draws into the vertical-river graph.regixo lineage

Prefer to ask instead of browse? Everything here is also readable by an AI agent — see With an AI agent.

Record (RoPA)

Compliance ▾ → Record (RoPA) — your GDPR Article 30 draft, always badged DRAFT. It is a list of activities. Each one names the tables it runs on, states what Regixo found in them, and says plainly what it cannot decide: the legal calls are marked needs you, never guessed. A 3-step progress block (Data mapped ✓ → Your part → Review & sign) sits in the “Where this stands” rail card.

what you'll see — the Record (RoPA): the letterhead, and one activity of 27 with every field badged
Regixo data catalog · free & local

GDPR · Art. 30 · drafted from the sources you configure — metadata only, never row values

Record of Processing Activities

DRAFT

A plain list of every way your company uses people’s personal data — drafted from the sources you configure. EU law (GDPR Art. 30) makes most companies keep one. Each entry is an activity: your datasets, grouped by the job they serve.

A narrow exemption exists for organisations under 250 people. It falls away if the processing is non-occasional, risky, or touches special-category or criminal-offence data — routine systems like payroll or a CRM already end it, so nearly every organisation keeps the record.

2 / 27

Uncategorised processing

4 open calls

kyc_documents

⚠ Needs you: confirm the legal fields (purpose, lawful basis, retention); these tables were grouped automatically — confirm they belong to one activity; add who you share this data with (recipients) — none could be detected from the schema.
PurposeDescribe the purpose of this processing activity needs you
Personal dataIdentifier found
Data subjects needs you
Recipients— none detected from your schema; add who you share this with needs you
Lawful basisChoose an Art. 6(1) lawful basis needs you
RetentionSet a retention period needs you
Transfers outside the EUNone identified from source regions suggested
Security measuresEncrypted at rest provided provided by engineer-portal · 15 Jul 2026 — not confirmed yet
A person confirms legal fields — not Regixo. Purpose, lawful basis and retention are legal judgements: Regixo drafts them from the data and never confirms one; the compliance team reviews and signs. Security measures, recipients and data subjects are not legal calls — they are facts about the systems, and the engineering side answers them.

Above the activity list sits Your part (its heading counts the questions still open — “three quick facts” in the picture below): the record captures ten things per activity — seven are legal calls your compliance team makes, and three are facts only the engineering side knows (how the data is protected, which outside services get a copy, whose data it is). You answer those once, here, and the answers travel with the record; per-activity exceptions are one disclosure away.

a close-up — “Your part” on the Record page: answer once, set exceptions only where an activity differs
§ Your part

Three quick facts only you can give

Your compliance team can’t answer these — they’re facts about your systems, and you know them. About a minute, then they travel with the record.

Why is this mine, not my compliance team’s?

Regixo’s record captures ten things per activity. Seven are legal calls your compliance team makes — Regixo never makes one. Three are facts only your engineering team knows:

  • which outside services get a copy?
  • whose data is it?
  • how is the data protected?

Leave them blank and they reach your compliance team as gaps — and the only way to close one is an email back to you.

1 of 3 answered · 2 still need you

Who receives this data?

Needs you

Outside services that get a copy of personal data. Regixo found no outside services among your connected sources, so name anyone outside your company who receives a copy.

One answer fills all 4 blank activities at once.

You can do: answer Your part (above), then hand the record off — with regixo invite, or without a terminal at all. The hand-off annex carries four controls:

Once forwarded, the rail flips to “✓ Forwarded — now it’s with your compliance team” with the live link. If your catalog moves on after you make the link, the annex says so plainly — “Your catalog has changed since you made this” — and a fresh invitation replaces the old one.

The legal calls stay read-only on this local free screen — filling and confirming happen on the forwarded compliance portal (or via regixo annotate). If a licence is present, an Unlock & sign card appears — the two questions set the plan and show the published price; paying and signing happen on the forwarded compliance portal.

Invite — before it leaves your machine

Record (RoPA) → Make the invitation. This is the upload that starts the hand-off, and the screen exists to show you the exact payload first. (regixo watch and regixo push also upload, and only when you run them.)

It opens with the headline “Before this leaves your machine”. If your own answers (“Your part”) are still blank it warns you — “a warning, not a gate”. The payload itself is a two-column ledger: What goes and What never goes.

what you'll see — the Invite screen: the gate warning, and the what-goes / what-never-goes ledger
Regixo data catalog · free & local

Before this leaves your machine

Making an invitation is the only upload you start by hand. Nothing moves until you press the button at the bottom.

45 of your own answers are still blank. How the data is protected, who you share it with, whose data it is — facts only your side knows. Your compliance team cannot fill them in, so they arrive as gaps and their only move is to email you. It takes about a minute: finish Your part. You can hand it over anyway — this is a warning, not a gate.

What goes

  • Table names44 The full path of each table that looks like it holds personal data — source, schema, table. For example bigquery/regixo_test/accounts.
  • The kinds of personal data found The categories the classifier worked out from your column names — Email, Name — listed per activity. Never the column name itself.
  • The drafted record Activity titles and Regixo’s suggested legal fields.
  • Your DORA register15 tables The draft register of your outside IT providers, so your compliance team can review it in the same place.
  • The address you type belowif you fill it in Exactly as you type it — not hashed, not masked, because that is what binds the record to that person. Leave it blank and no personal data goes at all.

What never goes

  • Your data Not one row, not one value, not ever — Regixo has never read one.
  • Your column names They do not leave the machine at all. The portal learns a column looks like an email address without learning what it is called.
  • Credentials & connection details They stay in your environment. Regixo never puts a secret in anything it uploads.
  • Column types The portal never learns whether a column is text, a date or a number.
  • Table owners The catalog records who owns each table. None of that is in the upload.

Apart from that address, everything else is a count, not a name — 10 sources · 62 datasets · 194 columns that look like personal data.

Exactly what leaves — the canonical payload Metadata only: the table paths of the tables that look personal, the kinds of personal data (categories, never the column name), the drafted record and your org name, and the recipient address only if you type it — exactly as typed. What never leaves: a row or value, column names, column types, credentials, table owners. Everything else is a count, not a name. The ledger above is computed from the actual payload, and the same reference is on the Data handling page.

You can do:

A second warning covers re-inviting: a fresh invitation replaces the one before it (the old link stops working; everything the compliance team filled in carries over). Regixo emails nobody — it makes a link; sharing it is yours to do. Prefer to see the record they will see, first? regixo invite --no-upload then regixo serve-claim serves it locally.

DORA register

Compliance ▾ → DORA register (shown only when DORA scope is on). The screen is honest about how far a scanner can get: a progress meterRegixo filled · you provided · partly · needs you — over the 15 sections, grouped A · Your company, B · Your contracts, C · Your IT suppliers, D · Your functions. Regixo part-fills the tables it can see from your sources (your IT providers, the services they run); contracts, branches and criticality it cannot see, and says so.

what you'll see — the DORA register: the letterhead, and the row list Regixo part-fills (B_05.01) under its group. Each row opens into its 13 fields; the open editor is shown on The DORA register
Regixo data catalog · free & local

DORA · Register of Information · Reg. (EU) 2024/2956 — drafted from the sources you configure

Your DORA register

DRAFT

The outside IT and software suppliers your business depends on. DORA requires a financial firm in its scope to keep a register of information like this one.

A

Your company

0 / 3 started
B

Your contracts

0 / 7 started
C

Your IT suppliers

1 / 2 started
B_05.01

Your IT third-party providers — ICT third-party service providers

partly auto

2 candidate ICT third-party provider(s) auto-identified from your sources (name, service type, country); each provider’s LEI is yours to add. Whether each provider counts as an ICT service under DORA is yours to confirm — a payment service from a regulated provider may be a financial, not an ICT, service (EC Q&A DORA030). Rule on each row: regixo dora set B_05.01 <rowKey> inScope confirmed|excluded.

Legal nameProvider codeService typeFieldsIn DORA scope?
BigQueryautoneeds youS19 — Cloud services: SaaSauto2 filled · 11 openCandidate
Stripeautoneeds youS19 — Cloud services: SaaSauto2 filled · 11 openCandidate
D

Your functions

2 / 3 started

You can do: read any of the 15 tables, copy the fill commands (regixo dora import / set), and turn scope off. A scope gate at the top of the register says why the screen is showing at all (regixo.yml: dora: true) and offers “Not regulated? Turn it off →”; below the tables, a “Who fills in the rest” block gives the two honest ways forward — forward it, or import it yourself. The progress meter lives in the “Where this stands” rail card. Filling the cells and the sealed export happen on the compliance portal or the CLI. Out of scope, it’s a friendly gate: “DORA isn’t switched on for this project.”

What changed

Catalog ▾ → What changed. A dated timeline of every change to your map — added, removed, reclassified, described — newest first, each entry saying in one sentence what moved and what it means. It’s the browser twin of regixo log, filled by regixo start and regixo watch.

what you'll see — What changed: three entries from the timeline
Regixo data catalog · free & local

What changed

4 days ago 7 Jul
You recorded a data flow involving customer.
mysql-db/shop/customers → stripe/stripe/customer
This says data moves between these datasets. It shows on the map and in the record.
15:14you
You recorded a data flow involving contacts.
mysql-db/shop/customers → hubspot/script/contacts
This says data moves between these datasets. It shows on the map and in the record.
15:14you
You recorded a data flow involving contacts.
app-db/app/customers → hubspot/script/contacts
This says data moves between these datasets. It shows on the map and in the record.
15:14you

Above the entries: a summary line, filter pills and a count; below them, Load older ↓. A first scan shows a “Baseline created” card instead. If a signed record has since drifted, a gold re-sign banner appears with Review & re-sign →.

Glossary

Catalog ▾ → Glossary. Your shared business dictionary, browsable by an A–Z strip (letters with no terms are dimmed). Each term carries its status — ✓ confirmed, or suggested when an agent proposed it — and the datasets it touches as source-qualified chips (fintech-loans / borrowers), so two tables that share a name are never confused.

what you'll see — the Glossary: the A–Z strip, and one term with its source-qualified datasets

+ Add term opens the composer. Its “Link to datasets” field is not a flat list: at any real estate size that would be hundreds of look-alike rows (thirteen tables called users). It is a filterable picker of source folds — one fold per source, each row named source / table — with a tray of what you’ve ticked above it, so Save stays in reach.

what you'll see — the Glossary composer: the “Link to datasets” picker — one fold per source, 2 of 10 shown
Regixo data catalog · free & local

Glossary

✎ Add a term

Fill this in and Save — the term appears in the dictionary straight away. It’s a local action: this runs on your own machine, nothing is uploaded.

Nothing linked yet — open a source below and tick its tables.
app-db7 tables6 personal
bigquery8 tables7 personal

personal data

Cancel

You can do: search the dictionary, + Add term, Edit a term (Remove term lives inside the editor), and confirm one an agent suggested. Same store path as regixo glossary set/confirm; served read-only to agents.

Agents (MCP)

Help ▾ → Agents (MCP). The screen that connects an AI assistant to your catalog — the no-terminal way to do it. Step 1 is the whole job: pick your tool (Claude Desktop / Claude Code / Cursor / VS Code / Other) and press Copy snippet for the ready-made config — Claude Code takes a single claude mcp add … line instead. The note under it hands your agent the reading playbook (regixo mcp --skill). Step 2 — not shown here — is simply: restart the app and ask it something. Full walkthrough: With an AI agent.

what you'll see — Agents (MCP): step 1 — pick your tool, copy the snippet
Regixo data catalog · free & local

Connect your AI assistant to your data

local · stdio — runs inside your AI app
1
Add Regixo to your AI tool

Pick your tool — we’ll show the exact snippet and the file it goes in (Claude Code takes a single command instead). Paste it and save. (regixo mcp --print-config prints this for you too.)

claude_desktop_config.jsonread-only
{
  "mcpServers": {
    "regixo": {
      "command": "npx",
      "args": [
        "regixo",
        "mcp"
      ],
      "env": {
        "REGIXO_DATA": "/Users/you/app",
        "REGIXO_CONFIG": "/Users/you/app"
      }
    }
  }
}
Paste into macOS: ~/Library/Application Support/Claude/claude_desktop_config.json · Windows: %APPDATA%\Claude\claude_desktop_config.json

This pins your project’s data dir + config, so the agent reads this catalog from wherever your AI app launches it.

📘
Hand your agent the reading playbook. One command prints a short markdown skill that teaches your agent when to call which tool — and how to read the trust signals (draft vs confirmed, staleness) — before it answers. Paste it into your agent’s instructions (an AGENTS.md, or your tool’s rules file).

Evidence bundle

Compliance ▾ → Evidence bundle. One machine-readable file that proves what your records say — the RoPA draft, the DORA register, the change log and the source list, with a real per-artifact sha256: fingerprint. You can do: ↓ Download, ↻ Regenerate. It’s a DRAFT bundle; the signed official bundle is the paid step. Twin of regixo evidence.

what you'll see — the Evidence bundle: the Create-it card, and the manifest with a sha256 per artifact
Regixo data catalog · free & local

One file that proves what your records say

draft ready

Create it

Bundle ready

Your latest file is below. Create a fresh one any time — each bundle is stamped with the moment it was made. It runs entirely on your machine — nothing is uploaded.

✓ Bundle ready
regixo-evidence-2026-07-11.json
DRAFT · 60 KB · 4 parts · generated just now (2026-07-11)
RoPA_DRAFT.json36 processing activitiessha256: 8201…87b1
DORA_DRAFT.json15 tables · in scopesha256: e18e…d764
change-log.json4 log entriessha256: be54…f8cd
sources.json10 sources · 10 reachablesha256: a219…a1e8

Settings

Help ▾ → Settings. Six sections down the side — Mode · Connections · DORA scope · Keep it current · Moving machines · About this install. The one that changes what Regixo is is Mode: two cards, not a radio — Full compliance toolData catalog only — each listing exactly what it turns on and off, with the current one marked. Moving to another machine is the numbered recipe for taking the install with you — “your install is four things; only the map rebuilds itself” — which pieces travel in git, and which one (your credentials) you carry by hand, every time.

what you'll see — Settings: the two mode cards (full compliance tool ⇄ data catalog only)
Regixo data catalog · free & local

Settings

Mode

✓ Current

Full compliance tool

For EU teams that need the GDPR paperwork done.

  • The data catalog — map, search, owners, lineage
  • The GDPR Record (RoPA), drafted for you
  • The compliance hand-off & official sign-off
  • Personal data labelled with its legal basis (Art. 9/10)
● You’re using this

Data catalog only

For teams that just want to map their data.

  • The data catalog — map, search, owners, lineage
  • Personal data still flagged — shown as plain “sensitive”
  • The Record (RoPA) tab — hidden
  • Compliance hand-off, DORA & sign-off — hidden

The other four sections: Connections — a read-only inventory of every source, whether it was reachable at the last scan, what env var it reads (the name only, never the secret), and its regixo test / regixo sources remove commands; DORA scope — on/off; Keep it current — Regixo has no built-in scheduler, so it shows per-source last-scanned ages and a copy-ready GitHub Actions snippet (plus a cron fallback) to run regixo watch yourself; and About this install. The toggles write the same regixo.yml fields as regixo config.

Commands

Help ▾ → Commands. The click-to-copy map of every regixo command. It opens with “Run Regixo by talking to your coding agent.” — because in practice most engineers now run Regixo by saying what they want, and their agent runs the same command in the same project shell. So every action here is one command shown two ways: the sentence you say (say) and the terminal command (run). One switch at the top — Show: Sentence | Command — sets which one leads, and it remembers your choice across pages. Neither is hidden: the other is always one click away, and both are copyable.

Three commands deliberately have no sentence at allregixo annotate set, regixo verify and regixo dora export. Confirming a legal field, signing a record and sealing the official register are a person’s acts, so the panel shows the command alone and says: “This one’s yours.”

what you'll see — Commands: one action shown two ways (say / run), and one only a person may run
Regixo data catalog · free & local
Show

Commands

Scan your databases, build the map, and draft the paperwork. Run this first, and again whenever you want a fresh scan. One source failed? regixo start --source <id> re-scans just that one.

say

“Set Regixo up in this project — scan my sources and build the data map.”

Show the commandHide the commandShow the sentenceHide the sentence
run

With a licence key, makes the record official — removes the DRAFT stamp and seals it under your compliance lead’s signature. The free draft never needs this.

run

This one’s yours. Only a person can sign a record.

Guide

Help ▾ → Guide. A short action plan — “What to do in Regixo” — that links each step to the screen or command that does it: the goal (get your first record to your compliance team), the labels you’ll meet (found · suggested · needs you), what happens after you send it, and what stays on your computer.

What the free portal can’t do (by design)
  • Scan or connect a source — no secret entry, no scan-from-server. Those are regixo start and regixo add.
  • Run regixo watch — it shows you how to schedule it.
  • Fill or confirm the RoPA legal fields — that is the compliance portal, or regixo annotate.
  • Take payment — paying, signing and the sealed export happen in the compliance portal, and some of that is not switched on yet.
What works there today is stated in The compliance portal →
REGIXO — documentation · the free portal runs on your machine, no login · Command reference