DHIS2 Audit Vision App

DHIS2 Audit Vision

2026 DHIS2 App Competition Finalist

DHIS2 Audit Vision is a powerful, open-source governance and monitoring application designed to give DHIS2 administrators and programme managers complete traceability over every metadata change in their instance in real time.

It serves as the operational oversight layer between a live DHIS2 instance and the teams responsible for its integrity, providing a clear, user-friendly interface to track who changed what, when, and what the impact of that change was.

Audit Vision brings together six integrated modules - Dashboard, Change Explorer, User Audit, Metadata Grouping, Severity Rules, and Rollback - into a single, cohesive platform that transforms how organisations govern their DHIS2 configurations.

By making metadata changes visible, auditable, and reversible, DHIS2 Audit Vision promotes accountability, reduces the risk of silent configuration errors, and enables faster, more confident management of DHIS2 instances at any scale.


Motivation

In any active DHIS2 instance, metadata is constantly evolving. Data elements are modified, organisation units are restructured, indicators are reconfigured, and programmes are updated - often by multiple users simultaneously, under operational pressure, and without a formal change management process.

Yet data cannot be correctly interpreted without knowing the exact metadata configuration under which it was collected. A single untracked change to a data element or indicator formula can silently invalidate months of reported data.

Despite this, most DHIS2 implementations lack a dedicated mechanism to answer the most fundamental governance questions:

  • Who made this change - and when exactly did it happen?

  • What was the configuration before this change?

  • How do we recover safely if something goes wrong?

  • Which users are most active and what is their impact on the system?

  • How do we get notified immediately when a critical change occurs?

DHIS2 Audit Vision was built to answer all of these questions.

Drawing from our experience working across multiple DHIS2 implementations in health, education, and logistics contexts, we identified a critical and unaddressed gap in the ecosystem: the absence of an operational governance layer for production instances - one that works continuously, alerts in real time, and gives administrators the ability to act immediately when something changes unexpectedly.


Architecture

DHIS2 Audit Vision is composed of two complementary components that work together seamlessly:

DHIS2 App - installed inside your instance A native DHIS2 application installed directly on your DHIS2 instance via the App Hub. This component reads the DHIS2 audit log, exposes the governance interface to administrators, and handles all communication with the DHIS2 API. It requires no external infrastructure and respects the instance’s existing authentication and permission model.

External Service - configurable from within Audit Vision A lightweight service that runs outside the DHIS2 instance and is responsible for dispatching automatic alerts via Email when severity rules are triggered. This component is fully configurable directly from the Audit Vision interface - administrators define rules, manage contacts, and customize message templates without ever leaving the application.


Features

DHIS2 Audit Vision comes equipped with a comprehensive set of features designed to make metadata governance practical, immediate, and impactful.

Real-Time Dashboard A consolidated command centre that gives administrators an instant overview of the instance’s governance status - total changes today, cumulative activity, high-risk events requiring review, and trends over time. Interactive charts show change distribution by action type (CREATE, UPDATE, DELETE) and rank the most active users, making it immediately clear where attention is needed.

Change Explorer The forensic heart of Audit Vision. A powerful search and filter engine over the complete metadata audit log, allowing administrators to find any change by object name, user, action type, metadata type, or date range. Each record opens a detailed side panel with a visual before-and-after diff highlighting exactly what changed field by field, a dependency tree of affected objects, and the raw JSON payload for technical inspection. Results can be exported as CSV or JSON.

Rollback - Undo Any Change Safely Audit Vision allows authorised administrators to reverse any metadata change recorded in the audit log through a structured, five-step process: select the change, preview the full diff, confirm via a mandatory dialog, execute the reversal. Every rollback is itself recorded as a new audit entry, creating a complete chain of custody. Only users with Administrator or Senior Auditor roles can execute rollbacks, ensuring that the power to undo is itself governed.

User Audit Real-time monitoring of all user activity across the instance. Individual profile cards show total changes made by each user. Clicking any user opens their complete chronological action history, filterable by type and date - enabling administrators to identify patterns, detect unusual behaviour, and understand the individual impact of each team member on the system.

Metadata Grouping Logical grouping of DHIS2 objects - programmes, datasets, data elements - into named collections that can be monitored as a unit. A programme manager responsible for HIV or Malaria surveillance can focus exclusively on changes affecting their objects, without needing access to the full system-wide audit log. Groups are available as filters across the Change Explorer and Dashboard.

Severity Rules & Automatic Alerts A configurable alert engine that detects and escalates critical events automatically. Administrators define rules based on action type and object type - for example, any DELETE on an organisationUnit triggers a HIGH severity alert - and configure notification contacts via Email. Alerts are dispatched from the moment the triggering event is detected. Message templates support dynamic tags ({object_name}, {action_type}, {user}, {timestamp}, {severity}) for rich, contextual notifications. All configuration is managed directly from within the Audit Vision interface.


Try It Out

Explore our live demo instance to experience firsthand how Audit Vision monitors and governs metadata changes in a real environment.

Our documentation provides a straightforward, step-by-step guide to get you up and running.

DHIS2 Audit Vision is fully open-source and welcomes contributions from the DHIS2 developer community. Whether you want to add new audit modules, extend the alert engine, or adapt the platform to specific implementation contexts, we encourage you to get involved.

Vote for DHIS2 Audit Vision in the 2026 DHIS2 App Competition here:

Thanks,
Edson Nhancale
HISP MOZAMBIQUE

This fills a real gap, having full traceability over metadata changes with rollback and real-time alerts is exactly what production DHIS2 instances need. Great work, Edson and the HISP Mozambique team!

Kudos to Mozambique team @EdsonNhancale very impressive

I will definitely explore this for the numerous DHIS2 instances that I am managing. Kudos to the team for this great work.

Great work there @EdsonNhancale! Kudos to you and the HISP Mozambique team :clap:

Hey! One question please, does this sort of solve the issue that’s been requested here: Jira ? I think @WaluQ , @Tangy , @elmoujarrade , and @plinnegan have all discussed and requested to solve the issue addressed in the ticket.

If it does, great job listening to the community! I’m wondering if this helps after an upgrade as well? because if it does then - winner or not :sweat_smile:, you will save us a lot of debugging! For example, sometimes people upgrade their instance and then they don’t know exactly what changed or which metadata is missing…etc

Thanks!

This sounds great