The Activity Log is an audit trail of who did what inside the POS - logins, employee record changes, permission edits, and password resets. Use it when something looks off and you need to find out who touched it.

Go to Employees > Activity Log.

The page shows a chronological list of recorded events, newest first. Each row has the date and time, the user who took the action, what they did, a short detail string, and the IP address they were on at the time.

Filters across the top

  • User: any specific employee or "All Users"
  • Action: a specific action type (login, password change, permission update, etc.) or "All Actions"
  • Date From / Date To: narrow to a window

Click "Filter" to apply, or "Clear" to reset. Results paginate 50 rows at a time.

Action types currently recorded

  • Login / Logout
  • Created Employee
  • Updated Employee
  • Changed Employee Status (active, inactive, locked)
  • Updated Permissions
  • Changed Password
  • Reset Password

Use this report to

  • Investigate "who changed this employee's role?" type questions
  • Confirm a staff member signed in (or didn't) on a specific day
  • Track password resets across the team
  • Spot unusual IP addresses on a sensitive account

Activity Log vs Security Audit: this log focuses on user-account and permission events. For broader security events (logins, PIN swaps, idle session timeouts, fast-switch terminal activity), go to Settings > Security and click "Open audit log". The two logs do not overlap on events; for a full picture of an incident, check both. Refund-override events are not captured in either log today.