The Activity Log is an audit trail of who did what inside the POS - logins, employee record changes, permission edits, and password resets. Use it when something looks off and you need to find out who touched it.
Go to Employees > Activity Log.
The page shows a chronological list of recorded events, newest first. Each row has the date and time, the user who took the action, what they did, a short detail string, and the IP address they were on at the time.
Filters across the top
- User: any specific employee or "All Users"
- Action: a specific action type (login, password change, permission update, etc.) or "All Actions"
- Date From / Date To: narrow to a window
Click "Filter" to apply, or "Clear" to reset. Results paginate 50 rows at a time.
Action types currently recorded
- Login / Logout
- Created Employee
- Updated Employee
- Changed Employee Status (active, inactive, locked)
- Updated Permissions
- Changed Password
- Reset Password
Use this report to
- Investigate "who changed this employee's role?" type questions
- Confirm a staff member signed in (or didn't) on a specific day
- Track password resets across the team
- Spot unusual IP addresses on a sensitive account
Activity Log vs Security Audit: this log focuses on user-account and permission events. For broader security events (logins, PIN swaps, idle session timeouts, fast-switch terminal activity), go to Settings > Security and click "Open audit log". The two logs do not overlap on events; for a full picture of an incident, check both. Refund-override events are not captured in either log today.