Activity Log
Read the Activity Log audit trail: header counts, quick filters, actor and category dropdowns, search, and time-grouped entries with before/after detail.
What the Activity Log is for
The Activity Log is your platform-wide audit trail. Every recorded action — staff logins, billing changes, service operations, ticket activity, settings edits and more — appears here with the person who performed it, the record it affected, and a summary of what changed. Use it for compliance, dispute resolution, and spotting unusual behavior.

How to open it
The Activity Log is reached from the top header bar of the admin panel. Look for the clipboard/list icon next to the Settings gear; hovering it shows the tooltip Activity Log. Click it to open the page. On narrow screens the same item lives under the header's More (three-dots) menu instead. The page is available to staff with settings-level access, and it loads the most recent activity first.
Reading the page
The page has four parts, top to bottom: the header counters, a row of quick-filter pills, the search and filter bar, and the date-grouped activity feed.
Header counters
Four inline stats sit in the top-right of the page header, each with its own icon:
- today — number of recorded actions so far today.
- this week — number of recorded actions over the last seven days.
- admin — count of actions performed by staff in the last 30 days.
- client — count of actions performed by customers in the last 30 days.
Quick-filter pills
Below the header, a Quick filters: row shows pill buttons for the most frequent action types over the last 30 days, each with a count in parentheses — for example Logged in (7) or Updated settings (3). Click a pill to filter the feed to just that action; the pill highlights to show it is active. Click it again to clear it.
Searching and filtering
The filter bar gives you a search box plus three dropdowns. They combine, so you can narrow the feed by several criteria at once.
- Search — type in the box to match by actor name, actor email, or action. Results update shortly after you stop typing.
- All Actors — restrict the feed to Admin (staff) actions or Client (customer) actions.
- All Categories — pick a topic such as Billing & Payments or Services. Choosing a category also limits the next dropdown to actions within it.
- All Actions — pick one specific action type. When no category is selected this lists every tracked action; when a category is selected it lists only that category's actions.
Whenever any filter or search is active, a Clear button appears at the end of the bar. Click it to reset every control and return to the full feed.
Filter reference
| Control | What it does |
|---|---|
| Search box | Matches actor name, actor email, or action across all entries. |
| All Actors | All actors, or only Admin (staff) or Client (customer) actions. |
| All Categories | Authentication, User Management, Services, Orders, Billing & Payments, Tickets, Settings, Account & Team, or Resellers. |
| All Actions | A single action type. Filtered to the chosen category when one is set. |
| Clear | Resets search and all dropdowns (shown only when a filter is active). |
The activity feed
Entries are grouped under date headings: Today, Yesterday, a weekday name for earlier days this week, and a full date for older entries.
Each entry row shows:
- A colored action icon and a plain-language label — for example Logged in, Invoice paid, Suspended service.
- An Admin badge when the action was performed by staff.
- A View link (with an eye icon) when the entry is tied to a record you can open directly, such as a client, service, order, invoice, or ticket.
- A short summary line drawn from the action's details (such as an invoice number, an email, or a status), shown when the row is collapsed.
- The actor: name plus email. The name links to the matching account record. Automated actions with no actor show as System.
- A relative time on the right (for example 5m ago, 2h ago). Hover it to see the exact date and time.
Expanding an entry
Click any row that has a chevron on the right to expand it. The expanded panel lists the fields that changed. Where a value was modified, it is shown as a before → after pair — the old value struck through, the new value in bold. When more than one field changed, a small fields changed note appears at the top. Sensitive values are never revealed; they display as ••• changed instead. If the action recorded one, the actor's IP address appears at the bottom of the panel. Click the row again to collapse it.
Common tasks
- Audit one staff member or customer — set All Actors to Admin or Client, then type their name or email in the search box.
- Focus on a topic — choose a category in All Categories (for example Billing & Payments), then optionally pick a specific action in the All Actions dropdown.
- Jump to the affected record — click the View link on any row that has one to open the related client, service, order, invoice, or ticket.
- Investigate a change — expand the row and read the before/after detail, then note the IP address if shown.
What gets tracked
The log captures actions across all major areas of the platform. The categories you can filter by are:
| Category | Examples |
|---|---|
| Authentication | Logged in, logged out, registered, password reset requested or completed, 2FA enabled or disabled. |
| User Management | User created, updated, deleted, suspended, activated, terminated, password reset, currency changed. |
| Services | Service created, updated, suspended, unsuspended, terminated, cancellation scheduled, and power actions (reboot, shut down, power on). |
| Orders | Order created, approved, completed, cancelled, or updated. |
| Billing & Payments | Invoices created, paid, cancelled, status changed or deleted; payments initiated, completed, captured, refunded, confirmed or failed; credit adjustments and manual payments. |
| Tickets | Ticket created, replied, closed, reopened, assigned, priority or status changed. |
| Settings | Settings updated. |
| Account & Team | Account settings updated; team members invited, updated, removed or left; invitations accepted or revoked. |
| Resellers | Reseller created, approved, suspended, or reactivated. |
Tips and notes
The feed loads up to 50 entries per page. When there is more, page controls appear at the bottom showing the range and total (for example 1–50 of 312). Use search and filters to narrow large volumes before paging through them.
Automated, system-initiated actions (such as scheduled billing runs) appear with System in place of an actor name, so you can tell apart actions taken by a person from those run by the platform.
Sensitive field changes are masked as ••• changed and never display the underlying value, so the log is safe to review without exposing secrets.
