View the Sign-In Log
Use the Log tab on the Access settings page to audit sign-in activity and provider configuration changes: who signed in (or was denied), which provider was involved, and what an administrator changed.
Permissions
Only users with the Admin role can view the sign-in log. See the Permissions page for details.
What the Log Shows
Each event row shows:
| Column | Description |
|---|---|
| Timestamp | When the event happened. |
| Event | The event type, such as Successful Sign-in, Account Locked, Invitation Sent, Account Linking Pending Approval, or SSO Verification Failed. |
| User | The user involved, when the event relates to an account. |
| Provider | The type of sign-in provider involved (OpenID Connect, SAML 2.0, or Email & Password). |
| IP Address | Where the request came from. |
| Outcome | Success or Failure. |

The log covers, among others:
- Sign-in activity: successful and failed sign-ins, account lockouts, and password resets.
- Denied sign-ins with the reason: an email domain not authorized for the provider, a group restriction, a missing email from the identity provider, or a deactivated account.
- Provider configuration changes: provider created, updated, or deleted, with the changed properties. Secrets are never shown.
- Identity linking: link requests created, approved, and rejected.
- Invitations: invitations sent and accepted.
Filtering and Sorting
- Filter by Report Date and Timeframe to focus on a period.
- Use the filter menu to narrow the log by Event type or Provider type.
- Sort events by timestamp, event type, or outcome.

Info
The Log tab covers authentication and sign-in configuration. For the platform-wide activity log of datastores, checks, and other assets, see the Platform Audit documentation.