Administration

Policy activity

Every access change, with who and when.

The Activity tab keeps a running timeline of the access events that matter across your organisation — who signed in, which security setting changed, and where a request was turned away. It draws on the same history as the audit trail, narrowed to the security side of the story, so you can watch the shape of access from the same place you manage roles and sharing.

The activity feed

You reach the feed from the Activity tab in the Policy workspace, alongside Roles, Access, and Explorer. Each line is one activity: an icon for the kind of event, a short summary of what happened, the person behind it, and how long ago. Related lines gather under a day heading — Today at the top, then earlier days as you scroll back.

The Policy workspace on the Activity tab, showing a timeline of sign-in activity grouped under a Today heading, with User and Date range filters and a refresh control above the feed.The Policy workspace on the Activity tab, showing a timeline of sign-in activity grouped under a Today heading, with User and Date range filters and a refresh control above the feed.

Two controls sit above the feed. Use User to narrow the timeline to a single person, and Date range to bound it to a window — a single day, a week, the run-up to an incident. Refresh pulls the latest activity on demand, and the feed also keeps itself up to date while you have the tab open, extending as you scroll toward the end.

Select any line to open its full detail beside the feed: the underlying events, the exact time, and how the action was carried out. The address in your browser updates to point at that item, so you can copy the link and send a colleague straight to the same activity.

What gets recorded

The feed carries the access side of your organisation's history, in three kinds of activity:

  • Sign-ins. Each attempt to sign in to Pyron, whether it succeeded or was refused, with the method the person used.
  • Security changes. Changes to sign-in and security settings — a reset MFA method, an updated credential, an adjusted enforcement rule.
  • Refused access. Attempts to do something a person's roles do not permit. These carry an amber marker, so a burst of them stands out as possible probing or a mis-scoped role.

This is the security slice of a wider picture. The Activity tab is fixed to these three kinds on the server, so it shows access and security events and nothing broader — a role's members, a directory share, or an edited form each live on their own screen. For the complete history, including data changes and configuration, open the audit trail.

You see the Activity tab when your roles let you manage policy. Someone without that permission reaches neither the tab nor its underlying feed.

Related

Need a hand? support@techly.au

Pyron Documentation