WayCool
WayCool
Docs
  • Docs
  • Changelog
  • Feature requests
  • Support portal
    • Administration Overview
    • Security Settings at a Glance
    • Users
    • Invitations
    • IP Address Access
    • Security Log
    • User Logs
    • User Groups: What Staff Can Open and Change
    • Data Access Rules: Limit Which Records Staff Can See
    • Managing Dropdown List Values
    • Troubleshooting: A module icon is missing from the sidebar
    • Plan & Billing Settings
    • Legal & Compliance Settings

Security Log

Review staff sign-ins, failed logins, logouts, and blocked IP addresses under Settings → Security → Security Log.

The Security Log is where administrators review staff sign-in activity for your organization — successful logins, failed logins, logouts, and blocked IP addresses.

Where to find it

Open Settings, then go to Security and choose Security Log.

What you'll see

Each row includes:

  • Time — when the event happened

  • Event — the kind of event (Login success, Login failure, IP denied, or Logout)

  • User — the person involved, when known

  • IP Address — the network address used for the attempt

  • Source — where CoolFocus recorded the event from

  • Details — extra context, such as an invalid password or an address that is not on the approved list

You cannot add or edit log entries here. The log is a read-only history.

Event types

  • Login success — the person signed in and was allowed into CoolFocus

  • Login failure — sign-in did not complete (for example, wrong password)

  • IP denied — the person was blocked because their IP address is not on your approved list

  • Logout — the person signed out

When a sign-in counts as Login success

A Login success is only recorded after the sign-in has passed your organization's IP address checks.

If IP Address Access blocks someone, you will see an IP denied event instead of Login success — even if they entered the correct password with your identity provider. That keeps the log from showing a successful sign-in for someone who was not actually allowed in.

Filter and search

  • Use the Event type filter to show one kind of event, or all events

  • Use the from and to date fields to limit the list to a date range

  • Use the search box to find matching text in the log

Changing a filter refreshes the list to match.

Approve a blocked IP

When someone is blocked by IP restrictions, an IP denied row can show an Approve IP button.

  • Choose Approve IP to add that address to your approved IP list so they can try again

  • Approval from this page is only available for a short time after the blocked attempt (about 30 minutes)

  • If the button is unavailable, ask the person to try signing in again so a fresh row appears, or add the address yourself under Settings → Security → IP Addresses

For more on approved locations, see IP Address Access.

When this helps

Use the Security Log when you are:

  • Investigating a reported sign-in problem

  • Confirming that IP restrictions are blocking or allowing access as expected

  • Reviewing recent sign-in activity for your organization

Security Log vs User Logs

The Security Log covers sign-in, logout, and IP denial history only.

If you need one timeline that also includes clinical record access and field-level record changes for a person, use User Logs instead.

Related

  • User Logs

  • IP Address Access

  • Security Settings at a Glance

  • Users

PrevIP Address Access
NextUser Logs
Was this helpful?