The Security Log is where administrators review staff sign-in activity for your organization — successful logins, failed logins, logouts, and blocked IP addresses.
Open Settings, then go to Security and choose Security Log.
Each row includes:
Time — when the event happened
Event — the kind of event (Login success, Login failure, IP denied, or Logout)
User — the person involved, when known
IP Address — the network address used for the attempt
Source — where CoolFocus recorded the event from
Details — extra context, such as an invalid password or an address that is not on the approved list
You cannot add or edit log entries here. The log is a read-only history.
Login success — the person signed in and was allowed into CoolFocus
Login failure — sign-in did not complete (for example, wrong password)
IP denied — the person was blocked because their IP address is not on your approved list
Logout — the person signed out
A Login success is only recorded after the sign-in has passed your organization's IP address checks.
If IP Address Access blocks someone, you will see an IP denied event instead of Login success — even if they entered the correct password with your identity provider. That keeps the log from showing a successful sign-in for someone who was not actually allowed in.
Use the Event type filter to show one kind of event, or all events
Use the from and to date fields to limit the list to a date range
Use the search box to find matching text in the log
Changing a filter refreshes the list to match.
When someone is blocked by IP restrictions, an IP denied row can show an Approve IP button.
Choose Approve IP to add that address to your approved IP list so they can try again
Approval from this page is only available for a short time after the blocked attempt (about 30 minutes)
If the button is unavailable, ask the person to try signing in again so a fresh row appears, or add the address yourself under Settings → Security → IP Addresses
For more on approved locations, see IP Address Access.
Use the Security Log when you are:
Investigating a reported sign-in problem
Confirming that IP restrictions are blocking or allowing access as expected
Reviewing recent sign-in activity for your organization
The Security Log covers sign-in, logout, and IP denial history only.
If you need one timeline that also includes clinical record access and field-level record changes for a person, use User Logs instead.