The Security Log is where administrators review staff sign-in activity for your organization — successful logins, failed logins, logouts, and blocked IP addresses.
Open Settings, then go to Security and choose Security Log.
Each row includes:
• Time — when the event happened
• Event — the kind of event (Login success, Login failure, IP denied, or Logout)
• User — the person involved, when known
• IP Address — the network address used for the attempt
• Source — where CoolFocus recorded the event from
• Details — extra context, such as an invalid password or an address that is not on the approved list
You cannot add or edit log entries here. The log is a read-only history.
• Login success — the person signed in and was allowed into CoolFocus
• Login failure — sign-in did not complete (for example, wrong password)
• IP denied — the person was blocked because their IP address is not on your approved list
• Logout — the person signed out
A Login success is only recorded after the sign-in has passed your organization's IP address checks.
If IP Address Access blocks someone, you will see an IP denied event instead of Login success — even if they entered the correct password with your identity provider. That keeps the log from showing a successful sign-in for someone who was not actually allowed in.
• Use the Event type filter to show one kind of event, or all events
• Use the from and to date fields to limit the list to a date range
• Use the search box to find matching text in the log
Changing a filter refreshes the list to match.
When someone is blocked by IP restrictions, an IP denied row can show an Approve IP button.
• Choose Approve IP to add that address to your approved IP list so they can try again
• Approval from this page is only available for a short time after the blocked attempt (about 30 minutes)
• If the button is unavailable, ask the person to try signing in again so a fresh row appears, or add the address yourself under Settings → Security → IP Addresses
For more on approved locations, see IP Address Access.
Use the Security Log when you are:
• Investigating a reported sign-in problem
• Confirming that IP restrictions are blocking or allowing access as expected
• Reviewing recent sign-in activity for your organization
The Security Log covers sign-in, logout, and IP denial history only.
If you need one timeline that also includes clinical record access and field-level record changes for a person, use User Logs instead.
• User Logs
• IP Address Access
• Security Settings at a Glance
• Users