Aller au contenu principal

Audit Logs

Track all changes and activities in your SSP Manager location with comprehensive audit logging. Audit logs provide a complete history of who did what and when, helping you maintain security, compliance, and accountability.

Overview​

Audit logs automatically record:

  • User actions and changes
  • System events
  • Data modifications
  • Access attempts
  • Configuration changes
  • Financial transactions

Key Benefits:

  • 🔍 Full visibility into system activity
  • 🔒 Enhanced security and fraud prevention
  • 📊 Compliance with regulatory requirements
  • 🐛 Troubleshooting and debugging
  • 👥 Staff accountability

Accessing Audit Logs​

Navigation: Locations → [Your Location] → Audit Logs

Required Permission: Manager or Owner role

What Gets Logged​

User Activities​

  • Login Events

    • Successful logins
    • Failed login attempts
    • Two-factor authentication events
    • Session timeouts
    • Logout events
  • User Management

    • User created
    • User updated
    • User deleted
    • Role changes
    • Permission modifications
    • User invitations sent
    • Invitation accepted/declined
  • Menu item created
  • Menu item updated (with before/after values)
  • Menu item deleted
  • Price changes
  • Menu category changes
  • Modifier changes
  • Item availability changes

Order Events​

  • Order created
  • Order modified
  • Order cancelled
  • Refund issued
  • Discount applied
  • Payment processed
  • Payment voided

Financial Events​

  • Cash drawer opened
  • Drawer counted
  • Bank deposit recorded
  • Payout initiated
  • Transaction voided
  • Tip adjusted

Configuration Changes​

  • Location settings updated
  • Operating hours changed
  • Tax rules modified
  • Printer settings changed
  • Integration connected/disconnected
  • Payment gateway configured

Table Management​

  • Table created/updated/deleted
  • Reservation made/modified/cancelled
  • Table assigned to server
  • Table status changed

Audit Log Interface​

Log Entry Details​

Each audit log entry contains:

Header Information:

  • Timestamp: Exact date and time of event
  • User: Who performed the action
  • Action Type: What was done
  • Status: Success, Failed, or Warning

Event Details:

  • Resource Type (e.g., Menu Item, User, Order)
  • Resource ID (unique identifier)
  • Before/After Values (for updates)
  • IP Address
  • Device Information
  • Session ID

Example Log Entry​

┌─────────────────────────────────────────────────────────────┐
│ 📝 Menu Item Updated │
├─────────────────────────────────────────────────────────────┤
│ Timestamp: Nov 8, 2025 2:45 PM PST │
│ User: john.smith@restaurant.com (Manager) │
│ Resource: Menu Item #1234 "Margherita Pizza" │
│ IP Address: 192.168.1.45 │
│ Device: Chrome on Windows │
├─────────────────────────────────────────────────────────────┤
│ Changes: │
│ Price: $12.99 → $13.99 │
│ Status: Active → Active │
│ Updated: Description text modified │
└─────────────────────────────────────────────────────────────┘

Filtering and Searching​

Filter Options​

By Date Range:

  • Today
  • Yesterday
  • Last 7 days
  • Last 30 days
  • Last 90 days
  • Custom range

By User:

  • Select specific user
  • Filter by role
  • Show system events

By Event Type:

  • Authentication events
  • Menu changes
  • Order events
  • User management
  • Configuration changes
  • Financial events
  • All events

By Resource:

  • Specific menu item
  • Specific user
  • Specific order
  • Specific table

By Status:

  • Success
  • Failed
  • Warning
  • All statuses

Search Functionality​

Search by:

  • Keyword in description
  • User email
  • Resource ID
  • IP address
  • Action type

Example Searches:

  • "refund" - Find all refund events
  • "john@" - Find all actions by John
  • "192.168.1" - Find events from specific IP range
  • "price" - Find all price changes

Common Use Cases​

1. Investigating Price Discrepancies​

Scenario: Customer complains about unexpected price change

Steps:

  1. Go to Audit Logs
  2. Filter by "Menu Changes"
  3. Search for the menu item name
  4. Review price change history
  5. Identify who made the change and when

2. Tracking Failed Login Attempts​

Scenario: Suspicious login activity detected

Steps:

  1. Filter by "Authentication Events"
  2. Select "Failed" status
  3. Review failed login attempts
  4. Check for unusual patterns (multiple failures, unknown IPs)
  5. Take appropriate security action

3. Compliance Audits​

Scenario: Need to provide audit trail for regulatory compliance

Steps:

  1. Set date range for audit period
  2. Filter by relevant event types
  3. Export logs to CSV
  4. Review and provide to auditors

4. Training and Accountability​

Scenario: Training new staff or reviewing performance

Steps:

  1. Filter by specific user
  2. Review their actions over time period
  3. Identify training needs or compliance issues
  4. Use as basis for coaching

5. Troubleshooting System Issues​

Scenario: Feature not working as expected

Steps:

  1. Set date range to when issue occurred
  2. Filter by relevant event type
  3. Review system events and errors
  4. Identify root cause
  5. Contact support with log details if needed

Exporting Audit Logs​

Export Options​

Formats Available:

  • CSV (Comma Separated Values)
  • PDF (Formatted report)
  • JSON (Machine-readable)

Export Process:

  1. Apply desired filters
  2. Click Export button
  3. Select format
  4. Choose date range (if not already filtered)
  5. Click Download

What's Included:

  • All visible log entries
  • All columns (timestamp, user, action, details)
  • Applied filters noted in export

Export Limits:

  • Maximum 10,000 entries per export
  • For larger datasets, use multiple date ranges
astuce

For regular compliance reporting, use the scheduled export feature to automatically email audit logs monthly or quarterly.

Retention Policy​

Standard Retention:

  • All audit logs retained for 90 days
  • After 90 days, logs are archived
  • Archived logs available on request

Extended Retention (Pro & Enterprise plans):

  • Retain logs for 1 year or 7 years
  • Configurable per location
  • Higher storage costs apply

Permanent Retention:

  • Critical financial events retained permanently
  • Order transactions
  • Refunds and voids
  • Payment processing

Security and Privacy​

Access Control​

Who Can View Audit Logs:

  • Organization owners: Full access to all locations
  • Location managers: Access to their location only
  • System administrators: Read-only access
  • Regular staff: No access

Audit Log Immutability:

  • Logs cannot be edited or deleted
  • Ensures integrity for compliance
  • Only system administrators can archive old logs

Data Privacy​

Personal Information:

  • User emails and names logged
  • IP addresses recorded
  • Device information captured

GDPR Compliance:

  • Right to data export (user can request their audit trail)
  • Data retention limits
  • Anonymization of archived logs after user deletion

PCI Compliance:

  • Payment card numbers never logged
  • Only last 4 digits and transaction IDs recorded
  • Compliant with PCI-DSS requirements

Automated Alerts​

Configurable Alerts​

Set up automatic notifications for specific events:

Security Alerts:

  • Multiple failed login attempts
  • User created or deleted
  • Permission changes
  • Access from new IP address or device

Financial Alerts:

  • Refund issued over $X amount
  • Large discount applied
  • Cash drawer variance
  • Void or comp threshold exceeded

Operational Alerts:

  • Menu price changed
  • Location settings modified
  • Integration disconnected
  • Printer offline

Setup:

  1. Go to Location Settings → Notifications
  2. Enable Audit Log Alerts
  3. Select alert types
  4. Choose notification method (email, SMS, in-app)
  5. Set threshold values

Advanced Features​

Batch Operations Tracking​

When bulk changes are made:

  • All individual changes logged separately
  • Batch operation ID links them together
  • Can filter to show only batch operations
  • Summary view of batch shows total changes

Example:

  • Bulk price update of 50 menu items
  • Shows as single "Batch Operation" entry
  • Expand to see all 50 individual changes

API Activity Logging​

For locations using SSP Manager API:

  • All API calls logged
  • Includes API key used
  • Request/response logged (sanitized)
  • Rate limiting events tracked

Integration Events​

For third-party integrations:

  • Data sync events
  • Integration errors
  • Configuration changes
  • Authentication events

Best Practices​

Regular Review​

Weekly:

  • Review failed login attempts
  • Check for unusual activity
  • Verify price changes are authorized

Monthly:

  • Export logs for backup
  • Review financial events
  • Audit user access and roles

Quarterly:

  • Compliance review
  • Update alert configurations
  • Archive old exports

Investigation Workflow​

  1. Identify the Issue

    • What happened?
    • When did it occur?
    • Who is affected?
  2. Filter Relevant Logs

    • Set appropriate date range
    • Select event type
    • Choose user if known
  3. Analyze Timeline

    • Review events in chronological order
    • Look for patterns
    • Identify related events
  4. Take Action

    • Correct the issue
    • Update processes/training if needed
    • Escalate if malicious activity suspected
  5. Document Findings

    • Export relevant logs
    • Note resolution
    • Update procedures if needed

Troubleshooting​

Logs Not Appearing​

Possible Causes:

  • Insufficient permissions (need Manager role)
  • Events occurred outside current filter range
  • Browser cache issue

Solutions:

  • Verify your role with location owner
  • Expand date range filter
  • Clear browser cache and refresh
  • Try "All Events" filter

Export Not Working​

Possible Causes:

  • Too many entries selected (>10,000)
  • Browser blocking download
  • Network issue

Solutions:

  • Narrow date range to reduce entries
  • Check browser pop-up settings
  • Try different export format
  • Check internet connection

Missing Event Details​

Possible Causes:

  • System event (no user action)
  • Automated process
  • API action

Solutions:

  • Check "User" field for "System" or "API"
  • Review integration logs if applicable
  • Contact support if unexpected

Compliance and Reporting​

Regulatory Compliance​

SOX Compliance:

  • Financial transaction logging
  • Segregation of duties tracking
  • Access control auditing

GDPR Compliance:

  • Personal data access logged
  • Consent tracking
  • Data export/deletion events

FDA (Food Service):

  • Food safety events
  • Temperature logging
  • Expiration tracking

Standard Reports​

Available Pre-Built Reports:

  1. User Activity Report

    • All actions by user
    • Time period summary
    • Most common actions
  2. Financial Changes Report

    • Price modifications
    • Discounts applied
    • Refunds and voids
  3. Security Events Report

    • Login history
    • Failed attempts
    • Role changes
  4. System Configuration Report

    • Settings changes
    • Integration events
    • Hardware configuration

Generate Report:

  1. Audit Logs → Reports tab
  2. Select report type
  3. Choose date range
  4. Click Generate
  5. Download PDF or CSV

FAQ​

How long are audit logs retained?​

Standard: 90 days. Pro/Enterprise: 1-7 years configurable. Financial events retained permanently.

Can audit logs be edited or deleted?​

No. Logs are immutable to ensure compliance and integrity.

Who can see audit logs?​

Only users with Manager or Owner roles. Regular staff cannot access audit logs.

Are API calls logged?​

Yes. All API activity is logged with request details and API key used.

Can I get alerts for specific events?​

Yes. Configure automated alerts in Location Settings → Notifications → Audit Alerts.

What if I need logs older than the retention period?​

Contact support. Archived logs can be retrieved for compliance or legal purposes.

Do audit logs impact system performance?​

No. Logging is asynchronous and does not affect operational performance.

Can I integrate audit logs with external systems?​

Yes (Enterprise plan). Use our API to stream audit logs to your SIEM or logging platform.

Getting Help​

Need assistance with audit logs?

  • 📧 Email: support@ssppos.com
  • 💬 Live Chat: Available in dashboard
  • 📚 Help Center: docs.ssppos.com

Maintain full visibility and accountability with SSP Manager Audit Logs.