User Activity Tracking

GSK POS Documentation | User Management
Last Updated: November 23, 2025 | Applies to: GSK POS Cloud System (gskpos.com) | Status: ✅ Code Verified | Chapter: Security & Access Control

Overview

User Activity Tracking (also called Activity Logging or Audit Trail) automatically records every action taken in GSK POS. This system provides accountability, security monitoring, and investigation capabilities.

What you'll learn:

  • What is tracked and why
  • How to use activity logs
  • Investigation and troubleshooting
  • Compliance and audit requirements

What Is Activity Tracking?

Definition: The system automatically logs every user action with complete details.

Every action records:

  • Who: Which user (username)
  • What: What action they performed
  • When: Date and time (timestamp)
  • Where: IP address and device
  • How: Browser/device information
  • Data: What data was involved (GET/POST parameters)

Automatic Logging:

  • No user action required
  • Cannot be disabled
  • Cannot be edited after creation
  • Permanent record
  • Secured database storage

Why Activity Tracking Matters

**Security & Fraud Prevention**

Detect Suspicious Activity:

  • Unauthorized access attempts
  • After-hours activity
  • Unusual deletion patterns
  • Data exports

Investigation:

  • Who deleted that sale?
  • Who changed the price?
  • Who accessed customer data?
  • When was account compromised?

**Accountability**

Clear Responsibility:

  • Every action traceable to person
  • No "someone did it" - know exactly who
  • Discourages misbehavior
  • Enables fair discipline

Performance Tracking:

  • Monitor productivity
  • Track sales per employee
  • Identify training needs

**Compliance & Audit**

Regulatory Requirements:

  • Many industries require audit trails
  • Financial regulations demand logging
  • Data protection laws require tracking
  • Tax authorities may request logs

Audit Support:

  • Provide auditors complete trail
  • Demonstrate internal controls
  • Prove who-did-what-when
  • Meet legal requirements

**Error Recovery**

Troubleshooting:

  • When did problem start?
  • What changed before issue?
  • Who was working at the time?
  • Sequence of events

Data Recovery:

  • See deleted data details
  • Understand what was changed
  • Reconstruct transactions
  • Identify mistakes

What Gets Tracked

**User Actions**

Account Operations:

  • User login (successful and failed)
  • User logout
  • Password changes
  • Account creation/editing/deletion

Sales Operations:

  • Create sale
  • Process payment
  • Print receipt
  • Undo/delete sale
  • Issue refund
  • Credit sale

Purchase Operations:

  • Record purchase
  • Receive stock
  • Delete purchase
  • Edit purchase

Inventory Operations:

  • Add product
  • Edit product
  • Delete product
  • Adjust stock
  • Stock transfer

Data Access:

  • View reports
  • Export data
  • Search records
  • View sensitive information

Settings Changes:

  • Edit business profile
  • Change settings
  • Configure printing
  • System configuration

**Logged Information**

For Each Action:

User Info:

  • User ID
  • Username
  • Role

Action Info:

  • Action name (e.g., "Create Sales")
  • Timestamp (YYYY-MM-DD HH:MM:SS)
  • Success/failure status

Request Info:

  • IP address (device location)
  • User agent (browser/device type)
  • HTTP method (GET/POST)

Data Involved:

  • GET parameters (URL data)
  • POST parameters (form data)
  • Business ID (which business)
  • Relevant record IDs

Example Log Entry:

`

User: john (ID: 45, Role: Cashier)

Action: Create Sales

Time: 2024-11-23 14:35:22

IP: 192.168.1.105

Device: Chrome on Windows

Data: Customer ID: 12, Amount: 150000, Items: [...]

Business ID: gsk_kampala_001

Status: Success

`

How to Access Activity Logs

**Who Can Access?**

Admins: Full access to all activity logs

Managers: May have access depending on permissions

Regular Users: Usually cannot access logs

**Accessing Logs**

Method 1: Activity Log Report

  1. Go to Reports menu
  2. Select Activity Log
  3. Choose filters:
    • Date range
    • Specific user
    • Action type
    • View results

Method 2: Database Query (Technical)

  • Requires database access
  • Admin/IT only
  • Direct SQL queries
  • Most complete data

Using Activity Logs

**Common Use Cases**

Case 1: Investigation - Missing Sale

Scenario: Customer claims they paid but transaction not in system

Investigation Steps:

  1. Get transaction details (date, time, amount)
  2. Access activity log
  3. Filter by date/time
  4. Search for amount
  5. Find relevant entries
  6. Check if sale was created then deleted
  7. Identify who deleted (if deleted)
  8. Review reason

Result: Either find the sale, or prove it never existed, or identify who removed it.

Case 2: Security - Unauthorized Access

Scenario: Suspicious activity detected

Investigation Steps:

  1. Review recent activity logs
  2. Look for:
    • After-hours logins
    • Failed login attempts
    • Unusual IP addresses
    • Data exports
    • Identify suspicious user/IP
    • Review all actions by that user
    • Take action (reset password, disable account)

Case 3: Compliance - Audit Request

Scenario: Auditor requests transaction trail

Response Steps:

  1. Export activity logs for audit period
  2. Filter by relevant actions (sales, purchases, etc.)
  3. Generate report
  4. Include:
    • All transactions
    • User details
    • Timestamps
    • Data changed
    • Provide to auditor

**Reading Activity Logs**

Important Columns:

Timestamp:

  • When action occurred
  • Look for patterns (time of day, day of week)
  • Sequence of events

User:

  • Who performed action
  • Check if appropriate person
  • Multiple users same IP? (shared computer)

Action:

  • What they did
  • Is it appropriate for their role?
  • Frequency/patterns

IP Address:

  • Where they were
  • Same IP always? (office computer)
  • Different IP? (mobile/home)
  • Foreign IP? (suspicious)

Data:

  • What was involved
  • Changes made
  • Amounts/quantities

Red Flags to Watch For

**Security Red Flags**

  • 🚩 Multiple Failed Logins
  • Someone guessing password
  • Account under attack
  • Action: Reset password, investigate
  • 🚩 After-Hours Activity
  • Logins at 2 AM
  • Nobody should be working
  • Action: Verify with user, investigate
  • 🚩 Unusual IP Address
  • Login from different country
  • Unfamiliar location
  • Action: Disable account, contact user

�� Excessive Data Exports

  • Downloading lots of reports
  • Possible data theft
  • Action: Investigate, limit access

**Fraud Red Flags**

  • 🚩 Pattern: Create → Delete Sales
  • User creates sale
  • Takes cash from customer
  • Deletes sale (pockets money)
  • Action: Review all their deletions, check cash drawer
  • 🚩 Stock Adjustments After Hours
  • Adjusting stock when nobody around
  • Could be hiding theft
  • Action: Physical count, investigate
  • 🚩 Excessive Permissions Granted
  • User giving themselves more access
  • Escalating privileges
  • Action: Review permission changes, revoke unauthorized
  • 🚩 Failed Permission Checks
  • Repeatedly trying unauthorized actions
  • Testing security
  • Action: Monitor closely, restrict if needed

Retention & Compliance

**How Long Logs Are Kept**

Standard Retention:

  • Activity logs stored indefinitely
  • Database space permitting
  • Oldest logs may be archived

Legal Requirements:

  • Check local regulations
  • Some industries require 7 years
  • Tax records often 7 years
  • Medical records often longer

Best Practice:

  • Keep at least 1 year online
  • Archive older logs
  • Never delete completely
  • Regular backups

**Compliance Considerations**

Data Protection:

  • Activity logs contain personal data
  • Subject to GDPR/privacy laws
  • Protect from unauthorized access
  • Don't share inappropriately

Audit Requirements:

  • Must be tamper-proof
  • Complete (no gaps)
  • Accurately timestamped
  • Include all relevant details

Legal Discovery:

  • May be subpoenaed in lawsuits
  • Must be producible
  • Consider legal hold requirements

Best Practices

**Regular Monitoring**

Daily Quick Check (5 minutes):

  • Review yesterday's failed logins
  • Check for after-hours activity
  • Scan for unusual actions

Weekly Review (30 minutes):

  • Review deleted transactions
  • Check permission changes
  • Monitor data exports
  • Identify patterns

Monthly Audit (2 hours):

  • Comprehensive review
  • Generate summary reports
  • Document findings
  • Take corrective actions
  • Update security policies

**Documentation**

Keep Records Of:

  • Unusual activity
  • Investigations conducted
  • Actions taken
  • Policy changes
  • Training provided

Incident Reports:

  • What happened
  • When discovered
  • Who investigated
  • Findings
  • Actions taken
  • Preventive measures

**Security Policies**

Implement:

  • Acceptable use policy
  • Password policy
  • Access control policy
  • Incident response plan
  • Regular security training

Communicate:

  • Tell users activity is logged
  • Explain why (accountability, not mistrust)
  • Make policies clear
  • Train on security

**Technical Measures**

Protect Logs:

  • Secure database access
  • Regular backups
  • Off-site storage
  • Encryption at rest
  • Restricted query access

Alerting:

  • Automated alerts for critical events
  • Failed login threshold
  • After-hours access
  • Large data exports
  • Permission escalation

Troubleshooting

**Cannot Find Activity**

Missing in logs:

  • Action may not be logged (some actions excluded)
  • Date filter too narrow
  • User filter wrong
  • Database issue

Solution:

  • Expand search criteria
  • Check spelling of username
  • Try broader date range
  • Contact technical support

**Too Many Results**

Log overwhelming:

  • Too much data to review
  • Need specific information

Solution:

  • Use more specific filters
  • Filter by action type
  • Filter by specific user
  • Export and use spreadsheet

**Suspicious Activity Found**

What to do:

  1. Don't panic
  2. Document what you found
  3. Gather all related logs
  4. Don't confront user yet
  5. Consult with management
  6. Follow incident response plan
  7. Consider legal/HR implications
  8. Take measured action

Summary

Activity Tracking provides:

  • ✅ Security - Detect and investigate threats
  • ✅ Accountability - Clear responsibility for actions
  • ✅ Compliance - Meet regulatory requirements
  • ✅ Troubleshooting - Understand what happened

Key Points:

  • Every action is automatically logged
  • Logs are permanent and cannot be edited
  • Regular monitoring prevents problems
  • Essential for security and compliance

Remember:

  • Activity logs protect everyone
  • Transparency builds trust
  • Regular review prevents issues
  • Proper use is ethical and legal

Chapter 4 Complete!

Congratulations! You've completed the User Management chapter.

You now know how to:

  • ✅ Create and manage user accounts
  • ✅ Understand roles and permissions
  • ✅ Change passwords securely
  • ✅ Track user activity for security and accountability

Next Steps:

  • Practice creating test users
  • Review your current user list
  • Audit permissions
  • Monitor activity logs
  • Document your security policies

What's Next?

Explore other GSK POS features:

  • Chapter 5: Settings & Configuration - Customize your system
  • Chapter 6: Advanced Features - Multi-branch, integrations, and more

Return to: [Documentation Home →](../index.html)

Next: Documentation Home

Continue your learning journey.

Next: Documentation Home →

Next: Permissions System

Learn how access control and permissions work in GSK POS.

Next: Permissions System →

Next: Sales & Purchase Reports

Learn how to generate detailed and summary reports for all your sales and purchase transactions.

Next: Sales & Purchase Reports →

Next: Purchases & Stock In

Learn how to record purchases from suppliers and increase your stock levels.

Next: Purchases & Stock In →