Active sessions and the audit log
Seen the message about the concurrent user limit? Or want to know who cancelled an invoice yesterday? These two screens under Settings answer both.
How seats are counted
Your subscription sets the number of concurrent users, meaning people signed in at the same moment, not the number of accounts you created. Create as many accounts as you like; what counts is who is working now through the three doors: the web panel, the POS app and the manager app.
- A user who already has an active session signs in again without taking a new seat.
- A new user is refused only when the number of active users has reached the limit, with the message
CONCURRENT_SESSION_LIMIT_REACHED. - "Active" means they did something within the idle window set under Point of sale settings, then User lock grace. Anyone idle longer than that releases their seat automatically.
The Billing and subscription screen shows "X of Y in use" computed the same way. To add seats, see the pricing page.
The Active sessions screen
Under Settings, then Active sessions. A table with columns: user, type (web, cashier, manager), device, IP address and last activity. Users holding the Terminate permission on sessions see an End button on every row.
When do you need it?
- An employee left with the app open on their device and the seat is held by it. End their session so the replacement can sign in now instead of waiting for the idle window.
- You suspect someone signs in from a device you do not recognise: the Device and IP columns reveal it, and End signs them out.
- Before changing the password of a dismissed employee: end their sessions first.
Tip
A short user lock grace frees seats faster but may sign out a cashier during a quiet spell. The default suits most shops; change it only if you are really short of seats.
The audit log
Under Settings, then Audit log. Every important action is recorded with who did it and when: date, user, action, subject (the affected document or record), details and IP address. The filter box at the top accepts an action name, for example pos.invoice.cancel for every cashier cancellation or pos_session.closed for shift closes.
Examples of what you find there:
| Action | When it is recorded | Details kept |
|---|---|---|
pos_session.opened | Shift opened | Opening float and its source (entered or cashbox balance) |
pos_session.closed | Shift closed | Expected and counted cash |
pos_session.cashbox_conflict | Shift opened on a cashbox held by another cashier | Cashbox id |
item.created / item.updated | Item defined or edited | SKU and name |
fund_transfer.posted | Fund transfer posted | Document number |
The log is read-only and nothing is ever deleted from it. Use it with the cashier report when the drawer count does not match the expected cash, and with System messages when you want to know why an action was refused.
Warning
Ending a cashier session during a sale does not damage their data: invoices saved on the device are uploaded at their next sign-in. Still, avoid doing it in the middle of a payment if you can wait a minute.
Frequently asked questions
Does the user count in the subscription limit the number of accounts?
No. It limits how many are signed in at the same time. Create an account for every employee without worry.
An employee cannot sign in although nobody is working. Why?
Usually an old session still inside the idle window. Open Active sessions and end the unused ones, or wait for the user lock grace to expire.
Can an employee remove their trace from the audit log?
No. The log is read-only and no user has a permission to delete from it.