Active sessions and the audit log

3 min read ·Updated

Seen the message about the concurrent user limit? Or want to know who cancelled an invoice yesterday? These two screens under Settings answer both.

On this page
  1. How seats are counted
  2. The Active sessions screen
  3. The audit log

How seats are counted

Your subscription sets the number of concurrent users, meaning people signed in at the same moment, not the number of accounts you created. Create as many accounts as you like; what counts is who is working now through the three doors: the web panel, the POS app and the manager app.

  • A user who already has an active session signs in again without taking a new seat.
  • A new user is refused only when the number of active users has reached the limit, with the message CONCURRENT_SESSION_LIMIT_REACHED.
  • "Active" means they did something within the idle window set under Point of sale settings, then User lock grace. Anyone idle longer than that releases their seat automatically.

The Billing and subscription screen shows "X of Y in use" computed the same way. To add seats, see the pricing page.

The Active sessions screen

Under Settings, then Active sessions. A table with columns: user, type (web, cashier, manager), device, IP address and last activity. Users holding the Terminate permission on sessions see an End button on every row.

When do you need it?

  1. An employee left with the app open on their device and the seat is held by it. End their session so the replacement can sign in now instead of waiting for the idle window.
  2. You suspect someone signs in from a device you do not recognise: the Device and IP columns reveal it, and End signs them out.
  3. Before changing the password of a dismissed employee: end their sessions first.

Tip

A short user lock grace frees seats faster but may sign out a cashier during a quiet spell. The default suits most shops; change it only if you are really short of seats.

The audit log

Under Settings, then Audit log. Every important action is recorded with who did it and when: date, user, action, subject (the affected document or record), details and IP address. The filter box at the top accepts an action name, for example pos.invoice.cancel for every cashier cancellation or pos_session.closed for shift closes.

Examples of what you find there:

ActionWhen it is recordedDetails kept
pos_session.openedShift openedOpening float and its source (entered or cashbox balance)
pos_session.closedShift closedExpected and counted cash
pos_session.cashbox_conflictShift opened on a cashbox held by another cashierCashbox id
item.created / item.updatedItem defined or editedSKU and name
fund_transfer.postedFund transfer postedDocument number

The log is read-only and nothing is ever deleted from it. Use it with the cashier report when the drawer count does not match the expected cash, and with System messages when you want to know why an action was refused.

Warning

Ending a cashier session during a sale does not damage their data: invoices saved on the device are uploaded at their next sign-in. Still, avoid doing it in the middle of a payment if you can wait a minute.

Frequently asked questions

Does the user count in the subscription limit the number of accounts?

No. It limits how many are signed in at the same time. Create an account for every employee without worry.

An employee cannot sign in although nobody is working. Why?

Usually an old session still inside the idle window. Open Active sessions and end the unused ones, or wait for the user lock grace to expire.

Can an employee remove their trace from the audit log?

No. The log is read-only and no user has a permission to delete from it.

Was this article helpful?