Church Cashbook Maintenance Manual
Review database activity summaries.
What the activity log is
The activity log is a database table (activity_logs) that records every significant user action — transaction creation, amendment, voiding, Gift Aid operations, user management changes, and system setting changes. Unlike the file-based audit log, the activity log is designed to be queried and reviewed through the application interface.
Accessing activity logs
Activity logs are accessible via Admin → Activity logs. The view can be filtered by church, user, event type, and date range. Superadmins can see activity across all churches; church-level administrators see only their own church.
The log is append-only — entries cannot be edited or deleted by any user, including superadmins. This is a deliberate integrity control.
What to look for
- Void spikes: An unusual number of voided transactions in a short period may indicate a data entry error or, in the worst case, deliberate interference. Review the specific transactions voided.
- Privilege changes: Any changes to user roles or access assignments should be expected and authorised. Unexpected role grants (particularly SUPERADMIN or TREASURER) warrant immediate investigation.
- Off-hours activity: Legitimate church administration rarely happens at 2am. Logins or transaction entries at unusual times are worth noting.
- System settings changes: Changes to site settings (maintenance mode, session timeout, Gift Aid settings) should be traceable to a known administrative action.
- Access from unexpected churches: A user who normally operates in one parish suddenly accessing another is unusual unless a role assignment change preceded it.
Relationship to the audit log
The activity log records what happened at the application level. The file-based audit log records errors and security events at the system level. Both should be reviewed together when investigating an incident — a suspicious activity log entry may have a corresponding error log entry that reveals more detail.