Audit logs: tracking who did what and when

How to read the School Vault audit log, what events are recorded, how to filter by user or date, and how to use audit logs to investigate disputed data changes.

Before you begin

  • You are logged in as School Owner or School Admin.

What the audit log records

Every significant action taken in School Vault is recorded in the audit log. An audit log entry contains:

  • Timestamp, date, time, and timezone of the action
  • User, the staff member or parent who performed the action
  • Action type, what was done (e.g. Login, Record Created, Record Edited, Record Deleted, Report Generated, Permission Changed)
  • Resource, what was acted on (e.g. Student: Amara Okonkwo, Attendance: Nursery 1A, 2026-09-04)
  • Before / After, for edits, the previous value and the new value (e.g. "Attendance status changed from Present to Absent")
  • IP address, the IP address of the device used

The audit log cannot be edited or deleted by school staff. It is append-only and retained for 3 years.

Viewing login activity

  1. Go to Settings → Login Activity.
  2. The table shows recent login sessions for all users in your school (last 200 entries), most recent first.
  3. Each row shows: User, Role, Device/Browser, IP Address, Login Time, Logout Time, Duration, and Status (Active or Ended).

Login Activity is useful for identifying unauthorised access (unexpected logins from unfamiliar IP addresses or devices) and confirming which staff members are actively using the system. For a complete record-level audit trail — who edited which student record, which attendance mark was changed, and the before/after values — contact support@schoolvault.ng. A detailed audit export is available on request.

Audit log view showing a filterable table with columns: Timestamp, User, Action, Resource, and a Details link for each row

Investigating a disputed change

Example scenario: a parent claims their child was marked absent on a day when they were at school. To investigate:

  1. Go to Settings → Login Activity and check which staff members were logged in at the relevant time and from which device.
  2. For a record-level audit (exactly who changed the attendance entry, from what value, and at what time), email support@schoolvault.ng with the student name and the date in question.
  3. School Vault retains a full internal audit trail of all data changes and will provide an export in writing, typically within one business day.

Bulk export

  1. Apply your filters to narrow the log to the period you want.
  2. Click Export CSV.
  3. A CSV of all matching audit entries is downloaded. This is suitable for external review or regulatory reporting.
School Vault support staff access is also audited. If a School Vault engineer accesses your data to investigate a reported issue, the access is logged in School Vault's internal audit system. To verify that support access was limited in scope, email support@schoolvault.ng and request an access log for your school — all support access is recorded and can be provided in writing.
Review Login Activity monthly. At the end of each month, check Settings → Login Activity for logins from unexpected devices, IP addresses, or unusual times. An unfamiliar session is an early warning sign of account compromise. For deletions or data-change auditing, request a detailed audit export from support@schoolvault.ng.

Common mistakes

  • Expecting Settings → Login Activity to show record-level changes — it shows login sessions only (who logged in, from where, and for how long). For a detailed audit trail of who edited a specific student record or attendance entry, contact support@schoolvault.ng.
  • Not checking login activity when investigating suspected unauthorised access — an unfamiliar device, IP address, or login at an unusual time is a meaningful signal even without record-level detail.
Version history
v1.0 23 Jul 2026 Article published for Academy v1.0.
v1.1 10 Aug 2026 Updated to reflect live UI. Settings has no "Audit Log" section — the actual section is "Login Activity" showing login sessions (User, Role, Device/Browser, IP, Login Time, Logout Time, Duration, Status). Record-level audit trail (who changed what field, before/after values) is available from support on request. Rewrote "Accessing the audit log", "Investigating a disputed change", and both callouts to match.