Platform access level: Org Admins. The Security log page is part of organization-level Settings, so only Org Admins can open it. Managers have access to everything else in Arist, including their own team's settings, but not to organization-level Settings pages like this one.
When someone asks who changed a course, when a schedule was altered, or whether anything moved in your settings last month, the security log has the answer. Arist records each change as its own entry, with a timestamp and, where a person made it, their name. Filter that list down to the change you are being asked about.
1. Reading the entries list
Open Settings and choose Security log in the sidebar. The heading counts your organization's entries, and the table lists them newest first.
Each row is one change, and the four columns describe it.
Item type: Names what kind of record changed. Organization is where a change to your organization's own settings lands, Course covers a course and the lessons inside it, and Schedule covers one course going out to one cohort.
Event: Reads Create when the record was first made and Update when it changed afterwards.
User: Names whoever made the change. A person's name links through to them on the Learners page, and a change that no person made names the process behind it instead, which section 4 explains.
Timestamp: Records the date and time of the change.
The log also tracks changes to records outside those three types, such as an enrollment. Those rows leave Item type empty and fill in Event, User, and Timestamp as usual, so read them from the other three columns and open the row to see exactly which fields changed.
Every column heading sorts, and the Show selector under the table sets how many entries fit on a page. Long-running organizations accumulate thousands of entries, so use the filters to reach a specific answer rather than paging through the list.
2. Narrowing the list with Filters
Select Filters above the table to combine three filters, and clear them from the same panel when you are done.
Filter | What it narrows to |
Event | Entries where a record was created, or entries where one was updated |
Item type | Entries for your organization's settings, for courses, or for schedules |
User | Entries recorded against one person you choose |
The three work together, so Item type Organization with Event Update narrows the list to changes made to your organization's settings. The count above the table follows your filters, so it tells you how many entries match. Sort by Timestamp after filtering to put the oldest entries first, which helps when the change you are looking for is not recent.
Tip: Filter by User when you need one person's history, for example before removing their access or after a question about a specific edit. That gives you every change the log holds for that person, in one view.
3. Opening an entry to see what changed
Open the three-dot menu at the end of a row and choose View, or select the entry's Item type. Either opens a panel with the entry's Item type, Event, User, and Timestamp.
The panel's Changes section lists each field that changed, with the value before the change and the value after it, so you can see that a course name was edited rather than only that the course was updated. An entry that recorded no field changes shows N/A there instead.
The log records changes rather than views. Every entry describes a record being created or updated, so it will not tell you who looked at a course or ran a report.
Try it: Filter the log to Item type Organization and Event Update, then open the newest entry and read its Changes list. If you do not recognize that change, it is the first thing to ask about.
4. Spotting changes Arist made for you
Plenty of changes in your organization come from Arist doing work on your behalf rather than from someone clicking in the app. Every one of those is recorded like any other change, and the User column names the process responsible instead of a person.
System: Arist's own background work, where no account is involved. If your organization uses the Microsoft Teams user sync, each run updates your organization's record, which is why the same entry can repeat through the day.
API sync: A change that arrived through Arist's API, which is how an integration keeps your learner and enrollment data current.
Automation: An automation firing, named with the automation's own number and name so you can tell which rule ran. See Setting Up Automations.
A process name is plain text rather than a link, because there is no person's page to open. For an access review, filter by User to read one person's history, and read these entries as work Arist did rather than edits someone made. Who holds access right now is a different question, and the roster download on the Users & roles page answers it. See Managing Users and Roles.
Related articles
Note: Need help at any point? Reach out to your Arist Customer Success contact, or email [email protected].


