Platform access level: Org Admins. The Security log page is part of organization-level Settings, so only Org Admins can open it. Managers have access to everything else in Arist, including their own team's settings, but not to organization-level Settings pages like this one.
When someone asks who changed a course, when a schedule was altered, or whether anything moved in your settings last month, the security log has the answer. Arist records each change as its own entry, with a timestamp and, where a person made it, their name. Filter that list down to the change you are being asked about.
1. Reading the entries list
Open Settings and choose Security log in the sidebar. The heading counts your organization's entries, and the table lists them newest first.
Each row is one change, and the four columns describe it.
Item type: Names what kind of record changed. Organization is where a change to your organization's own settings lands, Course covers a course and the lessons inside it, and Schedule covers one course going out to one cohort.
Event: Reads Create when the record was first made and Update when it changed afterwards.
User: Names the person who made the change and links through to them on the Learners page. Entries with no person behind them read System, which section 4 explains.
Timestamp: Records the date and time of the change.
Every column heading sorts, and the Show selector under the table sets how many entries fit on a page. Long-running organizations accumulate thousands of entries, so use the filters to reach a specific answer rather than paging through the list.
2. Narrowing the list with Filters
Select Filters above the table to combine three filters, and clear them from the same panel when you are done.
Filter | What it narrows to |
Event | Entries where a record was created, or entries where one was updated |
Item type | Entries for your organization's settings, for courses, or for schedules |
User | Entries recorded against one person you choose |
The three work together, so Item type Organization with Event Update narrows the list to changes made to your organization's settings. The count above the table follows your filters, so it tells you how many entries match. Sort by Timestamp after filtering to put the oldest entries first, which helps when the change you are looking for is not recent.
Tip: Filter by User when you need one person's history, for example before removing their access or after a question about a specific edit. That gives you every change the log holds for that person, in one view.
3. Opening an entry to see what changed
Open the three-dot menu at the end of a row and choose View, or select the entry's Item type. Either opens a panel with the entry's Item type, Event, User, and Timestamp.
The panel's Changes section lists each field that changed, with the value before the change and the value after it, so you can see that a course name was edited rather than only that the course was updated. An entry that recorded no field changes shows N/A there instead.
The log records changes rather than views. Every entry describes a record being created or updated, so it will not tell you who looked at a course or ran a report.
Try it: Filter the log to Item type Organization and Event Update, then open the newest entry and read its Changes list. If you do not recognize that change, it is the first thing to ask about.
4. Recognizing entries with no named user
An entry reads System under User when the change was not made by a person signed in to Arist. The change itself is recorded like any other, and only the person's name is missing. Two situations produce it.
Arist's own background work: A sync that runs on a schedule has no signed-in account behind it. If your organization uses the Microsoft Teams user sync, each run updates your organization's record, which is why the same entry can repeat through the day.
A request with nobody signed in: When a change reaches Arist without a signed-in session, there is no account to record, so the column has no person's name to show or link to.
For an access review, treat a System entry as a change no person made, and filter by User to see the edits a named user made. Who holds access right now is a different question, and the roster download on the Users & roles page answers it. See Managing Users and Roles.
Related articles
Note: Need help at any point? Reach out to your Arist Customer Success contact, or email [email protected].


