Summary
Learn how to track and view changes made to user permissions through the Access Control Levels.
This article covers:
About access control list permission changes
User access in Box+Dice is controlled through the Access Control List (ACL), which defines who can view or modify specific areas of the system. If a user’s permissions are unexpectedly granted or removed, these changes can be reviewed through the system’s audit trail. The audit trail helps identify what was changed, when it occurred, and who made the change.
Access record logs
You can view a record of permission changes made in the system through the record logs module.
To view a record of permission changes:
- Go to: Settings > General
- Click Access > Record Logs
This will open a module showing all historical access control changes.
Interpret log entries
Once inside the record logs module, you’ll see entries that provide a detailed audit of each permission change.
Here’s what to look for:
- What was changed - The specific action that was taken (e.g., “Admin allowed Admin to Save”)
- When - The date and time the change occurred
- By Who - The user who made the change
- Permission State - The previous and new permission levels
This shows that:
- An Admin permission was granted
- The change was made 9 days ago at 1:54 PM
- It was actioned by Peter Wolfenden
These logs are vital when investigating uncommunicated changes to user access or verifying actions for compliance and security audits. They also help with troubleshooting when users report unexpected changes in their access.
Audit logs are read-only and cannot be edited or deleted, ensuring the integrity of the information.