The Activity Log: "Who Changed This?" Without Accusing

Level Intermediate Role Owner Module Activity Log, Access Rights About 9 minutes
Updated

One morning you open a transaction and the figures are not what you remember. A price has changed, a discount appeared from nowhere, or stock on one item dropped without a sale.

What happens next is the same in most shops, and it is always bad. You ask one person; they do not know. You ask another; they do not either. Nobody is lying — they genuinely do not remember. But the air in the shop changes that day, and it does not go back to normal for weeks.

The Activity Log stops that cycle before it starts. Every data change leaves a named entry: which user, when, which record was touched, and what the change contained — which value became which.

The question becomes answerable without anybody needing to be suspected.

But one thing deserves saying plainly, because it is what people most often get wrong with a feature like this: a log is not a staff surveillance tool. A shop that uses it to spy will lose its good people long before it catches a dishonest one.

In practice, most findings from a log turn out not to be dishonesty at all — but a single step in the application that is far too easy to get wrong, done by different people, over and over. And it is not the people that need fixing.

Before you start

  • Every person has their own account. If everyone shares one login, the log can only ever name one person — and becomes useless.

Steps

  1. Open Settings → Rekam Aktifitas and understand what is recorded

    Every change leaves an entry: the kind of action, which data was touched, a pointer to the specific record, which user, the time, and the content of the change. Which means "who changed this" always has an answer rather than a guess.

    Activity log showing account, menu, action, and the changed data
    Every change is recorded together with who made it.
  2. The absolute precondition: one person, one account

    The log records whichever user is signed in. If your morning and afternoon staff share an account, every trail points to one name and you learn nothing. Before relying on the log at all, separate the accounts.

    User list — the log only reads correctly with one account per person
    One person, one account. Without it the log means nothing.
  3. Search from the problem data, never from the suspected person

    This habit decides everything. Start from the transaction or product whose figures look wrong, then follow the trail. Starting from a name means you find what you already wanted to find — and that is not an investigation, it is a prejudice.

    Elastic filter on the activity log for searching from the problem data
    Start from the data, not from the person you suspect.
  4. Narrow it down by when it happened

    You almost always know when the figure was still right and when it was already wrong. The window between those two is where to look. This cuts hundreds of rows to a handful in one move.

    Date column in the activity log for narrowing the time window
    Narrow it down by when it happened.
  5. Read the content of the change, not merely that a change occurred

    The entry stores what changed, so you can see which value became which. This is where most suspicion evaporates: what looked like manipulation turns out to be one extra zero, corrected five minutes later by the same person.

    The Data column holds the change itself, not merely that one occurred
    Read what changed, not just that something did.
  6. Distinguish three things that look identical on screen

    A typing mistake happens once and is usually fixed immediately. A process error happens repeatedly, by different people — which means the flow is confusing, not the person. Genuinely suspicious activity differs from both: repeated, by one person, and always favouring the same direction.

  7. When the pattern repeats, fix the process rather than the person

    The most common finding in a log is not dishonesty but a single step that is easy to get wrong. Fix it with sharper access rights, clearer field labels, or one written instruction. Telling somebody off does not repair a flow that was set up to trap them.

  8. Print the trail when the matter is serious

    A print view is available. For anything that may be discussed again weeks later, print it or save it as a file. A document that cannot shift is far calmer to discuss than a screen whose contents can.

    Print button on the activity log for preserving a serious trail
    Print the trail when the matter is serious.
  9. Tell everyone the log exists — it reassures rather than threatens

    A system that keeps a trail is most useful when everyone knows it is there. Not as a threat, but as protection: when something goes wrong, the people who did not do it can be shown not to have done it. Teams who know a trail exists work more calmly, not less.

  10. Close by telling people what you found

    Once the matter is settled, share the finding openly — including when it turns out nothing was wrong. An investigation that ends without explanation leaves a suspicion among your team that never quite goes away.

What you end up with

You can trace any data change back to a name, a time and the content of the change — and use that to improve how your shop works rather than to decide who to blame.

If something goes wrong

Every trail points to the same name

That means your shop is still on a shared account. Create individual accounts now — without them the log will never be useful, however rich its contents.

I cannot find the change I am looking for

Widen the time range first. If it still is not there, the data was probably not changed but created wrong in the first place — trace it from creation rather than from modification.

The change content is hard to read

The change record is stored as-is so it stays exact. You only need two things from it: which field changed, and to what value. Ignore the rest.

Staff feel watched once they learn the log exists

Usually because the log is only ever mentioned when something has gone wrong. Announce it during a calm week, explain that it proves who did not do something, and use findings to improve the process — not to reprimand people in front of others.