Registo de atividade de segurança
5 min de leitura
Este artigo está disponível apenas em inglês.
Version 2.0 | Last updated: August 2026
ClientFlow records the security-relevant events on your account — sign-ins, password changes, two-factor changes, session and device activity — and shows them to you at Settings → Security.
Scope: this log covers account security events. It is not a data-access audit trail: ClientFlow does not record which client records you opened or which payments you edited, and there is no per-record access history. If you need that for a regulator, ClientFlow cannot supply it today.
What Gets Logged
| Category | Events |
|---|---|
| Sign-in | Successful sign-in, failed sign-in, lockout, sign-out |
| Password | Password set, changed, reset requested, reset completed, admin-initiated reset |
| Two-factor | Enabled, disabled, verified, failed, backup code used, backup codes regenerated, recovery started or cancelled |
| Devices | Trusted device added or removed, sign-in from a new device, sign-in from a new location |
| Sessions | Session revoked, all sessions revoked |
| Connected accounts | OAuth provider linked, unlinked, or externally revoked |
| Account | Email changed, recovery email added, account deleted, activity flagged as suspicious |
What Is Not Logged
- Opening, editing or deleting a client, payment, appointment or note
- File downloads and exports
- The contents of any record
Reading the Log
Go to Settings → Security. Each entry shows the event, when it happened, and the IP address it came from. You can:
- Filter by event type
- Filter by date range
- Page through older entries
No export. The log is read-only in the dashboard — there is no CSV, JSON or PDF download. If you need a copy for an investigation, contact support.
Automatic Protections
| Trigger | What happens |
|---|---|
| 5 failed sign-in attempts | The account is locked for 15 minutes and a lockout event is written |
| Sign-in from a new device or location | An event is written so you can spot access you did not authorise |
| Rate limit exceeded | The request is throttled (HTTP 429) |
Revoking a session, or all sessions, from Settings → Security signs that device out immediately and records the action.
Questions
Support: support@clientflow.center
Read time: ~5 minutes | Audience: Account owners, IT
Isso foi útil?