Authentication Audit Log
A read-only record of every security-relevant authentication event for your organization: sign-ins, signups, password changes, MFA, and SSO, success and failure, with IP address and browser fingerprint.
What it is
LucentSkill records an append-only entry every time someone signs in, signs up, sets a password, completes or fails multi-factor authentication, signs in with single sign-on, or signs out. Each entry stores when it happened, the account (or the attempted email), the outcome, the IP address, the browser, and a machine-readable reason for any failure. The attempted email is stored as plaintext, deliberately, so it can be searched from the viewer's email filter; it is the one audit field that stays searchable rather than encrypted at rest. No credential is ever written: no password, token, secret, or verification code appears in the log.
Use
- Open the log from Admin Console, Security Audit Log. Owners and admins can view it; members cannot.
- Filter by event type to focus on failed sign-ins, MFA challenges, or SSO activity.
- Search by email address to see every authentication event for one person.
- Spot an attack early: a run of login_failed events with the reason unknown_email suggests account enumeration, while bad_credentials repeated for one account suggests a brute-force attempt.
Setup
The audit log is always on. Events are recorded automatically at every authentication boundary, so there is no configuration to enable. Retention follows your database backup policy.
Security
- The log is append-only and immutable: there is no update or delete path, so an event cannot be edited or erased.
- Log entries are sanitized before storage. Control characters and line breaks are stripped, so an attacker cannot forge or inject a fake log entry through a crafted email or browser string.
- IP addresses are partially masked in the viewer, and full addresses are never shown to a member.
- Only an owner or admin of the organization can read the log, and it is scoped to that organization. There is no cross-tenant access.