|
Purpose |
Review detailed CAREWare user actions, including the affected user or client, action description, record details, provider, and network information. |
|
Who should do this |
CAREWare administrators, security or compliance staff, data managers, or designated support staff with access to Administrative Reports. |
|
Use this report when |
You need an action-level audit trail for logins, report runs, client record views or edits, exports, deletions, or another specific user activity. |
|
Main warning |
The report can contain client names, usernames, IP addresses, and before-and-after data values. Limit access and protect every exported copy. |
|
Video walkthrough |
Quick path
|
Reports > Administrative Reports > User Action Report > set filters > Run Report |
Before you begin
• Confirm whether the review must cover Central Administration, several providers, or one provider. Central Administration can include provider information; a provider-level run is limited to that provider.
• Identify the date range, action type, acting user, or affected person connected to the event being reviewed.
• Start with a short date span. Use Set To Last 2 Weeks for a quick recent-activity review.
• Plan how any CSV, printed, or copied results will be stored, shared, and retained before exporting them.
|
Important The User Action Report is the detailed audit trail. Blank affected-user or affected-client fields can be normal when an action, such as logging in or running a report, did not affect a person record. |
Open User Action Report
Step 1. Sign in to Central Administration or the provider being reviewed.
Step 2. Click Reports.
Step 3. Click Administrative Reports.
Step 4. Click User Action Report.

|
Tip Run the report from Central Administration when the investigation may involve several providers. Run it inside a provider when the review should be limited to that provider. |
Set the report filters
Step 5. Enter the From and Through dates, or click Set To Last 2 Weeks.
Step 6. Select a Provider, or leave it blank in Central Administration to include all available providers.
Step 7. Select an Action Type when only one type of activity is needed.
Step 8. Select an Acting User to review one CAREWare account.
Step 9. Select an Affected Person to limit the report to actions that affected a specific user or client.


Run and review the report
Step 10. Click Run Report.
Step 11. Review the date span, entry count, and the first result columns.
Step 12. Use the page controls or entries-per-page list to move through the results.
Step 13. If the report has no rows, click Back and broaden the date range or remove one optional filter.

|
Warning Large date ranges can return thousands of audit records. Use a focused range during an investigation, then expand it only when additional history is required. |
Review details and narrow the displayed rows
Step 14. Scroll horizontally to review ActionType, UserActionDescription, TableName, EditDetails, Provider, RecordID, IP Address, and Forwarding IP Address.
Step 15. Enter a value in Search to narrow the displayed rows, such as Demographics, a provider name, a username, or an action description.
Step 16. Select a row when you need to keep the record highlighted during review.
Step 17. Use Column visibility to change which columns are available in the list.


User Action Report filter controls
|
Control |
What it does |
Guidance |
|
From / Through |
Defines the report date span. |
Use the smallest period that covers the event being reviewed. |
|
Set To Last 2 Weeks |
Sets a recent two-week date range. |
Use for a quick recent-activity review, then adjust the dates if needed. |
|
Provider |
Limits results to one provider. |
Leave blank in Central Administration to include all available providers. |
|
Action Type |
Limits results to one type of action. |
Use Run report, Login/Logout, Edit client record, Data Export, or another available action when investigating a specific event. |
|
Acting User |
Limits results to one CAREWare account. |
Use when reviewing the actions performed by a known user. |
|
Affected Person |
Limits results to actions that affected a specific user or client. |
Use when the affected person is known, even when the acting user is not. |
|
Run Report |
Opens the report with the current filters. |
Review the filters before running the report. |
|
CSV |
Exports the filtered report to a CSV file. |
Use only for approved analysis, documentation, or audit retention. |
Result controls
|
Control |
What it does |
|
Search |
Filters the displayed rows without rerunning the report. |
|
Column visibility |
Shows or hides result columns for the current review. |
|
Copy |
Copies selected or displayed grid information where supported. |
|
Print or Export |
Opens options for printing or exporting the result grid. |
|
Back |
Returns to the filter screen so the report can be rerun. |
Result columns: user and affected person
|
Column |
Description |
|
PK |
Unique database key for the recorded user action. |
|
Timestamp |
Date and time the action occurred. |
|
Username |
CAREWare username of the acting user. |
|
AffectedUser |
User account affected by the action, when applicable. |
|
AffectedClientFirstName |
First name of the client affected by the action, when applicable. |
|
AffectedClientMiddleName |
Middle name of the affected client, when available. |
|
AffectedClientLastName |
Last name of the affected client, when applicable. |
|
ActionType |
General category of activity, such as running a report, editing a client record, or logging in or out. |
Result columns: action and record details
|
Column |
Description |
|
UserActionDescription |
More detailed explanation of the activity, such as the name of a report that was run. |
|
TableName |
Database or CAREWare data area affected by a client-level view or edit. |
|
EditDetails |
Details of the change, which may include added or deleted records or before-and-after values. |
|
Provider |
Provider where the action occurred; Central Administration may be shown for central actions. |
|
RecordID |
Additional identifier for the affected record. |
|
IP Address |
Network address recorded for the acting user. |
|
Forwarding IP Address |
Forwarding network address when one is recorded. |
|
Warning EditDetails and exported audit files can reveal sensitive client data and system information. Export only the minimum data needed and follow local security, incident-response, and records-retention procedures. |
How to confirm the review is complete
• The report title shows the intended From and Through dates.
• The provider scope and optional filters match the event being investigated.
• Known actions appear with the expected username, timestamp, action type, and provider.
• Search terms narrow the displayed rows without changing the original report filters.
• Any copied or exported data is stored only in an approved location.
Troubleshooting and common questions
Why does the report return no rows?
Click Back, confirm the date span, and remove optional filters one at a time. A record must match every selected filter.
Why are the affected-user or affected-client fields blank?
Many actions, including logins, logouts, report runs, and administrative tasks, do not affect a specific user or client record.
Why are there too many results?
Shorten the date span or add one targeted filter, such as Provider, Action Type, Acting User, or Affected Person. After the report runs, use Search for a section or description such as Demographics.
Why can a user not open this report?
Review the user's Administrative Reports permissions and provider assignment in Provider User Manager. Grant only the access required for the user's role.
Related CAREWare guides and resources
|
Resource |
How it helps |
|
Maintain individual accounts so actions can be attributed to the correct user. |
|
|
Review provider assignments, permissions, and access to Administrative Reports. |
