Skip to main content

Overview - Directory Accounts

Updated over a week ago

The Accounts section is part of the Directory tab and provides a central hub for viewing, searching, and managing all user accounts on the platform.

This guide covers the main details for Directory "Accounts" section:


ACCOUNTS SUMMARY DETAILS

Accounts summary lists all available domain users with high level data points if needed for management or investigation reference.

Column Header

Description

Active Status

Green: Active in the last 24 Hours.

Yellow: No activity in the last 24 Hours-One Week.

Grey: No activity in the last Week.

Email

The primary email address associated with the user account.

Organizational Unit

The organizational unit the user belongs to (or "All" if unassigned).

Violations

The total number of policy violations recorded for this account.

Last Known Location

The last recorded geographical location of the user and the network/provider used.

Last Heard From

The date and time the platform last received data from this user's account.

Actions

Provides options to manage the individual account.


FINDING AND FILTERING ACCOUNTS

Filter input fields help quickly narrow down the summary section when needing to find specific accounts.

Filter Option

Description

Organizational Unit

Filter accounts based on their assigned organizational unit.

Domain

Filter accounts associated with a specific domain.

Email

Search for accounts by typing a full or partial email address.

Status

Filter accounts based on their current active or inactive status.

Violations Only

A toggle switch to display only accounts that currently have violations.

Date Range

Filter accounts based on when a specific event (e.g., last seen) occurred within a date range.

Click Search to apply the selected filters.

Click Reset to clear all filter fields and display the full list.


ACCOUNT USER DETAILS

Email and Actions column both provide option to check account details. This provides a detailed summary of profile info and activity logs for the selected user.

General:

Contains the core profile data for the selected user.

Field

Description

Email

The user's primary login email address.

First Name / Last Name

The user's registered name.

Organizational Unit

The group or department the user is assigned to.

Last Heard From

The most recent date and time the system recorded activity from the user.

Last Known Location

The geographical location of the user during the last recorded activity.

Date Range Selector

Allows administrators to filter the Account Activity list below to a specific time frame.

Account Activity:

Provides a chronological record of the user's browser related activity.

Column Header

Description

Date

The date and time (in PST) the activity was recorded.

URL

The website address the user accessed.

Input

Indicates if a text input (like a search query) was logged.

Risks

Highlights any policy violations or flagged risk keywords (e.g., "Blocklist").

External IP / Internal IP

The network addresses associated with the user's connection.

Device

The type of device used for the activity.

Actions

Contains a View button to open a detailed event log for that specific activity record.

Device Activity:

Provides a chronological record of the user's device related activity.

Column Header

Description

Start Date

The date and time the device session began.

End Date

The date and time the device session ended.

Device

The unique identifier or name of the device used. N/A indicates the device ID was not retrieved.

Internal IP

The local IP address of the device within the user's network during the session.

External IP

The public IP address used by the device during the session.

Named Location

The geographical location associated with the device's external IP address.

Action Icon

Action Name

Description

Eye

Start Tracking

Initiates real-time tracking of the device's current location and activity. This option appears if the device is currently active or not already being tracked.

Lock Icon

Mark Found or Retrieved

Sets updated status of device indicating that it's no longer missing or has been recovered. This option appears if the device was previously marked as missing.


FINDING AND FILTERING DATA

Filter allows you to narrow down the activity log to find specific events, devices, or risks associated with the user's account.

Filter Option

Description

Device Ip

Enter the unique identifier for a specific device to view activity originating only from that device.

URL

Search for activities related to a specific website address. Enter a full or partial URL.

Violations Only

Toggle ON to display only activities that have been flagged as policy violations or risks.

Input

Search for activities that contain specific input data (e.g., a specific search query or text entered).

Policy Type

Select a specific policy type (e.g., "Web Filtering," "Keyword Alerts") to filter activities related to the rules of that policy.

Risk(s)

Select a specific risk type (e.g., "Blocklist," "Self-Harm," or a custom risk) to view only activities associated with that flag.

Click Search to apply the selected filters.

Click Reset to clear all filter fields and display the full list.


REPORTING ON ACCOUNTS

Reports action downloads all currently displayed summary data. Apply filters to extract specific results or set scheduled report for future delivery.

Report Option

Description

CSV

Downloads the data in a Comma Separated Values (.csv) file format. This format is ideal for analyzing large datasets in spreadsheet software like Excel or Google Sheets.

PDF

Downloads a printable version of the account list in Portable Document Format (.pdf). This format is best for sharing a static, ready-to-view document.

Scheduled Report

Opens a configuration window where you can set up a recurring export of the data. This allows you to receive the report automatically via email at specified intervals (e.g., daily, weekly, monthly).

Did this answer your question?