Review account security activity
Review your personal sign-in, password, and MFA activity and see how much history your plan includes.
Recent Account Protection History shows security events for your own team sign-in. Your plan sets how far back you can view them.
Open your security history
- Open Personal Settings → Security.
- Find Recent Account Protection History.
- Scroll through the list. Older rows load as you reach the end.
The page shows the number of days you can view. If no events match that window, it shows an empty list. If the list cannot load, refresh the page before you use it to judge account safety.
How much security history can I view?
| Core | Growth | Power Team |
|---|---|---|
| 30 days | 180 days | 365 days |
These windows also apply to older plans with the same plan name. If you belong to more than one active workspace, Sydnee uses the highest paid plan you have access to. For example, a Core workspace and a Growth workspace give you 180 days. Switching workspaces keeps that same personal history.
This list covers your own sign-in, password, and MFA events. Other team members' events stay in their own histories.
To view plans, a workspace owner can open Company Settings → Plans. Other team members can ask a workspace owner about a longer history window.
Which actions appear, and which send an email?
This table lists the events you may see. It also shows when Sydnee sends an alert to your account email address.
| Action | What it means | History | Email alert |
|---|---|---|---|
| Signed in | A sign-in to your team account was completed. | ✅ Yes | ❌ No separate sign-in alert. |
| Signed out | A team account session ended. | ✅ Yes | ❌ No |
| Password changed | Your password was changed in Security settings. | ✅ Yes | ✅ Yes |
| Password reset requested | A recovery link was requested for your account. | ✅ Yes | ❌ No separate alert. Sydnee sends the recovery link by email. |
| Password reset completed | Your password was reset with a recovery link. | ✅ Yes | ✅ Yes |
| MFA enabled | An authenticator app was added to your account. | ✅ Yes | ✅ Yes |
| MFA disabled | Authenticator app protection was turned off. | ✅ Yes | ✅ Yes |
| Backup codes regenerated | A new set of MFA backup codes was made. | ✅ Yes | ✅ Yes |
| Multi-factor authentication succeeded | An authenticator or backup code completed sign-in. | ✅ Yes | ❌ No separate MFA success alert. |
| Backup code used for multi-factor authentication | A backup code was used for sign-in, a password change, or turning off MFA. | ✅ Yes | ✅ Yes for sign-in. Password changes and MFA disablement send their own alerts. |
“Yes” means Sydnee tries to send an alert after the action. It does not confirm delivery. One backup code sign-in may add more than one history row. Sydnee sends one backup code alert.
An event can show its time, device type, country, and IP address when those details are available. A country is an estimate based on the network address. It may be missing or different when a person uses a mobile network, company network, or VPN.
Review active sessions
The same Security page has Active Sessions. It lists the current login and other active team workspace sessions.
If you see another session you no longer use, select Log Out for that session. Sydnee asks for an authenticator code, backup code, or emailed verification code before ending it. This control ends other sessions only.
What should I do if I do not recognize an event?
- Check the exact time, device, country, and IP address.
- End any other active session you do not recognize.
- Change your password.
- Turn on MFA. If MFA is already on, regenerate the backup codes.
- Contact support if the event still looks wrong.
Send the visible event type and time. Do not send your password, MFA code, backup codes, QR code, or authenticator secret.
Why is an expected event missing?
- The history covers only your own login, not another team member.
- The event may fall outside your current history window.
- Some normal product actions are not security events.
- The newest page may need a refresh after a change.
- A deleted event stays deleted after a plan upgrade.
- A failed load is not the same as an empty history.