# Check who has access, and who actually signs in

> Two reports answer the access questions an audit, an offboarding or a quiet Friday afternoon will ask.

Source: https://infranest.io/docs/who-has-access
Last updated: 2026-09-06

---

This article is for anyone who needs to review who can get into InfraNest, and who has actually been using that access — useful for security audits, offboarding checks, or a routine tidy-up.

## Overview

- There are two separate reports because they answer two different questions: who has access *right now*, versus who signed in *over a period of time*.
- Both live under **Team**, and both can be exported or printed for an audit trail.
- Keeping them separate means neither one has to compromise — one always describes the present, the other always describes history.

## Check who has access right now

1. Open **Team** and go to the report that lists current members — their role, whether two-factor is **Enabled**, and when they last signed in.
<!-- screenshot: access-report -->

<!-- docs-screenshots:start:access-report -->

![Check who has access, and who actually signs in](/media/f16b328c-f6e1-4584-8d6a-eb3de5c12a38)

<!-- docs-screenshots:end:access-report -->

2. Look at the top of the list first: people **without two-factor are listed first**, since that's usually what a review is actually looking for.
3. Scroll down to see pending invitations. Any that have expired are marked as such — an unaccepted invitation is still a standing offer to join, so check this list during offboarding too.
4. If someone shows **Last signed in: never**, that's accurate — it means there's no record of them ever signing in, not a gap in the data.

## Check who signed in over a period

1. Go to the sign-ins report and choose a period — a month, a quarter or a **year**.
2. Review the results: each person shows how many times they signed in, how many separate days they were active, and the first and last of those days.
3. Check the top of the list first — people who **did not sign in at all** during the period are listed there with a zero. That's usually the reason to run this report in the first place.
4. Use "Days active" rather than raw sign-in count as your main signal — several sign-ins in one morning is one day of work, not several.

> [!NOTE]
Sign-in summaries are kept separately from the security log (which clears out after a few weeks), so "last signed in" keeps working correctly even for accounts that haven't been used in a long time. If you pick a period before that summary began, the report will tell you the earliest date it can report from instead of showing a blank period.

## Export evidence for an audit

1. Open either report and select **Download** to get a CSV of exactly the rows shown — this is typically what's attached to an ISO 27001 or SOC 2 access review ticket.
2. Copy the address bar to share the same report, with the same period and filters, with a colleague.
3. Select **Print** to save the report as a PDF, with the period and any filters restated on the page.

> [!TIP]
Every export is recorded in your **Audit Log**, so there's always a trail of who pulled the evidence and when.

## Good to know

- Roles are per organization. Someone who belongs to two of your organizations can be an owner in one and a viewer in the other — each report only shows their role in the organization you're currently in.
- Removing someone from the organization removes them from the access report immediately, but they'll still appear in the sign-ins report for any period when they were actually signed in. That's history, and it doesn't rewrite itself.
