InfraNestInfraNest
Organizations & members

Check who has access, and who actually signs in

Two reports answer the access questions an audit, an offboarding or a quiet Friday afternoon will ask.

This article is for anyone who needs to review who can get into InfraNest, and who has actually been using that access — useful for security audits, offboarding checks, or a routine tidy-up.

Overview

  • There are two separate reports because they answer two different questions: who has access right now, versus who signed in over a period of time.
  • Both live under Team, and both can be exported or printed for an audit trail.
  • Keeping them separate means neither one has to compromise — one always describes the present, the other always describes history.

Check who has access right now

  1. Open Team and go to the report that lists current members — their role, whether two-factor is Enabled, and when they last signed in.
Check who has access, and who actually signs in
  1. Look at the top of the list first: people without two-factor are listed first, since that's usually what a review is actually looking for.
  2. Scroll down to see pending invitations. Any that have expired are marked as such — an unaccepted invitation is still a standing offer to join, so check this list during offboarding too.
  3. If someone shows Last signed in: never, that's accurate — it means there's no record of them ever signing in, not a gap in the data.

Check who signed in over a period

  1. Go to the sign-ins report and choose a period — a month, a quarter or a year.
  2. Review the results: each person shows how many times they signed in, how many separate days they were active, and the first and last of those days.
  3. Check the top of the list first — people who did not sign in at all during the period are listed there with a zero. That's usually the reason to run this report in the first place.
  4. Use "Days active" rather than raw sign-in count as your main signal — several sign-ins in one morning is one day of work, not several.

NoteSign-in summaries are kept separately from the security log (which clears out after a few weeks), so "last signed in" keeps working correctly even for accounts that haven't been used in a long time. If you pick a period before that summary began, the report will tell you the earliest date it can report from instead of showing a blank period.

Export evidence for an audit

  1. Open either report and select Download to get a CSV of exactly the rows shown — this is typically what's attached to an ISO 27001 or SOC 2 access review ticket.
  2. Copy the address bar to share the same report, with the same period and filters, with a colleague.
  3. Select Print to save the report as a PDF, with the period and any filters restated on the page.

TipEvery export is recorded in your Audit Log, so there's always a trail of who pulled the evidence and when.

Good to know

  • Roles are per organization. Someone who belongs to two of your organizations can be an owner in one and a viewer in the other — each report only shows their role in the organization you're currently in.
  • Removing someone from the organization removes them from the access report immediately, but they'll still appear in the sign-ins report for any period when they were actually signed in. That's history, and it doesn't rewrite itself.

Related articles

Try this in your own account

Connect one provider and work through these steps against your own infrastructure.

Free plan · No credit card required · Set up in minutes