Skip to content

Staff actions

The staff actions log records actions Checktiv staff take against your data: action verb, timestamp, and the resource touched.

A staff action is anything a platform employee does that touches resources in your organization: starting or ending a staff session, unmasking an applicant’s personal data, or billing-side adjustments (goodwill grants, out-of-band wire funding, refunds, wallet balance changes, or SKU price overrides).

Actions that do not touch customer data are not surfaced here. Visibility is set per capability, and the log layers a defensive filter so a misconfigured flag cannot leak a non-staff row into this view.

The staff actions log is its own Staff actions page, separate from the activity log. Reach it from the link in the staff session banner shown while a staff member is active in your organization, or by opening its direct page link. Unlike the activity log, which is Owner/Admin-only, this page is visible to every organization member.

Each row shows the timestamp, the action, the actor type (Staff member, Internal service, or Automated), and the resource. Individual staff identities are suppressed.

The highest-impact staff actions require dual approval before they can run. A second staff member must approve, and the approver cannot be the requester — enforced as a hard constraint.

Capabilities that touch customer data and require dual approval:

  • Unmasking applicant personal data inside a verification.
  • Wallet balance adjustments, rate overrides, and SKU pricing overrides.

Starting a staff session is not one of them. It carries its own controls, listed under What we will and will not do, and you can refuse it outright from Staff access.

Internal staff-administration actions (such as assigning a staff role to a teammate) also require dual approval, but happen entirely on our side and are not surfaced in your log.

Dual approval pairs with fresh MFA, WebAuthn for the highest-risk capabilities, a required ticket reference, and time-boxed auto-expiring sessions.

While a staff member is working inside your organization, the console shows a persistent banner naming the staff member, when the session started, and how much time is left. The banner stays in sync across browser tabs, and its End session control lets you close the session yourself. The end event records the reason and appears in this log.

You decide whether staff sessions are possible at all. See Staff access.

Staff can do — every action below is recorded in this log:

  • Start a time-boxed staff session with a security key, a fresh MFA check, a required ticket reference, and only against the authorized region.
  • Unmask applicant personal data with dual approval, when a ticket justifies it.
  • Apply billing adjustments within cap-bounded controls.

Staff can do — recorded internally, not in this log:

  • Read your verifications and configuration to resolve a ticket you raised. Read access is recorded in our internal audit log but is not surfaced in your staff-actions feed.

Staff cannot do:

  • Act outside an approved capability — every action is checked against the staff capability registry.
  • Self-approve a dual-approval action.
  • Act against EU-resident data from a non-EU-authorized session, or vice versa.
  • Edit, delete, or hide a customer-visible audit row.

If you see an action you do not recognize, copy the timestamp and resource identifier and open a support ticket. We will respond with the ticket reference, the staff role, and the approval chain.