AUTHENTICATION EVIDENCE
Login Events
Review successful, failed, blocked, and session-related authentication activity.
Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.
True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.
Purpose
Login events help authorized reviewers identify who attempted to access the platform, whether authentication succeeded, what device and browser were used, and whether the attempt should be investigated.
Common Login Event Types
| Field | Function |
|---|---|
| Successful login | Records a completed authentication event and the identity, Provider, device, browser, IP address, and session context. |
| Failed login | Records an unsuccessful sign-in attempt and supports review of repeated failures or credential issues. |
| Blocked attempt | Records an attempt denied by account status, security controls, policy, or another protective condition. |
| Password reset | Records the security workflow used to reset or change credentials. |
| Session created | Records creation of an authenticated session after successful verification. |
| Session ended | Records logout, expiration, administrative termination, or another session-ending event. |
Review Procedure
- Confirm the user, Provider, date/time, and status.
- Compare IP address, location, browser, device, and operating system with expected patterns.
- Look for repeated failed attempts, unusual timing, or unexpected device changes.
- Correlate suspicious activity with Audit Logs, Security, Support, and user account status.
- Escalate according to the Provider's incident-response and workforce-security procedures.
