# Getting started: audit a user

1. [Home](https://www.agilicus.com/)
2. [Agilicus AnyX Administrative Web Interface](https://www.agilicus.com/anyx-guide/agilicus-anyx-administrative-web-interface/)
3. [Getting Started](https://www.agilicus.com/anyx-guide/agilicus-anyx-administrative-web-interface/getting-started/)
4. Getting started: audit a user

![](https://www.agilicus.com/www/36c930c5-featured-anyx-admin-getting-startedaudit-user.png)## Getting started: audit a user

[CONTACT](/contact-us/)

The fifth setup task confirms that you can diagnose access issues and see the audit trail. Agilicus AnyX records who accessed what, when, and whether it was allowed; this task makes sure you know where to look.

![Audit a user guide](https://www.agilicus.com/www/e4333234-audit-user.png)    ## What this task is for

When a user has a problem, or when you need to demonstrate compliance, you use the audit and diagnostics screens. This task walks through the main places to look so you are ready when you need them.

## Where to look

- **Authentication audit** (**Organisation &gt; Authentication Audit**): who signed in, when, and whether the sign-in succeeded. See [Authentication audit](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/authentication-audit/).
- **User audits** (**Access &gt; Audits**): everything a user has done across resources. See [Access audits](/anyx-guide/agilicus-anyx-administrative-web-interface/access/audits/).
- **Sessions** (**Organisation &gt; Sessions**): active and recent user sessions. See [Sessions](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/sessions/).
- **Application diagnose** (**Resources &gt; Applications &gt; Diagnose**): inspect live request and response traffic for a specific application. See [Applications](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/applications/).
- **Metrics** (**Metrics**): aggregated usage such as top users and active users. See [Metrics](/anyx-guide/agilicus-anyx-administrative-web-interface/metrics/overview/).

## How to do it

1. Open **Getting Started &gt; Audit User** from the left navigation.
2. Follow the guide through the audit screens it lists.
3. Practise a real scenario: ask a user to attempt access, then find their sign-in and access events in the audit screens.
4. Confirm you can see the reason for any denial (for example a policy rule).
5. Mark **Audit User** complete on the task board.

## Diagnostics versus configuration

The audit screens are **diagnostics**: they are read-only and do not change anything. Use them to observe. Configuration (changing who has access) happens in the [permissions](/anyx-guide/agilicus-anyx-administrative-web-interface/access/application-permissions/) and [policies](/anyx-guide/agilicus-anyx-administrative-web-interface/access/policies/) screens.

## Troubleshooting

- An event is missing: check the [audit subsystem](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/audit-subsystem/) health and the [audit destinations](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/audit-destinations/) if you forward logs.
- You cannot see a user's events: confirm you have permission to view audits for that user.

## See also

- [Audit and diagnostics](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/audit-and-diagnostics/)
- [Authentication audit](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/authentication-audit/)
- [Access audits](/anyx-guide/agilicus-anyx-administrative-web-interface/access/audits/)
- [Getting started: overview](/anyx-guide/agilicus-anyx-administrative-web-interface/getting-started/overview/)

## Web guide

- [Authentication audit](https://www.agilicus.com/product-guide/authentication-audit)
- [Zero trust audit logging](https://www.agilicus.com/zero-trust-audit)