Check the audit log
Who: the Super Admin. Go to: sidebar → Audit log. On a phone: More → Audit log.
A tamper-evident record of who did what, and when, in plain words: approvals and rejections (including automatic ones), role and approver changes, invites and removals, settings changes, sites, site people and site codes, clients and work types, kiosks, punches, punch and shift photos (added, removed, kept, viewed by a manager, and deleted by retention), corrections and missed shifts, rosters and publishing (bulk adds, changes and removals show as one entry, with each shift underneath), open-shift, cover and swap requests, leave and availability. Tap an entry to see the details, the device and the network it came from. Use the filter line at the top to narrow it by period, type of record, action or person.
Example: Maya's hours that count changed and she asks why. Priya filters the Audit log to Maya for This week and finds Tom's break change on her Tuesday entry, with his note Saw her take lunch 12–12:30.
Ask Vaultime: Super Admins can also ask in words: Who deleted Saturday's shifts?, Who changed Maya's hours last week?, Who turned off clock-in? It answers with who, what, when and before → after, and never shows the device, the network or fields kept from Ask Vaultime. Admins and staff can't ask it about the log.