Ceum keeps two kinds of "who did what" in two places: the tool activity page records calls made through its tools, and your sessions and connected devices are managed under Account settings. This article covers what's on each and when to use which.
Tool activity
The tool activity page is a read-only log of every call made through Ceum's tool surface, whoever made it: an external tool using one of your MCP tokens, Rocky, or the in-app command palette.
Each entry shows:
- Action — what was done (e.g. creating a task, updating an invoice).
- Type — whether the call read data or changed it.
- Outcome — whether it succeeded, was refused, or failed. A refusal means the caller asked for something it is not allowed to have: a tool its token was never granted, or a client or project outside the token's scope.
- Actor — who made the call: an external agent, Rocky, or the command line.
- Token — for an external agent, the friendly name of the token it used. The other actors hold no token, so this is blank for them; a dash here is not a missing credential.
- Resources — the records the call touched, linked to their pages. A call that touched more than three shows a +n more count; click it to open the full list. A record deleted since the call was logged is still named, by kind, rather than disappearing.
- When — the time, in your timezone and date format.
You can filter by action, by type, by outcome, by token name, by resource, and by date range, and sort by action, token name, or time. Export downloads the log — see Export data; the arguments a tool sent are an optional column there, off by default.
Reads are logged as well as changes, so this answers both "what did this token change?" and "what did it look at?". Filter Type to Write for the change history on its own.
Sessions and connected devices
The Account page holds two lists, and they cover two different things.
Active sessions are the browsers and apps you are signed in to. From there you can:
- See each session with device info and when it was last active.
- Sign out any single device remotely.
- Sign out of every other device at once.
Connected devices are the apps holding a durable credential of their own — at present, only the browser extension. Disconnect revokes that device's credential, and it stops working on its next request. Revoked and expired devices stay listed so a device that stopped working can still be accounted for.
The two are separate on purpose: signing out of other sessions does nothing to a connected device's credential, and disconnecting a device does not end a browser session. If you are securing an account you no longer trust, do both.
When to use which
- "Who edited this client?" — start with the record's own history (Entity changelog). If a tool made the change, jump to the tool activity page and filter to the date.
- Forgot to sign out somewhere — open Active sessions on the Account page and sign that device out.
- Lost the machine the extension was installed on — open Connected devices on the Account page and disconnect it.
- Suspect a leaked token — open Integrations, revoke the token, then review recent activity here and filter to that token.
- Checking one tool's behavior — filter by action to see every time it happened, across all tokens.
Tips and edge cases
- Reads are here too. A token that only reads data still leaves an entry, so a credential that quietly listed your clients is visible rather than showing up only as a Last used timestamp.
- Refused calls are recorded. A tool a token was never granted, or a record outside its scope, leaves a row saying it was refused — which is what makes a credential probing its own boundaries something you can see.
- Tool activity is kept for a while, not forever. How long depends on your plan — see Retention. The records the calls touched are unaffected; only the log entries age out.
- Token names stick around. Entries keep showing a token's original name even after you revoke it, so you can still recognize "the old Cursor token" months later.
- This is an audit surface. Read it when you have a reason, not as a daily check.
- A bulk call lists every record it touched. The table shows the first few and counts the rest; the +n more dialog and the export both carry the full set.
On mobile
- Sessions are there. A Sessions screen (reached from mobile Account → Security) lists your active devices and lets you sign out a single device or all other devices. A separate Security screen handles password changes.
- The MCP events log is web-only. Review what connected tools have read and changed from the web app's MCP events page.