How to See Who Changed a Browser Profile
Filter MaskPilot activity records by browser profile and action, identify the operator and time, and understand what the history does not prove.
Updated Sep 1, 2026When an unexpected profile change appears without signs of ongoing unauthorized access, start by preserving the visible evidence and checking the activity record. MaskPilot records supported profile and team actions with the affected target, owner, operator, and time so the owner can narrow the investigation. If credentials may be exposed or an unauthorized action is still in progress, secure access first: stop the affected profile, remove the relevant access, and reset exposed credentials before continuing the investigation.
The record is an activity trail, not a field-by-field version history. It can show that a supported update occurred, but it does not display every value before and after the change, roll back the profile, or prove why the operator made it.
Filter the activity records
- Sign in as the profile owner and open Activity > Activity log.
- Select the affected profile. If the target is a member or another team resource, leave the profile filter at All profiles.
- Select an available action such as opening, closing, creating, updating, deleting, sharing, or changing a member permission. For an action that is not listed in the filter, keep All actions selected and narrow the result by target and time instead.
- Check the affected target, owner, operator, and timestamp in each matching row.
- Clear one filter at a time if no row appears, then refresh before drawing a conclusion.
Start with the narrowest known fact: the profile name, approximate time, or type of change. Comparing that result with the current member assignments and permissions is more reliable than searching every action at once.
Understand who can see which records
The owner can review activity within the owner’s team scope. A team member sees only the activity attributed to that member, not the owner’s complete team history. If a member needs help investigating another person’s action, the owner must review the owner-scope records.
The team page also provides a recent member activity summary. Use that summary to identify a likely member or recent profile launch, then use Activity log for the profile and action filters.
What the record can and cannot answer
Use the record to answer:
- Which supported action was recorded.
- Which profile, member, or other visible target it affected.
- Which account owned the target and which account performed the action.
- When the action was recorded.
Do not treat it as proof of:
- The exact old and new value of every changed field.
- A complete screen recording, website activity history, or browser session history.
- An automatic rollback point or an immutable compliance archive.
- The absence of any change merely because the current filters return no row.
If the action involved a request that still needs review, activity and approval history answer different questions. Use the pending team action checklist to confirm who requested the action, its current approval state, and the review result.
Investigate an unexpected change safely
- Record the profile name, approximate time, visible symptom, and current filters.
- Compare the operator with the member currently assigned to the profile.
- Check whether that member still has the permission required for the recorded action. If visibility is correct but editing fails, follow the member cannot edit a profile checklist.
- Ask the operator to confirm the task and time without exchanging website passwords, session data, proxy credentials, or full screenshots containing private data.
- For routine access cleanup, change assignments or permissions after comparing the record with the current access state. If unauthorized access may be active, contain it first even when no matching record appears.
The OWASP logging guidance recommends recording the when, where, who, and what needed for investigation while excluding secrets and other sensitive data. Apply the same discipline when sharing MaskPilot diagnostic material: include the relevant action and time, but redact credentials, cookies, tokens, and unrelated personal information.
If no matching record appears
Clear the profile and action filters, refresh the page, and confirm that the action is one MaskPilot exposes in Activity log. A member should ask the owner to check the wider team scope. If the owner still cannot identify the event, preserve the exact time, affected profile name, visible result, and page message for support; do not infer that no change occurred from an empty filtered result alone.