Skip to content

User Profile Views

Papershift keeps an audit trail of who looked at a user’s personnel file fields. Every time a signed-in actor attempts to access an area of the employee file, a profile view record is stored with the area, how many fields were involved, and whether access was granted or denied. Field values are not stored.

Attribute Description Specifics
user_id The ID of the user whose file was viewed.
actor_id The ID of the user who attempted the view.
actor_email The email of the actor at that time. Denormalized, does not change
area The personnel file area that was accessed. One of general, master_data, master_data_sensitive, payroll_info
field_count How many fields were involved in the view. Non-negative integer
access_denied Whether the attempt was refused. Boolean
created_at When the view was recorded.

Relationships

Relationship Description
user The user whose file was viewed
actor The user who attempted the view (if still resolvable)

Example response:

{
"data": [
{
"id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"type": "profile_view",
"attributes": {
"user_id": "b7f8d3a9-6c5e-4e5c-9d8f-7b6c96d4e3c2",
"actor_id": "c2d3e4f5-6789-0abc-def1-234567890abc",
"actor_email": "jane.doe@example.com",
"area": "master_data",
"field_count": 28,
"access_denied": false,
"created_at": "2026-01-15T10:00:00.000Z"
}
},
{
...
}
]
}

This endpoint returns the profile view history for a user. Results are not sorted by default; use sort=-created_at to get the most recent views first.

For a merged timeline of views and field changes with correct pagination, use User Profile Histories instead.

GET /api/v1/users/:user_id/profile_views

Parameter Description
user_id The ID of the user whose profile view history to return.

In addition to the standard filter syntax, this endpoint supports filtering by one or more actor IDs, area, whether access was denied, and a date range:

Filter by the IDs of users who attempted views: GET /api/v1/users/:user_id/profile_views?filter[actor_id]=in:actor-id-1,actor-id-2

Filter by area: GET /api/v1/users/:user_id/profile_views?filter[area]=eq:master_data

Filter by access denied: GET /api/v1/users/:user_id/profile_views?filter[access_denied]=eq:false

Filter by a date range (combine both bounds as needed): GET /api/v1/users/:user_id/profile_views?filter[created_at_gteq]=2026-01-01&filter[created_at_lteq]=2026-01-31

This endpoint’s results are also paginated, see the pagination section for details.

Authorization uses the same account right as profile changes: profile_change.read.

Example response:

{
"data": {
"id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"type": "profile_view",
"attributes": {
"user_id": "b7f8d3a9-6c5e-4e5c-9d8f-7b6c96d4e3c2",
"actor_id": "c2d3e4f5-6789-0abc-def1-234567890abc",
"actor_email": "jane.doe@example.com",
"area": "master_data",
"field_count": 28,
"access_denied": false,
"created_at": "2026-01-15T10:00:00.000Z"
}
}
}

This endpoint returns a single profile view entry.

GET /api/v1/users/:user_id/profile_views/:profile_view_id

Parameter Description
user_id The ID of the user
profile_view_id The ID of the profile view entry to return