Activity log and blocking bookers
See what changed and who did it — and stop a problem customer rebooking.
Booked keeps a running record of the changes people make — who did it, when, and from where. It also keeps a list of people who are no longer allowed to book with you online. Both live under Settings, and neither is quite where most people go looking first.
Where the Activity log lives
Open Settings from the Booked menu, then pick Activity — the last tab down the left-hand rail. The sub-line changes to "Every change made in Booked — who did what, and when." so you know you have arrived. The tab is read-only, so it has no Save settings button, and neither do Your plan or Calendar sync. That is deliberate, not a fault.
Nothing is trimmed on a schedule, so the log reaches back to the day Booked was installed. It shows 50 rows a page, newest first, with Previous / Next and a "Page 1 / 7" counter underneath.
Every change made in Booked — who did what, and when.
| When | Who | What | Type | IP |
|---|---|---|---|---|
| 26 Aug 2026, 16:12 | Priya Sharma | Changed status: confirmed → cancelled Emily Carter · 28 Aug, 09:30 | booking | 92.40.18.7 |
| 26 Aug 2026, 15:58 | System | Blocked booking attempt — matched email “m.reed@example.com”. | booking | 203.0.113.4 |
| 26 Aug 2026, 11:03 | Oliver Ball | Service “Travel vaccination” updated Service #7 | service | 92.40.18.7 |
| 26 Aug 2026, 09:41 | System | Online booking by Daniel Okafor — Flu jab on 2026-09-02 at 10:15 Daniel Okafor · 2 Sep, 10:15 | booking | 81.132.6.22 |
| 25 Aug 2026, 18:20 | Priya Sharma | cURL error 28: Operation timed out after 60001 milliseconds — transport | error | 92.40.18.7 |
Settings › Activity log — the whole audit trail, newest first.
- 1Activity — the last tab in the rail. There is no Save settings button while you are on it.
- 2Search by person, action… — matches the message, the staff member's name and the internal action name. It waits a moment after you stop typing before it searches, and puts you back on page 1. It does not search the grey second line.
- 3Everything · Changes · Errors — Changes hides the error rows, Errors shows nothing else. Switching filter also resets you to page 1.
- 4The change itself — one plain sentence, with a second line naming the record it happened to. For a booking that is the customer plus the appointment date and time.
- 5An error row — highlighted and tagged in red. These are failures Booked caught behind the scenes, while whoever was on screen saw only a short, friendly message.
Reading a row
| Column | What it holds |
|---|---|
| When | Date and time of the change, in your site's own time — the timezone WordPress is set to, not the one on Settings › Region & currency. If you have those two set differently, this column follows WordPress. |
| Who | The display name of the WordPress user who was signed in. It reads System when nobody was — a booking made on your public form, or a scheduled job such as the daily digest email. |
| What | The change in plain words, plus a second line naming the record. Customer rows are named at the moment you read them, so if that person has since been deleted the name disappears. The search box does not look at this second line. |
| Type | The kind of record touched — booking, customer, service, settings and so on. Errors are badged in red. |
| IP | The address the request came from — useful for spotting repeat attempts from one place. |
Editing a booking writes one row per field you actually changed, so one save can produce several lines — "Changed time: 09:30 → 10:15", "Changed price: £45.00 → £35.00". Save a booking without changing anything and nothing is written at all.
Every edit to an appointment is logged, but deleting one outright from Bookings writes no entry at all — so the log will never tell you who removed it. The earlier rows about that appointment stay, but they lose the second line naming it, because the appointment they pointed at is gone. If you want to be able to answer "what happened to that one?" later, set it to Cancelled rather than deleting it.
Answering "who cancelled this?"
- Go to Settings, then ActivityThe log opens on Everything, newest first, so a cancellation from this morning is usually on the first page.
- Search for the change, not the customerType cancelled into Search by person, action…. The search reads the message text and staff names — it does not read the grey second line, so the customer's name will not find a cancellation on its own.
- Look for the status changeThe row you want reads "Changed status: confirmed → cancelled", with the customer's name and the appointment's date and time on the second line so you know it is the right one.
- Read the Who columnThat is the member of staff who did it. If it says System, the change did not come from anyone signed in to your admin.
The same trick answers the other awkward questions — search the words Booked writes, not the person they are about. Changed time finds who moved an appointment, Changed price who dropped a price, Changed customer who reassigned a booking, and Deleted a note who removed a note. Customer names do appear in some messages — "Online booking by Daniel Okafor", "Changed customer: Emily Carter → Daniel Okafor" — so searching a name is still worth a try, it just will not catch everything.
The Activity tab sits behind the same permission as the rest of Settings. A member of staff who can manage bookings and customers still cannot open it — so if a colleague says the tab isn't there, that is why.
The Errors filter, and when to use it
Pick Errors when something quietly did not work. These rows hold the real, technical reason behind a friendly on-screen message — an AI write-up that never came back, an analysis that failed, a deposit the payment step could not start. They are written in the language of the thing that broke, not in plain English, so expect timeouts and status codes rather than sentences.
Who is whoever's request ran into the problem. If a member of staff was signed in when it happened — asking for AI notes, running an analysis — their name is on the row. It reads System only when the failure came from the public booking form, where nobody is signed in.
When a customer is turned away, Booked shows them a short reference code after the apology, such as "(ref: GB-PAY-VERIFY)". Ask for that code, select Errors and paste it into the search box, and you land on the row that says what actually went wrong.
Blocking someone from booking
The blocklist is not its own tab. It is the last card on Settings › Booking rules, under Blocked from booking — scroll past Booking rules, Deposits, Booking references, Bank statement name, Appointment bundles and Group bookings and it is at the bottom. People hunt for it under Activity or Customers and give up; it is here.
Configure how Booked works.
Booking rules · Deposits · Booking references · Bank statement name · Appointment bundles · Group bookings
Blocked from booking
Stop specific emails, email domains, IP addresses or IP ranges from making a booking. Blocked attempts are turned away with a neutral message and recorded in the Activity log.
| Type | Value | Reason | |
|---|---|---|---|
| m.reed@example.com | Three no-shows, abusive on the phone | Remove | |
| Domain | mailinator.com | Throwaway addresses — fake travel-clinic bookings | Remove |
| IP range | 203.0.113.0/24 | — | Remove |
Settings › Booking rules — the blocklist sits at the bottom of the tab.
- 1Bookings — the tab the blocklist lives on. There is no "Blocklist" tab of its own.
- 2Type — Auto-detect, Email address, Email domain, IP address or IP range (CIDR). Auto-detect reads what you typed: a slash means a range, a valid IP means an IP, an @ with a dot means an email, and anything else is treated as a domain.
- 3Value — the address, domain, IP or range to bar. Pressing Enter here adds it. Anything Booked cannot make sense of is refused with "That doesn’t look like a valid email, domain, IP or range."
- 4Add to blocklist — takes effect the moment you press it. This card saves itself, so the page's Save settings button has nothing to do with it.
- 5Remove — lifts the block immediately, with no confirmation step.
Add the same thing twice and nothing happens — no duplicate row, no error, no confirmation. It looks as though the button did not work, but the entry is already there in the table below.
Booked blocks on the address your web server reports. If your site sits behind a CDN, a proxy or a load balancer, that can be the proxy's address rather than the visitor's — so an IP block may miss the person you meant and turn away everyone else arriving the same way. Blocking the email address is the safer choice. Blocking a whole domain bars everyone who uses it, which is right for a throwaway-mail domain and badly wrong for a common one.
What the blocked person sees
Nothing that tells them they are blocked. They fill in the form as usual, and when they try to book they get one neutral line. Expect a phone call rather than a complaint — which is normally what you want.
The message a blocked booker gets on your public form.
- 1The refusal — deliberately vague, and shown before anything is written: no appointment is created, no customer record is touched and no payment is taken. The code on the end is the giveaway — if someone rings quoting GB-BLOCK, they are on your list. Meanwhile a row appears in your Activity log reading "Blocked booking attempt — matched email “m.reed@example.com”."
One turned-away attempt actually writes two rows, not one. The plain "Blocked booking attempt" row is badged booking, and alongside it goes an error row carrying the same detail and the GB-BLOCK code. So blocked people show up under Errors as well as under Changes — worth knowing before you assume the error filter is showing you a fault.
What blocking does not do
- It only guards the public booking form. You or your staff can still create a booking for that person inside Booked — useful when you will take them by phone but not let them book themselves.
- It does not cancel anything. Appointments they have already made stay in the diary. Cancel those yourself from Bookings.
- It does not touch their customer record. Their history, notes and documents stay exactly where they were.
- Marking a customer "Inactive" is not a block. That field is a private marker and nothing reads it — it will not stop anyone booking. The blocklist is the only thing that does.
Lifting a block
Go back to Settings › Booking rules, find the row and press Remove. It goes at once — there is no "are you sure?" and no undo, so check you are on the right row first. Take the last entry away and the card returns to "Nothing is blocked. Anyone can book."
Both halves of this are recorded. Adding writes "Added a booking blocklist entry." and removing writes "Removed a booking blocklist entry.", each with your name against it — so if a blocked customer suddenly gets through, the Activity log will tell you who let them.