Security Settings

Last updated: 31 March 2026

Security Settings

Security settings control how users authenticate, how long sessions last, and whether role-based access control is enforced.

How to Get There

Navigate to Settings > Security.

Inactivity Lock Screen

Set how long a user can be idle before the screen locks. Options: 5, 10, 15, or 30 minutes, 1 or 2 hours, or Disabled.

When locked, users must re-authenticate using one of the allowed unlock methods:

  • Password
  • MFA (Authenticator app)
  • Google SSO
  • Microsoft SSO

At least one unlock method must remain enabled.

Automatic Logout

Set how long before an idle user is fully signed out. Options: 30 minutes, 1 hour, 2 hours, 4 hours, 8 hours, or Disabled.

This is different from the lock screen - logout requires the user to sign in again from scratch. A warning is shown if the logout timeout is shorter than the lock timeout.

Two-Factor Authentication (MFA)

Toggle to require MFA for all users in your organisation. When enabled:

  • Users without MFA set up are blocked from accessing the app until they configure it
  • An MFA Compliance Report appears showing each user's MFA status, enrolment date, and last verification
  • The overall compliance percentage is displayed

Allow SSO to bypass MFA: When enabled, you can add trusted email domains (e.g. company.com). Users signing in via Google or Microsoft from those domains skip the MFA step. Adding a domain does not grant access - users still need an invitation.

Role-Based Access Control (RBAC)

Toggle to enforce RBAC. When off, all members have full access to everything. When on, users can only perform actions allowed by their assigned roles.

A warning appears if any users have no role assigned when you enable RBAC - those users will have no permissions until a role is assigned.

Important: All security setting changes are logged in the audit log with their risk level. Review the audit log after making changes to confirm they were applied correctly.