Overview
The session lifetime policy limits how long users can remain signed in. It is configured separately for each organization and applies to both new and existing sessions. You need the Manage authentication (authenticationManage) permission to
view or change this policy. Platform authentication providers remain restricted
to platform Super Admins.
Configure session limits
1
Open Authentication settings
Go to Settings → Authentication and find Session Lifetime Policy in
the Security Policy card.
2
Select the organization
Platform Super Admins can select an organization. Other authorized
administrators can manage only their current organization.
3
Set the idle timeout
Enter the maximum period of inactivity before CaseBender requires the user
to sign in again. The allowed range is 5–1,440 minutes. The default is
30 minutes.
4
Set the absolute lifetime
Enter the maximum total age of a session, even while the user remains
active. The allowed range is 60–10,080 minutes. The default is
480 minutes (8 hours).
How enforcement works
- Activity refreshes the idle timer but never extends the absolute lifetime.
- CaseBender evaluates protected page and API requests against the current organization policy.
- A policy reduction also applies to sessions that were created before the change.
- When either limit is reached, the server revokes the session and requires a new sign-in.
- Policy updates can take up to 60 seconds to propagate to every application process.
A page already displayed in a browser does not disappear at the exact timeout
instant if it makes no server requests. The next protected navigation, data
refresh, or action is rejected and requires sign-in.
Recommended starting points
- Use a shorter idle timeout for privileged or shared-workstation users.
- Keep the absolute lifetime within a normal work shift unless your security policy requires a shorter period.
- Test policy reductions with a non-production account before applying them to a large organization.
- Coordinate these limits with your identity provider’s own session and single-sign-on policies. The shortest effective limit can require the user to authenticate again.
Troubleshooting
The policy controls are not visible
Confirm that your effective role includesauthenticationManage and that you
are using an internal account. External collaborators cannot access
Authentication settings.