Skip to content
Foxx Cyberfoxxcyber/docs

Sessions

How long a Bedrock GRC sign-in lasts, the two timeouts admins set, seeing and signing out your sessions, and everything else that ends a session.

Signing in starts a session in that browser. A session ends when you sign out, when one of the two timeouts below runs out, when you close the browser, or when something on this page ends it for you.

The two timeouts

Admins set both on the Team page, in the Sign-in security card under Session timeouts, and choose that row's Save:

SettingWhat it doesRangeDefault
Sign out after inactivityEnds a session after this many minutes without any request from it. Using Bedrock GRC keeps it alive.5 to 480 minutes30 minutes
Sign out after sign-inEnds a session this many hours after you signed in, however active it is.1 hour up to a ceiling set for the deployment12 hours

Your admins may have chosen other values; the Team page shows the ones in force. A change applies to every open session from its next request, so lowering a timeout signs out sessions that are already past it.

There is no countdown before a timeout. If your session has ended when you save a form, you are taken to the sign-in page and what you typed is not saved, so save long edits as you go.

The session cookie is not kept after the browser closes: closing the browser also signs you out.

Where you are signed in

Account → Where you are signed in lists every live session of yours:

ColumnWhat it shows
DeviceThe browser and system, such as "Chrome on macOS". This session marks the one you are using.
AddressThe network address the session was opened from.
Signed inWhen the session started, in your practice's time zone.
Last activeWhen it was last used.
  • Sign out on a row ends that session. Whoever is using it has to sign in again.
  • Sign out other sessions ends every session except this one.
  • Sign out at the foot of the sidebar ends this session.

If you see a session you don't recognize, sign it out, change your password and tell an admin.

What else ends sessions

EventSessions ended
You change your passwordYour other sessions. Your calendar feed is turned off too.
You turn on two-step sign-in, or move it to a new phoneYour other sessions.
An admin resets your password or your two-step sign-inAll of yours, and your calendar feed.
An admin chooses Sign out everywhere in your row's menu on the Team pageAll of yours.
An admin disables or offboards your accountAll of yours. You cannot sign in again until the account is enabled.
An admin changes your firm's single sign-on issuer, client ID or either rule, or removes single sign-onAll sessions of people in the firm who have linked their account, except the session the change is made from. Changing only the email domains or the client secret ends no session. See Single Sign-On.
An admin unlinks your single sign-on accountAll of yours.

A role change takes effect at your next request without signing you out. An account lockout does not end sessions that are already open; it stops new sign-ins, with a password or through single sign-on, except from a browser the person has signed in from before. Being asked to choose a new password because yours falls short of the password policy ends no session either; choosing it then signs out your other sessions, as any password change does.

Every sign-in, sign-out and session ended this way is written to the audit log.

Admin controls

On the Team page, admins:

  • set the two timeouts;
  • see each person's last sign-in;
  • choose Sign out everywhere in anyone else's row menu, after a confirmation.

See Team and Roles.

Client portal sessions

People at a client who open a portal link get a separate portal session of up to 12 hours that never outlives the link. Revoking the link ends it at once. See The Client Portal.

Last updated October 9, 2026