Sessions
How long a Bedrock GRC sign-in lasts, the two timeouts admins set, seeing and signing out your sessions, and everything else that ends a session.
Signing in starts a session in that browser. A session ends when you sign out, when one of the two timeouts below runs out, when you close the browser, or when something on this page ends it for you.
The two timeouts
Admins set both on the Team page, in the Sign-in security card under Session timeouts, and choose that row's Save:
| Setting | What it does | Range | Default |
|---|---|---|---|
| Sign out after inactivity | Ends a session after this many minutes without any request from it. Using Bedrock GRC keeps it alive. | 5 to 480 minutes | 30 minutes |
| Sign out after sign-in | Ends a session this many hours after you signed in, however active it is. | 1 hour up to a ceiling set for the deployment | 12 hours |
Your admins may have chosen other values; the Team page shows the ones in force. A change applies to every open session from its next request, so lowering a timeout signs out sessions that are already past it.
There is no countdown before a timeout. If your session has ended when you save a form, you are taken to the sign-in page and what you typed is not saved, so save long edits as you go.
The session cookie is not kept after the browser closes: closing the browser also signs you out.
Where you are signed in
Account → Where you are signed in lists every live session of yours:
| Column | What it shows |
|---|---|
| Device | The browser and system, such as "Chrome on macOS". This session marks the one you are using. |
| Address | The network address the session was opened from. |
| Signed in | When the session started, in your practice's time zone. |
| Last active | When it was last used. |
- Sign out on a row ends that session. Whoever is using it has to sign in again.
- Sign out other sessions ends every session except this one.
- Sign out at the foot of the sidebar ends this session.
If you see a session you don't recognize, sign it out, change your password and tell an admin.
What else ends sessions
| Event | Sessions ended |
|---|---|
| You change your password | Your other sessions. Your calendar feed is turned off too. |
| You turn on two-step sign-in, or move it to a new phone | Your other sessions. |
| An admin resets your password or your two-step sign-in | All of yours, and your calendar feed. |
| An admin chooses Sign out everywhere in your row's menu on the Team page | All of yours. |
| An admin disables or offboards your account | All of yours. You cannot sign in again until the account is enabled. |
| An admin changes your firm's single sign-on issuer, client ID or either rule, or removes single sign-on | All sessions of people in the firm who have linked their account, except the session the change is made from. Changing only the email domains or the client secret ends no session. See Single Sign-On. |
| An admin unlinks your single sign-on account | All of yours. |
A role change takes effect at your next request without signing you out. An account lockout does not end sessions that are already open; it stops new sign-ins, with a password or through single sign-on, except from a browser the person has signed in from before. Being asked to choose a new password because yours falls short of the password policy ends no session either; choosing it then signs out your other sessions, as any password change does.
Every sign-in, sign-out and session ended this way is written to the audit log.
Admin controls
On the Team page, admins:
- set the two timeouts;
- see each person's last sign-in;
- choose Sign out everywhere in anyone else's row menu, after a confirmation.
See Team and Roles.
Client portal sessions
People at a client who open a portal link get a separate portal session of up to 12 hours that never outlives the link. Revoking the link ends it at once. See The Client Portal.