Sessions
Session controls help protect workspace access after users authenticate. Bitaic records session lifecycle events, supports inactivity expiration, lets users log out manually, and gives Admins controls for reviewing and revoking active sessions.
Session Controls
- Inactivity expiration ends stale sessions after the configured security window.
- Manual logout ends the current user session.
- Admin revocation can terminate sessions during account recovery, offboarding, or suspected compromise.
- Session and device review helps users and Admins identify unfamiliar access.
- Session lifecycle events are recorded in the audit log for security review.
Account Protection
- Enable MFA for user accounts that administer users, service tokens, webhooks, integrations, exports, or security settings.
- Review active sessions after password resets, role changes, token changes, or suspicious login activity.
- Revoke sessions during offboarding or when a user no longer needs workspace access.
Audit Coverage
Session audit events include session creation, timeout, manual logout, and Admin termination. Session records use the active audit retention baseline unless workspace policy or contract sets a different period.
Best Practices
- Use MFA for accounts with administrative access.
- Log out of shared or temporary devices when work is complete.
- Review session history as part of access reviews.