Skip to main content
Security policies are under Settings → Security → Policies. Each policy has a switch and its own settings, which open when you click the row.
Changing policy settings requires Collabase Enterprise. The default values apply on every installation, including Community.

Session lifetime

Controls how long a sign-in stays valid. This policy is always active and cannot be switched off. Both timers run at the same time, and whichever is reached first ends the session. With the defaults, someone who steps away for a full working day has to sign in again, and someone who works daily has to sign in again after a month.
Changes apply to people signing in from now on. Anyone already signed in keeps the limits that were set when they signed in.

Choosing values

1

Open Settings → Security → Policies

Click the Session lifetime row to open its settings.
2

Set the inactivity timeout

Shorter is safer, but people will be asked to sign in more often. 8 hours covers a working day. 30 minutes suits shared or public computers.
3

Set the maximum lifetime

This is the hard limit. Even someone using Collabase every day has to sign in again once it is reached.
4

Save

Click Save. The new values apply to the next sign-in.

Your active devices

Everyone can see where their own account is signed in, under Settings → Profile → Security. The list shows the browser and operating system, the last time each device was used, and marks the one you are using now. Click Sign out next to a device to end that session, or Sign out all other devices to end every session except the current one. The device is signed out the next time it makes a request. Use this after signing in on a computer that is not yours, or if you suspect somebody else has access to your account.

Brute-force protection

Locks an account after repeated failed sign-in attempts, so a stolen email address cannot be paired with guessed passwords. Locked accounts are listed under Settings → Security → Brute Force Protection, where you can release one early.

SSO bypass

When single sign-on is enforced, everybody is sent to the identity provider. This policy lets named people and groups sign in with an email address and password instead. Keep at least one administrator on this list. If the identity provider becomes unreachable and nobody can bypass it, nobody can sign in.
1

Turn the policy on

Click the switch in the SSO bypass row.
2

Add the people who need it

Search for users and groups, and select them. Administrators responsible for recovery belong here.
3

Generate the bypass link

Click Generate token, then copy the link and share it with the people you selected. Opening it shows the password sign-in form.
4

Save

Click Save.
Last modified on July 23, 2026