Published
The “Security” screen: open sessions, known devices and an address limit
Everyone sees their own open sessions and can end them, the office owner sees the sessions of every member of staff, and a sign in from an unknown device sends an email.
“Who is working in the system under my name right now, and from where” was a question with nothing to answer it. There is now a Settings → “Security” screen, marked with a padlock, where every user sees two lists of their own: their open sessions and the devices the system already knows.
Each open session says which device it was opened from, that is the browser and the operating system, from which address on the network, and when it was last active. The session you are reading this from is marked “this session”, so that you do not end yourself by mistake. Any other session can be ended with one click, there is a “Sign out on all other devices” button, and a device can be dropped from the list with “forget device”.
A sign in from a new device is remembered: a protected mark is set in the browser for 400 days, and from then on the system recognises that device. If the sign in came from a device that is not known, the user gets an email at their own address: the browser and the operating system, the address, the time in the office time zone, and what to do if it was not them, which is to change the password and end the sessions. The very first sign in of a new member of staff sends no such email, because there is nothing to compare it with yet.
The office owner has a view of all the staff on the same screen: how many live sessions each of them has and when they last signed in. One click ends every session of one person, on the day they leave the office for instance. A defect was fixed along the way: until now archiving a member of staff left their open session open.
The owner can also limit access to the panel by address: up to 20 IPv4 addresses or subnets. An empty list means there is no limit. There is a safeguard against locking yourself out: a list cannot be saved unless it contains the address the owner is working from at that moment. Anyone trying to sign in from another address sees a page saying “Access from this address is closed by the office settings”.
- The Lidin operator is not covered by the limit. If the office does lock itself out, the block can be lifted.
- Mobile network addresses change on their own. The limit is worth turning on only when the office has a fixed address or a VPN.
- Every action on the screen is written into the access log, without personal data.
The screen adds no step to the daily sign in and needs no setting up: it answers a question that was left open and puts the button next to it. The help section has an article covering everything described here.
Want to see this on your own office's inquiries?