Security and sessions

Session lifetimes, ending sessions, and the security practices worth insisting on.

Written for
Administrators
Reading time
1 min
Last reviewed
August 3, 2026

Sessions are short-lived by design and refreshed transparently while a user is working. Idle sessions expire, and any session can be ended by an administrator.

Ending sessions

Ending a user's sessions signs them out everywhere immediately. Do it whenever a role changes, when a device is lost, and as part of offboarding.

Worth insisting on

  • MFA for every account that can reach billing configuration or user management.
  • One account per person. Shared logins destroy the attribution that makes the audit trail worth having.
  • Deactivation as part of offboarding, on the same day, not at the end of the month.
  • Periodic review of who holds tenant admin. It grows quietly.

Related

Still stuck?

Technical documentation

API references, data model, webhook payloads and integration guides — the detail behind the workflows described here. Available to signed-in Naveera customers.

Open documentation

Ask your team

Support requests are raised from inside Naveera Console, where your organization and your role are already known — which means the answer can be about your configuration rather than the general case.

Settings → Support, or ask your organization’s administrator