Rapid BI Catalog enforces a set of fixed session and password policies. The session and lockout controls apply to everyone; the password-history and rotation rules apply to local accounts (SSO accounts follow your Identity Provider).
Idle Timeout
Sessions time out after 15 minutes of inactivity. This is fixed and not admin-configurable; idle timeouts are recorded in the audit log.
Session Revocation
- Changing a user's password revokes that user's other active sessions.
- Changing a user's role revokes that user's active sessions.
Account Lockout
After 5 failed sign-in attempts, the account is locked for 15 minutes. Attempts are tracked per-email and per-IP.
Password Policy (Local Accounts)
- No reuse of the last 12 passwords.
- Forced rotation every 90 days — past 90 days the user is blocked at login until they change their password.
- SSO accounts are exempt — the Identity Provider owns the credential lifecycle.
Next Steps
- Roles & permissions: User Roles & Access Control
- Reset a password: Password Reset
- Multi-factor authentication: Multi-Factor Authentication