Security & Sessions

Session, lockout, and password policies that protect local accounts.

SessionsLockoutPassword policySecurity

Rapid BI Catalog enforces a set of fixed session and password policies. The session and lockout controls apply to everyone; the password-history and rotation rules apply to local accounts (SSO accounts follow your Identity Provider).

Idle Timeout

Sessions time out after 15 minutes of inactivity. This is fixed and not admin-configurable; idle timeouts are recorded in the audit log.

Session Revocation

  • Changing a user's password revokes that user's other active sessions.
  • Changing a user's role revokes that user's active sessions.

Account Lockout

After 5 failed sign-in attempts, the account is locked for 15 minutes. Attempts are tracked per-email and per-IP.

Password Policy (Local Accounts)

  • No reuse of the last 12 passwords.
  • Forced rotation every 90 days — past 90 days the user is blocked at login until they change their password.
  • SSO accounts are exempt — the Identity Provider owns the credential lifecycle.

Next Steps