Feature Request – Auto-Logout for Inactive Sessions (Security Enhancement)

I am writing to formally request the introduction of a configurable auto-logout feature for inactive user sessions within the Upmind platform, both for client and admin areas.

As our organisation places a high priority on data security and compliance, it is essential for us to ensure that accounts are not left vulnerable due to unattended sessions, especially in shared or public environments. The ability to automatically log out users after a defined period of inactivity is widely considered an industry standard for platforms handling sensitive customer and business data.

Implementing such a feature would not only enhance the security posture of all Upmind clients but also align the platform with best practices and regulatory requirements in various jurisdictions (including GDPR, PCI DSS, and others). Ideally, this setting should be customisable per organisation, allowing administrators to define the inactivity timeout period according to their risk profile and internal policies.

We strongly believe that enabling automatic session termination after user inactivity would significantly mitigate risks related to unauthorized access, and would be a valuable addition to the already robust security toolkit provided by Upmind.

Thank you in advance for considering this enhancement. We would appreciate any information regarding the roadmap or possible timelines for such an implementation.

Feature Request
Configurable Auto-Logout for Inactive Sessions
How Would You Use This in Upmind?
We would use this feature to automatically log out users (both clients and staff) after a configurable period of inactivity in the Upmind portal. This is essential for preventing unauthorized access to sensitive account information, especially in shared, public, or high-turnover environments. Ideally, administrators should be able to set the timeout duration according to internal security policies.
What problem does this solve for you?
Currently, there is no way to ensure that unattended sessions are terminated, leaving accounts potentially vulnerable if a user forgets to log out, especially on shared or public computers. The lack of this feature increases the risk of unauthorized access to customer data and sensitive business information.
Impact of not having this feature
Without this feature, our security posture is significantly weakened, and we may fall short of best practice or even compliance requirements (GDPR, PCI DSS, etc). It also exposes our clients and staff to unnecessary risk, which could ultimately harm trust in the platform and affect our willingness to use Upmind for mission-critical tasks.

Please authenticate to join the conversation.

Upvoters
Status

Later (Planned)

Board

Support System

Date

8 months ago

Author

ZEBRABYTE

Subscribe to post

Get notified by email when there are changes.