Session security — automatic logout and exclusions
Automatic logout is off by default and applies company-wide. The exclusion list looks minor, but it is the most common source of confusion, even for administrators.
Go to Settings → System → Session security. Only a company administrator can change these settings, and a fresh two-factor confirmation is required. Other roles see a read-only screen.
1. The setting is for the company, not a person
The Automatic logout after inactivity switch and minutes field apply to the whole company. There are no per-user or per-device settings — only one value and a list of exceptions.
The feature is off by default. A company where nobody has enabled it does not log anyone out.
The value applies to the company you currently have active. Two companies have two independent settings.
2. Exclusions — the most common source of confusion
You can exclude people and roles from automatic logout. Excluded users will never see a warning or be logged out for inactivity.
Administrators often appear on this list, usually through a role rather than a name, because the entire “Admins” role can be excluded with one click. In that case:
You are excluded, but the setting still applies to the rest of the company.
The screen says this directly: a blue notice above the form says your account is excluded and that the settings below apply to other people. If you see it, do not conclude from your own experience that the feature is off; check the switch.
Exclusions are not removed when the feature is switched off. The list remains visible and saved while the switch is off. Turning automatic logout back on restores the entire list.
3. Value ranges
| Setting | Range |
|---|---|
| Inactivity period | 1–1440 minutes |
| Warning before logout | 5–3600 seconds, always shorter than the inactivity period |
| Trusted device (2FA) | 1–365 days |
A value outside the range is rejected with a message beside the relevant field. The maximum inactivity period matters: without it, a sufficiently large value would not fit in the browser timer, and “log out after a very long time” would become “log everyone out immediately”.
4. When changes take effect
A saved change applies immediately to new logins. Already-open tabs and terminals learn about it within five minutes by polling the server, or immediately if the change was made in another tab in the same browser.
5. The browser runs the countdown
The countdown runs in the user’s browser tab, and that tab ends the session. One consequence: a session that could not finish logging out stays open. If the browser crashes, the handheld loses coverage, or its cover closes, logout cannot run.
Close such sessions manually. Each user can see their devices under My profile → Security and revoke each one or sign out everywhere.
6. What this setting does not cover
- The time-clock kiosk (punch screen at
/kiosk) is shared by the entire shift. It has its own Automatic logout setting at the kiosk, but that only returns to the start screen; it does not end the session. - Technical accounts (automations, integrations, and external programs such as n8n) do not log in or have sessions. Programs connect with the API token of their technical account (Settings → Company data → API access).
7. Audit trail
Every change on this screen creates an audit-log entry showing who changed what and when, including before and after values. This also covers disabling trusted devices, which revokes all trusted devices for the company; the number revoked appears in the same entry.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo