Concepts
Sessions and idle sign-out
How long you stay signed in, what the inactivity warning means, and how admins set the policy.
HRS Triage signs you out when you step away, and tells you before and after it happens.
What you will see
- Two minutes before an idle sign-out, a dialog asks Are you still there? with a countdown.
- Stay signed in keeps working. Pressing Escape does the same.
- Sign out now ends the session immediately.
- If nobody answers, you are signed out and the sign-in page says You were signed out after N minutes of inactivity.
- Every session also ends 12 hours after sign-in, whatever you are doing. The dialog warns you before that too, and the sign-in page then says Your session expired.
What counts as activity
Typing, clicking, scrolling and touching the page count. Pages that refresh themselves (notifications, the live Threat origins map) do not, so an unattended screen is still signed out. Activity in another Triage tab keeps every tab signed in. A dropped connection never signs you out by itself: the countdown only runs once the server has confirmed your session.
For admins: set the policy
Settings → General → Session security → Idle timeout. Choose 15 minutes, 30 minutes (recommended), 1, 4 or 8 hours, or no idle timeout (not recommended). The policy applies to everyone, so only HRS staff (global admins) change it; organization and MSP admins see it read-only. Every change is audited.
If a link on another website tries to sign you out, HRS Triage asks you to confirm first.
Signing in again after a timeout counts like any sign-in: repeated wrong passwords lock the account. See Locked out.