> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication policy

> What a password has to be, whether a second step is required to sign in, and who is currently signed in.

What a password has to be, what happens when somebody guesses wrong, whether a second step is
required, and how long being signed in lasts.

<Note>
  Nothing on this screen is enforced by the screen itself — every rule is applied by the server on
  every sign-in and every password change. What this screen does is describe the numbers, so an
  organisation that has never opened it is not an organisation with no policy: it is running on the
  product's own defaults until somebody changes them.
</Note>

## What a password has to be

Minimum length, and which character classes are required — a capital letter, a lower-case letter, a
digit, a symbol.

<Tip>
  A longer minimum costs an attacker more than requiring a capital, a digit and a symbol does — that
  combination tends to produce "Password1!" across a whole site. The character-class toggles are
  here for the security standard that requires them, not because they are the strongest choice
  available.
</Tip>

## What it may not be again

How many previous passwords are remembered, and the shortest time a new one must be kept before
being changed again — without a minimum age, someone can cycle through their history in a minute
and land back on the password you were stopping them reusing. Passwords can also be set to expire
after a number of days; left at zero, they never do.

## When somebody guesses

How many failed attempts lock an account, and for how long. Locking the wait can also double on
each repeat failure, up to a day, for the ordinary case where the same person still hasn't found
their password. An administrator clears a lockout from [people and access](/setup/access), and
doing so writes an audit row naming who cleared whose.

## Whether a password is enough

Two-step sign-in, for anybody signing in with a password:

| Setting | Effect |
| - | - |
| **Nobody is asked** | The product as it was before this existed |
| **Anybody may turn it on** | People set up an authenticator from their own profile; whoever has is asked for a code |
| **Everybody** | Anybody without one is asked to set it up at the sign-in screen — nobody is locked out |

Start with **Anybody may turn it on** rather than moving straight to **Everybody**: the middle
setting is what lets people enrol in their own time, ahead of the day it becomes required for
everyone.

Enrolling shows a QR code for an authenticator app and a set of recovery codes, shown once, on the
way in — not on a screen you have to sign in again to find. Each recovery code signs in once, and
is the way back from a lost phone that doesn't need an administrator.

<Note>
  This governs password sign-ins only. Somebody arriving through an identity provider is not asked
  again here — their second factor lives with their provider, administered by their own security
  team. See [identity providers](/setup/identity-providers).
</Note>

## How long being signed in lasts

| Setting | Answers |
| - | - |
| **Signed out after inactivity** | The session's real lifetime — enforced by the server, not a timer in the browser |
| **Signed out regardless, after** | The absolute cap, however active somebody has been |
| **Let a handset extend its session** | Off by default: a technician signs in once a shift. On, a handset that reaches the network pushes its own limit forward rather than signing out on a schedule it cannot see |
| **Sessions at once, per person** | Over the limit, the oldest session ends — so a lost tablet never blocks its replacement from signing in |

## Who is signed in

A live register of sessions — who, from where, since when — with an **End** action per row. Ending
a session refuses that token's next request; it is not the same as revoking a handset, which also
stops that device's sync and its ability to sign in again. For a lost handset, do both — see
[the Sync Center](/field/sync-center).

## Who can use this

Changing this policy needs the authentication permission, kept deliberately apart from general
configuration. Reading who is signed in, and ending a session, are governed separately again — see
[roles](/setup/roles).
