Security Settings
The Security tab configures password policies, authentication, and QC email notifications. Only the Lab Director role has access.
Navigation: Settings → Security
Passwords & Login
| Field | Description |
|---|
| Minimum password length | Minimum number of characters |
| Password expiry (days) | Days until password expires (0 = no expiry) |
| Session timeout (minutes) | Auto-logout after inactivity (0 = disabled) |
| Max failed login attempts | Failed logins before account lockout |
| Lockout duration (minutes) | How long the account stays locked |
Authentication
| Field | Description |
|---|
| Mandatory MFA | All users must enable an authenticator app |
| MFA reminder | Shows a reminder at login if MFA is not enabled |
| E-signature on approval | Requires password re-entry when approving an analysis |
| Password re-entry on approval | Requires password for every approval action |
Audit Trail
| Field | Description |
|---|
| Audit log retention (days) | How long audit records are kept (0 = forever) |
Email Notifications
| Field | Description |
|---|
| Enable notifications | Turns email notifications on or off |
| QC frequency | How often QC notifications are sent (Daily / Weekly) |
| QC send time | The time of day QC notifications are sent |
| QC recipients | Who receives notifications (Quality Manager / All Users) |
For ISO 17025 compliance, enable MFA and e-signatures.
Only the Lab Director (LAB_DIRECTOR) role can change security settings.