Security Settings
The Security tab configures password policies, authentication, and QC email notifications. Only the Lab Director role has access.
Navigation: Settings → Security & Access → Security
The foundations of authentication are not set per laboratory. They appear at the top of the page as a statement rather than as fields:
| Rule | Value |
|---|
| Minimum password length | 8 characters |
| Account lockout | after 5 failed attempts, for 15 minutes |
| Password storage | argon2 |
| Session | one active session, lasting 8 hours |
This is deliberate: a security floor every laboratory can relax is not a floor. If you need these numbers for your own documentation, they are here.
Passwords & Login
| Field | Description |
|---|
| Password expiry (days) | Days until password expires (0 = no expiry) |
| Session timeout (minutes) | Auto-logout after inactivity (0 = disabled) |
Authentication
| Field | Description |
|---|
| Mandatory MFA | Shows a login reminder to users who have not enabled an authenticator app — does not block login for users who haven't set it up |
| E-signature on approval | Requires re-entering the password when approving an analysis |
Audit Trail
| Field | Description |
|---|
| Audit log retention (days) | An inert field. Audit record retention is now governed by the Retention Policies; whatever you enter here, the server ignores it |
QC Notifications
| Field | Description |
|---|
| Notification warning days | How many days before a deadline (e.g. instrument calibration) a warning appears (0 = overdue only) |
| Daily notification check time | The time of day the daily QC notification check runs |
| Enable email notifications | Turns on the periodic QC digest for the WHOLE lab. It is not about your personal notifications — see below. Requires SMTP |
| Frequency | Daily or Weekly (Monday) |
| Send time | The time of day the digest email is sent |
| Recipients | Quality manager or All users |
Two different things are called "QC notifications"
They are easy to confuse and each is configured somewhere else:
| Here (Security) | Settings → Notifications |
|---|
| What it is | A periodic email digest | Personal push notifications |
| Who gets it | The whole lab, or the quality manager | You only |
| Who configures it | The director, once for everyone | Each user, for themselves |
For ISO 17025 compliance, enable MFA and e-signatures.
Only the Lab Director (LAB_DIRECTOR) role can change security settings.