Documentation
Tutorials
Workflows
Kebab actions
Daily Work
Dashboard & Reports
Quality Control
ISO 17025
Reagents & Storage
Logs
Contacts
Billing
Analysis Setup
Settings
Initial Setup
Help & Reference
Architecture decisions
Settings
0:000:00

Security Settings

The Security tab configures password policies, authentication, and QC email notifications. Only the Lab Director role has access.

Navigation: Settings → Security & Access → Security


Platform policy (not configurable)

The foundations of authentication are not set per laboratory. They appear at the top of the page as a statement rather than as fields:

RuleValue
Minimum password length8 characters
Account lockoutafter 5 failed attempts, for 15 minutes
Password storageargon2
Sessionone active session, lasting 8 hours

This is deliberate: a security floor every laboratory can relax is not a floor. If you need these numbers for your own documentation, they are here.

Passwords & Login

FieldDescription
Password expiry (days)Days until password expires (0 = no expiry)
Session timeout (minutes)Auto-logout after inactivity (0 = disabled)

Authentication

FieldDescription
Mandatory MFAShows a login reminder to users who have not enabled an authenticator app — does not block login for users who haven't set it up
E-signature on approvalRequires re-entering the password when approving an analysis

Audit Trail

FieldDescription
Audit log retention (days)An inert field. Audit record retention is now governed by the Retention Policies; whatever you enter here, the server ignores it

QC Notifications

FieldDescription
Notification warning daysHow many days before a deadline (e.g. instrument calibration) a warning appears (0 = overdue only)
Daily notification check timeThe time of day the daily QC notification check runs
Enable email notificationsTurns on the periodic QC digest for the WHOLE lab. It is not about your personal notifications — see below. Requires SMTP
FrequencyDaily or Weekly (Monday)
Send timeThe time of day the digest email is sent
RecipientsQuality manager or All users

Two different things are called "QC notifications"

They are easy to confuse and each is configured somewhere else:

Here (Security)Settings → Notifications
What it isA periodic email digestPersonal push notifications
Who gets itThe whole lab, or the quality managerYou only
Who configures itThe director, once for everyoneEach user, for themselves
For ISO 17025 compliance, enable MFA and e-signatures.
Only the Lab Director (LAB_DIRECTOR) role can change security settings.