प्लेटफ़ॉर्म दस्तावेज़ीकरण

Security, MFA, and sessions

Elevale supports multi-factor authentication, session management, and enterprise security controls. Members manage personal MFA on their profile. Admins configure workspace policies under Workspace Settings.

Who this is for

All members for personal MFA and sessions. Enterprise features such as required 2FA, idle timeout, SIEM webhook, and SSO need admin access and the right plan.

Before you start

  • Access to your profile or Workspace Settings as appropriate.

Steps

  1. Open your profile from the sidebar footer to update password and MFA.

  2. Enable MFA for stronger account protection.

  3. Workspace admins open Workspace Settings → General → Security.

  4. On Enterprise, require two-factor authentication for all workspace members from the same Security section.

  5. Set Idle timeout when you want members signed out after inactivity (15 minutes to 8 hours). Off by default.

  6. On Enterprise, configure the SIEM webhook HTTPS endpoint and enable Send events. Rotate the signing secret and verify X-Elevale-Signature on each POST.

  7. Sign out of other devices from your profile when you need to end a session elsewhere.

What you should see

MFA challenges appear at sign-in when enabled. Idle timeout signs members out after the chosen period. SIEM receives audit headlines without chat or wiki content.

Troubleshooting

  • I lost my MFA device Use backup codes if you saved them, or ask a workspace admin to help reset access.

  • Idle timeout signs me out too often Admins can raise the timeout or turn it off under Workspace Settings → General → Security.

  • SIEM events are missing Confirm the endpoint URL, Send events is on, and your receiver accepts the signing header.

Common questions

Is personal MFA the same as a workspace 2FA requirement?

No. Personal MFA is your choice on your profile. Enterprise admins can require 2FA for everyone in the workspace.

What data does the SIEM webhook include?

Audit headlines for security monitoring. Chat content, {{aiName}} prompts, and wiki diffs stay inside Elevale.

Where do I set up SSO?

See Enterprise SSO setup for domain verification and identity provider configuration.

Related articles