Portal security
Control offline access and inactivity timeouts for each Portal
Portals
1. Control offline access
Offline access lets signed-in users reopen content they have already loaded and queue supported changes when their connection drops. The setting is off by default for new and existing Portals, whether they are for colleagues or external users.
Enable offline access
- Open Settings, then Portals.
- Select the Portal you want to configure.
- Open the Security pane.
- Switch Offline access on.
- Select Save.
Ask each user to sign in and open the Portal online on the device they intend to use. This lets the browser prepare previously loaded Portal content for use without a connection.
Work while offline
When the connection drops, the Portal displays You are offline. Users can reopen previously loaded content, submit supported forms, and run available Workflow Actions. Changes are stored on the device until the connection returns.
After reconnecting, Kinabase tries the queued changes against the current rules and permissions. A change that needs attention displays Sync Error with a Review link. Users can also open Offline actions to view pending changes, retry an action, or remove it.
Public form links are not available offline.
Choose suitable Portals and devices
Enable offline access only where saving Portal data on the device is appropriate. Kinabase displays Not recommended for external users on shared devices. in the Security pane for an external Portal.
Leave offline access off for Portals used on public, borrowed, or shared devices. With the setting off, the Portal does not save record and report caches on the device.
Turn offline access off
Before turning the setting off, ask users to reconnect each device and allow pending work to synchronise. Then switch Offline access off and select Save.
When the disabled Portal next loads online on a device, Kinabase removes its stored Portal data and queued changes from that device.
2. Configure an inactivity timeout
When enabled, Kinabase tracks how long a portal user has been idle and automatically signs them out once the configured period elapses.
By default, portal sessions expire after 14 days of inactivity. With inactivity timeouts enabled, you can shorten this to as little as 30 minutes.
- Open Settings, then Portals.
- Select the Portal you want to configure.
- Open the Security pane.
- Turn on Enable inactivity timeout.
- Select a Timeout duration. The default is 1 day.
- Select Save.
The new timeout applies to all future sign-ins for that portal. Existing sessions continue with the previous 14-day expiry until the user signs in again.
Available timeout durations
| Duration |
|---|
| 30 minutes |
| 1 hour |
| 2 hours |
| 4 hours |
| 8 hours |
| 1 day |
| 2 days |
| 1 week |
| 2 weeks |
| 4 weeks |
To return to the default 14-day session expiry, turn Enable inactivity timeout off.
3. What Portal users see
When a session is about to expire, a window displays Are you still there? with two options:
- Continue Session resets the countdown so the user can keep working.
- Sign Out ends the session immediately.
If the user takes no action, they are signed out automatically and redirected to the portal sign-in page.
Multiple browser tabs
If a user has the portal open in multiple browser tabs, extending the session in one tab automatically refreshes the countdown in every other open tab. Users do not need to interact with each tab individually.
4. Who can change Portal security settings
Only colleagues
5. When to use inactivity timeouts
Consider a short timeout (30 minutes to 1 hour) for Portals that expose financial, personal, or confidential information. Select a duration that matches your organisation’s security and compliance policies.
Enable shift-length timeouts (4 to 8 hours) on portals used by warehouse staff, receptionists, or other users who share a terminal, so sessions are secured when staff walk away.
Consider a longer timeout for internal knowledge bases or low-sensitivity portals where users need to stay signed in for longer periods.
Apply different timeout policies across Portals, based on the work and the devices used to access them.
Related guides
- Portals overview — what Portals are and how they work
- External Portals — set up Portals for clients and partners
- Internal Portals — set up Portals for team members
- Managing Portal users — control access and invitations
Need more help? Ask your System admin, or contact our support team via Help & Support.