Kinabase Logo
Help & Support

Portal security

Control offline access and inactivity timeouts for each Portal


Portals

have separate controls for offline access and inactivity timeouts. Configure each Portal for the work its users do and the devices they use.


1. Control offline access

Offline access lets signed-in users reopen content they have already loaded and queue supported changes when their connection drops. The setting is off by default for new and existing Portals, whether they are for colleagues or external users.

Enable offline access

  1. Open Settings, then Portals.
  2. Select the Portal you want to configure.
  3. Open the Security pane.
  4. Switch Offline access on.
  5. Select Save.

Ask each user to sign in and open the Portal online on the device they intend to use. This lets the browser prepare previously loaded Portal content for use without a connection.

Work while offline

When the connection drops, the Portal displays You are offline. Users can reopen previously loaded content, submit supported forms, and run available Workflow Actions. Changes are stored on the device until the connection returns.

After reconnecting, Kinabase tries the queued changes against the current rules and permissions. A change that needs attention displays Sync Error with a Review link. Users can also open Offline actions to view pending changes, retry an action, or remove it.

Public form links are not available offline.

Choose suitable Portals and devices

Enable offline access only where saving Portal data on the device is appropriate. Kinabase displays Not recommended for external users on shared devices. in the Security pane for an external Portal.

Leave offline access off for Portals used on public, borrowed, or shared devices. With the setting off, the Portal does not save record and report caches on the device.

Turn offline access off

Before turning the setting off, ask users to reconnect each device and allow pending work to synchronise. Then switch Offline access off and select Save.

When the disabled Portal next loads online on a device, Kinabase removes its stored Portal data and queued changes from that device.


2. Configure an inactivity timeout

When enabled, Kinabase tracks how long a portal user has been idle and automatically signs them out once the configured period elapses.

By default, portal sessions expire after 14 days of inactivity. With inactivity timeouts enabled, you can shorten this to as little as 30 minutes.

  1. Open Settings, then Portals.
  2. Select the Portal you want to configure.
  3. Open the Security pane.
  4. Turn on Enable inactivity timeout.
  5. Select a Timeout duration. The default is 1 day.
  6. Select Save.

The new timeout applies to all future sign-ins for that portal. Existing sessions continue with the previous 14-day expiry until the user signs in again.

Available timeout durations

Duration
30 minutes
1 hour
2 hours
4 hours
8 hours
1 day
2 days
1 week
2 weeks
4 weeks

To return to the default 14-day session expiry, turn Enable inactivity timeout off.


3. What Portal users see

When a session is about to expire, a window displays Are you still there? with two options:

  • Continue Session resets the countdown so the user can keep working.
  • Sign Out ends the session immediately.

If the user takes no action, they are signed out automatically and redirected to the portal sign-in page.

Multiple browser tabs

If a user has the portal open in multiple browser tabs, extending the session in one tab automatically refreshes the countdown in every other open tab. Users do not need to interact with each tab individually.


4. Who can change Portal security settings

Only colleagues

with permission to edit Portal settings can configure offline access and inactivity timeouts. Portal users cannot change these settings themselves.


5. When to use inactivity timeouts

Sensitive data portals

Consider a short timeout (30 minutes to 1 hour) for Portals that expose financial, personal, or confidential information. Select a duration that matches your organisation’s security and compliance policies.

Shared device environments

Enable shift-length timeouts (4 to 8 hours) on portals used by warehouse staff, receptionists, or other users who share a terminal, so sessions are secured when staff walk away.

Low-risk portals

Consider a longer timeout for internal knowledge bases or low-sensitivity portals where users need to stay signed in for longer periods.

Mixed environments

Apply different timeout policies across Portals, based on the work and the devices used to access them.



Need more help? Ask your System admin, or contact our support team via Help & Support.