Reference table
Sessions and timeouts
Sets out session lengths, idle timeouts and re-authentication points, with the default values and where an administrator can adjust them.
This reference sets out how long a session lasts, when a workstation locks on idle, and the points where Pensieve asks a person to sign in again. It gives the default values and where an administrator adjusts them for a site.
Session and timeout defaults
A session is the period between sign-in and sign-out during which the platform knows who is present. The defaults below apply to a new site, and an administrator adjusts them within the limits the platform holds.
| Setting | Default | Applies to |
|---|---|---|
| Session length | 12 hours | Every signed-in person |
| Shared-workstation idle lock | Five minutes | Ward and clinical workstations |
| Single-user idle lock | 30 minutes | Office and administrative workstations |
| Warning before lock | One minute | Any workstation with an idle lock |
| Emergency-access window | Four hours | An emergency-access session |
| Emergency-access review clock | 72 hours | Review that follows an emergency-access session |
| Remote sign-out effect | One request | Any live session |
The session length is the outer bound. A person who stays active still signs in again once it passes, so the platform refreshes who is present at least once a shift.
Idle locks
An idle lock returns an unattended workstation to a locked state. A shared clinical machine locks sooner than a single-user office machine, because more people pass through it.
A lock keeps the session, not the screen
An idle lock closes the screen while the person's session stands. The same person signs back in with their PIN and continues, and their work is held for them.
Re-authentication points
Pensieve asks a person to prove who they are again at the points below. Each point ties an action, or a fresh stretch of work, to the person taking it.
| Point | What Pensieve asks | Why |
|---|---|---|
| Signing in on a shared workstation | Your PIN on the enrolled workstation | Ties the session to one person |
| A sensitive action | Your PIN again at the moment of the action | Confirms the person taking the action |
| Opening emergency access | Your PIN and a stated reason | Opens a time-boxed, logged session |
| After the session length | A full sign-in | Refreshes who is present |
A sensitive action asks for the PIN again at the moment it happens, so an open session is separate from consent to one weighty step. An emergency access opens a session that ends when its window passes.
Where an administrator adjusts these
An administrator sets these values per site in the access settings, hosted in Nexus Manager. The platform holds a floor and a ceiling for each, so a site tunes within a safe range.
How long a session lasts before a full sign-in, set per site.
The idle period before a shared clinical workstation locks.
The idle period before a single-user workstation locks.
How long an emergency-access session stays open.
Ending a session takes effect at once
Pensieve holds the state of every live session in one place. A sign-out, the next sign-in on the same workstation, or a change to an account ends the matching session, and the change takes effect within one request.
Common questions
Does a shorter idle lock make staff sign in more often?
It does, and quick sign-in is what makes that affordable. A shared workstation takes a PIN, so a lock costs a moment rather than a full passphrase.
What ends a session before its length passes?
A sign-out, the next person signing in on the same workstation, a remote sign-out from a phone, or a change to the account all end a session early.
Can a site remove the idle lock entirely?
A site tunes the idle period within the platform's floor and ceiling, so an unattended clinical workstation returns to a locked state within a bounded time.
These settings rest on identities that resolve to one person and on sessions that end on command. Read how each action ties to a named person at identity and sign-in, and how handover works on a shared machine at shared workstations.