To meet stricter security standards (NIST AAL2), your Qevlar organization admin can enable a tighter session policy:
- Inactivity timeout: signed out after 30 minutes of inactivity.
- Reauthentication: prompted to sign in again every 12 hours, regardless of activity.
When the policy is off, the standard session applies. Ask your Qevlar contact to enable it if your security team requires it.