+91-40-4033-4444 hello@office24by7.com Hyderabad, Telangana, India

See every login. End the wrong ones.

Live session control, MFA for sensitive roles, and scoped API keys for integrations.

Security & Access

Overview

Sessions & MFA gives administrators live visibility and control over how people reach the platform. Every login creates a User Session record capturing the user, IP address, device, location, start time and last activity — so an anomalous sign-in can be spotted and revoked before it becomes an incident. When someone loses a laptop or leaves the company, you end their sessions instantly rather than waiting for tokens to expire.

On top of session visibility sits strong authentication. Multi-factor authentication adds a second factor to logins, and you can require it for sensitive roles or the whole tenant. Machine access is handled separately: API Keys and Tokens are issued, scoped, rotated and revoked as their own credentials, so integrations never ride on a human login. Together these controls give you the sign-in hygiene that DPDP accountability and ISO 27001-style access controls expect.

Explore Security & Policies →
  • ✓ Live view of every active and past session
  • ✓ One-click session revocation for lost devices or exits
  • ✓ Multi-factor authentication enforced by role or tenant-wide
  • ✓ Device and location context on every login
  • ✓ Scoped API keys and tokens, separate from human logins
  • ✓ Risk signals surfaced on unusual sign-ins
Capabilities

Everything Sessions & MFA gives you

Multi-Factor Auth

Add a second authentication factor and require it for sensitive roles or the whole tenant.

Session Visibility

Track every active and past session with user, IP, device, location and last-active time.

Instant Revocation

End any session in one click when a device is lost or an employee leaves.

Device Context

See the device and geography behind each login to spot access that does not belong.

API Key Control

Issue, scope, rotate and revoke machine tokens so integrations never share a human account.

Risk Signals

Surface anomalous sessions by risk score so suspicious logins get attention first.

AI at work

How the AI agent helps with Sessions & MFA

The Flow-Cognition Agent spots risky sign-ins and suggests which sessions to revoke — an admin confirms each action, and every step is logged.

Sense

Flags sign-ins from new devices or unusual locations.

Decide

Ranks them by risk and suggests which sessions to revoke.

Act

An admin confirms each action, and every step is logged.

Five-tier model routing · field-level permissions · full audit trail. See the AI layer →

How it works

Live in four steps

1

Enable MFA

Turn on multi-factor authentication and require it for the roles that handle sensitive data.

2

Monitor sessions

Watch active logins with device, location and risk context in one console.

3

Revoke on risk

End any suspicious or stale session immediately, without waiting for expiry.

4

Rotate keys

Scope and rotate API keys and tokens on a schedule so machine access stays fresh.

Use cases

Where teams put it to work

Lost or stolen laptop

An admin finds the employee's active sessions by device, ends them instantly, and forces re-authentication so the missing laptop can no longer reach any data.

Protecting privileged roles

MFA is required for finance and admin roles, so even a stolen password cannot log in without the second factor.

Retiring an integration

When a third-party tool is decommissioned, its scoped API key is revoked in seconds, cutting off machine access without touching any user account.

Why it matters

The payoff

Reduce account takeover

MFA and instant revocation blunt stolen-password and lost-device attacks before they spread.

No shared logins

Scoped API keys give integrations their own credentials, so machine access is traceable and revocable.

Faster incident response

Live session data lets you see and cut off suspicious access in minutes, not days.

Audit-ready sign-in trail

Every session and login is recorded, supporting DPDP accountability and access-control evidence.

FAQ

Questions, answered

Yes. MFA can be required tenant-wide or scoped to specific roles, so you can mandate a second factor for privileged accounts like finance and admin while leaving it optional elsewhere.

You can revoke all of a user's active sessions instantly from the session console, which cuts off access immediately rather than waiting for tokens to time out on their own.

Integrations use API Keys and Tokens that are issued, scoped and rotated separately from human logins. Each key has its own permissions and can be revoked without affecting any user account.

Every session records IP, device, location and last-active time, and a risk score highlights anomalous access. You can filter for unusual sessions and revoke them directly from the same view.

Session controls are designed to complement centralized authentication so identity can be managed alongside your existing directory; MFA, session visibility and revocation all apply regardless of how users authenticate.

See Sessions & MFA in your workflow

Start free, or get a guided walkthrough with our team — on the one platform that runs Security & Access and your whole business.