Domain allowlist
The Domain allowlist is a list of email domains that can be invited to your organization, or self-sign up. Anyone with an email outside the list can’t join.- Add a domain — type a domain (e.g.
acme.com) and click Add. You’ll be reminded that this affects who can be invited or sign up going forward. - Remove a domain — click the trash icon next to it. At least one domain must remain on the list.
Adding or removing a domain affects future invites and sign-ups. People already in your team aren’t kicked out if their domain is removed.
Session policy
The Session policy sets how long someone stays signed in to the dashboard before being asked to log in again. Two values:
A badge tells you whether the current values are Default or Custom.
If you set values that don’t make sense (e.g. an idle timeout longer than the maximum lifetime), HelpAlive shows a warning before saving.
Session policy changes are admin-only. Members see the current policy but can’t change it.
Security overview
A read-only card shows your organization’s baseline security posture:- HTTPS required — all dashboard and API traffic uses HTTPS.
- CSRF protection — dashboard requests are protected from cross-site forgery.
Access control summary
The bottom card summarizes what each role can do:
To change someone’s role, go to Team.
Next steps
Team
Invite teammates and manage their access.
Privacy
What we collect, what we don’t, and where personal data is removed.

