Configuration
Set the guardrails for your workspace.
The Security card governs multi-factor authentication for the Admin Portal, how long governance records and export files are kept, how long sign-ins stay valid, and who may download data exports.
Overview
Security settings hold tenant-wide security policy: MFA for the Admin Portal, retention, session length, and data export governance.
A second tab, Configuration activity, shows a read-only log of configuration changes: who changed what, and when.
Before you begin
- Set up MFA on your own account before requiring it for others: the toggle checks this.
- Know your governance retention obligations before shortening any window.
Recommended setup order
- Open Configuration and select Security.
- Save the MFA policy with its own Save button after your own MFA is enrolled.
- Review Retention Policy: audit log retention and data export retention.
- Review Session Policy: how long a sign-in stays valid.
- Review Data Export Controls: the downloads toggle and minimum role.
- Check the Configuration activity tab when you need to see who changed a setting.
Key fields and settings
Require MFA for Admin Portal
Managers, admins, and owners must complete MFA after password sign-in before opening the Admin Portal. Staff-only portal access is unaffected, and tenant SSO sessions stay governed by your identity provider.
Audit log retention
How long tenant audit and operational change logs are kept, from 30 days to 10 years.
Data export retention
How long generated export files are kept before automatic cleanup.
Session timeout
How long a sign-in stays valid before users must sign in again. Applies to new sign-ins after you save.
Allow data export downloads
The master switch for the Data Export area. Turning it off hides export downloads entirely.
Minimum role to export
Admin and Owner, or Owner only. Enforced on the server, not just in the interface.
Configuration activity
A read-only log of configuration changes across the workspace: the change, the actor, and the time.
Best practice
- Enrol your own MFA first: the policy toggle stays locked until you do.
- Match retention windows to your governance obligations rather than the defaults.
- Restrict exports to Owner only if downloads should be a deliberate, rare act.
Common mistakes to avoid
- Requiring Admin Portal MFA before your own account has MFA working.
- Shortening audit retention below what your obligations require.
- Assuming session timeout signs out existing sessions immediately: it applies to new sign-ins.
What to do next
Related guides
Roles and Access
Understand Owner, Admin, Manager, Staff, Staff Portal access, auditor access, and platform administration separation.
Security, Roles, and AccessSSO and SCIM
Learn how BondiByte supports Microsoft SSO and SCIM provisioning foundations for identity-managed NDIS provider teams.
ConfigurationData Export
Export operational data by category with filters, preview, and download, governed by the Security card's export controls and retention cleanup.
Need help applying this setup path?
Book a BondiByte demo and we can walk through the right setup order for your provider.