Security and reporting

Two-step verification required or not, pseudonymous reports by default, named reports as an opt-in, and session settings.

Admins2 min read

The organization policy sets who must turn on two-step verification, how player results appear in reports, and how long sessions last. Every member can read it; Owners and Admins change it, in Organisation → Security.

Two-step verification

By default, two-step verification is optional: everyone chooses whether to turn it on, and you can create your organization, fork and publish a game without it. It is always needed for two kinds of actions:

  • managing the security of the organization (this page, SSO, API keys);
  • exposing player data (switching to named reports, the xAPI LMS connector).

You can require it in your organization:

Rule Who must turn it on
Nobody (optional) Nobody; the default
Privileged roles Owners, Admins, Editors and Analysts
Every member Every member, also to play the organization's private games

Requiring two-step verification:

  • asks you to confirm your identity again;
  • gives newly covered members 7 days to turn it on: during that time, a banner tells them the date, and each of those who have not turned it on yet gets an email;
  • after that, a covered member without two-step verification can no longer act in the organization: the site sends them to turn it on, then brings them back where they were;
  • is recorded in the audit log.

The page also shows how many members have already turned it on. Going from "Privileged roles" to "Every member" gives privileged roles no new delay. Making it optional applies at once.

Pseudonymous by default

By default, reports never show who played. Each player appears under a stable pseudonym (for example Player-7F3A), and a group of fewer than 5 players is never detailed.

Named reports

An organization can choose to show player names in its reports. Switching to named mode:

  • is reserved to Owners and Admins;
  • asks you to confirm your identity again (password or email code);
  • is recorded in the audit log, with who made the change and when;
  • is shown to players in the game, so they know their results are named.

Switching back to pseudonymous mode does not require confirmation.

Session settings

Setting Range Default
Maximum session length 1 hour to 30 days 30 days
Idle timeout for privileged roles 15 min to 24 hours 24 hours

The idle timeout applies to Owners, Admins, Editors and Analysts.

See also Roles and permissions.

Edit this page on GitHub (opens in a new tab)