Security and reporting
Two-step verification required or not, pseudonymous reports by default, named reports as an opt-in, and session settings.
The organization policy sets who must turn on two-step verification, how player results appear in reports, and how long sessions last. Every member can read it; Owners and Admins change it, in Organisation → Security.
Two-step verification
By default, two-step verification is optional: everyone chooses whether to turn it on, and you can create your organization, fork and publish a game without it. It is always needed for two kinds of actions:
- managing the security of the organization (this page, SSO, API keys);
- exposing player data (switching to named reports, the xAPI LMS connector).
You can require it in your organization:
| Rule | Who must turn it on |
|---|---|
| Nobody (optional) | Nobody; the default |
| Privileged roles | Owners, Admins, Editors and Analysts |
| Every member | Every member, also to play the organization's private games |
Requiring two-step verification:
- asks you to confirm your identity again;
- gives newly covered members 7 days to turn it on: during that time, a banner tells them the date, and each of those who have not turned it on yet gets an email;
- after that, a covered member without two-step verification can no longer act in the organization: the site sends them to turn it on, then brings them back where they were;
- is recorded in the audit log.
The page also shows how many members have already turned it on. Going from "Privileged roles" to "Every member" gives privileged roles no new delay. Making it optional applies at once.
Pseudonymous by default
By default, reports never show who played. Each player appears under a stable pseudonym (for
example Player-7F3A), and a group of fewer than 5 players is never detailed.
Named reports
An organization can choose to show player names in its reports. Switching to named mode:
- is reserved to Owners and Admins;
- asks you to confirm your identity again (password or email code);
- is recorded in the audit log, with who made the change and when;
- is shown to players in the game, so they know their results are named.
Switching back to pseudonymous mode does not require confirmation.
Session settings
| Setting | Range | Default |
|---|---|---|
| Maximum session length | 1 hour to 30 days | 30 days |
| Idle timeout for privileged roles | 15 min to 24 hours | 24 hours |
The idle timeout applies to Owners, Admins, Editors and Analysts.
See also Roles and permissions.