Platform active sessions

Active sessions shows every browser or device where your platform admin account is still signed in. Use it to spot a device you no longer trust and sign it out remotely — the same idea as tenant Active sessions, scoped to your platform admin account instead.

Screen overview

Platform active sessions list

Figure: Session list with current device badge and remote sign-out actions.

What each row means

Device

A best-effort name derived from the browser and operating system (for example "Chrome on macOS"). Shows Unknown device when IVPrior can't detect it — missing metadata, not necessarily a threat.

IP address

A partial IP for that session, for a quick sanity check on where it came from. Not a precise location.

Last activity

How recently the session was used to call the platform API. A stale session next to recent ones is a good candidate to sign out.

Signed in

The date that session's original sign-in happened, separate from Last activity.

Current badge

Marks the session for the browser tab you're using right now. You cannot sign out the current session from this list.

Why this matters

Platform admin accounts can manage every tenant, so an unnoticed open session here is higher risk than a tenant staff session. Review this list after using a shared or public computer, or periodically as good security hygiene.

Steps

  1. Open the sidebar → Account → Active sessions, or go to AccountActive sessions tab (/platform/account/profile?section=sessions).
  2. Review each row — device, partial IP, last activity, and sign-in date.
  3. Use Sign out on a remote session you no longer trust.
  4. Use Sign out all other devices to keep only your current browser signed in.

Signing out a session immediately invalidates it — the next API call from that device is rejected and it has to sign in again.