NearSync Help

Settings

Security and the Audit Log How workspace security is set, how to raise MFA, how to track who has enrolled, and how to find out who changed something.

Settings, Security. Two surfaces: your workspace's security posture, and the audit trail. You need weight 90; the audit log additionally needs the capability to view it.

Security Is Set By NearSync

Workspace security policy is platform-governed. Three fields are enforced, and you are shown them read-only:

  • Multi-factor authentication
  • Idle session timeout
  • Fortress mode

There is one thing you control: you can raise the MFA requirement above the NearSync baseline. You can never lower it. This is deliberate - a workspace should be able to be stricter than the platform floor, never weaker.

To request a change to the timeout or fortress mode, contact NearSync support.

Multi-Factor Authentication

The card shows the effective level: not required, required for admins, or required for everyone. If your workspace has raised it above the baseline, the card says so.

Raising It

Under the MFA row is Workspace choice, with two positions:

  • Match baseline - inherit whatever NearSync has set.
  • Require for everyone - raise it, whatever the baseline is.

Switch to "Require for everyone" and the requirement applies immediately, with a grace period.

The Grace Period

When MFA becomes required, people get seven days to enrol before they are locked out. The card shows the days remaining and the exact date the grace ends.

The grace is counted per person, from the later of two dates: when the policy was set, or when their account was created. A new hire joining after the policy took effect gets their own seven days rather than arriving to a locked door.

Once grace ends, anyone without MFA cannot sign in until they set it up.

Caution

Check the enrolment roster before the grace period ends, not after. The failure mode is people discovering they are locked out on a Monday morning, and the only fix is somebody with weight 90 resetting their factors.

Who Counts As An Admin

If the level is "required for admins", that means role weight 60 and above - department head band and up. Those are the people holding approvals, finance and personnel data.

Tracking Enrolment

Below the posture card is a live roster of everyone in the workspace, showing whether they are required, whether they have enrolled, what kind of factor they hold, when their grace ends and when they were last asked.

Two actions:

  • Ask to enrol sends the person an enrolment request. The row records when you last asked.
  • Reset removes all of someone's MFA factors so they re-enrol at next sign-in. This needs weight 90 and asks for confirmation.

Reset is the recovery path when someone loses their phone. It is also the one to use carefully - it lowers that account's protection until they re-enrol.

Session Timeout And Fortress Mode

Idle session timeout ends a signed-in session after that much inactivity. The card shows the effective value.

Fortress mode is heightened protection. When active, the session timeout is capped at 15 minutes regardless of the configured value, and an indicator appears in the header. If your configured timeout is longer, the card tells you it is being capped.

Both are NearSync-set.

Your Own MFA

Setting up your own factors is done in your account settings, under Security. See Your Account. Passkeys and authenticator apps both satisfy the requirement.

The Audit Log

Settings, Security, Audit Log. A field-level record of changes across the workspace: who changed which record, when, and from what to what.

Each entry carries the time, the person, the action, the record type, the field, and the before and after values. Entries where nobody was signed in - automated changes - show as System.

Finding A Change

  1. Search by person, record type, field name or action. All four are matched.
  2. Filter by action using the dropdown, which lists the actions present in what is loaded.
  3. Expand an entry to see the full before and after values.

The log loads the most recent 100 entries, newest first. It is scoped to your organisation.

Exporting

Export writes what is currently loaded to CSV, with the timestamp, person, action, record type, field, and the from and to values. Use it when you need to hand something to an auditor or attach it to an incident record.

Keep in mind

The export contains what is loaded, not the entire history. If you need a longer window than the most recent hundred entries, contact support rather than assuming the export is complete.

A Worked Investigation

Someone's salary figure looks wrong and you need to know what happened.

  1. Open the Audit Log.
  2. Search the field name rather than the person - you may not know who did it.
  3. Read the before and after on the matching entry.
  4. Note the person and the timestamp.
  5. Export if this is going anywhere formal.
  6. Check their role on the Permissions surface, and whether editing salary should have been within it.

Common Questions

Why can I not switch off MFA? You can only raise the requirement, never lower it below the NearSync baseline. If the baseline requires it, it is required.

Someone is locked out. If they never enrolled and the grace has ended, they must enrol - or someone with weight 90 resets their factors so they can set it up at next sign-in.

My session keeps ending quickly. Check whether fortress mode is active. It caps the timeout at 15 minutes regardless of the configured value.

The audit log does not show something I expected. It records field-level changes to records. Sign-ins and system events are not the same trail. If you need those, ask support.

9 minUpdated 28 July 2026

Did this answer your question?

No, ask a person