Control who can open a workspace by requiring specific Cortena sign-in methods and/or a maximum time since the last login. Other workspaces stay available on the same session.
Access · Login requirements must be enabled for your organisation (ask Cortena if you do not see the section). Only users with Admin on that workspace can change the settings.
1. What login requirements do
Each workspace can set its own login requirements:
| Setting | What it means |
|---|---|
| Allowed sign-in methods | Which Cortena login methods unlock this workspace (Google, Microsoft, Email magic link) |
| Maximum time since last login | How fresh that login must be (12 hours → 30 days) |
Your Cortena session can still stay signed in for other workspaces. If this workspace's rules are stricter than how you signed in, Cortena blocks that workspace only until you re-authenticate with an allowed method.
2. Where to configure it
- Open Settings for the workspace.
- Go to Tenant (workspace settings).
- Find Login requirements.
- Choose allowed methods and the maximum time since last login.
- Click Save login requirements.
Allowed sign-in methods
- Leave all unchecked to allow any Cortena login method for this workspace.
- When any are selected, only those methods unlock the workspace.
- Options: Google, Microsoft, Email magic link.
Other Cortena login options (for example DATEV or Exact Online as a sign-in method) do not unlock a workspace that only lists Google / Microsoft / email.
Maximum time since last login
Choose one of:
- 12 hours
- 1 day
- 3 days
- 7 days
- 30 days (default) · aligned with Cortena's normal session length
Changing the setting does not sign everyone out immediately. The next time someone opens this workspace, Cortena checks their current login against the new rules.
3. What users see when access is blocked
If your current login does not match this workspace's requirements, Cortena shows Re-authenticate to continue over the workspace content.
Typical reasons:
- Your current login method is not allowed for this workspace.
- Your session is older than this workspace allows.
You can still:
- Switch to another workspace from the account menu
- Create a new workspace
- Sign out
Use the buttons on the overlay (for example Continue with Google) to re-authenticate with an allowed method. After a successful login that meets the rules, the workspace unlocks.
4. Tips and limitations
- Login requirements are per workspace: set them separately for each legal entity that needs a different rule.
- Linked accounts in Settings are not enough: you must have signed in this session with an allowed method.
- Admins need Admin permission on the workspace to save changes.
- The feature must be enabled for your organisation before Login requirements appears.
- Machine access such as MCP tokens and tenant API keys is not limited by these rules yet; ask Cortena if you need that for a compliance programme.
Quick reference
| Task | Where |
|---|---|
| Open settings | Settings → Tenant |
| Choose sign-in methods | Login requirements → checkboxes |
| Set session freshness | Maximum time since last login |
| Save | Save login requirements |
| Unlock a blocked workspace | Overlay → allowed method (e.g. Continue with Google) |
| Use another workspace instead | Account menu → switch or create workspace |