Workspace security
The Security tab, under Security & access in the workspace settings, sets sign-in and access rules for everyone in the workspace. Only owners and admins can change these settings. Switches are saved as soon as you change them. The password policy and audit log settings have their own Save buttons.
Require two-factor authentication
Under Security Settings, turn on Require 2FA for all members. Members who have not set up two-factor authentication must set it up the next time they sign in before they can continue.
The requirement follows the person. If any workspace they belong to requires two-factor authentication, they need it to sign in.
Password policy
Turn on Enforce a password policy to set stricter password rules for members of this workspace:
- Minimum length: between 8 and 32 characters.
- Require an uppercase letter, Require a lowercase letter, Require a number, and Require a symbol.
- Passwords remembered: how many recent passwords, including the current one, a member cannot reuse. Up to 10. Set 0 to turn this off.
Click Save to apply the policy. The rules apply the next time a member sets, changes, or resets a password. When a member belongs to several workspaces, the strictest policy applies.
Session management
Under Audit & Compliance, turn on Auto-logout sessions to limit how long members stay signed in.
- Next to Current timeout:, click Edit.
- Enter the timeout in days, hours, and minutes. It can be from 10 minutes to 7 days.
- Click Save.
The timeout applies to sessions that start after you save it. If a member belongs to several workspaces with a timeout, the shortest one applies.
IP restrictions
Turn on Enable IP Control to allow access to this workspace only from approved network addresses.
- Under Allowed IPs, click Add.
- Enter an IP address or a CIDR range, such as
203.0.113.0/24. - Click Add.
Requests from other addresses are refused for this workspace. Qubit will not save a list that would block the address you are using, so you cannot lock yourself out. While the list is empty, no address is blocked.
Audit log
The Audit log section controls what Qubit records and for how long.
- Record workspace activity and AI runs turns recording of workspace activity and AI runs on or off. Sign-ins, data access, support sessions, and changes to these settings are always recorded.
- Keep records for sets the retention period, from 30 to 2,555 days. Click Save, or Use the default to return to the default period. If you shorten the period, records older than the new period are deleted at the next daily cleanup and cannot be recovered. Qubit asks you to confirm with Shorten retention.
- Open audit log opens the log. See Audit Logs.
Forward records to your SIEM
Under Forward to your SIEM, you can send every record to your security monitoring system shortly after it is written.
- Choose a Destination type:
- HTTPS (JSON): enter an Endpoint URL that uses https and a Signing secret of at least 24 characters, or click Generate. Each request is signed with HMAC-SHA256.
- Syslog over TLS: enter the Host and Port, choose a Message format of JSON or CEF, and optionally paste a CA certificate if your collector uses a private certificate authority.
- Turn on Forwarding on.
- Click Save destination, then Send test event to check delivery.
The section shows the delivery status, the last successful delivery, and any pending or failed records. To stop forwarding, click Remove destination. Records already sent stay in your SIEM.