Automatic sign-out
CaseFlow signs people out when they stop using it, so an unattended computer does not leave client files open on screen. This page explains exactly what happens and what you can change, because it is a question your clients, your bar association, and your insurer may all ask you.
The short answer
| Signed out after no activity for | 30 minutes by default, set by your firm |
| Every sign-in ends after | 12 hours, however active you have been |
| Warning before you are signed out | 1 minute, with a "Keep me signed in" button |
| Staying signed in on a device you trust | Up to 7 days, and only with two-factor authentication turned on |
| Applies to | Everyone on your team, and everyone using your client portal |
Automatic sign-out cannot be switched off. You can lengthen it, but there is always a limit.
What counts as activity
Anything you do counts: opening a matter, saving a time entry, running a report, moving between pages. Background work the browser does on its own does not count, so leaving CaseFlow open in a tab you are not using will not keep you signed in.
Typing does not count on its own. If you are part-way through a long note and have not saved for a while, the warning is what protects you: it appears a minute before you would be signed out, and one click keeps you working.
If you have CaseFlow open in several tabs, using any one of them keeps them all signed in.
Changing the timeout for your firm
A firm administrator can change it in Setup → Settings → Security, under Automatic sign-out. The choices are 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours, and 8 hours.
The change applies to everyone in your firm, including contacts using your client portal, and takes effect immediately.
A few things to know before you change it:
- Shorter is not automatically better. A timeout so short that people are signed out mid-task teaches them to work around it, and the most common workaround is leaving a machine unlocked. 30 minutes is the default because it is the point most professional guidance settles on.
- Longer needs a reason you would be comfortable stating. If you handle medical records in personal injury or family matters, or you have told a client that their file is protected by an inactivity timeout, 4 or 8 hours is a decision worth writing down.
- Every change is recorded. Changing this setting writes an entry to your audit log showing who changed it, when, and what it was before. That entry is part of the tamper-evident record, so you can show the history of your own security policy, not just assert it.
The 12-hour limit
Separately from inactivity, no single sign-in lasts more than 12 hours, even while you work continuously. This is not configurable.
It exists because an inactivity timeout alone cannot bound how long one sign-in remains usable, and a sign-in that never has to be repeated is one that cannot be revoked by anything short of disabling the account. Twelve hours is the figure used by the US federal standard for multi-factor-protected access (NIST SP 800-63B), which is the yardstick a firm handling trust funds is likely to be measured against.
If you reach it, you are warned a minute in advance and simply sign in again.
One thing to be precise about, because it is easy to overstate: the 12 hours limits a single sign-in, not how long you can go without typing your password. If you use Keep me signed in on a trusted device, your sign-in still ends at 12 hours, but CaseFlow starts a new one on that device without asking for your password. For that device, the figure that actually bounds password-free access is the 7 days below, not the 12 hours. Do not tell a client that nobody stays signed in longer than 12 hours if your team uses trusted devices.
Staying signed in on a device you trust
The Keep me signed in option on the sign-in page trusts the device you are using for 7 days, so you do not retype your password every morning.
It requires two-factor authentication. If you tick the box without two-factor turned on, you are signed in normally and told where to turn it on. This is deliberate: skipping the password for a week means the browser profile on that machine becomes the only thing standing between someone and your client files, which is a reasonable trade when a second factor is also required and an unreasonable one when it is not. See Two-factor authentication to turn it on.
A few specifics worth knowing:
- 7 days is fixed, measured from when you ticked the box. It does not extend because you kept using CaseFlow. After 7 days you sign in again, with your second factor.
- The 30-minute and 12-hour rules still apply to the session itself, and this is the part people find surprising. On a trusted device those limits are invisible: your session ends and the device quietly starts a new one, so you never see a sign-in screen. What the device is trusted for is skipping the password, not staying signed in forever.
- Signing out ends the trust for that device only. Your other trusted devices are unaffected.
- Changing your password ends trust on every device. However the password changes, including a reset from the forgotten-password email or an administrator setting a new one, every trusted device has to sign in again. If you think someone else has your password, changing it is enough.
- A deactivated account cannot get back in, trusted device or not.
Do not use Keep me signed in on a computer other people can reach. On a shared machine, sign out when you finish.
What your clients see
Contacts using your client portal are covered by the same firm setting and get the same warning before being signed out. They see the Keep me signed in box on the sign-in page, but it only takes effect if two-factor authentication is turned on for their contact record; otherwise they are told where to turn it on.
Answering the diligence question
If a client, an insurer, or opposing counsel asks how CaseFlow handles unattended sessions, the accurate answer is:
Sessions end automatically after 30 minutes of inactivity, configurable by the firm between 15 minutes and 8 hours, and no single session lasts longer than 12 hours regardless of activity. Automatic sign-out cannot be disabled. Where a user has enabled multi-factor authentication and opted to trust a device, sessions continue to expire on the same schedule but are re-established on that device without a password for up to 7 days, after which full authentication is required. Changes to the policy are recorded in a tamper-evident audit log.
Substitute your own figure if you have changed it.