The Access & security page brings together the settings that control who can get into Warrant and how long unused accounts stay open. It is for admins who look after sign-in and account hygiene, and for anyone filling in a security questionnaire about Warrant.
Where to find it
Click Settings at the foot of the workspace sidebar.
Under Members, select Access & security.
The page has these sections:
Sign-in: the switch that requires two-factor authentication for everyone. See Two-Factor Authentication (MFA).
Dormant account policy: automatically deactivates accounts nobody has used in a while. Covered below.
Trust Center controls: the live status of security controls for audits and risk assessments. Covered below.
Anomalous-login detection: flags sign-ins from impossible locations. Only Warrant super admins see this card. See Anomalous Login Detection.
Deactivate dormant accounts
Accounts with no sign-in activity for a set number of days are deactivated automatically. This keeps forgotten accounts, such as people who have changed roles or left, from staying open.
The policy is on by default. To change it:
In the Dormant account policy card, leave Auto-deactivation switched on, or switch it off to opt out.
Under Inactivity threshold, choose how many days without a login before an account is deactivated: 30 days, 60 days, 90 days (default) or 180 days.
Changes save as soon as you make them.
How it works
People receive an email warning 7 days before their account is deactivated. Signing in before then keeps the account active.
A deactivated account cannot sign in, and all of its active sessions end immediately.
Admins receive an email when an account is deactivated.
Reactivate an account
Go to Settings, then Members, then Members.
Open the person's page.
In the Account card, click Reactivate. Their access is restored with the same settings.
If you switch Auto-deactivation off, a yellow notice on the card reminds you that dormant accounts will not be deactivated until you switch it back on.
Trust Center controls
The Trust Center controls card shows the live status of security controls that appear in Warrant's Trust Center and in third-party risk assessments. Today it lists one control:
Dormant accounts disabled (SOC 2). Shows Met while the dormant account policy is on, and Not met if you have switched it off.
While the control is met, the Detail column includes a ready-made Questionnaire answer that reflects your current threshold. You can copy it straight into a vendor security questionnaire.
Who can use it
Only admins can see the Access & security page and change its settings. The Anomalous-login detection card is visible only to Warrant super admins.