Help
Open appBook a call

Workspace login requirements

Require Google, Microsoft, or email sign-in and/or a maximum time since last login per workspace. Soft-blocks that workspace until re-authentication; other workspaces stay available.

Control who can open a workspace by requiring specific Cortena sign-in methods and/or a maximum time since the last login. Other workspaces stay available on the same session.

Access · Login requirements must be enabled for your organisation (ask Cortena if you do not see the section). Only users with Admin on that workspace can change the settings.

1. What login requirements do

Each workspace can set its own login requirements:

SettingWhat it means
Allowed sign-in methodsWhich Cortena login methods unlock this workspace (Google, Microsoft, Email magic link)
Maximum time since last loginHow fresh that login must be (12 hours → 30 days)

Your Cortena session can still stay signed in for other workspaces. If this workspace's rules are stricter than how you signed in, Cortena blocks that workspace only until you re-authenticate with an allowed method.

2. Where to configure it

  1. Open Settings for the workspace.
  2. Go to Tenant (workspace settings).
  3. Find Login requirements.
  4. Choose allowed methods and the maximum time since last login.
  5. Click Save login requirements.
Login requirements in Settings → Tenant: Google selected, maximum time 12 hours

Login requirements in Settings → Tenant: Google selected, maximum time 12 hours

Press Esc or click outside to close

Allowed sign-in methods

  • Leave all unchecked to allow any Cortena login method for this workspace.
  • When any are selected, only those methods unlock the workspace.
  • Options: Google, Microsoft, Email magic link.

Other Cortena login options (for example DATEV or Exact Online as a sign-in method) do not unlock a workspace that only lists Google / Microsoft / email.

Maximum time since last login

Choose one of:

  • 12 hours
  • 1 day
  • 3 days
  • 7 days
  • 30 days (default) · aligned with Cortena's normal session length

Changing the setting does not sign everyone out immediately. The next time someone opens this workspace, Cortena checks their current login against the new rules.

3. What users see when access is blocked

If your current login does not match this workspace's requirements, Cortena shows Re-authenticate to continue over the workspace content.

Re-authenticate to continue overlay with Continue with Google

Re-authenticate to continue overlay with Continue with Google

Press Esc or click outside to close

Typical reasons:

  • Your current login method is not allowed for this workspace.
  • Your session is older than this workspace allows.

You can still:

  • Switch to another workspace from the account menu
  • Create a new workspace
  • Sign out

Use the buttons on the overlay (for example Continue with Google) to re-authenticate with an allowed method. After a successful login that meets the rules, the workspace unlocks.

4. Tips and limitations

  • Login requirements are per workspace: set them separately for each legal entity that needs a different rule.
  • Linked accounts in Settings are not enough: you must have signed in this session with an allowed method.
  • Admins need Admin permission on the workspace to save changes.
  • The feature must be enabled for your organisation before Login requirements appears.
  • Machine access such as MCP tokens and tenant API keys is not limited by these rules yet; ask Cortena if you need that for a compliance programme.

Quick reference

TaskWhere
Open settingsSettings → Tenant
Choose sign-in methodsLogin requirements → checkboxes
Set session freshnessMaximum time since last login
SaveSave login requirements
Unlock a blocked workspaceOverlay → allowed method (e.g. Continue with Google)
Use another workspace insteadAccount menu → switch or create workspace