Protect every unattended session automatically

Cerevantix Inactive Sessions Timeout closes the security gap left by unattended Odoo workstations — with a real Settings UI, a live countdown warning, per-role and per-user policies, and an active-session dashboard your auditors can actually see.

The problem

Odoo sessions stay logged in indefinitely by default. On shared workstations, front-desk terminals, and warehouse kiosks, an unattended session hands anyone who walks up full access to customer data, pricing, HR records, and accounting — a concrete compliance and breach risk for any business subject to data-protection or audit requirements.

The solution

This module enforces a policy-driven inactivity timeout at the server level, warns users with a live countdown before logging them out, and lets administrators tune the policy per role and per user — all from a proper Settings screen, with an active-session dashboard to prove the policy is working.

Capabilities

Everything a security-conscious admin needs

Every capability below is implemented in the module.

01

Configurable Inactivity Timeout

Set how long a session may sit idle before automatic logout, right from a dedicated Settings screen — no raw system parameters to edit.

02

Live Countdown Warning

Users see a clear on-screen countdown before they are logged out, with one click to stay active — no abrupt, work-losing surprises.

03

Per-Role Timeout Policies

Assign a stricter idle limit to high-sensitivity roles and a looser one to shared kiosks, directly from the Groups form or the Timeout Policies list.

04

Per-User Overrides

Give any individual user their own timeout that beats the role and global defaults, for the rare case a single account needs a tighter or looser policy.

05

Active Sessions Dashboard

See every logged-in session in a kanban or list view — user, device, IP, country, city, and idle time — with a one-click Terminate button.

06

Password Expiry Enforcement

Optionally require users to change their password on a schedule, with an audit list flagging expired and soon-to-expire accounts.

07

Path Exclusion List

Exempt background polling, keepalive, and login/logout routes from the idle timer with a plain-language, editable exclusion list.

08

Optional Server-Side Backstop

Turn on a hard, JS-independent session ceiling that caps every session server-side as an extra layer beneath the client-side countdown.

09

Seamless Re-Login

After a timeout, users simply sign back in and resume where they left off — security without sacrificing productivity.

Workflow

How it works

1

Enable the policy

Turn on inactivity timeout in Settings and set the idle minutes and warning length that fit your risk profile.

2

Tune by role and user

Set stricter timeouts for sensitive roles and add per-user overrides where a single account needs different treatment.

3

Users see a countdown

As idle time approaches the limit, a countdown dialog gives users the chance to stay logged in with one click.

4

Audit and adjust

Review the Active Sessions dashboard and Password Status list any time to confirm the policy is working, then adjust as needed.

Questions

Frequently asked

No sales fog. If your question isn't here, email us and we'll answer it the same way.

No. It works alongside Odoo’s native session and authentication system, adding a policy-driven inactivity timer, a countdown warning, and an optional server-side backstop on top — nothing about core login is replaced.

Get the app

Buy it on the Odoo App Store

Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.

Inactive Sessions Timeout

Automatic idle-session logout with a live countdown warning, per-role timeout policies, and an active-sessions dashboard — the session security auditors expect.

Buy on Odoo App Store