Skip to content

Account Security Settings

Security teams reviewing Pactly usually ask the same questions: how long until an idle session logs out, who gets told when someone is hammering a login, who is watching admin-level activity, and where a link in a document can point. This page is the reference for the account-level security controls that answer them.

Most of these settings live in the left menu under Security → General (the page header reads Security Settings). They apply to your whole company and are admin-only. Two-factor authentication is the exception: it is set per user under Account settings → Profile. This page covers the company-wide security configuration, not the sign-in flow itself; for how a user actually signs in (email-first, password vs. single sign-on, the one-time-password step), see Signing in to Pactly.

A timeout that signs a user out after a period of no activity, so an unattended session on a shared or unlocked machine does not stay open indefinitely.

SettingDetail
FieldTimeout (in minutes, 0 is disabled)
RangeAny number of minutes
DisabledEnter 0 to turn the timeout off
ScopeApplies to every user in the company

Set the value, then click Save inactivity settings.

Inactivity logout time box with a Timeout field set to 15 minutes and a Save Inactivity Settings button
The Inactivity logout time box. Enter a timeout in minutes (0 disables it) and click Save Inactivity Settings.

An email alert sent when a single account hits too many consecutive failed sign-in attempts, which can indicate a password-guessing attempt. Turn the toggle on to reveal its options.

SettingDetail
ToggleEnable failed login attempt alerts
Alert recipientsOne or more email addresses (comma-separated) that receive the alerts. Required when alerts are on.
Alert thresholdConsecutive failed attempts before an alert is sent. Between 3 and 20; defaults to 5.
Reset behaviorThe failed-attempt counter resets after a successful login.

Recipients do not have to be Pactly users, so you can send alerts to a security mailbox or SIEM intake address. Click Save failed login settings to apply.

Failed Login Alerts box with the toggle enabled, Alert recipients filled with two comma-separated emails, and Alert threshold set to 5
With the toggle on, the box reveals Alert recipients and Alert threshold. The counter resets after a successful login.

Email alerts for sensitive, admin-level operations, so a designated mailbox is notified whenever a high-privilege action happens. Turn the toggle on to reveal the recipients field.

SettingDetail
ToggleEnable privileged account monitoring alerts
Alert recipientsOne or more email addresses (comma-separated) that receive the alerts. Required when monitoring is on.

When enabled, Pactly emails the recipients for these monitored activities:

  • Admin or manager user creation
  • A user’s role being escalated to admin or manager
  • Export bundle downloads
  • Data export generation

Click Save monitoring settings to apply. As with failed-login alerts, recipients need not be Pactly users.

Privileged Account Monitoring box with the toggle enabled, an Alert recipients address filled, and the Monitored activities list
With the toggle on, the box shows the Alert recipients field and the list of monitored privileged activities.

The hosts your people may link to from a rich text form answer. A form answer does not stay in the form: it can be carried into later forms, into the agreement summary an approver reads, and into the signing email every signer receives. An unrestricted link there is a phishing surface wearing your branding, so Pactly only renders links to hosts you have named.

SettingDetail
Allowed hostsComma-separated hostnames, for example sharepoint.com, intranet.example.org. Empty by default.
SubdomainsA host covers its subdomains, so sharepoint.com also allows contoso.sharepoint.com. Name the narrowest host that works.
Empty listNo hyperlinks at all. The link button does not appear on rich text fields.
Who can linkPeople signed in to your company only. An external party filling your form never gets the link tool.

Enter the hosts and click Save hyperlink allowlist.

Links to a host that is not on the list, and any link typed by an external party, render as plain text everywhere they appear. The wording around the link is kept, so nothing the author wrote is lost.

Two-factor authentication (2FA) adds a one-time code from an authenticator app on top of the password. In Pactly it is set up by each user on their own account, not switched on company-wide from Security Settings.

To enable it, a user goes to Account settings → Profile, finds the Two-factor authentication section, enters their current password, and scans the QR code (or copies the secret key) into an authenticator app such as Microsoft Authenticator or Google Authenticator. They then enter the current one-time code to confirm. The section shows an Enabled or Disabled status pill.

Once 2FA is on, the user is asked for the one-time code as a second step after their password at sign-in. To turn it off, the user returns to the same section, enters their password, and disables it.