Home/Help Center/Sessions and view-as

Account, billing and security

Organisation sessions and view-as

See every active sign-in to your VGraple CRM organisation (device, browser, IP, last used), revoke sessions, and understand what view-as means when VGraple support looks.

By Chirag Darji · Updated 27 Aug 2026 · 5 min read

On this page
  1. Before you start
  2. Steps
  3. What you will see
  4. What a normal session list looks like
  5. Sessions and the audit log together
  6. Recommended routine
  7. How sessions work behind the scenes
  8. What view-as means
  9. Settings and options
  10. Troubleshooting
Team members in VGraple CRM with owner, admin and agent roles and their permissions

Organisation sessions shows every active sign-in to your workspace, across all members and both the web app and the Android app, with the device, browser, IP address, when it started, when it was last used and when it expires. Owners and Admins can revoke any session on the spot. The same page is where to check what a VGraple support session looked like when you asked for help.

Sessions and view-as

  1. 1Go to Settings
  2. 2Read the list
  3. 3To end a session
  4. 4If a member has left or a
  5. 5Check the audit log for actions taken
The steps on this page, in order.

Before you start

  • You need Owner or Admin access.
  • Sessions are created at sign-in and expire after 24 hours of inactivity; active sessions rotate their token every 6 hours.

Steps

  1. Go to Settings, then Organisation sessions.
  2. Read the list: each row shows the member's name, email and role, a device and browser label parsed from the user agent (for example "Android" or "Windows - Chrome"), the IP address, created time, last used and expiry.
  3. To end a session, click Revoke on its row. The member is signed out on their next request.
  4. If a member has left or a device was lost, deactivate the member under Team as well, so a fresh sign-in is impossible.
  5. Check the audit log for actions taken from the revoked session if you suspect misuse.

Profile settings in VGraple CRM with two-factor authentication

What you will see

Sessions are grouped per member with the most recently used first; inactive members still show their sessions until they expire or are revoked. A session from an unfamiliar country or an unexpected device is the signal to revoke and to ask the member to reset their password and enable 2FA.

What a normal session list looks like

A five-person team usually shows five to ten rows: one per member on the web, and one more for each member who also uses the Android app. Rows for the same member from the same device on consecutive days are normal (a new sign-in after the 24-hour idle expiry). Rows that deserve attention: two very different locations for the same member at the same time, a device type the member does not own, a session for a member who left, and any row still active for a device reported lost.

Sessions and the audit log together

The audit log answers "who did what"; sessions answer "from where and on which device". During an investigation, find the action in the log, note the actor and the time, then find the session that was active for that member at that time to see the device and IP. If the device or location does not match the member's normal pattern, revoke every session for that member, reset their password and turn on 2FA before anything else.

  • Monthly: scan the list, revoke anything unfamiliar, and deactivate members who have left.
  • On any staff change: deactivate the member the same day; their sessions end and their seat frees.
  • On a lost or stolen phone: revoke that device's session, ask the member to change their password, and confirm 2FA is on.
  • After any suspicious message or broadcast: match the time against sessions and the audit log to identify the actor.

How sessions work behind the scenes

A session is created at sign-in and stored with the device's user agent and IP. Every request checks it; while the member is active, the token rotates every six hours so a copied token has a short life, and after 24 hours without activity the session expires on its own. The Android app follows the same rules and shows in the list as an Android device. Revoking deletes the record, so the next request from that device is rejected with a sign-in prompt.

What view-as means

When you open a support thread, a VGraple platform super admin may need to see what you see. View-as lets them open your organisation with a simulated role (for example, as an Agent) to reproduce the problem. Three rules apply: the access is tied to a support request, every action is written to your audit log with the super admin flag, and secret values (API keys, payment and Conversions API settings) are never displayed. Support hours are Monday to Friday, 10 AM to 7 PM IST, and support actions happen inside those threads.

Settings and options

SettingWhat it doesDefault
RevokeEnds one session immediatelyPer row
Session expiryInactivity limit24 hours
Token rotationRefreshes the session token while activeEvery 6 hours
Member deactivationPrevents new sign-insUnder Team

Troubleshooting

SymptomLikely causeFix
A member says they were signed out unexpectedlyA session was revoked, or 24 hours of inactivity passedSign in again; check who revoked it in the audit log
The Android app keeps asking to sign inThe device clock is wrong, or the app version is oldSet the time automatically and update the app
A session shows "Unknown device"The client sent no recognisable user agentUsually an API client or an old browser; revoke if unexpected
A super admin session appearsA support request was handledCheck the linked support thread; contact support if you did not open one

Frequently asked questions

Where do I see who is signed in?
Settings, then Organisation sessions. It lists every active session across your members with device, browser, IP address, created time, last used and expiry.
Can I sign someone out remotely?
Yes. Click Revoke on the session. Their next request is rejected and they must sign in again.
How long does a session last?
Sessions expire after 24 hours of inactivity and rotate their token every 6 hours while active; the Android app keeps its own session on the same rules.
What is view-as?
A platform super admin can open your organisation to help with a support request. View-as simulates a role for troubleshooting; every action taken is written to your audit log and flagged as a super admin action.
Can support read my messages?
Only when acting inside your organisation for a support request, with the action logged. Personal fields are encrypted at rest and secrets stay hidden.
Does revoking a session change the password?
No. If you suspect a compromised account, revoke the session and reset the password, then enable 2FA.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.