On this page

Organisation sessions shows every active sign-in to your workspace, across all members and both the web app and the Android app, with the device, browser, IP address, when it started, when it was last used and when it expires. Owners and Admins can revoke any session on the spot. The same page is where to check what a VGraple support session looked like when you asked for help.
Sessions and view-as
- 1Go to Settings
- 2Read the list
- 3To end a session
- 4If a member has left or a
- 5Check the audit log for actions taken
Before you start
- You need Owner or Admin access.
- Sessions are created at sign-in and expire after 24 hours of inactivity; active sessions rotate their token every 6 hours.
Steps
- Go to Settings, then Organisation sessions.
- Read the list: each row shows the member's name, email and role, a device and browser label parsed from the user agent (for example "Android" or "Windows - Chrome"), the IP address, created time, last used and expiry.
- To end a session, click Revoke on its row. The member is signed out on their next request.
- If a member has left or a device was lost, deactivate the member under Team as well, so a fresh sign-in is impossible.
- Check the audit log for actions taken from the revoked session if you suspect misuse.

What you will see
Sessions are grouped per member with the most recently used first; inactive members still show their sessions until they expire or are revoked. A session from an unfamiliar country or an unexpected device is the signal to revoke and to ask the member to reset their password and enable 2FA.
What a normal session list looks like
A five-person team usually shows five to ten rows: one per member on the web, and one more for each member who also uses the Android app. Rows for the same member from the same device on consecutive days are normal (a new sign-in after the 24-hour idle expiry). Rows that deserve attention: two very different locations for the same member at the same time, a device type the member does not own, a session for a member who left, and any row still active for a device reported lost.
Sessions and the audit log together
The audit log answers "who did what"; sessions answer "from where and on which device". During an investigation, find the action in the log, note the actor and the time, then find the session that was active for that member at that time to see the device and IP. If the device or location does not match the member's normal pattern, revoke every session for that member, reset their password and turn on 2FA before anything else.
Recommended routine
- Monthly: scan the list, revoke anything unfamiliar, and deactivate members who have left.
- On any staff change: deactivate the member the same day; their sessions end and their seat frees.
- On a lost or stolen phone: revoke that device's session, ask the member to change their password, and confirm 2FA is on.
- After any suspicious message or broadcast: match the time against sessions and the audit log to identify the actor.
How sessions work behind the scenes
A session is created at sign-in and stored with the device's user agent and IP. Every request checks it; while the member is active, the token rotates every six hours so a copied token has a short life, and after 24 hours without activity the session expires on its own. The Android app follows the same rules and shows in the list as an Android device. Revoking deletes the record, so the next request from that device is rejected with a sign-in prompt.
What view-as means
When you open a support thread, a VGraple platform super admin may need to see what you see. View-as lets them open your organisation with a simulated role (for example, as an Agent) to reproduce the problem. Three rules apply: the access is tied to a support request, every action is written to your audit log with the super admin flag, and secret values (API keys, payment and Conversions API settings) are never displayed. Support hours are Monday to Friday, 10 AM to 7 PM IST, and support actions happen inside those threads.
Settings and options
| Setting | What it does | Default |
|---|---|---|
| Revoke | Ends one session immediately | Per row |
| Session expiry | Inactivity limit | 24 hours |
| Token rotation | Refreshes the session token while active | Every 6 hours |
| Member deactivation | Prevents new sign-ins | Under Team |
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| A member says they were signed out unexpectedly | A session was revoked, or 24 hours of inactivity passed | Sign in again; check who revoked it in the audit log |
| The Android app keeps asking to sign in | The device clock is wrong, or the app version is old | Set the time automatically and update the app |
| A session shows "Unknown device" | The client sent no recognisable user agent | Usually an API client or an old browser; revoke if unexpected |
| A super admin session appears | A support request was handled | Check the linked support thread; contact support if you did not open one |