Documentation

Library Settings

Explore Govform.com guidance, configuration details and practical steps for library settings.

Library session settings

Session settings control inactivity timeouts and warning behaviour for end users across the library. They must be applied separately to QA and Production.

Open the library, select Library settings, then Session settings.

Understand the two durations

Setting Behaviour
Session timeout Signs the user out after the configured number of minutes without activity.
Timeout warning display duration For an anonymous service, controls how long the warning is shown before the session expires and unsaved data is lost.

For a signed-in service, changes on the current page are saved in the background and restored after the person signs back in. For an anonymous service, the warning dialog explains that expiry will lose the session’s data. These behaviours make it essential to test both service access models rather than assuming one timeout experience.

Choose a proportionate timeout

Balance the sensitivity of the service, use on shared devices and the realistic time needed to complete a page. A very short timeout can exclude people who need more time to read, gather evidence or use assistive technology. A very long timeout can expose data on an unattended device.

Consider:

  • the longest page or document-review task;
  • whether users must leave the service to find information;
  • shared-device and kiosk use;
  • the sensitivity of displayed and entered data;
  • save-and-return behaviour for signed-in users;
  • support guidance after expiry.

The warning must last long enough for a person to understand it and choose to continue. Test with keyboard navigation and a screen reader, not only with a pointer.

Test the complete expiry path

  1. Apply a safe test duration to QA.
  2. Start a signed-in journey, change an answer and wait for expiry.
  3. Sign in again and confirm the current-page change is restored as intended.
  4. Repeat with an anonymous service and confirm the warning appears at the expected time.
  5. Allow the anonymous session to expire and check that the message and recovery route are clear.
  6. Choose to continue from the warning and confirm the timer is renewed.
  7. Check long pages, uploads and assistive-technology use.

Do not run a timeout test with real personal data in QA.

Apply the setting

The page shows when the session configuration was last applied to QA and Production. Apply to QA environment and Apply to Production environment are separate operations. A change saved to QA does not alter Production.

Coordinate a live timeout reduction with service owners and support teams. A person already part-way through a journey may experience the new policy after the environment update.

Related guides

Keep exploring

Explore more documentation

View all categories →