Purpose:
To manage session timeout configuration, the user must have the “Manage Tenant Settings” and “Manage User Settings” rights under System Users → System Configuration.

Timeout Settings:
For Basware Access, session expiration can be controlled per subscription (tenant) or per user. A user-specific setting overrides the tenant-specific idle timeout.
- Default idle timeout: 30 minutes.
- Tenant-specific timeout: 15–120 minutes.
- User-specific timeout: 15–120 minutes.
- Tenant-specific and user-specific timeout settings cannot be combined.
- Basware Access maximum session age: 24 hours; re-login is required after this period.
- Basware P2P maximum session age: 10 hours; re-login is required after this period.
- Purchase external catalogs can extend the idle period up to 2 hours.
- Workplace Collaboration does not idle-timeout while the user remains on that screen because it makes constant server requests.
Configuration – Tenant-Specific Timeout:
- Open Data Maintenance from AP Automation Workplace Configuration mode, General tab.
- Open the Tenant Setting edit type view (table: CMN_TENANT_SETTINGS).
- Set the default value in SessionExpiration.
- Supported range: 15–120 minutes.
- SessionExpiration cannot be used together with EnableUserBasedSessionExpiration = true.
Configuration – User-Specific Timeout:
- Open Data Maintenance from AP Automation Workplace Configuration mode, General tab.
- Open the Tenant Setting edit type view (table: CMN_TENANT_SETTINGS).
- Set EnableUserBasedSessionExpiration to true.
- Open P2P Administration → Users and select the required user.
- Set “Idle session timeout (minutes)” to the required value (15–120 minutes).
- If the field is left empty, the system-specific default of 30 minutes is used.
- This user-based feature is not supported on Purchase Manager integrated tenants.
- When EnableUserBasedSessionExpiration is true, SessionExpiration is no longer effective.

- Open P2P Administration
- Open Users
- Search for the one user who needs a different session idle timeout
- Set value to field "Idle session timeout (minutes):". Note that the field has a different name when the user language is not English.
- Supported range is 15-120 minutes.
- Leaving the field empty means that the system-specific session timeout (30 minutes) is used.

Best Practice:
It is recommended to retain the default idle session timeout of 30 minutes due to performance considerations.