Session timeouts: longer sessions and a new expiry warning
We have improved the way Bookassist Extranet handles inactive sessions. You now have more time before you are logged out, and the Extranet will warn you on screen before your session ends, so you are no longer signed out without notice.
At the same time, we have introduced a stricter, separate rule for users who work with credit card data, in line with the PCI DSS security standard for handling cardholder information.
What has changed
|
|
Users without credit card access |
Users with credit card access |
|
Before |
Logged out after 30 minutes of inactivity, with no warning |
Logged out after 30 minutes of inactivity, with no warning |
|
Now |
60 minutes of inactivity, with an on-screen warning beforehand |
15 minutes of inactivity, with an on-screen warning beforehand |
1. A longer session for most users
If your BEX account does not have access to credit card data, your session now lasts 60 minutes of inactivity instead of 30. That is double the time you had before, so you should find yourself signing back in far less often.
2. A warning before your session ends
BEX now shows an on-screen warning before your session expires. Previously, you were simply taken to the login page the next time you clicked something, which could mean losing unsaved work. The warning gives you the chance to save what you are doing.
3. A shorter session for users who handle card data
If your BEX account has access to credit card data, your session now ends after 15 minutes of inactivity. You will still receive the on-screen warning beforehand, but this session length cannot be extended.
Why users with card access are logged out after 15 minutes
This is a requirement of the PCI DSS security standard, which governs how payment card data must be protected. Requirement 8.2.8 states that any session with access to cardholder data must lock and require the user to sign in again after a maximum of 15 minutes of inactivity. It applies regardless of any other security measure in place, including multi-factor authentication.
In practice, this protects an account that has been left open and unattended — at a busy front desk, for example — from being used by someone who should not have access to your guests’ card details.
What this means for your property
- Reduced risk of unauthorised access to your guests’ payment information.
- Your property remains fully compliant with PCI DSS requirements.
- The trust your guests place in you when they share their card details is reinforced.
- Most of your team benefits from a longer, 60-minute session.
Do we need to do anything?
No. The change is applied automatically to all BEX accounts. There is no setting to configure and nothing to install.
We would simply suggest letting any team members who work with card data know that their session will now end after 15 minutes of inactivity, and that they should save their work when the warning appears.
Frequently asked questions
Can the 15-minute limit be extended for our property?
No. Fifteen minutes is the maximum permitted by PCI DSS for any session with access to card data, so it cannot be adjusted for individual properties or users.
We already use multi-factor authentication. Does that not cover it?
Multi-factor authentication protects the moment you sign in. The session timeout protects a session that is already open and left unattended. PCI DSS requires both.
Which of our users are affected by the 15-minute rule?
Only users whose account gives them access to credit card data. Everyone else has the 60-minute session.
Does 'inactivity' mean time spent with the Extranet open?
No. The timer counts time without activity in the Extranet. As long as you are working in the system, your session stays open.
Need help?
If you have any questions about this change, or you believe a user is being signed out earlier than described here, please contact your our Support team.