Limits and time frames
Session lengths, invite validity, attempt limits, the collection schedule and how long each kind of data is kept in Advisor.
Updated View as Markdown
Advisor default values. When a time frame affects what you see on screen, each feature's page explains the effect.
Access
| Item | Value |
|---|---|
| Session with email and password, or Google | 7 days |
| Session through company SSO | 8 hours |
| Verification code step at sign-in | 5 minutes, up to 5 wrong codes |
| Sign-in attempts | 5 per minute per IP address |
| Code checks | 10 per minute per IP address |
| Invite validity | 7 days, single use |
| Password | At least 10 characters, with a letter and a number; at most 72 bytes |
| Recovery codes | 8 codes, each single use |
There is no account lockout after wrong attempts. The limit applies per IP address and per minute.
Collection
| Item | Value |
|---|---|
| Scheduled collection | Every day at 02:00 (Brasília time), with metrics, posture, changes and DNS |
| Metrics fetched on the first collection | Up to 12 months back |
| Metrics window on screen | 24 months |
| Cloudflare account change history | Up to 18 months (Cloudflare limit) |
Spike Detection
| Item | Value |
|---|---|
| Measurement window | 5 minutes |
| History fetched when a rule is created | 7 days |
| Default baseline | 7 days (minimum 3) |
| Samples needed before a rule can fire | 80% of those expected for that time of day |
| Incident list refresh | Every 5 seconds |
| Proposed action validity | 24 hours, or until the incident closes |
Retention
| Data | How long |
|---|---|
| Notifications in the bell | 90 days |
| Audit trail | 365 days |
For how these time frames affect collection, refer to Connections and sync.