Overview
Workspace Expiration is available on Teams, Business and Enterprise plans and is currently in beta. Contact your support@sendsafely.com to have Workspace Expiration enabled for your portal.
Workspace File Expiration lets individual Workspace Owners and Managers configure automatic file expiration on a Workspace-by-Workspace basis.With enforcement, Admins can require Workspace expiration across your organization and define default, minimum, and maximum expiration periods. Once enabled, SendSafely will automatically bring all existing Workspaces into compliance with the new policy.
Before enabling enforcement, it’s important to understand the potential impact. Existing Workspaces without expiration will inherit your default setting, and files that are already older than the newly applied expiration period will expire immediately. We strongly recommend reviewing the Workspace Files admin report before enabling enforcement to identify files that may be affected, and downloading those files where appropriate.
Workspaces that need to persist indefinitely, such as those owned by service accounts or used for long-running integrations, can be exempted from enforcement using a Security group.
Setting Organization-wide Expiration Policies
From the Enterprise Console > Configuration tab, Portal Admins can define the following Workspace specific expiration parameters:
- Default – the expiration value, in days, applied to Workspaces when expiration is turned on for the first time. Admins can choose any default between 1 and 1095 days (3 years).
- Minimum – the shortest expiration period, in days, that a Workspace Owner is allowed to configure. Admins can choose a minimum as low as 1 day.
- Maximum – the longest expiration period, in days, that a Workspace Owner is allowed to configure. Admins can choose a max up to 1095 days (3 years).
- Enforced – a toggle that determines whether Workspace expiration is mandatory for every Workspace in the portal
Workspace Owners and Managers retain the ability to adjust expiration within the min/max range you set. If enforcement is enabled, they cannot turn expiration off.
How Enterprise Settings Affects Existing Workspaces
Once settings are adjusted and saved, SendSafely automatically brings every Workspace into compliance with your organization's policy. All changes to expiration settings as a result of these org wide policies are captured in each individual Workspace's Activity Log.
Adjusting Minimum and Maximum ranges
- Workspaces with an expiration setting outside the allowed minimum/maximum range are automatically adjusted to the nearest boundary of that range.
- Files older than the new maximum value are immediately expired.
- Workspace Owners and Manager can adjust Workspace settings within the min/max range.
Enforcing Workspace Expiration
- New Workspaces inherit the organization's default expiration setting
- Existing Workspaces without expiration enabled also inherit the organization's default expiration setting.
- Files older than the default setting are immediately expired.
- Workspace Owners and Manager are unable to turn Workspace Expiration off
Turning on Enforce Workspace Expiration immediately changes expiration settings across every Workspace in your portal — including Workspaces that have never had expiration enabled.
Before You Enable Enforcement
Because enforcing expiration can result in existing files becoming expired right away, it is important to review the impact before proceeding. Before enabling enforcement, run the Workspace Files admin report so you understand the scope of the change before it happens. We recommending downloading and exporting files for safe keeping and/or using Security Groups to exempt certain users and their workspaces.
When you enable enforcement, SendSafely displays a warning that summarizes the change you're about to make. Read this warning carefully before continuing.
Reviewing the Workspace Files Report
The Workspace Files admin report includes details for every file across every Workspace in the portal:
- Create Date/ Last Update Date (UTC) - the anchor date for expiration calculation. The workspace expiration setting (in days) is added to this date to determine expiration date.
- Expiration Date (UTC)– Populated if the Workspace is already subject to expiration. The date the file is scheduled to expire under the current policy. This date is blank if the Workspace does not have file expiration enabled.
- File State – whether the file is currently Active or Expired. Files remain in expired state for 30 days before being deleted.
Use this report both before enabling enforcement, to gauge impact, and afterward, to monitor which Workspaces and files are affected on an ongoing basis. We recommend focusing review on files with a create date older than the new, enforced default setting. These are the files that will be immediately expired.
Exempting Users from Enforcement
Some Workspaces are meant to persist indefinitely — for example, those owned by service accounts or used by long-running integrations. To support these cases, Portal Admins can exempt specific users from organization-wide Workspace expiration enforcement using a dedicated security group.
Adding a user to this security group exempts that user, and every Workspace they own, from the enforced expiration policy. Their Workspaces will not inherit the default expiration setting and will not be adjusted to the enforced min/max range. Contact support@sendsafely.com to configure the Workspace Expiration Security Group
Comments
0 comments
Article is closed for comments.