Security

Organization owners and admins open Settings → Security to manage session policies and view outbound IP addresses.

Session policies

Set Max session lifetime and Idle timeout in hours, then select Save. Leave either field empty to use its default behavior. Discard restores your saved values.

Sign out all members opens a confirmation before revoking the organization's browser sessions, except your current session. It does not revoke API keys.

See Session policies for limits, defaults, and how changes affect existing sessions.

Outbound IP addresses

Copy your organization's configured addresses in /32 format and allowlist every listed address on the destination firewall. These addresses apply to supported HTTPS connections from Sim and its background workers.

Contact Sim support or your deployment administrator to configure dedicated IPs and confirm connection coverage.

Connection coverage

Dedicated routing supports public IPv4 destinations over HTTPS on port 443. It applies to supported Search connector API requests, HTTP request blocks, MCP and A2A connections, and HTTP requests made through Sim's local Function runtime. Background jobs use the same organization assignment.

Native database connections, AWS SDK integrations, remote sandbox traffic, and browser requests keep their existing network paths. Other provider SDKs and OAuth authorization or token refresh calls require separate coverage confirmation. Dedicated IPs do not change access permissions in connected services.

Google Drive, Fireflies, Google Workspace user and group discovery, and Atlassian OAuth site discovery currently use their existing network paths.

If dedicated routing is unavailable, affected requests fail instead of using shared IPs. Organizations without dedicated routing keep their existing behavior.

Availability

On Sim Cloud, Security settings require an Enterprise organization and an owner or admin role. On self-hosted deployments, the outbound IP section is available to organization administrators; session controls appear only when session policies are enabled. See self-hosted enterprise configuration.