This feature allows you to permit access only from specific IP addresses (or ranges of IP addresses), while blocking all others. By allowing access only through designated routes such as your company network, branch offices, or VPN connections, you can significantly strengthen security.
Dive supports global IP address restrictions (IPv4/IPv6) in three formats: single IP, range, or CIDR. Once configured, login attempts from IP addresses not on the allowlist are blocked, even for users with Owner privileges. On the Enterprise plan, you can choose how to handle access from outside the allowed networks, such as "Only material upload is available" or "Available if multi-factor authentication is passed" (see "How to set access from outside the allowed networks" below).
Who can configure this
Only users with Owner privileges can configure this setting.
Before you start
This feature is a powerful restriction. There is a risk that misconfiguration could lock out even the Owner, so please make sure to check the following:
- Verify that the IP addresses you plan to register are global IPs (outbound IPs assigned by your ISP or VPN provider)
- Before configuring, make sure to include your own global IP address
- It is recommended to export to Excel and keep a backup of the allowed IP addresses so you can verify them immediately after configuration
* If you happen to get locked out of your account, please contact the Dive support team at customer-success@episotech.com.
Configuration steps
- Log in to Dive and click [Owner Functions]
- Select the [Security] tab at the top and open the [IP Address Restriction Settings] card
-
Check the box for "Use IP address restriction"
- Open the allowlist field and click one of the following options depending on the format you want to register
-
[+ Add]: Register a single IP address or CIDR format (example:
192.168.0.0/24) - [+ Add by range]: Register by specifying a range from start IP to end IP
-
[+ Add]: Register a single IP address or CIDR format (example:
-
Enter the IP addresses you want to allow (supports 3 formats)
-
Single IP:
203.0.113.5/2001:db8::1 -
Range:
203.0.113.5through203.0.113.50 -
CIDR:
192.168.0.0/24/2001:db8::/32
If the format is invalid while you are entering it, an error message in red will appear immediately
-
Single IP:
- When finished, click [Save]
Safety at save time
When you save, if the network currently being used for your session (the IP from which you are accessing) is not included in the allowlist, the following message will appear. It will be added automatically, so please click [OK]. This prevents you from being locked out immediately after configuration.
Additionally, if you have set the "People who passed multi-factor authentication" row below to [All features] and you are included in that group, this message will not appear. This is because you can reconnect using multi-factor authentication and change the setting. When it is set to [Material upload only], you cannot open the settings screen even after reconnecting, so the message will appear as before.
How to set access from outside the allowed networks
You can set how to handle access from networks not on the allowlist, such as business trip destinations or mobile networks, based on user segments. In the initial state, both segments are set to "Not available", and the behavior will not change until you modify it.
Even if you change this setting, the list of allowed IP addresses will not change. Usage from the allowed networks will remain the same. Only how users outside those networks are handled will change.
Two rows to decide
The setting is "who" and "what they can use" in two rows. Each row has a dropdown menu to select the range.
- People who passed multi-factor authentication …… [Not available] / [Material upload only] / [All features]
- Everyone else …… [Not available] / [Material upload only]
If you select anything other than [Not available], the targeting of the affected users will appear below that row. Select either [Everyone] or [Only the specified users]. If you select [Only the specified users] but don't specify any users, no one can use that row (a warning will also appear on the settings screen).
The two rows are independent. For example, if you want to operate such that "administrators can use all features from outside the network, but field staff can only upload materials from outside", set the first row to [All features] and the second row to [Material upload only]. Conversely, if you want to operate such that "procedures are not visible outside the network, but only allow access to those who passed multi-factor authentication", set the first row to [Material upload only] and the second row to [Not available].
The settings screen always displays how your current selections will branch. Before saving, verify that you have the intended combination.
Available plans
This setting is available on the Enterprise plan. Only users with Owner privileges can configure this setting.
Configuration steps
- Open [Owner Functions], select [Security] from the tabs at the top, and open the [IP Address Restriction Settings] card
- Verify that "Use IP address restriction" is enabled (if IP address restriction is disabled, this setting has no meaning)
- For each row under [Access from outside the allowed networks], select the range you want to allow. When you select [All features], a confirmation message will appear; please review the content and click [OK]
- Select [Everyone] or [Only the specified users] for each row. If [Only the specified users] is selected, choose the target users
- Verify the branching displayed under [How this setting behaves]
- Click [Save]
When you uncheck "Use IP address restriction", this setting will also be disabled at the same time. This prevents the unintended opening of access from outside the allowed networks when you re-enable IP address restriction.
What you can do with "Material upload only"
When users permitted in this range connect from outside the allowed network, only a single screen for uploading materials is displayed. Screens where you can view content, such as procedures, materials list, management screens, and reports, are not displayed.
● What you can do
- Upload videos, photos, and other files (including AI analysis during upload)
- Select the scope of visibility for the materials being uploaded (myself only / Group Shared / Team sharing)
- View progress of the files currently being uploaded
- Switch the display language and log out
● What you cannot do
- View, search, edit, or publish procedures (including shared URLs and offline playback saved on the device)
- Display the materials list or play/download uploaded materials
- View AI analysis results (results of materials you uploaded are also not displayed)
- Access any functions such as management screen, Usage Report, Skill Map, or courses
- Open account settings on your own (password changes, multi-factor authentication registration, profile)
After uploading materials, access the materials list from the allowed network to verify them. If you set the visibility scope to [Myself only], other users cannot access the materials until you access them from the allowed network.
Note that screens requiring action, such as password changes on first login or multi-factor authentication registration when MFA becomes mandatory, will be displayed even in this state.
Applicable login methods
The two rows support different login methods.
- "People who passed multi-factor authentication" row: Only users who log in with email address and password and have multi-factor authentication configured are eligible. Single sign-on (Microsoft Entra ID / SAML) cannot be verified for multi-factor authentication on Dive's side because identity verification is performed on the IdP side during login. Email-free accounts (IDs issued by administrators to log in) and smart glasses QR code logins are designed for shared device use, so neither can be targeted for this row
- "Everyone else" row: Since multi-factor authentication is not required, all of the above login methods can be targeted. For example, if field staff upload videos taken on mobile networks, configure it in this row
Applicable user permissions
In the row where you select [Material upload only], user permissions that can upload materials (Owner, Team Administrator, Group Administrator, Created user) are eligible. View-only users and guests will continue to be unable to use the service from outside the allowed networks.
User preparation
Users eligible for the "People who passed multi-factor authentication" row must register multi-factor authentication in advance. Please complete the registration while connected to the allowed network. For instructions, refer to Two-factor authentication (personal setup).
If operating team-wide, also consider using Making two-factor authentication (MFA) mandatory for all team members. This setting can be used even if MFA is not mandatory. Users who have not registered multi-factor authentication will simply not be eligible for this row.
No user preparation is required for the "Everyone else" row.
Messages when you cannot log in
- "IP address restriction: You cannot use the service on the network you are currently connected to": Both rows are set to [Not available]. Please connect from an allowed network
- "Multi-factor authentication setup is required to use the service from outside the allowed networks. Please connect to an allowed network and set it up": You are an eligible user for the "People who passed multi-factor authentication" row, but multi-factor authentication has not yet been registered
- "Use from outside the allowed networks is not permitted. Please check with your administrator": You are not included in the target users for either row. Ask the Owner to add you
- "From outside the allowed networks, only material upload is available. Your account cannot perform uploads": Your user permission does not allow material uploads (view-only user or guest)
- "With this login method, you cannot use the service from outside the allowed networks": This login method cannot be targeted for the "People who passed multi-factor authentication" row (single sign-on, email-free accounts, etc.). If you want to allow access to these users, set the "Everyone else" row to [Material upload only]
We also check again after you log in
Your connection's IP address is verified not only at login but also at the following times.
- Every 5 minutes while the screen is displayed
- When returning to the screen or app, or when reconnecting to the network
- When an administrator enables IP address restriction or changes the allowlist
- Before opening a procedure from a received link or QR code in the Dive app
If your connection is from an unauthorized network, it will be checked again after 10 seconds, and if it is still unauthorized, you will be logged out. The login screen will display "IP address restriction: You were logged out because you are now connecting from outside the allowed networks." If communication cannot be verified or cannot be determined, you will not be logged out. Users permitted through multi-factor authentication or the upload screen exception are not subject to this check.
A device that switches from a company Wi-Fi to a mobile network will be logged out if it does not reconnect within 10 seconds. If you have devices using mobile networks in the field, please verify the allowlist or the exception settings mentioned above.
Checking logs
Records of changes to the setting, permissions or denials of login from outside the allowed networks due to this setting, and logouts resulting from verification checks after login are retained in the audit log. You can verify who accessed the system from which IP address and when (refer to Export audit log to CSV).
Excel import and export
You can also manage the list of allowed IPs as a batch in Excel. Even for organizations managing many branch offices and VPNs, you can register lists prepared in Excel directly.
- [Export to Excel]: Download the current allowlist as an Excel file
- [Excel import]: Import the allowlist from an Excel file (.xlsx)
Use this feature when you want to keep backups for operational rule changes or audits.
Tips for effective use
- Always test before production deployment: Save with your global IP included in the minimal configuration and verify logout and re-login
- Force VPN usage: Effective when you want to prevent direct access from home or cafes and require login through a VPN
- When expanding branch offices: When a new branch office is established, add its global IP to the allowlist before starting operations
- In mixed IPv4/IPv6 environments: Some ISPs use both IPv4 and IPv6. Including both in the allowlist is safer