Dive provides owner-level Security Settings that allow fine-grained control to match your operational policies, including access restrictions, login authentication, data/sharing restrictions, per-feature permissions, device cache settings, audit logs, and more. This article provides an overview of all these settings.
Who can configure these settings
All security settings can only be changed by users with Owner permissions.
How to open the settings screen
- Log in to Dive with Owner permissions
- Open Owner Functions from the side menu
- Select the Security tab at the top
Overview of settings
Access restriction
- Set up IP address restriction — Allow access only from specific locations or via VPN (supports IPv4/IPv6, single IP, range, or CIDR)
Login authentication
- Set up password policy — Password expiration and mandatory password change on first login
- Make two-factor authentication (MFA) mandatory for all team members — Require TOTP for all team members (Enterprise plan only)
- Set up Single Sign-On (SSO) — Microsoft Entra ID (OIDC) / SAML 2.0 integration, disable non-SSO login (Enterprise plan only)
- Prohibit the use of email-free accounts — Prevent new issuance of ID login-type accounts
- Set up automatic logout (Session) — Configure the time until logout with no activity (30 minutes to 24 hours or unlimited) and the maximum time from login to logout (24 hours to 90 days or unlimited). You can also set whether viewing SOP player, during a remote support call, or while uploading materials should be counted as inactivity (by default, these activities are counted as inactivity). You can choose whether to apply automatic logout to Dive apps (smartphone/smartglasses) as well (default is browser only). You can also specify which groups or users should be excluded from automatic logout
- Logged-in devices — Check which devices team members are logged in from and force logout in case of device loss or resignation
Data / sharing restrictions
- External sharing prohibition setting (enable/disable external sharing) — Whether to allow the time-limited external sharing URL feature as a team
Permitted user roles per feature
- Permitted user roles per feature — Role thresholds for SOP file export / Download of file-based SOPs / Procedure list Excel export / external sharing / Media download / Download attachments / Development, Qualifications and Training export / Usage report export / Viewing records and checksheet export / Work analysis export / Creation Plan export (Enterprise plan only)
Device-side control
- Device cache settings (Do not leave view data on the device) — Disable offline playback and pre-loading to always require network connection (Enterprise plan only)
Logs
- Export audit log as CSV — Download operation logs for the entire team in CSV format
Related (Settings in the "Business rules" tab)
The following settings are in the Business rules tab of Owner Functions. They are separated as rules for business operations rather than security settings.
- Approval settings — Whether the originator can also be an approver, whether to allow publishing without approval, etc. (the approval workflow itself is configured from User management)
- Dictionary / glossary operation permissions — User roles who can propose, approve, or directly edit the Pronunciation Dictionary and Terminology Glossary
- Allow viewing folders under subordinate groups (Folder view scope) — Set whether selected roles (Group Administrator or above, Created user or above, View-only user or above) can view folders intended for their subordinate groups (configure view, target roles, and edit/revision permission; both view and edit are disabled by default)
Related (Personal settings / External connection requirements)
- Two-factor authentication (Set up personally)
- About allowlist in security (External connection domain)
Tips for effective use
- When setting up IP address restriction before production operation, if the setting administrator's IP is not included, it will be automatically added. If your IP is not covered by the restriction, you will not be able to log in even as an owner. Be careful if you are setting this up from outside your usual network.
- Before enabling MFA requirement, make sure the owner has already registered for MFA (enabling while unregistered will make you unable to operate)
- Before enabling SSO enforcement (disable non-SSO login), confirm SSO login with a test user
- The standard role threshold for each feature is Dive's recommendation. Adjust based on your organization's security policy