In Dive, we provide detailed control mechanisms for owners—such as access restrictions, login authentication, data sharing restrictions, role-based permissions, device cache settings, and audit logs—that align with your operational policies. This article covers the full overview.
Who can configure
All Security Settings can only be changed by users with Owner permissions.
How to access Security Settings
- Log in to Dive with Owner permissions
- Open [Owner Functions] from the side menu
- Select [Security] from the top tabs
Configuration options overview
Access restriction
- Configure IP address restrictions — Permit access only from specific locations or via VPN (supports IPv4 / IPv6, single IP, IP range, and CIDR)
Login authentication
- Configure password policy — Password expiration and forced password change at first login
- Require two-factor authentication (MFA) for all team members — Require TOTP for all team members (Enterprise plan only)
- Configure Single Sign-On (SSO) — Microsoft Entra ID (OIDC) / SAML 2.0 integration, prohibit non-SSO logins (Enterprise plan only)
- Prohibit the use of email-free accounts — Prohibit the issuance of new ID-type accounts
- Session — Time until logout with no activity (30 min - 24 hours / unlimited) and maximum time from login to logout (24 hours - 90 days / unlimited). You can also specify groups and users to exclude from auto-logout.
- Logged-in devices — View devices where members are logged in and force logout when devices are lost or members leave.
Data / sharing restrictions
- External sharing restrictions (Enable / disable external sharing) — Whether to allow time-limited external sharing URL functionality for the team
Permissions per feature
- Permitted user roles per feature — Role threshold for SOP export / folder Excel export / external sharing / media download / attachment download / skill map export / usage report export (Enterprise plan only)
Device-side controls
- Device cache settings (Do not retain view data on device) — Disable offline playback and preload, and always require network connection (Enterprise plan only)
Logs
- Export audit log as CSV — Download operation logs for the entire team as CSV
Related (Personal settings / External connection requirements)
- Two-factor authentication (Personal setup)
- About allowlists in security (External connection domains)
Tips for effective use
- Before production deployment, when configuring IP address restriction, if the administrator's own IP is not included, it will be automatically added. If an IP is outside the restriction, even owners cannot log in, so be careful when configuring from a network you do not normally use.
- Before enabling MFA requirement, ensure the owner has completed MFA registration (if enabled without registration, the owner will not be able to operate).
- Before enabling SSO enforcement (Prohibit non-SSO logins), confirm SSO login works with a test user.
- The default role threshold for each feature is Dive's recommendation. Adjust it according to your organization's security policy.