Skip to content

Settings and activity

3 results found

  1. 52 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Hi everyone, returning from my last update I wanted to confirm that we have released generative answers in Xero in app help for all customers.

    We appreciate this isn't a direct live chat feature that is being asked for in this idea and will move the status back to Submitted, however we'd recommend giving this a try when you're next looking for an answer while working in Xero.

    This feature takes into account what page you’re viewing, and the version of Xero you use, to do the best to ensure that the information provided is relevant to you.

    Live chat is not something we have planned at this stage but if any steps are planned toward this, we'll let you know here.

    Elizabeth Nuss supported this idea  · 
  2. 41 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Elizabeth Nuss shared this idea  · 
  3. 1,057 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Hi everyone, we appreciate the interest surrounding this idea, however we want to be open that we're unable to extend our log-out time past 60 minutes. Xero hold a lot of sensitive information including bank data and we're required to be as secure as online banking.
    Any session information running on a web browser can potentially be stolen. If the session does not time out. You then have an infinitely long vulnerability window to session hijacking. Our best option is to keep a tight expiration window on the session cookie, and regenerate them frequently. Even setting a long timeout doesn't help with this - too long a timeout will greatly increase the risk of invasion or potentially jeopardise your personal data and the safety and integrity of the Xero application itself. This is why we maintain control of this.
    If we detect there's been no activity on a page (e.g…

    Elizabeth Nuss supported this idea  · 
    An error occurred while saving the comment
    Elizabeth Nuss commented  · 

    It's not unusual to allow the account holder/administrator to personalise the time before the software logs company users out.

    Surely we can all be responsible for managing the risk in Xero according to our company needs.