Masterplan Optimiser

Security and Audit

Security, High Availability and Audit are separate root tabs. Runtime changes require recent passkey re-authentication and are recorded in the application audit log.

Activation email

The Security tab shows whether deployment-managed SMTP is ready, the sender identity and TLS mode. It can send a token-free test message and can invalidate every active activation/passkey-reset link. SMTP credentials are never shown in the browser.

Runtime security groups

Session Lifetimes

Participant, administrator and inactivity limits.

Offline Access

How long an authenticated calendar may remain available offline.

Authentication

Recent re-authentication window and activation-link lifetime.

Passkeys

Challenge, exchange-code, re-authentication and request-rate limits.

Data Retention

Revoked/expired sessions, used links, audit entries and secret age.

Desktop Publishing

Masterplan and public schedule publish rate limits.

Limits

Maximum schedule snapshots and announcements per event.

Audit Log tab

The separate Audit Log tab filters application actions by actor, action, resource and time, with expandable sanitised details. It does not expose raw passkey challenges, activation tokens, SMTP credentials or private recovery identities.

Infrastructure operations have a separate hash-chained MP-OPT audit trail. See MP-OPT Management Console.