Design Session and Device Management
Trust, Privacy & Ethics · security, authentication, privacy
Updated 2026-07-28
- Show people where they are signed in. A list of active sessions is one of the few security features ordinary users understand and act on.
- Describe each session in human terms. A device type, an approximate location, a browser, and a last-active time are recognisable, and an address alone is not.
- Mark the current session clearly so nobody signs themselves out while trying to remove someone else.
- Make ending a session immediate and obvious in its effect. Say plainly that the device will be signed out and what happens to any work in progress there.
- Provide a single control that ends every other session, and put it where someone would look during a panic rather than three levels into settings.
- Notify on new sign-ins from unfamiliar devices, with a direct route to revoke, because a notification without an action is only anxiety.
- Distinguish sessions from connected applications. Revoking a browser login and revoking an integration's access are different actions with different consequences.
- Keep the language calm and factual. Security screens written in alarming tones cause people to disable things they need or ignore the warnings entirely.
Users can only protect an account they can see, and a session list turns an abstract worry into something they can do something about.
Related guides