# Idle lock

> The desktop locks after 30 minutes without input and whenever the machine sleeps or locks. What locks, what keeps running, and the three ways back in.

Source: https://triagic.com/docs/desktop/lock

## When it locks [#when-it-locks]

* **30 minutes** with no click, keypress or scroll wheel in the Triagic window.
  Reading a long report without touching anything counts as idle; a poll or a
  running investigation does not count as activity.
* Immediately when macOS or Windows shows its own lock screen, when the machine
  goes to sleep, and at shutdown.

## What locks, and what does not [#what-locks-and-what-does-not]

The window swaps to a lock screen and every data request from it is refused until
you unlock. Cached ticket bodies are dropped from the window's memory at the same
time.

Everything in the background keeps going: ticket polling, automatic triage,
scheduled checkups and reports, the sync with your organization's configuration,
and every connected data source. A locked Triagic is still working; it is just not
showing you anything.

A lock is not a sign-out. Your session and this machine's link to the organization
are untouched, so unlocking is instant and works while offline where the door
allows it.

## Three ways back in [#three-ways-back-in]

| Door                        | Where               | Offline                                                                                                                                                    |
| --------------------------- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Touch ID**                | macOS with Touch ID | Yes                                                                                                                                                        |
| **Password**                | Everywhere          | No. The cloud checks it. You will see "Triagic can't reach the cloud to check your password" until you reconnect.                                          |
| **Passkey in your browser** | Everywhere          | No. The cloud checks the approval too. Same flow as [Sign in with browser](/docs/desktop/sign-in#sign-in-with-browser-passkeys), approved by you, for you. |

Windows has no biometric door: Electron exposes no Windows Hello API today, so
Windows gets password and passkey-in-browser. Both of those need the cloud, so
if you are offline on Windows when the lock triggers, there is no door that
works until you reconnect. On macOS, Touch ID still gets you back in.

Only the person who is locked out can unlock. A colleague's valid password or
passkey approval is refused with "That sign-in belongs to someone else"; the way
to switch users is **Sign out instead** at the bottom of the lock screen.

> **Note:** Changing the idle window
>
> 30 minutes is fixed in this release. A per-organization setting is planned; it
> will arrive through the same configuration sync as everything else.
