We have an InfoSec standard that requires that application sessions be terminated after a pre-determined period of time independent of user activity. This standard is separate from the standard that requires a user session be timed out after a pre-determined period of time based on user inactivity. The latter standard is supported by Aha! Roadmaps today; the former standard is not.
A finding will need to be submitted against Aha! for not meeting the standard.
Extend the current inactivity logout to include a second time range for session logout.